K07 · evidence-bundled critical-infrastructure assurance
Workload, device, and service identity
Direct answer
Bind every workload, device, model service and actuator to a scoped cryptographic identity, policy decision, key lifecycle, and revocation path.
Authority and evidence boundary. K07 publishes knowledge architecture, bounded reference records, procurement structures, local validation tools, signed synthetic fixtures, and point-in-time source review. It does not certify a facility, award a contract, authorize an operation, prove truth, establish deployment, or claim current operation.
Context
Network location and inherited administrator trust do not provide sufficient identity for autonomous cyber-physical action.
Proposed reference decision
Bind every workload, device, model service and actuator to a scoped cryptographic identity, policy decision, key lifecycle, and revocation path.
Alternatives considered
- IP-address trust
- shared service accounts
- long-lived static secrets
Consequences
- identity becomes a critical dependency
- revocation and offline operation require design
- actions can be attributed to a service identity
Defeaters and reversal conditions
- shared credential
- unknown key custody
- no revocation path
- identity authority unavailable during emergency
Source relationships
- NIST SP 800-161 Revision 1 Update 1 — Cybersecurity Supply Chain Risk Management Practices — National Institute of Standards and Technology; Revision 1 Update 1; FINAL. Exact claim-support entries: 1. Revalidated 2026-08-15T23:30:00Z.
Use boundary
This record is a proposed reference decision. A competent owner must bind it to actual site constraints, authority, hazards, license conditions, interfaces, implementation evidence, and change control.