K05 assurance architecture

Assurance Cases

Direct answer

An assurance case is a falsifiable claim-to-evidence argument. It is stronger than a checklist because it identifies assumptions, hazards, evidence gaps, and conditions that can defeat the claim.

Evidence boundary. These records describe architecture, control relationships, test requirements, and legal-source status. They do not certify a facility, authorize a mission, prove deployment, or replace current facility-specific engineering and legal review.

What the case is for

A named critical datacenter can preserve approved safety and mission functions under defined cyber, physical, electromagnetic, power, cooling, autonomy, and recovery stressors without transferring authority to an autonomous system.

Public, non-classified reference pattern. A facility must replace every generic assumption with site evidence, license conditions, actual topology, competent authority, and current test results.

Assurance claims

Authority and mission boundary is explicit

Every automated protection action and any external mission support is traceable to a competent authority, named asset scope, allowed effects, prohibited outcomes, duration, stop conditions, and review route.

AC-K05-C01

Recovery is clean, evidenced, and repeatable

Critical services can be restored from independently protected, provenance-verified states while preserving evidence and preventing reinfection or unsafe configuration reintroduction.

AC-K05-C08

Evidence supports readiness without overclaiming

Every public or procurement readiness state is traceable to exact releases, tests, defects, deployment identity, authority, incidents, uptime, restoration, and independent-verification status.

AC-K05-C09

Authorized external effects remain separate from facility defense

External cyber surveillance or effects support is never triggered solely by a facility defensive model and proceeds only through a separately approved mission package, federal or other competent authority, deconfliction, effect constraints, and post-operation accountability.

AC-K05-C10

What the case does not claim

  • No facility is certified by this pattern
  • No reactor or datacenter deployment is claimed
  • No offensive operation is authorized
  • No lethal-force authority is created
  • No mapping is a compliance determination