K05 assurance architecture
Assurance Cases
Direct answer
An assurance case is a falsifiable claim-to-evidence argument. It is stronger than a checklist because it identifies assumptions, hazards, evidence gaps, and conditions that can defeat the claim.
What the case is for
A named critical datacenter can preserve approved safety and mission functions under defined cyber, physical, electromagnetic, power, cooling, autonomy, and recovery stressors without transferring authority to an autonomous system.
Public, non-classified reference pattern. A facility must replace every generic assumption with site evidence, license conditions, actual topology, competent authority, and current test results.
Assurance claims
Authority and mission boundary is explicit
Every automated protection action and any external mission support is traceable to a competent authority, named asset scope, allowed effects, prohibited outcomes, duration, stop conditions, and review route.
High-consequence events are identified and bounded
The facility identifies the cyber-enabled physical and mission consequences that must be prevented, their initiating pathways, critical functions, and independent protections.
Deterministic separation protects safety functions
Safety-significant and critical OT functions cannot be commanded from lower-trust datacenter or external networks through an unverified software path.
Identity, firmware, and management planes remain trustworthy
Privileged identities, workload identities, signing keys, BMCs, firmware, update systems, model artifacts, and management networks are separately protected and continuously evidenced.
Autonomous defense is bounded, causal, and reversible
Autonomous defenders act only through pre-authorized internal actions whose physical consequence, confidence threshold, rollback, evidence, and safe-state behavior have been tested.
Sensor and model disagreement cannot directly control force
Physical-security autonomy separates sensing, classification, access denial, non-destructive protection, authorized responder routing, and any force-enabled response into independently governed layers.
Power, cooling, and timing failures do not defeat protected functions
The facility can detect corrupted or unavailable power, cooling, environmental, and timing data; reject unsafe commands; and transition to approved operating states without relying on the compromised channel.
Recovery is clean, evidenced, and repeatable
Critical services can be restored from independently protected, provenance-verified states while preserving evidence and preventing reinfection or unsafe configuration reintroduction.
Evidence supports readiness without overclaiming
Every public or procurement readiness state is traceable to exact releases, tests, defects, deployment identity, authority, incidents, uptime, restoration, and independent-verification status.
Authorized external effects remain separate from facility defense
External cyber surveillance or effects support is never triggered solely by a facility defensive model and proceeds only through a separately approved mission package, federal or other competent authority, deconfliction, effect constraints, and post-operation accountability.
What the case does not claim
- No facility is certified by this pattern
- No reactor or datacenter deployment is claimed
- No offensive operation is authorized
- No lethal-force authority is created
- No mapping is a compliance determination