K05 assurance architecture

Assurance Claim Register

Direct answer

Ten assurance claims connect mission and safety propositions to evidence, defeaters, hazards, recovery objectives, source qualifications, and site-tailoring questions.

Evidence boundary. These records describe architecture, control relationships, test requirements, and legal-source status. They do not certify a facility, authorize a mission, prove deployment, or replace current facility-specific engineering and legal review.

Claim collection

AC-K05-C01

Authority and mission boundary is explicit

Every automated protection action and any external mission support is traceable to a competent authority, named asset scope, allowed effects, prohibited outcomes, duration, stop conditions, and review route.

7 evidence requirements · 5 defeaters · 4 hazards

AC-K05-C02

High-consequence events are identified and bounded

The facility identifies the cyber-enabled physical and mission consequences that must be prevented, their initiating pathways, critical functions, and independent protections.

6 evidence requirements · 5 defeaters · 6 hazards

AC-K05-C03

Deterministic separation protects safety functions

Safety-significant and critical OT functions cannot be commanded from lower-trust datacenter or external networks through an unverified software path.

6 evidence requirements · 5 defeaters · 4 hazards

AC-K05-C04

Identity, firmware, and management planes remain trustworthy

Privileged identities, workload identities, signing keys, BMCs, firmware, update systems, model artifacts, and management networks are separately protected and continuously evidenced.

7 evidence requirements · 6 defeaters · 4 hazards

AC-K05-C05

Autonomous defense is bounded, causal, and reversible

Autonomous defenders act only through pre-authorized internal actions whose physical consequence, confidence threshold, rollback, evidence, and safe-state behavior have been tested.

7 evidence requirements · 6 defeaters · 4 hazards

AC-K05-C06

Sensor and model disagreement cannot directly control force

Physical-security autonomy separates sensing, classification, access denial, non-destructive protection, authorized responder routing, and any force-enabled response into independently governed layers.

7 evidence requirements · 6 defeaters · 5 hazards

AC-K05-C08

Recovery is clean, evidenced, and repeatable

Critical services can be restored from independently protected, provenance-verified states while preserving evidence and preventing reinfection or unsafe configuration reintroduction.

8 evidence requirements · 6 defeaters · 4 hazards

AC-K05-C09

Evidence supports readiness without overclaiming

Every public or procurement readiness state is traceable to exact releases, tests, defects, deployment identity, authority, incidents, uptime, restoration, and independent-verification status.

9 evidence requirements · 6 defeaters · 4 hazards

AC-K05-C10

Authorized external effects remain separate from facility defense

External cyber surveillance or effects support is never triggered solely by a facility defensive model and proceeds only through a separately approved mission package, federal or other competent authority, deconfliction, effect constraints, and post-operation accountability.

7 evidence requirements · 6 defeaters · 5 hazards

Machine records

Complete claim dataset · Top-level assurance case