K05 assurance architecture

Autonomous defense is bounded, causal, and reversible

Direct answer

Autonomous defenders act only through pre-authorized internal actions whose physical consequence, confidence threshold, rollback, evidence, and safe-state behavior have been tested.

Evidence boundary. These records describe architecture, control relationships, test requirements, and legal-source status. They do not certify a facility, authorize a mission, prove deployment, or replace current facility-specific engineering and legal review.

Claim

Autonomous defenders act only through pre-authorized internal actions whose physical consequence, confidence threshold, rollback, evidence, and safe-state behavior have been tested.

Argument

Machine-speed containment can reduce loss only when false-positive effects cannot exceed the threat being controlled.

Evidence requirements

  • allowed-action policy
  • causal dependency model
  • threshold and uncertainty records
  • rollback tests
  • false-positive consequence analysis
  • model and data provenance
  • decision receipts

Assurance defeaters

  • unbounded tool access
  • unknown physical consequence
  • model drift
  • poisoned telemetry
  • rollback failure
  • conflicting agent state

Hazards

  • self-inflicted outage
  • unsafe OT isolation
  • cascading agent failure
  • evidence loss

Recovery objectives

  • stop action on uncertainty
  • restore last known-good state
  • retain incident chronology
  • escalate unresolved state

Site-tailoring questions

  • action tier
  • protected process
  • latency requirement
  • operator authority
  • maintenance state

Sources and record

NIST SP 800-82 Revision 3 — Guide to Operational Technology Security · NIST SP 800-207 — Zero Trust Architecture · White House Launches GOLD EAGLE Initiative for Cybersecurity Vulnerability Coordination

Machine-readable claim · Location in complete case