K05 assurance architecture
Deterministic separation protects safety functions
Direct answer
Safety-significant and critical OT functions cannot be commanded from lower-trust datacenter or external networks through an unverified software path.
Evidence boundary. These records describe architecture, control relationships, test requirements, and legal-source status. They do not certify a facility, authorize a mission, prove deployment, or replace current facility-specific engineering and legal review.
Claim
Safety-significant and critical OT functions cannot be commanded from lower-trust datacenter or external networks through an unverified software path.
Argument
Physical or independently assured boundaries reduce dependence on the correctness of compromised enterprise software and autonomous models.
Evidence requirements
- network and data-flow diagrams
- hardware boundary inventory
- one-way-flow tests where used
- independent interlock tests
- configuration hashes
- change-control evidence
Assurance defeaters
- bidirectional maintenance path
- shared management plane
- unapproved remote access
- boundary bypass
- common timing or identity dependency
Hazards
- IT-to-OT pivot
- unauthorized control command
- loss of deterministic behavior
- hidden common-mode failure
Recovery objectives
- isolate affected trust zone
- preserve safety function
- restore verified boundary configuration
Site-tailoring questions
- license basis
- data historian flow
- vendor maintenance
- emergency communications
- support-system dependencies
Sources and record
10 CFR 73.54 — Protection of Digital Computer and Communication Systems and Networks · 10 CFR Part 73 Subpart J — Security Requirements at Commercial Nuclear Plants · NIST SP 800-82 Revision 3 — Guide to Operational Technology Security