K05 assurance architecture

Deterministic separation protects safety functions

Direct answer

Safety-significant and critical OT functions cannot be commanded from lower-trust datacenter or external networks through an unverified software path.

Evidence boundary. These records describe architecture, control relationships, test requirements, and legal-source status. They do not certify a facility, authorize a mission, prove deployment, or replace current facility-specific engineering and legal review.

Claim

Safety-significant and critical OT functions cannot be commanded from lower-trust datacenter or external networks through an unverified software path.

Argument

Physical or independently assured boundaries reduce dependence on the correctness of compromised enterprise software and autonomous models.

Evidence requirements

  • network and data-flow diagrams
  • hardware boundary inventory
  • one-way-flow tests where used
  • independent interlock tests
  • configuration hashes
  • change-control evidence

Assurance defeaters

  • bidirectional maintenance path
  • shared management plane
  • unapproved remote access
  • boundary bypass
  • common timing or identity dependency

Hazards

  • IT-to-OT pivot
  • unauthorized control command
  • loss of deterministic behavior
  • hidden common-mode failure

Recovery objectives

  • isolate affected trust zone
  • preserve safety function
  • restore verified boundary configuration

Site-tailoring questions

  • license basis
  • data historian flow
  • vendor maintenance
  • emergency communications
  • support-system dependencies

Sources and record

10 CFR 73.54 — Protection of Digital Computer and Communication Systems and Networks · 10 CFR Part 73 Subpart J — Security Requirements at Commercial Nuclear Plants · NIST SP 800-82 Revision 3 — Guide to Operational Technology Security

Machine-readable claim · Location in complete case