K05 assurance architecture

Power, cooling, and timing failures do not defeat protected functions

Direct answer

The facility can detect corrupted or unavailable power, cooling, environmental, and timing data; reject unsafe commands; and transition to approved operating states without relying on the compromised channel.

Evidence boundary. These records describe architecture, control relationships, test requirements, and legal-source status. They do not certify a facility, authorize a mission, prove deployment, or replace current facility-specific engineering and legal review.

Claim

The facility can detect corrupted or unavailable power, cooling, environmental, and timing data; reject unsafe commands; and transition to approved operating states without relying on the compromised channel.

Argument

Cybersecurity is incomplete when digital manipulation can drive an otherwise valid physical command into an unsafe state.

Evidence requirements

  • physical plausibility models
  • independent sensors
  • load-rejection tests
  • islanding and resynchronization tests
  • cooling-failure tests
  • timing holdover evidence
  • safe-state procedures

Assurance defeaters

  • single timing source
  • physics-unaware anomaly model
  • untested load step
  • shared cooling control
  • unavailable manual or independent fallback

Hazards

  • false relay trip
  • grid instability
  • thermal excursion
  • coolant loss
  • compute damage

Recovery objectives

  • maintain safety and essential cooling
  • stabilize electrical state
  • restore trusted time
  • rejoin service through verified sequence

Site-tailoring questions

  • grid topology
  • reactor and turbine response
  • UPS and storage
  • cooling technology
  • critical workload tiers

Sources and record

NIST SP 800-82 Revision 3 — Guide to Operational Technology Security · NERC Critical Infrastructure Protection Reliability Standards Catalog · 10 CFR Part 73 Subpart J — Security Requirements at Commercial Nuclear Plants

Machine-readable claim · Location in complete case