K05 assurance architecture
Power, cooling, and timing failures do not defeat protected functions
Direct answer
The facility can detect corrupted or unavailable power, cooling, environmental, and timing data; reject unsafe commands; and transition to approved operating states without relying on the compromised channel.
Claim
The facility can detect corrupted or unavailable power, cooling, environmental, and timing data; reject unsafe commands; and transition to approved operating states without relying on the compromised channel.
Argument
Cybersecurity is incomplete when digital manipulation can drive an otherwise valid physical command into an unsafe state.
Evidence requirements
- physical plausibility models
- independent sensors
- load-rejection tests
- islanding and resynchronization tests
- cooling-failure tests
- timing holdover evidence
- safe-state procedures
Assurance defeaters
- single timing source
- physics-unaware anomaly model
- untested load step
- shared cooling control
- unavailable manual or independent fallback
Hazards
- false relay trip
- grid instability
- thermal excursion
- coolant loss
- compute damage
Recovery objectives
- maintain safety and essential cooling
- stabilize electrical state
- restore trusted time
- rejoin service through verified sequence
Site-tailoring questions
- grid topology
- reactor and turbine response
- UPS and storage
- cooling technology
- critical workload tiers
Sources and record
NIST SP 800-82 Revision 3 — Guide to Operational Technology Security · NERC Critical Infrastructure Protection Reliability Standards Catalog · 10 CFR Part 73 Subpart J — Security Requirements at Commercial Nuclear Plants