K05 assurance architecture

Recovery is clean, evidenced, and repeatable

Direct answer

Critical services can be restored from independently protected, provenance-verified states while preserving evidence and preventing reinfection or unsafe configuration reintroduction.

Evidence boundary. These records describe architecture, control relationships, test requirements, and legal-source status. They do not certify a facility, authorize a mission, prove deployment, or replace current facility-specific engineering and legal review.

Claim

Critical services can be restored from independently protected, provenance-verified states while preserving evidence and preventing reinfection or unsafe configuration reintroduction.

Argument

Availability under attack depends on prepared restoration, not only detection or backup existence.

Evidence requirements

  • recovery architecture
  • immutable or protected backups
  • gold-image hashes
  • clean-room procedure
  • restore rehearsal results
  • dependency order
  • post-restore attestation
  • incident ledger

Assurance defeaters

  • backup shares compromise
  • unknown dependency order
  • stale credentials
  • unverified image
  • evidence overwritten
  • unsafe OT restart

Hazards

  • reinfection
  • loss of forensic continuity
  • unsafe process restart
  • prolonged mission loss

Recovery objectives

  • restore safety first
  • recover essential control and cooling
  • recover mission compute by priority
  • re-establish evidence continuity

Site-tailoring questions

  • RTO/RPO by function
  • licensing constraints
  • fuel and staffing
  • external service dependencies
  • data classification

Sources and record

NIST SP 800-82 Revision 3 — Guide to Operational Technology Security · NIST SP 800-53 Rev. 5, Release 5.2.0 Security and Privacy Controls

Machine-readable claim · Location in complete case