K05 assurance architecture
Recovery is clean, evidenced, and repeatable
Direct answer
Critical services can be restored from independently protected, provenance-verified states while preserving evidence and preventing reinfection or unsafe configuration reintroduction.
Evidence boundary. These records describe architecture, control relationships, test requirements, and legal-source status. They do not certify a facility, authorize a mission, prove deployment, or replace current facility-specific engineering and legal review.
Claim
Critical services can be restored from independently protected, provenance-verified states while preserving evidence and preventing reinfection or unsafe configuration reintroduction.
Argument
Availability under attack depends on prepared restoration, not only detection or backup existence.
Evidence requirements
- recovery architecture
- immutable or protected backups
- gold-image hashes
- clean-room procedure
- restore rehearsal results
- dependency order
- post-restore attestation
- incident ledger
Assurance defeaters
- backup shares compromise
- unknown dependency order
- stale credentials
- unverified image
- evidence overwritten
- unsafe OT restart
Hazards
- reinfection
- loss of forensic continuity
- unsafe process restart
- prolonged mission loss
Recovery objectives
- restore safety first
- recover essential control and cooling
- recover mission compute by priority
- re-establish evidence continuity
Site-tailoring questions
- RTO/RPO by function
- licensing constraints
- fuel and staffing
- external service dependencies
- data classification
Sources and record
NIST SP 800-82 Revision 3 — Guide to Operational Technology Security · NIST SP 800-53 Rev. 5, Release 5.2.0 Security and Privacy Controls