K05 assurance architecture

Bounded autonomous action tiering

Direct answer

Separate observe, recommend, contain, protect, restore, and external-effect tiers; authorize tools and outcomes independently at each tier.

Evidence boundary. These records describe architecture, control relationships, test requirements, and legal-source status. They do not certify a facility, authorize a mission, prove deployment, or replace current facility-specific engineering and legal review.

Objective

Separate observe, recommend, contain, protect, restore, and external-effect tiers; authorize tools and outcomes independently at each tier.

Implementation evidence

  • approved design and scope
  • exact configuration or policy artifact
  • test result
  • defect and exception record
  • operating observation where deployment is claimed
  • last review and evidence owner

Evidence of failure or insufficiency

  • missing or stale artifact
  • control bypass
  • unresolved defect
  • scope mismatch
  • unsupported compliance label
  • unavailable operating evidence

Qualified source mappings

  • NIST SP 800-82 Rev. 3 — INFORMSOT security program, architecture, risk, and control guidance
    Applies as guidance when OT is in scope; Revision 3 remains final while Revision 4 is under development.
    Source record
  • NIST SP 800-207 — INFORMSZero Trust Architecture principles
    Applies to identity- and resource-centric access design; does not replace OT safety analysis.
    Source record
  • INL Consequence-driven Cyber-informed Engineering — INFORMSConsequence prioritization and critical-function assurance
    Useful for high-consequence pathway analysis; not a regulatory certification.
    Source record
  • DoD Directive 3000.09 — APPLIES ONLY IF CAPABILITY IS A COVERED WEAPON SYSTEMWeapon-system applicability, human judgment, V&V/T&E, robustness, transparency, and abort behavior
    The directive expressly excludes autonomous cyberspace capabilities, unarmed platforms, and non-weapon autonomous systems.
    Source record

Assurance claims

AC-K05-C05 · AC-K05-C10

Authority boundary. Control design and mapping do not create mission authority, license approval, certification, or universal applicability.

Machine-readable control