K05 assurance architecture
Passive OT asset and dependency discovery
Direct answer
Discover OT assets and communication dependencies without unsafe active probing, then reconcile against authorized configuration.
Evidence boundary. These records describe architecture, control relationships, test requirements, and legal-source status. They do not certify a facility, authorize a mission, prove deployment, or replace current facility-specific engineering and legal review.
Objective
Discover OT assets and communication dependencies without unsafe active probing, then reconcile against authorized configuration.
Implementation evidence
- approved design and scope
- exact configuration or policy artifact
- test result
- defect and exception record
- operating observation where deployment is claimed
- last review and evidence owner
Evidence of failure or insufficiency
- missing or stale artifact
- control bypass
- unresolved defect
- scope mismatch
- unsupported compliance label
- unavailable operating evidence
Qualified source mappings
- NIST SP 800-82 Rev. 3 — INFORMSOT security program, architecture, risk, and control guidance
Applies as guidance when OT is in scope; Revision 3 remains final while Revision 4 is under development.
Source record - NIST SP 800-207 — INFORMSZero Trust Architecture principles
Applies to identity- and resource-centric access design; does not replace OT safety analysis.
Source record - INL Consequence-driven Cyber-informed Engineering — INFORMSConsequence prioritization and critical-function assurance
Useful for high-consequence pathway analysis; not a regulatory certification.
Source record - NRC 10 CFR Part 73 — MAY IMPLEMENT OR SUPPORT73.54/73.55 or 73.100/73.110/73.120 as selected and applicable
Only for an NRC-regulated facility within the selected licensing and security framework; license basis controls.
Source record
Assurance claims
Authority boundary. Control design and mapping do not create mission authority, license approval, certification, or universal applicability.