K05 assurance architecture

Tamper-evident decision receipts

Direct answer

Record observation, evidence inputs, model and software versions, authority, proposed and executed action, outcome, rollback, and reviewer disposition.

Evidence boundary. These records describe architecture, control relationships, test requirements, and legal-source status. They do not certify a facility, authorize a mission, prove deployment, or replace current facility-specific engineering and legal review.

Objective

Record observation, evidence inputs, model and software versions, authority, proposed and executed action, outcome, rollback, and reviewer disposition.

Implementation evidence

  • approved design and scope
  • exact configuration or policy artifact
  • test result
  • defect and exception record
  • operating observation where deployment is claimed
  • last review and evidence owner

Evidence of failure or insufficiency

  • missing or stale artifact
  • control bypass
  • unresolved defect
  • scope mismatch
  • unsupported compliance label
  • unavailable operating evidence

Qualified source mappings

  • NIST SP 800-82 Rev. 3 — INFORMSOT security program, architecture, risk, and control guidance
    Applies as guidance when OT is in scope; Revision 3 remains final while Revision 4 is under development.
    Source record
  • NIST SP 800-207 — INFORMSZero Trust Architecture principles
    Applies to identity- and resource-centric access design; does not replace OT safety analysis.
    Source record
  • INL Consequence-driven Cyber-informed Engineering — INFORMSConsequence prioritization and critical-function assurance
    Useful for high-consequence pathway analysis; not a regulatory certification.
    Source record
  • NERC CIP — MAY IMPLEMENT OR SUPPORTCurrent applicable CIP standards and implementation plans
    Only after BES registration, asset categorization, effective-date, and enforcement-jurisdiction analysis.
    Source record
  • DoD Directive 3000.09 — APPLIES ONLY IF CAPABILITY IS A COVERED WEAPON SYSTEMWeapon-system applicability, human judgment, V&V/T&E, robustness, transparency, and abort behavior
    The directive expressly excludes autonomous cyberspace capabilities, unarmed platforms, and non-weapon autonomous systems.
    Source record

Assurance claims

AC-K05-C05 · AC-K05-C09 · AC-K05-C10

Authority boundary. Control design and mapping do not create mission authority, license approval, certification, or universal applicability.

Machine-readable control