K05 assurance architecture
Tamper-evident decision receipts
Direct answer
Record observation, evidence inputs, model and software versions, authority, proposed and executed action, outcome, rollback, and reviewer disposition.
Evidence boundary. These records describe architecture, control relationships, test requirements, and legal-source status. They do not certify a facility, authorize a mission, prove deployment, or replace current facility-specific engineering and legal review.
Objective
Record observation, evidence inputs, model and software versions, authority, proposed and executed action, outcome, rollback, and reviewer disposition.
Implementation evidence
- approved design and scope
- exact configuration or policy artifact
- test result
- defect and exception record
- operating observation where deployment is claimed
- last review and evidence owner
Evidence of failure or insufficiency
- missing or stale artifact
- control bypass
- unresolved defect
- scope mismatch
- unsupported compliance label
- unavailable operating evidence
Qualified source mappings
- NIST SP 800-82 Rev. 3 — INFORMSOT security program, architecture, risk, and control guidance
Applies as guidance when OT is in scope; Revision 3 remains final while Revision 4 is under development.
Source record - NIST SP 800-207 — INFORMSZero Trust Architecture principles
Applies to identity- and resource-centric access design; does not replace OT safety analysis.
Source record - INL Consequence-driven Cyber-informed Engineering — INFORMSConsequence prioritization and critical-function assurance
Useful for high-consequence pathway analysis; not a regulatory certification.
Source record - NERC CIP — MAY IMPLEMENT OR SUPPORTCurrent applicable CIP standards and implementation plans
Only after BES registration, asset categorization, effective-date, and enforcement-jurisdiction analysis.
Source record - DoD Directive 3000.09 — APPLIES ONLY IF CAPABILITY IS A COVERED WEAPON SYSTEMWeapon-system applicability, human judgment, V&V/T&E, robustness, transparency, and abort behavior
The directive expressly excludes autonomous cyberspace capabilities, unarmed platforms, and non-weapon autonomous systems.
Source record
Assurance claims
Authority boundary. Control design and mapping do not create mission authority, license approval, certification, or universal applicability.