{
  "argument": "Physical or independently assured boundaries reduce dependence on the correctness of compromised enterprise software and autonomous models.",
  "canonicalUrl": "https://xn--mwe.com/assurance-case/claims/deterministic-separation-protects-safety-functions/",
  "claim": "Safety-significant and critical OT functions cannot be commanded from lower-trust datacenter or external networks through an unverified software path.",
  "defeaters": [
    "bidirectional maintenance path",
    "shared management plane",
    "unapproved remote access",
    "boundary bypass",
    "common timing or identity dependency"
  ],
  "evidenceRequirements": [
    "network and data-flow diagrams",
    "hardware boundary inventory",
    "one-way-flow tests where used",
    "independent interlock tests",
    "configuration hashes",
    "change-control evidence"
  ],
  "hazards": [
    "IT-to-OT pivot",
    "unauthorized control command",
    "loss of deterministic behavior",
    "hidden common-mode failure"
  ],
  "id": "AC-K05-C03",
  "name": "Deterministic separation protects safety functions",
  "recoveryObjectives": [
    "isolate affected trust zone",
    "preserve safety function",
    "restore verified boundary configuration"
  ],
  "releaseId": "K12-2026-08-16",
  "siteTailoring": [
    "license basis",
    "data historian flow",
    "vendor maintenance",
    "emergency communications",
    "support-system dependencies"
  ],
  "slug": "deterministic-separation-protects-safety-functions",
  "sourceIds": [
    "SRC-NRC-10CFR-73-54",
    "SRC-NRC-10CFR-73-SUBPART-J-2026",
    "SRC-NIST-800-82R3"
  ]
}
