{
  "canonicalClaimUrl": "https://xn--mwe.com/questions/what-evidence-required-before-preemptive-cyber-operation/#clm-k04-q-080",
  "claimStatus": "PROJECT POLICY PROPOSAL",
  "correctionStatus": "CURRENT K04 RECORD",
  "id": "CLM-K04-Q-080",
  "lastReviewed": "2026-08-15",
  "machineRecordUrl": "https://xn--mwe.com/data/claims/clm-k04-q-080.json",
  "name": "What evidence is required before a preemptive cyber operation?",
  "ownerAnchor": "clm-k04-q-080",
  "ownerId": "K01-Q-080",
  "ownerRoute": "/questions/what-evidence-required-before-preemptive-cyber-operation/",
  "ownerType": "question",
  "proposition": "A defensible record requires reliable attribution, adversary capability, verified hostile intent, target access, expected effects, imminence or last-window analysis, alternatives considered, necessity, proportionality, legal basis, competent approval, third-party infrastructure analysis, deconfliction, abort conditions, logging, and post-action review. Threat labels or intelligence confidence scores alone are insufficient.",
  "qualification": "The answer preserves contested legal states and does not create mission authority, target status, or verified current law.",
  "releaseId": "K12-2026-08-16",
  "releaseVersion": "2.1.0",
  "researchCutoff": "2026-08-15",
  "scope": "K04 direct answer for What evidence is required before a preemptive cyber operation?",
  "slug": "clm-k04-q-080",
  "sourceIds": [
    "SRC-NIST-SSDF",
    "SRC-NIST-800-53",
    "SRC-SLSA",
    "SRC-IN-TOTO"
  ],
  "sourceSections": [
    {
      "section": "Version 1.1 final publication",
      "sourceId": "SRC-NIST-SSDF",
      "supportRelationship": "QUALIFIES OR SUPPORTS WITHIN STATED SCOPE",
      "supports": "SSDF Version 1.1 provides high-level secure software development practices.",
      "url": "https://csrc.nist.gov/pubs/sp/800/218/final"
    },
    {
      "section": "Version 1.2 initial public draft",
      "sourceId": "SRC-NIST-SSDF",
      "supportRelationship": "QUALIFIES OR SUPPORTS WITHIN STATED SCOPE",
      "supports": "The official NIST record identifies SSDF Version 1.2 as an initial public draft published 2025-12-17.",
      "url": "https://csrc.nist.gov/pubs/sp/800/218/r1/ipd"
    },
    {
      "section": "Planning note — Release 5.2.0",
      "sourceId": "SRC-NIST-800-53",
      "supportRelationship": "QUALIFIES OR SUPPORTS WITHIN STATED SCOPE",
      "supports": "NIST issued SP 800-53 Release 5.2.0 on 2025-08-27 with specified additions and revisions.",
      "url": "https://csrc.nist.gov/pubs/sp/800/53/r5/upd1/final"
    },
    {
      "section": "Publication purpose",
      "sourceId": "SRC-NIST-800-53",
      "supportRelationship": "QUALIFIES OR SUPPORTS WITHIN STATED SCOPE",
      "supports": "SP 800-53 supplies a catalog of security and privacy controls; selection and assessment remain context-dependent.",
      "url": "https://csrc.nist.gov/pubs/sp/800/53/r5/upd1/final"
    },
    {
      "section": "Specification status",
      "sourceId": "SRC-SLSA",
      "supportRelationship": "QUALIFIES OR SUPPORTS WITHIN STATED SCOPE",
      "supports": "SLSA v1.2 is an approved specification for incrementally improving software supply-chain security.",
      "url": "https://slsa.dev/spec/v1.2/"
    },
    {
      "section": "Build requirements",
      "sourceId": "SRC-SLSA",
      "supportRelationship": "QUALIFIES OR SUPPORTS WITHIN STATED SCOPE",
      "supports": "SLSA levels and provenance requirements qualify build evidence; they do not prove that a deployed service is currently operating.",
      "url": "https://slsa.dev/spec/v1.2/build-requirements"
    },
    {
      "section": "Project overview",
      "sourceId": "SRC-IN-TOTO",
      "supportRelationship": "QUALIFIES OR SUPPORTS WITHIN STATED SCOPE",
      "supports": "in-toto records what software supply-chain steps were performed, by whom and in what order to support integrity review.",
      "url": "https://in-toto.io/"
    }
  ],
  "type": "ClaimRecord"
}
