{
  "assuranceClaimIds": [
    "AC-K05-C05",
    "AC-K05-C10"
  ],
  "authorityBoundary": "Control design and mapping do not create mission authority, license approval, certification, or universal applicability.",
  "canonicalUrl": "https://xn--mwe.com/controls/catalog/bounded-action-tiering/",
  "claimStatus": "PROJECT TECHNICAL PROPOSAL",
  "failureEvidence": [
    "missing or stale artifact",
    "control bypass",
    "unresolved defect",
    "scope mismatch",
    "unsupported compliance label",
    "unavailable operating evidence"
  ],
  "family": "Autonomy",
  "id": "AUT-01",
  "implementationEvidence": [
    "approved design and scope",
    "exact configuration or policy artifact",
    "test result",
    "defect and exception record",
    "operating observation where deployment is claimed",
    "last review and evidence owner"
  ],
  "lastReviewed": "2026-08-15",
  "mappings": [
    {
      "applicability": "Applies as guidance when OT is in scope; Revision 3 remains final while Revision 4 is under development.",
      "framework": "NIST SP 800-82 Rev. 3",
      "quality": "INFORMATIVE_RELATIONSHIP",
      "reference": "OT security program, architecture, risk, and control guidance",
      "relationship": "INFORMS",
      "sourceId": "SRC-NIST-800-82R3"
    },
    {
      "applicability": "Applies to identity- and resource-centric access design; does not replace OT safety analysis.",
      "framework": "NIST SP 800-207",
      "quality": "INFORMATIVE_RELATIONSHIP",
      "reference": "Zero Trust Architecture principles",
      "relationship": "INFORMS",
      "sourceId": "SRC-NIST-800-207"
    },
    {
      "applicability": "Useful for high-consequence pathway analysis; not a regulatory certification.",
      "framework": "INL Consequence-driven Cyber-informed Engineering",
      "quality": "INFORMATIVE_RELATIONSHIP",
      "reference": "Consequence prioritization and critical-function assurance",
      "relationship": "INFORMS",
      "sourceId": "SRC-INL-CCE"
    },
    {
      "applicability": "The directive expressly excludes autonomous cyberspace capabilities, unarmed platforms, and non-weapon autonomous systems.",
      "framework": "DoD Directive 3000.09",
      "quality": "UNRESOLVED_APPLICABILITY",
      "reference": "Weapon-system applicability, human judgment, V&V/T&E, robustness, transparency, and abort behavior",
      "relationship": "APPLIES ONLY IF CAPABILITY IS A COVERED WEAPON SYSTEM",
      "sourceId": "SRC-DODD-3000-09"
    }
  ],
  "name": "Bounded autonomous action tiering",
  "objective": "Separate observe, recommend, contain, protect, restore, and external-effect tiers; authorize tools and outcomes independently at each tier.",
  "releaseId": "K12-2026-08-16",
  "researchCutoff": "2026-08-15",
  "slug": "bounded-action-tiering"
}
