{
  "architecture": "least privilege; key lifecycle; immutable logs; build provenance; dependency controls; backups; failover; incident and correction records",
  "canonicalUrl": "https://xn--mwe.com/knowledge/security-resilience/",
  "claimStatus": "PROJECT DOCTRINE",
  "contradictionIds": [
    "CON-K03-002",
    "CON-K04-012"
  ],
  "correctionStatus": "CURRENT K05 RELEASE",
  "doctrine": "Machine Intelligence systems should expose evidence sufficient to attribute control, changes and failures without publishing protected secrets.",
  "evidenceLimitationIds": [
    "LIM-K02-006",
    "LIM-K03-002",
    "LIM-K03-003",
    "LIM-K04-016",
    "LIM-K04-017"
  ],
  "focus": "threat modeling, identity compromise, supply chain, monitoring, recovery, incident evidence and adversarial testing",
  "id": "K01-TOPIC-012",
  "knowledgeEdgeIds": [],
  "lastReviewed": "2026-08-16",
  "law": "Security obligations vary by sector and jurisdiction; evidence must distinguish mandatory controls from recommended practice.",
  "name": "Security and Resilience",
  "relatedQuestionUrls": [
    "https://xn--mwe.com/questions/what-is-reproducible-build/",
    "https://xn--mwe.com/questions/does-automation-prove-screen-reader-usability/",
    "https://xn--mwe.com/questions/what-evidence-required-before-preemptive-cyber-operation/",
    "https://xn--mwe.com/questions/does-autonomous-cyber-defense-create-legal-authority/",
    "https://xn--mwe.com/questions/how-evaluate-autonomous-security-at-nuclear-infrastructure/",
    "https://xn--mwe.com/questions/does-design-basis-threat-authorize-force/"
  ],
  "relatedReportIds": [
    "REP-K04-045",
    "REP-K04-043"
  ],
  "relatedTermIds": [
    "K01-TERM-065",
    "K01-TERM-116",
    "K01-TERM-120",
    "K01-TERM-131",
    "K01-TERM-132",
    "K01-TERM-133",
    "K01-TERM-134",
    "K01-TERM-136",
    "K01-TERM-137",
    "K01-TERM-179"
  ],
  "releaseId": "K12-2026-08-16",
  "researchCutoff": "2026-08-16",
  "risk": "credential theft, poisoned updates, unreviewable autonomy, fabricated telemetry, monoculture and incomplete recovery",
  "short": "Security protects confidentiality, integrity, availability and authorized control; resilience preserves critical functions and recoverability under failure or attack. Neither should be reduced to secrecy alone.",
  "slug": "security-resilience",
  "sourceRevalidatedAt": "2026-08-15T23:00:00Z",
  "sources": [
    "SRC-NIST-SSDF",
    "SRC-NIST-800-53",
    "SRC-SLSA",
    "SRC-IN-TOTO"
  ],
  "type": "Topic"
}
