K05 assurance architecture
Capability Evaluation Range
Direct answer
The range tests whether protection and recovery claims hold under representative, contained stress. It publishes objectives, observations, pass evidence, and safety limits while excluding exploit recipes, real targets, payloads, persistence, evasion, engagement logic, and weapon construction.
Evaluation principles
Representative stress
Test failure, adversarial pressure, timing, identity, autonomy, power, cooling, physical sensing, restoration, and evidence without connecting to an unauthorized target.
Hard containment
Use isolated networks, synthetic or approved data, effects-disabled substitutes, independent stop authority, and reset evidence.
Scenario library
IT-to-OT boundary pressure
Validate that an assumed-compromised enterprise zone cannot command or silently reconfigure protected OT and safety functions.
BMC and firmware trust failure
Evaluate detection, isolation, key revocation, signed recovery, and fleet blast-radius control when management-plane trust is withdrawn.
Workload identity compromise
Evaluate short-lived identity revocation, session termination, lateral-movement containment, and service continuity.
Model and data poisoning
Evaluate provenance checks, disagreement detection, drift thresholds, action suspension, and clean model/data restoration.
Sensor conflict and adversarial input
Evaluate multi-modal disagreement, sensor-health weighting, classification uncertainty, and non-destructive degraded response.
Timing integrity loss
Evaluate path-delay anomaly detection, clock-health scoring, holdover, safe process behavior, and trusted-time restoration.
Communications denial and partition
Evaluate decentralized safe operation, local authority, stale-command rejection, reconciliation, and evidence continuity during network partition.
UAS intrusion awareness
Evaluate detection, tracking, classification uncertainty, airspace-restriction data, authorized responder routing, and authority separation.
Electromagnetic disruption
Evaluate degradation of sensors, communications, timing, edge compute, and restoration assets under approved non-damaging interference simulation.
Power load rejection and islanding
Evaluate grid separation, load shedding, reactor or generation response models, UPS/storage behavior, essential cooling, and resynchronization.
Cooling telemetry corruption
Evaluate physics-aware detection and independent protective behavior when supervisory cooling data is wrong or unavailable.
Clean-room recovery and reinfection resistance
Evaluate dependency-aware restoration, credential rotation, evidence preservation, artifact attestation, and return-to-service gates.
Evidence ledger integrity
Evaluate detection and recovery when decision receipts, logs, hashes, or incident records are missing, reordered, stale, or contradicted.
Authority package failure
Evaluate automatic stop, minimization, notification, and evidence preservation when mission authority expires, target scope conflicts, or critical-outcome risk emerges.