K05 assurance architecture

Capability Evaluation Range

Direct answer

The range tests whether protection and recovery claims hold under representative, contained stress. It publishes objectives, observations, pass evidence, and safety limits while excluding exploit recipes, real targets, payloads, persistence, evasion, engagement logic, and weapon construction.

Evidence boundary. These records describe architecture, control relationships, test requirements, and legal-source status. They do not certify a facility, authorize a mission, prove deployment, or replace current facility-specific engineering and legal review.

Evaluation principles

Representative stress

Test failure, adversarial pressure, timing, identity, autonomy, power, cooling, physical sensing, restoration, and evidence without connecting to an unauthorized target.

Hard containment

Use isolated networks, synthetic or approved data, effects-disabled substitutes, independent stop authority, and reset evidence.

Scenario library

IT-to-OT boundary pressure

Validate that an assumed-compromised enterprise zone cannot command or silently reconfigure protected OT and safety functions.

RNG-01

BMC and firmware trust failure

Evaluate detection, isolation, key revocation, signed recovery, and fleet blast-radius control when management-plane trust is withdrawn.

RNG-02

Workload identity compromise

Evaluate short-lived identity revocation, session termination, lateral-movement containment, and service continuity.

RNG-03

Model and data poisoning

Evaluate provenance checks, disagreement detection, drift thresholds, action suspension, and clean model/data restoration.

RNG-04

Timing integrity loss

Evaluate path-delay anomaly detection, clock-health scoring, holdover, safe process behavior, and trusted-time restoration.

RNG-06

Communications denial and partition

Evaluate decentralized safe operation, local authority, stale-command rejection, reconciliation, and evidence continuity during network partition.

RNG-07

UAS intrusion awareness

Evaluate detection, tracking, classification uncertainty, airspace-restriction data, authorized responder routing, and authority separation.

RNG-08

Electromagnetic disruption

Evaluate degradation of sensors, communications, timing, edge compute, and restoration assets under approved non-damaging interference simulation.

RNG-09

Power load rejection and islanding

Evaluate grid separation, load shedding, reactor or generation response models, UPS/storage behavior, essential cooling, and resynchronization.

RNG-10

Cooling telemetry corruption

Evaluate physics-aware detection and independent protective behavior when supervisory cooling data is wrong or unavailable.

RNG-11

Evidence ledger integrity

Evaluate detection and recovery when decision receipts, logs, hashes, or incident records are missing, reordered, stale, or contradicted.

RNG-13

Authority package failure

Evaluate automatic stop, minimization, notification, and evidence preservation when mission authority expires, target scope conflicts, or critical-outcome risk emerges.

RNG-14

Open the complete specification