K05 assurance architecture
BMC and firmware trust failure
Direct answer
Evaluate detection, isolation, key revocation, signed recovery, and fleet blast-radius control when management-plane trust is withdrawn.
Evidence boundary. These records describe architecture, control relationships, test requirements, and legal-source status. They do not certify a facility, authorize a mission, prove deployment, or replace current facility-specific engineering and legal review.
Objective
Evaluate detection, isolation, key revocation, signed recovery, and fleet blast-radius control when management-plane trust is withdrawn.
Abstract injected condition
attestation mismatch, unauthorized configuration state, or simulated signed-artifact failure
Required observations
- protected-function state
- policy decision and confidence
- authority and configuration state
- timing and identity health
- incident chronology
- rollback or safe-state result
Pass evidence
affected management segment is isolated; trusted workloads remain protected; recovery uses verified firmware
Safety envelope
- isolated range or approved hardware-in-the-loop environment
- no production plant or public-network target
- synthetic or authorized data and identities
- effects-disabled or non-damaging test substitutes
- independent stop authority
- complete artifact removal and reset evidence
Excluded public detail
- exploit or payload instructions
- credential theft procedure
- persistence or evasion recipe
- targeting or engagement thresholds
- weapon construction
- real-world unauthorized access