K05 assurance architecture
Clean-room recovery and reinfection resistance
Direct answer
Evaluate dependency-aware restoration, credential rotation, evidence preservation, artifact attestation, and return-to-service gates.
Evidence boundary. These records describe architecture, control relationships, test requirements, and legal-source status. They do not certify a facility, authorize a mission, prove deployment, or replace current facility-specific engineering and legal review.
Objective
Evaluate dependency-aware restoration, credential rotation, evidence preservation, artifact attestation, and return-to-service gates.
Abstract injected condition
declared compromise state followed by controlled restoration exercise
Required observations
- protected-function state
- policy decision and confidence
- authority and configuration state
- timing and identity health
- incident chronology
- rollback or safe-state result
Pass evidence
restored components attest to approved state; reinfection path is blocked; evidence chain remains intact
Safety envelope
- isolated range or approved hardware-in-the-loop environment
- no production plant or public-network target
- synthetic or authorized data and identities
- effects-disabled or non-damaging test substitutes
- independent stop authority
- complete artifact removal and reset evidence
Excluded public detail
- exploit or payload instructions
- credential theft procedure
- persistence or evasion recipe
- targeting or engagement thresholds
- weapon construction
- real-world unauthorized access