K05 assurance architecture
Evidence ledger integrity
Direct answer
Evaluate detection and recovery when decision receipts, logs, hashes, or incident records are missing, reordered, stale, or contradicted.
Evidence boundary. These records describe architecture, control relationships, test requirements, and legal-source status. They do not certify a facility, authorize a mission, prove deployment, or replace current facility-specific engineering and legal review.
Objective
Evaluate detection and recovery when decision receipts, logs, hashes, or incident records are missing, reordered, stale, or contradicted.
Abstract injected condition
controlled evidence omission, hash mismatch, or chronology conflict
Required observations
- protected-function state
- policy decision and confidence
- authority and configuration state
- timing and identity health
- incident chronology
- rollback or safe-state result
Pass evidence
readiness automatically degrades; claim is suspended; authoritative evidence chain is restored or gap remains public
Safety envelope
- isolated range or approved hardware-in-the-loop environment
- no production plant or public-network target
- synthetic or authorized data and identities
- effects-disabled or non-damaging test substitutes
- independent stop authority
- complete artifact removal and reset evidence
Excluded public detail
- exploit or payload instructions
- credential theft procedure
- persistence or evasion recipe
- targeting or engagement thresholds
- weapon construction
- real-world unauthorized access