K05 assurance architecture

Evidence ledger integrity

Direct answer

Evaluate detection and recovery when decision receipts, logs, hashes, or incident records are missing, reordered, stale, or contradicted.

Evidence boundary. These records describe architecture, control relationships, test requirements, and legal-source status. They do not certify a facility, authorize a mission, prove deployment, or replace current facility-specific engineering and legal review.

Objective

Evaluate detection and recovery when decision receipts, logs, hashes, or incident records are missing, reordered, stale, or contradicted.

Abstract injected condition

controlled evidence omission, hash mismatch, or chronology conflict

Required observations

  • protected-function state
  • policy decision and confidence
  • authority and configuration state
  • timing and identity health
  • incident chronology
  • rollback or safe-state result

Pass evidence

readiness automatically degrades; claim is suspended; authoritative evidence chain is restored or gap remains public

Safety envelope

  • isolated range or approved hardware-in-the-loop environment
  • no production plant or public-network target
  • synthetic or authorized data and identities
  • effects-disabled or non-damaging test substitutes
  • independent stop authority
  • complete artifact removal and reset evidence

Excluded public detail

  • exploit or payload instructions
  • credential theft procedure
  • persistence or evasion recipe
  • targeting or engagement thresholds
  • weapon construction
  • real-world unauthorized access

Assurance claims evaluated

AC-K05-C09

Machine-readable scenario