K05 assurance architecture

United States — private critical-infrastructure operator

Direct answer

BOUNDED PRIVATE DEFENSE; NO GENERAL EXTERNAL CYBER OR COUNTER-UAS FORCE AUTHORITY

Evidence boundary. These records describe architecture, control relationships, test requirements, and legal-source status. They do not certify a facility, authorize a mission, prove deployment, or replace current facility-specific engineering and legal review.

Authority state

BOUNDED PRIVATE DEFENSE; NO GENERAL EXTERNAL CYBER OR COUNTER-UAS FORCE AUTHORITY

Issue matrix

United States — private critical-infrastructure operator authority boundaries
IssueStatusBoundary
Internal cyber defenseGENERALLY AVAILABLE SUBJECT TO LAW, CONTRACT, PRIVACY, SAFETY AND SECTOR RULESProtect owned or authorized systems; no general authority to access third-party systems.
Cyber surveillance or effects outside owned systemsREQUIRES SPECIFIC GOVERNMENT OR OTHER COMPETENT AUTHORITYThe August 2026 federal program requires contractual participation, federal control, package approval and written direction.
UAS detection and trackingACTOR-, METHOD- AND DATA-SPECIFICDetection does not automatically authorize interception, interference, seizure or destruction.
RF jammingNO GENERAL PRIVATE AUTHORITY IDENTIFIED47 U.S.C. §333 prohibits willful or malicious interference; identify an express authority before design or use.
Critical-infrastructure airspace restrictionFAA PROPOSED PETITION PROCESS AT K05 CUTOFFA proposed restriction process is not final mitigation authority.

Qualification

Not legal advice; sector, state, local, contract and emergency authorities may alter a case.

Sources: Expanding Capabilities to Combat Transnational Cyber-Enabled Crime · Restricting Drones Near Critical Infrastructure Sites — Proposed Rule · 47 U.S.C. § 333 — Willful or Malicious Interference

Machine-readable matrix