K05 assurance architecture
United States — private critical-infrastructure operator
Direct answer
BOUNDED PRIVATE DEFENSE; NO GENERAL EXTERNAL CYBER OR COUNTER-UAS FORCE AUTHORITY
Evidence boundary. These records describe architecture, control relationships, test requirements, and legal-source status. They do not certify a facility, authorize a mission, prove deployment, or replace current facility-specific engineering and legal review.
Authority state
BOUNDED PRIVATE DEFENSE; NO GENERAL EXTERNAL CYBER OR COUNTER-UAS FORCE AUTHORITY
Issue matrix
| Issue | Status | Boundary |
|---|---|---|
| Internal cyber defense | GENERALLY AVAILABLE SUBJECT TO LAW, CONTRACT, PRIVACY, SAFETY AND SECTOR RULES | Protect owned or authorized systems; no general authority to access third-party systems. |
| Cyber surveillance or effects outside owned systems | REQUIRES SPECIFIC GOVERNMENT OR OTHER COMPETENT AUTHORITY | The August 2026 federal program requires contractual participation, federal control, package approval and written direction. |
| UAS detection and tracking | ACTOR-, METHOD- AND DATA-SPECIFIC | Detection does not automatically authorize interception, interference, seizure or destruction. |
| RF jamming | NO GENERAL PRIVATE AUTHORITY IDENTIFIED | 47 U.S.C. §333 prohibits willful or malicious interference; identify an express authority before design or use. |
| Critical-infrastructure airspace restriction | FAA PROPOSED PETITION PROCESS AT K05 CUTOFF | A proposed restriction process is not final mitigation authority. |
Qualification
Not legal advice; sector, state, local, contract and emergency authorities may alter a case.
Sources: Expanding Capabilities to Combat Transnational Cyber-Enabled Crime · Restricting Drones Near Critical Infrastructure Sites — Proposed Rule · 47 U.S.C. § 333 — Willful or Malicious Interference