K07 · evidence-bundled critical-infrastructure assurance
Procurement Statements of Work
Direct answer
K07 turns all ten work packages into measurable performance statements with data requirements, acceptance evidence, bid criteria, evidence rights, explicit exclusions, and mandatory disclosure of negative results.
Performance-oriented work packages
Each statement of work defines purpose, owner-furnished information, required outcomes, deliverables, measurable standards, surveillance methods, dependencies, exclusions, data rights, and negative-result obligations.
Mission and authority analysis
Define the protected mission, competent authorities, asset scope, allowed actions, prohibited outcomes, decision rights, deconfliction, and evidence obligations before technology selection.
Consequence-driven Cyber-informed Engineering workshop
Identify high-consequence events, critical functions, system-of-systems pathways, digital dependencies, and engineered-out attack paths.
Cyber-physical architecture assessment
Assess separation, identity, management planes, OT, power, cooling, timing, physical sensing, autonomy, evidence, and recovery against the consequence model.
Control tailoring and applicability determination
Select, modify, reject, or defer controls with explicit mapping quality, applicability evidence, and unresolved gaps.
Evaluation-range design
Design an isolated, effects-bounded range or digital twin that can test claims without exposing production systems or reusable attack procedures.
Model and autonomous-agent assurance
Evaluate model provenance, data lineage, adversarial robustness, tool authority, memory boundaries, drift, fallback, and runtime constraints.
Critical-function recovery exercise
Demonstrate clean restoration of minimum viable mission and safe functions under isolated, degraded, and compromise-assumed conditions.
Assurance evidence package
Assemble claim-to-control-to-test-to-evidence traceability, provenance, currentness, signatures, limitations, defects, and decision receipts.
Independent verification
Challenge the assurance argument, replay evidence, test mappings, inspect defeaters, and record disagreements without inheriting the delivery team's conclusions.
Post-deployment observation
After owner-confirmed deployment, observe actual configuration, reachability, headers, service identity, operating evidence, incidents, drift, and recovery readiness against the approved manifest.
Procurement boundary
These records are reusable acquisition structures. They are not solicitations, offers, prices, contract awards, task orders, government requirements, facility authority, or proof that any work has been performed.