K07 · evidence-bundled critical-infrastructure assurance
Cyber-physical architecture assessment
Direct answer
Assess separation, identity, management planes, OT, power, cooling, timing, physical sensing, autonomy, evidence, and recovery against the consequence model.
Authority and evidence boundary. K07 publishes knowledge architecture, bounded reference records, procurement structures, local validation tools, signed synthetic fixtures, and point-in-time source review. It does not certify a facility, award a contract, authorize an operation, prove truth, establish deployment, or claim current operation.
Statement of work
Assess separation, identity, management planes, OT, power, cooling, timing, physical sensing, autonomy, evidence, and recovery against the consequence model.
| Current package ID | WP-K07-03 |
|---|---|
| Inherited stable ID | WP-K06-03 |
| Period | To be defined by the acquiring authority; no duration is inferred by the public pattern. |
| Dependencies | WP-K06-01; WP-K06-02 |
Required outcomes
- versioned architecture baseline
- trust and management-plane analysis
- defeater and common-cause register
- prioritized remediation roadmap
Owner-furnished information
- logical and physical diagrams
- configuration baselines
- identity and key architecture
- power and cooling controls
- OT and timing interfaces
Contractor deliverables
- architecture findings
- trust-zone model
- critical-interface register
- defeater register
- remediation roadmap
Performance standards
- Every finding cites a versioned source artifact
- IT, OT, power, cooling, physical, timing, model and recovery planes are assessed
- Fragile OT is not actively scanned without site approval
Quality surveillance
- finding replay
- coverage matrix
- activity log review
Exclusions
- no certification claim
- no uncontrolled active scanning of fragile OT
Acceptance matrix
| Criterion | Required result | Assessment | Outcome vocabulary |
|---|---|---|---|
| Reproducibility | Every finding cites a versioned source artifact | finding replay | PASS, FAIL, PARTIAL, UNAVAILABLE, or NOT APPLICABLE with rationale |
| Boundary coverage | IT, OT, power, cooling, physical, timing, model and recovery planes are assessed | coverage matrix | PASS, FAIL, PARTIAL, UNAVAILABLE, or NOT APPLICABLE with rationale |
| No uncontrolled scanning | Fragile OT is not actively scanned without site approval | activity log review | PASS, FAIL, PARTIAL, UNAVAILABLE, or NOT APPLICABLE with rationale |
Bid-evaluation criteria
- cyber-physical architecture depth
- OT-safe assessment method
- evidence provenance tooling
- independence from product resale incentives
- price realism and schedule credibility
- data-rights and evidence-delivery terms
- subcontractor and supply-chain transparency
Evidence rights
- The acquiring authority receives perpetual access to final reports, schemas, manifests, acceptance evidence, defects, and correction history within the negotiated data-rights regime.
- Contractor proprietary methods may remain protected only when they do not prevent independent replay of required results.
- Source artifacts, hashes, versions, tool outputs, and negative findings required for acceptance cannot be withheld merely because they are unfavorable.
- No clause transfers authority, licensing status, or ownership beyond the signed contract and governing law.
Negative-result clauses
- A failed, partial, stale, disputed, unavailable, or superseded result must be delivered and may not be converted into a pass.
- Discovery of a safety, authority, evidence, or common-cause defect triggers prompt notice and preserves stop authority.
- Acceptance of one deliverable does not waive latent defects, falsified evidence, or later-discovered nonconformance.
- The final package must distinguish work completed, work not performed, evidence unavailable, and owner decisions pending.
Data requirements
- logical and physical diagrams
- configuration baselines
- identity and key architecture
- power and cooling controls
- OT and timing interfaces