K07 · evidence-bundled critical-infrastructure assurance

Consequence-driven Cyber-informed Engineering workshop

Direct answer

Identify high-consequence events, critical functions, system-of-systems pathways, digital dependencies, and engineered-out attack paths.

Authority and evidence boundary. K07 publishes knowledge architecture, bounded reference records, procurement structures, local validation tools, signed synthetic fixtures, and point-in-time source review. It does not certify a facility, award a contract, authorize an operation, prove truth, establish deployment, or claim current operation.

Statement of work

Identify high-consequence events, critical functions, system-of-systems pathways, digital dependencies, and engineered-out attack paths.

Performance work statement
Current package IDWP-K07-02
Inherited stable IDWP-K06-02
PeriodTo be defined by the acquiring authority; no duration is inferred by the public pattern.
DependenciesWP-K06-01

Required outcomes

  • high-consequence event register
  • critical-function model
  • system-of-systems dependency map
  • engineered-out consequence-path recommendations

Owner-furnished information

  • hazard analyses
  • process and protection diagrams
  • operating envelopes
  • maintenance pathways
  • external service dependencies

Contractor deliverables

  • HCE register
  • critical-function model
  • consequence pathways
  • mitigation candidates
  • unverified-trust register

Performance standards

  • Every HCE maps to functions, pathways, controls and owners
  • Physical, cyber, power, cooling and restoration consequences are represented
  • Sensitive facility details remain access-controlled

Quality surveillance

  • cross-discipline review
  • independent challenge
  • artifact inspection

Exclusions

  • no production exploitation
  • no publication of real facility topology

Acceptance matrix

Measurable acceptance criteria
CriterionRequired resultAssessmentOutcome vocabulary
HCE traceabilityEvery HCE maps to functions, pathways, controls and ownerscross-discipline reviewPASS, FAIL, PARTIAL, UNAVAILABLE, or NOT APPLICABLE with rationale
Consequence coveragePhysical, cyber, power, cooling and restoration consequences are representedindependent challengePASS, FAIL, PARTIAL, UNAVAILABLE, or NOT APPLICABLE with rationale
No topology publicationSensitive facility details remain access-controlledartifact inspectionPASS, FAIL, PARTIAL, UNAVAILABLE, or NOT APPLICABLE with rationale

Bid-evaluation criteria

  • CIE/CCE facilitation experience
  • cross-discipline engineering capability
  • high-consequence evidence handling
  • safe abstraction method
  • price realism and schedule credibility
  • data-rights and evidence-delivery terms
  • subcontractor and supply-chain transparency

Evidence rights

  • The acquiring authority receives perpetual access to final reports, schemas, manifests, acceptance evidence, defects, and correction history within the negotiated data-rights regime.
  • Contractor proprietary methods may remain protected only when they do not prevent independent replay of required results.
  • Source artifacts, hashes, versions, tool outputs, and negative findings required for acceptance cannot be withheld merely because they are unfavorable.
  • No clause transfers authority, licensing status, or ownership beyond the signed contract and governing law.

Negative-result clauses

  • A failed, partial, stale, disputed, unavailable, or superseded result must be delivered and may not be converted into a pass.
  • Discovery of a safety, authority, evidence, or common-cause defect triggers prompt notice and preserves stop authority.
  • Acceptance of one deliverable does not waive latent defects, falsified evidence, or later-discovered nonconformance.
  • The final package must distinguish work completed, work not performed, evidence unavailable, and owner decisions pending.

Data requirements

  • hazard analyses
  • process and protection diagrams
  • operating envelopes
  • maintenance pathways
  • external service dependencies

Machine record

Inspect the complete JSON work package.