K07 · evidence-bundled critical-infrastructure assurance
Control tailoring and applicability determination
Direct answer
Select, modify, reject, or defer controls with explicit mapping quality, applicability evidence, and unresolved gaps.
Authority and evidence boundary. K07 publishes knowledge architecture, bounded reference records, procurement structures, local validation tools, signed synthetic fixtures, and point-in-time source review. It does not certify a facility, award a contract, authorize an operation, prove truth, establish deployment, or claim current operation.
Statement of work
Select, modify, reject, or defer controls with explicit mapping quality, applicability evidence, and unresolved gaps.
| Current package ID | WP-K07-04 |
|---|---|
| Inherited stable ID | WP-K06-04 |
| Period | To be defined by the acquiring authority; no duration is inferred by the public pattern. |
| Dependencies | WP-K06-03 |
Required outcomes
- site-specific control baseline
- applicability and mapping-quality decisions
- compensating-measure register
- implementation and evidence plan
Owner-furnished information
- applicable authority and contract scope
- facility pattern and site facts
- source requirements
- architecture findings
- risk and license conditions
Contractor deliverables
- tailored control baseline
- mapping-quality register
- not-applicable decisions
- conflict and supersession log
- implementation evidence plan
Performance standards
- Every control is exact, partial, informative, conflicting, superseded, not applicable or unresolved
- Mappings cite exact current source sections
- Control selection is not represented as compliance
Quality surveillance
- mapping validation
- citation replay
- language audit
Exclusions
- no compliance certificate
- no silent inheritance of framework scope
Acceptance matrix
| Criterion | Required result | Assessment | Outcome vocabulary |
|---|---|---|---|
| Applicability explicit | Every control is exact, partial, informative, conflicting, superseded, not applicable or unresolved | mapping validation | PASS, FAIL, PARTIAL, UNAVAILABLE, or NOT APPLICABLE with rationale |
| Source precision | Mappings cite exact current source sections | citation replay | PASS, FAIL, PARTIAL, UNAVAILABLE, or NOT APPLICABLE with rationale |
| No certification leap | Control selection is not represented as compliance | language audit | PASS, FAIL, PARTIAL, UNAVAILABLE, or NOT APPLICABLE with rationale |
Bid-evaluation criteria
- framework interpretation competence
- source-currentness process
- ability to document non-applicability
- control-neutral architecture
- price realism and schedule credibility
- data-rights and evidence-delivery terms
- subcontractor and supply-chain transparency
Evidence rights
- The acquiring authority receives perpetual access to final reports, schemas, manifests, acceptance evidence, defects, and correction history within the negotiated data-rights regime.
- Contractor proprietary methods may remain protected only when they do not prevent independent replay of required results.
- Source artifacts, hashes, versions, tool outputs, and negative findings required for acceptance cannot be withheld merely because they are unfavorable.
- No clause transfers authority, licensing status, or ownership beyond the signed contract and governing law.
Negative-result clauses
- A failed, partial, stale, disputed, unavailable, or superseded result must be delivered and may not be converted into a pass.
- Discovery of a safety, authority, evidence, or common-cause defect triggers prompt notice and preserves stop authority.
- Acceptance of one deliverable does not waive latent defects, falsified evidence, or later-discovered nonconformance.
- The final package must distinguish work completed, work not performed, evidence unavailable, and owner decisions pending.
Data requirements
- applicable authority and contract scope
- facility pattern and site facts
- source requirements
- architecture findings
- risk and license conditions