K07 · evidence-bundled critical-infrastructure assurance
Evaluation-range design
Direct answer
Design an isolated, effects-bounded range or digital twin that can test claims without exposing production systems or reusable attack procedures.
Authority and evidence boundary. K07 publishes knowledge architecture, bounded reference records, procurement structures, local validation tools, signed synthetic fixtures, and point-in-time source review. It does not certify a facility, award a contract, authorize an operation, prove truth, establish deployment, or claim current operation.
Statement of work
Design an isolated, effects-bounded range or digital twin that can test claims without exposing production systems or reusable attack procedures.
| Current package ID | WP-K07-05 |
|---|---|
| Inherited stable ID | WP-K06-05 |
| Period | To be defined by the acquiring authority; no duration is inferred by the public pattern. |
| Dependencies | WP-K06-02; WP-K06-04 |
Required outcomes
- isolated evaluation architecture
- effects-bounded scenario suite
- stop and reset mechanism
- artifact-removal and evidence-preservation procedure
Owner-furnished information
- assurance claims
- hazards and safety envelope
- system models
- control baseline
- approved synthetic or sanitized data
Contractor deliverables
- range architecture
- scenario set
- fault-injection plan
- stop authority
- reset and artifact-removal procedure
Performance standards
- No production route, credential or uncontrolled effect path exists
- Every scenario maps to claims, controls and expected evidence
- Known-good state and cleanup are demonstrated
Quality surveillance
- independent network and artifact inspection
- schema validation
- repeatable reset exercise
Exclusions
- no public exploit chain
- no unauthorized target
- no destructive production test
Acceptance matrix
| Criterion | Required result | Assessment | Outcome vocabulary |
|---|---|---|---|
| Isolation | No production route, credential or uncontrolled effect path exists | independent network and artifact inspection | PASS, FAIL, PARTIAL, UNAVAILABLE, or NOT APPLICABLE with rationale |
| Traceability | Every scenario maps to claims, controls and expected evidence | schema validation | PASS, FAIL, PARTIAL, UNAVAILABLE, or NOT APPLICABLE with rationale |
| Reset | Known-good state and cleanup are demonstrated | repeatable reset exercise | PASS, FAIL, PARTIAL, UNAVAILABLE, or NOT APPLICABLE with rationale |
Bid-evaluation criteria
- high-consequence range experience
- fault-injection safety
- digital-twin trust model
- non-actionable public reporting
- price realism and schedule credibility
- data-rights and evidence-delivery terms
- subcontractor and supply-chain transparency
Evidence rights
- The acquiring authority receives perpetual access to final reports, schemas, manifests, acceptance evidence, defects, and correction history within the negotiated data-rights regime.
- Contractor proprietary methods may remain protected only when they do not prevent independent replay of required results.
- Source artifacts, hashes, versions, tool outputs, and negative findings required for acceptance cannot be withheld merely because they are unfavorable.
- No clause transfers authority, licensing status, or ownership beyond the signed contract and governing law.
Negative-result clauses
- A failed, partial, stale, disputed, unavailable, or superseded result must be delivered and may not be converted into a pass.
- Discovery of a safety, authority, evidence, or common-cause defect triggers prompt notice and preserves stop authority.
- Acceptance of one deliverable does not waive latent defects, falsified evidence, or later-discovered nonconformance.
- The final package must distinguish work completed, work not performed, evidence unavailable, and owner decisions pending.
Data requirements
- assurance claims
- hazards and safety envelope
- system models
- control baseline
- approved synthetic or sanitized data