K07 · evidence-bundled critical-infrastructure assurance

Configuration and delivery chain of custody

Direct answer

Configuration and delivery chain of custody provides bounded component or provenance evidence and must be combined with authenticity, installed-state, vulnerability, custody, and recovery evidence.

Authority and evidence boundary. K07 publishes knowledge architecture, bounded reference records, procurement structures, local validation tools, signed synthetic fixtures, and point-in-time source review. It does not certify a facility, award a contract, authorize an operation, prove truth, establish deployment, or claim current operation.

Artifact class

Supply-chain record
Stable IDSCA-K07-009
Artifact typeDELIVERY-MANIFEST

Required fields

  • build identity
  • source commit or release hash
  • builder and environment
  • dependencies
  • artifact hashes
  • custody transitions
  • storage and transport protections
  • installation receipt

Validation expectations

  • reproducible or repeatable build evidence
  • hash verification at each custody step
  • destination comparison
  • tamper and substitution review

Limitations

  • reproducibility depends on complete inputs
  • matching bytes do not prove correct requirements
  • custody evidence can be incomplete

Source relationships

Assurance boundary

Inventory, signature, attestation, supplier status, vulnerability status, and installed configuration remain separate evidence properties. This record does not certify a product or prove that a deployed asset matches its declared bill of materials.