K07 · evidence-bundled critical-infrastructure assurance
Configuration and delivery chain of custody
Direct answer
Configuration and delivery chain of custody provides bounded component or provenance evidence and must be combined with authenticity, installed-state, vulnerability, custody, and recovery evidence.
Authority and evidence boundary. K07 publishes knowledge architecture, bounded reference records, procurement structures, local validation tools, signed synthetic fixtures, and point-in-time source review. It does not certify a facility, award a contract, authorize an operation, prove truth, establish deployment, or claim current operation.
Artifact class
| Stable ID | SCA-K07-009 |
|---|---|
| Artifact type | DELIVERY-MANIFEST |
Required fields
- build identity
- source commit or release hash
- builder and environment
- dependencies
- artifact hashes
- custody transitions
- storage and transport protections
- installation receipt
Validation expectations
- reproducible or repeatable build evidence
- hash verification at each custody step
- destination comparison
- tamper and substitution review
Limitations
- reproducibility depends on complete inputs
- matching bytes do not prove correct requirements
- custody evidence can be incomplete
Source relationships
- NIST SP 800-218A — Secure Software Development Practices for Generative AI and Dual-Use Foundation Models — National Institute of Standards and Technology; Final; FINAL. Exact claim-support entries: 1. Revalidated 2026-08-15T23:30:00Z.
- NIST SP 800-161 Revision 1 Update 1 — Cybersecurity Supply Chain Risk Management Practices — National Institute of Standards and Technology; Revision 1 Update 1; FINAL. Exact claim-support entries: 1. Revalidated 2026-08-15T23:30:00Z.
Assurance boundary
Inventory, signature, attestation, supplier status, vulnerability status, and installed configuration remain separate evidence properties. This record does not certify a product or prove that a deployed asset matches its declared bill of materials.