K07 · evidence-bundled critical-infrastructure assurance
Cryptographic provenance, custody, and revocation
Direct answer
Cryptographic provenance, custody, and revocation provides bounded component or provenance evidence and must be combined with authenticity, installed-state, vulnerability, custody, and recovery evidence.
Authority and evidence boundary. K07 publishes knowledge architecture, bounded reference records, procurement structures, local validation tools, signed synthetic fixtures, and point-in-time source review. It does not certify a facility, award a contract, authorize an operation, prove truth, establish deployment, or claim current operation.
Artifact class
| Stable ID | SCA-K07-007 |
|---|---|
| Artifact type | SIGNATURE-AND-ATTESTATION-CHAIN |
Required fields
- signer or attester identity
- key fingerprint
- algorithm and parameters
- signed payload hash
- time and sequence
- key status
- revocation and compromise record
- verification result
Validation expectations
- signature verification
- trust-root and scope check
- key status at event time
- replay and duplicate detection
- revocation propagation
Limitations
- signature proves key control and payload integrity, not factual truth, legal authority, or safe operation
- compromised keys require supersession and re-evaluation
Source relationships
- NIST SP 800-161 Revision 1 Update 1 — Cybersecurity Supply Chain Risk Management Practices — National Institute of Standards and Technology; Revision 1 Update 1; FINAL. Exact claim-support entries: 1. Revalidated 2026-08-15T23:30:00Z.
Assurance boundary
Inventory, signature, attestation, supplier status, vulnerability status, and installed configuration remain separate evidence properties. This record does not certify a product or prove that a deployed asset matches its declared bill of materials.