Skip to content
Black Atlas — Powered by KRYOS V6

Domain 8 · Security Control Assurance and Falsification

Control Validation and Claim Falsification


Attempt to defeat the organisation's own security claims, and check that expected state still equals actual state.

Classification

NATIVE

Maturity

OPERATIONAL, REQUIRES QUALIFIED HUMAN REVIEW

Authorization

Level 0 to Level 3, by named environment

Decision it answers

Does this control hold under adversarial pressure, or is it documented rather than effective?

Inputs it needs

  • Stated control set and assurance claims
  • Approved baselines and security invariants
  • Telemetry and logging coverage
  • Change and exception records

Methods applied

  • Claim falsification: search for evidence that would defeat the claim
  • Expected-state versus actual-state comparison for architectural regression
  • Defense independence calculation between nominally layered controls
  • Policy-as-constraint evaluation over the graph

Outputs produced

  • Validated, qualified or falsified control claims
  • Invariant violations
  • Illusory redundancy findings
  • Monitoring blindness and evidence-coverage gaps

Must remain human-owned

Authorization, acceptance of residual risk, containment decisions, disclosure and notification, and any communication to a board or regulator. No analytical capability creates operational authority.