Domain 8 · Security Control Assurance and Falsification
Control Validation and Claim Falsification
Attempt to defeat the organisation's own security claims, and check that expected state still equals actual state.
Decision it answers
Does this control hold under adversarial pressure, or is it documented rather than effective?
Inputs it needs
- Stated control set and assurance claims
- Approved baselines and security invariants
- Telemetry and logging coverage
- Change and exception records
Methods applied
- Claim falsification: search for evidence that would defeat the claim
- Expected-state versus actual-state comparison for architectural regression
- Defense independence calculation between nominally layered controls
- Policy-as-constraint evaluation over the graph
Outputs produced
- Validated, qualified or falsified control claims
- Invariant violations
- Illusory redundancy findings
- Monitoring blindness and evidence-coverage gaps
Must remain human-owned
Authorization, acceptance of residual risk, containment decisions, disclosure and notification, and any communication to a board or regulator. No analytical capability creates operational authority.
