Zero Trust Engineering — Remediation and re-verification lifecycle
securityv1/01 Views
/02 About
Devices and endpoints engineering reference for remediation and re-verification lifecycle, including policy, logical interfaces, recovery and assurance.
Purpose: Remediation and re-verification lifecycle. Domain: Devices and endpoints. Family: lifecycle. Scenario trigger: Receive device compliance remediation task. Input assurance: Detected defect, approved fix and device owner context. Evaluation: Verify corrective action succeeded and no new policy breach. Governing policy: Endpoint remediation authorization and closure policy. Resource-side obligation: Apply isolated repair then restore compliant access. Protected concern: Endpoint compliance remediation system. Logical interface: Remediation task target state evidence postcondition and recheck. Evidence: Repair plan test outcome and restored posture. Failure: Failed remediation, incomplete patch or nonresponsive endpoint. Required recovery: Keep restricted access and escalate supervised repair. Architectural invariant: Restored access requires independent verification of remediated state Adoption: replace reference roles with concrete owner-controlled services. Specify exact provider/consumer identities, schema fields and classifications, signal provenance and freshness, idempotency, authorization lifetime, timeout/retry limits, observation and tamper evidence. A denied or failed operation must not silently become a permitted one. Scope: original vendor-neutral, implementation-agnostic technical reference model. Illustrative logical components and behaviors are neither a deployed system nor evidence of regulatory compliance. Package identities remain stable within the package; cross-package semantic reconciliation requires separate explicit registry support.
Curated · other · unspecified · Published by Lattix · 29 elements · 34 relationships · validated on publish
/03 Contents
- Capability
- Devices and endpoints, Remediation and re-verification lifecycle
- Role
- Devices and endpoints owner
- Business Actor
- Lifecycle or resource administrator
- Activity
- Receive device compliance remediation task, Verify: Detected defect, approved fix and device owner context, Assess: Verify corrective action succeeded and no new policy breach, Execute: Apply isolated repair then restore compliant access, Exception: Failed remediation, incomplete patch or nonresponsive endpoint, Recover: Keep restricted access and escalate supervised repair
- Application Component
- Detected defect, approved fix and device owner context, Verify corrective action succeeded and no new policy breach, Apply isolated repair then restore compliant access
- Application
- Endpoint compliance remediation system
- Policy
- Endpoint remediation authorization and closure policy
- API
- Remediation and re-verification lifecycle logical interface
- Message/Event Schema
- Remediation task target state evidence postcondition and recheck
- Data Store
- Repair plan test outcome and restored posture
- Control
- Remediation and re-verification lifecycle enforcement assurance
- Risk
- Failed remediation, incomplete patch or nonresponsive endpoint risk
- Requirement
- Restored access requires independent verification of remediated state
- Measure
- Remediation and re-verification lifecycle assurance completeness
- Trust Boundary
- Remediation and re-verification lifecycle authority boundary
- State
- Transition verified, Lifecycle transition rejected, Baseline state established, Change pending independent validation, Transition suspended, Lifecycle transition closed