Library / Systems Engineering Principles Framework
Jump to passage
In this reading

Link to current text

Published source confirmed at last check

Source changed 2026-10-03 17:24:51 UTC · snapshot created 2026-10-03 17:30:20 UTC · last check 2026-10-03 18:55:10 UTC

SYSE.32:4.4 - Apply the exact authenticity Method when that claim is required

Use SLSA v1.2, Verifying artifacts with the consumer’s configured trust roots and expectations. Its operative verification includes the signature, the actual artifact’s correspondence to the provenance subject, the expected provenance type, and the recognized builder’s trust basis. Compare the claimed build with the expected builder, canonical source, build type and external parameters; a valid signature alone is insufficient.

Supply those expectations through the actual authorized trust arrangement. Unknown or unexpected parameters require the source Method’s explicit disposition, not silent acceptance. Use a verifier qualified for the deployed formats and trust system.

Distinguish missing provenance, invalid verification, an unexpected but correctly signed build, and unavailable verification. Each may require a different investigation or authorized exception decision, but none establishes the missing trust claim. If an authorized holder permits a bounded use without that assurance, retain the limitation and its scope.