# A-020

- **Artifact ID:** A-020
- **Status:** ACTIVE
- **Public record:** https://record.cybersecurityhq.com/assumptions#A-020
- **Machine-record SHA-256:** `b29fb870b63368c0a53c9e63d8f3e9ce5c6d5fc3bdd0727a062266ae11b18c1d`

## Complete structured record

```json
{
  "id": "A-020",
  "statement": "Control plane integrity can be verified independently of data plane activity",
  "status": "ACTIVE",
  "category": "Under Pressure",
  "ledger_references": [
    "2026-03-24 — CHQ-P-2026-014 evidence set: Cisco FMC (CVE-2026-20131), Oracle OIM (CVE-2026-21992), Quest KACE (CVE-2025-41080), ConnectWise ScreenConnect (CVE-2024-1709), Stryker/Intune weaponization. Management plane compromise produces effects that cannot be distinguished from legitimate policy propagation at the data plane. Control plane integrity is not independently verifiable when the compromise operates through the control plane's own authorized functions.",
    "2026-03-25 — CHQ-P-2026-015: Execution pipelines are a control plane whose integrity cannot be verified from outside the pipeline. Artifacts they produce carry no verifiable record of the authority that produced them. Additive to P-014 pressure from management plane angle."
  ],
  "related_positions": []
}
```
