Devices Terrain
The entry fords: device identification, posture as an access precondition, sensor liveness, execution control, lifecycle and sanitization
Every device with a path into the estate shall be represented on the terrain overlay with its management state, its owning population, and the terrain it can reach.
PurposeTo make devices positional, so that the crossings into the estate are known and can be defended rather than merely counted.Activities10 · Metrics4Device health shall be evaluated as a precondition of access to designated terrain, and failing posture shall deny access rather than raise a notification.
PurposeTo ensure a compromised or non-compliant device cannot spend a valid credential, closing the gap `M3` Envelopment leaves when identity alone is enforced.Activities10 · Metrics4Sensor coverage across the device estate shall be reconciled to the device inventory rather than to the sensor console, and a sensor that stops reporting shall be treated as a security event.
PurposeTo know what the estate can actually see, and to detect the loss of that visibility as an event rather than at the next assessment.Activities10 · Metrics4What may execute on designated device terrain shall be constrained to an approved, verified set, and unauthorized execution shall be prevented rather than recorded.
PurposeTo deny the adversary the ability to run code on the ground they cross into, which is the cheapest point at which most engagements can be stopped.Activities10 · Metrics4Devices shall be provisioned from a trusted baseline and, on retirement, loss or reassignment, shall be removed from the estate's trust and their media sanitized within a stated period.
PurposeTo close the ends of the device lifecycle — the point of entry and the point of exit — where trust is granted and where it is most often left behind.Activities10 · Metrics4