Control Statement
Every device with a path into the estate shall be represented on the terrain overlay with its management state, its owning population, and the terrain it can reach.
Purpose. To make devices positional, so that the crossings into the estate are known and can be defended rather than merely counted.
Discussion
The distinguishing requirement is **management state**, and the category that matters is the one most inventories omit: devices that reach the estate and are not managed by it. Contractor laptops, personal devices under a bring-your-own arrangement, vendor maintenance endpoints and unenrolled cloud workstations all cross the ford, and an inventory built from the management console will report none of them because the console can only see what it manages. Reconciling against the identity plane rather than the endpoint platform is what surfaces them.
Goals and Metrics
A metric that cannot come out badly is not a metric. Each of these is capable of reporting that the control is not working.
- Percentage of authenticating devices present on the overlay
- Unmanaged population as a share of devices reaching the estate
- Number of devices authenticating that the management platform does not hold
- Age of the device terrain against its stated refresh interval
Accountability
Exactly one role is accountable, and every other role carries at least Informed — no control in the published catalog leaves a role with zero relationship to it. That is a stated property of how these were authored, not a coincidence, and not a claim that every role's work is worth equal attention here.
| AO | CTI | SOC | HUNT | PLAT | ISSO |
|---|---|---|---|---|---|
| Authorizing Official / CISO: Accountable | Cyber Threat Intelligence cell: Informed | SOC / Defensive Operations: Consulted | Hunt team: Informed | Platform and product owners: Responsible | Governance / RMF / ISSO: Consulted |
AO Authorizing Official / CISOCTI Cyber Threat Intelligence cellSOC SOC / Defensive OperationsHUNT Hunt teamPLAT Platform and product ownersISSO Governance / RMF / ISSO
- AccountableAuthorizing Official / CISO
- InformedCyber Threat Intelligence cell
- ConsultedSOC / Defensive Operations
- InformedHunt team
- ResponsiblePlatform and product owners
- ConsultedGovernance / RMF / ISSO
Inputs and Outputs
Consumes
- TM-1 Terrain Inventory and OverlayTerrain overlay the device layer is placed on
- ID-1 Identity Plane DefinitionIdentity planes, from which devices reaching the estate are discovered
- ID-3 Authentication AssuranceAuthentication records naming the devices that actually connect
- Outside the frameworkEndpoint management platform, procurement and asset records
Produces
- DV-2 Device Posture as an Access PreconditionDevice population that posture is evaluated for
- DV-3 Endpoint Sensor Coverage and LivenessInventory that sensor coverage is reconciled against
- DV-4 Execution ControlDevice terrain over which execution control is scoped
- KT-3 Avenue of Approach AnalysisDevice crossings as avenues of approach
- DV-5 Device Lifecycle and SanitizationDevice terrain and its recorded holders
Activities
- L2Represent devices with a path into the estate on the terrain overlay.
- L2Record the management state of each — managed, unmanaged, or unknown.
- L2Record the population that operates each device class.
- L3Reconcile the device set against the identity plane (
ID-1) rather than against the endpoint management console, since the console can only report devices it already manages. - L3Record the terrain each device class can reach, so a device is scored by its reach rather than by its cost.
- L3Classify unmanaged devices as a measured population with an owner and a disposition, not as an exception to the inventory.
- L3Record the software inventory carried by each managed device class, so a component disclosure can be resolved to devices rather than to an estate.
- L4Trend the unmanaged population against the managed one, and set a threshold above which the estate is not fit to plan device defense from.
- L4Measure the interval between a device first authenticating and its appearance on the overlay.
- L5Remove the conditions that generate unmanaged reach — brokered access, virtual desktops, or enrollment requirements — rather than counting it indefinitely.
Measurement
Percentage of authenticating devices present on the overlay.
Unmanaged population as a share of devices reaching the estate.
Evidence and Assessment
Terrain overlay showing device classes with management state, population and reach; reconciliation record; software inventory.
Examine the overlay against the identity plane rather than the management console; test for device classes authenticating but absent from the overlay; examine the unmanaged population's disposition.
Related Guidance
- CM-8
- CM-8(1)
- PM-5
- ID.AM-01
- ID.AM-02
- ID.AM-05
Position in the Chain
Derived from the other controls’ own declarations, so the two directions cannot disagree.
Where This Control Is Used
Derived, in every case, from the declaration at the other end: the forms whose techniques name this control, the artifacts whose producing and consuming controls include it, the layers whose control lists name it, and the roles its own accountability chart puts to work. Nothing here is authored on this page, so the sheet cannot claim an edge the other end does not.
Forms of Maneuver It Assesses
- M1Screen / GuardGain early warning and buy reaction time before the adversary touches key terrain.2 of 15 techniques — M1.02, M1.15
- M2Defense in DepthEnsure no single failure is decisive.1 of 18 techniques — M2.05
Terrain It Is Named On
- T2DevicesPuts devices on the overlay as terrain, discovered from the identity plane outward — the management console can only report the population it already holds.
Artifacts It Stands On
- consumesCyber Terrain OverlayThe positional map of the estate: every element with a defensive layer, a defensive weight, a named accountable owner and its adjacencies. Not an asset inventory — an inventory enumerates, an overlay positions.
Roles It Puts to Work
- AccountableAuthorizing Official / CISOIntent, risk acceptance, and the scheme itself.
- ResponsiblePlatform and product ownersTheir own terrain. Obstacles get emplaced on their ground, so they site them.
- ConsultedSOC / Defensive OperationsManeuver. Executes fires and emplaces obstacles inside the standing rules of engagement.
- ConsultedGovernance / RMF / ISSOTranslating cycle outputs into FISMA and RMF artifacts, and owning the rules of engagement.
- InformedCyber Threat Intelligence cellFrame, Map and Fuse. The intelligence requirements, the threat courses of action, and the confidence levels.
- InformedHunt teamCounterattack. Works the hypotheses that Fuse raises.