Control Statement
Device health shall be evaluated as a precondition of access to designated terrain, and failing posture shall deny access rather than raise a notification.
Purpose. To ensure a compromised or non-compliant device cannot spend a valid credential, closing the gap M3 Envelopment leaves when identity alone is enforced.
Discussion
The word doing the work is **precondition**. A posture check that reports non-compliance into a ticket queue has measured device health; it has not defended anything, and the adversary holding the device proceeds unimpeded. This control is also where identity and device terrain meet: ID-3 requires authentication assurance commensurate with terrain, and device assurance is an input to that assurance rather than a parallel track. An estate enforcing strong authentication from an unhealthy endpoint has bought half the control.
Goals and Metrics
A metric that cannot come out badly is not a metric. Each of these is capable of reporting that the control is not working.
- Percentage of access to decisive-point terrain gated on posture
- Proportion of grants made with a current posture signal
- Size of the exception register
- Median age of an open posture exception
Accountability
Exactly one role is accountable, and every other role carries at least Informed — no control in the published catalog leaves a role with zero relationship to it. That is a stated property of how these were authored, not a coincidence, and not a claim that every role's work is worth equal attention here.
| AO | CTI | SOC | HUNT | PLAT | ISSO |
|---|---|---|---|---|---|
| Authorizing Official / CISO: Accountable | Cyber Threat Intelligence cell: Informed | SOC / Defensive Operations: Consulted | Hunt team: Consulted | Platform and product owners: Responsible | Governance / RMF / ISSO: Informed |
AO Authorizing Official / CISOCTI Cyber Threat Intelligence cellSOC SOC / Defensive OperationsHUNT Hunt teamPLAT Platform and product ownersISSO Governance / RMF / ISSO
- AccountableAuthorizing Official / CISO
- InformedCyber Threat Intelligence cell
- ConsultedSOC / Defensive Operations
- ConsultedHunt team
- ResponsiblePlatform and product owners
- InformedGovernance / RMF / ISSO
Inputs and Outputs
Consumes
- DV-1 Device Terrain IdentificationDevice terrain the posture requirement is applied across
- ID-5 Authorization Decision IntegrityAuthorization decision point that enforces the precondition
- KT-1 Decisive Point IdentificationDecisive points setting the strictest posture requirement
- Outside the frameworkPosture telemetry from the endpoint platform
- ID-3 Authentication AssuranceAssurance requirement that device posture is evaluated alongside
Produces
- ID-3 Authentication AssuranceDevice posture as a component of achieved assurance
- CE-4 Coverage and Residual Risk ComputationGated-access figures feeding coverage computation
Activities
- L2Evaluate device health signals before granting access to designated terrain.
- L2Define the posture requirement per terrain layer or access tier.
- L2Deny access on failing posture rather than recording an exception.
- L3Feed device assurance into the authorization decision under
ID-5, so posture and identity are evaluated together rather than in sequence. - L3Require posture for access to decisive points (
KT-1) without exception, and record any exception with an owner and expiry. - L3Re-evaluate posture during a session where the platform permits, not only at establishment.
- L3Define the fallback path for a device that cannot report posture, so an unreportable device is a decision rather than a bypass.
- L4Measure the proportion of access grants made with a current posture signal available, since a grant made without one is made blind.
- L4Trend the exception population and drive it toward a stated floor.
- L5Extend posture signals to the device classes that currently cannot report, rather than maintaining a permanent exception for them.
Measurement
Percentage of access to decisive-point terrain gated on posture.
Proportion of grants made with a current posture signal.
Evidence and Assessment
Posture requirements per terrain; grant records showing posture state; exception register with expiry.
Test that failing posture denies rather than notifies; examine whether posture reaches the authorization decision or runs beside it; examine the exception population against decisive-point terrain.
Related Guidance
- CM-6
- AC-3
- IA-3
- PR.AA-05
- PR.PS-01
Position in the Chain
Derived from the other controls’ own declarations, so the two directions cannot disagree.
Fed By
Feeds
Nothing downstream — this control terminates a chain.
Where This Control Is Used
Derived, in every case, from the declaration at the other end: the forms whose techniques name this control, the artifacts whose producing and consuming controls include it, the layers whose control lists name it, and the roles its own accountability chart puts to work. Nothing here is authored on this page, so the sheet cannot claim an edge the other end does not.
Forms of Maneuver It Assesses
- M3EnvelopmentMake identity, not network location, the decisive plane — surround the adversary with policy.2 of 20 techniques — M3.05, M3.10
- M2Defense in DepthEnsure no single failure is decisive.1 of 18 techniques — M2.06
Terrain It Is Named On
- T2DevicesMakes device posture a precondition of access, which is what stops a valid credential being spent from a compromised endpoint.
Artifacts It Stands On
- consumesDecisive point registerThe elements whose control confers decisive advantage — each carrying the evidence that raised it above merely important, and the protection floor it owes as a result.
Roles It Puts to Work
- AccountableAuthorizing Official / CISOIntent, risk acceptance, and the scheme itself.
- ResponsiblePlatform and product ownersTheir own terrain. Obstacles get emplaced on their ground, so they site them.
- ConsultedSOC / Defensive OperationsManeuver. Executes fires and emplaces obstacles inside the standing rules of engagement.
- ConsultedHunt teamCounterattack. Works the hypotheses that Fuse raises.
- InformedCyber Threat Intelligence cellFrame, Map and Fuse. The intelligence requirements, the threat courses of action, and the confidence levels.
- InformedGovernance / RMF / ISSOTranslating cycle outputs into FISMA and RMF artifacts, and owning the rules of engagement.