ASOM-Fedv6.1Open the explorer
DV-2 · Devices Terrain

Device Posture as an Access Precondition

Control Statement

Device health shall be evaluated as a precondition of access to designated terrain, and failing posture shall deny access rather than raise a notification.

Purpose. To ensure a compromised or non-compliant device cannot spend a valid credential, closing the gap M3 Envelopment leaves when identity alone is enforced.

Discussion

The word doing the work is **precondition**. A posture check that reports non-compliance into a ticket queue has measured device health; it has not defended anything, and the adversary holding the device proceeds unimpeded. This control is also where identity and device terrain meet: ID-3 requires authentication assurance commensurate with terrain, and device assurance is an input to that assurance rather than a parallel track. An estate enforcing strong authentication from an unhealthy endpoint has bought half the control.

Goals and Metrics

A metric that cannot come out badly is not a metric. Each of these is capable of reporting that the control is not working.

A compromised or non-compliant device cannot spend a valid credential.
  • Percentage of access to decisive-point terrain gated on posture
  • Proportion of grants made with a current posture signal
Posture exceptions are bounded and visible rather than permanent.
  • Size of the exception register
  • Median age of an open posture exception

Accountability

Exactly one role is accountable, and every other role carries at least Informed — no control in the published catalog leaves a role with zero relationship to it. That is a stated property of how these were authored, not a coincidence, and not a claim that every role's work is worth equal attention here.

AOCTISOCHUNTPLATISSO
Authorizing Official / CISO: AccountableCyber Threat Intelligence cell: InformedSOC / Defensive Operations: ConsultedHunt team: ConsultedPlatform and product owners: ResponsibleGovernance / RMF / ISSO: Informed

AO Authorizing Official / CISOCTI Cyber Threat Intelligence cellSOC SOC / Defensive OperationsHUNT Hunt teamPLAT Platform and product ownersISSO Governance / RMF / ISSO

  • AccountableAuthorizing Official / CISO
  • InformedCyber Threat Intelligence cell
  • ConsultedSOC / Defensive Operations
  • ConsultedHunt team
  • ResponsiblePlatform and product owners
  • InformedGovernance / RMF / ISSO

Inputs and Outputs

Consumes

Produces

Activities

  1. L2Evaluate device health signals before granting access to designated terrain.
  2. L2Define the posture requirement per terrain layer or access tier.
  3. L2Deny access on failing posture rather than recording an exception.
  4. L3Feed device assurance into the authorization decision under ID-5, so posture and identity are evaluated together rather than in sequence.
  5. L3Require posture for access to decisive points (KT-1) without exception, and record any exception with an owner and expiry.
  6. L3Re-evaluate posture during a session where the platform permits, not only at establishment.
  7. L3Define the fallback path for a device that cannot report posture, so an unreportable device is a decision rather than a bypass.
  8. L4Measure the proportion of access grants made with a current posture signal available, since a grant made without one is made blind.
  9. L4Trend the exception population and drive it toward a stated floor.
  10. L5Extend posture signals to the device classes that currently cannot report, rather than maintaining a permanent exception for them.

Measurement

Outcome

Percentage of access to decisive-point terrain gated on posture.

Performance

Proportion of grants made with a current posture signal.

Evidence and Assessment

Evidence expected

Posture requirements per terrain; grant records showing posture state; exception register with expiry.

Assessment procedure

Test that failing posture denies rather than notifies; examine whether posture reaches the authorization decision or runs beside it; examine the exception population against decisive-point terrain.

Related Guidance

Inherits
  • CM-6
  • AC-3
  • IA-3
Satisfies
  • PR.AA-05
  • PR.PS-01

Position in the Chain

Derived from the other controls’ own declarations, so the two directions cannot disagree.

Where This Control Is Used

Derived, in every case, from the declaration at the other end: the forms whose techniques name this control, the artifacts whose producing and consuming controls include it, the layers whose control lists name it, and the roles its own accountability chart puts to work. Nothing here is authored on this page, so the sheet cannot claim an edge the other end does not.

Forms of Maneuver It Assesses

  • M3EnvelopmentMake identity, not network location, the decisive plane — surround the adversary with policy.2 of 20 techniques — M3.05, M3.10
  • M2Defense in DepthEnsure no single failure is decisive.1 of 18 techniques — M2.06

Terrain It Is Named On

  • T2DevicesMakes device posture a precondition of access, which is what stops a valid credential being spent from a compromised endpoint.

Artifacts It Stands On

  • consumesDecisive point registerThe elements whose control confers decisive advantage — each carrying the evidence that raised it above merely important, and the protection floor it owes as a result.

Roles It Puts to Work