ASOM-Fedv6.1Open the explorer
DV-4 · Devices Terrain

Execution Control

Control Statement

What may execute on designated device terrain shall be constrained to an approved, verified set, and unauthorized execution shall be prevented rather than recorded.

Purpose. To deny the adversary the ability to run code on the ground they cross into, which is the cheapest point at which most engagements can be stopped.

Discussion

Execution control is the highest-yield and least-adopted device control, because it trades operational friction now against an outcome that is invisible when it works. The framework's position is that the constraint belongs on **designated terrain** rather than universally — decisive points, privileged access workstations, and devices reaching the data layer — which makes it affordable and keeps it enforceable. Universal application is where these programs fail, and where they are subsequently downgraded to audit mode and forgotten.

Goals and Metrics

A metric that cannot come out badly is not a metric. Each of these is capable of reporting that the control is not working.

Designated device terrain runs only approved code.
  • Percentage of designated device terrain under enforced execution control
  • Count of unauthorized execution events, trended
Execution exceptions decay rather than accumulate.
  • Exception population
  • Median age of an open execution exception

Accountability

Exactly one role is accountable, and every other role carries at least Informed — no control in the published catalog leaves a role with zero relationship to it. That is a stated property of how these were authored, not a coincidence, and not a claim that every role's work is worth equal attention here.

AOCTISOCHUNTPLATISSO
Authorizing Official / CISO: AccountableCyber Threat Intelligence cell: InformedSOC / Defensive Operations: ConsultedHunt team: ConsultedPlatform and product owners: ResponsibleGovernance / RMF / ISSO: Informed

AO Authorizing Official / CISOCTI Cyber Threat Intelligence cellSOC SOC / Defensive OperationsHUNT Hunt teamPLAT Platform and product ownersISSO Governance / RMF / ISSO

  • AccountableAuthorizing Official / CISO
  • InformedCyber Threat Intelligence cell
  • ConsultedSOC / Defensive Operations
  • ConsultedHunt team
  • ResponsiblePlatform and product owners
  • InformedGovernance / RMF / ISSO

Inputs and Outputs

Consumes

Produces

Activities

  1. L2Define what may execute on designated device terrain.
  2. L2Prevent execution outside the approved set on that terrain.
  3. L2Record attempted unauthorized execution as an event.
  4. L3Derive the approved set from verified provenance under LC-2 rather than from observed usage alone.
  5. L3Scope enforcement to designated terrain — decisive points, privileged access workstations, and devices reaching the data layer — rather than universally.
  6. L3Define the exception path with an owner and expiry, since an undefined exception path results in enforcement being disabled wholesale.
  7. L3Constrain script and interpreter execution as well as binaries, since restricting only executables displaces rather than prevents.
  8. L4Measure the proportion of designated terrain under enforcement rather than audit mode, and treat audit mode as unenforced.
  9. L4Trend attempted unauthorized executions, which is a detection signal as much as a prevention one.
  10. L5Extend enforcement outward from designated terrain as the exception rate falls, rather than attempting universal coverage at the outset.

Measurement

Outcome

Percentage of designated device terrain under enforced execution control.

Performance

Exception population and its median age.

Evidence and Assessment

Evidence expected

Approved execution set with provenance linkage; enforcement scope record distinguishing enforced from audit mode; exception register.

Assessment procedure

Test that unauthorized execution is prevented rather than logged on designated terrain; examine whether enforcement is active or in audit mode; examine the derivation of the approved set against LC-2.

Related Guidance

Inherits
  • CM-7
  • CM-7(5)
  • SI-7
Satisfies
  • PR.PS-05
  • PR.PS-02

Position in the Chain

Derived from the other controls’ own declarations, so the two directions cannot disagree.

Feeds

Nothing downstream — this control terminates a chain.

Where This Control Is Used

Derived, in every case, from the declaration at the other end: the forms whose techniques name this control, the artifacts whose producing and consuming controls include it, the layers whose control lists name it, and the roles its own accountability chart puts to work. Nothing here is authored on this page, so the sheet cannot claim an edge the other end does not.

Forms of Maneuver It Assesses

Terrain It Is Named On

  • T2DevicesConstrains what may execute on the ground the adversary crosses into — the cheapest point at which most engagements can be stopped.

Artifacts It Stands On

  • consumesDecisive point registerThe elements whose control confers decisive advantage — each carrying the evidence that raised it above merely important, and the protection floor it owes as a result.
  • consumesComponent provenance recordWhere components came from, from inventories, build manifests and supplier attestations — and which components have an origin that cannot be verified.

Roles It Puts to Work