Control Statement
What may execute on designated device terrain shall be constrained to an approved, verified set, and unauthorized execution shall be prevented rather than recorded.
Purpose. To deny the adversary the ability to run code on the ground they cross into, which is the cheapest point at which most engagements can be stopped.
Discussion
Execution control is the highest-yield and least-adopted device control, because it trades operational friction now against an outcome that is invisible when it works. The framework's position is that the constraint belongs on **designated terrain** rather than universally — decisive points, privileged access workstations, and devices reaching the data layer — which makes it affordable and keeps it enforceable. Universal application is where these programs fail, and where they are subsequently downgraded to audit mode and forgotten.
Goals and Metrics
A metric that cannot come out badly is not a metric. Each of these is capable of reporting that the control is not working.
- Percentage of designated device terrain under enforced execution control
- Count of unauthorized execution events, trended
- Exception population
- Median age of an open execution exception
Accountability
Exactly one role is accountable, and every other role carries at least Informed — no control in the published catalog leaves a role with zero relationship to it. That is a stated property of how these were authored, not a coincidence, and not a claim that every role's work is worth equal attention here.
| AO | CTI | SOC | HUNT | PLAT | ISSO |
|---|---|---|---|---|---|
| Authorizing Official / CISO: Accountable | Cyber Threat Intelligence cell: Informed | SOC / Defensive Operations: Consulted | Hunt team: Consulted | Platform and product owners: Responsible | Governance / RMF / ISSO: Informed |
AO Authorizing Official / CISOCTI Cyber Threat Intelligence cellSOC SOC / Defensive OperationsHUNT Hunt teamPLAT Platform and product ownersISSO Governance / RMF / ISSO
- AccountableAuthorizing Official / CISO
- InformedCyber Threat Intelligence cell
- ConsultedSOC / Defensive Operations
- ConsultedHunt team
- ResponsiblePlatform and product owners
- InformedGovernance / RMF / ISSO
Inputs and Outputs
Consumes
- DV-1 Device Terrain IdentificationDevice terrain over which enforcement is scoped
- KT-1 Decisive Point IdentificationDecisive points where enforcement is mandatory
- LC-2 Component ProvenanceComponent provenance establishing what may legitimately run
Produces
- EN-1 Event Declaration and TriageUnauthorized execution events as declaration triggers
- CE-4 Coverage and Residual Risk ComputationEnforcement scope feeding coverage computation
Activities
- L2Define what may execute on designated device terrain.
- L2Prevent execution outside the approved set on that terrain.
- L2Record attempted unauthorized execution as an event.
- L3Derive the approved set from verified provenance under
LC-2rather than from observed usage alone. - L3Scope enforcement to designated terrain — decisive points, privileged access workstations, and devices reaching the data layer — rather than universally.
- L3Define the exception path with an owner and expiry, since an undefined exception path results in enforcement being disabled wholesale.
- L3Constrain script and interpreter execution as well as binaries, since restricting only executables displaces rather than prevents.
- L4Measure the proportion of designated terrain under enforcement rather than audit mode, and treat audit mode as unenforced.
- L4Trend attempted unauthorized executions, which is a detection signal as much as a prevention one.
- L5Extend enforcement outward from designated terrain as the exception rate falls, rather than attempting universal coverage at the outset.
Measurement
Percentage of designated device terrain under enforced execution control.
Exception population and its median age.
Evidence and Assessment
Approved execution set with provenance linkage; enforcement scope record distinguishing enforced from audit mode; exception register.
Test that unauthorized execution is prevented rather than logged on designated terrain; examine whether enforcement is active or in audit mode; examine the derivation of the approved set against LC-2.
Related Guidance
- CM-7
- CM-7(5)
- SI-7
- PR.PS-05
- PR.PS-02
Position in the Chain
Derived from the other controls’ own declarations, so the two directions cannot disagree.
Feeds
Nothing downstream — this control terminates a chain.
Where This Control Is Used
Derived, in every case, from the declaration at the other end: the forms whose techniques name this control, the artifacts whose producing and consuming controls include it, the layers whose control lists name it, and the roles its own accountability chart puts to work. Nothing here is authored on this page, so the sheet cannot claim an edge the other end does not.
Forms of Maneuver It Assesses
- M2Defense in DepthEnsure no single failure is decisive.1 of 18 techniques — M2.11
- M4Obstacle / CanalizationForce the adversary onto ground you own and watch.1 of 17 techniques — M4.05
Terrain It Is Named On
- T2DevicesConstrains what may execute on the ground the adversary crosses into — the cheapest point at which most engagements can be stopped.
Artifacts It Stands On
- consumesDecisive point registerThe elements whose control confers decisive advantage — each carrying the evidence that raised it above merely important, and the protection floor it owes as a result.
- consumesComponent provenance recordWhere components came from, from inventories, build manifests and supplier attestations — and which components have an origin that cannot be verified.
Roles It Puts to Work
- AccountableAuthorizing Official / CISOIntent, risk acceptance, and the scheme itself.
- ResponsiblePlatform and product ownersTheir own terrain. Obstacles get emplaced on their ground, so they site them.
- ConsultedSOC / Defensive OperationsManeuver. Executes fires and emplaces obstacles inside the standing rules of engagement.
- ConsultedHunt teamCounterattack. Works the hypotheses that Fuse raises.
- InformedCyber Threat Intelligence cellFrame, Map and Fuse. The intelligence requirements, the threat courses of action, and the confidence levels.
- InformedGovernance / RMF / ISSOTranslating cycle outputs into FISMA and RMF artifacts, and owning the rules of engagement.