ASOM-Fedv6.1Open the explorer
DV-5 · Devices Terrain

Device Lifecycle and Sanitization

Control Statement

Devices shall be provisioned from a trusted baseline and, on retirement, loss or reassignment, shall be removed from the estate's trust and their media sanitized within a stated period.

Purpose. To close the ends of the device lifecycle — the point of entry and the point of exit — where trust is granted and where it is most often left behind.

Discussion

The exit end is where this control earns its place. A retired, lost or reassigned device frequently retains enrollment, certificates, cached credentials and stored data long after it has left the population it was issued to — which makes it an unattributed device holding valid trust, exactly the condition DV-1 is designed to surface and WF-5 assumes has been handled. The stated period matters as much as the action: a sanitization process that completes eventually is not a control against a device already outside the agency's physical control.

Goals and Metrics

A metric that cannot come out badly is not a metric. Each of these is capable of reporting that the control is not working.

No device holds estate trust without a current holder.
  • Count of devices holding estate trust with no current holder
  • Median elapsed time from retirement or loss to trust removal
Media leaving the estate is sanitized by a verified method.
  • Percentage of disposals with a sanitization record naming method and verification
  • Number of disposals completed without verification

Accountability

Exactly one role is accountable, and every other role carries at least Informed — no control in the published catalog leaves a role with zero relationship to it. That is a stated property of how these were authored, not a coincidence, and not a claim that every role's work is worth equal attention here.

AOCTISOCHUNTPLATISSO
Authorizing Official / CISO: AccountableCyber Threat Intelligence cell: InformedSOC / Defensive Operations: ConsultedHunt team: InformedPlatform and product owners: ResponsibleGovernance / RMF / ISSO: Consulted

AO Authorizing Official / CISOCTI Cyber Threat Intelligence cellSOC SOC / Defensive OperationsHUNT Hunt teamPLAT Platform and product ownersISSO Governance / RMF / ISSO

  • AccountableAuthorizing Official / CISO
  • InformedCyber Threat Intelligence cell
  • ConsultedSOC / Defensive Operations
  • InformedHunt team
  • ResponsiblePlatform and product owners
  • ConsultedGovernance / RMF / ISSO

Inputs and Outputs

Consumes

Produces

Activities

  1. L2Provision devices from a defined baseline image or configuration.
  2. L2Remove retired, lost and reassigned devices from the estate's trust.
  3. L2Sanitize media on retirement or reassignment.
  4. L3Verify the provisioning baseline's integrity and provenance under LC-2, so a trusted baseline is trusted for a reason.
  5. L3State the period within which trust must be removed following retirement, loss or reassignment, derived from what the device's retained trust could do, with provenance per GA4.
  6. L3Reconcile device retirement against the identity plane and WF-5 revocation, so a device leaving with a person is handled once rather than twice.
  7. L3Record sanitization with its method and verification, and record devices that left the estate unsanitised as findings rather than as losses.
  8. L4Measure elapsed time from retirement, loss or reassignment to trust removal, against the stated period.
  9. L4Trend the population of devices holding trust with no current holder, which is the direct measure of this control's exit end.
  10. L5Reduce what a device retains — moving to brokered access, ephemeral credentials and non-persistent workspaces — so retirement removes less.

Measurement

Outcome

Devices holding estate trust with no current holder.

Performance

Median elapsed time from retirement or loss to trust removal.

Evidence and Assessment

Evidence expected

Provisioning baseline with provenance record; trust removal times; sanitization records with method and verification; orphaned-trust findings.

Assessment procedure

Test trust removal against the stated period; examine sanitization verification on a sample; examine the population of devices holding trust with no current holder.

Related Guidance

Inherits
  • MP-6
  • CM-2
  • MA-2
Satisfies
  • ID.AM-08
  • PR.DS-11
  • PR.PS-02

Where This Control Is Used

Derived, in every case, from the declaration at the other end: the forms whose techniques name this control, the artifacts whose producing and consuming controls include it, the layers whose control lists name it, and the roles its own accountability chart puts to work. Nothing here is authored on this page, so the sheet cannot claim an edge the other end does not.

Forms of Maneuver It Assesses

  • M8Isolation / RetrogradeGive ground deliberately to preserve the force. Degrade gracefully; never fail open.2 of 17 techniques — M8.14, M8.17
  • M4Obstacle / CanalizationForce the adversary onto ground you own and watch.1 of 17 techniques — M4.09
  • M11ReconstitutionRestore the mission on evidence, not on hope — and prove it before you need it.1 of 11 techniques — M11.03

Terrain It Is Named On

  • T2DevicesCloses both ends of the lifecycle, where trust is granted and where it is most often left behind on a device nobody holds any more.

Artifacts It Stands On

  • consumesSeparation and revocation recordHow long it takes to remove everything an individual holds, per system, and which systems cannot be revoked in a single action. Feeds terrain ownership so revocation does not orphan an element.
  • consumesComponent provenance recordWhere components came from, from inventories, build manifests and supplier attestations — and which components have an origin that cannot be verified.

Roles It Puts to Work