Control Statement
Devices shall be provisioned from a trusted baseline and, on retirement, loss or reassignment, shall be removed from the estate's trust and their media sanitized within a stated period.
Purpose. To close the ends of the device lifecycle — the point of entry and the point of exit — where trust is granted and where it is most often left behind.
Discussion
The exit end is where this control earns its place. A retired, lost or reassigned device frequently retains enrollment, certificates, cached credentials and stored data long after it has left the population it was issued to — which makes it an unattributed device holding valid trust, exactly the condition DV-1 is designed to surface and WF-5 assumes has been handled. The stated period matters as much as the action: a sanitization process that completes eventually is not a control against a device already outside the agency's physical control.
Goals and Metrics
A metric that cannot come out badly is not a metric. Each of these is capable of reporting that the control is not working.
- Count of devices holding estate trust with no current holder
- Median elapsed time from retirement or loss to trust removal
- Percentage of disposals with a sanitization record naming method and verification
- Number of disposals completed without verification
Accountability
Exactly one role is accountable, and every other role carries at least Informed — no control in the published catalog leaves a role with zero relationship to it. That is a stated property of how these were authored, not a coincidence, and not a claim that every role's work is worth equal attention here.
| AO | CTI | SOC | HUNT | PLAT | ISSO |
|---|---|---|---|---|---|
| Authorizing Official / CISO: Accountable | Cyber Threat Intelligence cell: Informed | SOC / Defensive Operations: Consulted | Hunt team: Informed | Platform and product owners: Responsible | Governance / RMF / ISSO: Consulted |
AO Authorizing Official / CISOCTI Cyber Threat Intelligence cellSOC SOC / Defensive OperationsHUNT Hunt teamPLAT Platform and product ownersISSO Governance / RMF / ISSO
- AccountableAuthorizing Official / CISO
- InformedCyber Threat Intelligence cell
- ConsultedSOC / Defensive Operations
- InformedHunt team
- ResponsiblePlatform and product owners
- ConsultedGovernance / RMF / ISSO
Inputs and Outputs
Consumes
- DV-1 Device Terrain IdentificationDevice terrain and its recorded holders
- LC-2 Component ProvenanceBaseline provenance the provisioning image is built from
- WF-5 Separation and Revocation TempoSeparation triggers that start the trust-removal clock
Produces
- TM-6 Terrain CurrencyRetirement events that keep the terrain overlay current
- CG-4 Findings DispositionOrphaned-trust findings requiring disposition
Activities
- L2Provision devices from a defined baseline image or configuration.
- L2Remove retired, lost and reassigned devices from the estate's trust.
- L2Sanitize media on retirement or reassignment.
- L3Verify the provisioning baseline's integrity and provenance under
LC-2, so a trusted baseline is trusted for a reason. - L3State the period within which trust must be removed following retirement, loss or reassignment, derived from what the device's retained trust could do, with provenance per
GA4. - L3Reconcile device retirement against the identity plane and
WF-5revocation, so a device leaving with a person is handled once rather than twice. - L3Record sanitization with its method and verification, and record devices that left the estate unsanitised as findings rather than as losses.
- L4Measure elapsed time from retirement, loss or reassignment to trust removal, against the stated period.
- L4Trend the population of devices holding trust with no current holder, which is the direct measure of this control's exit end.
- L5Reduce what a device retains — moving to brokered access, ephemeral credentials and non-persistent workspaces — so retirement removes less.
Measurement
Devices holding estate trust with no current holder.
Median elapsed time from retirement or loss to trust removal.
Evidence and Assessment
Provisioning baseline with provenance record; trust removal times; sanitization records with method and verification; orphaned-trust findings.
Test trust removal against the stated period; examine sanitization verification on a sample; examine the population of devices holding trust with no current holder.
Related Guidance
- MP-6
- CM-2
- MA-2
- ID.AM-08
- PR.DS-11
- PR.PS-02
Where This Control Is Used
Derived, in every case, from the declaration at the other end: the forms whose techniques name this control, the artifacts whose producing and consuming controls include it, the layers whose control lists name it, and the roles its own accountability chart puts to work. Nothing here is authored on this page, so the sheet cannot claim an edge the other end does not.
Forms of Maneuver It Assesses
- M8Isolation / RetrogradeGive ground deliberately to preserve the force. Degrade gracefully; never fail open.2 of 17 techniques — M8.14, M8.17
- M4Obstacle / CanalizationForce the adversary onto ground you own and watch.1 of 17 techniques — M4.09
- M11ReconstitutionRestore the mission on evidence, not on hope — and prove it before you need it.1 of 11 techniques — M11.03
Terrain It Is Named On
- T2DevicesCloses both ends of the lifecycle, where trust is granted and where it is most often left behind on a device nobody holds any more.
Artifacts It Stands On
- consumesSeparation and revocation recordHow long it takes to remove everything an individual holds, per system, and which systems cannot be revoked in a single action. Feeds terrain ownership so revocation does not orphan an element.
- consumesComponent provenance recordWhere components came from, from inventories, build manifests and supplier attestations — and which components have an origin that cannot be verified.
Roles It Puts to Work
- AccountableAuthorizing Official / CISOIntent, risk acceptance, and the scheme itself.
- ResponsiblePlatform and product ownersTheir own terrain. Obstacles get emplaced on their ground, so they site them.
- ConsultedSOC / Defensive OperationsManeuver. Executes fires and emplaces obstacles inside the standing rules of engagement.
- ConsultedGovernance / RMF / ISSOTranslating cycle outputs into FISMA and RMF artifacts, and owning the rules of engagement.
- InformedCyber Threat Intelligence cellFrame, Map and Fuse. The intelligence requirements, the threat courses of action, and the confidence levels.
- InformedHunt teamCounterattack. Works the hypotheses that Fuse raises.