Control Statement
Incidents shall be escalated against defined criteria to an authority that is reachable within a stated period, and the authority exercised shall be recorded against the action taken.
Purpose. To remove the search for a decision-maker from the decision loop, which is where the decide segment is usually spent.
Discussion
TA-4 defines what may be done without escalation; this control governs what happens when escalation is required, and the two together constitute the decide segment. The binding constraint in most programs is not deliberation but locating someone with authority, and that is an availability problem rather than a judgment problem. Recording authority against action closes the loop in the other direction: an operator who acted correctly under written authority and is later questioned needs the record more than the organization does, and without it the practical effect is that the next operator escalates instead.
Goals and Metrics
A metric that cannot come out badly is not a metric. Each of these is capable of reporting that the control is not working.
- Time from escalation trigger to authority response
- Percentage of named authorities verified reachable out of hours
- Percentage of escalations recording the authority exercised
- Count of actions taken outside the pre-authorized set
Accountability
Exactly one role is accountable, and every other role carries at least Informed — no control in the published catalog leaves a role with zero relationship to it. That is a stated property of how these were authored, not a coincidence, and not a claim that every role's work is worth equal attention here.
| AO | CTI | SOC | HUNT | PLAT | ISSO |
|---|---|---|---|---|---|
| Authorizing Official / CISO: Accountable | Cyber Threat Intelligence cell: Informed | SOC / Defensive Operations: Responsible | Hunt team: Informed | Platform and product owners: Informed | Governance / RMF / ISSO: Consulted |
AO Authorizing Official / CISOCTI Cyber Threat Intelligence cellSOC SOC / Defensive OperationsHUNT Hunt teamPLAT Platform and product ownersISSO Governance / RMF / ISSO
- AccountableAuthorizing Official / CISO
- InformedCyber Threat Intelligence cell
- ResponsibleSOC / Defensive Operations
- InformedHunt team
- InformedPlatform and product owners
- ConsultedGovernance / RMF / ISSO
Inputs and Outputs
Consumes
- EN-1 Event Declaration and TriageDeclared and prioritized incidents
- TA-4 Pre-authorized ResponsePre-authorized response set, which bounds what needs escalating
- CG-3 Rules of EngagementRules of engagement defining the limits of authority
- CG-2 Phase DeclarationDeclared phase, which can widen standing authority
Produces
- TA-1 Decision Loop MeasurementAuthority response time within the decide segment
- TA-4 Pre-authorized ResponseEvidence for revising the pre-authorized set
- EN-5 Eradication and Transition to RecoveryThe decision authorizing transition to recovery
Activities
- L2Define the criteria at which an incident escalates.
- L2Define the authority level required at each escalation tier.
- L2Record the authority exercised against each action taken.
- L3State the period within which each named authority must be reachable, and maintain an out-of-hours path consistent with
CG-3. - L3Define escalation for the case where the named authority is unreachable, including who may act in their absence and under what constraint.
- L3Escalate on terrain rather than on severity alone — an incident touching a decisive point escalates regardless of apparent magnitude.
- L3Record escalations that were required by criteria and did not occur, so the gap between criteria and practice is visible.
- L4Measure time from escalation trigger to authority response, separately from total decide-segment time, since these fail for different reasons.
- L4Test reachability of each named authority out of hours rather than assuming it, at a defined cadence.
- L5Move recurring escalations that are always approved into the pre-authorized set under
TA-4, since a decision made identically every time is a policy rather than a decision.
Measurement
Time from escalation trigger to authority response.
Percentage of named authorities verified reachable out of hours.
Evidence and Assessment
Escalation criteria and tiers; escalation records with authority and response times; reachability test records; missed-escalation record.
Examine criteria against a sample of incidents; test out-of-hours reachability; examine whether authority was recorded against actions taken.
Related Guidance
- IR-4
- IR-6
- IR-7
- RS.MA-04
Position in the Chain
Derived from the other controls’ own declarations, so the two directions cannot disagree.
Where This Control Is Used
Derived, in every case, from the declaration at the other end: the forms whose techniques name this control, the artifacts whose producing and consuming controls include it, the layers whose control lists name it, and the roles its own accountability chart puts to work. Nothing here is authored on this page, so the sheet cannot claim an edge the other end does not.
Forms of Maneuver It Assesses
- M6DelayBuy decision time and prevent the adversary culminating on the objective.1 of 10 techniques — M6.05
- M7CounterattackSeize the initiative and evict before the adversary reaches the objective.1 of 17 techniques — M7.03
- M8Isolation / RetrogradeGive ground deliberately to preserve the force. Degrade gracefully; never fail open.1 of 17 techniques — M8.01
Terrain It Is Named On
Applies to all ten layersNames who may authorize action on this layer out of hours, which is where the decide segment is usually spent.
Artifacts It Stands On
- producesEngagement recordThe record of one engagement end to end: what was declared and on what criteria, the reconstruction with its dwell, scope and confidence, the evidence preserved and its custody, the authority exercised, and the verification that eradication actually happened before recovery began.
- consumesPhase declarationThe declared campaign phase and the scope it is declared against. Sets cadence, dominant forms of maneuver, and how wide the pre-authorization set runs.
- consumesRules of engagementWhich defensive actions may be taken by whom without escalation, which need the Authorizing Official, and what is prohibited outright. The cyber analog of engagement authority, and the single largest determinant of tempo.
- consumesPre-authorized response setThe specific containment and response actions the SOC may execute at machine speed, bounded by the statutory availability floor. Directly measurable: it shortens the decision segment of the defender loop.
- consumesChange recordEvery defensive action carried out, stamped twice — at the decision and at the effect. A thin, unglamorous table, and the one the headline metric is computed from.
- consumesAuthority exception logActions taken outside the standing rules of engagement, with who approved them and why. Exceptions are not failures; unrecorded exceptions are.
Roles It Puts to Work
- AccountableAuthorizing Official / CISOIntent, risk acceptance, and the scheme itself.
- ResponsibleSOC / Defensive OperationsManeuver. Executes fires and emplaces obstacles inside the standing rules of engagement.
- ConsultedGovernance / RMF / ISSOTranslating cycle outputs into FISMA and RMF artifacts, and owning the rules of engagement.
- InformedCyber Threat Intelligence cellFrame, Map and Fuse. The intelligence requirements, the threat courses of action, and the confidence levels.
- InformedHunt teamCounterattack. Works the hypotheses that Fuse raises.
- InformedPlatform and product ownersTheir own terrain. Obstacles get emplaced on their ground, so they site them.