Control Statement
Facilities shall be divided into zones whose boundaries are enforced and logged, and the zone containing each decisive point shall be identified.
Purpose. To establish physical boundaries that constrain movement and produce a record of crossing, so that physical terrain can be defended in depth rather than at a perimeter.
Discussion
These are physical zones and they are not the logical trust zones of TM-4; conflating the two produces an overlay that claims segmentation it does not have in either dimension. The word doing the work here is *enforced*, and its physical failure mode is specific: a boundary that opens for an authorized badge and admits whoever follows has controlled a door without attributing an entry. Enforcement in this control means individual attribution at the crossing, because a log that records which badge opened a door — rather than who passed through it — cannot answer the question an investigation will ask.
Goals and Metrics
A metric that cannot come out badly is not a metric. Each of these is capable of reporting that the control is not working.
- Number of physical zone boundaries enforced and logged versus signposted only
- Number of decisive points whose containing zone is not identified
Accountability
Exactly one role is accountable, and every other role carries at least Informed — no control in the published catalog leaves a role with zero relationship to it. That is a stated property of how these were authored, not a coincidence, and not a claim that every role's work is worth equal attention here.
| AO | CTI | SOC | HUNT | PLAT | ISSO |
|---|---|---|---|---|---|
| Authorizing Official / CISO: Accountable | Cyber Threat Intelligence cell: Informed | SOC / Defensive Operations: Consulted | Hunt team: Informed | Platform and product owners: Responsible | Governance / RMF / ISSO: Consulted |
AO Authorizing Official / CISOCTI Cyber Threat Intelligence cellSOC SOC / Defensive OperationsHUNT Hunt teamPLAT Platform and product ownersISSO Governance / RMF / ISSO
- AccountableAuthorizing Official / CISO
- InformedCyber Threat Intelligence cell
- ConsultedSOC / Defensive Operations
- InformedHunt team
- ResponsiblePlatform and product owners
- ConsultedGovernance / RMF / ISSO
Inputs and Outputs
Consumes
- FC-1 Facility Terrain IdentificationFacilities and their contents
- KT-1 Decisive Point IdentificationDecisive points requiring physical location
- TM-4 Trust Zone DefinitionLogical trust zones to reconcile against
Produces
- FC-3 Maintenance Access ControlZones within which maintenance access must be controlled
- KT-3 Avenue of Approach AnalysisPhysical approach routes to decisive points
- KT-5 Barrier SufficiencyPhysical barriers holding the line
Activities
- L2Divide each facility into zones and declare their boundaries.
- L2Identify the zone containing each decisive point.
- L2Log crossings at each declared boundary.
- L3Define each zone by the access assumption that holds inside it, and state what entitles a person to be there.
- L3Identify the mechanism enforcing each boundary and its owner, distinguishing boundaries enforced by construction, by mechanism, and by convention.
- L3Address unattributed entry — tailgating and piggybacking — at boundaries protecting decisive points, so a crossing resolves to a person rather than to a credential.
- L3Make crossing logs reviewable and retained for a period matched to the dwell estimate (TA-2), since an investigation reaching back further than retention finds nothing.
- L4Test a sample of boundaries by attempted traversal rather than by inspecting the access control configuration.
- L4Trend the count of convention-enforced boundaries protecting decisive points, driving it to zero.
- L5Re-zone where repeated exception grants show a boundary drawn across normal work, since a boundary routinely bypassed with permission is not a boundary.
Measurement
Percentage of decisive points inside a boundary with enforced, attributed crossing.
Traversal test pass rate on sampled boundaries.
Evidence and Assessment
Zone declaration with enforcement mechanism; access logs per boundary; traversal test records; retention configuration.
Examine zone boundaries and their enforcement; test that crossings are logged, attributed and reviewable; test a boundary by attempted traversal; compare log retention against the current dwell estimate.
Related Guidance
- PE-3(1)
- PE-5
- SC-7
- PR.AA-06
- PR.IR-02
- DE.CM-02
Position in the Chain
Derived from the other controls’ own declarations, so the two directions cannot disagree.
Where This Control Is Used
Derived, in every case, from the declaration at the other end: the forms whose techniques name this control, the artifacts whose producing and consuming controls include it, the layers whose control lists name it, and the roles its own accountability chart puts to work. Nothing here is authored on this page, so the sheet cannot claim an edge the other end does not.
Forms of Maneuver It Assesses
- M1Screen / GuardGain early warning and buy reaction time before the adversary touches key terrain.1 of 15 techniques — M1.13
- M2Defense in DepthEnsure no single failure is decisive.1 of 18 techniques — M2.17
- M4Obstacle / CanalizationForce the adversary onto ground you own and watch.1 of 17 techniques — M4.15
- M8Isolation / RetrogradeGive ground deliberately to preserve the force. Degrade gracefully; never fail open.1 of 17 techniques — M8.15
Terrain It Is Named On
- T8FacilitiesPhysical zone boundary, including the requirement that physical zones correspond to logical trust zones.
Artifacts It Stands On
- producesPhysical zone boundary recordZone divisions inside facilities, reconciled against the logical trust zones, with physical approach routes to decisive points enumerated as avenues.
- consumesTrust zones and the connection registerThe zone boundaries and the permitted- and denied-path register — the graph reachability is actually walked over, reconciled against observed flow telemetry rather than against intended configuration.
- consumesDecisive point registerThe elements whose control confers decisive advantage — each carrying the evidence that raised it above merely important, and the protection floor it owes as a result.
- consumesFacility terrain registerWhere elements physically are, which personnel populations are associated with each site, and which facilities carry mission services.
Roles It Puts to Work
- AccountableAuthorizing Official / CISOIntent, risk acceptance, and the scheme itself.
- ResponsiblePlatform and product ownersTheir own terrain. Obstacles get emplaced on their ground, so they site them.
- ConsultedSOC / Defensive OperationsManeuver. Executes fires and emplaces obstacles inside the standing rules of engagement.
- ConsultedGovernance / RMF / ISSOTranslating cycle outputs into FISMA and RMF artifacts, and owning the rules of engagement.
- InformedCyber Threat Intelligence cellFrame, Map and Fuse. The intelligence requirements, the threat courses of action, and the confidence levels.
- InformedHunt teamCounterattack. Works the hypotheses that Fuse raises.