Control Statement
For every element hosted in a shared or authorized service, the overlay shall record which controls are inherited from the provider and which remain the organization's responsibility.
Purpose. To ensure that the customer half of a shared responsibility model is owned by someone, so that inherited controls do not become nobody's job.
Discussion
The customer responsibility matrix is the most reliably unread document in federal cloud adoption. The provider states that a control is the customer's responsibility; the customer assumes that a FedRAMP-authorized service handles it; and the control is implemented by neither while appearing satisfied to both. That gap is invisible on any inventory and visible on this overlay, because an unassigned customer responsibility appears as an element with an inheritance claim and no owner. This control and CG-5 are the same discipline applied at different scopes — CG-5 verifies inheritance from a control baseline, FO-3 verifies it from a service provider.
Goals and Metrics
A metric that cannot come out badly is not a metric. Each of these is capable of reporting that the control is not working.
- Percentage of hosted elements with a recorded inheritance split
- Number of controls assumed inherited but not evidenced by the provider
Accountability
Exactly one role is accountable, and every other role carries at least Informed — no control in the published catalog leaves a role with zero relationship to it. That is a stated property of how these were authored, not a coincidence, and not a claim that every role's work is worth equal attention here.
| AO | CTI | SOC | HUNT | PLAT | ISSO |
|---|---|---|---|---|---|
| Authorizing Official / CISO: Accountable | Cyber Threat Intelligence cell: Informed | SOC / Defensive Operations: Consulted | Hunt team: Informed | Platform and product owners: Consulted | Governance / RMF / ISSO: Responsible |
AO Authorizing Official / CISOCTI Cyber Threat Intelligence cellSOC SOC / Defensive OperationsHUNT Hunt teamPLAT Platform and product ownersISSO Governance / RMF / ISSO
- AccountableAuthorizing Official / CISO
- InformedCyber Threat Intelligence cell
- ConsultedSOC / Defensive Operations
- InformedHunt team
- ConsultedPlatform and product owners
- ResponsibleGovernance / RMF / ISSO
Inputs and Outputs
Consumes
- TM-1 Terrain Inventory and OverlayHosted elements on the overlay
- Outside the frameworkProvider authorization packages and responsibility matrices
Produces
- CG-5 Control Inheritance MappingInheritance feeding the control baseline mapping
- CE-4 Coverage and Residual Risk ComputationInherited mitigation counted correctly in coverage
Activities
- L2Record the hosting provider for every element in a shared or authorized service.
- L2Record which controls are inherited and which remain the organization's responsibility.
- L2Report unassigned customer responsibilities as gaps.
- L3Derive the split from the provider's authorization package and customer responsibility matrix rather than from assumption.
- L3Assign an owner and an implementing maneuver to each customer responsibility, reconciled against terrain ownership (TM-7).
- L3Re-verify the split when the provider changes its offering, its authorization status, or its responsibility matrix.
- L3Record where a provider's authorization does not extend to the way the agency is actually using the service, since inheritance does not apply outside the authorized scope.
- L4Measure the proportion of customer responsibilities carrying both an owner and an operational move, since an owned but unimplemented responsibility is a gap that reports as assigned.
- L4Trend the count of unassigned responsibilities across cycles.
- L5Feed recurring inheritance gaps into acquisition, so that the responsibility split is evaluated before a service is adopted rather than after.
Measurement
Percentage of customer responsibilities with an owner and an operational move.
Currency of the inheritance record against the provider's current responsibility matrix.
Evidence and Assessment
Inheritance record per hosted element; customer responsibility matrix reconciled to assigned maneuvers; scope exceptions recorded.
Examine the inheritance record against the provider's authorization package; test that each customer responsibility has an owner and an assigned move; test whether agency usage falls within the authorized scope.
Related Guidance
- SA-9
- SC-7(21)
- PM-10
- GV.SC-07
- ID.AM-04
Where This Control Is Used
Derived, in every case, from the declaration at the other end: the forms whose techniques name this control, the artifacts whose producing and consuming controls include it, the layers whose control lists name it, and the roles its own accountability chart puts to work. Nothing here is authored on this page, so the sheet cannot claim an edge the other end does not.
Forms of Maneuver It Assesses
- M1Screen / GuardGain early warning and buy reaction time before the adversary touches key terrain.1 of 15 techniques — M1.02
Terrain It Is Named On
- T5DataMost of this layer now sits in shared tenancy, so which protections are inherited from the provider and which are the agency’s own has to be stated before coverage means anything.
Artifacts It Stands On
- producesTenancy and inheritance boundary recordWhat is inherited from a provider and what remains the agency’s, drawn from provider authorization packages and responsibility matrices, so inherited mitigation is counted once and correctly.
- consumesCyber Terrain OverlayThe positional map of the estate: every element with a defensive layer, a defensive weight, a named accountable owner and its adjacencies. Not an asset inventory — an inventory enumerates, an overlay positions.
Roles It Puts to Work
- AccountableAuthorizing Official / CISOIntent, risk acceptance, and the scheme itself.
- ResponsibleGovernance / RMF / ISSOTranslating cycle outputs into FISMA and RMF artifacts, and owning the rules of engagement.
- ConsultedSOC / Defensive OperationsManeuver. Executes fires and emplaces obstacles inside the standing rules of engagement.
- ConsultedPlatform and product ownersTheir own terrain. Obstacles get emplaced on their ground, so they site them.
- InformedCyber Threat Intelligence cellFrame, Map and Fuse. The intelligence requirements, the threat courses of action, and the confidence levels.
- InformedHunt teamCounterattack. Works the hypotheses that Fuse raises.