Control Statement
Operational technology, industrial control, and physical-effect systems shall be represented on the terrain overlay as a distinct defensive layer, with their connections to enterprise terrain declared.
Purpose. To stop operational technology being scored as though it were a server estate, and to make the connections between the two declarable.
Discussion
Operational technology is ground you cannot maneuver freely on. Systems that cannot be patched or restarted on the defender's schedule remove whole classes of move from availability, and the consequence of loss is physical rather than informational. Scoring OT against enterprise expectations produces findings the agency cannot action and obscures the ones it can. The connections are where the real risk sits: engineering workstations, vendor remote access, historian replication and shared identity are the paths by which enterprise compromise becomes physical consequence, and they are routinely absent from network diagrams that show an air gap.
Goals and Metrics
A metric that cannot come out badly is not a metric. Each of these is capable of reporting that the control is not working.
- Percentage of operational technology represented on the overlay
- Number of undeclared connections between operational technology and enterprise terrain
Accountability
Exactly one role is accountable, and every other role carries at least Informed — no control in the published catalog leaves a role with zero relationship to it. That is a stated property of how these were authored, not a coincidence, and not a claim that every role's work is worth equal attention here.
| AO | CTI | SOC | HUNT | PLAT | ISSO |
|---|---|---|---|---|---|
| Authorizing Official / CISO: Accountable | Cyber Threat Intelligence cell: Informed | SOC / Defensive Operations: Consulted | Hunt team: Informed | Platform and product owners: Responsible | Governance / RMF / ISSO: Consulted |
AO Authorizing Official / CISOCTI Cyber Threat Intelligence cellSOC SOC / Defensive OperationsHUNT Hunt teamPLAT Platform and product ownersISSO Governance / RMF / ISSO
- AccountableAuthorizing Official / CISO
- InformedCyber Threat Intelligence cell
- ConsultedSOC / Defensive Operations
- InformedHunt team
- ResponsiblePlatform and product owners
- ConsultedGovernance / RMF / ISSO
Inputs and Outputs
Consumes
- TM-1 Terrain Inventory and OverlayTerrain overlay
- Outside the frameworkEngineering and facilities system inventories
Produces
- TM-2 Defensive Layer ClassificationDistinct defensive layer for aggregation
- FC-1 Facility Terrain IdentificationFacility association for physical terrain
- KT-3 Avenue of Approach AnalysisEnterprise-to-operational crossings as avenues of approach
Activities
- L2Classify operational technology, industrial control and physical-effect systems to the OT terrain layer.
- L2Declare every connection between OT elements and enterprise zones.
- L2Highlight cross-layer connections on the overlay.
- L3Reconcile the OT layer against the operational inventory held by the engineering or facilities function, not against the IT asset inventory.
- L3Enumerate connections exhaustively, including engineering workstations, vendor remote access, historian and data-diode paths, and shared identity — the paths most often omitted from a claimed air gap.
- L3Record for each OT element which defensive moves are unavailable and why — patching windows, restart constraints, vendor certification, safety interlocks — so coverage is scored against what is achievable.
- L3Record the physical consequence of loss, so weighting under TM-3 reflects consequence rather than data value.
- L4Test declared connections against observed traffic, since an undeclared path into OT is the finding that matters most in this layer.
- L4Measure the proportion of OT elements whose unavailable-move set has been recorded, since an unrecorded constraint reads as an unremediated gap.
- L5Work with engineering and vendors to remove constraints that force moves to be unavailable, rather than accepting the constraint set as fixed.
Measurement
Percentage of OT elements with declared connections and recorded constraints.
Number of observed OT connections that were undeclared.
Evidence and Assessment
Terrain overlay showing the OT layer and its declared connections; constraint record per element; reconciliation against the operational inventory.
Examine the layer against the operational inventory; test the declared connections for completeness, including engineering workstations and remote access paths; test declared connections against observed traffic.
Related Guidance
- PM-5
- SC-7(21)
- SI-4(20)
- ID.AM-01
- PR.IR-01
Position in the Chain
Derived from the other controls’ own declarations, so the two directions cannot disagree.
Fed By
Nothing upstream — this control starts a chain.
Where This Control Is Used
Derived, in every case, from the declaration at the other end: the forms whose techniques name this control, the artifacts whose producing and consuming controls include it, the layers whose control lists name it, and the roles its own accountability chart puts to work. Nothing here is authored on this page, so the sheet cannot claim an edge the other end does not.
Forms of Maneuver It Assesses
- M4Obstacle / CanalizationForce the adversary onto ground you own and watch.2 of 17 techniques — M4.13, M4.14
- M1Screen / GuardGain early warning and buy reaction time before the adversary touches key terrain.1 of 15 techniques — M1.11
- M2Defense in DepthEnsure no single failure is decisive.1 of 18 techniques — M2.15
- M5AmbushTrade space for information and time, and impose cost.1 of 13 techniques — M5.11
- M7CounterattackSeize the initiative and evict before the adversary reaches the objective.1 of 17 techniques — M7.14
- M8Isolation / RetrogradeGive ground deliberately to preserve the force. Degrade gracefully; never fail open.1 of 17 techniques — M8.13
Terrain It Is Named On
- T6Operational TechnologyThe control that requires operational technology to be identified and treated as terrain in the first place. T6 is its scoring surface.
Artifacts It Stands On
- producesOperational technology terrain registerEngineering and facilities systems as their own defensive layer, with the enterprise-to-operational crossings enumerated as avenues of approach.
- consumesCyber Terrain OverlayThe positional map of the estate: every element with a defensive layer, a defensive weight, a named accountable owner and its adjacencies. Not an asset inventory — an inventory enumerates, an overlay positions.
Roles It Puts to Work
- AccountableAuthorizing Official / CISOIntent, risk acceptance, and the scheme itself.
- ResponsiblePlatform and product ownersTheir own terrain. Obstacles get emplaced on their ground, so they site them.
- ConsultedSOC / Defensive OperationsManeuver. Executes fires and emplaces obstacles inside the standing rules of engagement.
- ConsultedGovernance / RMF / ISSOTranslating cycle outputs into FISMA and RMF artifacts, and owning the rules of engagement.
- InformedCyber Threat Intelligence cellFrame, Map and Fuse. The intelligence requirements, the threat courses of action, and the confidence levels.
- InformedHunt teamCounterattack. Works the hypotheses that Fuse raises.