Control Statement
Where statute, regulation, or an authorizing instrument sets a deadline the mission must meet, the affected services shall be identified and their recovery objectives shall be set no weaker than that deadline requires.
Purpose. To identify the point at which a defensive action becomes a legal one, so that degradation decisions are bounded before they are needed.
Discussion
This is the control that tells the SOC when it must *not* degrade. Isolation and retrograde under M8 trade availability for containment, and that trade is ordinarily the accountable authority's to make — except where a statute sets a deadline the agency must meet, at which point the trade has a legal boundary that no security judgment overrides. Recording the floors in advance is what allows that boundary to be respected at three in the morning by someone who is not a lawyer, and it is why FO-5 feeds directly into the rules of engagement under CG-3.
Goals and Metrics
A metric that cannot come out badly is not a metric. Each of these is capable of reporting that the control is not working.
- Number of services with a statutory deadline identified
- Number of recovery objectives weaker than the deadline they must satisfy
Accountability
Exactly one role is accountable, and every other role carries at least Informed — no control in the published catalog leaves a role with zero relationship to it. That is a stated property of how these were authored, not a coincidence, and not a claim that every role's work is worth equal attention here.
| AO | CTI | SOC | HUNT | PLAT | ISSO |
|---|---|---|---|---|---|
| Authorizing Official / CISO: Accountable | Cyber Threat Intelligence cell: Informed | SOC / Defensive Operations: Consulted | Hunt team: Informed | Platform and product owners: Consulted | Governance / RMF / ISSO: Responsible |
AO Authorizing Official / CISOCTI Cyber Threat Intelligence cellSOC SOC / Defensive OperationsHUNT Hunt teamPLAT Platform and product ownersISSO Governance / RMF / ISSO
- AccountableAuthorizing Official / CISO
- InformedCyber Threat Intelligence cell
- ConsultedSOC / Defensive Operations
- InformedHunt team
- ConsultedPlatform and product owners
- ResponsibleGovernance / RMF / ISSO
Inputs and Outputs
Consumes
- Outside the frameworkStatute, regulation and authorizing instruments setting mission deadlines
- TM-1 Terrain Inventory and OverlayMission services on the overlay
Produces
- RC-1 Recovery ObjectivesFloor constraining recovery objectives
- CG-3 Rules of EngagementAvailability constraints bounding what may be degraded under contact
- TA-4 Pre-authorized ResponseLimits on pre-authorized actions that degrade a statutory service
- FO-7 Obligation Profile DeclarationStatutory availability floors that must appear in the profile
- LC-5 Supplier Severance CapabilityStatutory availability floor that must survive severance
Activities
- L2Identify services subject to a statutory, regulatory or instrument-set deadline.
- L2Record the governing instrument and its deadline against each.
- L2Raise a finding where a recovery objective is weaker than its floor.
- L3Obtain legal confirmation of each floor rather than deriving it from operational understanding.
- L3Set recovery objectives (RC-1) no weaker than the floor requires, accounting for the dependency chain rather than the service alone.
- L3Carry the floors into the rules of engagement (CG-3) and the pre-authorized response set (TA-4), so an operator knows which degradations are unavailable.
- L3Record seasonal or cyclical floors distinctly, since many federal deadlines bind only in defined periods and the constraint differs by date.
- L4Test operator awareness of the floors applying during the current period.
- L4Measure the interval between a change in governing instrument and its reflection in the register and the rules of engagement.
- L5Use the floors to argue for resilience investment, since a statutory deadline is the one availability requirement that does not need to be justified on risk terms.
Measurement
Percentage of affected services whose recovery objective satisfies its statutory floor.
Operator awareness of currently binding floors, tested.
Evidence and Assessment
Statutory availability register: service, instrument, deadline, resulting recovery objective; legal confirmation records.
Examine the register against the authorizing instruments; test that each affected service's recovery objective satisfies its floor; test operator awareness of currently binding floors.
Related Guidance
- CP-2(8)
- SC-5
- PM-11
- GV.OC-04
- RC.RP-01
Position in the Chain
Derived from the other controls’ own declarations, so the two directions cannot disagree.
Fed By
Nothing upstream — this control starts a chain.
Where This Control Is Used
Derived, in every case, from the declaration at the other end: the forms whose techniques name this control, the artifacts whose producing and consuming controls include it, the layers whose control lists name it, and the roles its own accountability chart puts to work. Nothing here is authored on this page, so the sheet cannot claim an edge the other end does not.
Forms of Maneuver It Assesses
- M11ReconstitutionRestore the mission on evidence, not on hope — and prove it before you need it.2 of 11 techniques — M11.01, M11.06
Terrain It Is Named On
- T3NetworksEgress and segmentation changes are the actions most likely to breach the statutory availability floor, so the floor has to be known before the action is authorized.
- T4Applications and WorkloadsThe statutory availability floor is carried by specific applications; naming them is what stops a containment action from breaching a filing deadline.
- T6Operational TechnologyWhere OT carries a mission process, the statutory availability floor constrains what may be done to defend it.
Artifacts It Stands On
- producesStatutory availability floorThe mission services whose availability is set by statute or regulation, and the floor below which degradation stops being a defensive choice. Bounds what may be pre-authorized and what may be degraded under contact.
- consumesCyber Terrain OverlayThe positional map of the estate: every element with a defensive layer, a defensive weight, a named accountable owner and its adjacencies. Not an asset inventory — an inventory enumerates, an overlay positions.
Roles It Puts to Work
- AccountableAuthorizing Official / CISOIntent, risk acceptance, and the scheme itself.
- ResponsibleGovernance / RMF / ISSOTranslating cycle outputs into FISMA and RMF artifacts, and owning the rules of engagement.
- ConsultedSOC / Defensive OperationsManeuver. Executes fires and emplaces obstacles inside the standing rules of engagement.
- ConsultedPlatform and product ownersTheir own terrain. Obstacles get emplaced on their ground, so they site them.
- InformedCyber Threat Intelligence cellFrame, Map and Fuse. The intelligence requirements, the threat courses of action, and the confidence levels.
- InformedHunt teamCounterattack. Works the hypotheses that Fuse raises.