Control Statement
The organization shall identify on the terrain overlay every authoritative identity plane, the policy decision and enforcement points it operates, and the trust relationships between planes.
Purpose. To make identity positional, so that the plane controlling movement everywhere else is itself defensible ground rather than an assumed service.
Discussion
Most estates have more than one identity plane and have never drawn the relationships between them: a primary provider, a legacy directory, a cloud tenant, one or more federated partners, and a set of local account stores that answer to nobody. Trust edges between planes are the highest-value terrain in the estate, because compromise of a low-assurance plane that a high-assurance plane trusts confers the higher assurance. That is the identity equivalent of an unmapped mobility corridor, and it is invisible on a network diagram.
Goals and Metrics
A metric that cannot come out badly is not a metric. Each of these is capable of reporting that the control is not working.
- Percentage of estate elements whose authorizing plane is recorded
- Number of elements reachable through a plane that is not on the overlay
- Count of identity planes and trust edges, trended
- Number of enforcement points discovered that were absent from the register
Accountability
Exactly one role is accountable, and every other role carries at least Informed — no control in the published catalog leaves a role with zero relationship to it. That is a stated property of how these were authored, not a coincidence, and not a claim that every role's work is worth equal attention here.
| AO | CTI | SOC | HUNT | PLAT | ISSO |
|---|---|---|---|---|---|
| Authorizing Official / CISO: Accountable | Cyber Threat Intelligence cell: Consulted | SOC / Defensive Operations: Consulted | Hunt team: Informed | Platform and product owners: Responsible | Governance / RMF / ISSO: Informed |
AO Authorizing Official / CISOCTI Cyber Threat Intelligence cellSOC SOC / Defensive OperationsHUNT Hunt teamPLAT Platform and product ownersISSO Governance / RMF / ISSO
- AccountableAuthorizing Official / CISO
- ConsultedCyber Threat Intelligence cell
- ConsultedSOC / Defensive Operations
- InformedHunt team
- ResponsiblePlatform and product owners
- InformedGovernance / RMF / ISSO
Inputs and Outputs
Consumes
- TM-1 Terrain Inventory and OverlayTerrain overlay the identity planes are drawn onto
- Outside the frameworkApplication authorization configuration
Produces
- KT-1 Decisive Point IdentificationIdentity planes as candidates for decisive-point designation
- KT-3 Avenue of Approach AnalysisTrust edges as avenues of approach
- ID-5 Authorization Decision IntegrityEnforcement point register the decision path is measured against
- DV-1 Device Terrain IdentificationAuthentication records used to discover devices reaching the estate
- ID-2 Credential Strength and BindingIdentity planes the credentials are bound within
- ID-3 Authentication AssuranceIdentity planes and their enforcement points
- ID-4 Identity Assertion ProtectionIdentity planes and the enforcement points that honor revocation
Activities
- L2Identify every authoritative identity plane serving the estate and place it on the overlay.
- L2Record the policy decision and enforcement points each plane operates.
- L2Record which elements depend on which plane for authorization.
- L3Enumerate trust relationships between planes — federation, synchronisation, directory trust, token exchange — and record their direction and assurance.
- L3Identify local and non-federated account stores as identity planes in their own right rather than as exceptions, since an unmapped store is an unmapped plane.
- L3Designate the primary plane and any plane whose compromise would confer control of it as decisive points under
KT-1. - L3Record for each enforcement point whether it is consulted on every authorization decision or only at session establishment.
- L4Trend the count of identity planes and trust edges; growth is terrain expansion that no asset inventory reports.
- L4Test that enforcement points are actually consulted, rather than accepting the architecture's claim that they are.
- L5Consolidate planes and retire trust edges where the estate permits, since reducing the terrain is more durable than defending more of it.
Measurement
Percentage of estate elements whose authorizing plane is recorded.
Count of identity planes and trust edges, trended.
Evidence and Assessment
Overlay showing identity planes, enforcement points and trust edges; plane dependency record.
Examine the overlay against directory and federation configuration; test for local or non-federated stores absent from the plane list; test whether a sampled enforcement point is consulted on authorization.
Related Guidance
- IA-8
- AC-3
- PM-5
- PR.AA-01
- ID.AM-01
Position in the Chain
Derived from the other controls’ own declarations, so the two directions cannot disagree.
Fed By
Nothing upstream — this control starts a chain.
Where This Control Is Used
Derived, in every case, from the declaration at the other end: the forms whose techniques name this control, the artifacts whose producing and consuming controls include it, the layers whose control lists name it, and the roles its own accountability chart puts to work. Nothing here is authored on this page, so the sheet cannot claim an edge the other end does not.
Forms of Maneuver It Assesses
- M3EnvelopmentMake identity, not network location, the decisive plane — surround the adversary with policy.3 of 20 techniques — M3.02, M3.13, M3.18
- M11ReconstitutionRestore the mission on evidence, not on hope — and prove it before you need it.1 of 11 techniques — M11.04
Terrain It Is Named On
- T1IdentityDraws the identity plane as ground: which planes exist, where their trust edges run, and which enforcement points stand on them. Every other control on this layer resolves against it.
Artifacts It Stands On
- consumesCyber Terrain OverlayThe positional map of the estate: every element with a defensive layer, a defensive weight, a named accountable owner and its adjacencies. Not an asset inventory — an inventory enumerates, an overlay positions.
Roles It Puts to Work
- AccountableAuthorizing Official / CISOIntent, risk acceptance, and the scheme itself.
- ResponsiblePlatform and product ownersTheir own terrain. Obstacles get emplaced on their ground, so they site them.
- ConsultedCyber Threat Intelligence cellFrame, Map and Fuse. The intelligence requirements, the threat courses of action, and the confidence levels.
- ConsultedSOC / Defensive OperationsManeuver. Executes fires and emplaces obstacles inside the standing rules of engagement.
- InformedHunt teamCounterattack. Works the hypotheses that Fuse raises.
- InformedGovernance / RMF / ISSOTranslating cycle outputs into FISMA and RMF artifacts, and owning the rules of engagement.