Control Statement
Users, services and devices shall be authenticated at an assurance level commensurate with the terrain being accessed, and the assurance achieved shall be recorded with the authorization decision.
Purpose. To ensure authentication strength varies with what is being reached, and that the level achieved is available to the decision that relies on it.
Discussion
M3 Envelopment's stated indicator is that a stolen credential alone yields no movement, and this is the control that makes it assessable. The requirement that assurance be *recorded with the decision* is the part usually missing: an estate can enforce strong authentication at the front door and then issue a session that every downstream service accepts without knowing how it was obtained. Carrying the assurance level into the authorization decision is what allows a service holding decisive-point data to refuse a session that was established weakly, which is the difference between authenticating once and authenticating appropriately.
Goals and Metrics
A metric that cannot come out badly is not a metric. Each of these is capable of reporting that the control is not working.
- Result of captured-credential testing against decisive-point terrain
- Number of terrain layers with no stated assurance requirement
- Percentage of authorization decisions with assurance level available
- Size and age of the authentication bypass register
Accountability
Exactly one role is accountable, and every other role carries at least Informed — no control in the published catalog leaves a role with zero relationship to it. That is a stated property of how these were authored, not a coincidence, and not a claim that every role's work is worth equal attention here.
| AO | CTI | SOC | HUNT | PLAT | ISSO |
|---|---|---|---|---|---|
| Authorizing Official / CISO: Accountable | Cyber Threat Intelligence cell: Informed | SOC / Defensive Operations: Consulted | Hunt team: Consulted | Platform and product owners: Responsible | Governance / RMF / ISSO: Informed |
AO Authorizing Official / CISOCTI Cyber Threat Intelligence cellSOC SOC / Defensive OperationsHUNT Hunt teamPLAT Platform and product ownersISSO Governance / RMF / ISSO
- AccountableAuthorizing Official / CISO
- InformedCyber Threat Intelligence cell
- ConsultedSOC / Defensive Operations
- ConsultedHunt team
- ResponsiblePlatform and product owners
- InformedGovernance / RMF / ISSO
Inputs and Outputs
Consumes
- ID-1 Identity Plane DefinitionIdentity planes and their enforcement points
- ID-2 Credential Strength and BindingCredential binding, which bounds achievable assurance
- TM-2 Defensive Layer ClassificationTerrain classification that sets the required level
- KT-1 Decisive Point IdentificationDecisive points requiring the highest assurance
- DV-2 Device Posture as an Access PreconditionDevice posture as a component of achieved assurance
Produces
- ID-5 Authorization Decision IntegrityAchieved assurance, as an input to the authorization decision
- DV-2 Device Posture as an Access PreconditionAssurance requirement that device posture is evaluated alongside
- ID-4 Identity Assertion ProtectionAssurance records the assertion carries
- DV-1 Device Terrain IdentificationAuthentication records naming the devices that actually connect
Activities
- L2Authenticate users, services and devices before granting access.
- L2Define the assurance level required per terrain layer or access tier.
- L2Record the assurance level achieved at authentication.
- L3Carry the achieved assurance level into the authorization decision, so a service can refuse a session established below its requirement.
- L3Require step-up authentication on transition to higher-assurance terrain rather than only at session establishment.
- L3Apply device assurance as an input where the terrain warrants it, so authentication is not credential-only.
- L3Record and time-bound every path that bypasses the assurance requirement, including legacy protocols that cannot carry it.
- L4Measure the proportion of authorization decisions made with assurance level available, since a decision made without it is made blind.
- L4Test resistance directly: attempt authentication with a captured credential and confirm it yields no usable session for decisive-point terrain.
- L5Retire bypass paths and legacy protocols rather than compensating for them, since each is a standing exception to the form's own indicator.
Measurement
Result of captured-credential testing against decisive-point terrain.
Percentage of authorization decisions with assurance level available.
Evidence and Assessment
Assurance requirements per terrain; achieved-assurance records; bypass register; credential resistance test results.
Examine the assurance standard against terrain classification; test that a captured credential yields no usable session for decisive-point terrain; examine the bypass register for expiry.
Related Guidance
- IA-2
- IA-2(1)
- IA-3
- PR.AA-03
- PR.AA-05
Position in the Chain
Derived from the other controls’ own declarations, so the two directions cannot disagree.
Where This Control Is Used
Derived, in every case, from the declaration at the other end: the forms whose techniques name this control, the artifacts whose producing and consuming controls include it, the layers whose control lists name it, and the roles its own accountability chart puts to work. Nothing here is authored on this page, so the sheet cannot claim an edge the other end does not.
Forms of Maneuver It Assesses
- M3EnvelopmentMake identity, not network location, the decisive plane — surround the adversary with policy.3 of 20 techniques — M3.01, M3.09, M3.17
- M6DelayBuy decision time and prevent the adversary culminating on the objective.1 of 10 techniques — M6.02
Terrain It Is Named On
- T1IdentityVaries authentication assurance with the terrain being reached, and makes the level achieved available to the decision that relies on it.
Artifacts It Stands On
- consumesCyber Terrain OverlayThe positional map of the estate: every element with a defensive layer, a defensive weight, a named accountable owner and its adjacencies. Not an asset inventory — an inventory enumerates, an overlay positions.
- consumesDecisive point registerThe elements whose control confers decisive advantage — each carrying the evidence that raised it above merely important, and the protection floor it owes as a result.
Roles It Puts to Work
- AccountableAuthorizing Official / CISOIntent, risk acceptance, and the scheme itself.
- ResponsiblePlatform and product ownersTheir own terrain. Obstacles get emplaced on their ground, so they site them.
- ConsultedSOC / Defensive OperationsManeuver. Executes fires and emplaces obstacles inside the standing rules of engagement.
- ConsultedHunt teamCounterattack. Works the hypotheses that Fuse raises.
- InformedCyber Threat Intelligence cellFrame, Map and Fuse. The intelligence requirements, the threat courses of action, and the confidence levels.
- InformedGovernance / RMF / ISSOTranslating cycle outputs into FISMA and RMF artifacts, and owning the rules of engagement.