ASOM-Fedv6.1Open the explorer
ID-3 · Identity Terrain

Authentication Assurance

Control Statement

Users, services and devices shall be authenticated at an assurance level commensurate with the terrain being accessed, and the assurance achieved shall be recorded with the authorization decision.

Purpose. To ensure authentication strength varies with what is being reached, and that the level achieved is available to the decision that relies on it.

Discussion

M3 Envelopment's stated indicator is that a stolen credential alone yields no movement, and this is the control that makes it assessable. The requirement that assurance be *recorded with the decision* is the part usually missing: an estate can enforce strong authentication at the front door and then issue a session that every downstream service accepts without knowing how it was obtained. Carrying the assurance level into the authorization decision is what allows a service holding decisive-point data to refuse a session that was established weakly, which is the difference between authenticating once and authenticating appropriately.

Goals and Metrics

A metric that cannot come out badly is not a metric. Each of these is capable of reporting that the control is not working.

Authentication strength varies with the terrain being reached.
  • Result of captured-credential testing against decisive-point terrain
  • Number of terrain layers with no stated assurance requirement
The assurance actually achieved is available to the decision that relies on it.
  • Percentage of authorization decisions with assurance level available
  • Size and age of the authentication bypass register

Accountability

Exactly one role is accountable, and every other role carries at least Informed — no control in the published catalog leaves a role with zero relationship to it. That is a stated property of how these were authored, not a coincidence, and not a claim that every role's work is worth equal attention here.

AOCTISOCHUNTPLATISSO
Authorizing Official / CISO: AccountableCyber Threat Intelligence cell: InformedSOC / Defensive Operations: ConsultedHunt team: ConsultedPlatform and product owners: ResponsibleGovernance / RMF / ISSO: Informed

AO Authorizing Official / CISOCTI Cyber Threat Intelligence cellSOC SOC / Defensive OperationsHUNT Hunt teamPLAT Platform and product ownersISSO Governance / RMF / ISSO

  • AccountableAuthorizing Official / CISO
  • InformedCyber Threat Intelligence cell
  • ConsultedSOC / Defensive Operations
  • ConsultedHunt team
  • ResponsiblePlatform and product owners
  • InformedGovernance / RMF / ISSO

Inputs and Outputs

Consumes

Produces

Activities

  1. L2Authenticate users, services and devices before granting access.
  2. L2Define the assurance level required per terrain layer or access tier.
  3. L2Record the assurance level achieved at authentication.
  4. L3Carry the achieved assurance level into the authorization decision, so a service can refuse a session established below its requirement.
  5. L3Require step-up authentication on transition to higher-assurance terrain rather than only at session establishment.
  6. L3Apply device assurance as an input where the terrain warrants it, so authentication is not credential-only.
  7. L3Record and time-bound every path that bypasses the assurance requirement, including legacy protocols that cannot carry it.
  8. L4Measure the proportion of authorization decisions made with assurance level available, since a decision made without it is made blind.
  9. L4Test resistance directly: attempt authentication with a captured credential and confirm it yields no usable session for decisive-point terrain.
  10. L5Retire bypass paths and legacy protocols rather than compensating for them, since each is a standing exception to the form's own indicator.

Measurement

Outcome

Result of captured-credential testing against decisive-point terrain.

Performance

Percentage of authorization decisions with assurance level available.

Evidence and Assessment

Evidence expected

Assurance requirements per terrain; achieved-assurance records; bypass register; credential resistance test results.

Assessment procedure

Examine the assurance standard against terrain classification; test that a captured credential yields no usable session for decisive-point terrain; examine the bypass register for expiry.

Related Guidance

Inherits
  • IA-2
  • IA-2(1)
  • IA-3
Satisfies
  • PR.AA-03
  • PR.AA-05

Position in the Chain

Derived from the other controls’ own declarations, so the two directions cannot disagree.

Where This Control Is Used

Derived, in every case, from the declaration at the other end: the forms whose techniques name this control, the artifacts whose producing and consuming controls include it, the layers whose control lists name it, and the roles its own accountability chart puts to work. Nothing here is authored on this page, so the sheet cannot claim an edge the other end does not.

Forms of Maneuver It Assesses

  • M3EnvelopmentMake identity, not network location, the decisive plane — surround the adversary with policy.3 of 20 techniques — M3.01, M3.09, M3.17
  • M6DelayBuy decision time and prevent the adversary culminating on the objective.1 of 10 techniques — M6.02

Terrain It Is Named On

  • T1IdentityVaries authentication assurance with the terrain being reached, and makes the level achieved available to the decision that relies on it.

Artifacts It Stands On

  • consumesCyber Terrain OverlayThe positional map of the estate: every element with a defensive layer, a defensive weight, a named accountable owner and its adjacencies. Not an asset inventory — an inventory enumerates, an overlay positions.
  • consumesDecisive point registerThe elements whose control confers decisive advantage — each carrying the evidence that raised it above merely important, and the protection floor it owes as a result.

Roles It Puts to Work