Control Statement
Identity assertions, tokens and session material shall be protected against interception, replay and forgery, and their validity shall be bounded in time and scope.
Purpose. To prevent a valid authentication from becoming a durable, portable credential in an adversary's hands.
Discussion
Strong authentication is routinely defeated downstream rather than at the point of authentication: the token issued after a phishing-resistant login is frequently a bearer credential with a long lifetime, broad scope and no binding to the device that obtained it. An adversary who takes it inherits the assurance without the credential. Signing key protection is the same problem one level up — an adversary holding the issuing key can forge assertions at any assurance level and will not appear in authentication logs at all.
Goals and Metrics
A metric that cannot come out badly is not a metric. Each of these is capable of reporting that the control is not working.
- Assertion lifetime distribution against requirement, tail-weighted
- Number of assertions issued without scope binding
- Measured time to effect for estate-wide session revocation
- Date of the most recent revocation test, against its required interval
Accountability
Exactly one role is accountable, and every other role carries at least Informed — no control in the published catalog leaves a role with zero relationship to it. That is a stated property of how these were authored, not a coincidence, and not a claim that every role's work is worth equal attention here.
| AO | CTI | SOC | HUNT | PLAT | ISSO |
|---|---|---|---|---|---|
| Authorizing Official / CISO: Accountable | Cyber Threat Intelligence cell: Informed | SOC / Defensive Operations: Consulted | Hunt team: Consulted | Platform and product owners: Responsible | Governance / RMF / ISSO: Informed |
AO Authorizing Official / CISOCTI Cyber Threat Intelligence cellSOC SOC / Defensive OperationsHUNT Hunt teamPLAT Platform and product ownersISSO Governance / RMF / ISSO
- AccountableAuthorizing Official / CISO
- InformedCyber Threat Intelligence cell
- ConsultedSOC / Defensive Operations
- ConsultedHunt team
- ResponsiblePlatform and product owners
- InformedGovernance / RMF / ISSO
Inputs and Outputs
Consumes
- ID-1 Identity Plane DefinitionIdentity planes and the enforcement points that honor revocation
- ID-3 Authentication AssuranceAssurance records the assertion carries
- CG-2 Phase DeclarationCampaign phase, which can shorten required lifetimes
Produces
- TA-1 Decision Loop MeasurementRevocation time as the containment segment of the decision loop
- EN-5 Eradication and Transition to RecoveryIdentity-plane revocation, without which eradication cannot be claimed
Activities
- L2Protect assertions and tokens in transit and at rest.
- L2Bound assertion validity in time.
- L2Bound assertion scope to the access required.
- L3Bind assertions to the device or client that obtained them where the platform permits, so a stolen token is not portable.
- L3Protect assertion signing keys at a level commensurate with the access forgeable assertions would confer, and record where they are held.
- L3Key assertion lifetime to campaign phase (
CG-2), so a declared Phase III shortens session lifetimes without a change request. - L3Provide estate-wide session revocation and verify it reaches every consuming service, not only the issuing plane.
- L4Measure assertion lifetime distribution against the requirement per terrain, and trend the tail rather than the median.
- L4Test estate-wide revocation end to end and measure elapsed time to effect across consuming services.
- L5Move toward continuous evaluation, so authorization is re-decided during a session rather than settled at its start.
Measurement
Measured time to effect for estate-wide session revocation.
Assertion lifetime distribution against requirement, tail-weighted.
Evidence and Assessment
Assertion protection configuration; lifetime and scope records; signing key protection record; revocation test results.
Examine lifetime and scope against terrain requirements; test estate-wide revocation reaching consuming services; examine signing key protection against the access forgeable assertions would confer.
Related Guidance
- IA-5(2)
- SC-8
- SC-23
- PR.AA-04
- PR.DS-02
Position in the Chain
Derived from the other controls’ own declarations, so the two directions cannot disagree.
Fed By
Nothing upstream — this control starts a chain.
Where This Control Is Used
Derived, in every case, from the declaration at the other end: the forms whose techniques name this control, the artifacts whose producing and consuming controls include it, the layers whose control lists name it, and the roles its own accountability chart puts to work. Nothing here is authored on this page, so the sheet cannot claim an edge the other end does not.
Forms of Maneuver It Assesses
- M3EnvelopmentMake identity, not network location, the decisive plane — surround the adversary with policy.2 of 20 techniques — M3.11, M3.16
- M6DelayBuy decision time and prevent the adversary culminating on the objective.1 of 10 techniques — M6.04
- M8Isolation / RetrogradeGive ground deliberately to preserve the force. Degrade gracefully; never fail open.1 of 17 techniques — M8.02
Terrain It Is Named On
- T1IdentityBounds how long an assertion is useful and how fast it can be withdrawn — the difference between a contained credential theft and an uncontained one.
Artifacts It Stands On
- consumesPhase declarationThe declared campaign phase and the scope it is declared against. Sets cadence, dominant forms of maneuver, and how wide the pre-authorization set runs.
Roles It Puts to Work
- AccountableAuthorizing Official / CISOIntent, risk acceptance, and the scheme itself.
- ResponsiblePlatform and product ownersTheir own terrain. Obstacles get emplaced on their ground, so they site them.
- ConsultedSOC / Defensive OperationsManeuver. Executes fires and emplaces obstacles inside the standing rules of engagement.
- ConsultedHunt teamCounterattack. Works the hypotheses that Fuse raises.
- InformedCyber Threat Intelligence cellFrame, Map and Fuse. The intelligence requirements, the threat courses of action, and the confidence levels.
- InformedGovernance / RMF / ISSOTranslating cycle outputs into FISMA and RMF artifacts, and owning the rules of engagement.