ASOM-Fedv6.1Open the explorer
KT · 5 controls

Key Terrain and Decisive Points

What must not be lost, and whether an adversary can reach it

KT-1
Decisive Point IdentificationAccountable: Authorizing Official / CISO

The organization shall identify and designate the elements whose compromise would unhinge the wider defense, and shall justify each designation.

PurposeTo concentrate defensive effort on the small number of elements whose loss is decisive, so that priority is a stated judgment rather than an emergent property of the asset register.Activities10 · Metrics3
KT-2
Decisive Point Protection FloorAccountable: Authorizing Official / CISO

Every designated decisive point shall have at least one defensive move assigned and operational, and shall meet a defined minimum effective coverage.

PurposeTo ensure designation produces protection, so that identifying a decisive point is an act with consequences rather than an annotation.Activities10 · Metrics2
KT-3
Avenue of Approach AnalysisAccountable: Authorizing Official / CISO

The routes by which an adversary could approach designated decisive points shall be enumerated and assessed.

PurposeTo convert the estate's connectivity into a set of named approach routes, so that defense can be emplaced on the routes that exist rather than distributed evenly across ground.Activities10 · Metrics2
KT-4
Adversary Reachability AssessmentAccountable: Authorizing Official / CISO

The organization shall determine, on permitted paths only, whether any threat actor position can reach any designated decisive point, and shall record the result each cycle.

PurposeTo produce a computed, repeatable answer to the question a control catalog cannot ask — can they get there from here — and to record the answer as a trend rather than a one-time finding.Activities10 · Metrics3
KT-5
Barrier SufficiencyAccountable: Authorizing Official / CISO

Where reachability is prevented by denied paths, those barriers shall be identified, enforced technically, and monitored for change.

PurposeTo make the barriers on which negative reachability results depend into named, owned, monitored controls, so that the assurance KT-4 provides cannot be silently withdrawn.Activities10 · Metrics3