Control Statement
The organization shall identify and designate the elements whose compromise would unhinge the wider defense, and shall justify each designation.
Purpose. To concentrate defensive effort on the small number of elements whose loss is decisive, so that priority is a stated judgment rather than an emergent property of the asset register.
Discussion
A decisive point is not the same as a high-weight asset. Weight measures consequence of loss; decisiveness measures whether losing it collapses everything else. An identity policy decision point may carry moderate weight and still be decisive, because holding it confers control of movement everywhere. The justification requirement exists because the designation is a judgment, and an unjustified judgment cannot be argued with or inherited by a successor.
Goals and Metrics
A metric that cannot come out badly is not a metric. Each of these is capable of reporting that the control is not working.
- Number of designated decisive points and the recorded justification for each
- Proportion of total defensive weight concentrated in designated decisive points
- Ratio of decisive points to total elements — a designation covering most of the estate has designated nothing
Accountability
Exactly one role is accountable, and every other role carries at least Informed — no control in the published catalog leaves a role with zero relationship to it. That is a stated property of how these were authored, not a coincidence, and not a claim that every role's work is worth equal attention here.
| AO | CTI | SOC | HUNT | PLAT | ISSO |
|---|---|---|---|---|---|
| Authorizing Official / CISO: Accountable | Cyber Threat Intelligence cell: Responsible | SOC / Defensive Operations: Consulted | Hunt team: Informed | Platform and product owners: Consulted | Governance / RMF / ISSO: Informed |
AO Authorizing Official / CISOCTI Cyber Threat Intelligence cellSOC SOC / Defensive OperationsHUNT Hunt teamPLAT Platform and product ownersISSO Governance / RMF / ISSO
- AccountableAuthorizing Official / CISO
- ResponsibleCyber Threat Intelligence cell
- ConsultedSOC / Defensive Operations
- InformedHunt team
- ConsultedPlatform and product owners
- InformedGovernance / RMF / ISSO
Inputs and Outputs
Consumes
- TM-1 Terrain Inventory and OverlayCandidate elements and their position
- TM-3 Asset WeightingDefensive weight supporting the designation
- CG-1 Defensive IntentDefensive intent identifying what the campaign exists to protect
- FO-1 Privacy Terrain IdentificationCandidate decisive points among privacy holdings
- ID-1 Identity Plane DefinitionIdentity planes as candidates for decisive-point designation
Produces
- KT-2 Decisive Point Protection FloorDesignated points requiring a protection floor
- KT-3 Avenue of Approach AnalysisTargets whose approach routes must be enumerated
- KT-4 Adversary Reachability AssessmentTargets for the reachability assessment
- SM-4 Main Effort DesignationCandidates for main-effort designation
- SM-7 Deception EmplacementDecisive points whose approaches are seeded first
- RC-3 Trusted Rebuild PathDesignated decisive points requiring a rebuild path
- WF-1 Workforce Terrain IdentificationDecisive points whose operators constitute high-consequence roles
- FC-2 Physical Zone BoundaryDecisive points requiring physical location
- LC-3 Supplier Access ConstraintDecisive points to which standing access is prohibited
- ID-2 Credential Strength and BindingDecisive points, which set the strength the credential must meet
- ID-3 Authentication AssuranceDecisive points requiring the highest assurance
- DV-2 Device Posture as an Access PreconditionDecisive points setting the strictest posture requirement
- DV-4 Execution ControlDecisive points where enforcement is mandatory
Activities
- L2Identify candidate decisive points from the terrain overlay, considering elements that control movement, control authorization, or control recovery.
- L2Designate each decisive point on the overlay so it is visually distinct from surrounding terrain.
- L2Record a justification for each designation stating what its compromise would unhinge.
- L3Define the designation criteria in advance and derive them from the defensive intent (CG-1), so a candidate is tested against stated purpose rather than assessed on instinct.
- L3Record, for each high-weight element *not* designated, why it was excluded — the exclusions carry as much information as the designations.
- L3Obtain the accountable authority's approval of the designated set as a whole, not element by element.
- L3Re-run designation on material architectural change and at defined cadence.
- L4Measure the concentration of defensive weight held by the designated set and set a threshold above which the set is too large to be meaningful.
- L4Test designations against incident and exercise evidence: an element whose compromise did *not* unhinge the defense is a designation to revisit.
- L5Re-derive the designation criteria from observed engagements, so what counts as decisive is learned from contact rather than assumed at the outset.
Measurement
Share of total defensive weight held by the designated set.
Percentage of designations carrying a recorded, current justification.
Evidence and Assessment
Key Terrain section of the Brief with justification per element; exclusion record; approval record.
Examine designations and justifications; interview the CISO on why non-designated high-weight assets were excluded; test whether the designated set has grown beyond the stated threshold.
Related Guidance
- RA-9
- CP-2(8)
- PM-11
- ID.AM-05
- ID.RA-04
Position in the Chain
Derived from the other controls’ own declarations, so the two directions cannot disagree.
Fed By
Feeds
- KT-2 Decisive Point Protection Floor
- KT-3 Avenue of Approach Analysis
- SM-4 Main Effort Designation
- SM-7 Deception Emplacement
- RC-3 Trusted Rebuild Path
- WF-1 Workforce Terrain Identification
- FC-2 Physical Zone Boundary
- LC-3 Supplier Access Constraint
- ID-2 Credential Strength and Binding
- ID-3 Authentication Assurance
- DV-2 Device Posture as an Access Precondition
- DV-4 Execution Control
Where This Control Is Used
Derived, in every case, from the declaration at the other end: the forms whose techniques name this control, the artifacts whose producing and consuming controls include it, the layers whose control lists name it, and the roles its own accountability chart puts to work. Nothing here is authored on this page, so the sheet cannot claim an edge the other end does not.
Forms of Maneuver It Assesses
- M3EnvelopmentMake identity, not network location, the decisive plane — surround the adversary with policy.2 of 20 techniques — M3.02, M3.18
- M2Defense in DepthEnsure no single failure is decisive.1 of 18 techniques — M2.03
- M7CounterattackSeize the initiative and evict before the adversary reaches the objective.1 of 17 techniques — M7.06
- M11ReconstitutionRestore the mission on evidence, not on hope — and prove it before you need it.1 of 11 techniques — M11.04
Terrain It Is Named On
Applies to all ten layersIdentifies the decisive point on this layer rather than accepting the one this page names by default.
Artifacts It Stands On
- producesDecisive point registerThe elements whose control confers decisive advantage — each carrying the evidence that raised it above merely important, and the protection floor it owes as a result.
- consumesDefensive intent paragraphOne signed paragraph stating what the defense exists to protect, what may be degraded to protect it, and the acceptable risk. The commander’s-intent analog, and the citation every downstream designation rests on.
- consumesCyber Terrain OverlayThe positional map of the estate: every element with a defensive layer, a defensive weight, a named accountable owner and its adjacencies. Not an asset inventory — an inventory enumerates, an overlay positions.
- consumesBill of DefensePer mission service: the maneuvers and assets protecting it, its rolled-up coverage, and its residual risk. The view that lets a mission owner see their own defense rather than the enterprise average.
Roles It Puts to Work
- AccountableAuthorizing Official / CISOIntent, risk acceptance, and the scheme itself.
- ResponsibleCyber Threat Intelligence cellFrame, Map and Fuse. The intelligence requirements, the threat courses of action, and the confidence levels.
- ConsultedSOC / Defensive OperationsManeuver. Executes fires and emplaces obstacles inside the standing rules of engagement.
- ConsultedPlatform and product ownersTheir own terrain. Obstacles get emplaced on their ground, so they site them.
- InformedHunt teamCounterattack. Works the hypotheses that Fuse raises.
- InformedGovernance / RMF / ISSOTranslating cycle outputs into FISMA and RMF artifacts, and owning the rules of engagement.