Control Statement
The routes by which an adversary could approach designated decisive points shall be enumerated and assessed.
Purpose. To convert the estate's connectivity into a set of named approach routes, so that defense can be emplaced on the routes that exist rather than distributed evenly across ground.
Discussion
An avenue of approach is a property of the architecture, not of any particular adversary, which is what makes it enumerable in advance. The assessment step matters more than the enumeration: a route with neither a barrier nor a compensating detection is an open approach, and knowing about it without acting is worse than not knowing, because it converts a gap into an accepted one without anyone accepting it.
Goals and Metrics
A metric that cannot come out badly is not a metric. Each of these is capable of reporting that the control is not working.
- Number of enumerated avenues of approach per decisive point
- Number of avenues with no defensive move sited on them
Accountability
Exactly one role is accountable, and every other role carries at least Informed — no control in the published catalog leaves a role with zero relationship to it. That is a stated property of how these were authored, not a coincidence, and not a claim that every role's work is worth equal attention here.
| AO | CTI | SOC | HUNT | PLAT | ISSO |
|---|---|---|---|---|---|
| Authorizing Official / CISO: Accountable | Cyber Threat Intelligence cell: Responsible | SOC / Defensive Operations: Informed | Hunt team: Consulted | Platform and product owners: Consulted | Governance / RMF / ISSO: Informed |
AO Authorizing Official / CISOCTI Cyber Threat Intelligence cellSOC SOC / Defensive OperationsHUNT Hunt teamPLAT Platform and product ownersISSO Governance / RMF / ISSO
- AccountableAuthorizing Official / CISO
- ResponsibleCyber Threat Intelligence cell
- InformedSOC / Defensive Operations
- ConsultedHunt team
- ConsultedPlatform and product owners
- InformedGovernance / RMF / ISSO
Inputs and Outputs
Consumes
- KT-1 Decisive Point IdentificationDecisive points to be approached
- TM-5 Connection and Denied-Path RegisterPermitted connections forming candidate routes
- TM-4 Trust Zone DefinitionZone boundaries a route must cross
- Outside the frameworkThreat intelligence on adversary tradecraft and observed campaign behavior
- TM-1 Terrain Inventory and OverlayPositional map used to enumerate avenues of approach
- FO-4 Operational Technology TerrainEnterprise-to-operational crossings as avenues of approach
- FO-6 Supply Chain ObligationSupplier paths as avenues of approach
- FC-2 Physical Zone BoundaryPhysical approach routes to decisive points
- FC-3 Maintenance Access ControlMaintenance access as an avenue of approach
- LC-1 Supplier Terrain RegisterSupplier paths as avenues of approach
- ID-1 Identity Plane DefinitionTrust edges as avenues of approach
- DV-1 Device Terrain IdentificationDevice crossings as avenues of approach
Produces
- KT-4 Adversary Reachability AssessmentRoute set for formal reachability assessment
- SM-2 Maneuver AssignmentRoutes requiring a maneuver to be sited on them
- CE-2 Priority Intelligence RequirementsIntelligence gaps arising from unassessed routes
- SM-5 Branches and SequelsAvenues of approach informing likely courses of action
- SM-7 Deception EmplacementAvenues of approach that determine where deception is worth placing
Activities
- L2Trace permitted paths from each external actor and each lower-trust zone to each designated decisive point.
- L2Record each distinct route as a named avenue with its origin, its path, and its terminus.
- L2Identify, for each avenue, whether a barrier or a detection currently covers it.
- L3Enumerate avenues systematically from the connection register rather than from analyst recall, so completeness is a property of the method.
- L3Include approach routes through workforce, facility and supplier terrain, not only network paths — three of the most-used federal intrusion paths are not network routes.
- L3Assess each avenue for whether its coverage is a barrier, a detection, or neither, and record the result distinctly.
- L3Raise a finding for every avenue with neither, with an owner and a date.
- L4Measure the count of uncovered avenues per decisive point and trend it.
- L4Test a sample of avenues by attempting traversal, rather than accepting the register's account of coverage.
- L5Update the enumeration method from routes observed in real engagements that the method had not predicted.
Measurement
Percentage of enumerated avenues carrying a barrier or a detection.
Percentage of avenues verified by traversal test rather than by record.
Evidence and Assessment
Adversary reach analysis; traced route figures; coverage classification per avenue.
Examine enumerated avenues; test that each has either a barrier or a compensating detection; test whether non-network approach routes were enumerated at all.
Related Guidance
- RA-3
- CA-8
- RA-5
- ID.RA-01
Position in the Chain
Derived from the other controls’ own declarations, so the two directions cannot disagree.
Fed By
- TM-1 Terrain Inventory and Overlay
- TM-4 Trust Zone Definition
- TM-5 Connection and Denied-Path Register
- KT-1 Decisive Point Identification
- FO-4 Operational Technology Terrain
- FO-6 Supply Chain Obligation
- FC-2 Physical Zone Boundary
- FC-3 Maintenance Access Control
- LC-1 Supplier Terrain Register
- ID-1 Identity Plane Definition
- DV-1 Device Terrain Identification
Where This Control Is Used
Derived, in every case, from the declaration at the other end: the forms whose techniques name this control, the artifacts whose producing and consuming controls include it, the layers whose control lists name it, and the roles its own accountability chart puts to work. Nothing here is authored on this page, so the sheet cannot claim an edge the other end does not.
Forms of Maneuver It Assesses
- M1Screen / GuardGain early warning and buy reaction time before the adversary touches key terrain.3 of 15 techniques — M1.01, M1.03, M1.04
- M5AmbushTrade space for information and time, and impose cost.1 of 13 techniques — M5.06
- M9Spoiling AttackDisrupt adversary staging before the attack is launched.1 of 9 techniques — M9.03
Terrain It Is Named On
- T2DevicesA compromised endpoint is the most common first avenue of approach in the reference profile; the avenue analysis is where that gets written down.
- T3NetworksAvenues of approach are drawn on this layer; almost every avenue in the reference profile is a network path plus an identity.
- T9Supply ChainA supplier route is an avenue of approach, and one that bypasses every perimeter the avenue analysis usually starts from.
Artifacts It Stands On
- producesAvenue-of-approach analysisThe enumerated routes an adversary could take toward each decisive point, including physical, supplier and maintenance routes, with unassessed routes recorded as intelligence gaps rather than as absence of risk.
- producesThreat course-of-action sketchTwo courses of action, most likely and most dangerous, drawn against the decisive points already designated. Each is a route across ground the estate really has, not a category of threat.
- consumesTrust zones and the connection registerThe zone boundaries and the permitted- and denied-path register — the graph reachability is actually walked over, reconciled against observed flow telemetry rather than against intended configuration.
- consumesDecisive point registerThe elements whose control confers decisive advantage — each carrying the evidence that raised it above merely important, and the protection floor it owes as a result.
Roles It Puts to Work
- AccountableAuthorizing Official / CISOIntent, risk acceptance, and the scheme itself.
- ResponsibleCyber Threat Intelligence cellFrame, Map and Fuse. The intelligence requirements, the threat courses of action, and the confidence levels.
- ConsultedHunt teamCounterattack. Works the hypotheses that Fuse raises.
- ConsultedPlatform and product ownersTheir own terrain. Obstacles get emplaced on their ground, so they site them.
- InformedSOC / Defensive OperationsManeuver. Executes fires and emplaces obstacles inside the standing rules of engagement.
- InformedGovernance / RMF / ISSOTranslating cycle outputs into FISMA and RMF artifacts, and owning the rules of engagement.