Control Statement
The organization shall determine, on permitted paths only, whether any threat actor position can reach any designated decisive point, and shall record the result each cycle.
Purpose. To produce a computed, repeatable answer to the question a control catalog cannot ask — can they get there from here — and to record the answer as a trend rather than a one-time finding.
Discussion
This is one of the framework's genuinely net-new controls: no federal catalog requires a computed reachability result. Its integrity depends entirely on the denied-path register under TM-5. A negative result — no route exists — is a claim about configuration that holds only while the barriers holding the line remain enforced, which is why KT-5 exists and why the two controls should never be assessed apart.
Goals and Metrics
A metric that cannot come out badly is not a metric. Each of these is capable of reporting that the control is not working.
- Number of decisive points reachable from any threat-actor position
- Number of cycles in which the assessment was run and recorded
- Mean time from a reachable finding to the path being denied or a risk being formally accepted
Accountability
Exactly one role is accountable, and every other role carries at least Informed — no control in the published catalog leaves a role with zero relationship to it. That is a stated property of how these were authored, not a coincidence, and not a claim that every role's work is worth equal attention here.
| AO | CTI | SOC | HUNT | PLAT | ISSO |
|---|---|---|---|---|---|
| Authorizing Official / CISO: Accountable | Cyber Threat Intelligence cell: Responsible | SOC / Defensive Operations: Consulted | Hunt team: Informed | Platform and product owners: Consulted | Governance / RMF / ISSO: Informed |
AO Authorizing Official / CISOCTI Cyber Threat Intelligence cellSOC SOC / Defensive OperationsHUNT Hunt teamPLAT Platform and product ownersISSO Governance / RMF / ISSO
- AccountableAuthorizing Official / CISO
- ResponsibleCyber Threat Intelligence cell
- ConsultedSOC / Defensive Operations
- InformedHunt team
- ConsultedPlatform and product owners
- InformedGovernance / RMF / ISSO
Inputs and Outputs
Consumes
- KT-3 Avenue of Approach AnalysisEnumerated avenues of approach
- TM-5 Connection and Denied-Path RegisterPermitted-path graph — denied paths are excluded by definition
- KT-1 Decisive Point IdentificationTargets for the reachability assessment
- ID-5 Authorization Decision IntegrityAuthorization paths over which reachability is computed
Produces
- KT-5 Barrier SufficiencyThe specific barriers holding the line where reachability is prevented
- CE-4 Coverage and Residual Risk ComputationReachability result feeding the residual risk picture
- CE-7 Brief Generation and DistributionHeadline finding for the cycle brief
- CG-4 Findings DispositionReachable decisive points requiring disposition
- CG-2 Phase DeclarationReachability result as a phase-change indicator
Activities
- L2Define the threat actor start positions to be assessed, at minimum the unauthenticated internet and any compromised-user position.
- L2Compute, over permitted paths only, whether a route exists from each start position to each decisive point.
- L2Record the result for the cycle, including the routes found and the points proven unreachable.
- L3Derive start positions from current threat courses of action rather than from a fixed list, so the assessment tracks the threat.
- L3Report, for each negative result, the specific denied paths holding the line, and hand them to KT-5.
- L3Re-compute on material architectural change as well as at cycle cadence.
- L3Validate the computation against the connection register so that a route the register permits cannot be absent from the result.
- L4Trend reachability results across cycles; a point that becomes reachable between cycles is a reportable condition, not a backlog item.
- L4Measure the interval between a permitting change and its appearance in a reachability result.
- L5Reconcile computed reachability against routes actually used in engagements, and correct the model where contact disagrees with it.
Measurement
Number of decisive points reachable from any assessed start position.
Elapsed time from a permitting configuration change to its reflection in a reachability result.
Evidence and Assessment
Adversary Reach section of the Brief; per-cycle result series; barrier dependency list.
Test the reachability computation against the connection register; examine the result trend across cycles; test that a recent permitting change appeared in the subsequent result. **Assess jointly with KT-5:** a negative reachability result is a claim about configuration that holds only while the barriers under KT-5 remain enforced, so KT-4 assessed alone can certify a conclusion that a subsequent barrier change has already invalidated.
Related Guidance
- RA-3(4)
- CA-8
- ID.RA-05
- DE.AE-07
Position in the Chain
Derived from the other controls’ own declarations, so the two directions cannot disagree.
Where This Control Is Used
Derived, in every case, from the declaration at the other end: the forms whose techniques name this control, the artifacts whose producing and consuming controls include it, the layers whose control lists name it, and the roles its own accountability chart puts to work. Nothing here is authored on this page, so the sheet cannot claim an edge the other end does not.
Forms of Maneuver It Assesses
- M5AmbushTrade space for information and time, and impose cost.3 of 13 techniques — M5.03, M5.07, M5.08
- M7CounterattackSeize the initiative and evict before the adversary reaches the objective.1 of 17 techniques — M7.08
Terrain It Is Named On
- T1IdentityReachability of the policy decision point from the public tier is the single most consequential reachability question in the estate.
- T4Applications and WorkloadsReachability of the pipeline from a developer workstation, and of the mission tier from the portal, are the two reachability questions this layer turns on.
- T5DataReachability of the crown-jewel store, from where and by whom, is the reachability question the others are asked in service of.
Artifacts It Stands On
- producesAdversary reachability assessmentThe formal result: from each entry point, which decisive points are reachable over the permitted-path graph. The framework’s hardest single finding, and the headline of the brief when it changes.
- producesHunt results, including negative resultsWhat was hunted, how, and what was not found. Negative results are the half most often discarded, and they are the half that says what has actually been cleared.
- consumesTrust zones and the connection registerThe zone boundaries and the permitted- and denied-path register — the graph reachability is actually walked over, reconciled against observed flow telemetry rather than against intended configuration.
- consumesAvenue-of-approach analysisThe enumerated routes an adversary could take toward each decisive point, including physical, supplier and maintenance routes, with unassessed routes recorded as intelligence gaps rather than as absence of risk.
- consumesThreat course-of-action sketchTwo courses of action, most likely and most dangerous, drawn against the decisive points already designated. Each is a route across ground the estate really has, not a category of threat.
Roles It Puts to Work
- AccountableAuthorizing Official / CISOIntent, risk acceptance, and the scheme itself.
- ResponsibleCyber Threat Intelligence cellFrame, Map and Fuse. The intelligence requirements, the threat courses of action, and the confidence levels.
- ConsultedSOC / Defensive OperationsManeuver. Executes fires and emplaces obstacles inside the standing rules of engagement.
- ConsultedPlatform and product ownersTheir own terrain. Obstacles get emplaced on their ground, so they site them.
- InformedHunt teamCounterattack. Works the hypotheses that Fuse raises.
- InformedGovernance / RMF / ISSOTranslating cycle outputs into FISMA and RMF artifacts, and owning the rules of engagement.