ASOM-Fedv6.1Open the explorer
KT-4 · Key Terrain and Decisive Points

Adversary Reachability Assessment

Control Statement

The organization shall determine, on permitted paths only, whether any threat actor position can reach any designated decisive point, and shall record the result each cycle.

Purpose. To produce a computed, repeatable answer to the question a control catalog cannot ask — can they get there from here — and to record the answer as a trend rather than a one-time finding.

Discussion

This is one of the framework's genuinely net-new controls: no federal catalog requires a computed reachability result. Its integrity depends entirely on the denied-path register under TM-5. A negative result — no route exists — is a claim about configuration that holds only while the barriers holding the line remain enforced, which is why KT-5 exists and why the two controls should never be assessed apart.

Goals and Metrics

A metric that cannot come out badly is not a metric. Each of these is capable of reporting that the control is not working.

Reachability is assessed and recorded every cycle.
  • Number of decisive points reachable from any threat-actor position
  • Number of cycles in which the assessment was run and recorded
The result is acted upon.
  • Mean time from a reachable finding to the path being denied or a risk being formally accepted

Accountability

Exactly one role is accountable, and every other role carries at least Informed — no control in the published catalog leaves a role with zero relationship to it. That is a stated property of how these were authored, not a coincidence, and not a claim that every role's work is worth equal attention here.

AOCTISOCHUNTPLATISSO
Authorizing Official / CISO: AccountableCyber Threat Intelligence cell: ResponsibleSOC / Defensive Operations: ConsultedHunt team: InformedPlatform and product owners: ConsultedGovernance / RMF / ISSO: Informed

AO Authorizing Official / CISOCTI Cyber Threat Intelligence cellSOC SOC / Defensive OperationsHUNT Hunt teamPLAT Platform and product ownersISSO Governance / RMF / ISSO

  • AccountableAuthorizing Official / CISO
  • ResponsibleCyber Threat Intelligence cell
  • ConsultedSOC / Defensive Operations
  • InformedHunt team
  • ConsultedPlatform and product owners
  • InformedGovernance / RMF / ISSO

Inputs and Outputs

Consumes

Produces

Activities

  1. L2Define the threat actor start positions to be assessed, at minimum the unauthenticated internet and any compromised-user position.
  2. L2Compute, over permitted paths only, whether a route exists from each start position to each decisive point.
  3. L2Record the result for the cycle, including the routes found and the points proven unreachable.
  4. L3Derive start positions from current threat courses of action rather than from a fixed list, so the assessment tracks the threat.
  5. L3Report, for each negative result, the specific denied paths holding the line, and hand them to KT-5.
  6. L3Re-compute on material architectural change as well as at cycle cadence.
  7. L3Validate the computation against the connection register so that a route the register permits cannot be absent from the result.
  8. L4Trend reachability results across cycles; a point that becomes reachable between cycles is a reportable condition, not a backlog item.
  9. L4Measure the interval between a permitting change and its appearance in a reachability result.
  10. L5Reconcile computed reachability against routes actually used in engagements, and correct the model where contact disagrees with it.

Measurement

Outcome

Number of decisive points reachable from any assessed start position.

Performance

Elapsed time from a permitting configuration change to its reflection in a reachability result.

Evidence and Assessment

Evidence expected

Adversary Reach section of the Brief; per-cycle result series; barrier dependency list.

Assessment procedure

Test the reachability computation against the connection register; examine the result trend across cycles; test that a recent permitting change appeared in the subsequent result. **Assess jointly with KT-5:** a negative reachability result is a claim about configuration that holds only while the barriers under KT-5 remain enforced, so KT-4 assessed alone can certify a conclusion that a subsequent barrier change has already invalidated.

Related Guidance

Inherits
  • RA-3(4)
  • CA-8
Satisfies
  • ID.RA-05
  • DE.AE-07

Position in the Chain

Derived from the other controls’ own declarations, so the two directions cannot disagree.

Where This Control Is Used

Derived, in every case, from the declaration at the other end: the forms whose techniques name this control, the artifacts whose producing and consuming controls include it, the layers whose control lists name it, and the roles its own accountability chart puts to work. Nothing here is authored on this page, so the sheet cannot claim an edge the other end does not.

Forms of Maneuver It Assesses

  • M5AmbushTrade space for information and time, and impose cost.3 of 13 techniques — M5.03, M5.07, M5.08
  • M7CounterattackSeize the initiative and evict before the adversary reaches the objective.1 of 17 techniques — M7.08

Terrain It Is Named On

  • T1IdentityReachability of the policy decision point from the public tier is the single most consequential reachability question in the estate.
  • T4Applications and WorkloadsReachability of the pipeline from a developer workstation, and of the mission tier from the portal, are the two reachability questions this layer turns on.
  • T5DataReachability of the crown-jewel store, from where and by whom, is the reachability question the others are asked in service of.

Artifacts It Stands On

  • producesAdversary reachability assessmentThe formal result: from each entry point, which decisive points are reachable over the permitted-path graph. The framework’s hardest single finding, and the headline of the brief when it changes.
  • producesHunt results, including negative resultsWhat was hunted, how, and what was not found. Negative results are the half most often discarded, and they are the half that says what has actually been cleared.
  • consumesTrust zones and the connection registerThe zone boundaries and the permitted- and denied-path register — the graph reachability is actually walked over, reconciled against observed flow telemetry rather than against intended configuration.
  • consumesAvenue-of-approach analysisThe enumerated routes an adversary could take toward each decisive point, including physical, supplier and maintenance routes, with unassessed routes recorded as intelligence gaps rather than as absence of risk.
  • consumesThreat course-of-action sketchTwo courses of action, most likely and most dangerous, drawn against the decisive points already designated. Each is a route across ground the estate really has, not a category of threat.

Roles It Puts to Work