Control Statement
Where reachability is prevented by denied paths, those barriers shall be identified, enforced technically, and monitored for change.
Purpose. To make the barriers on which negative reachability results depend into named, owned, monitored controls, so that the assurance KT-4 provides cannot be silently withdrawn.
Discussion
This control exists because of a specific failure sequence: a reachability assessment returns negative, the result is briefed, a firewall rule is changed six weeks later for an unrelated reason, and nobody recomputes. The assurance persists in the record long after the configuration that justified it has gone. Change monitoring on the barrier set is the only thing that closes that window.
Goals and Metrics
A metric that cannot come out badly is not a metric. Each of these is capable of reporting that the control is not working.
- Number of barriers holding the line that are technically enforced versus procedurally asserted
- Number of barriers with a named owner and a monitoring mechanism
- Mean time to detect an unplanned change to a load-bearing barrier
Accountability
Exactly one role is accountable, and every other role carries at least Informed — no control in the published catalog leaves a role with zero relationship to it. That is a stated property of how these were authored, not a coincidence, and not a claim that every role's work is worth equal attention here.
| AO | CTI | SOC | HUNT | PLAT | ISSO |
|---|---|---|---|---|---|
| Authorizing Official / CISO: Accountable | Cyber Threat Intelligence cell: Consulted | SOC / Defensive Operations: Consulted | Hunt team: Informed | Platform and product owners: Responsible | Governance / RMF / ISSO: Informed |
AO Authorizing Official / CISOCTI Cyber Threat Intelligence cellSOC SOC / Defensive OperationsHUNT Hunt teamPLAT Platform and product ownersISSO Governance / RMF / ISSO
- AccountableAuthorizing Official / CISO
- ConsultedCyber Threat Intelligence cell
- ConsultedSOC / Defensive Operations
- InformedHunt team
- ResponsiblePlatform and product owners
- InformedGovernance / RMF / ISSO
Inputs and Outputs
Consumes
- KT-4 Adversary Reachability AssessmentThe denied paths identified as preventing reachability
- TM-7 Terrain OwnershipAccountable owner for each enforcing element
- TM-5 Connection and Denied-Path RegisterDenied paths that become barriers requiring enforcement and monitoring
- CE-6 Cycle Record and TrendBarrier inventory tracked for erosion across cycles
- RC-2 Isolated Recovery CapabilityThe isolation boundary as a load-bearing barrier requiring monitoring
- FC-2 Physical Zone BoundaryPhysical barriers holding the line
- LC-4 Update Integrity and StagingThe staging gate as a barrier requiring monitoring
- ID-5 Authorization Decision IntegrityBarrier set whose continued enforcement is monitored
Produces
- SM-2 Maneuver AssignmentBarriers requiring an obstacle maneuver to be assigned and maintained
- CE-6 Cycle Record and TrendBarrier inventory tracked across cycles for silent erosion
- TA-5 Tempo Degradation TriggerBarrier failure as a tempo degradation trigger
Activities
- L2Extract from each negative reachability result the specific denied paths that held the line.
- L2Record each as a control with a named owner rather than leaving it as a register entry.
- L2Identify the technical configuration enforcing each barrier.
- L3Verify by test that each barrier is enforced by configuration and not by convention, documentation or expectation.
- L3Place change detection on every enforcing configuration, with an alert path that reaches someone able to act.
- L3Define the response to a detected barrier change, including re-running KT-4 before the change is accepted.
- L3Review barrier ownership when the underlying platform or its owner changes.
- L4Trend barrier test pass rate and the count of convention-enforced barriers, driving the latter toward zero.
- L4Measure mean time to detect an unauthorized change to a barrier.
- L5Feed every barrier failure back into the enumeration method, so the class of barrier that failed is looked for elsewhere in the estate.
Measurement
Percentage of load-bearing barriers with verified technical enforcement and active change detection.
Mean time to detect an unauthorized barrier change.
Evidence and Assessment
Barrier list from route analysis; supporting configuration evidence; change-detection coverage record.
Test each barrier against enforcing configuration; examine change-detection coverage on those barriers; test the response path by introducing a monitored change. **Assess jointly with KT-4:** this control exists to sustain KT-4's negative results, and its findings invalidate them directly.
Related Guidance
- SC-7(5)
- AC-4
- CM-3
- PR.IR-01
- DE.CM-01
Position in the Chain
Derived from the other controls’ own declarations, so the two directions cannot disagree.
Fed By
Where This Control Is Used
Derived, in every case, from the declaration at the other end: the forms whose techniques name this control, the artifacts whose producing and consuming controls include it, the layers whose control lists name it, and the roles its own accountability chart puts to work. Nothing here is authored on this page, so the sheet cannot claim an edge the other end does not.
Forms of Maneuver It Assesses
- M4Obstacle / CanalizationForce the adversary onto ground you own and watch.8 of 17 techniques — M4.01, M4.02, M4.03, M4.04, M4.08, M4.11, M4.13, M4.14
- M2Defense in DepthEnsure no single failure is decisive.2 of 18 techniques — M2.04, M2.10
- M3EnvelopmentMake identity, not network location, the decisive plane — surround the adversary with policy.1 of 20 techniques — M3.16
- M5AmbushTrade space for information and time, and impose cost.1 of 13 techniques — M5.04
- M7CounterattackSeize the initiative and evict before the adversary reaches the objective.1 of 17 techniques — M7.08
- M8Isolation / RetrogradeGive ground deliberately to preserve the force. Degrade gracefully; never fail open.1 of 17 techniques — M8.07
Terrain It Is Named On
- T2DevicesBarrier sufficiency asks whether the endpoint controls actually stop the crossing they are credited with, rather than whether they are deployed.
- T3NetworksBarrier sufficiency is where a segmentation claim is tested rather than believed.
- T6Operational TechnologyBarrier sufficiency on the OT boundary is testable in a way most of this layer is not, which makes it the highest-yield assessment available here.
Artifacts It Stands On
- producesBarrier sufficiency registerThe specific barriers holding the line where reachability is prevented, each with a named enforcing owner. What the reachability result depends on, made explicit so its erosion is visible.
- consumesCyber Terrain OverlayThe positional map of the estate: every element with a defensive layer, a defensive weight, a named accountable owner and its adjacencies. Not an asset inventory — an inventory enumerates, an overlay positions.
- consumesAdversary reachability assessmentThe formal result: from each entry point, which decisive points are reachable over the permitted-path graph. The framework’s hardest single finding, and the headline of the brief when it changes.
- consumesHunt results, including negative resultsWhat was hunted, how, and what was not found. Negative results are the half most often discarded, and they are the half that says what has actually been cleared.
Roles It Puts to Work
- AccountableAuthorizing Official / CISOIntent, risk acceptance, and the scheme itself.
- ResponsiblePlatform and product ownersTheir own terrain. Obstacles get emplaced on their ground, so they site them.
- ConsultedCyber Threat Intelligence cellFrame, Map and Fuse. The intelligence requirements, the threat courses of action, and the confidence levels.
- ConsultedSOC / Defensive OperationsManeuver. Executes fires and emplaces obstacles inside the standing rules of engagement.
- InformedHunt teamCounterattack. Works the hypotheses that Fuse raises.
- InformedGovernance / RMF / ISSOTranslating cycle outputs into FISMA and RMF artifacts, and owning the rules of engagement.