ASOM-Fedv6.1Open the explorer
KT-5 · Key Terrain and Decisive Points

Barrier Sufficiency

Control Statement

Where reachability is prevented by denied paths, those barriers shall be identified, enforced technically, and monitored for change.

Purpose. To make the barriers on which negative reachability results depend into named, owned, monitored controls, so that the assurance KT-4 provides cannot be silently withdrawn.

Discussion

This control exists because of a specific failure sequence: a reachability assessment returns negative, the result is briefed, a firewall rule is changed six weeks later for an unrelated reason, and nobody recomputes. The assurance persists in the record long after the configuration that justified it has gone. Change monitoring on the barrier set is the only thing that closes that window.

Goals and Metrics

A metric that cannot come out badly is not a metric. Each of these is capable of reporting that the control is not working.

Load-bearing barriers are identified and enforced.
  • Number of barriers holding the line that are technically enforced versus procedurally asserted
  • Number of barriers with a named owner and a monitoring mechanism
Barrier change is detected.
  • Mean time to detect an unplanned change to a load-bearing barrier

Accountability

Exactly one role is accountable, and every other role carries at least Informed — no control in the published catalog leaves a role with zero relationship to it. That is a stated property of how these were authored, not a coincidence, and not a claim that every role's work is worth equal attention here.

AOCTISOCHUNTPLATISSO
Authorizing Official / CISO: AccountableCyber Threat Intelligence cell: ConsultedSOC / Defensive Operations: ConsultedHunt team: InformedPlatform and product owners: ResponsibleGovernance / RMF / ISSO: Informed

AO Authorizing Official / CISOCTI Cyber Threat Intelligence cellSOC SOC / Defensive OperationsHUNT Hunt teamPLAT Platform and product ownersISSO Governance / RMF / ISSO

  • AccountableAuthorizing Official / CISO
  • ConsultedCyber Threat Intelligence cell
  • ConsultedSOC / Defensive Operations
  • InformedHunt team
  • ResponsiblePlatform and product owners
  • InformedGovernance / RMF / ISSO

Inputs and Outputs

Consumes

Produces

Activities

  1. L2Extract from each negative reachability result the specific denied paths that held the line.
  2. L2Record each as a control with a named owner rather than leaving it as a register entry.
  3. L2Identify the technical configuration enforcing each barrier.
  4. L3Verify by test that each barrier is enforced by configuration and not by convention, documentation or expectation.
  5. L3Place change detection on every enforcing configuration, with an alert path that reaches someone able to act.
  6. L3Define the response to a detected barrier change, including re-running KT-4 before the change is accepted.
  7. L3Review barrier ownership when the underlying platform or its owner changes.
  8. L4Trend barrier test pass rate and the count of convention-enforced barriers, driving the latter toward zero.
  9. L4Measure mean time to detect an unauthorized change to a barrier.
  10. L5Feed every barrier failure back into the enumeration method, so the class of barrier that failed is looked for elsewhere in the estate.

Measurement

Outcome

Percentage of load-bearing barriers with verified technical enforcement and active change detection.

Performance

Mean time to detect an unauthorized barrier change.

Evidence and Assessment

Evidence expected

Barrier list from route analysis; supporting configuration evidence; change-detection coverage record.

Assessment procedure

Test each barrier against enforcing configuration; examine change-detection coverage on those barriers; test the response path by introducing a monitored change. **Assess jointly with KT-4:** this control exists to sustain KT-4's negative results, and its findings invalidate them directly.

Related Guidance

Inherits
  • SC-7(5)
  • AC-4
  • CM-3
Satisfies
  • PR.IR-01
  • DE.CM-01

Position in the Chain

Derived from the other controls’ own declarations, so the two directions cannot disagree.

Where This Control Is Used

Derived, in every case, from the declaration at the other end: the forms whose techniques name this control, the artifacts whose producing and consuming controls include it, the layers whose control lists name it, and the roles its own accountability chart puts to work. Nothing here is authored on this page, so the sheet cannot claim an edge the other end does not.

Forms of Maneuver It Assesses

  • M4Obstacle / CanalizationForce the adversary onto ground you own and watch.8 of 17 techniques — M4.01, M4.02, M4.03, M4.04, M4.08, M4.11, M4.13, M4.14
  • M2Defense in DepthEnsure no single failure is decisive.2 of 18 techniques — M2.04, M2.10
  • M3EnvelopmentMake identity, not network location, the decisive plane — surround the adversary with policy.1 of 20 techniques — M3.16
  • M5AmbushTrade space for information and time, and impose cost.1 of 13 techniques — M5.04
  • M7CounterattackSeize the initiative and evict before the adversary reaches the objective.1 of 17 techniques — M7.08
  • M8Isolation / RetrogradeGive ground deliberately to preserve the force. Degrade gracefully; never fail open.1 of 17 techniques — M8.07

Terrain It Is Named On

  • T2DevicesBarrier sufficiency asks whether the endpoint controls actually stop the crossing they are credited with, rather than whether they are deployed.
  • T3NetworksBarrier sufficiency is where a segmentation claim is tested rather than believed.
  • T6Operational TechnologyBarrier sufficiency on the OT boundary is testable in a way most of this layer is not, which makes it the highest-yield assessment available here.

Artifacts It Stands On

  • producesBarrier sufficiency registerThe specific barriers holding the line where reachability is prevented, each with a named enforcing owner. What the reachability result depends on, made explicit so its erosion is visible.
  • consumesCyber Terrain OverlayThe positional map of the estate: every element with a defensive layer, a defensive weight, a named accountable owner and its adjacencies. Not an asset inventory — an inventory enumerates, an overlay positions.
  • consumesAdversary reachability assessmentThe formal result: from each entry point, which decisive points are reachable over the permitted-path graph. The framework’s hardest single finding, and the headline of the brief when it changes.
  • consumesHunt results, including negative resultsWhat was hunted, how, and what was not found. Negative results are the half most often discarded, and they are the half that says what has actually been cleared.

Roles It Puts to Work