Control Statement
Suppliers, integrators and managed-service providers with a path into the estate shall be registered on the terrain overlay, with the access each holds and the elements it reaches recorded.
Purpose. To make third parties positional, so that supplier risk is assessed against what a supplier can reach rather than against what they were contracted to do.
Discussion
Procurement already holds a vendor list; this is not that. The distinguishing requirement is *the elements it reaches* — a supplier with a narrow contract and broad technical access is the case this control exists to surface, and it is invisible on any acquisition record because the contract describes intent while the entitlement describes capability. Reconciling the register against provisioned access rather than against contracts is therefore the control's operative activity, and it routinely finds access that outlived the engagement that justified it.
Goals and Metrics
A metric that cannot come out badly is not a metric. Each of these is capable of reporting that the control is not working.
- Percentage of suppliers with estate access on the register
- Number of registered suppliers whose access reaches a decisive point
Accountability
Exactly one role is accountable, and every other role carries at least Informed — no control in the published catalog leaves a role with zero relationship to it. That is a stated property of how these were authored, not a coincidence, and not a claim that every role's work is worth equal attention here.
| AO | CTI | SOC | HUNT | PLAT | ISSO |
|---|---|---|---|---|---|
| Authorizing Official / CISO: Accountable | Cyber Threat Intelligence cell: Informed | SOC / Defensive Operations: Consulted | Hunt team: Informed | Platform and product owners: Responsible | Governance / RMF / ISSO: Consulted |
AO Authorizing Official / CISOCTI Cyber Threat Intelligence cellSOC SOC / Defensive OperationsHUNT Hunt teamPLAT Platform and product ownersISSO Governance / RMF / ISSO
- AccountableAuthorizing Official / CISO
- InformedCyber Threat Intelligence cell
- ConsultedSOC / Defensive Operations
- InformedHunt team
- ResponsiblePlatform and product owners
- ConsultedGovernance / RMF / ISSO
Inputs and Outputs
Consumes
- FO-6 Supply Chain ObligationSuppliers represented as external actors on the overlay
- Outside the frameworkContract and procurement records
Produces
- LC-3 Supplier Access ConstraintAccess requiring constraint
- LC-5 Supplier Severance CapabilityPopulation for severance capability
- KT-3 Avenue of Approach AnalysisSupplier paths as avenues of approach
- FC-3 Maintenance Access ControlSuppliers holding maintenance access
- LC-2 Component ProvenanceSuppliers providing the components
- LC-4 Update Integrity and StagingSuppliers providing updates
Activities
- L2Register every supplier, integrator and managed-service provider holding a path into the estate as an external actor on the overlay.
- L2Record the access each holds and the elements that access reaches.
- L2Raise a finding for suppliers holding unrecorded access.
- L3Reconcile the register against provisioned access in the identity and network estate, not against the acquisition record, since contracts describe intent and entitlements describe capability.
- L3Record reach transitively where a supplier's access permits movement beyond the element it terminates on.
- L3Raise a finding for any supplier holding standing access to a decisive point (KT-1), and route it to LC-3 for constraint.
- L3Reconcile against the SCRM scope under FO-6, so an access-holding supplier outside that scope is a recorded position rather than an oversight.
- L4Trend the count of suppliers and the aggregate weight of elements they reach, since supplier reach expands quietly through renewals and scope changes.
- L4Measure the interval between engagement end and access removal, which is the window in which reach exists with no contract behind it.
- L5Feed reach findings into acquisition, so access scope is specified before award rather than discovered at the next reconciliation.
Measurement
Percentage of suppliers whose recorded reach matches provisioned access.
Median interval between engagement end and access removal.
Evidence and Assessment
Supplier terrain register reconciled to provisioned access; standing-access findings; FO-6 scope reconciliation.
Examine the register against contracts and against provisioned access; test for suppliers holding access not in the register; test whether reach was recorded transitively.
Related Guidance
- SR-2
- SA-9
- PM-30
- GV.SC-04
- ID.AM-04
Position in the Chain
Derived from the other controls’ own declarations, so the two directions cannot disagree.
Where This Control Is Used
Derived, in every case, from the declaration at the other end: the forms whose techniques name this control, the artifacts whose producing and consuming controls include it, the layers whose control lists name it, and the roles its own accountability chart puts to work. Nothing here is authored on this page, so the sheet cannot claim an edge the other end does not.
Forms of Maneuver It Assesses
- M1Screen / GuardGain early warning and buy reaction time before the adversary touches key terrain.1 of 15 techniques — M1.14
- M9Spoiling AttackDisrupt adversary staging before the attack is launched.1 of 9 techniques — M9.09
- M10Exploitation & PursuitConvert contact into durable advantage rather than closing the ticket.1 of 7 techniques — M10.07
Terrain It Is Named On
- T9Supply ChainThe supplier terrain register, which is what makes anything else on this layer computable.
Artifacts It Stands On
- producesSupplier terrain registerSuppliers as external actors on the overlay, with the access each holds, the paths that access implies, and the contract behind it.
Roles It Puts to Work
- AccountableAuthorizing Official / CISOIntent, risk acceptance, and the scheme itself.
- ResponsiblePlatform and product ownersTheir own terrain. Obstacles get emplaced on their ground, so they site them.
- ConsultedSOC / Defensive OperationsManeuver. Executes fires and emplaces obstacles inside the standing rules of engagement.
- ConsultedGovernance / RMF / ISSOTranslating cycle outputs into FISMA and RMF artifacts, and owning the rules of engagement.
- InformedCyber Threat Intelligence cellFrame, Map and Fuse. The intelligence requirements, the threat courses of action, and the confidence levels.
- InformedHunt teamCounterattack. Works the hypotheses that Fuse raises.