ASOM-Fedv6.1Open the explorer
LC-1 · Lines of Communication

Supplier Terrain Register

Control Statement

Suppliers, integrators and managed-service providers with a path into the estate shall be registered on the terrain overlay, with the access each holds and the elements it reaches recorded.

Purpose. To make third parties positional, so that supplier risk is assessed against what a supplier can reach rather than against what they were contracted to do.

Discussion

Procurement already holds a vendor list; this is not that. The distinguishing requirement is *the elements it reaches* — a supplier with a narrow contract and broad technical access is the case this control exists to surface, and it is invisible on any acquisition record because the contract describes intent while the entitlement describes capability. Reconciling the register against provisioned access rather than against contracts is therefore the control's operative activity, and it routinely finds access that outlived the engagement that justified it.

Goals and Metrics

A metric that cannot come out badly is not a metric. Each of these is capable of reporting that the control is not working.

Suppliers with access are registered with what that access reaches.
  • Percentage of suppliers with estate access on the register
  • Number of registered suppliers whose access reaches a decisive point

Accountability

Exactly one role is accountable, and every other role carries at least Informed — no control in the published catalog leaves a role with zero relationship to it. That is a stated property of how these were authored, not a coincidence, and not a claim that every role's work is worth equal attention here.

AOCTISOCHUNTPLATISSO
Authorizing Official / CISO: AccountableCyber Threat Intelligence cell: InformedSOC / Defensive Operations: ConsultedHunt team: InformedPlatform and product owners: ResponsibleGovernance / RMF / ISSO: Consulted

AO Authorizing Official / CISOCTI Cyber Threat Intelligence cellSOC SOC / Defensive OperationsHUNT Hunt teamPLAT Platform and product ownersISSO Governance / RMF / ISSO

  • AccountableAuthorizing Official / CISO
  • InformedCyber Threat Intelligence cell
  • ConsultedSOC / Defensive Operations
  • InformedHunt team
  • ResponsiblePlatform and product owners
  • ConsultedGovernance / RMF / ISSO

Inputs and Outputs

Consumes

Produces

Activities

  1. L2Register every supplier, integrator and managed-service provider holding a path into the estate as an external actor on the overlay.
  2. L2Record the access each holds and the elements that access reaches.
  3. L2Raise a finding for suppliers holding unrecorded access.
  4. L3Reconcile the register against provisioned access in the identity and network estate, not against the acquisition record, since contracts describe intent and entitlements describe capability.
  5. L3Record reach transitively where a supplier's access permits movement beyond the element it terminates on.
  6. L3Raise a finding for any supplier holding standing access to a decisive point (KT-1), and route it to LC-3 for constraint.
  7. L3Reconcile against the SCRM scope under FO-6, so an access-holding supplier outside that scope is a recorded position rather than an oversight.
  8. L4Trend the count of suppliers and the aggregate weight of elements they reach, since supplier reach expands quietly through renewals and scope changes.
  9. L4Measure the interval between engagement end and access removal, which is the window in which reach exists with no contract behind it.
  10. L5Feed reach findings into acquisition, so access scope is specified before award rather than discovered at the next reconciliation.

Measurement

Outcome

Percentage of suppliers whose recorded reach matches provisioned access.

Performance

Median interval between engagement end and access removal.

Evidence and Assessment

Evidence expected

Supplier terrain register reconciled to provisioned access; standing-access findings; FO-6 scope reconciliation.

Assessment procedure

Examine the register against contracts and against provisioned access; test for suppliers holding access not in the register; test whether reach was recorded transitively.

Related Guidance

Inherits
  • SR-2
  • SA-9
  • PM-30
Satisfies
  • GV.SC-04
  • ID.AM-04

Position in the Chain

Derived from the other controls’ own declarations, so the two directions cannot disagree.

Where This Control Is Used

Derived, in every case, from the declaration at the other end: the forms whose techniques name this control, the artifacts whose producing and consuming controls include it, the layers whose control lists name it, and the roles its own accountability chart puts to work. Nothing here is authored on this page, so the sheet cannot claim an edge the other end does not.

Forms of Maneuver It Assesses

  • M1Screen / GuardGain early warning and buy reaction time before the adversary touches key terrain.1 of 15 techniques — M1.14
  • M9Spoiling AttackDisrupt adversary staging before the attack is launched.1 of 9 techniques — M9.09
  • M10Exploitation & PursuitConvert contact into durable advantage rather than closing the ticket.1 of 7 techniques — M10.07

Terrain It Is Named On

  • T9Supply ChainThe supplier terrain register, which is what makes anything else on this layer computable.

Artifacts It Stands On

  • producesSupplier terrain registerSuppliers as external actors on the overlay, with the access each holds, the paths that access implies, and the contract behind it.

Roles It Puts to Work