ASOM-Fedv6.1Open the explorer
LC-3 · Lines of Communication

Supplier Access Constraint

Control Statement

Supplier access shall be brokered through the organization's own identity plane and constrained to the elements the engagement requires, with no standing access to a decisive point.

Purpose. To keep supplier access scoped, observable, and revocable by the agency rather than by the supplier.

Discussion

Brokering is the requirement that carries the rest. Where a supplier holds credentials the supplier issued, the agency can request removal but cannot perform it — which means LC-5's severance capability does not exist regardless of what the contract says. Routing access through the agency's own identity plane converts severance from a negotiation into an action. The scoping requirement addresses the second failure: supplier access is habitually provisioned at the privilege level the supplier requests, which reflects their convenience across all customers rather than this engagement's need.

Goals and Metrics

A metric that cannot come out badly is not a metric. Each of these is capable of reporting that the control is not working.

Supplier access is brokered and constrained.
  • Number of supplier access paths not brokered through the organization’s identity plane
  • Number of suppliers holding standing access to a decisive point

Accountability

Exactly one role is accountable, and every other role carries at least Informed — no control in the published catalog leaves a role with zero relationship to it. That is a stated property of how these were authored, not a coincidence, and not a claim that every role's work is worth equal attention here.

AOCTISOCHUNTPLATISSO
Authorizing Official / CISO: AccountableCyber Threat Intelligence cell: InformedSOC / Defensive Operations: ConsultedHunt team: InformedPlatform and product owners: ResponsibleGovernance / RMF / ISSO: Consulted

AO Authorizing Official / CISOCTI Cyber Threat Intelligence cellSOC SOC / Defensive OperationsHUNT Hunt teamPLAT Platform and product ownersISSO Governance / RMF / ISSO

  • AccountableAuthorizing Official / CISO
  • InformedCyber Threat Intelligence cell
  • ConsultedSOC / Defensive Operations
  • InformedHunt team
  • ResponsiblePlatform and product owners
  • ConsultedGovernance / RMF / ISSO

Inputs and Outputs

Consumes

Produces

Activities

  1. L2Route supplier access through the organization's own identity plane.
  2. L2Scope each supplier's access to the elements the engagement requires.
  3. L2Raise a finding for standing access to any designated decisive point.
  4. L3Record for each supplier access grant its broker, scope and expiry, and set an expiry in every case rather than only where one is obvious.
  5. L3Verify that revocation is technically within the agency's control, not dependent on supplier action.
  6. L3Apply the constraint to supplier-managed infrastructure and vendor-operated services, where the identity plane is most often the supplier's by default.
  7. L3Re-scope on engagement change rather than allowing scope to accumulate across successive contracts.
  8. L4Measure provisioned supplier access against engagement scope and trend the divergence.
  9. L4Measure the proportion of supplier access grants that are agency-revocable without supplier cooperation.
  10. L5Move brokering requirements into contract terms at renewal, so the constraint is a condition of engagement rather than an exception negotiated per grant.

Measurement

Outcome

Percentage of supplier access grants brokered, scoped and agency-revocable.

Performance

Divergence between provisioned access and engagement scope.

Evidence and Assessment

Evidence expected

Supplier access records showing broker, scope and expiry; revocability verification results.

Assessment procedure

Examine provisioned supplier access against the engagement scope; test that revocation is within the agency's control; test whether supplier-managed infrastructure is brokered or exempted.

Related Guidance

Inherits
  • SR-5
  • AC-20
  • SA-9(2)
Satisfies
  • GV.SC-07
  • PR.AA-05
  • DE.CM-06

Position in the Chain

Derived from the other controls’ own declarations, so the two directions cannot disagree.

Where This Control Is Used

Derived, in every case, from the declaration at the other end: the forms whose techniques name this control, the artifacts whose producing and consuming controls include it, the layers whose control lists name it, and the roles its own accountability chart puts to work. Nothing here is authored on this page, so the sheet cannot claim an edge the other end does not.

Forms of Maneuver It Assesses

  • M4Obstacle / CanalizationForce the adversary onto ground you own and watch.2 of 17 techniques — M4.16, M4.17
  • M3EnvelopmentMake identity, not network location, the decisive plane — surround the adversary with policy.1 of 20 techniques — M3.20

Terrain It Is Named On

  • T8FacilitiesSupplier access constraint governs the same vendors from the logical side; reconciling the two lists is where this layer pays for itself.
  • T9Supply ChainSupplier access constraint, which is where this layer meets T1 privileged access and T8 maintenance access.

Artifacts It Stands On

  • producesSupplier access constraint recordHow supplier access is brokered, time-bounded and constrained — and the prohibition on standing supplier access to designated decisive points.
  • consumesDecisive point registerThe elements whose control confers decisive advantage — each carrying the evidence that raised it above merely important, and the protection floor it owes as a result.
  • consumesPrivacy and controlled-information terrain registerWhere privacy holdings and controlled unclassified information sit, the authorities under which they are held, and the boundaries their handling requires — expressed as denied paths, not as policy statements.
  • consumesSupplier terrain registerSuppliers as external actors on the overlay, with the access each holds, the paths that access implies, and the contract behind it.

Roles It Puts to Work