Control Statement
Supplier access shall be brokered through the organization's own identity plane and constrained to the elements the engagement requires, with no standing access to a decisive point.
Purpose. To keep supplier access scoped, observable, and revocable by the agency rather than by the supplier.
Discussion
Brokering is the requirement that carries the rest. Where a supplier holds credentials the supplier issued, the agency can request removal but cannot perform it — which means LC-5's severance capability does not exist regardless of what the contract says. Routing access through the agency's own identity plane converts severance from a negotiation into an action. The scoping requirement addresses the second failure: supplier access is habitually provisioned at the privilege level the supplier requests, which reflects their convenience across all customers rather than this engagement's need.
Goals and Metrics
A metric that cannot come out badly is not a metric. Each of these is capable of reporting that the control is not working.
- Number of supplier access paths not brokered through the organization’s identity plane
- Number of suppliers holding standing access to a decisive point
Accountability
Exactly one role is accountable, and every other role carries at least Informed — no control in the published catalog leaves a role with zero relationship to it. That is a stated property of how these were authored, not a coincidence, and not a claim that every role's work is worth equal attention here.
| AO | CTI | SOC | HUNT | PLAT | ISSO |
|---|---|---|---|---|---|
| Authorizing Official / CISO: Accountable | Cyber Threat Intelligence cell: Informed | SOC / Defensive Operations: Consulted | Hunt team: Informed | Platform and product owners: Responsible | Governance / RMF / ISSO: Consulted |
AO Authorizing Official / CISOCTI Cyber Threat Intelligence cellSOC SOC / Defensive OperationsHUNT Hunt teamPLAT Platform and product ownersISSO Governance / RMF / ISSO
- AccountableAuthorizing Official / CISO
- InformedCyber Threat Intelligence cell
- ConsultedSOC / Defensive Operations
- InformedHunt team
- ResponsiblePlatform and product owners
- ConsultedGovernance / RMF / ISSO
Inputs and Outputs
Consumes
- LC-1 Supplier Terrain RegisterRegistered supplier access
- KT-1 Decisive Point IdentificationDecisive points to which standing access is prohibited
- FO-2 Controlled Unclassified Information HandlingControlled information constraints
Produces
- TM-5 Connection and Denied-Path RegisterSupplier paths recorded as permitted or denied
- LC-5 Supplier Severance CapabilityBrokered access as the severance point
- FC-3 Maintenance Access ControlConstraints applied to maintenance windows
Activities
- L2Route supplier access through the organization's own identity plane.
- L2Scope each supplier's access to the elements the engagement requires.
- L2Raise a finding for standing access to any designated decisive point.
- L3Record for each supplier access grant its broker, scope and expiry, and set an expiry in every case rather than only where one is obvious.
- L3Verify that revocation is technically within the agency's control, not dependent on supplier action.
- L3Apply the constraint to supplier-managed infrastructure and vendor-operated services, where the identity plane is most often the supplier's by default.
- L3Re-scope on engagement change rather than allowing scope to accumulate across successive contracts.
- L4Measure provisioned supplier access against engagement scope and trend the divergence.
- L4Measure the proportion of supplier access grants that are agency-revocable without supplier cooperation.
- L5Move brokering requirements into contract terms at renewal, so the constraint is a condition of engagement rather than an exception negotiated per grant.
Measurement
Percentage of supplier access grants brokered, scoped and agency-revocable.
Divergence between provisioned access and engagement scope.
Evidence and Assessment
Supplier access records showing broker, scope and expiry; revocability verification results.
Examine provisioned supplier access against the engagement scope; test that revocation is within the agency's control; test whether supplier-managed infrastructure is brokered or exempted.
Related Guidance
- SR-5
- AC-20
- SA-9(2)
- GV.SC-07
- PR.AA-05
- DE.CM-06
Position in the Chain
Derived from the other controls’ own declarations, so the two directions cannot disagree.
Where This Control Is Used
Derived, in every case, from the declaration at the other end: the forms whose techniques name this control, the artifacts whose producing and consuming controls include it, the layers whose control lists name it, and the roles its own accountability chart puts to work. Nothing here is authored on this page, so the sheet cannot claim an edge the other end does not.
Forms of Maneuver It Assesses
- M4Obstacle / CanalizationForce the adversary onto ground you own and watch.2 of 17 techniques — M4.16, M4.17
- M3EnvelopmentMake identity, not network location, the decisive plane — surround the adversary with policy.1 of 20 techniques — M3.20
Terrain It Is Named On
- T8FacilitiesSupplier access constraint governs the same vendors from the logical side; reconciling the two lists is where this layer pays for itself.
- T9Supply ChainSupplier access constraint, which is where this layer meets T1 privileged access and T8 maintenance access.
Artifacts It Stands On
- producesSupplier access constraint recordHow supplier access is brokered, time-bounded and constrained — and the prohibition on standing supplier access to designated decisive points.
- consumesDecisive point registerThe elements whose control confers decisive advantage — each carrying the evidence that raised it above merely important, and the protection floor it owes as a result.
- consumesPrivacy and controlled-information terrain registerWhere privacy holdings and controlled unclassified information sit, the authorities under which they are held, and the boundaries their handling requires — expressed as denied paths, not as policy statements.
- consumesSupplier terrain registerSuppliers as external actors on the overlay, with the access each holds, the paths that access implies, and the contract behind it.
Roles It Puts to Work
- AccountableAuthorizing Official / CISOIntent, risk acceptance, and the scheme itself.
- ResponsiblePlatform and product ownersTheir own terrain. Obstacles get emplaced on their ground, so they site them.
- ConsultedSOC / Defensive OperationsManeuver. Executes fires and emplaces obstacles inside the standing rules of engagement.
- ConsultedGovernance / RMF / ISSOTranslating cycle outputs into FISMA and RMF artifacts, and owning the rules of engagement.
- InformedCyber Threat Intelligence cellFrame, Map and Fuse. The intelligence requirements, the threat courses of action, and the confidence levels.
- InformedHunt teamCounterattack. Works the hypotheses that Fuse raises.