ASOM-Fedv6.1Open the explorer
LC-4 · Lines of Communication

Update Integrity and Staging

Control Statement

Supplier-provided updates shall be integrity-verified before deployment and shall pass through a staging ring for a stated period before reaching the whole estate.

Purpose. To limit the blast radius of a compromised trusted update, so that supply chain compromise reaches a ring rather than the estate.

Discussion

The soak period is the control, and its length is the part most often chosen arbitrarily. A staging ring protects only if the soak exceeds the time the organization needs to notice something wrong — so the period should be derived from the measured detection segment of the decision loop under TA-1, not from a release calendar. An estate with a ten-day detect segment and a twenty-four-hour soak has implemented staging and gained almost nothing from it, and that mismatch is invisible unless the two figures are compared deliberately.

Goals and Metrics

A metric that cannot come out badly is not a metric. Each of these is capable of reporting that the control is not working.

Updates are verified and staged before estate-wide deployment.
  • Percentage of supplier updates integrity-verified before deployment
  • Actual soak period in the staging ring against the stated period

Accountability

Exactly one role is accountable, and every other role carries at least Informed — no control in the published catalog leaves a role with zero relationship to it. That is a stated property of how these were authored, not a coincidence, and not a claim that every role's work is worth equal attention here.

AOCTISOCHUNTPLATISSO
Authorizing Official / CISO: AccountableCyber Threat Intelligence cell: ConsultedSOC / Defensive Operations: ConsultedHunt team: InformedPlatform and product owners: ResponsibleGovernance / RMF / ISSO: Informed

AO Authorizing Official / CISOCTI Cyber Threat Intelligence cellSOC SOC / Defensive OperationsHUNT Hunt teamPLAT Platform and product ownersISSO Governance / RMF / ISSO

  • AccountableAuthorizing Official / CISO
  • ConsultedCyber Threat Intelligence cell
  • ConsultedSOC / Defensive Operations
  • InformedHunt team
  • ResponsiblePlatform and product owners
  • InformedGovernance / RMF / ISSO

Inputs and Outputs

Consumes

Produces

Activities

  1. L2Integrity-verify supplier-provided updates before deployment.
  2. L2Pass updates through a staging ring before general release.
  3. L2Record the staging ring composition and the soak period applied.
  4. L3Derive the soak period from the measured detection segment under TA-1, with provenance per GA4, rather than from a release calendar.
  5. L3Compose the staging ring to be representative of the estate rather than of the systems most tolerant of disruption, since an unrepresentative ring detects nothing about the systems that matter.
  6. L3Define and record the emergency bypass path, its authority and its compensating measures, since bypass will occur and an undefined bypass is unbounded.
  7. L3Instrument the ring for behavioral change, not only for functional failure — a compromised update usually works correctly.
  8. L4Measure the proportion of updates traversing the ring against those bypassing it, and trend bypass rate.
  9. L4Compare the applied soak period against the current detection segment each cycle, and raise a finding where soak is shorter.
  10. L5Shorten the required soak by improving detection rather than by accepting more risk, since the two are the same trade viewed from opposite ends.

Measurement

Outcome

Percentage of updates traversing the staging ring for the full soak period.

Performance

Applied soak period against the current measured detection segment.

Evidence and Assessment

Evidence expected

Staging records with soak periods; integrity verification results per update; bypass records with authority and compensating measures.

Assessment procedure

Examine the declared soak period and its rationale against the measured detection segment; test that a sample of updates traversed the ring; examine the bypass rate and its authorizations.

Related Guidance

Inherits
  • SI-2
  • SR-11(1)
  • CM-3
Satisfies
  • ID.RA-01
  • PR.PS-02

Position in the Chain

Derived from the other controls’ own declarations, so the two directions cannot disagree.

Feeds

Nothing downstream — this control terminates a chain.

Where This Control Is Used

Derived, in every case, from the declaration at the other end: the forms whose techniques name this control, the artifacts whose producing and consuming controls include it, the layers whose control lists name it, and the roles its own accountability chart puts to work. Nothing here is authored on this page, so the sheet cannot claim an edge the other end does not.

Forms of Maneuver It Assesses

  • M2Defense in DepthEnsure no single failure is decisive.1 of 18 techniques — M2.18
  • M6DelayBuy decision time and prevent the adversary culminating on the objective.1 of 10 techniques — M6.10
  • M7CounterattackSeize the initiative and evict before the adversary reaches the objective.1 of 17 techniques — M7.16
  • M9Spoiling AttackDisrupt adversary staging before the attack is launched.1 of 9 techniques — M9.09

Terrain It Is Named On

  • T4Applications and WorkloadsUpdate integrity and staging governs supplier code arriving through this layer’s pipeline; T4 and T9 meet at the deployment gate.
  • T9Supply ChainUpdate integrity and staging — the decisive point stated as a control.

Artifacts It Stands On

  • producesUpdate integrity and staging recordHow updates arriving from suppliers are verified and staged before reaching production. The staging gate is a barrier in its own right and is monitored as one.
  • consumesSupplier terrain registerSuppliers as external actors on the overlay, with the access each holds, the paths that access implies, and the contract behind it.
  • consumesComponent provenance recordWhere components came from, from inventories, build manifests and supplier attestations — and which components have an origin that cannot be verified.

Roles It Puts to Work