Control Statement
The organization shall be able to sever a supplier's access within a stated period and continue the mission, and shall have demonstrated it.
Purpose. To retain the option of cutting a line of communication, so that a compromised or failed supplier is a decision rather than a dependency.
Discussion
Two halves, and the second is the one usually missing. Severing access is an identity and network action that LC-3's brokering makes achievable. Continuing the mission afterwards is an operational question that nobody answers until it is urgent — and for a managed-service provider or a sole-source integrator, the honest answer may be that the mission cannot continue, which is itself a finding worth having in advance rather than during. Severance without continuity is not a defensive option; it is an outage the agency chose.
Goals and Metrics
A metric that cannot come out badly is not a metric. Each of these is capable of reporting that the control is not working.
- Measured time to sever a supplier’s access in exercise
- Number of suppliers whose severance has been demonstrated within the stated period
- Mission services degraded beyond their statutory floor during a severance exercise
Accountability
Exactly one role is accountable, and every other role carries at least Informed — no control in the published catalog leaves a role with zero relationship to it. That is a stated property of how these were authored, not a coincidence, and not a claim that every role's work is worth equal attention here.
| AO | CTI | SOC | HUNT | PLAT | ISSO |
|---|---|---|---|---|---|
| Authorizing Official / CISO: Accountable | Cyber Threat Intelligence cell: Informed | SOC / Defensive Operations: Consulted | Hunt team: Informed | Platform and product owners: Responsible | Governance / RMF / ISSO: Consulted |
AO Authorizing Official / CISOCTI Cyber Threat Intelligence cellSOC SOC / Defensive OperationsHUNT Hunt teamPLAT Platform and product ownersISSO Governance / RMF / ISSO
- AccountableAuthorizing Official / CISO
- InformedCyber Threat Intelligence cell
- ConsultedSOC / Defensive Operations
- InformedHunt team
- ResponsiblePlatform and product owners
- ConsultedGovernance / RMF / ISSO
Inputs and Outputs
Consumes
- LC-1 Supplier Terrain RegisterSupplier register
- LC-3 Supplier Access ConstraintBrokered access forming the severance point
- FO-5 Statutory Availability FloorStatutory availability floor that must survive severance
Produces
- RC-5 Reconstitution ExerciseSeverance scenarios included in reconstitution exercise
- CE-5 Remediation Backlog PrioritizationSuppliers that cannot be severed within the period entering the backlog
- CE-6 Cycle Record and TrendDemonstration results recorded across cycles
Activities
- L2Define the procedure for severing each supplier's access.
- L2State the period within which severance must be achievable.
- L2Record the authority required to initiate severance.
- L3Assess mission continuity following severance for each supplier, and record where the mission cannot continue as a finding rather than as an accepted state.
- L3Derive the required period from what the supplier's access could do if turned hostile, with provenance per GA4, rather than from contractual notice terms.
- L3Demonstrate severance for suppliers whose reach includes a decisive point, rather than for the easiest supplier to test.
- L3Distinguish severance from termination, since access must be removable without ending the commercial relationship.
- L4Measure demonstrated severance time against the stated period and trend it.
- L4Measure the proportion of decisive-point-reaching suppliers whose severance has been demonstrated at all.
- L5Reduce single-supplier dependency where continuity assessment shows the mission cannot survive severance, since that is a resilience problem that no access control resolves.
Measurement
Percentage of decisive-point-reaching suppliers with demonstrated severance within the stated period.
Demonstrated severance time against stated period, trended.
Evidence and Assessment
Severance exercise record: supplier, elapsed time, mission impact observed; continuity assessment per supplier; findings where continuity fails.
Examine the procedure and its authorization; test severance for one supplier against the stated period; examine whether any decisive-point-reaching supplier has been tested; examine continuity findings.
Related Guidance
- SR-8
- IR-4
- CP-2(7)
- GV.SC-10
- RS.MA-01
Position in the Chain
Derived from the other controls’ own declarations, so the two directions cannot disagree.
Feeds
Nothing downstream — this control terminates a chain.
Where This Control Is Used
Derived, in every case, from the declaration at the other end: the forms whose techniques name this control, the artifacts whose producing and consuming controls include it, the layers whose control lists name it, and the roles its own accountability chart puts to work. Nothing here is authored on this page, so the sheet cannot claim an edge the other end does not.
Forms of Maneuver It Assesses
- M8Isolation / RetrogradeGive ground deliberately to preserve the force. Degrade gracefully; never fail open.1 of 17 techniques — M8.16
- M11ReconstitutionRestore the mission on evidence, not on hope — and prove it before you need it.1 of 11 techniques — M11.10
Terrain It Is Named On
- T9Supply ChainSupplier severance capability: the ability to cut a supply route on decision is the retrograde option on this layer.
Artifacts It Stands On
- producesSupplier severance demonstrationEvidence that each supplier’s access can actually be cut inside a stated period, without breaching the statutory availability floor — demonstrated, not asserted.
- consumesStatutory availability floorThe mission services whose availability is set by statute or regulation, and the floor below which degradation stops being a defensive choice. Bounds what may be pre-authorized and what may be degraded under contact.
- consumesSupplier terrain registerSuppliers as external actors on the overlay, with the access each holds, the paths that access implies, and the contract behind it.
- consumesSupplier access constraint recordHow supplier access is brokered, time-bounded and constrained — and the prohibition on standing supplier access to designated decisive points.
Roles It Puts to Work
- AccountableAuthorizing Official / CISOIntent, risk acceptance, and the scheme itself.
- ResponsiblePlatform and product ownersTheir own terrain. Obstacles get emplaced on their ground, so they site them.
- ConsultedSOC / Defensive OperationsManeuver. Executes fires and emplaces obstacles inside the standing rules of engagement.
- ConsultedGovernance / RMF / ISSOTranslating cycle outputs into FISMA and RMF artifacts, and owning the rules of engagement.
- InformedCyber Threat Intelligence cellFrame, Map and Fuse. The intelligence requirements, the threat courses of action, and the confidence levels.
- InformedHunt teamCounterattack. Works the hypotheses that Fuse raises.