Intent, Mechanism and Indicator
Ensure no single failure is decisive.
Role. The form that makes no single failure decisive
Layered controls across every terrain layer; TIC 3.0 trust zones; zero-trust segmentation.
An adversary must defeat three or more independent controls to reach data terrain.
Terrain It Consumes
Derived from where the form’s techniques are actually emplaced. The highlighted layer is the one the catalog names as its principal ground — the rest is terrain the form still has to touch, and that spread is how much of the estate employing it implicates.
- T2DevicesThe entry fords3 techniques
- T3NetworksThe corridors2 techniques · principal ground
- T4Applications and WorkloadsThe urban terrain3 techniques
- T5DataThe objective4 techniques
- T6Operational TechnologyGround you cannot maneuver freely on1 technique
- T7WorkforceTerrain that is also the force1 technique
- T8FacilitiesThe physical boundary1 technique
- T9Supply ChainThe lines of communication1 technique
- TXCross-CuttingThe enablers of movement2 techniques
Campaign Phasing
Dominance is taken from the campaign model; participation is derived from the techniques themselves. A form is usually present in more phases than it leads, and confusing the two is how a scheme ends up with no main effort.
| Phase | Role | Phase objective | Techniques employed |
|---|---|---|---|
| Phase 0 — ShapeSet conditions | Dominant — main effort | Continuous terrain preparation, zero-trust hardening, partnerships, threat intelligence. | 18 of 18 |
| Phase I — DeterRaise adversary cost | Supporting | Visible hardening, a deception grid, and a stated attribution posture. | 2 of 18 |
| Phase III — DominateDefeat the attempt | Supporting | Hunt, contain, evict. | 1 of 18 |
| Phase IV — StabilizeRestore secure operations | Supporting | Eradicate, verify, and preserve availability through the recovery. | 1 of 18 |
Phase 0 — Shape
Set conditions
- Role
- Dominant — main effort
- Phase objective
- Continuous terrain preparation, zero-trust hardening, partnerships, threat intelligence.
- Techniques employed
- 18 of 18
Phase I — Deter
Raise adversary cost
- Role
- Supporting
- Phase objective
- Visible hardening, a deception grid, and a stated attribution posture.
- Techniques employed
- 2 of 18
Phase III — Dominate
Defeat the attempt
- Role
- Supporting
- Phase objective
- Hunt, contain, evict.
- Techniques employed
- 1 of 18
Phase IV — Stabilize
Restore secure operations
- Role
- Supporting
- Phase objective
- Eradicate, verify, and preserve availability through the recovery.
- Techniques employed
- 1 of 18
Employment
When to Choose It
Choose depth when the estate cannot state how many independent controls stand between an internet-facing surface and its most sensitive records, or when the answer turns out to be one. It is the form to reach for after a near miss in which a single control held and nobody can explain what would have happened had it not.
Precondition
A terrain overlay that names the crown-jewel record set. Depth is measured toward something; layering applied uniformly across an estate is not depth, it is spend.
What It Costs
The highest sustained cost of the eleven, and the least visible. Each layer is a license, an integration, an owner, an upgrade path and a failure mode of its own. Depth also imposes a permanent tax on change: every new service must be threaded through every layer, and the layers are where delivery teams learn to route around security.
Rules of Engagement
Emplacement and maintenance are terrain-owner work under standing authority. Removing a layer — decommissioning a control, granting a permanent exception — is a risk-acceptance decision and belongs to the Authorizing Official.
How It Fails
Not whether it fails — how. Each of these is a state in which the form is still reported as implemented and has stopped producing the advantage it was chosen for.
- The layers share a dependency. Three controls that all trust the same identity plane, the same endpoint agent, or the same vendor are one control wearing three badges, and they fail on the same afternoon.
- Depth is counted in products rather than in independence, so the metric rises while the adversary’s path length does not.
- A layer is defeated silently. Depth without instrumentation on each layer means the defender learns the outer two failed only when the third one does.
- Depth is applied evenly across the estate, which is the same as designating no main effort — the crown jewels end up defended exactly as hard as the cafeteria menu.
Techniques (18)
Grouped by the terrain layer each is emplaced on. Techniques are the perishable layer of the framework — they churn, the form does not — so each is stated as what it does and the observable that shows it is working, never as a product.
T2 · Devices — 3 techniques
- M2.05
Endpoint Detection and Response Coverage
Achieve and prove sensor coverage across the managed fleet, with unmanaged devices treated as a measured gap rather than an assumption.
IndicatorCoverage is reconciled to the inventory, not to the console.
Phases- 0
- M2.06
Device Posture Gating
Make device health a precondition of access, so a compromised or non-compliant endpoint cannot spend a valid credential.
IndicatorFailing posture denies access rather than raising a ticket.
Phases- 0
- I
- M2.11
Workload Hardening Baseline
Hold servers, images and containers to a declared baseline, and treat drift from it as a finding.
IndicatorBaseline drift is detected on a stated cadence and dispositioned.
Phases- 0
T3 · Networks — 2 techniques
- M2.01
Trust Zone Architecture
Define trust zones that reflect real boundaries and assurance differences, and record which elements sit in which.
IndicatorEvery element on the terrain resolves to exactly one declared zone.
Phases- 0
- M2.02
Policy Enforcement Point Placement
Place an enforcement point at every zone boundary so that crossing is a decision, not a route.
IndicatorNo path reaches a higher-trust zone without transiting an enforcement point.
Phases- 0
T4 · Applications and Workloads — 3 techniques
- M2.07
Web Application Protection
Front public applications with request-level inspection tuned to the application, not to a generic ruleset.
IndicatorApplication-layer attacks are stopped at the edge and counted.
Phases- 0
- M2.08
API Authorization Enforcement
Enforce per-call authorization at an API gateway rather than trusting network position or a shared key.
IndicatorNo API path authorizes on network location alone.
Phases- 0
- M2.12
Secrets Management
Remove long-lived secrets from code, images and configuration into brokered, rotated, audited storage.
IndicatorNo decisive system authenticates with a static embedded secret.
Phases- 0
T5 · Data — 4 techniques
- M2.03
Crown-Jewel Enclave
Isolate the decisive data behind its own enforcement point, with its own authorization policy and its own telemetry.
IndicatorReaching the data layer requires defeating controls nothing else shares.
Phases- 0
- I
- M2.09
Data-at-Rest Encryption and Key Separation
Encrypt decisive data with keys held outside the system that reads it, so storage compromise is not data compromise.
IndicatorExfiltrating storage does not yield readable records.
Phases- 0
- M2.10
Egress Data Loss Prevention
Inspect and constrain outbound movement of the record types the campaign exists to protect.
IndicatorBulk movement of protected records is blocked or alerted at egress.
Phases- 0
- III
- M2.13
Backup Isolation and Immutability
Hold recovery data outside the blast radius of the production identity plane and make it immutable for its retention window.
IndicatorRecovery is possible after full compromise of production identity.
Phases- 0
- IV
T6 · Operational Technology — 1 technique
- M2.15
Safety Instrumented Layer Integrity
Keep the safety layer independent of the control layer, so a compromise of operations cannot defeat the function that prevents harm.
IndicatorSafety functions hold when the control network is assumed hostile.
Phases- 0
T7 · Workforce — 1 technique
- M2.16
Role-Based Privilege Minimization
Give each role the least authority its work requires, so a compromised person yields the least ground.
IndicatorNo role holds authority its documented duties do not require.
Phases- 0
T8 · Facilities — 1 technique
- M2.17
Facility Defense in Depth
Layer physical controls so that defeating one barrier does not deliver the floor, the rack or the media inside it.
IndicatorReaching a decisive asset physically requires defeating three independent controls.
Phases- 0
T9 · Supply Chain — 1 technique
- M2.18
Component Provenance Verification
Know what is inside what you deploy, and verify it came from who it claims, before it runs on your ground.
IndicatorEvery deployed component resolves to a verified origin and a current inventory.
Phases- 0
TX · Cross-Cutting — 2 techniques
- M2.04
Independent Control Redundancy
Ensure the controls guarding key terrain fail independently — no shared agent, identity, console or vendor across a protection floor.
IndicatorNo single control, credential or vendor failure exposes a decisive point.
Phases- 0
- M2.14
Control Failure Detection
Detect when a control stops working — sensor silent, policy unapplied, agent removed — as a security event in its own right.
IndicatorA silent control is detected in hours, not at the next assessment.
Phases- 0
Controls That Assess It
Derived from the controls the form’s own techniques name, so the assessment surface cannot disagree with the catalog. A control reached by many techniques is load-bearing for this form; one reached by a single technique is not, and an assessor sampling it will learn very little.
By Family
- KTKey Terrain and Decisive Points3 controls · reaches 11 of 18 techniques
- SMScheme of Maneuver4 controls · reaches 6 of 18 techniques
- TMTerrain Management5 controls · reaches 5 of 18 techniques
- DVDevices Terrain4 controls · reaches 4 of 18 techniques
- FOFederal Obligations2 controls · reaches 2 of 18 techniques
- IDIdentity Terrain2 controls · reaches 2 of 18 techniques
- CECycle Execution and Assurance1 control · reaches 1 of 18 techniques
- CGCommand and Governance1 control · reaches 1 of 18 techniques
- FCFacilities Terrain2 controls · reaches 1 of 18 techniques
- LCLines of Communication2 controls · reaches 1 of 18 techniques
- WFWorkforce Terrain2 controls · reaches 1 of 18 techniques
By Control
- KT-2 Decisive Point Protection Floor11 techniques — To ensure designation produces protection, so that identifying a decisive point is an act with consequences rather than an annotation.
- SM-2 Maneuver Assignment3 techniques — To bind defensive intent to specific ground, so that coverage reflects what protects which element rather than what the program has bought.
- DV-3 Endpoint Sensor Coverage and Liveness2 techniques — To know what the estate can actually see, and to detect the loss of that visibility as an event rather than at the next assessment.
- KT-5 Barrier Sufficiency2 techniques — To make the barriers on which negative reachability results depend into named, owned, monitored controls, so that the assurance KT-4 provides cannot be silently withdrawn.
- SM-3 Implementation State Tracking2 techniques — To make the coverage figure reflect what is defending the estate rather than what is intended to, by weighting mitigation by implementation state.
- TM-4 Trust Zone Definition2 techniques — To establish boundaries that something enforces, so that reachability and denied-path analysis rest on configuration rather than on design intent.
- TM-6 Terrain Currency2 techniques — To keep the overlay current against both the clock and the change, so that planning is conducted against ground as it currently is.
- CE-6 Cycle Record and Trend1 technique — To answer whether the program is improving — a question no point-in-time assessment can address.
- CG-4 Findings Disposition1 technique — To ensure every finding reaches a decision, so that the open set reflects work in progress rather than accumulated neglect.
- DV-1 Device Terrain Identification1 technique — To make devices positional, so that the crossings into the estate are known and can be defended rather than merely counted.
- DV-2 Device Posture as an Access Precondition1 technique — To ensure a compromised or non-compliant device cannot spend a valid credential, closing the gap `M3` Envelopment leaves when identity alone is enforced.
- DV-4 Execution Control1 technique — To deny the adversary the ability to run code on the ground they cross into, which is the cheapest point at which most engagements can be stopped.
- FC-1 Facility Terrain Identification1 technique — To resolve the estate to physical locations, so that defense, recovery and continuity can be reasoned about in the place things actually are.
- FC-2 Physical Zone Boundary1 technique — To establish physical boundaries that constrain movement and produce a record of crossing, so that physical terrain can be defended in depth rather than at a perimeter.
- FO-2 Controlled Unclassified Information Handling1 technique — To make CUI movement declarable and therefore detectable, so that handling obligations attach to information rather than to systems.
- FO-4 Operational Technology Terrain1 technique — To stop operational technology being scored as though it were a server estate, and to make the connections between the two declarable.
- ID-2 Credential Strength and Binding1 technique — To ensure the credential is as strong as the access behind it, so that proofing and authentication assurance are matched rather than assumed.
- ID-5 Authorization Decision Integrity1 technique — To ensure the policy that governs movement is actually consulted and cannot be altered without trace.
- KT-1 Decisive Point Identification1 technique — To concentrate defensive effort on the small number of elements whose loss is decisive, so that priority is a stated judgment rather than an emergent property of the asset register.
- LC-2 Component Provenance1 technique — To know where deployed components came from and what is inside them, so that a compromise disclosed anywhere can be located here.
- LC-4 Update Integrity and Staging1 technique — To limit the blast radius of a compromised trusted update, so that supply chain compromise reaches a ring rather than the estate.
- SM-5 Branches and Sequels1 technique — To decide contingency responses before contact, so that the decision loop under pressure is a selection rather than a design exercise.
- SM-6 Maneuver Effectiveness Validation1 technique — To replace assumed effectiveness with demonstrated effectiveness, so the coverage figure reflects what controls do rather than what was assumed of them.
- TM-2 Defensive Layer Classification1 technique — To make posture summable and comparable by layer, and to force an explicit ownership decision for every element.
- TM-3 Asset Weighting1 technique — To convert an undifferentiated inventory into a priority order, so that coverage figures carry meaning and investment can be argued from mission consequence.
- TM-5 Connection and Denied-Path Register1 technique — To record connectivity as three distinct states — permitted, denied, unknown — so that reachability conclusions rest on tested denials rather than on absence of evidence.
- WF-2 Privileged Human Register1 technique — To ensure privilege is held by accountable people, so that every privileged action has a person behind it.
- WF-3 Role-Based Readiness1 technique — To prepare people for the attacks their role attracts, and to know whether the preparation worked.
Reachability analysis is the honest test: not how many controls exist, but how many independent ones an adversary must defeat to touch the objective. The control-failure and coverage controls test whether a defeated layer is detectable. No control tests for correlated failure across layers; that has to be argued in the scheme and reviewed by a human.
Sequencing
A scheme names a sequence, not a set. These are the ordinary neighbors of this form — not a mandatory order, but the order in which each one’s preconditions are usually met.
Typically Preceded By
- M1 Screen / GuardYou cannot layer ground you have not enumerated.
Typically Followed By
- M3 EnvelopmentLayers need an enforcement plane to sit on, and identity is it.
- M4 Obstacle / CanalizationDepth without canalization leaves the adversary free to choose which layer to test.
Named as a successor by M1 Screen / Guard, M9 Spoiling Attack, M10 Exploitation & Pursuit, M11 Reconstitution. Derived from those forms’ own declarations, so the two directions of the sequence cannot disagree.
Named as a predecessor by M3 Envelopment, M4 Obstacle / Canalization. Derived the same way, from the other direction.