ASOM-Fedv6.1Open the explorer
M4 · Shaping · 17 techniques

Obstacle / Canalization

Force the adversary onto ground you own and watch.

Intent, Mechanism and Indicator

Force the adversary onto ground you own and watch.

Role. The form that chooses the ground

Mechanism

Microsegmentation, egress control, allow-listing — herding lateral movement into monitored corridors.

Observable indicator

Observed lateral attempts land in instrumented segments.

Terrain It Consumes

Derived from where the form’s techniques are actually emplaced. The highlighted layer is the one the catalog names as its principal ground — the rest is terrain the form still has to touch, and that spread is how much of the estate employing it implicates.

Campaign Phasing

Dominance is taken from the campaign model; participation is derived from the techniques themselves. A form is usually present in more phases than it leads, and confusing the two is how a scheme ends up with no main effort.

PhaseRolePhase objectiveTechniques employed
Phase 0 — ShapeSet conditionsSupportingContinuous terrain preparation, zero-trust hardening, partnerships, threat intelligence.14 of 17
Phase I — DeterRaise adversary costDominant — main effortVisible hardening, a deception grid, and a stated attribution posture.13 of 17
Phase II — Seize InitiativeContest first contactDominant — main effortDetect early, canalize movement, and buy decision time.3 of 17

Phase 0 — Shape

Set conditions

Role
Supporting
Phase objective
Continuous terrain preparation, zero-trust hardening, partnerships, threat intelligence.
Techniques employed
14 of 17

Phase I — Deter

Raise adversary cost

Role
Dominant — main effort
Phase objective
Visible hardening, a deception grid, and a stated attribution posture.
Techniques employed
13 of 17

Phase II — Seize Initiative

Contest first contact

Role
Dominant — main effort
Phase objective
Detect early, canalize movement, and buy decision time.
Techniques employed
3 of 17

Employment

When to Choose It

Choose canalization when detection is adequate but placement is not — when you believe you would recognize lateral movement and cannot say where you would see it. It is also the correct answer wherever the estate contains ground you cannot patch or instrument freely: operational technology, legacy mission systems, supplier connections. If you cannot harden it, decide what it is allowed to reach.

Precondition

A sensor on the corridor. An obstacle that funnels movement into unmonitored ground has made the adversary’s route more predictable and told you nothing.

What It Costs

Paid in operations. Every denial is a future outage ticket, and the exception queue is permanent. Canalization is the form most likely to be quietly eroded by delivery pressure, because each individual exception is small, urgent, and argued by someone with a deadline.

Rules of Engagement

Emplacing and tightening obstacles is terrain-owner work under standing authority. Cutting a supplier or partner connection, or severing a segment carrying a statutory service, is a mission decision and belongs to the AO under the pre-agreed availability floor.

How It Fails

Not whether it fails — how. Each of these is a state in which the form is still reported as implemented and has stopped producing the advantage it was chosen for.

  1. Obstacles are emplaced without a covering sensor, so the corridor exists and nobody is watching it.
  2. Deny-lists are used where allow-lists were meant. A rule that names the bad paths is obsolete the moment the estate changes; a rule that names the permitted ones fails closed.
  3. The instrumented corridor becomes the convenient administrative path, so legitimate traffic saturates the exact channel that was supposed to be anomalous by construction.
  4. Rules decay toward permissiveness. Nobody removes a rule; everybody widens one. Measure the trend in rule breadth, not the count.
  5. Segmentation is asserted from configuration rather than tested from the adversary’s side, so a denied path is denied only in the diagram.

Techniques (17)

Grouped by the terrain layer each is emplaced on. Techniques are the perishable layer of the framework — they churn, the form does not — so each is stated as what it does and the observable that shows it is working, never as a product.

T2 · Devices2 techniques

  • M4.05

    Application Allow-Listing

    Constrain what may execute on decisive endpoints to what is approved and signed.

    IndicatorUnapproved executables do not run on decisive endpoints.

    Phases
    • 0
    • I
    Assessed by
  • M4.09

    Removable Media Control

    Constrain and log removable media on endpoints holding or reaching decisive data.

    IndicatorMedia use on decisive endpoints is either denied or recorded.

    Phases
    • 0
    Assessed by

T3 · Networks10 techniques

  • M4.01

    Microsegmentation

    Reduce reachability between workloads to what is declared, so lateral movement requires defeating policy rather than finding a route.

    IndicatorReachable-neighbor counts fall against a declared target.

    Phases
    • 0
    • I
    Assessed by
  • M4.02

    East-West Deny by Default

    Make the default answer between segments "no", with exceptions declared, owned and expiring.

    IndicatorNew east-west paths exist only where they are declared.

    Phases
    • 0
    • I
    Assessed by
  • M4.03

    Egress Filtering and Allow-Listing

    Constrain outbound destinations so command channels must use paths you inspect.

    IndicatorOutbound connections resolve to an allow-listed destination or fail.

    Phases
    • 0
    • I
    Assessed by
  • M4.04

    DNS Control and Sinkholing

    Route resolution through controlled resolvers, log it, and sinkhole known-bad and newly registered domains.

    IndicatorResolution to staged infrastructure fails and alerts.

    Phases
    • 0
    • I
    Assessed by
  • M4.06

    Administrative Path Restriction

    Confine administrative protocols to declared corridors from declared sources.

    IndicatorAdministrative access from outside the corridor fails and alerts.

    Phases
    • 0
    • I
    Assessed by
  • M4.07

    Cloud Boundary Enforcement

    Enforce account, VPC and role boundaries in the cloud with the same rigor as network segments on the ground.

    IndicatorCross-account reachability matches the declared design exactly.

    Phases
    • 0
    Assessed by
  • M4.08

    Instrumented Corridor Design

    Deliberately leave the paths you want an adversary to take, and instrument them heavily.

    IndicatorObserved lateral attempts land in instrumented segments.

    Phases
    • I
    • II
    Assessed by
  • M4.10

    Bastion and Jump-Host Enforcement

    Force privileged access to decisive systems through recorded, brokered hosts.

    IndicatorPrivileged sessions to decisive systems are recorded without exception.

    Phases
    • 0
    • I
    Assessed by
  • M4.11

    Protocol and Port Restriction

    Permit only the protocols the design requires, and treat the rest as a canalization opportunity.

    IndicatorNon-design protocols are denied at the boundary and counted.

    Phases
    • 0
    Assessed by
  • M4.12

    Denied-Path Register Enforcement

    Maintain the explicit register of paths that must never exist, and test continuously that they do not.

    IndicatorEvery denied path is tested on a stated cadence and holds.

    Phases
    • 0
    Assessed by

T6 · Operational Technology2 techniques

  • M4.13

    Operational Technology Segregation

    Separate control-system networks from the enterprise with an enforced, inspectable boundary rather than a documented intention.

    IndicatorNo route exists from an office endpoint to a controller without transiting an enforcement point.

    Phases
    • 0
    • I
    Assessed by
  • M4.14

    Control Protocol Constraint

    Permit only the industrial protocols and function codes the process requires, and deny engineering commands from outside the corridor.

    IndicatorWrite and program commands originate only from declared engineering stations.

    Phases
    • 0
    • I
    Assessed by

T8 · Facilities2 techniques

  • M4.15

    Physical Zone Segregation

    Divide facilities into zones whose boundaries are enforced and logged, so physical movement is as canalised as network movement.

    IndicatorMovement between physical zones is enforced and recorded.

    Phases
    • 0
    • I
    Assessed by
  • M4.16

    Maintenance Access Constraint

    Force vendor and remote maintenance onto a supervised, time-boxed path instead of standing access into the estate.

    IndicatorNo maintenance path is available outside an approved, supervised window.

    Phases
    • I
    • II
    Assessed by

T9 · Supply Chain1 technique

  • M4.17

    Supplier Access Canalisation

    Route every supplier into a defined broker rather than directly onto mission systems, so their traffic crosses ground you instrument.

    IndicatorNo supplier reaches a mission system except through the brokered path.

    Phases
    • I
    • II
    Assessed by

Controls That Assess It

Derived from the controls the form’s own techniques name, so the assessment surface cannot disagree with the catalog. A control reached by many techniques is load-bearing for this form; one reached by a single technique is not, and an assessor sampling it will learn very little.

By Family

By Control

  • KT-5 Barrier Sufficiency8 techniquesTo make the barriers on which negative reachability results depend into named, owned, monitored controls, so that the assurance KT-4 provides cannot be silently withdrawn.
  • TM-5 Connection and Denied-Path Register7 techniquesTo record connectivity as three distinct states — permitted, denied, unknown — so that reachability conclusions rest on tested denials rather than on absence of evidence.
  • KT-2 Decisive Point Protection Floor4 techniquesTo ensure designation produces protection, so that identifying a decisive point is an act with consequences rather than an annotation.
  • TM-4 Trust Zone Definition3 techniquesTo establish boundaries that something enforces, so that reachability and denied-path analysis rest on configuration rather than on design intent.
  • CE-2 Priority Intelligence Requirements2 techniquesTo direct analytic effort at named questions, so that collection and hunting answer what the accountable authority needs rather than processing what arrives.
  • FO-4 Operational Technology Terrain2 techniquesTo stop operational technology being scored as though it were a server estate, and to make the connections between the two declarable.
  • LC-3 Supplier Access Constraint2 techniquesTo keep supplier access scoped, observable, and revocable by the agency rather than by the supplier.
  • TM-2 Defensive Layer Classification2 techniquesTo make posture summable and comparable by layer, and to force an explicit ownership decision for every element.
  • CG-3 Rules of Engagement1 techniqueTo let operators act inside a known mandate rather than guessing at one, and to make the boundaries of that mandate legally and operationally sound.
  • DV-4 Execution Control1 techniqueTo deny the adversary the ability to run code on the ground they cross into, which is the cheapest point at which most engagements can be stopped.
  • DV-5 Device Lifecycle and Sanitization1 techniqueTo close the ends of the device lifecycle — the point of entry and the point of exit — where trust is granted and where it is most often left behind.
  • FC-1 Facility Terrain Identification1 techniqueTo resolve the estate to physical locations, so that defense, recovery and continuity can be reasoned about in the place things actually are.
  • FC-2 Physical Zone Boundary1 techniqueTo establish physical boundaries that constrain movement and produce a record of crossing, so that physical terrain can be defended in depth rather than at a perimeter.
  • FC-3 Maintenance Access Control1 techniqueTo ensure the maintenance path — authorized, expected, and outside the normal identity plane — is bounded in time and observed while open.
  • SM-6 Maneuver Effectiveness Validation1 techniqueTo replace assumed effectiveness with demonstrated effectiveness, so the coverage figure reflects what controls do rather than what was assumed of them.

The terrain controls test that segments and denied paths are registered rather than remembered; the key-terrain controls test reachability from an adversary position; the maneuver-tracking controls test that each obstacle has a named owner and an implementation state. Ask for a lateral-path audit result, not a firewall export.

Sequencing

A scheme names a sequence, not a set. These are the ordinary neighbors of this form — not a mandatory order, but the order in which each one’s preconditions are usually met.

Typically Preceded By

  • M2 Defense in DepthTrust zones and enforcement points are what obstacles are anchored to.
  • M3 EnvelopmentConstraining who may move first makes constraining where they may move tractable.

Typically Followed By

  • M5 AmbushA corridor you built and watch is the only place an ambush reliably pays.
  • M6 DelayMovement forced into one channel is movement you can throttle.

Named as a successor by M1 Screen / Guard, M2 Defense in Depth, M3 Envelopment, M9 Spoiling Attack. Derived from those forms’ own declarations, so the two directions of the sequence cannot disagree.

Named as a predecessor by M5 Ambush. Derived the same way, from the other direction.