ASOM-Fedv6.1Open the explorer
Program · Cybersecurity and Infrastructure Security Agency

Trusted Internet Connections 3.0

The federal program that replaced a single physical internet gateway with trust zones and distributed policy enforcement, together with a capability catalog and a set of use cases.

4/4Obligations addressedEvery one of them carries a stated gap; none of them is claimed as satisfied.
9Controls carrying itEach with an evidence artifact and an assessment procedure
3Stated boundariesWhat this framework does not do for this regime
The Claim

What This Framework Contributes.

The framework borrows TIC’s boundary vocabulary and contributes nothing to its capability catalog. It draws the zones an agency already documents and then asks what can cross them.

The Boundary

What it does not do for TIC 3.0.

Read this before the crosswalk, not after it. A reader who takes the mappings below as coverage of TIC 3.0 will be wrong in a way that is expensive to discover later.

Obligation by Obligation

4 elements, each with what is missing.

TIC 3.0 publishes no control-level index for a catalog to be turned round against, so these edges are authored rather than derived. Each one is stated as a citation and resolved against the real catalog when the site is built: the prose can go stale, the links cannot go dead.

Trust zones

2 controls · T3 Networks

Traffic is segmented into zones of differing trust, and the boundaries between them are defined explicitly rather than implied by physical topology.

What the framework supplies

Zone definition is a control here, and the overlay is drawn in the zones the agency already documents — so a boundary on the map is the same boundary the program recognizes.

What it does not

The framework does not define an agency’s zones for it, and it says nothing about which trust level a given zone should carry.

Policy enforcement points

3 controls · T3 Networks

Security capabilities are applied at distributed enforcement points positioned between trust zones, rather than at a single physical gateway.

What the framework supplies

An enforcement point is a locatable element on the overlay, which is what allows it to be designated a decisive point and given a protection floor that does not move with the budget.

What it does not

The capability catalog is not crosswalked. A framework control that names an enforcement point makes no claim about which of the program’s capabilities it implements.

Declared traffic flows

2 controls · T3 Networks

The flows crossing each boundary are known, and the ones that are not permitted are known to be not permitted.

What the framework supplies

The connection and denied-path register records both halves. A denied path that nothing tests is a belief, so avenue-of-approach analysis exists to test it.

What it does not

Enforcement is the agency’s. The register states what should cross and what should not; whether the device agrees is an assessment result, not a register entry.

Telemetry and shared visibility

2 controls · TX Cross-Cutting

Agencies provide the program with visibility of traffic crossing their boundaries, in the formats the program specifies.

What the framework supplies

Nothing directly. The framework requires that crossings be observed and that the observation stay current, which is a precondition for having anything to share.

What it does not

No feed, no format, no participation in the program’s reporting. Observation required by this framework is the agency’s own and stays with the agency.

Authored edges, derived resolution. Each program element cites control ids and, where the ground is specific, the terrain layer it sits on. What the framework takes from this source and what it declines to take is set out in sources and provenance; the controls named on this page each carry their full lineage on their own sheet.