Control Statement
The means of recovery shall be held outside the trust boundary of the production identity plane, such that compromise of production credentials cannot reach, alter, or destroy them.
Purpose. To ensure the recovery capability survives the compromise it exists to recover from.
Discussion
This is the ransomware lesson stated as a control. Backups that authenticate against the production identity provider are reachable by anyone who holds production administrative credentials, which is precisely the position an adversary occupies at the moment recovery becomes necessary. The operative test is narrower and more useful than "held outside the boundary": can a production administrator credential, used adversarially, reach the recovery store? That question has a demonstrable answer, and a great many recovery architectures that satisfy the general statement fail the specific test.
Goals and Metrics
A metric that cannot come out badly is not a metric. Each of these is capable of reporting that the control is not working.
- Number of recovery repositories reachable using production credentials
- Whether isolation has been tested by attempting access with production credentials
Accountability
Exactly one role is accountable, and every other role carries at least Informed — no control in the published catalog leaves a role with zero relationship to it. That is a stated property of how these were authored, not a coincidence, and not a claim that every role's work is worth equal attention here.
| AO | CTI | SOC | HUNT | PLAT | ISSO |
|---|---|---|---|---|---|
| Authorizing Official / CISO: Accountable | Cyber Threat Intelligence cell: Informed | SOC / Defensive Operations: Consulted | Hunt team: Consulted | Platform and product owners: Responsible | Governance / RMF / ISSO: Informed |
AO Authorizing Official / CISOCTI Cyber Threat Intelligence cellSOC SOC / Defensive OperationsHUNT Hunt teamPLAT Platform and product ownersISSO Governance / RMF / ISSO
- AccountableAuthorizing Official / CISO
- InformedCyber Threat Intelligence cell
- ConsultedSOC / Defensive Operations
- ConsultedHunt team
- ResponsiblePlatform and product owners
- InformedGovernance / RMF / ISSO
Inputs and Outputs
Consumes
- TM-4 Trust Zone DefinitionTrust zone boundaries defining what production credentials can reach
- RC-1 Recovery ObjectivesRecovery point objectives determining retention
Produces
- RC-3 Trusted Rebuild PathTrusted media source for the rebuild path
- RC-4 Recovery Integrity VerificationIndependent store supporting integrity verification
- KT-5 Barrier SufficiencyThe isolation boundary as a load-bearing barrier requiring monitoring
Activities
- L2Place the recovery store in a trust zone separate from production.
- L2Record the authentication path by which the recovery store is reached.
- L2Raise a finding where the recovery store shares an identity provider with production.
- L3Test whether a production administrator credential can reach, alter or delete the recovery store, rather than inferring independence from architecture.
- L3Verify that the credentials governing the recovery store are issued, held and rotated independently of production.
- L3Apply the same independence test to the recovery store's own management plane, including its console, its orchestration and its monitoring.
- L3Verify immutability or retention locking where the platform supports it, and record where it does not.
- L4Test independence on a defined cadence and after any change to either identity plane, and trend the pass rate.
- L4Measure the elapsed time between an identity-plane change and the next independence test, since that interval is the exposure window.
- L5Re-derive the independence test from adversary tradecraft observed in engagements and in sector reporting, rather than testing only the paths the original design anticipated.
Measurement
Result of the production-credential reachability test against the recovery store.
Currency of the last independence test relative to the last identity-plane change.
Evidence and Assessment
Terrain overlay showing the recovery zone and its trust boundary; credential separation record; independence test results.
Test whether a production administrator credential can reach the recovery store; examine the authentication path for independence; test the recovery store's management plane by the same method.
Related Guidance
- CP-6
- CP-9(3)
- SC-28
- RC.RP-01
- PR.DS-11
- PR.IR-03
Position in the Chain
Derived from the other controls’ own declarations, so the two directions cannot disagree.
Fed By
Nothing upstream — this control starts a chain.
Where This Control Is Used
Derived, in every case, from the declaration at the other end: the forms whose techniques name this control, the artifacts whose producing and consuming controls include it, the layers whose control lists name it, and the roles its own accountability chart puts to work. Nothing here is authored on this page, so the sheet cannot claim an edge the other end does not.
Forms of Maneuver It Assesses
- M11ReconstitutionRestore the mission on evidence, not on hope — and prove it before you need it.1 of 11 techniques — M11.02
Terrain It Is Named On
- T8FacilitiesIsolated recovery capability has a physical location, and its separation from production is partly a facilities property.
Artifacts It Stands On
- producesTrusted rebuild pathA documented, walked path to rebuild each decisive point inside its recovery time budget, from media held outside the production identity plane — including a path for the identity plane itself.
- producesIsolated recovery capability recordThe means of recovery held outside the production identity plane, and the isolation boundary that keeps it there — itself a load-bearing barrier that has to be monitored.
- consumesTrust zones and the connection registerThe zone boundaries and the permitted- and denied-path register — the graph reachability is actually walked over, reconciled against observed flow telemetry rather than against intended configuration.
- consumesRecovery objectives registerA declared recovery time and recovery point objective per mission service, agreed with the service owner and constrained by statutory deadlines rather than by what is currently achievable.
Roles It Puts to Work
- AccountableAuthorizing Official / CISOIntent, risk acceptance, and the scheme itself.
- ResponsiblePlatform and product ownersTheir own terrain. Obstacles get emplaced on their ground, so they site them.
- ConsultedSOC / Defensive OperationsManeuver. Executes fires and emplaces obstacles inside the standing rules of engagement.
- ConsultedHunt teamCounterattack. Works the hypotheses that Fuse raises.
- InformedCyber Threat Intelligence cellFrame, Map and Fuse. The intelligence requirements, the threat courses of action, and the confidence levels.
- InformedGovernance / RMF / ISSOTranslating cycle outputs into FISMA and RMF artifacts, and owning the rules of engagement.