Control Statement
Defensive moves shall be assigned to specific elements of terrain rather than declared at program level.
Purpose. To bind defensive intent to specific ground, so that coverage reflects what protects which element rather than what the program has bought.
Discussion
Program-level declaration is the single largest source of coverage inflation. "We do microsegmentation" is true of an organization and false of most of its elements, and the gap between those two statements is invisible until an assignment register forces the question element by element. This control is what makes an unprotected-asset report possible at all.
Goals and Metrics
A metric that cannot come out badly is not a metric. Each of these is capable of reporting that the control is not working.
- Percentage of assigned moves bound to a specific terrain element
- Number of program-level claims with no element-level assignment
- Proportion of assigned moves sited on enumerated avenues of approach
Accountability
Exactly one role is accountable, and every other role carries at least Informed — no control in the published catalog leaves a role with zero relationship to it. That is a stated property of how these were authored, not a coincidence, and not a claim that every role's work is worth equal attention here.
| AO | CTI | SOC | HUNT | PLAT | ISSO |
|---|---|---|---|---|---|
| Authorizing Official / CISO: Accountable | Cyber Threat Intelligence cell: Informed | SOC / Defensive Operations: Consulted | Hunt team: Informed | Platform and product owners: Responsible | Governance / RMF / ISSO: Consulted |
AO Authorizing Official / CISOCTI Cyber Threat Intelligence cellSOC SOC / Defensive OperationsHUNT Hunt teamPLAT Platform and product ownersISSO Governance / RMF / ISSO
- AccountableAuthorizing Official / CISO
- InformedCyber Threat Intelligence cell
- ConsultedSOC / Defensive Operations
- InformedHunt team
- ResponsiblePlatform and product owners
- ConsultedGovernance / RMF / ISSO
Inputs and Outputs
Consumes
- SM-1 Maneuver Catalog AdoptionThe adopted catalog of defensive forms
- TM-2 Defensive Layer ClassificationDefensive layer constraining applicable forms
- KT-3 Avenue of Approach AnalysisAvenues of approach requiring a move to be sited on them
- KT-5 Barrier SufficiencyBarriers requiring an obstacle move to maintain them
Produces
- SM-3 Implementation State TrackingAssignments requiring an implementation state
- KT-2 Decisive Point Protection FloorAssigned moves counted toward the decisive-point protection floor
- CE-4 Coverage and Residual Risk ComputationMitigation input to the coverage computation
Activities
- L2Assign moves to specific elements rather than declaring them at program level.
- L2Produce a report of elements carrying no assigned move.
- L2Record assignments in the register against the element.
- L3Derive assignment priority from asset weight (TM-3) and decisive point designation (KT-1) rather than from ease of assignment.
- L3Verify by sampling that a move recorded as assigned is genuinely present on that element, not present somewhere in the estate.
- L3Use bulk assignment for genuinely common patterns, but require the same sampling verification as individually assigned moves.
- L3Reconcile assignments after architectural change, since an element rebuilt on a new platform rarely retains its moves.
- L4Trend the count and weight of unprotected elements, and set a threshold on weight rather than on count.
- L4Measure the divergence between program-level claims and element-level assignment, which is the inflation figure.
- L5Revise assignment patterns where sampling repeatedly finds a class of move recorded but absent, since that indicates a systemic rather than a local gap.
Measurement
Percentage of defensive weight carried by elements with at least one assigned move.
Sampling pass rate on assignments verified present.
Evidence and Assessment
Per-asset maneuver assignment; unprotected-asset report; sampling record.
Examine assignments against the register; test that a sample of assigned moves is genuinely present on that element.
Related Guidance
- PL-2
- CA-2
- PR.PS-01
- ID.IM-01
Position in the Chain
Derived from the other controls’ own declarations, so the two directions cannot disagree.
Where This Control Is Used
Derived, in every case, from the declaration at the other end: the forms whose techniques name this control, the artifacts whose producing and consuming controls include it, the layers whose control lists name it, and the roles its own accountability chart puts to work. Nothing here is authored on this page, so the sheet cannot claim an edge the other end does not.
Forms of Maneuver It Assesses
- M3EnvelopmentMake identity, not network location, the decisive plane — surround the adversary with policy.9 of 20 techniques — M3.01, M3.02, M3.03, M3.04, M3.09, M3.10, M3.12, M3.16, M3.17
- M2Defense in DepthEnsure no single failure is decisive.3 of 18 techniques — M2.06, M2.07, M2.08
- M6DelayBuy decision time and prevent the adversary culminating on the objective.3 of 10 techniques — M6.01, M6.02, M6.07
Terrain It Is Named On
- T3NetworksObstacle and canalization maneuvers are assigned to specific segments here; an unassigned maneuver is an intention.
Artifacts It Stands On
- producesScheme of maneuverOne graphic and one narrative: which forms of maneuver are sited where, in what sequence. The assignment record behind it carries the element, the avenue and the implementation state for every move.
- consumesCyber Terrain OverlayThe positional map of the estate: every element with a defensive layer, a defensive weight, a named accountable owner and its adjacencies. Not an asset inventory — an inventory enumerates, an overlay positions.
- consumesAvenue-of-approach analysisThe enumerated routes an adversary could take toward each decisive point, including physical, supplier and maintenance routes, with unassessed routes recorded as intelligence gaps rather than as absence of risk.
- consumesBarrier sufficiency registerThe specific barriers holding the line where reachability is prevented, each with a named enforcing owner. What the reachability result depends on, made explicit so its erosion is visible.
- consumesThreat course-of-action sketchTwo courses of action, most likely and most dangerous, drawn against the decisive points already designated. Each is a route across ground the estate really has, not a category of threat.
- consumesAdopted maneuver catalogThe forms of defensive maneuver the organization has adopted, each with the effectiveness it is assumed to deliver — recorded so the assumption can later be validated rather than believed indefinitely.
Roles It Puts to Work
- AccountableAuthorizing Official / CISOIntent, risk acceptance, and the scheme itself.
- ResponsiblePlatform and product ownersTheir own terrain. Obstacles get emplaced on their ground, so they site them.
- ConsultedSOC / Defensive OperationsManeuver. Executes fires and emplaces obstacles inside the standing rules of engagement.
- ConsultedGovernance / RMF / ISSOTranslating cycle outputs into FISMA and RMF artifacts, and owning the rules of engagement.
- InformedCyber Threat Intelligence cellFrame, Map and Fuse. The intelligence requirements, the threat courses of action, and the confidence levels.
- InformedHunt teamCounterattack. Works the hypotheses that Fuse raises.