Control Statement
Deception shall be emplaced across designated terrain, and every interaction with a deception element shall raise an alert that reaches a human within a defined period.
Purpose. To obtain detection with no false-positive budget, and to ensure that signal is acted on rather than queued.
Discussion
A deception element has a property no other detection has: nothing legitimate touches it, so an interaction is an incident with no triage burden and no false-positive budget. That property is destroyed by routing the alert into a queue triaged tomorrow, which is the ordinary failure and the reason the alert path is written into the control rather than left to detection engineering. The second requirement is placement: deception emplaced where an adversary would not look is decoration, and placement should follow the avenues enumerated under KT-3 rather than convenience.
Goals and Metrics
A metric that cannot come out badly is not a metric. Each of these is capable of reporting that the control is not working.
- Terrain layers carrying emplaced deception, against those designated
- Number of designated avenues of approach with no deception on them
- Elapsed time from deception interaction to human response
- Percentage of interactions routed to a named responder rather than a shared queue
Accountability
Exactly one role is accountable, and every other role carries at least Informed — no control in the published catalog leaves a role with zero relationship to it. That is a stated property of how these were authored, not a coincidence, and not a claim that every role's work is worth equal attention here.
| AO | CTI | SOC | HUNT | PLAT | ISSO |
|---|---|---|---|---|---|
| Authorizing Official / CISO: Accountable | Cyber Threat Intelligence cell: Consulted | SOC / Defensive Operations: Responsible | Hunt team: Consulted | Platform and product owners: Informed | Governance / RMF / ISSO: Informed |
AO Authorizing Official / CISOCTI Cyber Threat Intelligence cellSOC SOC / Defensive OperationsHUNT Hunt teamPLAT Platform and product ownersISSO Governance / RMF / ISSO
- AccountableAuthorizing Official / CISO
- ConsultedCyber Threat Intelligence cell
- ResponsibleSOC / Defensive Operations
- ConsultedHunt team
- InformedPlatform and product owners
- InformedGovernance / RMF / ISSO
Inputs and Outputs
Consumes
- KT-3 Avenue of Approach AnalysisAvenues of approach that determine where deception is worth placing
- KT-1 Decisive Point IdentificationDecisive points whose approaches are seeded first
- TM-2 Defensive Layer ClassificationTerrain classification, so decoys are plausible for their layer
- TA-1 Decision Loop MeasurementDecide-segment measurement the response target is set against
Produces
- EN-1 Event Declaration and TriageInteraction alerts carrying no false-positive budget
- TA-1 Decision Loop MeasurementDetection events contributing to the detect segment
- CE-4 Coverage and Residual Risk ComputationEmplacement coverage feeding the posture computation
Activities
- L2Emplace deception elements across designated terrain.
- L2Monitor every deception element for interaction.
- L2Raise an alert on interaction.
- L3Place deception along the avenues of approach enumerated under
KT-3and adjacent to designated decisive points, rather than where placement is easiest. - L3Define the period within which a deception alert must reach a human, derived from the decide segment measured under
TA-1, with provenance perGA4. - L3Ensure deception elements are indistinguishable from real ones to an adversary and identifiable to defenders, and record how each property is achieved.
- L3Ensure no legitimate process, scanner or inventory tool interacts with deception elements, so the no-false-positive property holds in practice.
- L3Extend deception across terrain layers — identity, data, network, endpoint — rather than a single layer, so it is present wherever movement occurs.
- L4Measure elapsed time from deception interaction to human response, against the defined period.
- L4Test emplacement by exercise: a red team given an objective should encounter deception, and an exercise in which none is encountered is a placement finding.
- L5Re-place deception from observed adversary movement and from engagements, rather than leaving an initial layout in place indefinitely.
Measurement
Elapsed time from deception interaction to human response.
Terrain layers carrying emplaced deception, against those designated.
Evidence and Assessment
Emplacement record by terrain layer; interaction alerts with response times; exclusion configuration; exercise encounter records.
Examine emplacement against enumerated avenues; test that an interaction reaches a human within the defined period; test that no legitimate tooling interacts with deception elements; examine whether a recent exercise encountered deception.
Related Guidance
- SC-26
- SC-30
- SI-4
- DE.CM-01
- DE.AE-02
Position in the Chain
Derived from the other controls’ own declarations, so the two directions cannot disagree.
Fed By
Nothing upstream — this control starts a chain.
Where This Control Is Used
Derived, in every case, from the declaration at the other end: the forms whose techniques name this control, the artifacts whose producing and consuming controls include it, the layers whose control lists name it, and the roles its own accountability chart puts to work. Nothing here is authored on this page, so the sheet cannot claim an edge the other end does not.
Forms of Maneuver It Assesses
- M5AmbushTrade space for information and time, and impose cost.13 of 13 techniques — M5.01, M5.02, M5.03, M5.04, M5.05, M5.06, M5.07, M5.08, M5.09, M5.10, M5.11, M5.12, M5.13
Terrain It Is Named On
Applies to all ten layersDeception is emplaced per layer, on the approaches to that layer’s decisive point — the one detection here with no false-positive budget.
Artifacts It Stands On
- consumesCyber Terrain OverlayThe positional map of the estate: every element with a defensive layer, a defensive weight, a named accountable owner and its adjacencies. Not an asset inventory — an inventory enumerates, an overlay positions.
- consumesDecisive point registerThe elements whose control confers decisive advantage — each carrying the evidence that raised it above merely important, and the protection floor it owes as a result.
- consumesAvenue-of-approach analysisThe enumerated routes an adversary could take toward each decisive point, including physical, supplier and maintenance routes, with unassessed routes recorded as intelligence gaps rather than as absence of risk.
- consumesThreat course-of-action sketchTwo courses of action, most likely and most dangerous, drawn against the decisive points already designated. Each is a route across ground the estate really has, not a category of threat.
- consumesDefender decision loop measurementDetect to decide to contain, measured per incident from the change record’s timestamps and reported as a distribution rather than as a mean.
- consumesTemporal advantage resultDefender decision loop against adversary dwell, reported as a ratio against the threshold set at Frame, with the result written as a word: met, or not met. The framework’s single honest scoreboard.
Roles It Puts to Work
- AccountableAuthorizing Official / CISOIntent, risk acceptance, and the scheme itself.
- ResponsibleSOC / Defensive OperationsManeuver. Executes fires and emplaces obstacles inside the standing rules of engagement.
- ConsultedCyber Threat Intelligence cellFrame, Map and Fuse. The intelligence requirements, the threat courses of action, and the confidence levels.
- ConsultedHunt teamCounterattack. Works the hypotheses that Fuse raises.
- InformedPlatform and product ownersTheir own terrain. Obstacles get emplaced on their ground, so they site them.
- InformedGovernance / RMF / ISSOTranslating cycle outputs into FISMA and RMF artifacts, and owning the rules of engagement.