Control Statement
Defensive actions that may be executed without escalation shall be defined in advance and approved by the accountable authority.
Purpose. To remove authority latency from the decision loop, so that the segment most programs cannot shorten with tooling is shortened by governance.
Discussion
This is the highest-leverage control in the family and the cheapest to implement, because it costs no technology. TA-1's segment breakdown usually shows the decide segment dominating the loop, and decide latency is almost entirely the time spent locating someone with authority. Pre-authorization converts that from an incident-time search into a design-time decision. The constraint is that it must be genuinely bounded: an authority so broad that it permits degrading a public service without reference will not survive its first use, and one so narrow that every real action falls outside it changes nothing.
Goals and Metrics
A metric that cannot come out badly is not a metric. Each of these is capable of reporting that the control is not working.
- Percentage of routine containment actions that are pre-authorized
- Number of incidents in which containment waited on an authorization that could have been pre-granted
Accountability
Exactly one role is accountable, and every other role carries at least Informed — no control in the published catalog leaves a role with zero relationship to it. That is a stated property of how these were authored, not a coincidence, and not a claim that every role's work is worth equal attention here.
| AO | CTI | SOC | HUNT | PLAT | ISSO |
|---|---|---|---|---|---|
| Authorizing Official / CISO: Accountable | Cyber Threat Intelligence cell: Informed | SOC / Defensive Operations: Consulted | Hunt team: Informed | Platform and product owners: Informed | Governance / RMF / ISSO: Consulted |
AO Authorizing Official / CISOCTI Cyber Threat Intelligence cellSOC SOC / Defensive OperationsHUNT Hunt teamPLAT Platform and product ownersISSO Governance / RMF / ISSO
- AccountableAuthorizing Official / CISO
- InformedCyber Threat Intelligence cell
- ConsultedSOC / Defensive Operations
- InformedHunt team
- InformedPlatform and product owners
- ConsultedGovernance / RMF / ISSO
Inputs and Outputs
Consumes
- SM-5 Branches and SequelsBranch actions that need to execute at speed
- CG-3 Rules of EngagementRules of engagement defining authority levels
- FO-5 Statutory Availability FloorStatutory availability floor constraining what may be degraded
- EN-4 Escalation and Engagement AuthorityEvidence for revising the pre-authorized set
Produces
- TA-1 Decision Loop MeasurementReduced decision segment in the measured loop
- CG-3 Rules of EngagementThe approved pre-authorization set, recorded in the rules of engagement
- EN-4 Escalation and Engagement AuthorityPre-authorized response set, which bounds what needs escalating
Activities
- L2Define which defensive actions may be executed without escalation.
- L2Obtain the accountable authority's approval of that set.
- L2Link each pre-authorized action to the maneuvers it enables.
- L3Bound each authorization by condition, scope and duration, rather than by action type alone — "revoke sessions for a confirmed compromised account" is bounded; "revoke sessions" is not.
- L3Define the escalation matrix for actions outside the pre-authorized set, naming the authority and the reachable path to it at any hour.
- L3Key the pre-authorized set to campaign phase, so a declared Phase III widens what may be executed without reference.
- L3Rehearse the authority in exercise, confirming operators can state what they may do unaided.
- L4Measure the proportion of executed actions that fell inside the pre-authorized set, since a low proportion means the set is drawn in the wrong place.
- L4Measure decide-segment latency for pre-authorized versus escalated actions, so the control's contribution is quantified rather than assumed.
- L5Widen or narrow the set from observed use — actions repeatedly escalated and always approved are candidates for pre-authorization; actions pre-authorized and never used are candidates for removal.
Measurement
Proportion of executed defensive actions falling inside the pre-authorized set.
Decide-segment latency for pre-authorized versus escalated actions.
Evidence and Assessment
Approved rules of engagement with bounds; escalation matrix; rehearsal records; action logs referencing authorization.
Examine the approval; test that operators executed within authority during a recorded incident; interview operators on whether they believe the authority will be honored.
Related Guidance
- IR-4(2)
- AC-2(13)
- IR-9
- RS.MA-01
- RS.MI-01
- GV.RR-01
Position in the Chain
Derived from the other controls’ own declarations, so the two directions cannot disagree.
Where This Control Is Used
Derived, in every case, from the declaration at the other end: the forms whose techniques name this control, the artifacts whose producing and consuming controls include it, the layers whose control lists name it, and the roles its own accountability chart puts to work. Nothing here is authored on this page, so the sheet cannot claim an edge the other end does not.
Forms of Maneuver It Assesses
- M8Isolation / RetrogradeGive ground deliberately to preserve the force. Degrade gracefully; never fail open.5 of 17 techniques — M8.01, M8.02, M8.05, M8.06, M8.07
- M7CounterattackSeize the initiative and evict before the adversary reaches the objective.4 of 17 techniques — M7.03, M7.04, M7.05, M7.17
- M6DelayBuy decision time and prevent the adversary culminating on the objective.3 of 10 techniques — M6.02, M6.04, M6.05
- M3EnvelopmentMake identity, not network location, the decisive plane — surround the adversary with policy.2 of 20 techniques — M3.03, M3.11
- M9Spoiling AttackDisrupt adversary staging before the attack is launched.2 of 9 techniques — M9.01, M9.05
- M1Screen / GuardGain early warning and buy reaction time before the adversary touches key terrain.1 of 15 techniques — M1.06
- M5AmbushTrade space for information and time, and impose cost.1 of 13 techniques — M5.09
Terrain It Is Named On
- T1IdentitySession and credential revocation is the archetypal pre-authorized response — its value is entirely in whether it can be executed without an escalation.
- T3NetworksSevering a segment is a pre-authorized action or it is a forty-minute conference call. Which one it is decides whether M8 exists in this estate.
- TXCross-CuttingPre-authorized response is where the ceiling on every contested maneuver is actually set.
Artifacts It Stands On
- producesPre-authorized response setThe specific containment and response actions the SOC may execute at machine speed, bounded by the statutory availability floor. Directly measurable: it shortens the decision segment of the defender loop.
- consumesThreat course-of-action sketchTwo courses of action, most likely and most dangerous, drawn against the decisive points already designated. Each is a route across ground the estate really has, not a category of threat.
- consumesBranch and sequel planThe branches answer the most-dangerous course of action; the sequels answer success. Every one names the authority it needs, and any expected to run inside the decision window is pre-authorized when it is written.
- consumesRules of engagementWhich defensive actions may be taken by whom without escalation, which need the Authorizing Official, and what is prohibited outright. The cyber analog of engagement authority, and the single largest determinant of tempo.
- consumesChange recordEvery defensive action carried out, stamped twice — at the decision and at the effect. A thin, unglamorous table, and the one the headline metric is computed from.
- consumesAuthority exception logActions taken outside the standing rules of engagement, with who approved them and why. Exceptions are not failures; unrecorded exceptions are.
- consumesStatutory availability floorThe mission services whose availability is set by statute or regulation, and the floor below which degradation stops being a defensive choice. Bounds what may be pre-authorized and what may be degraded under contact.
Roles It Puts to Work
- AccountableAuthorizing Official / CISOIntent, risk acceptance, and the scheme itself.
- ConsultedSOC / Defensive OperationsManeuver. Executes fires and emplaces obstacles inside the standing rules of engagement.
- ConsultedGovernance / RMF / ISSOTranslating cycle outputs into FISMA and RMF artifacts, and owning the rules of engagement.
- InformedCyber Threat Intelligence cellFrame, Map and Fuse. The intelligence requirements, the threat courses of action, and the confidence levels.
- InformedHunt teamCounterattack. Works the hypotheses that Fuse raises.
- InformedPlatform and product ownersTheir own terrain. Obstacles get emplaced on their ground, so they site them.