ASOM-Fedv6.1Open the explorer
M3.02 · M3 Envelopment · 2 of 20

Conditional Access Policy Engine

What It Does

Concentrate access decisions in one policy decision point that sees identity, device, network and behavior together.

Observable indicator. Access decisions are made in one place and are inspectable.

Where It Sits

A technique is chosen from inside a form and emplaced on one layer. Both are the catalog’s own declarations; the position is counted in catalog order.

  • Form of maneuverM3 EnvelopmentMake identity, not network location, the decisive plane — surround the adversary with policy.
  • Terrain layerT1 IdentityThe high ground. Key terrain: The ICAM policy decision point, privileged accounts, external-user and mission-staff identities.
  • Position in the form2 of 20M3 carries 20 cataloged techniques; this is the 2nd in catalog order.

Phases It Is Employed In

Employed in 2 of the campaign’s six phases. A phase named here means at least this technique is live in it — not that the form it belongs to is the main effort.

  • Phase 0ShapeContinuous terrain preparation, zero-trust hardening, partnerships, threat intelligence.
  • Phase IDeterVisible hardening, a deception grid, and a stated attribution posture.

Controls That Assess It

The controls the catalog names against this technique. They are what an assessor would test to establish that it is emplaced and working — the indicator above is what shows it is working, which is a different question.

  • KT-1 Decisive Point IdentificationKey Terrain and Decisive PointsTo concentrate defensive effort on the small number of elements whose loss is decisive, so that priority is a stated judgment rather than an emergent property of the asset register.
  • SM-2 Maneuver AssignmentScheme of ManeuverTo bind defensive intent to specific ground, so that coverage reflects what protects which element rather than what the program has bought.
  • ID-1 Identity Plane DefinitionIdentity TerrainTo make identity positional, so that the plane controlling movement everywhere else is itself defensible ground rather than an assumed service.

In MITRE D3FEND

What this technique is called in MITRE’s countermeasure ontology. The join runs technique-to-technique: D3FEND catalogs countermeasures, and the thing with a countermeasure’s shape here is the technique, not the control.

That a technique reaches a D3FEND countermeasure says the two describe the same defensive act. It does not say the countermeasure is deployed, configured, or working — that is an assessment finding about your estate, not a property of the framework.

Related Techniques

The catalog declares no relation for this entry, and no other entry names it — the inverse is derived here, so an incoming edge would show up even though this one never declared it. The techniques below share its assessment surface, which is the nearest adjacency the data supports.

Assessed Alongside

Not a declared relation: these are the techniques whose assessing controls overlap this one’s, ranked by how much of the two assessment surfaces coincide. Showing 6 of 19 that share at least one control.