The Ground
The entry fords.
A ford is where a force can cross an obstacle it otherwise cannot. Fords are few, they are known, and they are where a defender concentrates observation, because crossing is the moment the crossing force is most exposed and most predictable. Devices are the fords of a federal estate: the point at which an adversary transitions from operating outside the boundary to operating inside it, with a session, a token and a legitimate-looking process behind them.
The metaphor carries a warning about aggregation. Fords are not interchangeable — a managed laptop with a healthy agent and a contractor’s unmanaged machine are two different crossings with different depths, and a maturity score that averages them together reports a river that is passable nowhere and impassable nowhere. This is why device compliance and BYOD are separate sub-towers rather than one "endpoint" score.
It also explains the layer’s peculiar role: T2 rarely holds anything an adversary wants. Its value is almost entirely as the ground on which a crossing can be observed and denied — which is why its most consequential output is not protection but a signal the policy engine on T1 is willing to trust.
A CISA Zero Trust Maturity Model pillar, carried with its name and boundary unchanged so an agency reporting maturity under OMB M-22-09 reports the same rung here.
- Device assets — mission-staff laptops, mobile and BYOD, contractor devices, the server and VM fleet, build agents
Key Terrain
Key terrain is what confers decisive advantage if you hold it. Everything else on this layer is defended in order to hold these.
- Mission-staff laptopsThe devices that hold sessions to the case-processing systems. Compromising one is the cheapest route to mission-record access that does not require defeating the identity plane directly.
- Contractor and vendor devicesDevices with legitimate access and an unmanaged posture, present in the estate because the contract required access, not because the security program approved the endpoint.
- The server and VM fleetNumerically the largest device population, routinely exempted from endpoint tooling for performance reasons, and the ground lateral movement actually crosses.
- Build agentsDevices with credentials to production and, in many estates, no endpoint agent at all — the intersection of this layer with the decisive point on T4.
The Decisive Point
The device-posture signal the policy engine trusts
The decisive point is the device-posture signal the policy engine trusts — not the endpoint tool that produces it.
This is a deliberately awkward answer, and it is the right one. Posture only changes an outcome at the moment it is consumed as an input to an authorization decision. Posture that is collected, dashboarded and reported monthly has produced a report; posture that denies a non-compliant device access to the mission tier has produced a defense. The point where that conversion happens is the point worth holding.
It is decisive in the adversary’s direction too. An adversary on a compromised endpoint is in a position to lie about its health, so the integrity of the posture signal — not its existence — is what an attack on this layer is actually aimed at. An estate whose posture signal cannot be forged has genuinely closed the ford; one that trusts a self-reported attribute has drawn a ford on the map where there is none.
Sub-Towers, Rung by Rung
Maturity is scored here, not on the layer. Each rung below is stated for this sub-tower specifically — “Advanced” means something testable on each one, and something different on each one. The rung marked current is the illustrative position on the Federal Reference Agency profile.
Endpoint Protection (EDR)
Detection and response capability resident on the endpoint itself, and the telemetry it returns.
- Criticality 4
- Exposure 5
- Weight 20
- Illustrative rung Advanced · 75%
Signature antivirus on staff laptops. Servers are exempted for performance, telemetry is retained locally, and the security team learns about an endpoint event when a user reports it.
EDR deployed across the managed staff fleet with alerts routed to the SOC. Gaps on servers, build agents and contractor devices are known informally and are not tracked as coverage.
EDR on every managed endpoint and server, including build agents, with agent health monitored as a coverage metric. The SOC can isolate, terminate and collect without raising a ticket to the platform team.
Agent absence is itself an alert, raised against the asset register rather than the agent console. Isolation is pre-authorized under the rules of engagement for defined conditions and executes inside a stated number of minutes. Detections feed hunt hypotheses, not only a ticket queue.
ObservableShare of assets in the terrain overlay carrying a healthy agent — measured against the overlay, because an agent console can only report the devices it already knows about.
Device Compliance / Posture
The statement of a device’s health, and whether that statement changes any access decision.
- Criticality 4
- Exposure 4
- Weight 16
- Illustrative rung Initial · 50%
Patch state arrives monthly from a scanner. Compliance is a report with a percentage on it; nothing is denied as a result.
Posture — patch level, disk encryption, agent presence — is collected centrally and non-compliance generates a remediation ticket.
Posture is an input to the authorization decision. A non-compliant device is denied the mission tier rather than reported as non-compliant.
Posture is evaluated during the session rather than at connection, so a device that falls out of compliance mid-session loses key terrain. Posture signals are integrity-protected, so a compromised endpoint cannot assert its own health.
ObservableShare of mission-tier sessions where a posture signal was actually evaluated, and the rate at which hunt finds devices reporting health they do not have.
Mobile & BYOD
The unmanaged crossing: personal and unenrolled devices that reach agency data.
- Criticality 3
- Exposure 5
- Weight 15
- Illustrative rung Initial · 50%
Personal devices reach mail and collaboration with no management and no separation between agency data and the rest of the device.
Enrollment is required for mail. Broader personal-device use is governed by an acceptable-use policy that is not technically enforced.
Agency data is confined to a managed container or a browser-isolated session. Unmanaged devices reach a defined low-sensitivity subset and nothing else, and that boundary is enforced by the policy engine rather than by policy text.
The unmanaged path is treated as external terrain: mediated, fully logged, and incapable of holding data at rest. A reported lost device is a revocation event, not the opening of an investigation.
ObservableVolume of mission data reachable from unmanaged devices, and the measured time from a loss report to revocation.
Server / Workload Hardening
The configuration state of the server and workload fleet, and how it is kept.
- Criticality 4
- Exposure 3
- Weight 12
- Illustrative rung Initial · 50%
Servers are built by hand from a base image and hardened once at build. Drift accumulates and is unmeasured; the oldest hosts are the ones nobody will touch.
A hardened baseline exists and is applied at build. Drift is found by periodic scanning and remediated through the ticket queue.
Workloads are rebuilt from image rather than patched in place. Baseline compliance is measured continuously and drift is remediated by redeployment. Administrative access is brokered rather than direct.
Workloads are immutable and short-lived, so drift has no time to accumulate. The build path is the only path to production and is itself defended terrain. An interactive login to a production workload is an alertable exception rather than a Tuesday.
ObservableMedian age of running workloads, and the count of interactive logins to production workloads per cycle.
Weight, Coverage and Residual Risk
Weight is criticality × exposure, 1–25 per sub-tower. Coverage is the weighted mean of the sub-towers’ maturity coverage — never a flat average. Residual risk is reported both as the inverse percentage and in weight points, because the points are what rank a backlog.
- 63Layer weightSum of criticality × exposure across 4 sub-towers
- 57.9%Rolled-up coverageWeighted mean of the sub-tower maturity coverage
- 42.1%Residual riskThe inverse of coverage, before weight is considered
- 26.5Residual pointsWeight left uncovered — the figure that ranks against other layers
| Sub-tower | Criticality | Exposure | Weight | Illustrative rung | Coverage | Residual points |
|---|---|---|---|---|---|---|
| Endpoint Protection (EDR) | 4 | 5 | 20 | Advanced | 75% | 5 |
| Device Compliance / Posture | 4 | 4 | 16 | Initial | 50% | 8 |
| Mobile & BYOD | 3 | 5 | 15 | Initial | 50% | 7.5 |
| Server / Workload Hardening | 4 | 3 | 12 | Initial | 50% | 6 |
Endpoint Protection (EDR)
- Criticality
- 4
- Exposure
- 5
- Weight
- 20
- Illustrative rung
- Advanced
- Coverage
- 75%
- Residual points
- 5
Device Compliance / Posture
- Criticality
- 4
- Exposure
- 4
- Weight
- 16
- Illustrative rung
- Initial
- Coverage
- 50%
- Residual points
- 8
Mobile & BYOD
- Criticality
- 3
- Exposure
- 5
- Weight
- 15
- Illustrative rung
- Initial
- Coverage
- 50%
- Residual points
- 7.5
Server / Workload Hardening
- Criticality
- 4
- Exposure
- 3
- Weight
- 12
- Illustrative rung
- Initial
- Coverage
- 50%
- Residual points
- 6
Exposure dominates criticality on this layer, which inverts the T1 pattern. A single staff laptop is not critical — losing it costs the mission almost nothing directly — but its exposure is maximal, because it is operated by a human, reads external mail, and holds a live session to the mission tier.
That means the useful weighting on T2 is per device population rather than per device: the managed staff fleet as one asset, contractor devices as another, the server fleet as a third. Weighting individual endpoints produces thousands of low-weight rows that sum to a number nobody acts on, and hides the fact that the contractor population is a single high-exposure asset with no owner.
Residual risk on this layer is usually understated for a specific and detectable reason: coverage is computed from the endpoint tool’s own console, which by construction can only count devices it is installed on. Computing the same figure against the terrain overlay typically moves it several points, and the difference between the two numbers is a better finding than either number alone.
Maneuvers That Consume This Layer
The primary list is derived from each form’s own primary-terrain declaration in the maneuver catalog, so the two cannot disagree. The supporting list is authored: “consumes without being principally about” is a judgment, and deriving it would be a false claim of rigour.
Primary — Derived
No form of maneuver names this layer as its primary terrain. That is a real gap in the catalog rather than a property of the layer: the eleven forms were derived before T2 existed, and a form whose primary ground is this layer has not yet been added. Until it is, this layer is consumed only in support.
Supporting — Authored
- M2 Defense in DepthThe endpoint is one of the independent layers an adversary must defeat; defense in depth counts it as a layer only if it is instrumented across the whole fleet, not the managed part of it.
- M3 EnvelopmentEnvelopment is executed on T1 but is only as strong as the posture signal T2 supplies. Identity policy with no device signal is a one-dimensional envelopment.
- M7 CounterattackCounterattack is executed largely through endpoint response actions — isolation, termination, collection — so the hunt team’s reach is bounded by this layer’s coverage.
Controls That Apply
Two lists. The first is specific to this ground; the second is the spine every layer runs through, stated once here rather than repeated ten times across the reference.
Specific to T2
- DV-1 Device Terrain IdentificationPuts devices on the overlay as terrain, discovered from the identity plane outward — the management console can only report the population it already holds.
- DV-2 Device Posture as an Access PreconditionMakes device posture a precondition of access, which is what stops a valid credential being spent from a compromised endpoint.
- DV-3 Endpoint Sensor Coverage and LivenessEstablishes what this layer can actually see, and turns the loss of that visibility into an event rather than an assessment finding.
- DV-4 Execution ControlConstrains what may execute on the ground the adversary crosses into — the cheapest point at which most engagements can be stopped.
- DV-5 Device Lifecycle and SanitizationCloses both ends of the lifecycle, where trust is granted and where it is most often left behind on a device nobody holds any more.
- TM-5 Connection and Denied-Path RegisterThe connection register is what makes an endpoint’s reachability a stated fact rather than an assumption about the network it is plugged into.
- KT-3 Avenue of Approach AnalysisA compromised endpoint is the most common first avenue of approach in the reference profile; the avenue analysis is where that gets written down.
- KT-5 Barrier SufficiencyBarrier sufficiency asks whether the endpoint controls actually stop the crossing they are credited with, rather than whether they are deployed.
- SM-3 Implementation State TrackingImplementation-state tracking is what distinguishes "EDR purchased" from "EDR enforcing", which on this layer is the whole distinction.
- TA-1 Decision Loop MeasurementEndpoint detection time is usually the first term in the decision loop measurement, so this layer sets the tempo the rest of the loop inherits.
The Common Spine
- TM-1 Terrain Inventory and OverlayPuts the layer’s elements on the overlay in the first place. Nothing below can be computed for terrain that is not inventoried.
- TM-2 Defensive Layer ClassificationAssigns each element to a layer. This is the control that decides whether a thing is scored here or somewhere else.
- TM-3 Asset WeightingSets criticality and exposure per asset, which is the allocation driver every coverage and residual-risk number on the layer is weighted by.
- TM-6 Terrain CurrencyAges the overlay. A layer’s coverage figure inherits the staleness of the inventory it was computed from.
- TM-7 Terrain OwnershipNames an owner for the ground, so a coverage gap has somebody to be assigned to.
- KT-1 Decisive Point IdentificationIdentifies the decisive point on this layer rather than accepting the one this page names by default.
- KT-2 Decisive Point Protection FloorSets the minimum protection the layer’s decisive point must hold regardless of its rolled-up coverage.
- FO-7 Obligation Profile DeclarationDeclares which federal obligations bind the estate, which is what makes any FO coverage figure on this layer comparable to another agency’s.
- EN-1 Event Declaration and TriageAn engagement on this layer starts by being declared. Until it is, nothing below this line is running.
- EN-2 Engagement ReconstructionReconstruction is what establishes how far the adversary actually got across this layer, and it is what corrects the dwell estimate the layer’s tempo figures use.
- EN-3 Evidence PreservationSets how long this layer’s telemetry must survive — measured against estimated dwell, not against a retention default.
- EN-4 Escalation and Engagement AuthorityNames who may authorize action on this layer out of hours, which is where the decide segment is usually spent.
- EN-5 Eradication and Transition to RecoveryVerifies the adversary is off this layer before the mission is restored onto it.
- EN-6 Engagement CommunicationReports what happened on this layer to those who must know, inside and outside the agency.
- SM-7 Deception EmplacementDeception is emplaced per layer, on the approaches to that layer’s decisive point — the one detection here with no false-positive budget.
- CE-4 Coverage and Residual Risk ComputationPerforms the coverage and residual-risk computation described below, on the cycle cadence.
- CE-5 Remediation Backlog PrioritizationTurns weight multiplied by coverage gap into a ranked backlog, which is what the layer’s numbers are for.