ASOM-Fedv6.1Open the explorer
T3 · CISA ZTMM pillar · The corridors

Networks

Movement corridors and the obstacles that canalize them. This is the layer where you decide which ground the adversary is allowed to walk on.

The Ground

The corridors.

A mobility corridor is ground that permits movement at speed; an obstacle is anything that denies, delays or canalizes it. Corridors and obstacles are the same subject seen from the two sides, and a defender who understands the corridors chooses where an adversary is permitted to walk rather than trying to be strong everywhere.

The network layer is the only terrain in the model where a defender can genuinely shape the ground rather than merely occupy it. Identity determines whether a move is permitted; the network determines whether a permitted move is observed and where it emerges. This is why obstacle and canalization (M4) is the form of maneuver most native to this layer — the intent is not to stop lateral movement, which is not achievable, but to make it happen in an instrumented corridor of the defender’s choosing.

The metaphor’s discipline is that corridors are a property of the estate as built, not as diagrammed. A network diagram shows intent; the connection register shows corridors. Where they disagree, the register is the terrain.

Origin

A CISA Zero Trust Maturity Model pillar, carried with its name and boundary unchanged so an agency reporting maturity under OMB M-22-09 reports the same rung here.

Asset pools feeding it
  • Network assets — TIC 3.0 access points, edge and content delivery, web application firewalls, load balancers, DNS, segments and VLANs, cloud VPC and peering

Key Terrain

Key terrain is what confers decisive advantage if you hold it. Everything else on this layer is defended in order to hold these.

  • TIC 3.0 access pointsThe declared crossings between the estate and everything outside it. Their value is that they are declared — an undeclared egress path is worth more to an adversary than any of them.
  • Segment boundariesWhere policy is enforceable east-west. A boundary that exists only as an address range is a boundary an adversary does not have to cross.
  • Cloud VPC peering and transitThe corridors that most often bypass the perimeter model entirely, because they were built by a platform team to solve a delivery problem.
  • DNS resolution pathsThe one corridor almost every adversary uses and almost every estate permits by default.

The Decisive Point

The east-west boundary between the public tier and the mission tier

The decisive point is the east-west boundary between the public and mission tiers. Until an adversary holding a public-facing service crosses it, the foothold buys them very little.

It is decisive rather than merely important because it is the last boundary at which the defender still has both options. Before it, containment is cheap and the mission is unaffected. After it, the adversary is inside the tier where records live, and every subsequent defensive action trades mission availability for containment. The whole value of isolation and retrograde (M8) depends on the choice being made on the near side of this boundary.

It is also the boundary most likely to be quietly permissive, because the public tier legitimately needs to reach mission services to function. The question a decisive-point protection floor should ask here is not "is there a firewall" but "which named flows cross, who owns each, and when was the denied-path assumption last tested".

Sub-Towers, Rung by Rung

Maturity is scored here, not on the layer. Each rung below is stated for this sub-tower specifically — “Advanced” means something testable on each one, and something different on each one. The rung marked current is the illustrative position on the Federal Reference Agency profile.

Perimeter / TIC 3.0

The declared boundary between the estate and everything outside it, and the enforcement at each crossing.

  • Criticality 4
  • Exposure 5
  • Weight 20
  • Illustrative rung Advanced · 75%
Traditional25% coverage

A single traditional perimeter. Cloud traffic is either backhauled through it or egresses uninspected, and remote users terminate on a concentrator that puts them inside.

Initial50% coverage

TIC 3.0 use cases are identified and trust zones documented. Enforcement points exist at the main internet boundary; cloud and remote paths are described as future work.

Advanced75% coverage · current

Every avenue in and out of the estate crosses a defined trust-zone boundary with an enforcement point, cloud and remote-user paths included. The zone model matches the terrain overlay rather than the network diagram.

Optimal100% coverage

Boundary policy is generated from the overlay rather than maintained by hand, so a new avenue appearing without a boundary is detected as a terrain-currency failure inside the stated refresh interval.

ObservableCount of ingress and egress paths reconciled against the overlay each cycle, and how many were found that nobody had registered.

Microsegmentation

East-west policy: which internal element may reach which other internal element.

  • Criticality 5
  • Exposure 4
  • Weight 20
  • Illustrative rung Initial · 50%
Traditional25% coverage

A flat internal network. VLANs exist for addressing rather than for policy, and east-west traffic is unrestricted once a host is on the network.

Initial50% coverage · current

Coarse segments separate the public tier from the internal tier. Rules are permissive, exceptions accumulate, and no one can say which of them are still needed.

Advanced75% coverage

Segmentation is expressed as allowed flows between named terrain elements, default-deny east-west into the data tier, with a register of the denied paths that are known to be attempted.

Optimal100% coverage

Policy is identity- and workload-aware rather than address-aware, so a workload keeps its policy when it moves. Every denied-path assumption in the overlay is tested by exercise rather than asserted.

ObservableShare of east-west flows into the data tier explicitly allowed by policy, and the date each denied path was last actually tested.

Egress & DNS Control

What may leave, to where, and whether the resolution and the transfer are visible.

  • Criticality 4
  • Exposure 4
  • Weight 16
  • Illustrative rung Initial · 50%
Traditional25% coverage

Outbound traffic is broadly permitted. DNS resolution is unlogged, so command-and-control is indistinguishable from ordinary traffic in retrospect as well as in real time.

Initial50% coverage · current

Egress is filtered by category and DNS is logged centrally. Protective DNS is deployed to part of the estate.

Advanced75% coverage

Default-deny egress for server and workload segments with an allow-list tied to the asset register. Protective DNS everywhere, cloud workloads included. Resolution logs are retained for at least the declared hunt window.

Optimal100% coverage

Egress allow-lists are generated from declared dependencies rather than requested by exception. Newly registered or newly resolving destinations are blocked pending review — which is the mechanism a spoiling attack (M9) actually runs on.

ObservableShare of egress from mission-tier workloads matched to a declared dependency, and DNS log retention measured against the stated hunt window.

WAF & DDoS

Protection of internet-facing services against application abuse and volumetric denial.

  • Criticality 4
  • Exposure 5
  • Weight 20
  • Illustrative rung Advanced · 75%
Traditional25% coverage

A web application firewall in front of the main portal, in monitor mode. Volumetric events are handled by telephoning the carrier.

Initial50% coverage

The firewall is in blocking mode with vendor rule sets, and edge denial-of-service protection is contracted for the primary portal.

Advanced75% coverage · current

Every internet-facing service sits behind the edge with rules tuned to the application. Rate limits and step-up challenges are configured deliberately as delay (M6), not only as blocking. The capacity to absorb a volumetric event is stated rather than assumed.

Optimal100% coverage

Edge policy is exercised against the statutory availability floor: the agency knows which services must survive a flood timed to a filing deadline and has demonstrated that they do. Edge telemetry is treated as a screening sensor feeding the running estimate.

ObservableTime from onset of a volumetric event to stable service, measured in exercise, against the availability floor of the affected mission service.

Weight, Coverage and Residual Risk

Weight is criticality × exposure, 1–25 per sub-tower. Coverage is the weighted mean of the sub-towers’ maturity coverage — never a flat average. Residual risk is reported both as the inverse percentage and in weight points, because the points are what rank a backlog.

  • 76Layer weightSum of criticality × exposure across 4 sub-towers
  • 63.2%Rolled-up coverageWeighted mean of the sub-tower maturity coverage
  • 36.8%Residual riskThe inverse of coverage, before weight is considered
  • 28Residual pointsWeight left uncovered — the figure that ranks against other layers
Sub-towerCriticalityExposureWeightIllustrative rungCoverageResidual points
Perimeter / TIC 3.04520Advanced75%5
Microsegmentation5420Initial50%10
Egress & DNS Control4416Initial50%8
WAF & DDoS4520Advanced75%5

Perimeter / TIC 3.0

Criticality
4
Exposure
5
Weight
20
Illustrative rung
Advanced
Coverage
75%
Residual points
5

Microsegmentation

Criticality
5
Exposure
4
Weight
20
Illustrative rung
Initial
Coverage
50%
Residual points
10

Egress & DNS Control

Criticality
4
Exposure
4
Weight
16
Illustrative rung
Initial
Coverage
50%
Residual points
8

WAF & DDoS

Criticality
4
Exposure
5
Weight
20
Illustrative rung
Advanced
Coverage
75%
Residual points
5

Network assets are weighted by what crosses them, not by what they cost. A boundary device between the public tier and the data tier inherits the criticality of the records behind it; an access switch in an office inherits almost nothing. This is the layer where a naive asset-value weighting produces the most wrong answer.

Exposure on T3 has an unusual property: it is partly a defender’s choice. Segmenting reduces the exposure score of everything behind the new boundary, which means the same remediation shows up twice in the model — once as coverage on the Microsegmentation sub-tower, once as reduced exposure on the assets it now protects. Adopters should score exposure from the current state and let the recomputation show the second effect, rather than pre-crediting it.

The honest limit here is that segmentation coverage is the easiest figure in the whole model to overstate. A default-deny policy with two hundred standing exceptions scores as default-deny in every tool that reports it. This is why the sub-tower’s observable is the date each denied path was last tested, not the policy’s stated posture.

Maneuvers That Consume This Layer

The primary list is derived from each form’s own primary-terrain declaration in the maneuver catalog, so the two cannot disagree. The supporting list is authored: “consumes without being principally about” is a judgment, and deriving it would be a false claim of rigour.

Primary — Derived

Supporting — Authored

  • M5 AmbushNetwork-resident decoys — unused segments, decoy services, responder traps — are ambush positions emplaced on this layer even though the classic decoy is a data-layer artifact.
  • M9 Spoiling AttackPre-blocking staged adversary infrastructure is executed as egress and DNS policy, so a spoiling attack is only as fast as this layer’s change path.
  • M11 ReconstitutionReconstitution needs a network path that does not run through the compromised production corridors; whether one exists is a T3 property.

Controls That Apply

Two lists. The first is specific to this ground; the second is the spine every layer runs through, stated once here rather than repeated ten times across the reference.

Specific to T3

  • TM-4 Trust Zone DefinitionTrust-zone definition is the control that turns a network diagram into terrain with declared boundaries.
  • TM-5 Connection and Denied-Path RegisterThe connection and denied-path register is the authoritative statement of which corridors exist and which are asserted closed — the second half is the part usually missing.
  • KT-3 Avenue of Approach AnalysisAvenues of approach are drawn on this layer; almost every avenue in the reference profile is a network path plus an identity.
  • KT-5 Barrier SufficiencyBarrier sufficiency is where a segmentation claim is tested rather than believed.
  • SM-2 Maneuver AssignmentObstacle and canalization maneuvers are assigned to specific segments here; an unassigned maneuver is an intention.
  • TA-4 Pre-authorized ResponseSevering a segment is a pre-authorized action or it is a forty-minute conference call. Which one it is decides whether M8 exists in this estate.
  • FO-5 Statutory Availability FloorEgress and segmentation changes are the actions most likely to breach the statutory availability floor, so the floor has to be known before the action is authorized.

The Common Spine