ASOM-Fedv6.1Open the explorer
T9 · ASOM-Fed v3.0 · The lines of communication

Supply Chain

Doctrinally, an army’s lines of communication are terrain an enemy attacks precisely because they are not defended like the front. Software supply chain is the same idea with a different noun.

The Ground

The lines of communication.

Lines of communication are the routes by which a force is supplied, reinforced and updated. Doctrine treats them as terrain, and treats them as terrain an opponent attacks precisely because they are not defended like the front: they run through ground the force does not control, they are operated in part by people who are not the force, and interdicting them defeats a position without ever engaging it.

A software supply chain is the same idea with different nouns. Code, updates, components and contractor labor arrive continuously along routes the agency does not own, and an adversary who interdicts one of those routes reaches inside every position it supplies simultaneously. The reason to state this as terrain rather than as third-party risk management is that terrain gets an overlay, an owner, a coverage figure and a residual-risk number — and third-party risk management, in most agencies, gets a questionnaire.

The metaphor also predicts where the defense has to sit. You do not defend a line of communication along its length; you defend it at the point where it enters your own ground. That point is the staging gate, and it is why this layer’s decisive point is a deployment control rather than a supplier assessment.

Origin

Added by ASOM-Fed in v3.0. Not a CISA pillar — the justification is stated in full below.

Asset pools feeding it
  • Supply-chain assets — suppliers with logical or physical access, managed service providers and integrators, software components and dependencies, vendor update channels

Key Terrain

Key terrain is what confers decisive advantage if you hold it. Everything else on this layer is defended in order to hold these.

  • Suppliers with production accessVendors and contractors holding credentials into the estate. Legitimate access, agency-issued, and rarely time-bounded.
  • Component provenanceThe open-source and vendor components inside agency-built software. The route by which a compromise arrives without anyone logging in.
  • The update path into productionThe recurring, trusted, automated crossing that every other supplier route eventually converges on.
  • Managed service and integrator platformsThird parties operating parts of the estate, whose own compromise is an agency compromise with a longer notification path.

The Decisive Point

The staging gate an untrusted update must pass before it reaches production

The decisive point is the staging gate an untrusted update must pass before it reaches production.

It is decisive because it is the only point on this layer where the agency has unilateral authority. It cannot assure a supplier’s development practice, cannot audit a sub-tier dependency, and cannot make a vendor’s support model less permissive. It can decide what is allowed to cross into its own ground, and the gate is where that decision is executed.

It is also where the layer’s value converts into something testable. Supplier assessments produce documents; a gate produces a rejection. An agency that has never rejected an update at its gate has a gate whose function has not been demonstrated, which is why the Optimal rung on that sub-tower requires the rehearsal rather than the mechanism.

Sub-Towers, Rung by Rung

Maturity is scored here, not on the layer. Each rung below is stated for this sub-tower specifically — “Advanced” means something testable on each one, and something different on each one. The rung marked current is the illustrative position on the Federal Reference Agency profile.

Supplier Register

Knowing which third parties can reach the estate, through what, and under which contract.

  • Criticality 4
  • Exposure 4
  • Weight 16
  • Illustrative rung Initial · 50%
Traditional25% coverage

Suppliers are known to procurement as contracts, not to the security program as terrain. No one can produce a list of who currently has production access.

Initial50% coverage · current

A list of major vendors exists with a security review performed at onboarding. Sub-tier suppliers and software dependencies are out of scope by convention.

Advanced75% coverage

Every supplier with logical access, physical access or code in the estate is registered, with what they can reach, under which contract, and who owns the relationship.

Optimal100% coverage

The register is reconciled continuously against observed access and against the component inventory, so a supplier reaching production without an entry is a detection. Criticality and exposure are scored per supplier and feed the same weighting as any other asset.

ObservableCount of suppliers observed with production access but absent from the register.

Component Provenance

Knowing what the software in production is made of, and whether that claim is verified.

  • Criticality 4
  • Exposure 4
  • Weight 16
  • Illustrative rung Traditional · 25%
Traditional25% coverage · current

Software composition is unknown. Third-party components enter through developer choice and vendor packaging, and the question "are we running that" cannot be answered.

Initial50% coverage

Component inventories are requested from vendors at procurement and filed. They are not machine-readable, not refreshed, and not reconciled against what is deployed.

Advanced75% coverage

A machine-readable component inventory exists for every internally built and externally supplied production system, refreshed on build and queryable within hours when a component is named in an advisory.

Optimal100% coverage

Provenance is verified rather than declared: artifacts are signed, signatures are checked at admission, and the inventory is the artifact the agency answers a national advisory from, inside the interval the advisory demands.

ObservableMeasured time to answer “are we running component X, and where” — taken from a real advisory rather than from an exercise.

Access Constraint

What supplier identities may reach, for how long, and through what mediation.

  • Criticality 5
  • Exposure 4
  • Weight 20
  • Illustrative rung Initial · 50%
Traditional25% coverage

Supplier staff hold ordinary staff accounts, often with standing privilege and no defined end date. The account outlives the engagement by default.

Initial50% coverage · current

Supplier accounts are identifiable as such. Access is granted per project and reviewed annually, which is longer than most engagements.

Advanced75% coverage

Supplier access is time-boxed to the engagement, scoped to named systems, mediated through a broker that records the session, and expires by default at contract milestones.

Optimal100% coverage

Supplier access carries no standing privilege and is subject to the same just-in-time machinery as internal privilege. The blast radius of any single supplier is stated in the overlay, and severance can be executed on decision rather than negotiated.

ObservableNumber of supplier identities holding standing access, and the demonstrated time to sever a named supplier.

Update Staging

The gate every change of external origin passes before it reaches production.

  • Criticality 5
  • Exposure 4
  • Weight 20
  • Illustrative rung Initial · 50%
Traditional25% coverage

Vendor updates are applied to production directly, on the vendor’s schedule, because that is how the product is supported.

Initial50% coverage · current

Updates are tested in a lower environment. The test is for breakage rather than for integrity, so a signed-but-malicious update passes it.

Advanced75% coverage

Every update reaching production passes a staging gate that verifies integrity and origin as well as function. Emergency bypasses are defined, authorized, rare, and each one is recorded.

Optimal100% coverage

The gate is the only path to production for supplier code as well as internal code, it verifies provenance cryptographically, and the agency has rehearsed rejecting an update — because a gate that has never stopped anything has not been shown to work.

ObservableShare of production changes of supplier origin that passed the gate, and the count of bypasses with their disposition.

Weight, Coverage and Residual Risk

Weight is criticality × exposure, 1–25 per sub-tower. Coverage is the weighted mean of the sub-towers’ maturity coverage — never a flat average. Residual risk is reported both as the inverse percentage and in weight points, because the points are what rank a backlog.

  • 72Layer weightSum of criticality × exposure across 4 sub-towers
  • 44.4%Rolled-up coverageWeighted mean of the sub-tower maturity coverage
  • 55.6%Residual riskThe inverse of coverage, before weight is considered
  • 40Residual pointsWeight left uncovered — the figure that ranks against other layers
Sub-towerCriticalityExposureWeightIllustrative rungCoverageResidual points
Supplier Register4416Initial50%8
Component Provenance4416Traditional25%12
Access Constraint5420Initial50%10
Update Staging5420Initial50%10

Supplier Register

Criticality
4
Exposure
4
Weight
16
Illustrative rung
Initial
Coverage
50%
Residual points
8

Component Provenance

Criticality
4
Exposure
4
Weight
16
Illustrative rung
Traditional
Coverage
25%
Residual points
12

Access Constraint

Criticality
5
Exposure
4
Weight
20
Illustrative rung
Initial
Coverage
50%
Residual points
10

Update Staging

Criticality
5
Exposure
4
Weight
20
Illustrative rung
Initial
Coverage
50%
Residual points
10

Suppliers are weighted by reach rather than by contract value, and the two correlate poorly. A small integrator with standing production credentials outweighs a large commodity supplier with none, and a weighting derived from procurement data will get this exactly backwards.

Exposure on this layer includes the supplier’s own exposure, which the agency cannot measure directly and should not pretend to. The workable proxy is the agency-side property: how many systems the supplier can reach, whether the access is standing or time-boxed, and whether their code reaches production through a gate.

Residual risk here is the least reducible in the model, because a large part of it lies outside the agency’s authority. The correct treatment is to reduce what is reducible — access constraint and the staging gate, both entirely agency-side — and to record the rest as accepted risk with a named acceptor. A supply-chain figure that trends to zero is describing a questionnaire, not a defense.

Maneuvers That Consume This Layer

The primary list is derived from each form’s own primary-terrain declaration in the maneuver catalog, so the two cannot disagree. The supporting list is authored: “consumes without being principally about” is a judgment, and deriving it would be a false claim of rigour.

Primary — Derived

No form of maneuver names this layer as its primary terrain. That is a real gap in the catalog rather than a property of the layer: the eleven forms were derived before T9 existed, and a form whose primary ground is this layer has not yet been added. Until it is, this layer is consumed only in support.

Supporting — Authored

  • M1 Screen / GuardScreening this layer means watching advisories and supplier disclosures as a sensor, which is the earliest warning available for a route the agency cannot instrument.
  • M9 Spoiling AttackA spoiling attack on this layer is pre-patching or pre-blocking a component named in intelligence before the campaign that uses it arrives.
  • M2 Defense in DepthThe staging gate is an independent layer in a depth calculation, and the only one that acts on the supply route rather than on its consequences.

Controls That Apply

Two lists. The first is specific to this ground; the second is the spine every layer runs through, stated once here rather than repeated ten times across the reference.

Specific to T9

The Common Spine

Why ASOM-Fed Adds This Layer

T9 is not a CISA pillar. Extending someone else’s taxonomy requires a reason per addition, and the reason cannot be completeness. The objection is stated first, at its strongest.

The challenge

Supply chain risk management already has a federal home: SR controls in 800-53, C-SCRM under NIST 800-161, FedRAMP for cloud services, and a procurement organization that owns supplier relationships. A terrain layer duplicates all of it and gives the security program a scoring surface it has no authority to act on.

  1. The duplication objection has force against a layer that re-assessed suppliers, which this one does not. It scores four agency-side properties: whether the suppliers with reach are registered, whether the components in production are known, whether supplier access is constrained, and whether external changes cross a gate. Every one of those is inside the agency’s authority, and none of them is what a supplier questionnaire measures.
  2. Terrain treatment changes what happens to the answer. C-SCRM produces a supplier risk rating held by a procurement or risk function. This layer produces a weighted coverage figure that rolls into the residual risk of a named mission consumer, so a supplier weakness appears in the same ranked backlog as an unsegmented network and competes with it honestly. That comparison is not available when the two are assessed by different programs on different scales.
  3. The doctrinal argument is the one that decides it. An adversary who compromises an update channel is not attacking a supplier — they are attacking the mission that the update channel supplies, along a route the agency has not defended because it is not on the agency’s map. Lines of communication are terrain precisely because their defenders keep treating them as logistics.
  4. The practical test the layer has to pass is an advisory. When a component is named nationally, the agency either can or cannot say within hours whether it is running it and where. That is a terrain question — it requires an overlay, not a supplier rating — and an agency that cannot answer it has an unmapped route into its own estate regardless of how mature its vendor management is.

What it does not fixThis layer does not assess suppliers, does not replace C-SCRM or FedRAMP inheritance, and cannot see beyond the first tier of a supply chain with any confidence. Its residual risk is the least reducible in the model, and an agency that drives this figure down without changing access constraint or the staging gate has improved its paperwork. The layer’s honest claim is narrower than the discipline’s: it puts the route on the map and measures the gate at the end of it.