Control Statement
Every element on the terrain shall be classified to exactly one defensive layer: identity, devices, networks, applications and workloads, data, operational technology, workforce, facilities, or supply chain. Elements that enable maneuver across layers rather than constituting ground — visibility and analytics, automation and orchestration, governance — shall be classified to the cross-cutting domain.
Purpose. To make posture summable and comparable by layer, and to force an explicit ownership decision for every element.
Discussion
Classification is what allows posture to be rolled up and compared. The one-layer rule is what keeps the matrix partitionable: coverage summed across layers must equal total coverage, and an element counted twice inflates both. The failure this correction addresses is structural — a framework that added four terrain layers in v2.0 and v3.0 while leaving the classification control at five made those layers doctrinally present and practically unscoreable.
Goals and Metrics
A metric that cannot come out badly is not a metric. Each of these is capable of reporting that the control is not working.
- Number of unclassified elements
- Number of elements claimed by more than one layer during review
Accountability
Exactly one role is accountable, and every other role carries at least Informed — no control in the published catalog leaves a role with zero relationship to it. That is a stated property of how these were authored, not a coincidence, and not a claim that every role's work is worth equal attention here.
| AO | CTI | SOC | HUNT | PLAT | ISSO |
|---|---|---|---|---|---|
| Authorizing Official / CISO: Accountable | Cyber Threat Intelligence cell: Consulted | SOC / Defensive Operations: Informed | Hunt team: Informed | Platform and product owners: Responsible | Governance / RMF / ISSO: Informed |
AO Authorizing Official / CISOCTI Cyber Threat Intelligence cellSOC SOC / Defensive OperationsHUNT Hunt teamPLAT Platform and product ownersISSO Governance / RMF / ISSO
- AccountableAuthorizing Official / CISO
- ConsultedCyber Threat Intelligence cell
- InformedSOC / Defensive Operations
- InformedHunt team
- ResponsiblePlatform and product owners
- InformedGovernance / RMF / ISSO
Inputs and Outputs
Consumes
- TM-1 Terrain Inventory and OverlayElement list from the terrain overlay
- FO-4 Operational Technology TerrainDistinct defensive layer for aggregation
Produces
- CE-4 Coverage and Residual Risk ComputationLayer assignment used to aggregate coverage per defensive layer
- SM-2 Maneuver AssignmentLayer context constraining which maneuvers can apply to an element
- SM-7 Deception EmplacementTerrain classification, so decoys are plausible for their layer
- ID-3 Authentication AssuranceTerrain classification that sets the required level
- ID-5 Authorization Decision IntegrityTerrain classification the policy is written against
- EN-3 Evidence PreservationTerrain classification determining what must be preserved
Activities
- L2Classify every element to exactly one of the nine terrain layers, or to the cross-cutting domain where the element enables movement rather than being ground.
- L2Flag unclassified elements automatically rather than relying on review.
- L2Record the classification against the element in the register.
- L3Where an element plausibly spans layers, assign it to the layer whose loss would defeat it, and cross-reference from the others rather than duplicating.
- L3Treat unclassified elements as findings with an owner and a due date.
- L3Reconcile layer totals to the full inventory each cycle; a shortfall means elements are unclassified, an excess means one is double-counted.
- L3Record rationale for any classification a reviewer would find surprising, so the decision survives its author.
- L4Trend reclassification rate; a layer with high churn indicates the criteria are ambiguous rather than that the estate is changing.
- L4Measure the population of each of T6–T9 and escalate where a declared terrain layer holds no classified elements at all.
- L5Refine the layer criteria where reclassification patterns show a boundary that practitioners cannot apply consistently.
Measurement
Percentage of elements carrying exactly one layer.
Reconciliation variance between layer totals and inventory count.
Evidence and Assessment
Asset Register, "Defensive layer" column; reconciliation record.
Examine the register for unclassified elements; test that layer totals reconcile to the full inventory; test that at least one element on each of T6, T7, T8 and T9 is classified and scored.
Related Guidance
- CM-8(1)
- RA-2
- PM-5
- ID.AM-05
- ID.AM-01
Position in the Chain
Derived from the other controls’ own declarations, so the two directions cannot disagree.
Where This Control Is Used
Derived, in every case, from the declaration at the other end: the forms whose techniques name this control, the artifacts whose producing and consuming controls include it, the layers whose control lists name it, and the roles its own accountability chart puts to work. Nothing here is authored on this page, so the sheet cannot claim an edge the other end does not.
Forms of Maneuver It Assesses
- M4Obstacle / CanalizationForce the adversary onto ground you own and watch.2 of 17 techniques — M4.05, M4.09
- M1Screen / GuardGain early warning and buy reaction time before the adversary touches key terrain.1 of 15 techniques — M1.11
- M2Defense in DepthEnsure no single failure is decisive.1 of 18 techniques — M2.05
- M3EnvelopmentMake identity, not network location, the decisive plane — surround the adversary with policy.1 of 20 techniques — M3.05
Terrain It Is Named On
Applies to all ten layersAssigns each element to a layer. This is the control that decides whether a thing is scored here or somewhere else.
Artifacts It Stands On
- producesCyber Terrain OverlayThe positional map of the estate: every element with a defensive layer, a defensive weight, a named accountable owner and its adjacencies. Not an asset inventory — an inventory enumerates, an overlay positions.
Roles It Puts to Work
- AccountableAuthorizing Official / CISOIntent, risk acceptance, and the scheme itself.
- ResponsiblePlatform and product ownersTheir own terrain. Obstacles get emplaced on their ground, so they site them.
- ConsultedCyber Threat Intelligence cellFrame, Map and Fuse. The intelligence requirements, the threat courses of action, and the confidence levels.
- InformedSOC / Defensive OperationsManeuver. Executes fires and emplaces obstacles inside the standing rules of engagement.
- InformedHunt teamCounterattack. Works the hypotheses that Fuse raises.
- InformedGovernance / RMF / ISSOTranslating cycle outputs into FISMA and RMF artifacts, and owning the rules of engagement.