Control Statement
All permitted connections between elements shall be recorded, and paths that are deliberately blocked shall be recorded distinctly as denied paths.
Purpose. To record connectivity as three distinct states — permitted, denied, unknown — so that reachability conclusions rest on tested denials rather than on absence of evidence.
Discussion
Denied paths are the load-bearing entries. KT-4 concludes that a decisive point is unreachable precisely because certain paths are blocked; if those denials are not recorded and enforced, the conclusion is unfounded. The three-state distinction matters as much as the recording: treating unknown connectivity as absent is how a reachability model becomes confidently wrong.
Goals and Metrics
A metric that cannot come out badly is not a metric. Each of these is capable of reporting that the control is not working.
- Number of observed flows with no corresponding permitted connection
- Number of recorded permitted connections with no observed traffic in the period
- Number of denied paths recorded with a named enforcing control
Accountability
Exactly one role is accountable, and every other role carries at least Informed — no control in the published catalog leaves a role with zero relationship to it. That is a stated property of how these were authored, not a coincidence, and not a claim that every role's work is worth equal attention here.
| AO | CTI | SOC | HUNT | PLAT | ISSO |
|---|---|---|---|---|---|
| Authorizing Official / CISO: Accountable | Cyber Threat Intelligence cell: Consulted | SOC / Defensive Operations: Consulted | Hunt team: Informed | Platform and product owners: Responsible | Governance / RMF / ISSO: Informed |
AO Authorizing Official / CISOCTI Cyber Threat Intelligence cellSOC SOC / Defensive OperationsHUNT Hunt teamPLAT Platform and product ownersISSO Governance / RMF / ISSO
- AccountableAuthorizing Official / CISO
- ConsultedCyber Threat Intelligence cell
- ConsultedSOC / Defensive Operations
- InformedHunt team
- ResponsiblePlatform and product owners
- InformedGovernance / RMF / ISSO
Inputs and Outputs
Consumes
- TM-4 Trust Zone DefinitionZone boundaries the connections cross
- Outside the frameworkFirewall, security-group and policy configuration; observed flow telemetry
- FO-2 Controlled Unclassified Information HandlingDenied paths required to enforce declared boundaries
- FO-6 Supply Chain ObligationSupplier connections recorded in the connection register
- FC-3 Maintenance Access ControlMaintenance paths recorded in the connection register
- LC-3 Supplier Access ConstraintSupplier paths recorded as permitted or denied
Produces
- KT-3 Avenue of Approach AnalysisPermitted paths from which avenues of approach are derived
- KT-4 Adversary Reachability AssessmentThe permitted-path graph the reachability tracer walks
- KT-5 Barrier SufficiencyDenied paths that become barriers requiring enforcement and monitoring
- FO-2 Controlled Unclassified Information HandlingConnection register showing where information can move
- EN-2 Engagement ReconstructionConnection and denied-path register bounding plausible movement
Activities
- L2Record every permitted connection with direction and protocol.
- L2Record deliberately blocked paths as first-class entries, distinguishable from paths that simply have no entry.
- L2Record observation-only paths separately from permitted flows.
- L3Record the business reason each permitted connection exists, so the register doubles as a rationale record.
- L3Represent unknown connectivity as a third state visible as such, rather than collapsing it into absence.
- L3Bind each denied path to the configuration enforcing it and the owner of that configuration.
- L3Test a sample of denied paths each cycle against firewall or policy configuration.
- L3Place change detection on the configurations enforcing denied paths.
- L4Trend denied-path test pass rate and measure mean time to detect an unauthorized change to a denied path.
- L5Feed paths discovered during engagements — which the register did not contain — back into the enumeration method, not only into the register.
Measurement
Percentage of denied paths with verified enforcement.
Mean time to detect an unauthorized change to a denied path.
Evidence and Assessment
Connection register; denied paths rendered distinctly on the overlay; change-detection coverage record.
Examine the register; test a sample of denied paths against firewall or policy configuration to confirm they are enforced.
Related Guidance
- AC-4
- SC-7(5)
- CA-3
- PR.IR-01
- ID.AM-03
Position in the Chain
Derived from the other controls’ own declarations, so the two directions cannot disagree.
Fed By
Where This Control Is Used
Derived, in every case, from the declaration at the other end: the forms whose techniques name this control, the artifacts whose producing and consuming controls include it, the layers whose control lists name it, and the roles its own accountability chart puts to work. Nothing here is authored on this page, so the sheet cannot claim an edge the other end does not.
Forms of Maneuver It Assesses
- M4Obstacle / CanalizationForce the adversary onto ground you own and watch.7 of 17 techniques — M4.02, M4.03, M4.06, M4.07, M4.11, M4.12, M4.17
- M8Isolation / RetrogradeGive ground deliberately to preserve the force. Degrade gracefully; never fail open.2 of 17 techniques — M8.05, M8.10
- M2Defense in DepthEnsure no single failure is decisive.1 of 18 techniques — M2.01
- M3EnvelopmentMake identity, not network location, the decisive plane — surround the adversary with policy.1 of 20 techniques — M3.13
- M9Spoiling AttackDisrupt adversary staging before the attack is launched.1 of 9 techniques — M9.06
Terrain It Is Named On
- T2DevicesThe connection register is what makes an endpoint’s reachability a stated fact rather than an assumption about the network it is plugged into.
- T3NetworksThe connection and denied-path register is the authoritative statement of which corridors exist and which are asserted closed — the second half is the part usually missing.
- T6Operational TechnologyThe connection and denied-path register is where OT crossings are stated; the OT boundary is the register’s hardest case and its most valuable one.
Artifacts It Stands On
- producesTrust zones and the connection registerThe zone boundaries and the permitted- and denied-path register — the graph reachability is actually walked over, reconciled against observed flow telemetry rather than against intended configuration.
Roles It Puts to Work
- AccountableAuthorizing Official / CISOIntent, risk acceptance, and the scheme itself.
- ResponsiblePlatform and product ownersTheir own terrain. Obstacles get emplaced on their ground, so they site them.
- ConsultedCyber Threat Intelligence cellFrame, Map and Fuse. The intelligence requirements, the threat courses of action, and the confidence levels.
- ConsultedSOC / Defensive OperationsManeuver. Executes fires and emplaces obstacles inside the standing rules of engagement.
- InformedHunt teamCounterattack. Works the hypotheses that Fuse raises.
- InformedGovernance / RMF / ISSOTranslating cycle outputs into FISMA and RMF artifacts, and owning the rules of engagement.