ASOM-Fedv6.1Open the explorer
TM-5 · Terrain Management

Connection and Denied-Path Register

Control Statement

All permitted connections between elements shall be recorded, and paths that are deliberately blocked shall be recorded distinctly as denied paths.

Purpose. To record connectivity as three distinct states — permitted, denied, unknown — so that reachability conclusions rest on tested denials rather than on absence of evidence.

Discussion

Denied paths are the load-bearing entries. KT-4 concludes that a decisive point is unreachable precisely because certain paths are blocked; if those denials are not recorded and enforced, the conclusion is unfounded. The three-state distinction matters as much as the recording: treating unknown connectivity as absent is how a reachability model becomes confidently wrong.

Goals and Metrics

A metric that cannot come out badly is not a metric. Each of these is capable of reporting that the control is not working.

The connection register reflects reality.
  • Number of observed flows with no corresponding permitted connection
  • Number of recorded permitted connections with no observed traffic in the period
Denied paths are recorded as decisions, not absences.
  • Number of denied paths recorded with a named enforcing control

Accountability

Exactly one role is accountable, and every other role carries at least Informed — no control in the published catalog leaves a role with zero relationship to it. That is a stated property of how these were authored, not a coincidence, and not a claim that every role's work is worth equal attention here.

AOCTISOCHUNTPLATISSO
Authorizing Official / CISO: AccountableCyber Threat Intelligence cell: ConsultedSOC / Defensive Operations: ConsultedHunt team: InformedPlatform and product owners: ResponsibleGovernance / RMF / ISSO: Informed

AO Authorizing Official / CISOCTI Cyber Threat Intelligence cellSOC SOC / Defensive OperationsHUNT Hunt teamPLAT Platform and product ownersISSO Governance / RMF / ISSO

  • AccountableAuthorizing Official / CISO
  • ConsultedCyber Threat Intelligence cell
  • ConsultedSOC / Defensive Operations
  • InformedHunt team
  • ResponsiblePlatform and product owners
  • InformedGovernance / RMF / ISSO

Inputs and Outputs

Consumes

Produces

Activities

  1. L2Record every permitted connection with direction and protocol.
  2. L2Record deliberately blocked paths as first-class entries, distinguishable from paths that simply have no entry.
  3. L2Record observation-only paths separately from permitted flows.
  4. L3Record the business reason each permitted connection exists, so the register doubles as a rationale record.
  5. L3Represent unknown connectivity as a third state visible as such, rather than collapsing it into absence.
  6. L3Bind each denied path to the configuration enforcing it and the owner of that configuration.
  7. L3Test a sample of denied paths each cycle against firewall or policy configuration.
  8. L3Place change detection on the configurations enforcing denied paths.
  9. L4Trend denied-path test pass rate and measure mean time to detect an unauthorized change to a denied path.
  10. L5Feed paths discovered during engagements — which the register did not contain — back into the enumeration method, not only into the register.

Measurement

Outcome

Percentage of denied paths with verified enforcement.

Performance

Mean time to detect an unauthorized change to a denied path.

Evidence and Assessment

Evidence expected

Connection register; denied paths rendered distinctly on the overlay; change-detection coverage record.

Assessment procedure

Examine the register; test a sample of denied paths against firewall or policy configuration to confirm they are enforced.

Related Guidance

Inherits
  • AC-4
  • SC-7(5)
  • CA-3
Satisfies
  • PR.IR-01
  • ID.AM-03

Position in the Chain

Derived from the other controls’ own declarations, so the two directions cannot disagree.

Where This Control Is Used

Derived, in every case, from the declaration at the other end: the forms whose techniques name this control, the artifacts whose producing and consuming controls include it, the layers whose control lists name it, and the roles its own accountability chart puts to work. Nothing here is authored on this page, so the sheet cannot claim an edge the other end does not.

Forms of Maneuver It Assesses

  • M4Obstacle / CanalizationForce the adversary onto ground you own and watch.7 of 17 techniques — M4.02, M4.03, M4.06, M4.07, M4.11, M4.12, M4.17
  • M8Isolation / RetrogradeGive ground deliberately to preserve the force. Degrade gracefully; never fail open.2 of 17 techniques — M8.05, M8.10
  • M2Defense in DepthEnsure no single failure is decisive.1 of 18 techniques — M2.01
  • M3EnvelopmentMake identity, not network location, the decisive plane — surround the adversary with policy.1 of 20 techniques — M3.13
  • M9Spoiling AttackDisrupt adversary staging before the attack is launched.1 of 9 techniques — M9.06

Terrain It Is Named On

  • T2DevicesThe connection register is what makes an endpoint’s reachability a stated fact rather than an assumption about the network it is plugged into.
  • T3NetworksThe connection and denied-path register is the authoritative statement of which corridors exist and which are asserted closed — the second half is the part usually missing.
  • T6Operational TechnologyThe connection and denied-path register is where OT crossings are stated; the OT boundary is the register’s hardest case and its most valuable one.

Artifacts It Stands On

  • producesTrust zones and the connection registerThe zone boundaries and the permitted- and denied-path register — the graph reachability is actually walked over, reconciled against observed flow telemetry rather than against intended configuration.

Roles It Puts to Work