Fracture the path from compromise to consequence.
An attacker can gain access, credentials, and new routes without gaining any authority over your organization. Authority Control can interrupt the attack path when progression requires a consequential result that is outside organizational authority.
Compromise changes what an attacker can reach. It does not change what the organization has authorized.
Scale
Run many attempts in parallel across a large environment.
Each consequential result is evaluated against the authority that applies, however many attempts there are.
Scope
Move through identity, applications, vendors, and infrastructure toward the same result.
Different routes to one result meet one authority question.
Pace
Find new routes faster than controls can be redesigned around each one.
A new route does not create new authority. The result is checked against current authority.
Reach and authority are different things.
Valid credentials, added privilege, and familiar workflows describe what an attacker can reach. The authority to create a consequential result on the organization's behalf comes only from the organization.
- Valid credentials and sessions
- Additional privilege or capability
- Movement through connected systems
- Use of familiar applications and workflows
- Movement of value
- Production and configuration changes
- Release of sensitive information
- Changes to trust, limits, or permissions
Compromise of a technical path does not establish authority for the consequential result.
Two different questions about the same activity.
Security tools keep governing identities, access, endpoints, networks, detection, and response. Authority Control adds one question about the result.
Is this activity compromised, anomalous, or unsafe?
Is this result within the organization's authority?
A determination says nothing about intent. The result is evaluated whether or not the activity looks malicious.
Authority Control does not generally control network movement itself. It can interrupt attack-path progression when the next consequential result is one the organization has placed under Authority Control and the result is outside authority.
Results reached through other execution paths remain outside enforcement, so keeping integration current as systems, agents, vendors, and workflows change is part of the work. Authority Control does not detect intrusions, prevent initial access, remove malware, or revoke credentials.
Related: Authority Control and Zero Trust · Where capability becomes consequence