Six Control Dimensions
Endpoint security operates across six dimensions that determine what an attacker can accomplish after initial access. Each dimension controls specific attacker actions, and failure in any dimension creates exploitable conditions.Execution control governs what processes can run and under what conditions. This includes application allowlisting, code signing validation, and behavioral analysis of running processes. When execution control fails, malicious processes execute because nothing prevents them. The attacker runs their tools with the same privileges the compromised user or system had.Telemetry determines what activity is observed and at what investigative depth. This encompasses process creation, file system changes, network connections, registry modifications, and memory manipulation events. When telemetry fails, detection fires but investigation cannot establish attack scope from available data. Response teams operate on incomplete information about what the attacker accessed or modified.Configuration controls whether the system's state matches a defined security baseline. This includes patch levels, service configurations, security settings, and software inventory management. When configuration control fails, drift from baseline creates exploitable conditions that accumulate silently. The endpoint develops vulnerabilities or misconfigurations that bypass other security controls.Privilege governs what users and processes can access and do. This includes local administrator rights, service account permissions, file system access controls, and registry permissions. When privilege control fails, over-privileged accounts and processes enable lateral movement and persistence without additional credential theft. The attacker leverages existing access rights to expand their foothold.Containment determines what the endpoint can do to limit damage during active compromise. This includes network isolation, process termination, file quarantine, and evidence preservation capabilities. When containment fails, detection fires but the endpoint cannot isolate, terminate processes, or preserve telemetry during execution. A single endpoint incident becomes an enterprise recovery event.
Recovery handoff controls what the endpoint layer produces for the rest of the response process. This includes structured evidence collection, timeline reconstruction, and impact assessment data. When recovery handoff fails, response teams receive insufficient scope data and must operate on guesswork. Recovery takes longer and may miss compromised systems.
Where The Controls Connect
These six dimensions are not independent — failure in one degrades others systematically. Privilege failure enables execution of attacker tools that would otherwise be blocked. Configuration drift creates conditions that bypass detection logic, leaving gaps in telemetry. Telemetry gaps prevent investigation from establishing attack scope, which compromises containment decisions. Containment failure converts an endpoint incident into an enterprise recovery event requiring broader response resources.NSA and CISA joint guidance identifies that the most impactful endpoint security misconfigurations involve gaps in privilege control, configuration management, and detection coverage — establishing that endpoint security failures are most often architecture failures, not tool failures (Source: NSA/CISA Joint Cybersecurity Advisory AA23-278A, https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-278a). The tools may work correctly while the overall control architecture produces inadequate protection.Consider a common failure pattern: an endpoint with working antivirus but local administrator access for standard users. Execution control blocks known malware, but privilege failure allows the attacker to disable protection, install new tools, or modify system configurations. The execution control that was working becomes ineffective because privilege control failed.Similarly, strong containment capabilities become ineffective without adequate telemetry. Network isolation can stop lateral movement, but if telemetry gaps prevent investigators from understanding what the attacker accessed, containment decisions operate on incomplete information. The response team may isolate the wrong systems or miss compromised assets.The architecture works as a system where each dimension reinforces the others. Effective privilege control makes execution control more reliable because attackers cannot disable protection mechanisms. Comprehensive telemetry makes containment decisions more precise because responders can see exactly what requires isolation. Strong configuration control keeps all other dimensions operating within defined parameters.What The Architecture Produces
When all six dimensions are controlled and validated, the organization gains specific operational capabilities rather than endpoint security as an abstract concept. These capabilities determine what happens when an attacker gains initial access to an endpoint.The ability to prevent known-bad process execution means attackers cannot run standard tools and must develop custom capabilities for that environment. This increases their cost and time investment while providing more opportunities for detection.Investigation-grade telemetry from behavioral anomalies enables response teams to establish attack timelines, identify affected systems, and assess data exposure with precision. Investigation proceeds from evidence rather than assumptions about what the attacker might have done.Continuous configuration state governance means the endpoint maintains defined security baselines despite software updates, user modifications, and administrative changes. Security controls remain effective over time rather than degrading silently.Privilege limited to authorized scope contains compromise to specific systems and accounts rather than allowing enterprise-wide access. Lateral movement requires additional credential theft or exploitation rather than leveraging existing over-privileged access.Compromise containment before spread prevention converts endpoint incidents into contained events rather than enterprise breaches. The security team manages single-system recovery instead of organization-wide response.Structured evidence handoff to response teams provides investigation scope, timeline data, and impact assessment without requiring forensic reconstruction. Recovery planning operates from known facts rather than incident response guesswork.Program Readiness Test
Three questions test whether endpoint control architecture is working without specifying particular tools or vendors. Each question requires demonstrating operational capability rather than confirming tool deployment.Can your security team establish attack scope within four hours of initial detection? This tests whether telemetry, privilege controls, and recovery handoff work together to provide investigation-grade evidence. If the answer requires forensic imaging or extended analysis, telemetry depth may be inadequate for operational response.Can compromised endpoints be contained without affecting business operations on uncompromised systems? This tests whether containment capabilities work precisely enough to isolate specific threats rather than broadly disrupting network access. If containment requires network-wide changes, the architecture may lack granular control capabilities.Can configuration drift be detected and corrected automatically without manual verification? This tests whether configuration control operates continuously rather than through periodic assessments. If drift detection requires manual auditing, the architecture may not maintain baseline security over time.Together, these three questions test the control architecture as a whole, not the tools inside it. A program that can answer all three with demonstrated capability has endpoint control that limits what an attacker can accomplish after initial access. A program that cannot has tool deployment without architectural control — and that gap is where a single endpoint incident becomes an enterprise breach.Sources- NSA/CISA Joint Cybersecurity Advisory AA23-278A. Available at: https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-278a
- Verizon Data Breach Investigations Report 2024. Available at: https://www.verizon.com/business/resources/reports/dbir/




