Target-System Analysis and Cyber Key Terrain
Find the function, dependencies, control points, observability, and recovery paths behind a target label.
In this lesson, you will learn to:
- Produce and challenge a target-system folder that supports both effects planning and defence.
Target-System Analysis and Cyber Key Terrain
Learners develop target folders centered on mission behavior rather than asset lists. The method integrates technical mapping, human workflow, intelligence confidence, and civilian dependencies.
Model the function before the component
Define the adversary function: communicate orders, move fuel, identify targets, distribute propaganda, restore power, or authenticate operators. Map inputs, transformations, outputs, decision points, people, software, hardware, suppliers, trust, and feedback. Identify which elements are necessary, redundant, replaceable, or merely visible.
A target folder should include the five cyberspace layers, ownership and geography, normal and crisis workflows, alternate paths, maintenance, observability, failure modes, and recovery. Mark facts, inferences, age, and source. Validate architecture against telemetry and subject-matter experts. A stale diagram can turn precision into collateral effect.
Find control points whose availability or integrity materially changes the function during the relevant window. Then red-team them: Can operators switch to voice, paper, another cloud, a spare radio, or manual control? Does the “single point” also serve civilians or partners? Target value is conditional on timing and adversary adaptation.
Build a target folder that can be challenged
The folder must answer: why the function matters; the desired effect and duration; technical and human control points; access confidence; intelligence gaps; civilian and partner co-use; expected adversary response; restoration; and indicators for target change. Include a “do not infer” page listing attractive but unsupported claims.
Run multidisciplinary challenge. Operators test feasibility, defenders expose detection and recovery, intelligence challenges identity and intent, engineers test process assumptions, counsel tests legal character, and regional experts test political context. Record dissent. Approval should expire when a critical assumption changes.
This same product supports defence. The linked cyber key terrain and mission-dependency mapping guide turns decisive terrain into monitoring priorities; alternate paths become continuity requirements; access hypotheses become hunt plans; recovery dependencies become exercise injects. Offensive and defensive analysis meet in the system model.
Resources
- NIST Developing Cyber-Resilient Systems — Systems-engineering guidance for anticipating, withstanding, recovering from, and adapting to adverse cyber conditions.