This session will explain the concept of Rate of Security Control Degradation and the contribution it has on root cause of intrusions. Presenters will then propose a life cycle that includes unscheduled tests in the context of specific threat scenarios, control points, and monitoring that matches Threat Informed Defense efforts to mitigate the effects.