Framework version 6.1 · generated from versions.json by build.py — do not edit by hand.
Each control carries an independent semantic version. MAJOR changes the control statement or its scope. MINOR adds or removes activities, components or mappings. PATCH is editorial. A control's version is bumped whenever its content changes, including when the change is prompted by a later family.
4.0.0 = first authoring at COBIT 2019 depth. Controls not listed below remain at 4.0.0 with no changes since first authoring.
Controls changed since first authoring
72 of 78 controls carry changes.
| Control | Version | Family |
|---|---|---|
TM-2 Defensive Layer Classification | 4.1.0 | TM |
TM-5 Connection and Denied-Path Register | 4.1.0 | TM |
KT-1 Decisive Point Identification | 4.0.1 | KT |
KT-2 Decisive Point Protection Floor | 4.2.0 | KT |
KT-3 Avenue of Approach Analysis | 4.1.0 | KT |
KT-4 Adversary Reachability Assessment | 4.0.1 | KT |
KT-5 Barrier Sufficiency | 4.0.1 | KT |
SM-1 Maneuver Catalog Adoption | 4.1.0 | SM |
SM-3 Implementation State Tracking | 4.2.0 | SM |
SM-4 Main Effort Designation | 4.1.0 | SM |
SM-5 Branches and Sequels | 4.0.1 | SM |
SM-6 Maneuver Effectiveness Validation | 4.1.0 | SM |
SM-7 Deception Emplacement | 5.0.0 | SM |
TA-1 Decision Loop Measurement | 4.2.0 | TA |
TA-2 Adversary Dwell Estimation | 4.1.1 | TA |
TA-3 Temporal Advantage Threshold | 4.1.0 | TA |
TA-4 Pre-authorized Response | 4.1.0 | TA |
TA-5 Tempo Degradation Trigger | 4.1.0 | TA |
CE-1 Cycle Cadence | 4.1.0 | CE |
CE-2 Priority Intelligence Requirements | 4.1.0 | CE |
CE-3 Fusion and Confidence | 4.1.0 | CE |
CE-4 Coverage and Residual Risk Computation | 4.1.0 | CE |
CE-5 Remediation Backlog Prioritization | 4.1.1 | CE |
CE-6 Cycle Record and Trend | 4.1.0 | CE |
CE-7 Brief Generation and Distribution | 4.1.0 | CE |
CG-1 Defensive Intent | 4.1.0 | CG |
CG-2 Phase Declaration | 4.2.0 | CG |
CG-3 Rules of Engagement | 4.1.0 | CG |
CG-4 Findings Disposition | 4.1.0 | CG |
CG-5 Control Inheritance Mapping | 4.1.1 | CG |
RC-1 Recovery Objectives | 4.1.1 | RC |
RC-2 Isolated Recovery Capability | 4.1.1 | RC |
RC-3 Trusted Rebuild Path | 4.2.0 | RC |
RC-4 Recovery Integrity Verification | 4.2.0 | RC |
RC-5 Reconstitution Exercise | 4.1.0 | RC |
FO-1 Privacy Terrain Identification | 4.1.0 | FO |
FO-2 Controlled Unclassified Information Handling | 4.1.0 | FO |
FO-3 Tenancy and Inheritance Boundary | 4.1.0 | FO |
FO-4 Operational Technology Terrain | 4.1.0 | FO |
FO-5 Statutory Availability Floor | 4.1.0 | FO |
FO-6 Supply Chain Obligation | 5.1.0 | FO |
FO-7 Obligation Profile Declaration | 5.0.0 | FO |
WF-1 Workforce Terrain Identification | 4.1.0 | WF |
WF-2 Privileged Human Register | 4.1.0 | WF |
WF-3 Role-Based Readiness | 4.1.0 | WF |
WF-4 Insider Risk Position | 4.1.0 | WF |
WF-5 Separation and Revocation Tempo | 4.2.0 | WF |
FC-1 Facility Terrain Identification | 4.1.0 | FC |
FC-2 Physical Zone Boundary | 4.1.0 | FC |
FC-3 Maintenance Access Control | 4.1.0 | FC |
FC-4 Environmental Continuity | 4.1.0 | FC |
LC-1 Supplier Terrain Register | 4.2.0 | LC |
LC-2 Component Provenance | 4.1.0 | LC |
LC-3 Supplier Access Constraint | 4.1.0 | LC |
LC-4 Update Integrity and Staging | 4.1.0 | LC |
LC-5 Supplier Severance Capability | 4.1.0 | LC |
ID-1 Identity Plane Definition | 5.0.0 | ID |
ID-2 Credential Strength and Binding | 5.0.0 | ID |
ID-3 Authentication Assurance | 5.0.0 | ID |
ID-4 Identity Assertion Protection | 5.0.0 | ID |
ID-5 Authorization Decision Integrity | 5.0.0 | ID |
EN-1 Event Declaration and Triage | 5.0.0 | EN |
EN-2 Engagement Reconstruction | 5.0.0 | EN |
EN-3 Evidence Preservation | 5.0.0 | EN |
EN-4 Escalation and Engagement Authority | 5.0.0 | EN |
EN-5 Eradication and Transition to Recovery | 5.0.0 | EN |
EN-6 Engagement Communication | 5.0.0 | EN |
DV-1 Device Terrain Identification | 6.0.0 | DV |
DV-2 Device Posture as an Access Precondition | 6.0.0 | DV |
DV-3 Endpoint Sensor Coverage and Liveness | 6.0.0 | DV |
DV-4 Execution Control | 6.0.0 | DV |
DV-5 Device Lifecycle and Sanitization | 6.0.0 | DV |
Detail
TM-1 — Terrain Inventory and Overlay · v4.0.0
- 4.0.0 — First authoring at 2019 depth. Retrofitted from the 4.1 Control Practices pilot: numbered practices became capability-leveled activities; value and risk drivers absorbed into purpose, discussion and the culture component.
TM-2 — Defensive Layer Classification · v4.1.0
- 4.1.0 — MAJOR-adjacent scope correction. v3.0 statement enumerated five defensive layers, making every element on T6-T9 and TX unclassifiable under the control mandating classification, while FO-4, WF-1, FC-1 and LC-1 all require that classification. Statement now carries the full v3.0 ten-layer model. Added L4 activity requiring escalation where a declared terrain layer holds no classified elements. Added PM-5 to inheritance and ID.AM-01 to CSF mapping.
TM-3 — Asset Weighting · v4.0.0
- 4.0.0 — First authoring at 2019 depth.
TM-4 — Trust Zone Definition · v4.0.0
- 4.0.0 — First authoring at 2019 depth.
TM-5 — Connection and Denied-Path Register · v4.1.0
- 4.1.0 — MINOR. Added an explicit third connectivity state (unknown), distinguished from absence. v3.0 recorded permitted and denied only, which caused unknown connectivity to be treated as absent and produced confidently wrong reachability results downstream in KT-4.
TM-6 — Terrain Currency · v4.0.0
- 4.0.0 — First authoring at 2019 depth.
TM-7 — Terrain Ownership · v4.0.0
- 4.0.0 — First authoring at 2019 depth.
KT-1 — Decisive Point Identification · v4.0.1
- 4.0.1 — PATCH. Backfill after CG authoring: designation criteria now derived from the defensive intent (CG-1) rather than from an unsourced standard. Decisiveness is a judgment about purpose, and CG-1 is where purpose is stated.
- 4.0.0 — First authoring at 2019 depth.
KT-2 — Decisive Point Protection Floor · v4.2.0
- 4.2.0 — MINOR. Backfill after FO-4 and SM-3: constrained moves are excluded from the effective coverage denominator, so a decisive point on operational technology is scored against achievable coverage rather than against a floor it cannot reach.
- 4.1.0 — MINOR. Backfill after TA-3 and GA4: the coverage floor now requires accountable-authority approval with the date recorded relative to first measurement. Without this, the floor is set wherever the program already passes and can never report a deficit.
- 4.0.0 — First authoring at 2019 depth.
KT-3 — Avenue of Approach Analysis · v4.1.0
- 4.1.0 — MINOR, scope-widening. Activity 5 now requires enumeration of approach routes through workforce, facility and supplier terrain, not only network paths. v3.0 read as network path analysis while declaring T7-T9 as terrain; those are three of the most-used federal intrusion paths.
KT-4 — Adversary Reachability Assessment · v4.0.1
- 4.0.1 — PATCH. Added mandatory joint assessment with KT-5. A negative reachability result holds only while KT-5 barriers remain enforced, so KT-4 assessed alone can certify a conclusion a later barrier change has already invalidated.
- 4.0.0 — First authoring at 2019 depth.
KT-5 — Barrier Sufficiency · v4.0.1
- 4.0.1 — PATCH. Mirror of the KT-4 joint assessment requirement.
- 4.0.0 — First authoring at 2019 depth.
SM-1 — Maneuver Catalog Adoption · v4.1.0
- 4.1.0 — MINOR. Corrects the published CSV, which recorded 'the ten-move catalog' against a v3.0 framework carrying eleven forms; the DOCX was already correct. Added the five admission criteria for locally defined moves, which v3.0 referenced only implicitly.
SM-2 — Maneuver Assignment · v4.0.0
- 4.0.0 — First authoring at 2019 depth.
SM-3 — Implementation State Tracking · v4.2.0
- 4.2.0 — MINOR. Backfill after FO-4: adds a fourth implementation state, constrained, for moves made genuinely unavailable by a recorded terrain constraint. Without it an OT element that cannot be patched or restarted on the defender's schedule sits permanently as planned and depresses coverage forever, which trains OT owners to disengage from the program.
- 4.1.0 — MINOR. Added state definitions tied to observable conditions, an evidence requirement for transition to operational, and a false-operational rate metric derived from sampling. SM-3 carries the entire posture computation and was the framework's most fragile control: defeasible by optimistic self-declaration with no downstream detection.
SM-4 — Main Effort Designation · v4.1.0
- 4.1.0 — MINOR. Added an explicit subordination requirement (state what is deprioritized) and a resourcing evidence test. A main effort that subordinates nothing and moved no allocation is a label, and the v3.0 assessment could not distinguish the two.
SM-5 — Branches and Sequels · v4.0.1
- 4.0.1 — PATCH. CSF recovery: adds ID.IM-04 (incident response plans established) — branches and sequels with linked response procedures constitute the plan.
- 4.0.0 — First authoring at 2019 depth.
SM-6 — Maneuver Effectiveness Validation · v4.1.0
- 4.1.0 — MINOR. RACI responsibility assigned to the hunt team rather than terrain owners, on independence grounds: the party that emplaced a move is the wrong party to certify it. Added an assessment step examining whether any effectiveness weighting has ever been reduced.
SM-7 — Deception Emplacement · v5.0.0
- 5.0.0 — NEW in v5.0. Closes the Deceive tactic, which reverse coverage found at zero of D3FEND's seven despite M5 Ambush carrying thirteen techniques and being the dominant effort of Phase I. Alert-to-human period derived from the TA-1 decide segment: a deception alert routed to a queue triaged tomorrow discards the no-false-positive property that made it worth emplacing.
TA-1 — Decision Loop Measurement · v4.2.0
- 4.2.0 — MINOR. Backfill after EN: the decide segment is constituted by EN-1 triage and EN-4 escalation, and time should be attributed between them — a slow triage and an unreachable authority are different problems with different remedies.
- 4.1.0 — MINOR. Requires segment-level measurement (detect / decide / contain) reported separately. The segments fail for different reasons and the binding constraint is usually decide latency, which no detection investment shortens. v3.0 reported the total only.
TA-2 — Adversary Dwell Estimation · v4.1.1
- 4.1.1 — PATCH. Backfill after EN: the local dwell series is built from EN-2 reconstructions, which is now a control rather than an M10 intention.
- 4.1.0 — MINOR. Requires explicit statement of the estimate's known bias: dwell is observable only in discovered intrusions, biasing the sample toward slow adversaries. The signature metric rests half on an imported figure and that should be visible in the result rather than concealed in the ratio.
TA-3 — Temporal Advantage Threshold · v4.1.0
- 4.1.0 — MINOR. Records threshold approval date relative to first measurement, closing the post-hoc threshold problem. Generalised framework-wide as GA4.
TA-4 — Pre-authorized Response · v4.1.0
- 4.1.0 — MINOR. Added RS.MI-01 to the CSF mapping; pre-authorized containment genuinely supports the Respond/Mitigate outcome. First deliberate step against the Detect/Respond thinness identified in the v3.0 catalog analysis. Authorizations now bounded by condition, scope and duration, and keyed to campaign phase.
TA-5 — Tempo Degradation Trigger · v4.1.0
- 4.1.0 — MINOR. Degradation conditions widened to organizational causes: contract transition, key-person absence, hiring gaps, handover windows. v3.0 read as out-of-hours coverage only. Added incident-timing correlation against degraded windows.
CE-1 — Cycle Cadence · v4.1.0
- 4.1.0 — MINOR. Added definition of which cycle steps may be abbreviated under load, and correlation of lapses against incident volume. The cycle is sacrificed exactly when it is most needed, and a cadence holding only in quiet periods is not a cadence.
CE-2 — Priority Intelligence Requirements · v4.1.0
- 4.1.0 — MINOR. Added closure as 'unanswerable with current collection', raised as a visibility finding. Converts a perpetually open requirement into a finding about collection rather than an item carried forward indefinitely.
CE-3 — Fusion and Confidence · v4.1.0
- 4.1.0 — MINOR. Added measurement of the distribution of issued confidence levels and calibration review against subsequent evidence. A function that never publishes low confidence is unfalsifiable rather than careful.
CE-4 — Coverage and Residual Risk Computation · v4.1.0
- 4.1.0 — MINOR. Requires the denominator to be stated wherever the figure is published, including the ground-held versus techniques-evidenced choice and its rationale; requires framework version recorded against every computed figure; adds sensitivity analysis against the most uncertain input.
CE-5 — Remediation Backlog Prioritization · v4.1.1
- 4.1.1 — PATCH. CSF recovery: adds GV.RM-06 (risk response prioritization) — CE-5 ranks by risk retired per unit effort.
- 4.1.0 — MINOR. Requires effort estimates on a defined scale so the risk-per-effort ratio can be computed rather than intuited. A backlog with risk scores and no effort estimates has not implemented this control.
CE-6 — Cycle Record and Trend · v4.1.0
- 4.1.0 — MINOR, correctness-critical. Requires the framework version against every point and a visible break in the trend line at any version boundary. The framework's own versioning rules make cross-version coverage scores incomparable; a series plotted across a boundary shows movement that is a denominator artifact. Two structural releases have already occurred, so existing multi-cycle series in the field are likely affected.
CE-7 — Brief Generation and Distribution · v4.1.0
- 4.1.0 — MINOR. Requires decisions taken from each Brief to be recorded, so use is evidenced rather than assumed. Generation and distribution satisfy the literal requirement while delivering nothing.
CG-1 — Defensive Intent · v4.1.0
- 4.1.0 — MINOR. Requires the intent to state what may be traded and in what order. An intent that subordinates nothing cannot resolve the decision it exists for, and the operator escalates, which is the decide latency TA-1 measures. Added comprehension testing against a decision the intent should resolve.
CG-2 — Phase Declaration · v4.2.0
- 4.2.0 — MINOR. Backfill after EN-1: phase entry conditions bound to declaration criteria, so a declared incident meeting a phase entry condition routes to the transition decision rather than being handled locally.
- 4.1.0 — MINOR. Requires at least one consequential control to be keyed to phase, and the assessment now tests what materially changed at the last transition rather than that a declaration exists.
CG-3 — Rules of Engagement · v4.1.0
- 4.1.0 — MINOR. Requires the boundary limit (no action outside the agency's own terrain) to be written rather than inferred from doctrine; requires statutory constraints recorded with reference to FO-5 availability floors; requires out-of-hours authority reachability to be tested rather than assumed.
CG-4 — Findings Disposition · v4.1.0
- 4.1.0 — MINOR. Requires acceptance by a named person whose risk authority covers the exposure, and an expiry forcing re-decision. Adds trending of accepted alongside open. Closes the route by which a program reports a shrinking open set while the accepted set grows without limit.
CG-5 — Control Inheritance Mapping · v4.1.1
- 4.1.1 — PATCH. Backfill after FO-3: names FO-3 as the provider-scope sibling. CG-5 verifies inheritance from a control baseline, FO-3 from a service provider, and a requirement can fall between the two if neither is checked.
- 4.1.0 — MINOR. Requires inheritance claims to be verified against the specific assessment result cited rather than asserted at family level, and a failed verification to be recorded as an unassessed requirement. Adds measurement of ASOM-Fed's true marginal assessment cost over the existing baseline.
RC-1 — Recovery Objectives · v4.1.1
- 4.1.1 — PATCH. CSF recovery: adds GV.OC-05 (dependencies determined) — RC-1 already requires the dependency chain per mission service.
- 4.1.0 — MINOR. Requires objectives to satisfy any statutory availability floor under FO-5, and to be approved by the service owner with provenance per GA4. Adds the distinction between a declared objective and a demonstrated one, which is RC-5's object.
RC-2 — Isolated Recovery Capability · v4.1.1
- 4.1.1 — PATCH. CSF recovery: adds PR.IR-03 (resilience mechanisms) — isolated recovery capability is a resilience mechanism in the CSF sense.
- 4.1.0 — MINOR. Adds explicit authentication-path independence testing. v3.0 required the recovery store to sit outside the production trust boundary; the operative test is whether a production administrator credential can reach it, which is narrower and testable.
RC-3 — Trusted Rebuild Path · v4.2.0
- 4.2.0 — MINOR. Backfill after LC-2: trusted rebuild media must also carry verified component provenance. Media independent of the compromised environment but built from a compromised supply chain reconstitutes the intrusion with the system, which media-source independence alone does not catch.
- 4.1.0 — MINOR. Requires the rebuild path for the identity plane itself to be tested. Most rebuild plans assume a working identity plane; where identity is what was compromised, the plan carries a circular dependency that only surfaces during recovery.
RC-4 — Recovery Integrity Verification · v4.2.0
- 4.2.0 — MINOR. Backfill after EN-2: restore point selected against the engagement reconstruction where one exists, falling back to the TA-2 dwell estimate otherwise. A reconstruction gives the actual entry time; the estimate is only a bound.
- 4.1.0 — MINOR. Requires the integrity record to predate the earliest plausible compromise, not merely to be independently maintained. Restoring from a point after intrusion reinstates the adversary with the data.
RC-5 — Reconstitution Exercise · v4.1.0
- 4.1.0 — MINOR. Requires every declared objective to have been demonstrated within its stated period, and scenario realism to include loss of the identity plane. Adds exercise cadence provenance per GA4.
FO-1 — Privacy Terrain Identification · v4.1.0
- 4.1.0 — MINOR. Requires derived and incidental holdings (logs, caches, analytics stores, backups) to be included, and unauthorized holdings to be dispositioned as removal rather than protection where the mission permits. Adds two-way reconciliation against privacy impact assessments and systems of records notices. Adds trending on the count and weight of privacy terrain, which a defensible program should see fall.
FO-2 — Controlled Unclassified Information Handling · v4.1.0
- 4.1.0 — MINOR. Requires declared boundaries to be instrumented, not only prohibited: an undeclared flow across an uninstrumented boundary is an absence rather than a finding. Extends flow declaration to flows leaving the authorization boundary, and requires declaration by CUI category where handling requirements differ.
FO-3 — Tenancy and Inheritance Boundary · v4.1.0
- 4.1.0 — MINOR. Requires each customer responsibility to carry both an owner and an operational move, since an owned but unimplemented responsibility reports as assigned. Adds recording of cases where agency usage falls outside the provider's authorized scope, in which inheritance does not apply.
FO-4 — Operational Technology Terrain · v4.1.0
- 4.1.0 — MINOR. Requires the unavailable-move set to be recorded per OT element with its cause (patch window, restart constraint, vendor certification, safety interlock), so coverage is scored against what is achievable rather than carrying permanent unactionable findings. Requires reconciliation against the engineering or facilities operational inventory rather than the IT asset inventory, and testing of declared connections against observed traffic.
FO-5 — Statutory Availability Floor · v4.1.0
- 4.1.0 — MINOR. Requires floors to be carried into the rules of engagement (CG-3) and the pre-authorized response set (TA-4), so an operator knows at incident time which degradations are legally unavailable. Requires seasonal and cyclical floors to be recorded distinctly, since many federal deadlines bind only in defined periods. Requires legal confirmation rather than operational derivation.
FO-6 — Supply Chain Obligation · v5.1.0
- 5.1.0 — MINOR. CSF recovery: adds GV.SC-01 (SCRM program established), GV.SC-06 (pre-contract due diligence) and ID.RA-10 (critical supplier assessment). FO-6 is the SCRM program control and requires pre-award assessment, so these were excluded in error rather than by scope.
- 5.0.0 — MAJOR, scope change. The v3.0 statement duplicated LC-1 Supplier Terrain Register: both required suppliers with a path into the estate to be represented on the overlay with access recorded. Duplicate controls double-count supply chain coverage in every scored estate, which the framework's own design rules identify as the failure mode degrading a catalog fastest. FO-6 is narrowed to the federal SCRM obligation and its recorded scope; LC-1 retains the operational terrain register. Retitled from 'Supply Chain Terrain' to 'Supply Chain Obligation'. Requires framework owner ratification before publication.
- 4.0.0 — First authoring at 2019 depth, prior to the duplication being identified.
FO-7 — Obligation Profile Declaration · v5.0.0
- 5.0.0 — NEW in v5.0. Declares the per-agency obligation profile the v2.0 design assumed but never required. Makes the FO denominator an approved, published position so coverage figures are comparable between agencies and exclusions are recorded decisions rather than silences.
WF-1 — Workforce Terrain Identification · v4.1.0
- 4.1.0 — MINOR. Requires roles with indirect access to be included (helpdesk, delegated administration, approval authorities, equivalent-reach contractor roles), exclusion justifications to be recorded, and population size to be trended. Population growth in a high-value role is an expansion of terrain no asset inventory reports.
WF-2 — Privileged Human Register · v4.1.0
- 4.1.0 — MINOR. Requires vetting to be verified against access currently held rather than access held when vetted; requires shared, service and non-human accounts to be recorded distinctly with a named accountable human rather than treated as register exceptions; adds measurement of accumulated privilege per holder, entitlement growth around a correctly vetted person being the common failure.
WF-3 — Role-Based Readiness · v4.1.0
- 4.1.0 — MINOR. Requires explicit rules on how individual results may and may not be used, and correlation of measured readiness against real incidents involving those roles. A program that sanctions individuals for simulation failure trains concealment of real incidents. Adds threshold provenance per GA4.
WF-4 — Insider Risk Position · v4.1.0
- 4.1.0 — MINOR. Rights safeguards made assessable rather than advisory: legal and privacy review recorded before use, staged access rules so escalation of access follows escalation of evidence, explicit residue rules for unsubstantiated closures, and defined handoff to HR, counsel or law enforcement. Adds measurement of the unsubstantiated closure rate as a two-sided indicator of whether the initiation threshold is set correctly. RACI responsibility assigned to governance rather than the SOC.
WF-5 — Separation and Revocation Tempo · v4.2.0
- 4.2.0 — MINOR. Backfill after FC-2: physical access (badge and facility credentials) made explicit in the enumeration of access outside the primary identity provider. Revocation processes routinely disable the identity-provider account and leave the badge live, which satisfies the single-action property on paper while leaving the person able to enter the building.
- 4.1.0 — MINOR. Requires the period to be derived from the tempo at which access could be misused rather than from current process capability; requires enumeration of access outside the primary identity provider; distinguishes planned departure, immediate separation and suspension; requires revocation verified by testing access rather than by ticket closure.
FC-1 — Facility Terrain Identification · v4.1.0
- 4.1.0 — MINOR. Requires every designated decisive point to resolve to a named facility or a recorded provider region. An agency that cannot say which building its identity provider's hardware occupies cannot defend it physically, plan its rebuild under RC-3, or compare its environmental sustain period against dependent recovery objectives. Adds physical verification of sampled facility contents and concentration findings for siting.
FC-2 — Physical Zone Boundary · v4.1.0
- 4.1.0 — MINOR. Requires individual attribution at boundaries protecting decisive points, addressing unattributed entry (tailgating): a log recording which badge opened a door rather than who passed through cannot answer an investigation's question. Requires crossing log retention matched to the dwell estimate (TA-2) rather than to a fixed period. Distinguishes physical zones from TM-4 logical trust zones explicitly.
FC-3 — Maintenance Access Control · v4.1.0
- 4.1.0 — MINOR. Requires maintenance access to be technically absent outside its window rather than merely unused, with the achieving mechanism recorded; requires session activity logged to agency-held storage so the record survives the vendor relationship; requires scoping to the task rather than to the privilege the vendor requests. States the boundary with LC-3 explicitly to prevent the FO-6/LC-1 duplication pattern recurring.
FC-4 — Environmental Continuity · v4.1.0
- 4.1.0 — MINOR. Requires sustain periods to be tested rather than taken from design specification or vendor rating, and compared against the recovery objectives (RC-1) of services housed in the facility, raising a finding on every contradiction. A four-hour supply under a twenty-four-hour objective is invisible while the two figures live in separate documents. Adds the degradation sequence so loss order is planned rather than discovered.
LC-1 — Supplier Terrain Register · v4.2.0
- 4.2.0 — MINOR. Confirmed as sole owner of the supplier terrain register following the FO-6 narrowing. Requires reconciliation against provisioned access rather than the acquisition record, since contracts describe intent and entitlements describe capability; requires transitive reach to be recorded; requires reconciliation against SCRM scope under FO-6 so an access-holding supplier outside scope is a recorded position rather than an oversight.
- 4.0.0 — First authoring at 2019 depth.
LC-2 — Component Provenance · v4.1.0
- 4.1.0 — MINOR. Separates provenance from contents explicitly: a correctly signed package containing a vulnerable transitive dependency has verified provenance and unknown content. Requires the inventory to extend to transitive dependencies and to be current at deployment rather than reconstructed under disclosure pressure. Outcome metric changed to time-to-answer whether a named component is deployed and where, which is the control's real capability.
LC-3 — Supplier Access Constraint · v4.1.0
- 4.1.0 — MINOR. Requires verification that revocation is technically within the agency's control rather than dependent on supplier action, which is the precondition for LC-5 severance. Requires an expiry on every grant rather than only where obvious, and application to supplier-managed infrastructure where the identity plane is the supplier's by default. States the FC-3 boundary explicitly.
LC-4 — Update Integrity and Staging · v4.1.0
- 4.1.0 — MINOR. Soak period derived from the measured detection segment under TA-1 with provenance per GA4, rather than chosen from a release calendar: a ring protects only if soak exceeds time-to-notice. Requires the ring to be representative of the estate rather than of the systems most tolerant of disruption, behavioral instrumentation rather than functional testing alone, and a defined emergency bypass path with named authority.
LC-5 — Supplier Severance Capability · v4.1.0
- 4.1.0 — MINOR. Requires mission continuity assessment following severance, recorded as a finding where the mission cannot continue rather than accepted silently. Requires the period derived from what the access could do if turned hostile rather than from contractual notice terms; requires demonstration for suppliers reaching decisive points rather than for the easiest supplier to test; distinguishes severance from termination.
ID-1 — Identity Plane Definition · v5.0.0
- 5.0.0 — NEW in v5.0. Identity plane, enforcement point and trust edge mapping. Trust edges between planes are the highest-value terrain in the estate and are invisible on a network diagram.
ID-2 — Credential Strength and Binding · v5.0.0
- 5.0.0 — NEW in v5.0. Proofing and credential strength matched to conferred access, extended to non-human identities where long-lived secrets are the dominant failure.
ID-3 — Authentication Assurance · v5.0.0
- 5.0.0 — NEW in v5.0. Authentication assurance carried into the authorization decision, with direct captured-credential testing. Makes M3 Envelopment's stated indicator assessable for the first time.
ID-4 — Identity Assertion Protection · v5.0.0
- 5.0.0 — NEW in v5.0. Assertion, token and session protection with lifetime keyed to campaign phase and verified estate-wide revocation. Strong authentication is routinely defeated downstream by long-lived bearer tokens.
ID-5 — Authorization Decision Integrity · v5.0.0
- 5.0.0 — NEW in v5.0. Authorization decision point coverage and policy change integrity. An adversary who can add a policy rule authorizes themselves without defeating any other control in the family.
EN-1 — Event Declaration and Triage · v5.0.0
- 5.0.0 — NEW in v5.0. Event declaration, triage, validation, categorization and prioritization. Declaration criteria fix the threshold so it does not move with analyst judgment or workload, which is what makes cross-cycle tempo comparison valid.
EN-2 — Engagement Reconstruction · v5.0.0
- 5.0.0 — NEW in v5.0. Engagement reconstruction — entry, movement, dwell, scope, magnitude and investigation record. M10's stated precondition, previously an intention with no control behind it. RC-4, TA-2, CE-2 and M10.02 all depend on it.
EN-3 — Evidence Preservation · v5.0.0
- 5.0.0 — NEW in v5.0. Evidence preservation with retention derived from the dwell estimate and chain of custody. Retention is the one failure that cannot be remediated afterwards.
EN-4 — Escalation and Engagement Authority · v5.0.0
- 5.0.0 — NEW in v5.0. Escalation criteria and reachable authority. With TA-4 this constitutes the decide segment; the binding constraint is usually locating a decision-maker, which is an availability problem rather than a judgment one.
EN-5 — Eradication and Transition to Recovery · v5.0.0
- 5.0.0 — NEW in v5.0. Eradication verified by hunting against reconstructed tradecraft rather than inferred from absence of observation, including identity-plane eradication, plus the decided transition to recovery with scoped actions.
EN-6 — Engagement Communication · v5.0.0
- 5.0.0 — NEW in v5.0. Engagement communication across internal, federal community and public audiences, with statutory reporting windows and designated authority per audience.
DV-1 — Device Terrain Identification · v6.0.0
- 6.0.0 — PATCH. Technique back-references added so the control is reachable from the maneuver matrix, closing the orphan condition the suite auditor now fails the build on.
- 5.2.0 — NEW in v5.2. Device terrain identification with management state, population and reach, reconciled against the identity plane rather than the endpoint console — the console can only report devices it already manages. Recovers ID.AM-02 software inventory.
DV-2 — Device Posture as an Access Precondition · v6.0.0
- 6.0.0 — PATCH. Technique back-references added so the control is reachable from the maneuver matrix, closing the orphan condition the suite auditor now fails the build on.
- 5.2.0 — NEW in v5.2. Device posture as an access precondition, feeding device assurance into the ID-5 authorization decision. Failing posture must deny, not notify. Recovers PR.PS-01.
DV-3 — Endpoint Sensor Coverage and Liveness · v6.0.0
- 6.0.0 — PATCH. Technique back-references added so the control is reachable from the maneuver matrix, closing the orphan condition the suite auditor now fails the build on.
- 5.2.0 — NEW in v5.2. Sensor coverage reconciled to the device inventory rather than the sensor console, and sensor liveness treated as a security event. Endpoint retention derived from the dwell estimate so EN-2 reconstruction can reach the entry point. Recovers PR.PS-04 and DE.CM-09.
DV-4 — Execution Control · v6.0.0
- 6.0.0 — PATCH. Technique back-references added so the control is reachable from the maneuver matrix, closing the orphan condition the suite auditor now fails the build on.
- 5.2.0 — NEW in v5.2. Execution control scoped to designated terrain rather than universally, with the approved set derived from LC-2 provenance. Recovers PR.PS-05.
DV-5 — Device Lifecycle and Sanitization · v6.0.0
- 6.0.0 — PATCH. Technique back-references added so the control is reachable from the maneuver matrix, closing the orphan condition the suite auditor now fails the build on.
- 5.2.0 — NEW in v5.2. Device lifecycle: trusted provisioning and, critically, trust removal and sanitization on retirement, loss or reassignment within a period derived from what retained trust could do.