HISTORY

Control Changelog

Per-control version history. Every control carries an independent semantic version, so an adopter can see exactly what moved beneath them.

ASOM-Fed v6.1 · Unclassified / Illustrative · agency-agnostic reference framework · built from public sources only

Framework version 6.1 · generated from versions.json by build.py — do not edit by hand.

Each control carries an independent semantic version. MAJOR changes the control statement or its scope. MINOR adds or removes activities, components or mappings. PATCH is editorial. A control's version is bumped whenever its content changes, including when the change is prompted by a later family.

4.0.0 = first authoring at COBIT 2019 depth. Controls not listed below remain at 4.0.0 with no changes since first authoring.


Controls changed since first authoring

72 of 78 controls carry changes.

ControlVersionFamily
TM-2 Defensive Layer Classification4.1.0TM
TM-5 Connection and Denied-Path Register4.1.0TM
KT-1 Decisive Point Identification4.0.1KT
KT-2 Decisive Point Protection Floor4.2.0KT
KT-3 Avenue of Approach Analysis4.1.0KT
KT-4 Adversary Reachability Assessment4.0.1KT
KT-5 Barrier Sufficiency4.0.1KT
SM-1 Maneuver Catalog Adoption4.1.0SM
SM-3 Implementation State Tracking4.2.0SM
SM-4 Main Effort Designation4.1.0SM
SM-5 Branches and Sequels4.0.1SM
SM-6 Maneuver Effectiveness Validation4.1.0SM
SM-7 Deception Emplacement5.0.0SM
TA-1 Decision Loop Measurement4.2.0TA
TA-2 Adversary Dwell Estimation4.1.1TA
TA-3 Temporal Advantage Threshold4.1.0TA
TA-4 Pre-authorized Response4.1.0TA
TA-5 Tempo Degradation Trigger4.1.0TA
CE-1 Cycle Cadence4.1.0CE
CE-2 Priority Intelligence Requirements4.1.0CE
CE-3 Fusion and Confidence4.1.0CE
CE-4 Coverage and Residual Risk Computation4.1.0CE
CE-5 Remediation Backlog Prioritization4.1.1CE
CE-6 Cycle Record and Trend4.1.0CE
CE-7 Brief Generation and Distribution4.1.0CE
CG-1 Defensive Intent4.1.0CG
CG-2 Phase Declaration4.2.0CG
CG-3 Rules of Engagement4.1.0CG
CG-4 Findings Disposition4.1.0CG
CG-5 Control Inheritance Mapping4.1.1CG
RC-1 Recovery Objectives4.1.1RC
RC-2 Isolated Recovery Capability4.1.1RC
RC-3 Trusted Rebuild Path4.2.0RC
RC-4 Recovery Integrity Verification4.2.0RC
RC-5 Reconstitution Exercise4.1.0RC
FO-1 Privacy Terrain Identification4.1.0FO
FO-2 Controlled Unclassified Information Handling4.1.0FO
FO-3 Tenancy and Inheritance Boundary4.1.0FO
FO-4 Operational Technology Terrain4.1.0FO
FO-5 Statutory Availability Floor4.1.0FO
FO-6 Supply Chain Obligation5.1.0FO
FO-7 Obligation Profile Declaration5.0.0FO
WF-1 Workforce Terrain Identification4.1.0WF
WF-2 Privileged Human Register4.1.0WF
WF-3 Role-Based Readiness4.1.0WF
WF-4 Insider Risk Position4.1.0WF
WF-5 Separation and Revocation Tempo4.2.0WF
FC-1 Facility Terrain Identification4.1.0FC
FC-2 Physical Zone Boundary4.1.0FC
FC-3 Maintenance Access Control4.1.0FC
FC-4 Environmental Continuity4.1.0FC
LC-1 Supplier Terrain Register4.2.0LC
LC-2 Component Provenance4.1.0LC
LC-3 Supplier Access Constraint4.1.0LC
LC-4 Update Integrity and Staging4.1.0LC
LC-5 Supplier Severance Capability4.1.0LC
ID-1 Identity Plane Definition5.0.0ID
ID-2 Credential Strength and Binding5.0.0ID
ID-3 Authentication Assurance5.0.0ID
ID-4 Identity Assertion Protection5.0.0ID
ID-5 Authorization Decision Integrity5.0.0ID
EN-1 Event Declaration and Triage5.0.0EN
EN-2 Engagement Reconstruction5.0.0EN
EN-3 Evidence Preservation5.0.0EN
EN-4 Escalation and Engagement Authority5.0.0EN
EN-5 Eradication and Transition to Recovery5.0.0EN
EN-6 Engagement Communication5.0.0EN
DV-1 Device Terrain Identification6.0.0DV
DV-2 Device Posture as an Access Precondition6.0.0DV
DV-3 Endpoint Sensor Coverage and Liveness6.0.0DV
DV-4 Execution Control6.0.0DV
DV-5 Device Lifecycle and Sanitization6.0.0DV

Detail

TM-1 — Terrain Inventory and Overlay · v4.0.0

TM-2 — Defensive Layer Classification · v4.1.0

TM-3 — Asset Weighting · v4.0.0

TM-4 — Trust Zone Definition · v4.0.0

TM-5 — Connection and Denied-Path Register · v4.1.0

TM-6 — Terrain Currency · v4.0.0

TM-7 — Terrain Ownership · v4.0.0

KT-1 — Decisive Point Identification · v4.0.1

KT-2 — Decisive Point Protection Floor · v4.2.0

KT-3 — Avenue of Approach Analysis · v4.1.0

KT-4 — Adversary Reachability Assessment · v4.0.1

KT-5 — Barrier Sufficiency · v4.0.1

SM-1 — Maneuver Catalog Adoption · v4.1.0

SM-2 — Maneuver Assignment · v4.0.0

SM-3 — Implementation State Tracking · v4.2.0

SM-4 — Main Effort Designation · v4.1.0

SM-5 — Branches and Sequels · v4.0.1

SM-6 — Maneuver Effectiveness Validation · v4.1.0

SM-7 — Deception Emplacement · v5.0.0

TA-1 — Decision Loop Measurement · v4.2.0

TA-2 — Adversary Dwell Estimation · v4.1.1

TA-3 — Temporal Advantage Threshold · v4.1.0

TA-4 — Pre-authorized Response · v4.1.0

TA-5 — Tempo Degradation Trigger · v4.1.0

CE-1 — Cycle Cadence · v4.1.0

CE-2 — Priority Intelligence Requirements · v4.1.0

CE-3 — Fusion and Confidence · v4.1.0

CE-4 — Coverage and Residual Risk Computation · v4.1.0

CE-5 — Remediation Backlog Prioritization · v4.1.1

CE-6 — Cycle Record and Trend · v4.1.0

CE-7 — Brief Generation and Distribution · v4.1.0

CG-1 — Defensive Intent · v4.1.0

CG-2 — Phase Declaration · v4.2.0

CG-3 — Rules of Engagement · v4.1.0

CG-4 — Findings Disposition · v4.1.0

CG-5 — Control Inheritance Mapping · v4.1.1

RC-1 — Recovery Objectives · v4.1.1

RC-2 — Isolated Recovery Capability · v4.1.1

RC-3 — Trusted Rebuild Path · v4.2.0

RC-4 — Recovery Integrity Verification · v4.2.0

RC-5 — Reconstitution Exercise · v4.1.0

FO-1 — Privacy Terrain Identification · v4.1.0

FO-2 — Controlled Unclassified Information Handling · v4.1.0

FO-3 — Tenancy and Inheritance Boundary · v4.1.0

FO-4 — Operational Technology Terrain · v4.1.0

FO-5 — Statutory Availability Floor · v4.1.0

FO-6 — Supply Chain Obligation · v5.1.0

FO-7 — Obligation Profile Declaration · v5.0.0

WF-1 — Workforce Terrain Identification · v4.1.0

WF-2 — Privileged Human Register · v4.1.0

WF-3 — Role-Based Readiness · v4.1.0

WF-4 — Insider Risk Position · v4.1.0

WF-5 — Separation and Revocation Tempo · v4.2.0

FC-1 — Facility Terrain Identification · v4.1.0

FC-2 — Physical Zone Boundary · v4.1.0

FC-3 — Maintenance Access Control · v4.1.0

FC-4 — Environmental Continuity · v4.1.0

LC-1 — Supplier Terrain Register · v4.2.0

LC-2 — Component Provenance · v4.1.0

LC-3 — Supplier Access Constraint · v4.1.0

LC-4 — Update Integrity and Staging · v4.1.0

LC-5 — Supplier Severance Capability · v4.1.0

ID-1 — Identity Plane Definition · v5.0.0

ID-2 — Credential Strength and Binding · v5.0.0

ID-3 — Authentication Assurance · v5.0.0

ID-4 — Identity Assertion Protection · v5.0.0

ID-5 — Authorization Decision Integrity · v5.0.0

EN-1 — Event Declaration and Triage · v5.0.0

EN-2 — Engagement Reconstruction · v5.0.0

EN-3 — Evidence Preservation · v5.0.0

EN-4 — Escalation and Engagement Authority · v5.0.0

EN-5 — Eradication and Transition to Recovery · v5.0.0

EN-6 — Engagement Communication · v5.0.0

DV-1 — Device Terrain Identification · v6.0.0

DV-2 — Device Posture as an Access Precondition · v6.0.0

DV-3 — Endpoint Sensor Coverage and Liveness · v6.0.0

DV-4 — Execution Control · v6.0.0

DV-5 — Device Lifecycle and Sanitization · v6.0.0