Generated from the published catalog, so this page and the machine-readable export cannot disagree. 78 controls, 784 activities.
TM · Terrain Management
Inventory, classification, weighting, zones, connections, currency, ownership
TM-1 · Terrain Inventory and Overlay
Control. The organization shall maintain a current graphical overlay of all systems, data stores, and external actors within the authorization boundary, including the trust zones in which they reside.
Purpose. To establish one authoritative positional picture of the estate, so that every later judgment about priority, reachability and risk is made against the same ground.
A register in a spreadsheet is not terrain. Terrain is positional: it records where an element sits relative to boundaries and to other elements, because position determines how an adversary moves. The overlay is the single artifact from which every other ASOM product is derived, which means an error introduced here propagates to reachability, coverage, backlog ranking and the Brief without being independently detectable in any of them.
| Level | Activity |
|---|---|
| L2 | Establish the authorization boundary as the overlay's outer edge, and record what was deliberately excluded and on whose authority. |
| L2 | Populate the overlay from the authoritative asset inventory. |
| L2 | Represent external actors — public users, partner agencies, suppliers, unauthenticated internet — as first-class elements rather than as an arrow at the boundary. |
| L3 | Reconcile count and identity against the inventory rather than transcribing a subset, so completeness is a property of the method. |
| L3 | Group every element into the trust zone that actually contains it, taken from enforced configuration rather than architectural intent. |
| L3 | Record the derivation of each element: system of record, date, and who confirmed it. |
| L3 | Publish the overlay in a form readable without the tool that produced it, so the artifact survives a change of platform. |
| L4 | Measure reconciliation variance between overlay and inventory each cycle and set a threshold above which the overlay is not fit to plan from. |
| L4 | Trend the age of the overlay at the moment it is used for a decision, not at the moment it was refreshed. |
| L5 | Feed elements discovered during engagements — which the inventory did not contain — back into the inventory process, not only onto the overlay. |
| Accountable | AO |
|---|---|
| Responsible | TO |
| Outcome metric | percentage of inventory elements present on the overlay. |
| Performance metric | median age of the overlay at time of use. |
| Evidence | Cyber Terrain Overlay (Figure 1 of the Brief); exported diagram source; derivation and reconciliation record. |
| Assessment | Examine the overlay; interview the architecture owner; compare against the authoritative asset inventory for completeness. |
| SP 800-53 Rev. 5 | CM-8, PM-5, RA-9 |
| CSF 2.0 | ID.AM-01, ID.AM-03 |
TM-2 · Defensive Layer Classification
Control. Every element on the terrain shall be classified to exactly one defensive layer: identity, devices, networks, applications and workloads, data, operational technology, workforce, facilities, or supply chain. Elements that enable maneuver across layers rather than constituting ground — visibility and analytics, automation and orchestration, governance — shall be classified to the cross-cutting domain.
Purpose. To make posture summable and comparable by layer, and to force an explicit ownership decision for every element.
Classification is what allows posture to be rolled up and compared. The one-layer rule is what keeps the matrix partitionable: coverage summed across layers must equal total coverage, and an element counted twice inflates both. The failure this correction addresses is structural — a framework that added four terrain layers in v2.0 and v3.0 while leaving the classification control at five made those layers doctrinally present and practically unscoreable.
| Level | Activity |
|---|---|
| L2 | Classify every element to exactly one of the nine terrain layers, or to the cross-cutting domain where the element enables movement rather than being ground. |
| L2 | Flag unclassified elements automatically rather than relying on review. |
| L2 | Record the classification against the element in the register. |
| L3 | Where an element plausibly spans layers, assign it to the layer whose loss would defeat it, and cross-reference from the others rather than duplicating. |
| L3 | Treat unclassified elements as findings with an owner and a due date. |
| L3 | Reconcile layer totals to the full inventory each cycle; a shortfall means elements are unclassified, an excess means one is double-counted. |
| L3 | Record rationale for any classification a reviewer would find surprising, so the decision survives its author. |
| L4 | Trend reclassification rate; a layer with high churn indicates the criteria are ambiguous rather than that the estate is changing. |
| L4 | Measure the population of each of T6–T9 and escalate where a declared terrain layer holds no classified elements at all. |
| L5 | Refine the layer criteria where reclassification patterns show a boundary that practitioners cannot apply consistently. |
| Accountable | AO |
|---|---|
| Responsible | TO |
| Outcome metric | percentage of elements carrying exactly one layer. |
| Performance metric | reconciliation variance between layer totals and inventory count. |
| Evidence | Asset Register, "Defensive layer" column; reconciliation record. |
| Assessment | Examine the register for unclassified elements; test that layer totals reconcile to the full inventory; test that at least one element on each of T6, T7, T8 and T9 is classified and scored. |
| SP 800-53 Rev. 5 | CM-8(1), RA-2, PM-5 |
| CSF 2.0 | ID.AM-05, ID.AM-01 |
TM-3 · Asset Weighting
Control. Each element shall carry a defensive weight derived from its criticality to the mission and its exposure to untrusted actors, on a defined and consistently applied scale.
Purpose. To convert an undifferentiated inventory into a priority order, so that coverage figures carry meaning and investment can be argued from mission consequence.
Without weighting, coverage percentages are misleading: protecting fifty low-value assets and leaving one crown jewel exposed can still report high compliance. The scale's integrity depends on calibration rather than on definition — two assessors applying a well-written scale will still diverge until they have scored a reference set together and reconciled the disagreement.
| Level | Activity |
|---|---|
| L2 | Score every element on criticality and on exposure. |
| L2 | Compute weight as the product of the two scores. |
| L2 | Record the scores against the element. |
| L3 | Define both scales, including what distinguishes adjacent points, before any element is scored. |
| L3 | Derive criticality from the mission the element serves, obtained from the mission owner rather than assigned by the security function. |
| L3 | Derive exposure from reachability on permitted paths, not from network location alone. |
| L3 | Calibrate by scoring a reference set collectively and reconciling divergence before scoring at scale. |
| L3 | Re-score on mission change, on architectural change, and at cadence regardless of either. |
| L4 | Measure inter-assessor variance on the calibration set and set a threshold above which the scale is not fit for trend use. |
| L5 | Re-base the scales from observed incident consequence, so criticality reflects what loss actually cost rather than what it was assumed to cost. |
| Accountable | AO |
|---|---|
| Responsible | TO |
| Outcome metric | share of total defensive weight held by designated key terrain. |
| Performance metric | inter-assessor variance on the calibration set. |
| Evidence | Asset Register weight column; total defensive weight in the Brief; calibration record. |
| Assessment | Examine the weighting scale definition; interview owners on two high-weight and two low-weight assets to confirm consistent application. |
| SP 800-53 Rev. 5 | RA-2, RA-3 |
| CSF 2.0 | ID.AM-05, ID.RA-05 |
TM-4 · Trust Zone Definition
Control. Trust zones shall be defined with explicit boundaries, and every element shall reside within a declared zone.
Purpose. To establish boundaries that something enforces, so that reachability and denied-path analysis rest on configuration rather than on design intent.
A zone that exists only on a diagram is a description of intent. Everything downstream — KT-3 avenues, KT-4 reachability, M4 canalization — computes over zone boundaries, so an unenforced zone does not merely fail to protect: it produces confident false negatives in the analysis that depends on it.
| Level | Activity |
|---|---|
| L2 | Draw zones on the overlay and place every element inside one. |
| L2 | Raise a finding for any element sitting outside every declared zone. |
| L2 | Identify, for each zone, the mechanism intended to enforce its boundary. |
| L3 | Define each zone by the trust assumption that holds inside it, and state what must be true for an element to belong. |
| L3 | Name the owner of each enforcing mechanism. |
| L3 | Test a sample of boundaries against enforcing configuration each cycle rather than accepting the design. |
| L3 | Record zones enforced by convention rather than configuration, and treat each as an open finding. |
| L3 | Review zone membership when an element changes function or hosting. |
| L4 | Trend boundary test pass rate and the count of convention-enforced zones, driving the latter toward zero. |
| L5 | Revise zone design where repeated membership exceptions show the boundary is drawn in the wrong place. |
| Accountable | AO |
|---|---|
| Responsible | TO |
| Outcome metric | percentage of elements inside a declared zone. |
| Performance metric | boundary sample test pass rate. |
| Evidence | Terrain overlay showing zone membership; boundary enforcement record. |
| Assessment | Examine the overlay for elements outside declared zones; test boundary enforcement against network configuration. |
| SP 800-53 Rev. 5 | SC-7, AC-4 |
| CSF 2.0 | PR.IR-01 |
TM-5 · Connection and Denied-Path Register
Control. All permitted connections between elements shall be recorded, and paths that are deliberately blocked shall be recorded distinctly as denied paths.
Purpose. To record connectivity as three distinct states — permitted, denied, unknown — so that reachability conclusions rest on tested denials rather than on absence of evidence.
Denied paths are the load-bearing entries. KT-4 concludes that a decisive point is unreachable precisely because certain paths are blocked; if those denials are not recorded and enforced, the conclusion is unfounded. The three-state distinction matters as much as the recording: treating unknown connectivity as absent is how a reachability model becomes confidently wrong.
| Level | Activity |
|---|---|
| L2 | Record every permitted connection with direction and protocol. |
| L2 | Record deliberately blocked paths as first-class entries, distinguishable from paths that simply have no entry. |
| L2 | Record observation-only paths separately from permitted flows. |
| L3 | Record the business reason each permitted connection exists, so the register doubles as a rationale record. |
| L3 | Represent unknown connectivity as a third state visible as such, rather than collapsing it into absence. |
| L3 | Bind each denied path to the configuration enforcing it and the owner of that configuration. |
| L3 | Test a sample of denied paths each cycle against firewall or policy configuration. |
| L3 | Place change detection on the configurations enforcing denied paths. |
| L4 | Trend denied-path test pass rate and measure mean time to detect an unauthorized change to a denied path. |
| L5 | Feed paths discovered during engagements — which the register did not contain — back into the enumeration method, not only into the register. |
| Accountable | AO |
|---|---|
| Responsible | TO |
| Outcome metric | percentage of denied paths with verified enforcement. |
| Performance metric | mean time to detect an unauthorized change to a denied path. |
| Evidence | Connection register; denied paths rendered distinctly on the overlay; change-detection coverage record. |
| Assessment | Examine the register; test a sample of denied paths against firewall or policy configuration to confirm they are enforced. |
| SP 800-53 Rev. 5 | AC-4, SC-7(5), CA-3 |
| CSF 2.0 | PR.IR-01, ID.AM-03 |
TM-6 · Terrain Currency
Control. The terrain overlay shall be refreshed at a defined cadence and upon any material architectural change.
Purpose. To keep the overlay current against both the clock and the change, so that planning is conducted against ground as it currently is.
A stale overlay is more dangerous than no overlay, because it is trusted. Currency has two triggers, and a program honoring only the cadence will plan from a map that a deployment invalidated the week after it was drawn. Wiring the change trigger into change management is what stops the second trigger depending on someone remembering.
| Level | Activity |
|---|---|
| L2 | Refresh the overlay at a stated interval. |
| L2 | Record each refresh with its date and trigger. |
| L2 | Retain superseded overlays rather than overwriting them. |
| L3 | Define the refresh cadence and the rationale for its interval. |
| L3 | Define what counts as a material architectural change, specifically enough for a change board to apply without judgment calls. |
| L3 | Wire the change-triggered refresh into the change management process so it fires without depending on memory. |
| L3 | Record a lapse in cadence as a finding with justification rather than allowing silent slippage. |
| L4 | Trend overlay age at time of use and the elapsed time from material change to refresh. |
| L4 | Measure drift per cycle as the delta between successive overlays, and escalate where drift exceeds the interval's assumption. |
| L5 | Adjust the cadence from measured drift, shortening it where the estate moves faster than the interval assumed. |
| Accountable | AO |
|---|---|
| Responsible | TO |
| Outcome metric | percentage of cycles meeting the defined cadence. |
| Performance metric | median elapsed time from material change to overlay refresh. |
| Evidence | Cycle history with dates; snapshot series; change-trigger record. |
| Assessment | Examine cycle dates against the defined cadence; interview on the change-triggered refresh process; test that a recent material change produced a refresh. |
| SP 800-53 Rev. 5 | CM-8(1), CA-7 |
| CSF 2.0 | ID.AM-08, ID.IM-03 |
TM-7 · Terrain Ownership
Control. Every element shall have a named accountable owner recorded against it.
Purpose. To attach every element to a person who can be asked to act, so that findings convert into work rather than accumulating.
Ownership is what converts a finding into work. An unowned element cannot be remediated, re-scored or defended, because there is nobody the requirement attaches to. The acceptance requirement distinguishes this control from an org chart lookup: ownership assigned silently is routinely discovered, at the worst moment, to have been news to its holder.
| Level | Activity |
|---|---|
| L2 | Record a named individual — not a team, distribution list or vacant post — as accountable for each element. |
| L2 | Flag unowned elements automatically. |
| L2 | Raise a finding for each unowned element. |
| L3 | Obtain explicit acceptance of accountability from each named owner rather than assigning it silently. |
| L3 | Confirm owners hold the authority and budget to act on findings against their elements, and escalate where they do not. |
| L3 | Reconcile ownership against the personnel record each cycle so departures surface as unowned elements. |
| L3 | Define the interim owner for an element whose owner has departed, so accountability never falls to nobody. |
| L4 | Trend ownership gap duration and set a disposition period beyond which gaps escalate. |
| L4 | Measure remediation velocity per owner, since an owner with no closures is a different problem from an element with no owner. |
| L5 | Adjust ownership assignment where velocity data shows accountability sitting persistently away from the authority to act. |
| Accountable | AO |
|---|---|
| Responsible | GOV |
| Outcome metric | percentage of elements with an accepted named owner. |
| Performance metric | median duration of an ownership gap. |
| Evidence | Asset Register owner column; open findings list; acceptance record. |
| Assessment | Examine the register for unowned elements; interview a sample of named owners to confirm they accept accountability. |
| SP 800-53 Rev. 5 | CM-8(4), PM-5 |
| CSF 2.0 | GV.RR-02 |
KT · Key Terrain and Decisive Points
What must not be lost, and whether an adversary can reach it
KT-1 · Decisive Point Identification
Control. The organization shall identify and designate the elements whose compromise would unhinge the wider defense, and shall justify each designation.
Purpose. To concentrate defensive effort on the small number of elements whose loss is decisive, so that priority is a stated judgment rather than an emergent property of the asset register.
A decisive point is not the same as a high-weight asset. Weight measures consequence of loss; decisiveness measures whether losing it collapses everything else. An identity policy decision point may carry moderate weight and still be decisive, because holding it confers control of movement everywhere. The justification requirement exists because the designation is a judgment, and an unjustified judgment cannot be argued with or inherited by a successor.
| Level | Activity |
|---|---|
| L2 | Identify candidate decisive points from the terrain overlay, considering elements that control movement, control authorization, or control recovery. |
| L2 | Designate each decisive point on the overlay so it is visually distinct from surrounding terrain. |
| L2 | Record a justification for each designation stating what its compromise would unhinge. |
| L3 | Define the designation criteria in advance and derive them from the defensive intent (CG-1), so a candidate is tested against stated purpose rather than assessed on instinct. |
| L3 | Record, for each high-weight element not designated, why it was excluded — the exclusions carry as much information as the designations. |
| L3 | Obtain the accountable authority's approval of the designated set as a whole, not element by element. |
| L3 | Re-run designation on material architectural change and at defined cadence. |
| L4 | Measure the concentration of defensive weight held by the designated set and set a threshold above which the set is too large to be meaningful. |
| L4 | Test designations against incident and exercise evidence: an element whose compromise did not unhinge the defense is a designation to revisit. |
| L5 | Re-derive the designation criteria from observed engagements, so what counts as decisive is learned from contact rather than assumed at the outset. |
| Accountable | AO |
|---|---|
| Responsible | CTI |
| Outcome metric | share of total defensive weight held by the designated set. |
| Performance metric | percentage of designations carrying a recorded, current justification. |
| Evidence | Key Terrain section of the Brief with justification per element; exclusion record; approval record. |
| Assessment | Examine designations and justifications; interview the CISO on why non-designated high-weight assets were excluded; test whether the designated set has grown beyond the stated threshold. |
| SP 800-53 Rev. 5 | RA-9, CP-2(8), PM-11 |
| CSF 2.0 | ID.AM-05, ID.RA-04 |
KT-2 · Decisive Point Protection Floor
Control. Every designated decisive point shall have at least one defensive move assigned and operational, and shall meet a defined minimum effective coverage.
Purpose. To ensure designation produces protection, so that identifying a decisive point is an act with consequences rather than an annotation.
The gap between designation and protection is where most programs fail. An element can be starred on the overlay for four consecutive cycles with a planned maneuver against it and never receive one. The operational qualifier is doing the work here: a move recorded as planned or partial does not satisfy the floor, because an adversary is not slowed by intent.
| Level | Activity |
|---|---|
| L2 | Assign at least one defensive maneuver to each designated decisive point. |
| L2 | Record the implementation state of each assignment as planned, partial or operational. |
| L2 | Raise a finding where a decisive point carries no operational move. |
| L3 | Define the minimum effective coverage floor and the basis on which it was set, and obtain the accountable authority's approval recording the date relative to first measurement (GA4). |
| L3 | Compute effective coverage per decisive point, weighting by implementation state so that partial assignments do not count in full, and excluding moves recorded as constrained under FO-4 so that a decisive point on operational technology is scored against achievable coverage rather than against a floor it cannot reach. |
| L3 | Assign an owner and a target date to each decisive point below the floor. |
| L3 | Verify by sampling that moves recorded as operational are present and functioning in production, not merely licensed. |
| L4 | Trend the number of decisive points below the floor across cycles and escalate where the count fails to fall. |
| L4 | Measure the elapsed time from designation to first operational move, since that interval is the window in which designation was decorative. |
| L5 | Re-base the floor from exercise and incident evidence rather than leaving it at the value first chosen. |
| Accountable | AO |
|---|---|
| Responsible | TO |
| Outcome metric | percentage of decisive points meeting the coverage floor. |
| Performance metric | median elapsed time from designation to first operational move. |
| Evidence | Findings list; per-asset maneuver assignment in the Register; sampling record. |
| Assessment | Test each decisive point for assigned and operational moves; examine effective coverage against the defined floor; test a sample of "operational" states against production reality. |
| SP 800-53 Rev. 5 | SC-7, AC-6, SI-4 |
| CSF 2.0 | PR.AA-05, PR.PS-01 |
KT-3 · Avenue of Approach Analysis
Control. The routes by which an adversary could approach designated decisive points shall be enumerated and assessed.
Purpose. To convert the estate's connectivity into a set of named approach routes, so that defense can be emplaced on the routes that exist rather than distributed evenly across ground.
An avenue of approach is a property of the architecture, not of any particular adversary, which is what makes it enumerable in advance. The assessment step matters more than the enumeration: a route with neither a barrier nor a compensating detection is an open approach, and knowing about it without acting is worse than not knowing, because it converts a gap into an accepted one without anyone accepting it.
| Level | Activity |
|---|---|
| L2 | Trace permitted paths from each external actor and each lower-trust zone to each designated decisive point. |
| L2 | Record each distinct route as a named avenue with its origin, its path, and its terminus. |
| L2 | Identify, for each avenue, whether a barrier or a detection currently covers it. |
| L3 | Enumerate avenues systematically from the connection register rather than from analyst recall, so completeness is a property of the method. |
| L3 | Include approach routes through workforce, facility and supplier terrain, not only network paths — three of the most-used federal intrusion paths are not network routes. |
| L3 | Assess each avenue for whether its coverage is a barrier, a detection, or neither, and record the result distinctly. |
| L3 | Raise a finding for every avenue with neither, with an owner and a date. |
| L4 | Measure the count of uncovered avenues per decisive point and trend it. |
| L4 | Test a sample of avenues by attempting traversal, rather than accepting the register's account of coverage. |
| L5 | Update the enumeration method from routes observed in real engagements that the method had not predicted. |
| Accountable | AO |
|---|---|
| Responsible | CTI |
| Outcome metric | percentage of enumerated avenues carrying a barrier or a detection. |
| Performance metric | percentage of avenues verified by traversal test rather than by record. |
| Evidence | Adversary reach analysis; traced route figures; coverage classification per avenue. |
| Assessment | Examine enumerated avenues; test that each has either a barrier or a compensating detection; test whether non-network approach routes were enumerated at all. |
| SP 800-53 Rev. 5 | RA-3, CA-8, RA-5 |
| CSF 2.0 | ID.RA-01 |
KT-4 · Adversary Reachability Assessment
Control. The organization shall determine, on permitted paths only, whether any threat actor position can reach any designated decisive point, and shall record the result each cycle.
Purpose. To produce a computed, repeatable answer to the question a control catalog cannot ask — can they get there from here — and to record the answer as a trend rather than a one-time finding.
This is one of the framework's genuinely net-new controls: no federal catalog requires a computed reachability result. Its integrity depends entirely on the denied-path register under TM-5. A negative result — no route exists — is a claim about configuration that holds only while the barriers holding the line remain enforced, which is why KT-5 exists and why the two controls should never be assessed apart.
| Level | Activity |
|---|---|
| L2 | Define the threat actor start positions to be assessed, at minimum the unauthenticated internet and any compromised-user position. |
| L2 | Compute, over permitted paths only, whether a route exists from each start position to each decisive point. |
| L2 | Record the result for the cycle, including the routes found and the points proven unreachable. |
| L3 | Derive start positions from current threat courses of action rather than from a fixed list, so the assessment tracks the threat. |
| L3 | Report, for each negative result, the specific denied paths holding the line, and hand them to KT-5. |
| L3 | Re-compute on material architectural change as well as at cycle cadence. |
| L3 | Validate the computation against the connection register so that a route the register permits cannot be absent from the result. |
| L4 | Trend reachability results across cycles; a point that becomes reachable between cycles is a reportable condition, not a backlog item. |
| L4 | Measure the interval between a permitting change and its appearance in a reachability result. |
| L5 | Reconcile computed reachability against routes actually used in engagements, and correct the model where contact disagrees with it. |
| Accountable | AO |
|---|---|
| Responsible | CTI |
| Outcome metric | number of decisive points reachable from any assessed start position. |
| Performance metric | elapsed time from a permitting configuration change to its reflection in a reachability result. |
| Evidence | Adversary Reach section of the Brief; per-cycle result series; barrier dependency list. |
| Assessment | Test the reachability computation against the connection register; examine the result trend across cycles; test that a recent permitting change appeared in the subsequent result. Assess jointly with KT-5: a negative reachability result is a claim about configuration that holds only while the barriers under KT-5 remain enforced, so KT-4 assessed alone can certify a conclusion that a subsequent barrier change has already invalidated. |
| SP 800-53 Rev. 5 | RA-3(4), CA-8 |
| CSF 2.0 | ID.RA-05, DE.AE-07 |
KT-5 · Barrier Sufficiency
Control. Where reachability is prevented by denied paths, those barriers shall be identified, enforced technically, and monitored for change.
Purpose. To make the barriers on which negative reachability results depend into named, owned, monitored controls, so that the assurance KT-4 provides cannot be silently withdrawn.
This control exists because of a specific failure sequence: a reachability assessment returns negative, the result is briefed, a firewall rule is changed six weeks later for an unrelated reason, and nobody recomputes. The assurance persists in the record long after the configuration that justified it has gone. Change monitoring on the barrier set is the only thing that closes that window.
| Level | Activity |
|---|---|
| L2 | Extract from each negative reachability result the specific denied paths that held the line. |
| L2 | Record each as a control with a named owner rather than leaving it as a register entry. |
| L2 | Identify the technical configuration enforcing each barrier. |
| L3 | Verify by test that each barrier is enforced by configuration and not by convention, documentation or expectation. |
| L3 | Place change detection on every enforcing configuration, with an alert path that reaches someone able to act. |
| L3 | Define the response to a detected barrier change, including re-running KT-4 before the change is accepted. |
| L3 | Review barrier ownership when the underlying platform or its owner changes. |
| L4 | Trend barrier test pass rate and the count of convention-enforced barriers, driving the latter toward zero. |
| L4 | Measure mean time to detect an unauthorized change to a barrier. |
| L5 | Feed every barrier failure back into the enumeration method, so the class of barrier that failed is looked for elsewhere in the estate. |
| Accountable | AO |
|---|---|
| Responsible | TO |
| Outcome metric | percentage of load-bearing barriers with verified technical enforcement and active change detection. |
| Performance metric | mean time to detect an unauthorized barrier change. |
| Evidence | Barrier list from route analysis; supporting configuration evidence; change-detection coverage record. |
| Assessment | Test each barrier against enforcing configuration; examine change-detection coverage on those barriers; test the response path by introducing a monitored change. Assess jointly with KT-4: this control exists to sustain KT-4's negative results, and its findings invalidate them directly. |
| SP 800-53 Rev. 5 | SC-7(5), AC-4, CM-3 |
| CSF 2.0 | PR.IR-01, DE.CM-01 |
ID · Identity Terrain
The identity plane as ground: planes, credentials, assurance, assertions, authorization integrity
ID-1 · Identity Plane Definition
Control. The organization shall identify on the terrain overlay every authoritative identity plane, the policy decision and enforcement points it operates, and the trust relationships between planes.
Purpose. To make identity positional, so that the plane controlling movement everywhere else is itself defensible ground rather than an assumed service.
Most estates have more than one identity plane and have never drawn the relationships between them: a primary provider, a legacy directory, a cloud tenant, one or more federated partners, and a set of local account stores that answer to nobody. Trust edges between planes are the highest-value terrain in the estate, because compromise of a low-assurance plane that a high-assurance plane trusts confers the higher assurance. That is the identity equivalent of an unmapped mobility corridor, and it is invisible on a network diagram.
| Level | Activity |
|---|---|
| L2 | Identify every authoritative identity plane serving the estate and place it on the overlay. |
| L2 | Record the policy decision and enforcement points each plane operates. |
| L2 | Record which elements depend on which plane for authorization. |
| L3 | Enumerate trust relationships between planes — federation, synchronisation, directory trust, token exchange — and record their direction and assurance. |
| L3 | Identify local and non-federated account stores as identity planes in their own right rather than as exceptions, since an unmapped store is an unmapped plane. |
| L3 | Designate the primary plane and any plane whose compromise would confer control of it as decisive points under KT-1. |
| L3 | Record for each enforcement point whether it is consulted on every authorization decision or only at session establishment. |
| L4 | Trend the count of identity planes and trust edges; growth is terrain expansion that no asset inventory reports. |
| L4 | Test that enforcement points are actually consulted, rather than accepting the architecture's claim that they are. |
| L5 | Consolidate planes and retire trust edges where the estate permits, since reducing the terrain is more durable than defending more of it. |
| Accountable | AO |
|---|---|
| Responsible | TO |
| Outcome metric | percentage of estate elements whose authorizing plane is recorded. |
| Performance metric | count of identity planes and trust edges, trended. |
| Evidence | Overlay showing identity planes, enforcement points and trust edges; plane dependency record. |
| Assessment | Examine the overlay against directory and federation configuration; test for local or non-federated stores absent from the plane list; test whether a sampled enforcement point is consulted on authorization. |
| SP 800-53 Rev. 5 | IA-8, AC-3, PM-5 |
| CSF 2.0 | PR.AA-01, ID.AM-01 |
ID-2 · Credential Strength and Binding
Control. Identities shall be proofed to a level commensurate with the access they confer, and bound to credentials whose strength matches that level.
Purpose. To ensure the credential is as strong as the access behind it, so that proofing and authentication assurance are matched rather than assumed.
The failure this addresses is drift rather than misconfiguration. A person proofed at one level and issued a credential appropriate to it accumulates access over subsequent years, and nothing re-examines whether the original proofing still justifies the current entitlement. WF-2 catches this for privileged humans; this control generalises it to every identity including non-human ones, where the problem is worse because service identities are routinely issued long-lived secrets and then granted whatever access their consuming application later requires.
| Level | Activity |
|---|---|
| L2 | Record the proofing level applied to each identity. |
| L2 | Record the credential type bound to each identity. |
| L2 | Raise a finding where credential strength is below the access conferred. |
| L3 | Define the required proofing and credential strength per access tier, with provenance per GA4. |
| L3 | Apply the requirement to non-human identities — service accounts, workload identities, API credentials — where binding is to an owning system and a named accountable human rather than to a person. |
| L3 | Require phishing-resistant credentials for identities reaching decisive points, and record exceptions with expiry. |
| L3 | Re-examine proofing adequacy when access changes, not only when the identity is created. |
| L4 | Measure the gap between proofing level and access conferred across the population, and trend it. |
| L4 | Measure the count and age of long-lived non-human secrets, since these are the credentials least likely to be rotated and most likely to be exfiltrated. |
| L5 | Move non-human identities to short-lived, workload-attested credentials where the platform permits, retiring the long-lived secret class rather than managing it. |
| Accountable | AO |
|---|---|
| Responsible | TO |
| Outcome metric | percentage of identities whose credential strength matches conferred access. |
| Performance metric | count and median age of long-lived non-human secrets. |
| Evidence | Proofing and credential record per identity; mismatch findings; non-human secret inventory with ages. |
| Assessment | Examine the proofing standard and its provenance; test a sample of identities for credential strength against conferred access; test whether non-human identities are within scope in practice. |
| SP 800-53 Rev. 5 | IA-5, IA-12, IA-9 |
| CSF 2.0 | PR.AA-02, PR.AA-01 |
ID-3 · Authentication Assurance
Control. Users, services and devices shall be authenticated at an assurance level commensurate with the terrain being accessed, and the assurance achieved shall be recorded with the authorization decision.
Purpose. To ensure authentication strength varies with what is being reached, and that the level achieved is available to the decision that relies on it.
M3 Envelopment's stated indicator is that a stolen credential alone yields no movement, and this is the control that makes it assessable. The requirement that assurance be recorded with the decision is the part usually missing: an estate can enforce strong authentication at the front door and then issue a session that every downstream service accepts without knowing how it was obtained. Carrying the assurance level into the authorization decision is what allows a service holding decisive-point data to refuse a session that was established weakly, which is the difference between authenticating once and authenticating appropriately.
| Level | Activity |
|---|---|
| L2 | Authenticate users, services and devices before granting access. |
| L2 | Define the assurance level required per terrain layer or access tier. |
| L2 | Record the assurance level achieved at authentication. |
| L3 | Carry the achieved assurance level into the authorization decision, so a service can refuse a session established below its requirement. |
| L3 | Require step-up authentication on transition to higher-assurance terrain rather than only at session establishment. |
| L3 | Apply device assurance as an input where the terrain warrants it, so authentication is not credential-only. |
| L3 | Record and time-bound every path that bypasses the assurance requirement, including legacy protocols that cannot carry it. |
| L4 | Measure the proportion of authorization decisions made with assurance level available, since a decision made without it is made blind. |
| L4 | Test resistance directly: attempt authentication with a captured credential and confirm it yields no usable session for decisive-point terrain. |
| L5 | Retire bypass paths and legacy protocols rather than compensating for them, since each is a standing exception to the form's own indicator. |
| Accountable | AO |
|---|---|
| Responsible | TO |
| Outcome metric | result of captured-credential testing against decisive-point terrain. |
| Performance metric | percentage of authorization decisions with assurance level available. |
| Evidence | Assurance requirements per terrain; achieved-assurance records; bypass register; credential resistance test results. |
| Assessment | Examine the assurance standard against terrain classification; test that a captured credential yields no usable session for decisive-point terrain; examine the bypass register for expiry. |
| SP 800-53 Rev. 5 | IA-2, IA-2(1), IA-3 |
| CSF 2.0 | PR.AA-03, PR.AA-05 |
ID-4 · Identity Assertion Protection
Control. Identity assertions, tokens and session material shall be protected against interception, replay and forgery, and their validity shall be bounded in time and scope.
Purpose. To prevent a valid authentication from becoming a durable, portable credential in an adversary's hands.
Strong authentication is routinely defeated downstream rather than at the point of authentication: the token issued after a phishing-resistant login is frequently a bearer credential with a long lifetime, broad scope and no binding to the device that obtained it. An adversary who takes it inherits the assurance without the credential. Signing key protection is the same problem one level up — an adversary holding the issuing key can forge assertions at any assurance level and will not appear in authentication logs at all.
| Level | Activity |
|---|---|
| L2 | Protect assertions and tokens in transit and at rest. |
| L2 | Bound assertion validity in time. |
| L2 | Bound assertion scope to the access required. |
| L3 | Bind assertions to the device or client that obtained them where the platform permits, so a stolen token is not portable. |
| L3 | Protect assertion signing keys at a level commensurate with the access forgeable assertions would confer, and record where they are held. |
| L3 | Key assertion lifetime to campaign phase (CG-2), so a declared Phase III shortens session lifetimes without a change request. |
| L3 | Provide estate-wide session revocation and verify it reaches every consuming service, not only the issuing plane. |
| L4 | Measure assertion lifetime distribution against the requirement per terrain, and trend the tail rather than the median. |
| L4 | Test estate-wide revocation end to end and measure elapsed time to effect across consuming services. |
| L5 | Move toward continuous evaluation, so authorization is re-decided during a session rather than settled at its start. |
| Accountable | AO |
|---|---|
| Responsible | TO |
| Outcome metric | measured time to effect for estate-wide session revocation. |
| Performance metric | assertion lifetime distribution against requirement, tail-weighted. |
| Evidence | Assertion protection configuration; lifetime and scope records; signing key protection record; revocation test results. |
| Assessment | Examine lifetime and scope against terrain requirements; test estate-wide revocation reaching consuming services; examine signing key protection against the access forgeable assertions would confer. |
| SP 800-53 Rev. 5 | IA-5(2), SC-8, SC-23 |
| CSF 2.0 | PR.AA-04, PR.DS-02 |
ID-5 · Authorization Decision Integrity
Control. Authorization policy shall be enforced at a decision point that every access path consults, and changes to that policy shall be controlled, logged and reviewable.
Purpose. To ensure the policy that governs movement is actually consulted and cannot be altered without trace.
M3 Envelopment's precondition, in the framework's own words, is a policy decision point that something actually enforces — an authorization engine no service consults is a document, and it will score well. This control makes that testable in both directions: paths that bypass the decision point, and changes to policy that leave no trace. The second is the higher-value target. An adversary who can add a policy rule does not need to defeat any control in this family; they authorize themselves, and unless policy change is logged and reviewed against an expected-change baseline, the alteration is indistinguishable from routine administration.
| Level | Activity |
|---|---|
| L2 | Enforce authorization policy at a defined decision point. |
| L2 | Log every change to authorization policy. |
| L2 | Record which access paths consult the decision point. |
| L3 | Enumerate access paths that do not consult the decision point and record each as a finding with an owner, since these are where envelopment fails. |
| L3 | Review policy changes against expected change, not merely retain the log — an unreviewed change log detects nothing. |
| L3 | Require authorization for policy change at a level above the access the policy governs, so self-authorization requires two failures rather than one. |
| L3 | Place change detection on the policy store itself and route it to a monitored path, consistent with KT-5 barrier monitoring. |
| L4 | Measure the proportion of access paths consulting the decision point, and trend it toward complete coverage. |
| L4 | Measure time to detect an unauthorized authorization policy change, tested rather than assumed. |
| L5 | Move toward policy as reviewed, version-controlled configuration, so change review is a property of the deployment process rather than a periodic audit. |
| Accountable | AO |
|---|---|
| Responsible | TO |
| Outcome metric | percentage of access paths consulting the authorization decision point. |
| Performance metric | measured time to detect an unauthorized policy change. |
| Evidence | Path coverage record; policy change log with review results; bypass findings; change detection coverage on the policy store. |
| Assessment | Examine paths that bypass the decision point; test whether policy changes are reviewed against expected change rather than only retained; test time to detect an introduced policy change. |
| SP 800-53 Rev. 5 | AC-3, AC-6, AU-6 |
| CSF 2.0 | PR.AA-05, DE.CM-09 |
DV · Devices Terrain
The entry fords: device identification, posture as an access precondition, sensor liveness, execution control, lifecycle and sanitization
DV-1 · Device Terrain Identification
Control. Every device with a path into the estate shall be represented on the terrain overlay with its management state, its owning population, and the terrain it can reach.
Purpose. To make devices positional, so that the crossings into the estate are known and can be defended rather than merely counted.
The distinguishing requirement is management state, and the category that matters is the one most inventories omit: devices that reach the estate and are not managed by it. Contractor laptops, personal devices under a bring-your-own arrangement, vendor maintenance endpoints and unenrolled cloud workstations all cross the ford, and an inventory built from the management console will report none of them because the console can only see what it manages. Reconciling against the identity plane rather than the endpoint platform is what surfaces them.
| Level | Activity |
|---|---|
| L2 | Represent devices with a path into the estate on the terrain overlay. |
| L2 | Record the management state of each — managed, unmanaged, or unknown. |
| L2 | Record the population that operates each device class. |
| L3 | Reconcile the device set against the identity plane (ID-1) rather than against the endpoint management console, since the console can only report devices it already manages. |
| L3 | Record the terrain each device class can reach, so a device is scored by its reach rather than by its cost. |
| L3 | Classify unmanaged devices as a measured population with an owner and a disposition, not as an exception to the inventory. |
| L3 | Record the software inventory carried by each managed device class, so a component disclosure can be resolved to devices rather than to an estate. |
| L4 | Trend the unmanaged population against the managed one, and set a threshold above which the estate is not fit to plan device defense from. |
| L4 | Measure the interval between a device first authenticating and its appearance on the overlay. |
| L5 | Remove the conditions that generate unmanaged reach — brokered access, virtual desktops, or enrollment requirements — rather than counting it indefinitely. |
| Accountable | AO |
|---|---|
| Responsible | TO |
| Outcome metric | percentage of authenticating devices present on the overlay. |
| Performance metric | unmanaged population as a share of devices reaching the estate. |
| Evidence | Terrain overlay showing device classes with management state, population and reach; reconciliation record; software inventory. |
| Assessment | Examine the overlay against the identity plane rather than the management console; test for device classes authenticating but absent from the overlay; examine the unmanaged population's disposition. |
| SP 800-53 Rev. 5 | CM-8, CM-8(1), PM-5 |
| CSF 2.0 | ID.AM-01, ID.AM-02, ID.AM-05 |
DV-2 · Device Posture as an Access Precondition
Control. Device health shall be evaluated as a precondition of access to designated terrain, and failing posture shall deny access rather than raise a notification.
Purpose. To ensure a compromised or non-compliant device cannot spend a valid credential, closing the gap M3 Envelopment leaves when identity alone is enforced.
The word doing the work is precondition. A posture check that reports non-compliance into a ticket queue has measured device health; it has not defended anything, and the adversary holding the device proceeds unimpeded. This control is also where identity and device terrain meet: ID-3 requires authentication assurance commensurate with terrain, and device assurance is an input to that assurance rather than a parallel track. An estate enforcing strong authentication from an unhealthy endpoint has bought half the control.
| Level | Activity |
|---|---|
| L2 | Evaluate device health signals before granting access to designated terrain. |
| L2 | Define the posture requirement per terrain layer or access tier. |
| L2 | Deny access on failing posture rather than recording an exception. |
| L3 | Feed device assurance into the authorization decision under ID-5, so posture and identity are evaluated together rather than in sequence. |
| L3 | Require posture for access to decisive points (KT-1) without exception, and record any exception with an owner and expiry. |
| L3 | Re-evaluate posture during a session where the platform permits, not only at establishment. |
| L3 | Define the fallback path for a device that cannot report posture, so an unreportable device is a decision rather than a bypass. |
| L4 | Measure the proportion of access grants made with a current posture signal available, since a grant made without one is made blind. |
| L4 | Trend the exception population and drive it toward a stated floor. |
| L5 | Extend posture signals to the device classes that currently cannot report, rather than maintaining a permanent exception for them. |
| Accountable | AO |
|---|---|
| Responsible | TO |
| Outcome metric | percentage of access to decisive-point terrain gated on posture. |
| Performance metric | proportion of grants made with a current posture signal. |
| Evidence | Posture requirements per terrain; grant records showing posture state; exception register with expiry. |
| Assessment | Test that failing posture denies rather than notifies; examine whether posture reaches the authorization decision or runs beside it; examine the exception population against decisive-point terrain. |
| SP 800-53 Rev. 5 | CM-6, AC-3, IA-3 |
| CSF 2.0 | PR.AA-05, PR.PS-01 |
DV-3 · Endpoint Sensor Coverage and Liveness
Control. Sensor coverage across the device estate shall be reconciled to the device inventory rather than to the sensor console, and a sensor that stops reporting shall be treated as a security event.
Purpose. To know what the estate can actually see, and to detect the loss of that visibility as an event rather than at the next assessment.
Two failures hide behind a healthy coverage figure. The first is the console denominator: a platform reporting 100% coverage is reporting 100% of the devices it knows about, which is a tautology, and reconciling to DV-1's inventory is the only way to get a real number. The second is silence. A sensor removed, disabled or crashed produces no telemetry, and an absence of alerts is indistinguishable from an absence of adversary — which is precisely the condition an adversary works to create. Liveness is therefore a control in its own right, not a platform health metric.
| Level | Activity |
|---|---|
| L2 | Deploy sensor coverage across the managed device estate. |
| L2 | Report coverage as a proportion of the device inventory. |
| L2 | Detect sensors that have stopped reporting. |
| L3 | Reconcile coverage against the DV-1 inventory rather than the sensor console, and report the reconciled figure as the coverage number. |
| L3 | Treat a silent sensor as a security event with a response path, consistent with M2.14 Control Failure Detection, rather than as a platform ticket. |
| L3 | Ensure telemetry generation and retention on device terrain meet the retention EN-3 requires against the dwell estimate, since reconstruction cannot reach further back than the endpoint retained. |
| L3 | Record device classes that cannot carry a sensor, with the compensating measure and an owner. |
| L4 | Measure time to detect a silent sensor, tested rather than assumed. |
| L4 | Trend the gap between console-reported and inventory-reconciled coverage; a widening gap is an inventory finding, not a sensor one. |
| L5 | Extend or replace sensing for device classes carrying persistent compensating measures, rather than accepting the compensation indefinitely. |
| Accountable | AO |
|---|---|
| Responsible | SOC |
| Outcome metric | sensor coverage reconciled to the device inventory. |
| Performance metric | measured time to detect a silent sensor. |
| Evidence | Reconciled coverage figure with its denominator stated; silent-sensor event records; uncovered device class register with compensations. |
| Assessment | Examine which denominator the reported coverage uses; test detection of a deliberately silenced sensor; compare endpoint retention against the current dwell estimate. |
| SP 800-53 Rev. 5 | SI-4, AU-2, AU-12 |
| CSF 2.0 | DE.CM-09, PR.PS-04, ID.AM-08 |
DV-4 · Execution Control
Control. What may execute on designated device terrain shall be constrained to an approved, verified set, and unauthorized execution shall be prevented rather than recorded.
Purpose. To deny the adversary the ability to run code on the ground they cross into, which is the cheapest point at which most engagements can be stopped.
Execution control is the highest-yield and least-adopted device control, because it trades operational friction now against an outcome that is invisible when it works. The framework's position is that the constraint belongs on designated terrain rather than universally — decisive points, privileged access workstations, and devices reaching the data layer — which makes it affordable and keeps it enforceable. Universal application is where these programs fail, and where they are subsequently downgraded to audit mode and forgotten.
| Level | Activity |
|---|---|
| L2 | Define what may execute on designated device terrain. |
| L2 | Prevent execution outside the approved set on that terrain. |
| L2 | Record attempted unauthorized execution as an event. |
| L3 | Derive the approved set from verified provenance under LC-2 rather than from observed usage alone. |
| L3 | Scope enforcement to designated terrain — decisive points, privileged access workstations, and devices reaching the data layer — rather than universally. |
| L3 | Define the exception path with an owner and expiry, since an undefined exception path results in enforcement being disabled wholesale. |
| L3 | Constrain script and interpreter execution as well as binaries, since restricting only executables displaces rather than prevents. |
| L4 | Measure the proportion of designated terrain under enforcement rather than audit mode, and treat audit mode as unenforced. |
| L4 | Trend attempted unauthorized executions, which is a detection signal as much as a prevention one. |
| L5 | Extend enforcement outward from designated terrain as the exception rate falls, rather than attempting universal coverage at the outset. |
| Accountable | AO |
|---|---|
| Responsible | TO |
| Outcome metric | percentage of designated device terrain under enforced execution control. |
| Performance metric | exception population and its median age. |
| Evidence | Approved execution set with provenance linkage; enforcement scope record distinguishing enforced from audit mode; exception register. |
| Assessment | Test that unauthorized execution is prevented rather than logged on designated terrain; examine whether enforcement is active or in audit mode; examine the derivation of the approved set against LC-2. |
| SP 800-53 Rev. 5 | CM-7, CM-7(5), SI-7 |
| CSF 2.0 | PR.PS-05, PR.PS-02 |
DV-5 · Device Lifecycle and Sanitization
Control. Devices shall be provisioned from a trusted baseline and, on retirement, loss or reassignment, shall be removed from the estate's trust and their media sanitized within a stated period.
Purpose. To close the ends of the device lifecycle — the point of entry and the point of exit — where trust is granted and where it is most often left behind.
The exit end is where this control earns its place. A retired, lost or reassigned device frequently retains enrollment, certificates, cached credentials and stored data long after it has left the population it was issued to — which makes it an unattributed device holding valid trust, exactly the condition DV-1 is designed to surface and WF-5 assumes has been handled. The stated period matters as much as the action: a sanitization process that completes eventually is not a control against a device already outside the agency's physical control.
| Level | Activity |
|---|---|
| L2 | Provision devices from a defined baseline image or configuration. |
| L2 | Remove retired, lost and reassigned devices from the estate's trust. |
| L2 | Sanitize media on retirement or reassignment. |
| L3 | Verify the provisioning baseline's integrity and provenance under LC-2, so a trusted baseline is trusted for a reason. |
| L3 | State the period within which trust must be removed following retirement, loss or reassignment, derived from what the device's retained trust could do, with provenance per GA4. |
| L3 | Reconcile device retirement against the identity plane and WF-5 revocation, so a device leaving with a person is handled once rather than twice. |
| L3 | Record sanitization with its method and verification, and record devices that left the estate unsanitised as findings rather than as losses. |
| L4 | Measure elapsed time from retirement, loss or reassignment to trust removal, against the stated period. |
| L4 | Trend the population of devices holding trust with no current holder, which is the direct measure of this control's exit end. |
| L5 | Reduce what a device retains — moving to brokered access, ephemeral credentials and non-persistent workspaces — so retirement removes less. |
| Accountable | AO |
|---|---|
| Responsible | TO |
| Outcome metric | devices holding estate trust with no current holder. |
| Performance metric | median elapsed time from retirement or loss to trust removal. |
| Evidence | Provisioning baseline with provenance record; trust removal times; sanitization records with method and verification; orphaned-trust findings. |
| Assessment | Test trust removal against the stated period; examine sanitization verification on a sample; examine the population of devices holding trust with no current holder. |
| SP 800-53 Rev. 5 | MP-6, CM-2, MA-2 |
| CSF 2.0 | ID.AM-08, PR.DS-11, PR.PS-02 |
SM · Scheme of Maneuver
Choosing moves, assigning them to ground, honest implementation states, deception emplacement
SM-1 · Maneuver Catalog Adoption
Control. The organization shall adopt a defined catalog of defensive moves expressed as intent and mechanism rather than as product names.
Purpose. To fix a shared vocabulary of defensive moves stated as intent, so the plan survives replacement of the tools that implement it.
Products are replaced every few years; intent is durable. Expressing the catalog as intent means the framework survives procurement cycles and lets leaders direct without technical fluency. The adoption test is not whether the catalog exists but whether leadership can actually issue direction in its terms — a catalog nobody commands with is a glossary.
| Level | Activity |
|---|---|
| L2 | Adopt the eleven-move catalog as issued, or extend it with locally defined moves in the same form. |
| L2 | Record each move's intent, mechanism and effectiveness weighting. |
| L2 | Publish the catalog where those who must use it can reach it. |
| L3 | State every move as intent and mechanism, and reject any candidate that names a product category rather than a defensive effect. |
| L3 | Require any locally defined move to meet the same admission criteria as an issued one: durable, expressible as intent, distinct in effect, supported by at least five techniques, and capable of being absent. |
| L3 | Confirm by interview that leadership can direct using the catalog's terms without translation by an engineer. |
| L3 | Review the catalog when the framework issues a version, and record which local extensions were superseded. |
| L4 | Measure how often direction is actually issued in catalog terms versus in product terms, since the second indicates adoption has not occurred. |
| L5 | Contribute locally defined moves that met the admission criteria back to the framework steward, so the catalog improves from field use. |
| Accountable | AO |
|---|---|
| Responsible | GOV |
| Outcome metric | percentage of defensive direction issued in catalog terms. |
| Performance metric | percentage of local extensions meeting the admission criteria. |
| Evidence | Adopted catalog with intent, mechanism and effectiveness weighting per move; local extension record. |
| Assessment | Examine the adopted catalog; interview leadership on their ability to direct using it. |
| SP 800-53 Rev. 5 | PL-2, PM-7 |
| CSF 2.0 | GV.PO-01 |
SM-2 · Maneuver Assignment
Control. Defensive moves shall be assigned to specific elements of terrain rather than declared at program level.
Purpose. To bind defensive intent to specific ground, so that coverage reflects what protects which element rather than what the program has bought.
Program-level declaration is the single largest source of coverage inflation. "We do microsegmentation" is true of an organization and false of most of its elements, and the gap between those two statements is invisible until an assignment register forces the question element by element. This control is what makes an unprotected-asset report possible at all.
| Level | Activity |
|---|---|
| L2 | Assign moves to specific elements rather than declaring them at program level. |
| L2 | Produce a report of elements carrying no assigned move. |
| L2 | Record assignments in the register against the element. |
| L3 | Derive assignment priority from asset weight (TM-3) and decisive point designation (KT-1) rather than from ease of assignment. |
| L3 | Verify by sampling that a move recorded as assigned is genuinely present on that element, not present somewhere in the estate. |
| L3 | Use bulk assignment for genuinely common patterns, but require the same sampling verification as individually assigned moves. |
| L3 | Reconcile assignments after architectural change, since an element rebuilt on a new platform rarely retains its moves. |
| L4 | Trend the count and weight of unprotected elements, and set a threshold on weight rather than on count. |
| L4 | Measure the divergence between program-level claims and element-level assignment, which is the inflation figure. |
| L5 | Revise assignment patterns where sampling repeatedly finds a class of move recorded but absent, since that indicates a systemic rather than a local gap. |
| Accountable | AO |
|---|---|
| Responsible | TO |
| Outcome metric | percentage of defensive weight carried by elements with at least one assigned move. |
| Performance metric | sampling pass rate on assignments verified present. |
| Evidence | Per-asset maneuver assignment; unprotected-asset report; sampling record. |
| Assessment | Examine assignments against the register; test that a sample of assigned moves is genuinely present on that element. |
| SP 800-53 Rev. 5 | PL-2, CA-2 |
| CSF 2.0 | PR.PS-01, ID.IM-01 |
SM-3 · Implementation State Tracking
Control. Each assigned move shall carry an implementation state of planned, partial, or operational, and only operational moves shall count in full toward risk reduction.
Purpose. To make the coverage figure reflect what is defending the estate rather than what is intended to, by weighting mitigation by implementation state.
This is the honesty control, and the entire posture computation rests on it. An adversary is not slowed by a planned maneuver, so a framework that counts one is producing a number about ambition rather than about defense. The control is also the framework's most fragile, because it can be defeated without any technical failure: if "operational" becomes the state recorded to avoid a finding, no assessment procedure downstream can recover. That is why the assessment tests production reality rather than the field.
| Level | Activity |
|---|---|
| L2 | Record an implementation state of planned, partial or operational against every assigned move. |
| L2 | Weight mitigation by state so that planned and partial do not count in full. |
| L2 | Report coverage separately at full weight and at state-weighted value. |
| L3 | Define each state against an observable condition, so the distinction between partial and operational is testable rather than a matter of judgment. Record a fourth state, constrained, where a terrain constraint recorded under FO-4 makes the move genuinely unavailable, and exclude constrained assignments from the coverage denominator rather than carrying them indefinitely as planned. |
| L3 | Require evidence for any transition to operational, rather than allowing the state to be self-declared. |
| L3 | Sample states each cycle and test against production, prioritizing moves on decisive points. |
| L3 | Record the date of each state transition, so the age of an operational claim is visible. |
| L4 | Measure the false-operational rate found by sampling, and treat a rising rate as a governance finding rather than a data quality one. |
| L4 | Trend the duration moves spend in planned and partial, since a move that has been planned for four cycles is not a plan. |
| L5 | Automate state derivation from telemetry where the observable condition permits, replacing declaration with detection. |
| Accountable | AO |
|---|---|
| Responsible | TO |
| Outcome metric | state-weighted effective coverage against full-weight coverage. |
| Performance metric | false-operational rate found by sampling. |
| Evidence | Implementation state per assignment with transition dates; effective coverage computation; sampling record. |
| Assessment | Test a sample of moves recorded as operational to confirm they are in production and effective; examine the false-operational rate trend. |
| SP 800-53 Rev. 5 | CA-5, PM-4 |
| CSF 2.0 | ID.IM-02 |
SM-4 · Main Effort Designation
Control. For each phase, the organization shall designate where defensive priority is concentrated.
Purpose. To concentrate defensive priority at a declared point, so that subordinate decisions follow from it without referral.
Main effort is the concept a control catalog structurally cannot hold, because a catalog has no way to say that one requirement matters more this quarter. The designation is only real if resourcing moved: a main effort that changed no budget line, no staffing allocation and no queue priority is a label applied after the fact. The assessment procedure therefore examines resourcing rather than the declaration.
| Level | Activity |
|---|---|
| L2 | Declare the current campaign phase. |
| L2 | Designate where defensive priority is concentrated for that phase. |
| L2 | Record the designation in the Brief. |
| L3 | Derive the designation from the phase's dominant forms and from current threat courses of action, rather than from standing organizational preference. |
| L3 | State what is being accepted as lower priority, since a main effort that subordinates nothing is not a main effort. |
| L3 | Align resourcing — budget, staffing, queue priority — to the designation, and record the specific allocations that moved. |
| L3 | Re-designate on phase transition and on material change in the threat picture. |
| L4 | Measure the proportion of defensive effort actually expended on the designated main effort, and compare it against the designation. |
| L4 | Trend the interval between phase transition and resourcing realignment. |
| L5 | Review past designations against engagement outcomes, and adjust the derivation where the main effort was repeatedly designated away from where contact occurred. |
| Accountable | AO |
|---|---|
| Responsible | AO |
| Outcome metric | proportion of defensive effort expended on the designated main effort. |
| Performance metric | elapsed time from phase transition to resourcing realignment. |
| Evidence | Phase declaration and main-effort statement in the Brief; subordination record; resourcing allocation record. |
| Assessment | Examine the designation; interview on how resourcing followed it; test that at least one allocation demonstrably moved. |
| SP 800-53 Rev. 5 | PM-11, RA-2 |
| CSF 2.0 | GV.RM-01 |
SM-5 · Branches and Sequels
Control. Pre-planned contingency maneuvers shall be defined for the most likely and most dangerous adversary courses of action.
Purpose. To decide contingency responses before contact, so that the decision loop under pressure is a selection rather than a design exercise.
The distinction between most likely and most dangerous is the whole value of the control. Planning only against the likely course produces a program that is efficient until the day it is not; planning only against the dangerous one produces a program that cannot afford its own contingencies. Holding both, and knowing which cells both demand, is where a single investment answers two threats.
| Level | Activity |
|---|---|
| L2 | Define contingency moves against the most likely adversary course of action. |
| L2 | Define contingency moves against the most dangerous course of action. |
| L2 | Link each to the response procedure that executes it. |
| L3 | Derive both courses of action from current intelligence rather than from a standing scenario library. |
| L3 | Identify the moves demanded by both courses, since those are where one investment answers two threats. |
| L3 | State the trigger condition for each branch, specifically enough that an operator can recognize it without escalating to ask. |
| L3 | Exercise at least one branch per cycle through tabletop or live test. |
| L4 | Measure the elapsed time from trigger condition to branch execution in exercise, and compare it against the tempo the branch assumes. |
| L4 | Trend branch currency against the threat picture; a branch built for a course of action no longer assessed is a maintenance liability. |
| L5 | Re-derive branches from engagements, replacing assumed adversary behavior with observed behavior. |
| Accountable | AO |
|---|---|
| Responsible | CTI |
| Outcome metric | percentage of assessed courses of action carrying a current branch. |
| Performance metric | elapsed time from trigger to execution in exercise. |
| Evidence | Branch and sequel register with triggers; linked response procedures; exercise records. |
| Assessment | Examine defined branches; test one through a tabletop exercise; examine currency against the current threat assessment. |
| SP 800-53 Rev. 5 | IR-4, CP-2 |
| CSF 2.0 | RS.MA-01, ID.IM-02, ID.IM-04 |
SM-6 · Maneuver Effectiveness Validation
Control. The assumed effectiveness of each move shall be validated through exercise, testing, or observed incident performance, and adjusted where evidence contradicts assumption.
Purpose. To replace assumed effectiveness with demonstrated effectiveness, so the coverage figure reflects what controls do rather than what was assumed of them.
The framework's own design documentation concedes that the riskReduction weightings are an allocation model for prioritization rather than an empirical finding, and states that they should be re-based against an agency's own incident history. SM-6 is the control that discharges that obligation. An agency running the framework for several cycles without adjusting a single weighting has not validated anything — it has confirmed its priors, and its coverage figure remains a statement about doctrine rather than about its estate.
| Level | Activity |
|---|---|
| L2 | Test or exercise assigned moves and record the result. |
| L2 | Record the basis on which each effectiveness weighting currently rests. |
| L2 | Adjust weightings where evidence contradicts assumption. |
| L3 | Define what constitutes validating evidence for each move, distinguishing exercise, red-team test and observed incident performance. |
| L3 | Use each technique's success indicator as the pass/fail condition, so validation tests the framework's own stated observable. |
| L3 | Record every adjustment with its justification and the evidence that drove it. |
| L3 | Propagate adjusted weightings into the posture computation rather than holding them as a separate finding. |
| L4 | Measure the proportion of weightings resting on evidence rather than on issued default, and trend it upward. |
| L4 | Measure the divergence between assumed and demonstrated effectiveness, since a consistently positive divergence indicates the defaults are optimistic. |
| L5 | Re-base the full weighting distribution against accumulated agency incident history, and contribute the finding to the framework steward. |
| Accountable | AO |
|---|---|
| Responsible | HT |
| Outcome metric | percentage of effectiveness weightings resting on agency evidence rather than issued default. |
| Performance metric | divergence between assumed and demonstrated effectiveness. |
| Evidence | Validation results; adjusted weightings with justification and supporting evidence. |
| Assessment | Examine validation evidence; test that adjustments were reflected in the posture computation; examine whether any weighting has ever been reduced. |
| SP 800-53 Rev. 5 | CA-2, CA-8, IR-3 |
| CSF 2.0 | ID.IM-02, ID.IM-03 |
SM-7 · Deception Emplacement
Control. Deception shall be emplaced across designated terrain, and every interaction with a deception element shall raise an alert that reaches a human within a defined period.
Purpose. To obtain detection with no false-positive budget, and to ensure that signal is acted on rather than queued.
A deception element has a property no other detection has: nothing legitimate touches it, so an interaction is an incident with no triage burden and no false-positive budget. That property is destroyed by routing the alert into a queue triaged tomorrow, which is the ordinary failure and the reason the alert path is written into the control rather than left to detection engineering. The second requirement is placement: deception emplaced where an adversary would not look is decoration, and placement should follow the avenues enumerated under KT-3 rather than convenience.
| Level | Activity |
|---|---|
| L2 | Emplace deception elements across designated terrain. |
| L2 | Monitor every deception element for interaction. |
| L2 | Raise an alert on interaction. |
| L3 | Place deception along the avenues of approach enumerated under KT-3 and adjacent to designated decisive points, rather than where placement is easiest. |
| L3 | Define the period within which a deception alert must reach a human, derived from the decide segment measured under TA-1, with provenance per GA4. |
| L3 | Ensure deception elements are indistinguishable from real ones to an adversary and identifiable to defenders, and record how each property is achieved. |
| L3 | Ensure no legitimate process, scanner or inventory tool interacts with deception elements, so the no-false-positive property holds in practice. |
| L3 | Extend deception across terrain layers — identity, data, network, endpoint — rather than a single layer, so it is present wherever movement occurs. |
| L4 | Measure elapsed time from deception interaction to human response, against the defined period. |
| L4 | Test emplacement by exercise: a red team given an objective should encounter deception, and an exercise in which none is encountered is a placement finding. |
| L5 | Re-place deception from observed adversary movement and from engagements, rather than leaving an initial layout in place indefinitely. |
| Accountable | AO |
|---|---|
| Responsible | SOC |
| Outcome metric | elapsed time from deception interaction to human response. |
| Performance metric | terrain layers carrying emplaced deception, against those designated. |
| Evidence | Emplacement record by terrain layer; interaction alerts with response times; exclusion configuration; exercise encounter records. |
| Assessment | Examine emplacement against enumerated avenues; test that an interaction reaches a human within the defined period; test that no legitimate tooling interacts with deception elements; examine whether a recent exercise encountered deception. |
| SP 800-53 Rev. 5 | SC-26, SC-30, SI-4 |
| CSF 2.0 | DE.CM-01, DE.AE-02 |
TA · Tempo and Temporal Advantage
Making speed of decision measurable, governed and pre-authorized
TA-1 · Decision Loop Measurement
Control. The organization shall measure the elapsed time from detection through decision to containment, and shall record it each cycle.
Purpose. To make the defender's tempo a measured quantity rather than an impression, so that the numerator of temporal advantage exists at all.
The loop has three segments and they fail differently. Detection latency is a tooling and coverage problem; decision latency is an authority problem; containment latency is an execution problem. Reporting only the total hides which one is binding, and in most programs the binding constraint is the middle segment — which no amount of detection investment will shorten. Measuring the segments separately is what makes the metric actionable rather than merely honest.
| Level | Activity |
|---|---|
| L2 | Record, for each incident, the timestamps of detection, decision and containment. |
| L2 | Compute elapsed time across the full loop and record it for the cycle. |
| L2 | Report the cycle figure into the Brief. |
| L3 | Define each timestamp against an observable event, so "decision" means a recorded authorization rather than the moment someone formed a view. |
| L3 | Measure and report the three segments separately — detect, decide, contain — so the binding constraint is visible. The decide segment is constituted by EN-1 triage and EN-4 escalation; attribute time between them, since a slow triage and an unreachable authority are different problems. |
| L3 | Derive the cycle figure from a stated statistic (median, or a named percentile) rather than from a mean, which a single outlier distorts. |
| L3 | Exclude no incident from the population without a recorded justification. |
| L4 | Trend each segment independently across cycles and set a threshold on the segment that is binding rather than on the total. |
| L4 | Measure the spread as well as the central figure; a stable median with a widening tail is a degrading capability that the median conceals. |
| L5 | Attribute segment improvement to the specific change that produced it, so tempo investment is directed by evidence rather than by assumption. |
| Accountable | AO |
|---|---|
| Responsible | SOC |
| Outcome metric | median detect-to-contain elapsed time for the cycle. |
| Performance metric | percentage of incidents with all three timestamps recorded. |
| Evidence | Temporal advantage assessment; supporting incident timing records; segment breakdown. |
| Assessment | Examine the derivation from incident data; test against a sample of recorded incidents; examine whether timestamp definitions have changed between cycles being compared. |
| SP 800-53 Rev. 5 | IR-4, SI-4, AU-6 |
| CSF 2.0 | DE.AE-06, RS.MA-01 |
TA-2 · Adversary Dwell Estimation
Control. The organization shall maintain a documented estimate of adversary dwell time relevant to its threat profile, with a stated basis.
Purpose. To establish the denominator of temporal advantage with an explicit, challengeable basis, so the comparison the framework rests on can be argued with.
This is the framework's most epistemically exposed control, and it should be stated plainly rather than buried. An agency can measure its own decision loop directly; it almost never measures adversary dwell against itself, because dwell is observable only in the intrusions that were eventually found — which is a biased sample by construction, and biased toward the slow adversaries. The estimate is therefore imported from external reporting and adjusted, and the signature metric consequently rests half on measurement and half on a cited assumption. The stated basis requirement exists so that this is visible to anyone reading the result rather than concealed inside a ratio.
| Level | Activity |
|---|---|
| L2 | Record a dwell time estimate applicable to the agency's threat profile. |
| L2 | Record the source of the estimate. |
| L2 | Carry the estimate into the temporal advantage computation. |
| L3 | Select sources matched to the agency's sector, size and adversary set rather than adopting a global industry median. |
| L3 | State the known bias in the estimate explicitly — that dwell is observed only in discovered intrusions — so the figure is read as a bound rather than a fact. |
| L3 | Adjust the imported figure against any locally observed dwell from the agency's own incidents, and record the adjustment. |
| L3 | Review the estimate each cycle and on material change to the threat assessment. |
| L4 | Record a confidence level against the estimate, consistent with CE-3, and carry that confidence through to the temporal advantage result. |
| L4 | Track divergence between the imported estimate and locally observed dwell as evidence about which is wrong. |
| L5 | Build a local dwell series from the reconstructions required by EN-2, and transition the estimate from imported to measured as the series matures. |
| Accountable | AO |
|---|---|
| Responsible | CTI |
| Outcome metric | currency of the dwell estimate in cycles since last review. |
| Performance metric | divergence between imported estimate and locally observed dwell. |
| Evidence | Dwell estimate with cited basis, stated bias and confidence level. |
| Assessment | Examine the source; interview the intelligence function on its applicability; test whether the estimate has been adjusted against local observation where local observation exists. |
| SP 800-53 Rev. 5 | RA-3, PM-16 |
| CSF 2.0 | ID.RA-02, ID.RA-03 |
TA-3 · Temporal Advantage Threshold
Control. The organization shall define the minimum acceptable ratio of adversary dwell to defender decision loop, and shall treat a deficit as a reportable condition.
Purpose. To convert the temporal advantage figure into a governed condition with an escalation consequence, so that being behind is a decision the organization has to make rather than a number it can note.
The sequencing requirement is what makes this control real. A threshold set after the first measurement will be set wherever the organization already passes, which produces a governed-looking metric that has never once reported a problem. Approving the threshold before the figure is known — or at minimum recording that it was approved after, and by whom — is the difference between a risk appetite and a post-hoc justification.
| Level | Activity |
|---|---|
| L2 | Define the minimum acceptable ratio of adversary dwell to defender loop. |
| L2 | Compare the measured result to the threshold each cycle. |
| L2 | Report the result as advantage or deficit. |
| L3 | Obtain the accountable authority's approval of the threshold, recording the date of approval relative to the date of first measurement. |
| L3 | Define the escalation path a deficit triggers, including who is informed and within what period. |
| L3 | Carry the confidence level from TA-2 into the reported result, so a deficit at low confidence is distinguishable from one at high confidence. |
| L3 | Re-approve the threshold on material change to the mission or threat picture, rather than treating it as permanent. |
| L4 | Trend the result against the threshold across cycles and measure the duration of any sustained deficit. |
| L4 | Test the escalation path on a recorded deficit rather than assuming it fires. |
| L5 | Re-base the threshold against demonstrated containment outcomes — whether incidents at a given ratio were in fact contained before loss. |
| Accountable | AO |
|---|---|
| Responsible | GOV |
| Outcome metric | measured ratio against approved threshold, with confidence. |
| Performance metric | elapsed time from recorded deficit to escalation. |
| Evidence | Declared threshold with approval date; scoreboard result per cycle; escalation records. |
| Assessment | Examine the threshold and its approval; test the escalation path on a recorded deficit; examine whether the threshold was approved before or after the first measurement. |
| SP 800-53 Rev. 5 | IR-4, PM-6 |
| CSF 2.0 | GV.RM-02, GV.OV-03 |
TA-4 · Pre-authorized Response
Control. Defensive actions that may be executed without escalation shall be defined in advance and approved by the accountable authority.
Purpose. To remove authority latency from the decision loop, so that the segment most programs cannot shorten with tooling is shortened by governance.
This is the highest-leverage control in the family and the cheapest to implement, because it costs no technology. TA-1's segment breakdown usually shows the decide segment dominating the loop, and decide latency is almost entirely the time spent locating someone with authority. Pre-authorization converts that from an incident-time search into a design-time decision. The constraint is that it must be genuinely bounded: an authority so broad that it permits degrading a public service without reference will not survive its first use, and one so narrow that every real action falls outside it changes nothing.
| Level | Activity |
|---|---|
| L2 | Define which defensive actions may be executed without escalation. |
| L2 | Obtain the accountable authority's approval of that set. |
| L2 | Link each pre-authorized action to the maneuvers it enables. |
| L3 | Bound each authorization by condition, scope and duration, rather than by action type alone — "revoke sessions for a confirmed compromised account" is bounded; "revoke sessions" is not. |
| L3 | Define the escalation matrix for actions outside the pre-authorized set, naming the authority and the reachable path to it at any hour. |
| L3 | Key the pre-authorized set to campaign phase, so a declared Phase III widens what may be executed without reference. |
| L3 | Rehearse the authority in exercise, confirming operators can state what they may do unaided. |
| L4 | Measure the proportion of executed actions that fell inside the pre-authorized set, since a low proportion means the set is drawn in the wrong place. |
| L4 | Measure decide-segment latency for pre-authorized versus escalated actions, so the control's contribution is quantified rather than assumed. |
| L5 | Widen or narrow the set from observed use — actions repeatedly escalated and always approved are candidates for pre-authorization; actions pre-authorized and never used are candidates for removal. |
| Accountable | AO |
|---|---|
| Responsible | AO |
| Outcome metric | proportion of executed defensive actions falling inside the pre-authorized set. |
| Performance metric | decide-segment latency for pre-authorized versus escalated actions. |
| Evidence | Approved rules of engagement with bounds; escalation matrix; rehearsal records; action logs referencing authorization. |
| Assessment | Examine the approval; test that operators executed within authority during a recorded incident; interview operators on whether they believe the authority will be honored. |
| SP 800-53 Rev. 5 | IR-4(2), AC-2(13), IR-9 |
| CSF 2.0 | RS.MA-01, RS.MI-01, GV.RR-01 |
TA-5 · Tempo Degradation Trigger
Control. Conditions under which the defender decision loop is expected to degrade shall be identified, with compensating measures defined.
Purpose. To plan for the periods in which tempo predictably falls, so that the measured advantage is not a statement about the organization's best hours only.
Tempo is not a constant, and its degradation is not random. Nights, weekends, federal holidays, shift handovers, key-person absence, hiring gaps, contract transitions and major change windows all reduce the loop — and adversaries select those windows deliberately. A temporal advantage figure computed across a cycle averages over these conditions and therefore overstates the position at exactly the moments contact is most likely. This control exists so the average is not mistaken for the floor.
| Level | Activity |
|---|---|
| L2 | Identify the conditions under which the decision loop is expected to degrade. |
| L2 | Define a compensating measure for each condition. |
| L2 | Record both alongside the tempo measurement. |
| L3 | Include organizational conditions as well as operational ones — contract transition, key-person absence, hiring gaps and handover windows, not only nights and weekends. |
| L3 | Estimate the expected degradation per condition, so compensation can be sized rather than gestured at. |
| L3 | Assign an owner to each compensating measure and confirm it is available during the condition it compensates for. |
| L3 | Report tempo at the degraded condition as well as in aggregate, so the floor is visible next to the average. |
| L4 | Measure actual loop performance during degraded conditions against the estimate, and correct the estimate where it was optimistic. |
| L4 | Correlate incident timing against degraded windows, since adversary selection of those windows is itself a measurable finding. |
| L5 | Redesign staffing, automation or authority scope to remove the degradation condition rather than compensating for it indefinitely. |
| Accountable | AO |
|---|---|
| Responsible | SOC |
| Outcome metric | measured loop performance during degraded conditions against the aggregate figure. |
| Performance metric | percentage of identified conditions with an owned, available compensating measure. |
| Evidence | Degradation register with compensating measures and owners; degraded-condition tempo figures; incident-timing correlation. |
| Assessment | Examine the register; interview operations on a recent period of degraded capacity; test whether the compensating measure was in fact available during it. |
| SP 800-53 Rev. 5 | IR-4, CP-2, PS-2 |
| CSF 2.0 | RS.MA-01, ID.IM-01 |
EN · Engagement and Pursuit
Declaration, triage, reconstruction, evidence, escalation, eradication, communication
EN-1 · Event Declaration and Triage
Control. Adverse events shall be declared as incidents against defined criteria, and every declared incident shall be triaged, validated, categorized and prioritized within a stated period.
Purpose. To convert raw events into a decided position quickly, since this is the segment of the decision loop that most often binds.
TA-1 measures the decide segment; this control is what the decide segment consists of. Declaration criteria matter more than they appear: an estate without them declares incidents by judgment, which means the threshold moves with analyst experience, workload and the hour of day, and the resulting tempo measurement compares populations that were selected differently in each cycle. Validation is the second half — a triage process that categorizes without validating produces confident categorizations of events that never happened, and the cost lands on the eviction path.
| Level | Activity |
|---|---|
| L2 | Declare incidents when adverse events meet defined criteria. |
| L2 | Triage and validate each declared incident. |
| L2 | Categorize and prioritize each validated incident. |
| L3 | Define declaration criteria in terms an analyst can apply without escalating, so the threshold does not move with judgment or workload. |
| L3 | Prioritize against terrain: an incident touching a designated decisive point (KT-1) or high-weight element (TM-3) outranks one that does not, and the ranking basis is recorded. |
| L3 | State the period within which triage must complete, derived from the decide segment target under TA-1, with provenance per GA4. |
| L3 | Route declaration to CG-2 where the incident meets the entry condition for a campaign phase transition, since phase is how the estate changes posture. |
| L3 | Record events considered and not declared, so the declaration boundary is examinable rather than invisible. |
| L4 | Measure triage elapsed time against the stated period, and measure the false-declaration and missed-declaration rates as a two-sided check on the criteria. |
| L4 | Correlate declaration rate against degraded tempo conditions (TA-5), since a falling declaration rate during a holiday weekend is a detection finding rather than a quiet period. |
| L5 | Re-derive declaration criteria from engagements that were declared late or not at all, rather than from the criteria's original authoring assumptions. |
| Accountable | AO |
|---|---|
| Responsible | SOC |
| Outcome metric | triage elapsed time against the stated period. |
| Performance metric | false-declaration and missed-declaration rates. |
| Evidence | Declaration criteria; declared incidents with category, priority and ranking basis; non-declaration record; triage timing. |
| Assessment | Examine the criteria for applicability without escalation; test a sample of declarations against them; examine the non-declaration record for events that met criteria; test triage times against the stated period. |
| SP 800-53 Rev. 5 | IR-4, IR-5, SI-4 |
| CSF 2.0 | DE.AE-08, RS.MA-02, RS.MA-03 |
EN-2 · Engagement Reconstruction
Control. For every declared incident, the organization shall reconstruct what took place — the entry, the movement, the dwell interval and the scope reached — and shall record the actions taken during the investigation.
Purpose. To establish what actually happened, since every consolidation activity depends on a reconstruction and none of them can be performed without one.
M10's stated precondition is a dwell reconstruction, and the framework's own material observes that the reconstruction gets harder every day after the ticket closes. This is the control that makes it a requirement rather than an intention. The reconstruction is also load-bearing far beyond the incident it describes: RC-4 selects a restore point against it, TA-2 corrects the imported dwell estimate against it, M10.02 verifies avenue closure against it, and CE-2 revises intelligence requirements from what it showed could not be seen. An agency that closes incidents without reconstructing them has disabled four controls it believes it operates.
| Level | Activity |
|---|---|
| L2 | Reconstruct the entry point, the movement path and the scope reached for each declared incident. |
| L2 | Estimate the dwell interval from first access to detection. |
| L2 | Record the actions taken during the investigation, with times and actors. |
| L3 | Estimate incident magnitude — elements affected, data reached, mission impact — and record the confidence level per CE-3. |
| L3 | Record what could not be reconstructed and why, since a visibility gap is the most actionable output of an engagement and is otherwise lost. |
| L3 | Reconcile the reconstructed path against the terrain overlay and record every place the map was wrong, feeding TM-1 and M10.03. |
| L3 | Complete reconstruction before the incident is closed, with closure withheld until it is recorded. |
| L4 | Measure the proportion of declared incidents carrying a completed reconstruction, distinguishing closed from reconstructed. |
| L4 | Compare reconstructed dwell against the imported estimate under TA-2, and feed the divergence back into it. |
| L5 | Build a local dwell series from accumulated reconstructions, transitioning TA-2 from an imported figure to a measured one. |
| Accountable | AO |
|---|---|
| Responsible | HT |
| Outcome metric | percentage of declared incidents with a completed reconstruction. |
| Performance metric | divergence between reconstructed dwell and the TA-2 estimate. |
| Evidence | Reconstruction per incident with dwell, scope, magnitude and confidence; investigation action record; visibility gap findings; overlay corrections. |
| Assessment | Examine reconstructions for completeness; test that closure was withheld pending reconstruction; examine whether visibility gaps were raised as findings; compare reconstructed dwell against the estimate in use. |
| SP 800-53 Rev. 5 | IR-4(4), AU-6, IR-4 |
| CSF 2.0 | RS.AN-03, RS.AN-06, RS.AN-08, DE.AE-04 |
EN-3 · Evidence Preservation
Control. Incident data and metadata shall be preserved at a fidelity and for a period sufficient to support reconstruction, legal action and subsequent analysis, under a defined chain of custody.
Purpose. To ensure the material an engagement depends on still exists when it is needed, and is admissible where that matters.
Retention is the failure that cannot be remediated after the fact. If telemetry retention is thirty days and plausible dwell is ninety, the reconstruction under EN-2 cannot reach the entry point, RC-4 cannot select a safe restore point, and no amount of subsequent investment recovers the data. Retention should therefore be set against the dwell estimate rather than against storage cost, which is the same reasoning applied by FC-2 to physical crossing logs. Chain of custody is the second requirement and is frequently omitted until an incident turns out to involve an insider or a criminal referral, at which point it cannot be established retrospectively.
| Level | Activity |
|---|---|
| L2 | Preserve incident data and metadata on declaration. |
| L2 | Record what was preserved, by whom and when. |
| L2 | Define the retention period for preserved evidence. |
| L3 | Set telemetry retention against the dwell estimate under TA-2 rather than against storage cost, and raise a finding where retention is shorter. |
| L3 | Define chain of custody for material that may support legal or personnel action, consistent with the safeguards in WF-4. |
| L3 | Preserve material outside the environment under investigation, so evidence is not held where an adversary with access could alter it. |
| L3 | Extend preservation to volatile material where the terrain warrants it, since it is lost by containment actions taken minutes later. |
| L4 | Measure telemetry retention against the current dwell estimate per terrain layer, and trend the shortfall. |
| L4 | Test evidentiary integrity by verifying preserved material against its recorded hash or equivalent on a defined cadence. |
| L5 | Extend retention and fidelity where reconstructions repeatedly fail to reach the entry point, rather than accepting the limit as fixed. |
| Accountable | AO |
|---|---|
| Responsible | SOC |
| Outcome metric | telemetry retention against the current dwell estimate, by terrain layer. |
| Performance metric | evidentiary integrity verification pass rate. |
| Evidence | Preserved evidence inventory with custody records; retention configuration by terrain; integrity verification results. |
| Assessment | Compare retention against the current dwell estimate; test chain of custody on a sample; test that preserved material is held outside the investigated environment. |
| SP 800-53 Rev. 5 | AU-9, AU-11, IR-4 |
| CSF 2.0 | RS.AN-07 |
EN-4 · Escalation and Engagement Authority
Control. Incidents shall be escalated against defined criteria to an authority that is reachable within a stated period, and the authority exercised shall be recorded against the action taken.
Purpose. To remove the search for a decision-maker from the decision loop, which is where the decide segment is usually spent.
TA-4 defines what may be done without escalation; this control governs what happens when escalation is required, and the two together constitute the decide segment. The binding constraint in most programs is not deliberation but locating someone with authority, and that is an availability problem rather than a judgment problem. Recording authority against action closes the loop in the other direction: an operator who acted correctly under written authority and is later questioned needs the record more than the organization does, and without it the practical effect is that the next operator escalates instead.
| Level | Activity |
|---|---|
| L2 | Define the criteria at which an incident escalates. |
| L2 | Define the authority level required at each escalation tier. |
| L2 | Record the authority exercised against each action taken. |
| L3 | State the period within which each named authority must be reachable, and maintain an out-of-hours path consistent with CG-3. |
| L3 | Define escalation for the case where the named authority is unreachable, including who may act in their absence and under what constraint. |
| L3 | Escalate on terrain rather than on severity alone — an incident touching a decisive point escalates regardless of apparent magnitude. |
| L3 | Record escalations that were required by criteria and did not occur, so the gap between criteria and practice is visible. |
| L4 | Measure time from escalation trigger to authority response, separately from total decide-segment time, since these fail for different reasons. |
| L4 | Test reachability of each named authority out of hours rather than assuming it, at a defined cadence. |
| L5 | Move recurring escalations that are always approved into the pre-authorized set under TA-4, since a decision made identically every time is a policy rather than a decision. |
| Accountable | AO |
|---|---|
| Responsible | SOC |
| Outcome metric | time from escalation trigger to authority response. |
| Performance metric | percentage of named authorities verified reachable out of hours. |
| Evidence | Escalation criteria and tiers; escalation records with authority and response times; reachability test records; missed-escalation record. |
| Assessment | Examine criteria against a sample of incidents; test out-of-hours reachability; examine whether authority was recorded against actions taken. |
| SP 800-53 Rev. 5 | IR-4, IR-6, IR-7 |
| CSF 2.0 | RS.MA-04 |
EN-5 · Eradication and Transition to Recovery
Control. Incidents shall be eradicated, the eradication verified, and the transition to recovery made against defined criteria with recovery actions selected, scoped and prioritized.
Purpose. To ensure the adversary is actually gone before the mission is restored, and that the transition is a decision rather than a drift.
The transition from M8 Isolation to M11 Reconstitution is the most consequential judgment in an engagement and is usually made informally, under pressure to restore availability, on the basis that nothing further has been observed. Absence of observation is not verification, particularly where EN-2 found visibility gaps. The recovery-action scoping requirement addresses the other half: RC-3 sequences rebuild paths and RC-5 exercises them, but nothing selected which actions this particular incident requires, and restoring more than necessary extends outage while restoring less leaves the adversary a foothold.
| Level | Activity |
|---|---|
| L2 | Eradicate the adversary's presence and access. |
| L2 | Define the criteria for transition from containment to recovery. |
| L2 | Select and scope the recovery actions this incident requires. |
| L3 | Verify eradication actively — by hunting against the reconstructed tradecraft from EN-2 — rather than concluding from absence of further observation. |
| L3 | Include identity-plane eradication explicitly: credential, token and assertion revocation across every plane identified under ID-1, since access persists there after endpoint eradication. |
| L3 | Prioritize recovery actions against mission and terrain, and record the basis. |
| L3 | Require the transition decision to be taken by the authority defined in EN-4 and recorded, rather than occurring by default. |
| L3 | Withhold transition where EN-2 recorded visibility gaps material to the eradication claim, or record the residual risk acceptance under CG-4. |
| L4 | Measure recurrence: an incident recurring through the same avenue within a defined window is an eradication failure and should be counted as one. |
| L4 | Measure elapsed time from containment to verified eradication, which is a distinct interval from the containment measured under TA-1. |
| L5 | Feed eradication failures into M10 avenue closure verification and into the detection engineering backlog, since a recurrence is a detection gap as much as an eradication one. |
| Accountable | AO |
|---|---|
| Responsible | HT |
| Outcome metric | recurrence rate through previously used avenues within the defined window. |
| Performance metric | elapsed time from containment to verified eradication. |
| Evidence | Eradication verification results including identity-plane revocation; recovery action selection with basis; transition decision record with authority; recurrence findings. |
| Assessment | Test that eradication was verified by hunting rather than inferred from absence; examine whether identity-plane eradication occurred; test that the transition decision was taken by the defined authority and recorded. |
| SP 800-53 Rev. 5 | IR-4, IR-4(4), CP-10 |
| CSF 2.0 | RS.MI-02, RS.MA-05, RC.RP-02 |
EN-6 · Engagement Communication
Control. Incident and recovery information shall be shared with designated internal stakeholders, external partners and the public as the situation and the agency's obligations require, within stated periods.
Purpose. To ensure the people who must know, do — inside the agency, across the federal community, and among those the mission serves.
This control covers three audiences with different clocks and is distinct from CE-7, which distributes the cycle Brief internally on a cadence. Internal stakeholder notification is an operational obligation; federal reporting to CISA and sector partners is frequently a statutory one with a defined window; and public communication during a recovery is where a federal agency's obligation to the people it serves becomes concrete. The framework's own material puts the community reporting case well: reporting is not altruism in a federal community — it is how the next agency's spoiling attack becomes possible, and how yours does.
| Level | Activity |
|---|---|
| L2 | Identify the internal stakeholders, external partners and public audiences to be informed. |
| L2 | Communicate incident information to each within stated periods. |
| L2 | Communicate recovery status and completion as the situation develops. |
| L3 | Record the statutory or policy reporting windows applying to each recipient, with provenance per GA4, and treat a missed window as a finding. |
| L3 | Define what may be shared with each audience at each stage, so operational sensitivity and the duty to inform are reconciled in advance rather than negotiated during. |
| L3 | Share indicators and tradecraft with sector partners and CISA once eradication permits, consistent with M10.05 and the agency's disclosure authorities. |
| L3 | Designate the communication authority per audience, since public communication is a command decision rather than an analyst's. |
| L3 | Provide recovery status to those affected by the mission impact, not only to internal stakeholders. |
| L4 | Measure communication timeliness against each stated window and trend it. |
| L4 | Measure the proportion of eradicated incidents that resulted in a community contribution, since a program that only receives from the community is not participating in it. |
| L5 | Review communications after each engagement against what recipients actually needed, and revise the audience and content definitions. |
| Accountable | AO |
|---|---|
| Responsible | GOV |
| Outcome metric | percentage of required communications delivered within their stated window. |
| Performance metric | proportion of eradicated incidents resulting in a community contribution. |
| Evidence | Communication records with recipients, content, authority and timing; reporting window register; community contribution records; missed-window findings. |
| Assessment | Examine communications against stated windows; test that the designated authority approved public communication; examine whether recent engagements produced community contributions. |
| SP 800-53 Rev. 5 | IR-6, IR-9, PM-16 |
| CSF 2.0 | RS.CO-02, RS.CO-03, RC.CO-03, RC.CO-04 |
CE · Cycle Execution and Assurance
Cadence, intelligence requirements, posture computation, the evidentiary record
CE-1 · Cycle Cadence
Control. The organization shall execute the full analytic cycle at a defined cadence and shall not allow the interval to lapse without recorded justification.
Purpose. To keep the loop turning, so that defensive posture is a maintained position rather than a periodic assessment.
The cycle is the first thing sacrificed when the SOC is busy, and the SOC is busy precisely when the cycle would be most valuable. That inversion is the failure mode this control exists to catch. A lapse is also invisible by default — nothing alerts when a cadence quietly stretches from monthly to quarterly, and a program can discover it only by looking at dates it has no reason to look at. Requiring a recorded justification makes the lapse an event rather than an absence.
| Level | Activity |
|---|---|
| L2 | Execute the full analytic cycle and record its date and phase. |
| L2 | Define the cadence at which the cycle is expected to run. |
| L2 | Maintain a cycle history from which the interval can be read. |
| L3 | State the rationale for the interval, so it can be challenged rather than inherited. |
| L3 | Record a justification for any interval that exceeds the cadence, naming who accepted the lapse. |
| L3 | Define which steps of the cycle may be abbreviated under load and which may not, so pressure produces a known degradation rather than an ad hoc one. |
| L3 | Separate cycle execution ownership from incident response ownership where staffing permits, so the two do not compete for the same people. |
| L4 | Trend the actual interval against the defined cadence and escalate a sustained overrun rather than a single one. |
| L4 | Correlate lapses against incident load, since a cadence that holds only in quiet periods is not a cadence. |
| L5 | Adjust the cadence from measured estimate drift — if the terrain and threat picture move faster than the interval assumes, the interval is wrong. |
| Accountable | AO |
|---|---|
| Responsible | CTI |
| Outcome metric | percentage of intervals meeting the defined cadence. |
| Performance metric | median interval between completed cycles. |
| Evidence | Cycle history with dates and phase; lapse justifications with named acceptor. |
| Assessment | Examine cycle records against the defined cadence; examine whether lapses cluster against periods of high incident load. |
| SP 800-53 Rev. 5 | CA-7, PM-31 |
| CSF 2.0 | ID.IM-03, GV.OV-01 |
CE-2 · Priority Intelligence Requirements
Control. Each cycle shall begin with a defined set of priority intelligence requirements that drive collection and hunting.
Purpose. To direct analytic effort at named questions, so that collection and hunting answer what the accountable authority needs rather than processing what arrives.
Hunting without a requirement is sampling, and sampling an estate of federal scale returns whatever the analyst already expected to find. The tracking requirement is what separates this from a wish list: requirements that are recorded, never answered, and silently carried forward for four cycles describe an intelligence function that is busy rather than one that is directed. A requirement should close — as answered, as no longer relevant, or as unanswerable with current collection, which is itself a finding about visibility.
| Level | Activity |
|---|---|
| L2 | Define the priority intelligence requirements for the cycle before collection begins. |
| L2 | Record each requirement with a status of open, watching or answered. |
| L2 | Direct collection and hunting activity against the open requirements. |
| L3 | Derive requirements from the defensive intent (CG-1), the declared phase (CG-2) and the current threat courses of action, rather than from analyst preference. |
| L3 | State for each requirement what an answer would look like, so it can be recognized when obtained. |
| L3 | Close requirements explicitly, including closure as unanswerable with current collection — which is raised as a visibility finding rather than dropped. |
| L3 | Carry unanswered requirements forward with a recorded reason rather than by default. |
| L4 | Measure the proportion of requirements answered per cycle and the age of the oldest open requirement. |
| L4 | Measure the proportion of hunting effort attributable to a named requirement, since unattributed effort is sampling. |
| L5 | Revise the requirement-setting method where answered requirements repeatedly fail to change any decision, since a requirement that changes nothing was the wrong question. |
| Accountable | AO |
|---|---|
| Responsible | CTI |
| Outcome metric | percentage of cycle requirements closed with a recorded disposition. |
| Performance metric | percentage of hunting effort attributable to a named requirement. |
| Evidence | Intelligence requirement register with status and closure dispositions; visibility findings raised from unanswerable requirements. |
| Assessment | Examine the register; test that collection or hunting activity addressed a sample of open requirements; examine the age of the oldest open item. |
| SP 800-53 Rev. 5 | PM-16, RA-10, SI-5 |
| CSF 2.0 | ID.RA-02, DE.AE-07 |
CE-3 · Fusion and Confidence
Control. Analytic conclusions shall be recorded with an explicit confidence level and the basis for that confidence.
Purpose. To distinguish assessment from assertion, so that decisions taken on analytic conclusions carry the uncertainty of those conclusions with them.
Confidence is what makes an analytic product falsifiable. A conclusion offered without it cannot be wrong in any useful sense, because it never committed to a degree of belief. The scale also has to be usable in both directions: if every product is issued at high confidence, the scale conveys no information and the field is decorative. An analytic function that has never published a low-confidence assessment on a significant question is not being careful, it is being unfalsifiable.
| Level | Activity |
|---|---|
| L2 | Record a confidence level against each analytic conclusion. |
| L2 | Record the basis on which that confidence rests. |
| L2 | Carry confidence into the products the conclusion feeds. |
| L3 | Define the confidence scale and what distinguishes adjacent levels, so it is applied consistently between analysts. |
| L3 | Apply structured analytic techniques to significant conclusions and record which were used. |
| L3 | State the key assumptions a conclusion depends on, so a change in assumption can be traced to the conclusions it invalidates. |
| L3 | Carry confidence through to derived figures — notably the temporal advantage result (TA-3) — rather than dropping it at the first computation. |
| L4 | Measure the distribution of confidence levels issued; a distribution concentrated at high confidence indicates the scale is not being used. |
| L4 | Review past conclusions against subsequent evidence and measure calibration — whether high-confidence assessments were in fact more often right. |
| L5 | Adjust analytic practice from measured calibration error rather than from reviewer preference. |
| Accountable | AO |
|---|---|
| Responsible | CTI |
| Outcome metric | percentage of conclusions carrying an explicit confidence and basis. |
| Performance metric | calibration error measured against subsequent evidence. |
| Evidence | Findings with stated confidence and basis; structured technique records; assumption register. |
| Assessment | Examine a sample of conclusions for stated confidence and basis; interview analysts on the scale used; examine the distribution of confidence levels issued across recent cycles. |
| SP 800-53 Rev. 5 | RA-3, SI-4(16), PM-16 |
| CSF 2.0 | DE.AE-02, DE.AE-03, ID.RA-05 |
CE-4 · Coverage and Residual Risk Computation
Control. Defensive coverage and residual risk shall be computed from asset weighting, layer maturity, and operational move mitigation, using a documented method.
Purpose. To produce a posture figure that can be reproduced and challenged rather than asserted, so that the number carries authority beyond the tool that generated it.
The denominator determines the answer, and the choice of denominator is a judgment that must be published rather than embedded. Counting techniques evidenced rewards tagging a crowded intersection over a sparse one for identical effort; counting ground held — terrain × form cells occupied — does not, which is why the framework scores that way. But the reasoning is only defensible if it is stated where the figure appears. A coverage percentage whose denominator is undisclosed is not a measurement, and an adopter who cannot reproduce it cannot argue with it.
| Level | Activity |
|---|---|
| L2 | Compute defensive coverage from asset weighting, layer maturity and operational move mitigation. |
| L2 | Compute residual risk from the same inputs. |
| L2 | Report both figures for the cycle. |
| L3 | Document the method in sufficient detail that an assessor can recompute the figure from the recorded inputs without access to the tool. |
| L3 | State the denominator explicitly wherever the figure is published, including the choice between ground held and techniques evidenced and the reason for it. |
| L3 | Weight mitigation by implementation state (SM-3), so planned and partial moves do not count in full. |
| L3 | Record the framework version against every computed figure, since a change in the framework's shape changes the denominator. |
| L4 | Recompute at least one prior cycle's figure from its recorded inputs each cycle, confirming the method is stable and the inputs were preserved. |
| L4 | Measure the sensitivity of the figure to its most uncertain input, so the reported precision does not exceed the underlying certainty. |
| L5 | Revise the method where sensitivity analysis shows the figure is dominated by an input the organization cannot measure well. |
| Accountable | AO |
|---|---|
| Responsible | GOV |
| Outcome metric | coverage and residual risk for the cycle, with denominator stated. |
| Performance metric | percentage of prior-cycle figures reproducible from retained inputs. |
| Evidence | Posture computation in the Brief; documented method with denominator; retained inputs; recomputation record. |
| Assessment | Examine the method; test the computation by recomputing from source inputs; examine whether the framework version is recorded against each figure. |
| SP 800-53 Rev. 5 | RA-3, CA-2, PM-9 |
| CSF 2.0 | ID.RA-05, GV.RM-02 |
CE-5 · Remediation Backlog Prioritization
Control. Identified gaps shall be ranked by the residual risk they retire per unit of effort, and shall be assigned owners and target dates.
Purpose. To make the backlog answer where the next hour of work goes, rather than enumerate everything wrong.
Ranking by risk alone produces a backlog headed by items nobody can afford; ranking by effort alone produces a quarter of completed busywork with the risk position unchanged. The ratio is the whole point, and it is also the part most often dropped in implementation, because effort estimates are uncomfortable to produce and easy to omit. A backlog with risk scores and no effort estimates has not implemented this control.
| Level | Activity |
|---|---|
| L2 | Record identified gaps as a backlog. |
| L2 | Estimate the residual risk each gap retires if closed. |
| L2 | Assign an owner and a target date to each item. |
| L3 | Estimate the effort each item requires, on a defined scale, so the ratio can be computed rather than intuited. |
| L3 | Rank by risk retired per unit of effort and publish the ranking basis. |
| L3 | Reconcile ownership against terrain ownership (TM-7), so backlog items land on people who already hold the ground. |
| L3 | Re-rank each cycle from current figures rather than preserving a stale order. |
| L4 | Measure realized risk retirement against estimate for completed items, and correct the estimation method where it is systematically optimistic. |
| L4 | Trend backlog age by rank band; high-ranked items ageing indicates the ranking is not driving allocation. |
| L5 | Feed completion data back into effort estimation, so the ratio improves in accuracy as the program accumulates history. |
| Accountable | AO |
|---|---|
| Responsible | GOV |
| Outcome metric | residual risk retired per cycle. |
| Performance metric | median age of items in the top rank band. |
| Evidence | Ranked backlog with owners, target dates, effort estimates and ranking basis. |
| Assessment | Examine the ranking basis; test progress against target dates; examine whether effort estimates exist at all for the top-ranked items. |
| SP 800-53 Rev. 5 | CA-5, RA-7, PM-4 |
| CSF 2.0 | ID.RA-06, ID.IM-02, GV.RM-06 |
CE-6 · Cycle Record and Trend
Control. Each cycle shall be recorded with its posture result, and the trend across cycles shall be reported.
Purpose. To answer whether the program is improving — a question no point-in-time assessment can address.
A trend is only interpretable if the denominator did not change between its points, and the framework's own versioning rules make this concrete: a structural change adds or removes a form, a terrain layer or a phase, and every coverage score computed against the prior version becomes incomparable. A series that silently spans a version boundary is not a trend, it is two trends drawn as one — and it will show improvement or decline that is an artifact of the denominator rather than of the estate. Recording the framework version against each point is what makes the series honest.
| Level | Activity |
|---|---|
| L2 | Record each cycle's posture result. |
| L2 | Report the change since the prior cycle. |
| L2 | Preserve the series rather than overwriting the current position. |
| L3 | Record the framework version against every point in the series. |
| L3 | Break the trend line visibly at any version boundary that changed the denominator, rather than plotting across it. |
| L3 | Preserve the inputs to each figure, not only the figure, so a point can be recomputed under CE-4. |
| L3 | Record alongside each point the material events of that cycle — incidents, architectural changes, staffing changes — so a movement can be attributed. |
| L4 | Distinguish movement caused by estate change from movement caused by measurement change, and report the two separately. |
| L4 | Measure the proportion of cycle-over-cycle movement that can be attributed to a recorded cause. |
| L5 | Use the series to test the framework's own assumptions — a weighting that never moves the aggregate is a weighting carrying no information. |
| Accountable | AO |
|---|---|
| Responsible | GOV |
| Outcome metric | direction and magnitude of posture movement across the current series. |
| Performance metric | percentage of movement attributable to a recorded cause. |
| Evidence | Cycle history table; movement-over-time section of the Brief; version stamps; attribution records. |
| Assessment | Examine the series for completeness; test two entries against their source computations; examine whether any version boundary is plotted across without a break. |
| SP 800-53 Rev. 5 | CA-7(3), AU-6, PM-31 |
| CSF 2.0 | ID.IM-03, GV.OV-01 |
CE-7 · Brief Generation and Distribution
Control. Each cycle shall produce a brief recording terrain, decisive points, scheme of maneuver, posture, findings, and trend, distributed to the accountable authority.
Purpose. To produce one document per cycle that an Authorizing Official can decide from, rather than a dashboard nobody decides from.
Generation and distribution are the easy halves; use is the control's actual object. A Brief that is produced, distributed and never decided from satisfies every literal reading of the requirement and delivers nothing, which is why the assessment interviews recipients rather than examining distribution lists. The Brief is also the framework's compliance exhaust: because each section cites the controls it evidences, a retained series of Briefs is the FISMA continuous-monitoring record, produced as a by-product of defending.
| Level | Activity |
|---|---|
| L2 | Generate a Brief each cycle covering terrain, decisive points, scheme of maneuver, posture, findings and trend. |
| L2 | Distribute it to the accountable authority. |
| L2 | Retain it as the cycle record. |
| L3 | Cite in each section the controls it evidences, so the Brief serves as assessment evidence without separate authoring. |
| L3 | Head the Brief with the defensive intent (CG-1) and the declared phase (CG-2), so posture is read against stated purpose. |
| L3 | State confidence on assessments carried into the Brief, consistent with CE-3. |
| L3 | Record the decisions taken from each Brief, so use is evidenced rather than assumed. |
| L4 | Measure the proportion of Briefs from which a recorded decision followed. |
| L4 | Measure elapsed time from cycle completion to distribution, since a Brief arriving after the situation has moved is a historical document. |
| L5 | Revise Brief content from what recipients actually decided from, removing sections that have never informed a decision. |
| Accountable | AO |
|---|---|
| Responsible | CTI |
| Outcome metric | percentage of Briefs from which a recorded decision followed. |
| Performance metric | elapsed time from cycle completion to distribution. |
| Evidence | Generated Briefs, dated and retained, with control citations; decision records. |
| Assessment | Examine retained briefs; interview recipients on receipt and use; test whether a decision is recorded against a sample of Briefs. |
| SP 800-53 Rev. 5 | CA-7, PM-31, PL-2 |
| CSF 2.0 | GV.OV-01, ID.IM-03 |
CG · Command and Governance
Intent, phase, rules of engagement, findings disposition, inheritance
CG-1 · Defensive Intent
Control. The accountable authority shall issue a defensive intent stating the end-state to be protected and the risk that is acceptable, expressed in plain language.
Purpose. To give subordinate decisions a reference point, so that people can act correctly without referring upward.
The test of an intent is operational, not literary: can someone two levels down, at three in the morning, make a decision from it without calling? Most published intents fail that test because they state aspiration rather than acceptable risk. "Protect mission-transaction integrity and sensitive records; degrade gracefully, never fail open" tells an operator what to trade when they must trade something. A statement that lists everything as important tells them nothing, and they will escalate — which is the decide-segment latency TA-1 measures.
| Level | Activity |
|---|---|
| L2 | Issue a defensive intent stating the end-state to be protected. |
| L2 | State the risk that is acceptable in pursuit of it. |
| L2 | Publish the intent where those executing it can reach it. |
| L3 | Express the intent in plain language, without technology or product terms, so it survives re-tooling and is legible to mission staff. |
| L3 | State explicitly what may be traded and in what order, since an intent that subordinates nothing cannot resolve a conflict. |
| L3 | Obtain the accountable authority's signature and record the date. |
| L3 | Head every generated Brief with the current intent, so posture is always read against purpose. |
| L4 | Test comprehension by interviewing operators on a decision the intent should resolve, and measure whether they resolve it consistently. |
| L4 | Review the intent on material change to mission or threat, and record the review even where no change results. |
| L5 | Revise the intent where recorded escalations show a recurring decision the intent does not resolve. |
| Accountable | AO |
|---|---|
| Responsible | AO |
| Outcome metric | consistency of operator decisions on a test case the intent should resolve. |
| Performance metric | currency of the intent in cycles since last review. |
| Evidence | Signed intent statement with date; publication record; comprehension test results. |
| Assessment | Examine the statement and its approval; interview operators on whether they can act on it unaided; test comprehension against a decision the intent should resolve. |
| SP 800-53 Rev. 5 | PM-1, PL-1, PM-29 |
| CSF 2.0 | GV.OC-01, GV.PO-01 |
CG-2 · Phase Declaration
Control. The organization shall declare its current campaign phase, and shall align main effort and resourcing to it.
Purpose. To make "we are in Phase III" a sentence that changes behavior, rather than a label applied to a state of affairs.
Phase declaration shares a failure mode with main effort designation: both are trivially satisfiable as labels and both are meaningless unless something downstream is keyed to them. The framework's design keys real consequences to phase — pre-authorized response sets widen (TA-4), session lifetimes shorten, dominant forms change, and resourcing shifts. If none of those change on transition, the declaration is a status field. The assessment therefore tests what changed, not what was declared.
| Level | Activity |
|---|---|
| L2 | Declare the current campaign phase. |
| L2 | Record the declaration with its date and the condition that triggered it. |
| L2 | Score readiness against the phase's dominant forms. |
| L3 | Define the entry and exit conditions for each phase, so transition is a recognizable event rather than a judgment call, and bind them to the declaration criteria under EN-1 so a declared incident meeting a phase entry condition routes to the transition decision rather than being handled locally. |
| L3 | Key at least one consequential control to phase — pre-authorized response, session lifetime, or cadence — so declaration changes behavior. |
| L3 | Align main effort (SM-4) and resourcing to the declared phase on transition. |
| L3 | Communicate transition to everyone whose authority or task changes as a result. |
| L4 | Measure what actually changed on the last transition — authorizations, allocations, configurations — and treat an empty answer as a finding. |
| L4 | Trend time spent in each phase; a program permanently in Phase 0 has not implemented phasing. |
| L5 | Revise phase entry conditions where transitions were repeatedly declared late relative to when contact began. |
| Accountable | AO |
|---|---|
| Responsible | AO |
| Outcome metric | number of consequential controls whose state changed on last transition. |
| Performance metric | elapsed time from transition condition to declaration. |
| Evidence | Declared phase with trigger and date; phase readiness score; record of what changed on transition. |
| Assessment | Examine the declaration and readiness score; interview on resourcing alignment; test what materially changed at the last transition. |
| SP 800-53 Rev. 5 | PM-11, IR-4, CP-2 |
| CSF 2.0 | GV.RM-01, ID.IM-01 |
CG-3 · Rules of Engagement
Control. The organization shall maintain approved rules of engagement defining which defensive actions may be executed at which authority level.
Purpose. To let operators act inside a known mandate rather than guessing at one, and to make the boundaries of that mandate legally and operationally sound.
Rules of engagement carry a constraint the rest of the framework does not: some defensive actions have statutory consequences. Degrading a public service where a statute sets a deadline, or acting on a system holding regulated records, is not purely a security decision. The ROE is where those limits are recorded, and it is also where the framework's boundary sits — nothing in ASOM-Fed contemplates action outside the agency's own terrain, and the ROE should say so explicitly rather than leaving it to inference from doctrine.
| Level | Activity |
|---|---|
| L2 | Define which defensive actions may be executed at which authority level. |
| L2 | Obtain approval from the accountable authority. |
| L2 | Link the rules to the maneuvers and pre-authorized actions they govern. |
| L3 | Record the statutory and regulatory constraints bounding specific actions, referencing the availability floors under FO-5 where they apply. |
| L3 | State explicitly that no action extends outside the agency's own boundary, so the limit is written rather than inferred. |
| L3 | Ensure the authority named for each escalation level is reachable at any hour, and record the path. |
| L3 | Review the rules on phase transition, on legal change, and at cadence. |
| L4 | Measure adherence during recorded incidents — actions taken outside authority, and actions not taken because authority could not be reached. |
| L4 | Test reachability of each named authority out of hours rather than assuming it. |
| L5 | Revise authority levels where measured adherence shows the rules are routinely worked around rather than followed. |
| Accountable | AO |
|---|---|
| Responsible | GOV |
| Outcome metric | percentage of recorded incident actions taken within written authority. |
| Performance metric | percentage of named authorities verified reachable out of hours. |
| Evidence | Approved rules of engagement with legal bounds; reachability test records; incident action logs referencing authority. |
| Assessment | Examine approval and currency; test adherence in a recorded incident; test whether a named out-of-hours authority is in fact reachable. |
| SP 800-53 Rev. 5 | IR-4, AC-2, PM-1 |
| CSF 2.0 | GV.RR-01, RS.MA-01 |
CG-4 · Findings Disposition
Control. Findings raised by architectural review shall be dispositioned as remediated, accepted with justification, or transferred, within a defined period.
Purpose. To ensure every finding reaches a decision, so that the open set reflects work in progress rather than accumulated neglect.
Acceptance is where this control is defeated. A finding accepted permanently, by someone without the authority to accept it, disappears from view while the risk remains — and a program with a large accepted set can report a small open set indefinitely. Two requirements close that: acceptance must be by a person whose risk authority covers the exposure, and it must expire, forcing periodic re-decision rather than one-time disposal.
| Level | Activity |
|---|---|
| L2 | Record every finding with its source and date. |
| L2 | Disposition each as remediated, accepted with justification, or transferred. |
| L2 | Define the period within which disposition must occur. |
| L3 | Require acceptance to be made by a person whose risk authority covers the exposure, recorded by name. |
| L3 | Give every acceptance an expiry, after which it returns for re-decision rather than persisting. |
| L3 | Record for transferred findings who received them and their acknowledgment. |
| L3 | Escalate findings exceeding the disposition period rather than ageing them. |
| L4 | Trend the accepted set alongside the open set, since a shrinking open set and a growing accepted set is not improvement. |
| L4 | Measure re-decision outcomes on expiry — acceptances renewed without change indicate risk being deferred rather than managed. |
| L5 | Feed recurring finding types back into the control that generates them, since a finding class that keeps recurring is a design problem rather than a remediation backlog. |
| Accountable | AO |
|---|---|
| Responsible | GOV |
| Outcome metric | percentage of findings dispositioned within the defined period. |
| Performance metric | ratio of accepted to remediated dispositions, trended. |
| Evidence | Findings register with disposition, dates, named acceptors and expiries; transfer acknowledgments. |
| Assessment | Examine open findings against the defined period; test the justification recorded for accepted risks; test whether acceptors held authority covering the exposure. |
| SP 800-53 Rev. 5 | CA-5, CA-7, RA-7 |
| CSF 2.0 | ID.IM-02, GV.RM-03 |
CG-5 · Control Inheritance Mapping
Control. The organization shall maintain the mapping between these controls and its existing control baseline, and shall assess inherited controls once rather than twice.
Purpose. To keep the framework additive, so that adopting it adds assessment effort only where it adds assessable content.
This is the control adoption depends on. A framework layered onto SP 800-53 that re-assesses what 800-53 already covers doubles the assessment burden and will be declined regardless of merit — and the decline will be correct. The mapping has to be maintained rather than published once: control baselines are tailored, overlays change, and an inheritance claim citing an assessment that no longer covers the requirement is worse than no claim, because it retires a requirement that nothing is actually testing. FO-3 applies the same discipline at a different scope: CG-5 verifies inheritance from a control baseline, FO-3 verifies it from a service provider, and a requirement can fall between the two if neither is checked.
| Level | Activity |
|---|---|
| L2 | Maintain the mapping between ASOM-Fed controls and the existing baseline. |
| L2 | Declare for each control whether it is inherited, extended, or net new. |
| L2 | Cite existing assessment results as evidence where inheritance applies. |
| L3 | Verify that each cited assessment actually covers the requirement claimed, rather than covering the control family it belongs to. |
| L3 | Assess only the delta for extended controls, and state what that delta is. |
| L3 | Re-verify inheritance claims when the baseline is tailored, an overlay is applied, or a cited assessment expires. |
| L3 | Record where an inheritance claim fails verification, since that requirement is then unassessed by anything. |
| L4 | Measure the assessment effort attributable to ASOM-Fed over and above the existing baseline, which is the framework's true marginal cost. |
| L4 | Measure the proportion of inheritance claims that survive verification, since a low rate means the mapping is aspirational. |
| L5 | Feed verification failures back to the framework steward, since a claim that fails at multiple agencies is a defect in the published crosswalk rather than in the adopter. |
| Accountable | AO |
|---|---|
| Responsible | GOV |
| Outcome metric | percentage of inheritance claims verified against a current assessment result. |
| Performance metric | assessment effort attributable to ASOM-Fed beyond the baseline. |
| Evidence | Maintained crosswalk with inheritance decisions and verification status; cited assessment results; unassessed-requirement findings. |
| Assessment | Examine the crosswalk; test two inherited controls to confirm the cited assessment covers the requirement; examine whether any claim has ever failed verification. |
| SP 800-53 Rev. 5 | PM-10, CA-2, SA-4 |
| CSF 2.0 | GV.SC-07, GV.OV-02 |
RC · Reconstitution and Recovery
Recovery held outside the blast radius and proven by exercise
RC-1 · Recovery Objectives
Control. Every mission service shall have a declared recovery time objective and recovery point objective, approved by the service owner, recorded on the terrain overlay before an incident occurs.
Purpose. To establish what recovery must achieve, so that restoration can succeed or fail rather than simply take however long it takes.
Without a stated time and a stated tolerable data loss, recovery has no success condition. The approval requirement matters as much as the numbers: an objective set by the security or infrastructure function is a capability estimate, whereas one set by the service owner is a mission judgment about what the agency can survive. Those are different claims, and only the second can justify the investment the first implies. A declared objective is also not a demonstrated one — that distinction is RC-5's object, and an agency holding objectives it has never tested holds aspirations.
| Level | Activity |
|---|---|
| L2 | Declare a recovery time objective and a recovery point objective for every mission service. |
| L2 | Record both on the terrain overlay against the service. |
| L2 | Flag mission services carrying no declared objective. |
| L3 | Obtain the service owner's approval of both figures, recorded by name and date, so the objective is a mission judgment rather than a capability estimate. |
| L3 | Verify that each objective satisfies any statutory or regulatory availability floor applying to that service (FO-5), and raise a finding where it does not. |
| L3 | State the dependency chain for each service, since a service cannot recover faster than the identity, network and data services it depends on. |
| L3 | Record objectives with approval provenance per GA4. |
| L4 | Compare declared objectives against demonstrated recovery times from RC-5, and flag every objective whose demonstrated time exceeds it. |
| L4 | Measure the proportion of mission services whose objectives have been demonstrated at all, distinguishing declared from proven. |
| L5 | Re-base objectives from demonstrated capability and mission consequence together, rather than allowing the declared figure to persist unchallenged against repeated failure to meet it. |
| Accountable | AO |
|---|---|
| Responsible | TO |
| Outcome metric | percentage of mission services with an owner-approved objective. |
| Performance metric | percentage of objectives demonstrated within their stated period. |
| Evidence | Recovery objectives table with owner approval and dates; statutory floor verification; dependency chains. |
| Assessment | Examine the objectives table for completeness against the mission service list; interview service owners on whether the stated figures reflect a mission judgment they made; test that no objective is weaker than its statutory floor. |
| SP 800-53 Rev. 5 | CP-2, CP-2(3), PM-11 |
| CSF 2.0 | RC.RP-01, GV.OC-04, GV.OC-05 |
RC-2 · Isolated Recovery Capability
Control. The means of recovery shall be held outside the trust boundary of the production identity plane, such that compromise of production credentials cannot reach, alter, or destroy them.
Purpose. To ensure the recovery capability survives the compromise it exists to recover from.
This is the ransomware lesson stated as a control. Backups that authenticate against the production identity provider are reachable by anyone who holds production administrative credentials, which is precisely the position an adversary occupies at the moment recovery becomes necessary. The operative test is narrower and more useful than "held outside the boundary": can a production administrator credential, used adversarially, reach the recovery store? That question has a demonstrable answer, and a great many recovery architectures that satisfy the general statement fail the specific test.
| Level | Activity |
|---|---|
| L2 | Place the recovery store in a trust zone separate from production. |
| L2 | Record the authentication path by which the recovery store is reached. |
| L2 | Raise a finding where the recovery store shares an identity provider with production. |
| L3 | Test whether a production administrator credential can reach, alter or delete the recovery store, rather than inferring independence from architecture. |
| L3 | Verify that the credentials governing the recovery store are issued, held and rotated independently of production. |
| L3 | Apply the same independence test to the recovery store's own management plane, including its console, its orchestration and its monitoring. |
| L3 | Verify immutability or retention locking where the platform supports it, and record where it does not. |
| L4 | Test independence on a defined cadence and after any change to either identity plane, and trend the pass rate. |
| L4 | Measure the elapsed time between an identity-plane change and the next independence test, since that interval is the exposure window. |
| L5 | Re-derive the independence test from adversary tradecraft observed in engagements and in sector reporting, rather than testing only the paths the original design anticipated. |
| Accountable | AO |
|---|---|
| Responsible | TO |
| Outcome metric | result of the production-credential reachability test against the recovery store. |
| Performance metric | currency of the last independence test relative to the last identity-plane change. |
| Evidence | Terrain overlay showing the recovery zone and its trust boundary; credential separation record; independence test results. |
| Assessment | Test whether a production administrator credential can reach the recovery store; examine the authentication path for independence; test the recovery store's management plane by the same method. |
| SP 800-53 Rev. 5 | CP-6, CP-9(3), SC-28 |
| CSF 2.0 | RC.RP-01, PR.DS-11, PR.IR-03 |
RC-3 · Trusted Rebuild Path
Control. For every decisive point, the organization shall maintain a documented and tested path to rebuild the element from trusted media within its declared recovery time objective.
Purpose. To ensure that what must not be lost can be rebuilt, from a source the adversary did not touch, inside the time the mission requires.
Most rebuild procedures assume a working identity plane — they begin with authenticating to something. Where identity is itself the decisive point that was compromised, the procedure contains a circular dependency, and it surfaces at the worst possible moment. The identity plane's own rebuild path therefore has to be tested independently and first, because every other path in the estate depends on it. The trusted-media requirement carries the second half of the problem: media stored, indexed or validated by the compromised environment is not trusted media regardless of where it physically sits.
| Level | Activity |
|---|---|
| L2 | Document a rebuild path for every designated decisive point. |
| L2 | Identify the media source each path rebuilds from. |
| L2 | Record the most recent rebuild test and its elapsed time. |
| L3 | Verify that each media source is independently trusted — not stored, indexed or validated by the environment being rebuilt. |
| L3 | Test the rebuild path for the identity plane itself, and sequence it first, since every other path depends on a working identity service. |
| L3 | Record the dependency order across rebuild paths, so reconstitution can be sequenced rather than attempted in parallel. |
| L3 | Compare each tested elapsed time against the element's declared recovery time objective (RC-1) and raise a finding where it exceeds. |
| L4 | Test each decisive point's rebuild path on a defined cadence and trend the elapsed times, since procedures decay as platforms change. |
| L4 | Measure the proportion of decisive points whose rebuild path has been tested at all, distinguishing documented from tested. |
| L5 | Re-engineer paths whose tested time persistently exceeds the objective, rather than repeatedly recording the same finding. |
| Accountable | AO |
|---|---|
| Responsible | TO |
| Outcome metric | percentage of decisive points with a tested rebuild path meeting their objective. |
| Performance metric | median age of the most recent rebuild test per decisive point. |
| Evidence | Rebuild procedure per decisive point; record of the most recent rebuild test and its elapsed time; media provenance verification; dependency sequence. |
| Assessment | Examine the procedures for currency; test one rebuild against its stated recovery time objective; verify the media source is independently trusted; test whether the identity plane's own rebuild path has been exercised. |
| SP 800-53 Rev. 5 | CP-10, SI-7, CM-2 |
| CSF 2.0 | RC.RP-04, PR.PS-02 |
RC-4 · Recovery Integrity Verification
Control. Restored data and rebuilt systems shall be verified against an integrity record maintained independently of the system being restored, before the service is returned to use.
Purpose. To ensure restoration returns the mission to a known-good state rather than reinstating the compromise.
Recovery has a failure mode that looks exactly like success: restoring from a point after the intrusion began returns the service, the data and the adversary together. The integrity record therefore has to satisfy two conditions rather than one — it must be maintained independently of the system being restored, and it must predate the earliest plausible compromise. The second condition is what connects this control to dwell estimation: if adversary dwell may have been ninety days, an integrity baseline taken thirty days ago verifies nothing useful, and the restore point has to be chosen against the dwell estimate rather than against the last known-good backup.
| Level | Activity |
|---|---|
| L2 | Record the integrity source used to verify each recovery store. |
| L2 | Verify restored data and rebuilt systems against that source before returning the service to use. |
| L2 | Record the verification result. |
| L3 | Verify that the integrity record is maintained independently of the system being restored, including independently of its identity plane. |
| L3 | Verify that the record predates the earliest plausible compromise, selecting the restore point against the engagement reconstruction (EN-2) where one exists and against the dwell estimate (TA-2) otherwise, rather than against the most recent backup. |
| L3 | Define what happens when verification fails, including the authority to refuse return to service. |
| L3 | Retain verification results as evidence rather than as a transient check. |
| L4 | Measure the interval covered by retained integrity records against the current dwell estimate, and raise a finding where retention is shorter than plausible dwell. |
| L4 | Trend verification failure rates from exercise, since a rate of zero usually means verification is not discriminating. |
| L5 | Extend integrity record retention and granularity where dwell estimates or observed engagements show the current window is insufficient. |
| Accountable | AO |
|---|---|
| Responsible | TO |
| Outcome metric | percentage of restorations verified before return to service. |
| Performance metric | integrity record retention window against the current dwell estimate. |
| Evidence | Integrity verification results for the most recent restoration or exercise; restore point rationale; retention window record. |
| Assessment | Examine the verification method and its independence; test a restoration for verification before return to service; test whether the integrity record retention exceeds the current dwell estimate. |
| SP 800-53 Rev. 5 | CP-9(1), SI-7(1), AU-9 |
| CSF 2.0 | RC.RP-05, RC.RP-03 |
RC-5 · Reconstitution Exercise
Control. The organization shall exercise reconstitution against a stated failure scenario on a defined cadence, and every declared recovery objective shall have been demonstrated within its stated period.
Purpose. To convert declared recovery capability into demonstrated capability, so that objectives are proven before they are needed.
This is the control that makes the rest of the family real, and it is the one the framework's own analysis identifies as most often asserted rather than demonstrated. The scenario is where exercises usually fall short: an exercise that restores a single application from a clean environment demonstrates a procedure, not a reconstitution. The scenarios that test what RC-2 and RC-3 actually claim are the uncomfortable ones — loss of the identity plane, loss of the management plane, recovery under an assumption that production credentials are held by the adversary. An exercise program that has never run those has not tested the family's central dependency.
| Level | Activity |
|---|---|
| L2 | Exercise reconstitution against a stated failure scenario. |
| L2 | Record the scenario, participants, measured elapsed times and findings raised. |
| L2 | Compare measured times against declared objectives. |
| L3 | Define the exercise cadence with provenance per GA4, and flag objectives overdue for demonstration. |
| L3 | Include at least one scenario per period in which the identity plane is unavailable and production credentials are assumed adversary-held. |
| L3 | Exercise the dependency sequence across services (RC-3) rather than single services in isolation. |
| L3 | Disposition findings raised by exercise through CG-4 rather than closing them with the exercise report. |
| L4 | Measure the proportion of declared objectives demonstrated within their stated period, and treat a shortfall as a reportable condition. |
| L4 | Trend measured recovery times across exercises, since drift upward indicates decay in procedures that still pass. |
| L5 | Derive scenarios from observed adversary tradecraft and from engagements under M10, rather than repeating a scenario library that the estate has learned to pass. |
| Accountable | AO |
|---|---|
| Responsible | SOC |
| Outcome metric | percentage of declared objectives demonstrated within their stated period. |
| Performance metric | trend in measured recovery times across successive exercises. |
| Evidence | Exercise record: scenario, participants, measured recovery times, findings raised and their disposition. |
| Assessment | Examine the exercise records for cadence and scenario realism; compare measured times against declared objectives; test that findings were dispositioned; examine whether any scenario has assumed loss of the identity plane. |
| SP 800-53 Rev. 5 | CP-4, CP-4(1), IR-3 |
| CSF 2.0 | RC.RP-06, ID.IM-02 |
FO · Federal Obligations
Terrain that exists because the organization is a federal one
FO-1 · Privacy Terrain Identification
Control. Elements holding personally identifiable information shall be identified on the terrain overlay, with the authority under which the information is held recorded against each.
Purpose. To make privacy exposure positional, so that the elements holding personal information can be defended, minimized and accounted for as terrain.
Privacy terrain is the only ground in the framework where holding more of it is itself the risk. Everywhere else, an element on the overlay is an asset to be defended; here, an element holding personal information without a recorded authority is an exposure that should be removed rather than protected. The authority requirement is therefore doing double duty — it satisfies the federal obligation, and it surfaces holdings that no authority covers, which are the ones a defense should not be built around in the first place.
| Level | Activity |
|---|---|
| L2 | Mark elements holding personally identifiable information on the terrain overlay. |
| L2 | Record against each the authority under which the information is held. |
| L2 | Flag marked elements carrying no recorded authority. |
| L3 | Reconcile the marked set against the agency's privacy impact assessments and systems of records notices, in both directions — unmarked elements that appear in a notice, and marked elements that appear in none. |
| L3 | Record the categories held, so that exposure can be assessed by sensitivity rather than by presence alone. |
| L3 | Raise a finding for any holding with no covering authority, dispositioned as removal rather than as protection wherever the mission permits. |
| L3 | Include derived and incidental holdings — logs, caches, analytics stores, backups — which are the holdings least likely to appear in a notice. |
| L4 | Trend the count and weight of privacy terrain, since a defensible program should see it fall rather than grow. |
| L4 | Measure the interval between a new holding appearing and its authority being recorded. |
| L5 | Feed recurring unauthorized holdings back into system design and data retention practice, rather than remediating the same class each cycle. |
| Accountable | AO |
|---|---|
| Responsible | GOV |
| Outcome metric | percentage of privacy terrain elements with a recorded covering authority. |
| Performance metric | trend in the count and weight of privacy terrain across cycles. |
| Evidence | Terrain overlay with privacy elements marked; authority recorded per element; reconciliation record against assessments and notices. |
| Assessment | Examine the overlay against the privacy impact assessments and systems of records notices; test for elements holding such information that are unmarked, including logs, caches and backups. |
| SP 800-53 Rev. 5 | PT-2, PT-3, RA-8 |
| CSF 2.0 | GV.OC-03, ID.AM-07 |
FO-2 · Controlled Unclassified Information Handling
Control. Elements processing, storing, or transmitting controlled unclassified information shall be identified on the terrain overlay, and the boundaries across which that information may move shall be declared.
Purpose. To make CUI movement declarable and therefore detectable, so that handling obligations attach to information rather than to systems.
CUI is defined by the information, not by the system, which means it moves — into a spreadsheet, an email, a ticketing system, a contractor's environment — and each move takes the obligation with it. Marking elements is therefore only half the control; declaring permitted flows is what makes an undeclared movement a detectable event rather than an invisible one. The failure mode is a correctly marked estate with no declared flows, in which every element is compliant and the information is nonetheless everywhere.
| Level | Activity |
|---|---|
| L2 | Mark elements processing, storing or transmitting controlled unclassified information on the overlay. |
| L2 | Declare the boundaries across which that information may move. |
| L2 | Raise a finding for observed flows that were not declared. |
| L3 | Reconcile marked elements against the agency's CUI categorization record. |
| L3 | Declare flows by category where categories carry different handling requirements, rather than treating CUI as a single class. |
| L3 | Extend declaration to flows leaving the authorization boundary — to contractors, to shared services, to other agencies — since those are where handling obligations most often lapse. |
| L3 | Instrument the declared boundaries sufficiently that an undeclared flow can be observed rather than only prohibited. |
| L4 | Measure observed flows against declared flows and trend the divergence. |
| L4 | Measure the proportion of declared boundaries carrying detection, since an undeclared flow across an uninstrumented boundary is not a finding, it is an absence. |
| L5 | Revise the declared flow set from observed legitimate movement, so the declaration reflects how the mission actually works rather than how it was designed to. |
| Accountable | AO |
|---|---|
| Responsible | GOV |
| Outcome metric | percentage of observed CUI flows that were declared. |
| Performance metric | percentage of declared boundaries carrying detection. |
| Evidence | Terrain overlay with marked elements and declared flows; the flow declaration itself; divergence findings. |
| Assessment | Examine the marked elements against the categorization record; test observed flows against the declared set; test whether declared boundaries are instrumented. |
| SP 800-53 Rev. 5 | MP-4, SC-28, AC-21 |
| CSF 2.0 | PR.DS-01, GV.OC-03 |
FO-3 · Tenancy and Inheritance Boundary
Control. For every element hosted in a shared or authorized service, the overlay shall record which controls are inherited from the provider and which remain the organization's responsibility.
Purpose. To ensure that the customer half of a shared responsibility model is owned by someone, so that inherited controls do not become nobody's job.
The customer responsibility matrix is the most reliably unread document in federal cloud adoption. The provider states that a control is the customer's responsibility; the customer assumes that a FedRAMP-authorized service handles it; and the control is implemented by neither while appearing satisfied to both. That gap is invisible on any inventory and visible on this overlay, because an unassigned customer responsibility appears as an element with an inheritance claim and no owner. This control and CG-5 are the same discipline applied at different scopes — CG-5 verifies inheritance from a control baseline, FO-3 verifies it from a service provider.
| Level | Activity |
|---|---|
| L2 | Record the hosting provider for every element in a shared or authorized service. |
| L2 | Record which controls are inherited and which remain the organization's responsibility. |
| L2 | Report unassigned customer responsibilities as gaps. |
| L3 | Derive the split from the provider's authorization package and customer responsibility matrix rather than from assumption. |
| L3 | Assign an owner and an implementing maneuver to each customer responsibility, reconciled against terrain ownership (TM-7). |
| L3 | Re-verify the split when the provider changes its offering, its authorization status, or its responsibility matrix. |
| L3 | Record where a provider's authorization does not extend to the way the agency is actually using the service, since inheritance does not apply outside the authorized scope. |
| L4 | Measure the proportion of customer responsibilities carrying both an owner and an operational move, since an owned but unimplemented responsibility is a gap that reports as assigned. |
| L4 | Trend the count of unassigned responsibilities across cycles. |
| L5 | Feed recurring inheritance gaps into acquisition, so that the responsibility split is evaluated before a service is adopted rather than after. |
| Accountable | AO |
|---|---|
| Responsible | GOV |
| Outcome metric | percentage of customer responsibilities with an owner and an operational move. |
| Performance metric | currency of the inheritance record against the provider's current responsibility matrix. |
| Evidence | Inheritance record per hosted element; customer responsibility matrix reconciled to assigned maneuvers; scope exceptions recorded. |
| Assessment | Examine the inheritance record against the provider's authorization package; test that each customer responsibility has an owner and an assigned move; test whether agency usage falls within the authorized scope. |
| SP 800-53 Rev. 5 | SA-9, SC-7(21), PM-10 |
| CSF 2.0 | GV.SC-07, ID.AM-04 |
FO-4 · Operational Technology Terrain
Control. Operational technology, industrial control, and physical-effect systems shall be represented on the terrain overlay as a distinct defensive layer, with their connections to enterprise terrain declared.
Purpose. To stop operational technology being scored as though it were a server estate, and to make the connections between the two declarable.
Operational technology is ground you cannot maneuver freely on. Systems that cannot be patched or restarted on the defender's schedule remove whole classes of move from availability, and the consequence of loss is physical rather than informational. Scoring OT against enterprise expectations produces findings the agency cannot action and obscures the ones it can. The connections are where the real risk sits: engineering workstations, vendor remote access, historian replication and shared identity are the paths by which enterprise compromise becomes physical consequence, and they are routinely absent from network diagrams that show an air gap.
| Level | Activity |
|---|---|
| L2 | Classify operational technology, industrial control and physical-effect systems to the OT terrain layer. |
| L2 | Declare every connection between OT elements and enterprise zones. |
| L2 | Highlight cross-layer connections on the overlay. |
| L3 | Reconcile the OT layer against the operational inventory held by the engineering or facilities function, not against the IT asset inventory. |
| L3 | Enumerate connections exhaustively, including engineering workstations, vendor remote access, historian and data-diode paths, and shared identity — the paths most often omitted from a claimed air gap. |
| L3 | Record for each OT element which defensive moves are unavailable and why — patching windows, restart constraints, vendor certification, safety interlocks — so coverage is scored against what is achievable. |
| L3 | Record the physical consequence of loss, so weighting under TM-3 reflects consequence rather than data value. |
| L4 | Test declared connections against observed traffic, since an undeclared path into OT is the finding that matters most in this layer. |
| L4 | Measure the proportion of OT elements whose unavailable-move set has been recorded, since an unrecorded constraint reads as an unremediated gap. |
| L5 | Work with engineering and vendors to remove constraints that force moves to be unavailable, rather than accepting the constraint set as fixed. |
| Accountable | AO |
|---|---|
| Responsible | TO |
| Outcome metric | percentage of OT elements with declared connections and recorded constraints. |
| Performance metric | number of observed OT connections that were undeclared. |
| Evidence | Terrain overlay showing the OT layer and its declared connections; constraint record per element; reconciliation against the operational inventory. |
| Assessment | Examine the layer against the operational inventory; test the declared connections for completeness, including engineering workstations and remote access paths; test declared connections against observed traffic. |
| SP 800-53 Rev. 5 | PM-5, SC-7(21), SI-4(20) |
| CSF 2.0 | ID.AM-01, PR.IR-01 |
FO-5 · Statutory Availability Floor
Control. Where statute, regulation, or an authorizing instrument sets a deadline the mission must meet, the affected services shall be identified and their recovery objectives shall be set no weaker than that deadline requires.
Purpose. To identify the point at which a defensive action becomes a legal one, so that degradation decisions are bounded before they are needed.
This is the control that tells the SOC when it must not degrade. Isolation and retrograde under M8 trade availability for containment, and that trade is ordinarily the accountable authority's to make — except where a statute sets a deadline the agency must meet, at which point the trade has a legal boundary that no security judgment overrides. Recording the floors in advance is what allows that boundary to be respected at three in the morning by someone who is not a lawyer, and it is why FO-5 feeds directly into the rules of engagement under CG-3.
| Level | Activity |
|---|---|
| L2 | Identify services subject to a statutory, regulatory or instrument-set deadline. |
| L2 | Record the governing instrument and its deadline against each. |
| L2 | Raise a finding where a recovery objective is weaker than its floor. |
| L3 | Obtain legal confirmation of each floor rather than deriving it from operational understanding. |
| L3 | Set recovery objectives (RC-1) no weaker than the floor requires, accounting for the dependency chain rather than the service alone. |
| L3 | Carry the floors into the rules of engagement (CG-3) and the pre-authorized response set (TA-4), so an operator knows which degradations are unavailable. |
| L3 | Record seasonal or cyclical floors distinctly, since many federal deadlines bind only in defined periods and the constraint differs by date. |
| L4 | Test operator awareness of the floors applying during the current period. |
| L4 | Measure the interval between a change in governing instrument and its reflection in the register and the rules of engagement. |
| L5 | Use the floors to argue for resilience investment, since a statutory deadline is the one availability requirement that does not need to be justified on risk terms. |
| Accountable | AO |
|---|---|
| Responsible | GOV |
| Outcome metric | percentage of affected services whose recovery objective satisfies its statutory floor. |
| Performance metric | operator awareness of currently binding floors, tested. |
| Evidence | Statutory availability register: service, instrument, deadline, resulting recovery objective; legal confirmation records. |
| Assessment | Examine the register against the authorizing instruments; test that each affected service's recovery objective satisfies its floor; test operator awareness of currently binding floors. |
| SP 800-53 Rev. 5 | CP-2(8), SC-5, PM-11 |
| CSF 2.0 | GV.OC-04, RC.RP-01 |
FO-6 · Supply Chain Obligation
Control. The organization shall maintain a supply chain risk management program meeting its federal obligations, and shall record which acquisitions fall within its scope.
Purpose. To discharge the statutory supply chain risk obligation, and to make the boundary of its scope explicit rather than assumed.
The distinction between this control and LC-1 is the difference between an obligation and an operation. LC-1 asks who has a path into the estate and what it reaches — a terrain question, answered on the overlay. FO-6 asks whether the agency runs the program it is required to run, and to which acquisitions that program applies. Scope is where this control does its work: supply chain obligations rarely apply to every acquisition, and an agency that has never recorded the boundary cannot demonstrate either compliance inside it or a considered position outside it.
| Level | Activity |
|---|---|
| L2 | Maintain a supply chain risk management program meeting the agency's federal obligations. |
| L2 | Record which acquisitions fall within its scope. |
| L2 | Record the basis on which acquisitions are excluded. |
| L3 | Derive scope from the governing obligations rather than from acquisition value thresholds alone. |
| L3 | Integrate the program's determinations into acquisition decisions before award rather than after. |
| L3 | Reconcile in-scope acquisitions against the supplier terrain register (LC-1), so a supplier with estate access that fell outside SCRM scope is visible as a deliberate position rather than an oversight. |
| L3 | Record prohibited-source and exclusion determinations and the action taken. |
| L4 | Measure the proportion of in-scope acquisitions assessed before award. |
| L4 | Measure the gap between suppliers holding estate access (LC-1) and suppliers within SCRM scope, and treat a large gap as a finding about scope. |
| L5 | Revise scope where the reconciliation with LC-1 repeatedly shows access-holding suppliers falling outside it. |
| Accountable | AO |
|---|---|
| Responsible | GOV |
| Outcome metric | percentage of in-scope acquisitions assessed before award. |
| Performance metric | count of access-holding suppliers falling outside SCRM scope. |
| Evidence | SCRM program record with scope and recorded exclusions; pre-award assessments; reconciliation against the supplier terrain register. |
| Assessment | Examine the program against the governing obligations; test that in-scope acquisitions were assessed before award; test the reconciliation against LC-1 for access-holding suppliers outside scope. |
| SP 800-53 Rev. 5 | SR-3, SR-6, SA-9 |
| CSF 2.0 | GV.SC-01, GV.SC-04, GV.SC-06, GV.SC-09, ID.RA-09, ID.RA-10 |
FO-7 · Obligation Profile Declaration
Control. The organization shall declare which federal obligations it stands on, with the basis for each inclusion and exclusion, approved by the accountable authority; obligations outside the declared profile shall be scored out of scope rather than as gaps.
Purpose. To make the scope of the FO family an approved position, so that coverage figures are comparable and exclusions are decisions rather than silences.
This control exists because a denominator that is never written down cannot be compared or challenged. Two agencies reporting FO coverage of sixty percent may have scored against entirely different obligation sets, and neither figure means anything without the profile behind it. The exclusion basis carries more weight than the inclusion basis: including an obligation that does not apply is merely wasteful, while excluding one that does is a compliance failure concealed inside a scoping decision that nobody recorded.
| Level | Activity |
|---|---|
| L2 | Declare which federal obligations the organization stands on. |
| L2 | Record the basis for each inclusion. |
| L2 | Record the basis for each exclusion. |
| L3 | Obtain the accountable authority's approval of the profile as a whole, recorded with date, rather than obligation by obligation. |
| L3 | Obtain legal confirmation for exclusions, since an exclusion is a determination that a governing instrument does not apply. |
| L3 | Publish the profile alongside any FO coverage figure, so the denominator travels with the number. |
| L3 | Score obligations outside the profile as out of scope rather than as gaps, and ensure the posture computation under CE-4 reflects the profile denominator. |
| L4 | Review the profile on change of mission, authority or governing instrument, and measure the interval between such a change and the profile's revision. |
| L4 | Measure the proportion of exclusions carrying legal confirmation rather than operational judgment. |
| L5 | Reconcile the profile against obligations that arose in practice — an obligation encountered operationally but absent from the profile indicates the derivation method is incomplete rather than the instance exceptional. |
| Accountable | AO |
|---|---|
| Responsible | GOV |
| Outcome metric | percentage of FO obligations with a recorded, approved inclusion or exclusion basis. |
| Performance metric | currency of the profile against the most recent change of governing instrument. |
| Evidence | Approved obligation profile with inclusion and exclusion bases and approval date; legal confirmations for exclusions; published denominator. |
| Assessment | Examine the profile and its approval; test that exclusions carry legal confirmation; test that FO coverage figures are computed against the declared profile rather than the full family. |
| SP 800-53 Rev. 5 | PM-1, PM-9, PL-1 |
| CSF 2.0 | GV.OC-03, GV.OV-02 |
WF · Workforce Terrain
The people who operate the estate, held as ground
WF-1 · Workforce Terrain Identification
Control. The organization shall identify on the terrain overlay the roles whose compromise would materially advance an adversary, and record the population holding each.
Purpose. To make the workforce positional, so that defensive effort concentrates on the roles an adversary would actually target.
Identifying roles rather than individuals is what makes this terrain defensible without becoming personnel monitoring. A role is a standing property of the estate; the people in it change, and defending the role survives that change. Population size is the second half of the picture and is routinely omitted: a privileged role held by three named engineers can be defended by measures that are absurd for a role held by four hundred caseworkers, and a program that records only the role list will apply the wrong move to one or the other.
| Level | Activity |
|---|---|
| L2 | Mark on the terrain overlay the roles whose compromise would materially advance an adversary. |
| L2 | Record the population currently holding each marked role. |
| L2 | Flag privileged roles that are unmarked. |
| L3 | Define the marking criterion in terms of what an adversary gains, not in terms of seniority or job title. |
| L3 | Include roles whose access is indirect — helpdesk, delegated administration, approval authorities, and contractor roles with equivalent reach. |
| L3 | Record the accountable owner for each marked role, reconciled against terrain ownership (TM-7). |
| L3 | Justify the exclusion of privileged roles that were considered and not marked, so the boundary is a recorded judgment. |
| L4 | Trend population size per marked role; growth in a high-value role's population is an expansion of terrain that no asset inventory will report. |
| L4 | Measure the interval between a role's creation or reclassification and its appearance on the overlay. |
| L5 | Re-derive the marking criterion from roles actually targeted in engagements and in sector reporting, rather than from assumed adversary preference. |
| Accountable | AO |
|---|---|
| Responsible | TO |
| Outcome metric | percentage of privileged roles marked or explicitly excluded with justification. |
| Performance metric | trend in population size across marked high-value roles. |
| Evidence | Workforce terrain section of the Brief; role-to-population record; exclusion justifications; ownership record. |
| Assessment | Examine the marked roles against the privileged-access record; interview the accountable owner on why unmarked roles were excluded; test whether indirect-access roles were considered. |
| SP 800-53 Rev. 5 | AT-2, PS-2, PM-12 |
| CSF 2.0 | GV.RR-04, ID.AM-03 |
WF-2 · Privileged Human Register
Control. Every privileged account shall resolve to a named, currently employed, appropriately vetted individual, and the register shall be reconciled on a defined cadence.
Purpose. To ensure privilege is held by accountable people, so that every privileged action has a person behind it.
Three failure classes hide behind an apparently clean privileged account list: accounts bound to departed staff, accounts bound to nobody at all — shared, service, or legacy — and accounts bound to people whose vetting no longer covers the access they hold. The reconciliation cadence catches the first, the resolution requirement catches the second, and the vetting check catches the third, which is the one most often missed because it fails silently as access accumulates around a person who was correctly cleared for their original role.
| Level | Activity |
|---|---|
| L2 | Bind every privileged account to a named individual. |
| L2 | Raise a finding for privileged accounts that resolve to no named holder. |
| L2 | Reconcile the register against the identity provider on a defined cadence. |
| L3 | Verify that each named holder is currently employed or under current contract, reconciled against the personnel record. |
| L3 | Verify that each holder's vetting covers the access currently held, not the access held when they were vetted. |
| L3 | Record shared, service and non-human accounts distinctly, each with a named accountable human owner, rather than treating them as exceptions to the register. |
| L3 | Record and time-bound justified exceptions rather than allowing them to persist unmarked. |
| L4 | Measure accumulated privilege per holder over time, since the common failure is entitlement growth around a correctly vetted person rather than an improperly granted account. |
| L4 | Trend the count of unresolved and exception accounts, driving both toward zero. |
| L5 | Drive privilege toward just-in-time issuance where the platform supports it, so the register shrinks rather than being reconciled more often. |
| Accountable | AO |
|---|---|
| Responsible | TO |
| Outcome metric | percentage of privileged accounts resolving to a current, adequately vetted named individual. |
| Performance metric | accumulated privilege per holder, trended. |
| Evidence | Privileged human register with reconciliation dates; exception list with justification and expiry; vetting adequacy records. |
| Assessment | Examine the register against the identity provider; test a sample of privileged accounts for a current, vetted holder; test whether vetting covers the access currently held rather than the access originally granted. |
| SP 800-53 Rev. 5 | PS-3, AC-2(7), IA-2(1) |
| CSF 2.0 | PR.AA-05, GV.RR-02 |
WF-3 · Role-Based Readiness
Control. Personnel in identified workforce terrain shall receive preparation specific to how their role is actually attacked, and their readiness shall be measured rather than attested.
Purpose. To prepare people for the attacks their role attracts, and to know whether the preparation worked.
Completion is attestation; performance is measurement, and the gap between them is where most awareness programs live. A hundred percent completion rate across generic annual training tells you about administration, not about readiness. Role specificity is the other half: the attacks aimed at a finance approver, a systems administrator and a public-facing caseworker are different, and generic content prepares none of them well. The design constraint worth stating is that measurement here is of a role's readiness, and results should be used to direct preparation rather than to identify individuals for sanction — a program that punishes failure gets under-reporting, which is the opposite of what it needs.
| Level | Activity |
|---|---|
| L2 | Provide preparation to personnel in identified workforce terrain. |
| L2 | Measure readiness by test or exercise rather than by completion. |
| L2 | Record results against the role. |
| L3 | Derive content per role from current reporting on how that role is actually attacked, rather than from a generic curriculum. |
| L3 | Define the readiness threshold per role and its provenance per GA4. |
| L3 | Use results to direct further preparation at the role, and define explicitly how individual results may and may not be used. |
| L3 | Refresh content when the attack pattern against a role changes, not on an annual calendar alone. |
| L4 | Trend measured readiness per role against its threshold and escalate roles that remain below it across cycles. |
| L4 | Correlate readiness against real incidents involving those roles, since a readiness measure that does not predict incident involvement is measuring the wrong thing. |
| L5 | Redesign the role or its controls where readiness cannot be brought to threshold, on the basis that a role people cannot reliably hold is a design problem rather than a training problem. |
| Accountable | AO |
|---|---|
| Responsible | GOV |
| Outcome metric | measured readiness per marked role against its threshold. |
| Performance metric | currency of role content against current attack reporting. |
| Evidence | Exercise results by role; content mapped to the campaigns it prepares for; threshold definitions with provenance. |
| Assessment | Examine content against current threat reporting for those roles; test measured results against the stated readiness threshold; examine whether individual results are used within the stated limits. |
| SP 800-53 Rev. 5 | AT-3, AT-2(1), PS-7 |
| CSF 2.0 | PR.AT-01, PR.AT-02 |
WF-4 · Insider Risk Position
Control. The organization shall define, and be able to execute, a rights-respecting process for resolving an indication of insider risk, with a stated disposition period.
Purpose. To be able to resolve an indication proportionately and lawfully, so that the organization is neither unable to act nor acting without safeguards.
This control is written around resolving an indication, not around monitoring a population, and the distinction is the whole design. A process that begins with an indication and proceeds under defined safeguards is insider risk management; a capability that continuously scores individuals for propensity is workforce surveillance, and it corrodes exactly the cooperation that makes the rest of this family work. The rights safeguards are therefore assessed as part of the control rather than treated as an external constraint: legal and privacy review of the process, defined authority to initiate, minimum-necessary access to personal information, a disposition period that prevents indefinite open suspicion, and a route by which a closed indication leaves no residue against the person.
| Level | Activity |
|---|---|
| L2 | Define the process for resolving an indication of insider risk. |
| L2 | Name the process owner and the authority required to initiate. |
| L2 | State the disposition period within which an indication must be resolved. |
| L3 | Obtain legal and privacy review of the process before it is used, and record the review. |
| L3 | Define the minimum information the process may access at each stage, so escalation of access follows escalation of evidence rather than preceding it. |
| L3 | Define how a closed indication is recorded, including that an unsubstantiated indication leaves no adverse residue against the individual. |
| L3 | Define the route for referral to human resources, counsel or law enforcement, and the point at which the security function ceases to lead. |
| L3 | Flag open indications exceeding the disposition period. |
| L4 | Measure disposition times against the stated period, and the proportion of indications closed as unsubstantiated — a rate near zero suggests the threshold to initiate is set too high, and a rate near one that it is too low. |
| L4 | Test the process against a documented scenario rather than waiting for a real indication to discover it does not work. |
| L5 | Review closed indications for the conditions that produced them and address those conditions, since most substantiated insider events have precursors that were organizational rather than individual. |
| Accountable | AO |
|---|---|
| Responsible | GOV |
| Outcome metric | percentage of indications dispositioned within the stated period. |
| Performance metric | proportion of indications closed as unsubstantiated, trended. |
| Evidence | Documented process with legal and privacy review; disposition record for closed indications; scenario test record. |
| Assessment | Examine the process for rights safeguards and approval; test that closed indications met the stated period; test whether access escalation followed evidence escalation; examine whether unsubstantiated closures left residue. |
| SP 800-53 Rev. 5 | PM-12, AU-6(9), PS-8 |
| CSF 2.0 | DE.CM-03, GV.RR-04 |
WF-5 · Separation and Revocation Tempo
Control. All access held by a departing or suspended individual shall be removable in a single action, within a period measured against the tempo at which that access could be misused.
Purpose. To close the window between a person ceasing to be trusted and their access ceasing to work.
Two properties are being required, and they fail independently. Single action fails when access exists outside the primary identity provider — local accounts, SaaS applications provisioned outside single sign-on, VPN credentials, API keys, shared secrets — each of which survives a correctly executed identity-provider disablement. Within tempo fails when the process is complete but slow: a revocation that takes four days is not a control against access that could be misused in twenty minutes. The tempo comparison is what connects this control to the TA family, and the period should be derived from what the access could do rather than from what the offboarding process currently achieves.
| Level | Activity |
|---|---|
| L2 | Define the revocation process for departing and suspended individuals. |
| L2 | Measure the elapsed time from trigger to complete revocation. |
| L2 | Raise a finding where measured time exceeds the stated period. |
| L3 | Derive the required period from the tempo at which the access could be misused, not from current process capability, with provenance per GA4. |
| L3 | Enumerate every access location outside the primary identity provider and bring each into the single revocation action or record it as an exception. |
| L3 | Distinguish planned departure, immediate separation and suspension, since the tempo requirement differs sharply between them. |
| L3 | Verify revocation by testing the access rather than by confirming the ticket closed. |
| L4 | Trend measured revocation time by separation type against its required period. |
| L4 | Measure surviving access found by post-revocation testing, which is the direct measure of the single-action property. |
| L5 | Reduce the number of access locations outside the primary identity provider, since consolidation improves this control more durably than accelerating the process that compensates for fragmentation. |
| Accountable | AO |
|---|---|
| Responsible | TO |
| Outcome metric | measured revocation time by separation type against required period. |
| Performance metric | surviving access found by post-revocation testing. |
| Evidence | Measured revocation times from exercise or real separations; exception register; post-revocation verification results. |
| Assessment | Test a revocation end to end against the stated tempo; examine for access surviving in systems outside the primary identity provider; test whether verification tests access or only confirms process completion. |
| SP 800-53 Rev. 5 | PS-4, PS-5, AC-2(3) |
| CSF 2.0 | PR.AA-01, GV.RR-02 |
FC · Facilities Terrain
Buildings, zones, and the maintenance paths reaching through them
FC-1 · Facility Terrain Identification
Control. Facilities housing mission systems, data, or personnel in identified workforce terrain shall be represented on the terrain overlay, with the elements each contains recorded.
Purpose. To resolve the estate to physical locations, so that defense, recovery and continuity can be reasoned about in the place things actually are.
The test that makes this control concrete is whether every designated decisive point resolves to a named facility. An agency that cannot say which building its identity provider's hardware sits in cannot defend it physically, cannot plan its rebuild under RC-3, and cannot assess whether the environmental sustain period of that building satisfies the recovery objective of everything depending on it. Cloud-hosted elements resolve to a provider region rather than an agency facility, and recording that distinction is part of the control rather than an exemption from it.
| Level | Activity |
|---|---|
| L2 | Represent on the terrain overlay every facility housing mission systems, data, or personnel in identified workforce terrain. |
| L2 | Record the elements each facility contains. |
| L2 | Flag mission elements whose facility is unrecorded. |
| L3 | Reconcile the facility set against the agency's real property and lease record, including leased, shared and co-located space. |
| L3 | Resolve every designated decisive point (KT-1) to a named facility or to a recorded provider region, and raise a finding where neither is possible. |
| L3 | Record facilities housing operational technology and building management systems (FO-4), since those are simultaneously facility and OT terrain. |
| L3 | Record the accountable owner for each facility, who is frequently outside the security function and must still be reconciled against TM-7. |
| L4 | Measure the proportion of decisive points resolving to a named location, and trend it. |
| L4 | Test the recorded contents of a sample of facilities against physical verification rather than against the asset record alone. |
| L5 | Feed concentration findings into siting decisions — a facility holding a disproportionate share of decisive points is a single point of failure that the overlay makes visible and that procurement can address. |
| Accountable | AO |
|---|---|
| Responsible | TO |
| Outcome metric | percentage of decisive points resolving to a named facility or recorded provider region. |
| Performance metric | physical verification pass rate on sampled facility contents. |
| Evidence | Terrain overlay showing facilities and their contents; real property reconciliation; decisive-point location resolution record. |
| Assessment | Examine the overlay against the real property record; test that decisive points resolve to a named facility; verify a sample of recorded contents physically. |
| SP 800-53 Rev. 5 | PE-2, PE-3, PM-8 |
| CSF 2.0 | ID.AM-01, PR.IR-02 |
FC-2 · Physical Zone Boundary
Control. Facilities shall be divided into zones whose boundaries are enforced and logged, and the zone containing each decisive point shall be identified.
Purpose. To establish physical boundaries that constrain movement and produce a record of crossing, so that physical terrain can be defended in depth rather than at a perimeter.
These are physical zones and they are not the logical trust zones of TM-4; conflating the two produces an overlay that claims segmentation it does not have in either dimension. The word doing the work here is enforced, and its physical failure mode is specific: a boundary that opens for an authorized badge and admits whoever follows has controlled a door without attributing an entry. Enforcement in this control means individual attribution at the crossing, because a log that records which badge opened a door — rather than who passed through it — cannot answer the question an investigation will ask.
| Level | Activity |
|---|---|
| L2 | Divide each facility into zones and declare their boundaries. |
| L2 | Identify the zone containing each decisive point. |
| L2 | Log crossings at each declared boundary. |
| L3 | Define each zone by the access assumption that holds inside it, and state what entitles a person to be there. |
| L3 | Identify the mechanism enforcing each boundary and its owner, distinguishing boundaries enforced by construction, by mechanism, and by convention. |
| L3 | Address unattributed entry — tailgating and piggybacking — at boundaries protecting decisive points, so a crossing resolves to a person rather than to a credential. |
| L3 | Make crossing logs reviewable and retained for a period matched to the dwell estimate (TA-2), since an investigation reaching back further than retention finds nothing. |
| L4 | Test a sample of boundaries by attempted traversal rather than by inspecting the access control configuration. |
| L4 | Trend the count of convention-enforced boundaries protecting decisive points, driving it to zero. |
| L5 | Re-zone where repeated exception grants show a boundary drawn across normal work, since a boundary routinely bypassed with permission is not a boundary. |
| Accountable | AO |
|---|---|
| Responsible | TO |
| Outcome metric | percentage of decisive points inside a boundary with enforced, attributed crossing. |
| Performance metric | traversal test pass rate on sampled boundaries. |
| Evidence | Zone declaration with enforcement mechanism; access logs per boundary; traversal test records; retention configuration. |
| Assessment | Examine zone boundaries and their enforcement; test that crossings are logged, attributed and reviewable; test a boundary by attempted traversal; compare log retention against the current dwell estimate. |
| SP 800-53 Rev. 5 | PE-3(1), PE-5, SC-7 |
| CSF 2.0 | PR.AA-06, PR.IR-02, DE.CM-02 |
FC-3 · Maintenance Access Control
Control. Vendor and remote maintenance shall occur only within an approved, time-boxed, supervised window, and no maintenance path shall exist outside one.
Purpose. To ensure the maintenance path — authorized, expected, and outside the normal identity plane — is bounded in time and observed while open.
Maintenance access is the path that bypasses everything else precisely because it is legitimate. It is often granted outside the agency's own identity plane, frequently at a level of privilege the vendor specifies rather than the agency scopes, and it is renewed indefinitely because removing it risks a support contract. The requirement that no path exist outside a window is the whole control; a maintenance account that is disabled between windows and a maintenance account that merely goes unused between windows look identical in a register and behave completely differently under compromise.
| Level | Activity |
|---|---|
| L2 | Record every vendor and remote maintenance path into the estate. |
| L2 | Approve each maintenance occurrence in advance, time-boxed to a defined window. |
| L2 | Raise a finding for any standing maintenance path. |
| L3 | Verify that maintenance access is technically absent outside its window, not merely unused, and record the mechanism achieving that. |
| L3 | Supervise maintenance sessions with a named agency observer for access touching decisive points, and record the supervision. |
| L3 | Scope each window to the elements the maintenance requires rather than to the privilege level the vendor requests. |
| L3 | Log maintenance session activity to the agency's own record, not only to the vendor's, so the account survives the relationship. |
| L4 | Test that a maintenance path is unavailable outside its window, rather than inspecting the configuration that should make it so. |
| L4 | Measure the proportion of maintenance sessions with complete agency-side activity records. |
| L5 | Negotiate maintenance access terms into contract renewal, so the constraint is a procurement condition rather than a recurring exception fought at each occurrence. |
| Accountable | AO |
|---|---|
| Responsible | TO |
| Outcome metric | number of standing maintenance paths, target zero. |
| Performance metric | percentage of maintenance sessions with agency-side activity records. |
| Evidence | Maintenance window record with approver and supervision evidence; agency-side session logs; path inventory. |
| Assessment | Examine the maintenance path inventory for standing access; test that a path is unavailable outside its window; test whether session activity is recorded to the agency's own systems. |
| SP 800-53 Rev. 5 | MA-4, MA-5, MA-3 |
| CSF 2.0 | PR.AA-05, PR.PS-03 |
FC-4 · Environmental Continuity
Control. For each facility carrying a mission service, the environmental conditions the service depends on shall be identified, and the period the facility can sustain the service without them shall be stated.
Purpose. To know how long the physical ground holds without support, so that recovery objectives are not contradicted by the buildings the services sit in.
This control's value is almost entirely in a comparison that two separate documents make impossible: the environmental sustain period of a facility against the recovery time objectives of the services housed in it. A four-hour uninterruptible supply under a twenty-four-hour recovery objective is a contradiction that is obvious once the two figures are placed side by side and invisible while they live in a facilities record and a continuity plan respectively. Putting facilities on the overlay is what makes the comparison routine.
| Level | Activity |
|---|---|
| L2 | Identify the environmental conditions each mission-carrying facility depends on — power, cooling, water, connectivity, physical access. |
| L2 | State the period the facility can sustain the service without each. |
| L2 | Record both against the facility on the overlay. |
| L3 | Test the stated sustain periods rather than taking them from design specification or vendor rating. |
| L3 | Compare each sustain period against the recovery objectives (RC-1) of the services housed there, and raise a finding on every contradiction. |
| L3 | Include dependencies on external providers and on other facilities, since a sustain period assuming resupply is contingent on the resupply arriving. |
| L3 | Record the degradation sequence — which services lose availability first as a condition is lost — so the loss is a plan rather than a discovery. |
| L4 | Trend tested sustain periods, since capacity degrades with equipment age while the recorded figure does not. |
| L4 | Measure the interval since each sustain period was last tested rather than last recorded. |
| L5 | Feed persistent contradictions between sustain period and recovery objective into siting, investment or objective revision, rather than carrying the finding indefinitely. |
| Accountable | AO |
|---|---|
| Responsible | TO |
| Outcome metric | percentage of mission-carrying facilities whose tested sustain period satisfies the recovery objectives of services housed there. |
| Performance metric | median age of the most recent sustain period test. |
| Evidence | Environmental dependency record; ride-through test results; comparison against recovery objectives; degradation sequence. |
| Assessment | Examine the stated periods against test evidence; compare against the recovery objectives of the services housed there; test whether periods derive from measurement or from design specification. |
| SP 800-53 Rev. 5 | PE-11, PE-13, CP-2 |
| CSF 2.0 | PR.IR-04, RC.RP-01 |
LC · Lines of Communication
Suppliers, components, and the routes they reach the estate on
LC-1 · Supplier Terrain Register
Control. Suppliers, integrators and managed-service providers with a path into the estate shall be registered on the terrain overlay, with the access each holds and the elements it reaches recorded.
Purpose. To make third parties positional, so that supplier risk is assessed against what a supplier can reach rather than against what they were contracted to do.
Procurement already holds a vendor list; this is not that. The distinguishing requirement is the elements it reaches — a supplier with a narrow contract and broad technical access is the case this control exists to surface, and it is invisible on any acquisition record because the contract describes intent while the entitlement describes capability. Reconciling the register against provisioned access rather than against contracts is therefore the control's operative activity, and it routinely finds access that outlived the engagement that justified it.
| Level | Activity |
|---|---|
| L2 | Register every supplier, integrator and managed-service provider holding a path into the estate as an external actor on the overlay. |
| L2 | Record the access each holds and the elements that access reaches. |
| L2 | Raise a finding for suppliers holding unrecorded access. |
| L3 | Reconcile the register against provisioned access in the identity and network estate, not against the acquisition record, since contracts describe intent and entitlements describe capability. |
| L3 | Record reach transitively where a supplier's access permits movement beyond the element it terminates on. |
| L3 | Raise a finding for any supplier holding standing access to a decisive point (KT-1), and route it to LC-3 for constraint. |
| L3 | Reconcile against the SCRM scope under FO-6, so an access-holding supplier outside that scope is a recorded position rather than an oversight. |
| L4 | Trend the count of suppliers and the aggregate weight of elements they reach, since supplier reach expands quietly through renewals and scope changes. |
| L4 | Measure the interval between engagement end and access removal, which is the window in which reach exists with no contract behind it. |
| L5 | Feed reach findings into acquisition, so access scope is specified before award rather than discovered at the next reconciliation. |
| Accountable | AO |
|---|---|
| Responsible | TO |
| Outcome metric | percentage of suppliers whose recorded reach matches provisioned access. |
| Performance metric | median interval between engagement end and access removal. |
| Evidence | Supplier terrain register reconciled to provisioned access; standing-access findings; FO-6 scope reconciliation. |
| Assessment | Examine the register against contracts and against provisioned access; test for suppliers holding access not in the register; test whether reach was recorded transitively. |
| SP 800-53 Rev. 5 | SR-2, SA-9, PM-30 |
| CSF 2.0 | GV.SC-04, ID.AM-04 |
LC-2 · Component Provenance
Control. Software and hardware components deployed into the estate shall resolve to a verified origin, and the organization shall maintain a current inventory of what those components contain.
Purpose. To know where deployed components came from and what is inside them, so that a compromise disclosed anywhere can be located here.
Provenance and contents are two different questions and both are required. Provenance answers where a component came from; the inventory answers what it carries. A correctly signed package containing a vulnerable transitive dependency has verified provenance and unknown content, and an agency holding only the first cannot answer the question that actually arrives — are we running this? — when a component compromise is disclosed. The practical measure of this control is time to answer that question across the whole estate, which is why that is its outcome metric rather than inventory completeness.
| Level | Activity |
|---|---|
| L2 | Record the origin of each deployed software and hardware component. |
| L2 | Verify signatures or equivalent origin evidence before deployment. |
| L2 | Maintain an inventory of what each deployed component contains. |
| L3 | Extend the inventory to transitive dependencies rather than to direct components alone, since disclosure typically names a dependency. |
| L3 | Raise a finding for artifacts whose origin cannot be verified, and define whether deployment may proceed and under whose authority. |
| L3 | Keep the inventory current at deployment rather than reconstructing it on demand, since reconstruction under disclosure pressure is slow and incomplete. |
| L3 | Extend provenance to firmware and hardware components, where verification is hardest and substitution is least visible. |
| L4 | Measure time to answer "are we running this component, and where" across the estate, and treat that interval as the control's real capability. |
| L4 | Measure inventory coverage against the deployed estate, distinguishing components inventoried from components merely recorded. |
| L5 | Automate inventory generation into the deployment pipeline, so currency is a property of deploying rather than a periodic exercise. |
| Accountable | AO |
|---|---|
| Responsible | TO |
| Outcome metric | time to answer whether a named component is deployed and where. |
| Performance metric | percentage of deployed artifacts with verified provenance and a current component inventory. |
| Evidence | Component inventory per artifact; signature and origin verification results; unverifiable-artifact findings with authorization. |
| Assessment | Examine the inventory for currency and completeness; test verification on a sample of deployed artifacts; test the estate-wide search by naming a component and timing the answer. |
| SP 800-53 Rev. 5 | SR-4, SR-11, SA-10 |
| CSF 2.0 | GV.SC-08, ID.RA-09 |
LC-3 · Supplier Access Constraint
Control. Supplier access shall be brokered through the organization's own identity plane and constrained to the elements the engagement requires, with no standing access to a decisive point.
Purpose. To keep supplier access scoped, observable, and revocable by the agency rather than by the supplier.
Brokering is the requirement that carries the rest. Where a supplier holds credentials the supplier issued, the agency can request removal but cannot perform it — which means LC-5's severance capability does not exist regardless of what the contract says. Routing access through the agency's own identity plane converts severance from a negotiation into an action. The scoping requirement addresses the second failure: supplier access is habitually provisioned at the privilege level the supplier requests, which reflects their convenience across all customers rather than this engagement's need.
| Level | Activity |
|---|---|
| L2 | Route supplier access through the organization's own identity plane. |
| L2 | Scope each supplier's access to the elements the engagement requires. |
| L2 | Raise a finding for standing access to any designated decisive point. |
| L3 | Record for each supplier access grant its broker, scope and expiry, and set an expiry in every case rather than only where one is obvious. |
| L3 | Verify that revocation is technically within the agency's control, not dependent on supplier action. |
| L3 | Apply the constraint to supplier-managed infrastructure and vendor-operated services, where the identity plane is most often the supplier's by default. |
| L3 | Re-scope on engagement change rather than allowing scope to accumulate across successive contracts. |
| L4 | Measure provisioned supplier access against engagement scope and trend the divergence. |
| L4 | Measure the proportion of supplier access grants that are agency-revocable without supplier cooperation. |
| L5 | Move brokering requirements into contract terms at renewal, so the constraint is a condition of engagement rather than an exception negotiated per grant. |
| Accountable | AO |
|---|---|
| Responsible | TO |
| Outcome metric | percentage of supplier access grants brokered, scoped and agency-revocable. |
| Performance metric | divergence between provisioned access and engagement scope. |
| Evidence | Supplier access records showing broker, scope and expiry; revocability verification results. |
| Assessment | Examine provisioned supplier access against the engagement scope; test that revocation is within the agency's control; test whether supplier-managed infrastructure is brokered or exempted. |
| SP 800-53 Rev. 5 | SR-5, AC-20, SA-9(2) |
| CSF 2.0 | GV.SC-07, PR.AA-05, DE.CM-06 |
LC-4 · Update Integrity and Staging
Control. Supplier-provided updates shall be integrity-verified before deployment and shall pass through a staging ring for a stated period before reaching the whole estate.
Purpose. To limit the blast radius of a compromised trusted update, so that supply chain compromise reaches a ring rather than the estate.
The soak period is the control, and its length is the part most often chosen arbitrarily. A staging ring protects only if the soak exceeds the time the organization needs to notice something wrong — so the period should be derived from the measured detection segment of the decision loop under TA-1, not from a release calendar. An estate with a ten-day detect segment and a twenty-four-hour soak has implemented staging and gained almost nothing from it, and that mismatch is invisible unless the two figures are compared deliberately.
| Level | Activity |
|---|---|
| L2 | Integrity-verify supplier-provided updates before deployment. |
| L2 | Pass updates through a staging ring before general release. |
| L2 | Record the staging ring composition and the soak period applied. |
| L3 | Derive the soak period from the measured detection segment under TA-1, with provenance per GA4, rather than from a release calendar. |
| L3 | Compose the staging ring to be representative of the estate rather than of the systems most tolerant of disruption, since an unrepresentative ring detects nothing about the systems that matter. |
| L3 | Define and record the emergency bypass path, its authority and its compensating measures, since bypass will occur and an undefined bypass is unbounded. |
| L3 | Instrument the ring for behavioral change, not only for functional failure — a compromised update usually works correctly. |
| L4 | Measure the proportion of updates traversing the ring against those bypassing it, and trend bypass rate. |
| L4 | Compare the applied soak period against the current detection segment each cycle, and raise a finding where soak is shorter. |
| L5 | Shorten the required soak by improving detection rather than by accepting more risk, since the two are the same trade viewed from opposite ends. |
| Accountable | AO |
|---|---|
| Responsible | TO |
| Outcome metric | percentage of updates traversing the staging ring for the full soak period. |
| Performance metric | applied soak period against the current measured detection segment. |
| Evidence | Staging records with soak periods; integrity verification results per update; bypass records with authority and compensating measures. |
| Assessment | Examine the declared soak period and its rationale against the measured detection segment; test that a sample of updates traversed the ring; examine the bypass rate and its authorizations. |
| SP 800-53 Rev. 5 | SI-2, SR-11(1), CM-3 |
| CSF 2.0 | ID.RA-01, PR.PS-02 |
LC-5 · Supplier Severance Capability
Control. The organization shall be able to sever a supplier's access within a stated period and continue the mission, and shall have demonstrated it.
Purpose. To retain the option of cutting a line of communication, so that a compromised or failed supplier is a decision rather than a dependency.
Two halves, and the second is the one usually missing. Severing access is an identity and network action that LC-3's brokering makes achievable. Continuing the mission afterwards is an operational question that nobody answers until it is urgent — and for a managed-service provider or a sole-source integrator, the honest answer may be that the mission cannot continue, which is itself a finding worth having in advance rather than during. Severance without continuity is not a defensive option; it is an outage the agency chose.
| Level | Activity |
|---|---|
| L2 | Define the procedure for severing each supplier's access. |
| L2 | State the period within which severance must be achievable. |
| L2 | Record the authority required to initiate severance. |
| L3 | Assess mission continuity following severance for each supplier, and record where the mission cannot continue as a finding rather than as an accepted state. |
| L3 | Derive the required period from what the supplier's access could do if turned hostile, with provenance per GA4, rather than from contractual notice terms. |
| L3 | Demonstrate severance for suppliers whose reach includes a decisive point, rather than for the easiest supplier to test. |
| L3 | Distinguish severance from termination, since access must be removable without ending the commercial relationship. |
| L4 | Measure demonstrated severance time against the stated period and trend it. |
| L4 | Measure the proportion of decisive-point-reaching suppliers whose severance has been demonstrated at all. |
| L5 | Reduce single-supplier dependency where continuity assessment shows the mission cannot survive severance, since that is a resilience problem that no access control resolves. |
| Accountable | AO |
|---|---|
| Responsible | TO |
| Outcome metric | percentage of decisive-point-reaching suppliers with demonstrated severance within the stated period. |
| Performance metric | demonstrated severance time against stated period, trended. |
| Evidence | Severance exercise record: supplier, elapsed time, mission impact observed; continuity assessment per supplier; findings where continuity fails. |
| Assessment | Examine the procedure and its authorization; test severance for one supplier against the stated period; examine whether any decisive-point-reaching supplier has been tested; examine continuity findings. |
| SP 800-53 Rev. 5 | SR-8, IR-4, CP-2(7) |
| CSF 2.0 | GV.SC-10, RS.MA-01 |