DESIGN

Design and Philosophy

Why the framework is shaped the way it is, and the criteria every entry must meet to be admitted — the document to read before extending it.

ASOM-Fed v6.1 · Unclassified / Illustrative · agency-agnostic reference framework · built from public sources only

Version 6.1 · Unclassified · built from public doctrine and public sources only

Why the framework is shaped the way it is — the object model, the level of abstraction it deliberately occupies, the criteria every form of maneuver, technique and control must meet to be admitted, and where it sits among the frameworks a federal agency already runs.

What this document is. The design rationale, not the framework. It does not enumerate the catalog — the Defensive Maneuver Matrix and the Application and Control Guide do that. It explains the object model, the abstraction level and the admission criteria, so an adopter can extend ASOM-Fed correctly and a reviewer can argue with it precisely. Its structure follows the convention MITRE established for ATT&CK: Design and Philosophy, because a framework that asks to be adopted owes its adopters an account of how it was built.


1. Introduction

Federal network defense is still largely run as garrison security: a boundary, a control catalog, an assessment calendar, and a queue of alerts worked in the order they arrive. The posture is static by construction — its unit of planning is the control, and controls do not move.

The adversaries that matter do not operate that way. Nation-state collectors, fraud rings working public service portals, and ransomware crews exploiting deadline-sensitive availability all behave like a maneuvering force: they seek positional advantage, mass at a decisive point, and win by operating inside the defender's decision cycle. A defense whose only vocabulary is the control cannot describe what is happening to it, let alone respond in kind.

ASOM-Fed supplies the missing vocabulary. It reframes defense as a maneuver problem led by intelligence analysis, in a form that is assessable, machine-readable, and mappable onto the compliance obligations an agency already carries.

1.1 What the framework measures, and what it measured

A framework that cannot be wrong is not worth adopting. ASOM-Fed is falsifiable in several directions, and every one of them has now returned uncomfortable answers about the framework itself.

Against the control baseline. Every ASOM-Fed control cites the SP 800-53 Rev. 5 controls it inherits from, which makes the families it never cites a direct measure of the federal estate it fails to reach. That test has driven two structural releases. Version 2.0 inherited from sixteen of the twenty families and never once from AT, IA, MA or PE, which said plainly that the framework modeled the machines of a federal estate and not the people who operate it, the buildings it sits in, or the suppliers who reach into it; version 3.0 added those as terrain. Version 4.0's crosswalk then showed IA cited exactly once across sixty controls — incidentally, through a workforce control about privileged account holders — on the terrain the framework calls the high ground. Version 6.1 added the Identity Terrain family in answer.

Against real architectures. Ten agency archetypes are scored on every release. Coverage is measured as ground held rather than techniques touched: the framework is 77 terrain × form cells, and a node tagged with one form evidences every technique in its cell at once. Counting techniques therefore rewards tagging a crowded cell over a sparse one for identical effort, and lets a design be driven toward 100% without doing anything more. Cells are the unit the model can defend.

Against the outcome catalogs, in reverse. Version 6.1 introduced a discipline the earlier releases lacked: checking not only that every ASOM-Fed control carries mappings, but that every referenced outcome has a control pointing at it. That test found Respond at two of thirteen CSF 2.0 outcomes, three CSF categories at zero, and the D3FEND Deceive tactic at zero controls — despite M5 Ambush carrying thirteen techniques and being the dominant effort of an entire campaign phase. An agency could operate a complete deception grid or none at all and score identically. The EN family and SM-7 are the answer.

Against its own artifacts. Version 6.1 also checked whether the framework's published documents agreed with each other. They did not. The doctrine document stated sixty controls across eleven families in prose and showed thirty-five across six in the table immediately below it; the terrain table listed five of its nine layers; two controls cited retired CSF 1.1 identifiers in a CSF 2.0 mapping; one control duplicated another; and the connector shipped thirteen controls that no technique cited. None of this was visible from reading any single artifact.

MeasureResultWhat it says
Ground held, best to worst estate7–44%Even the strongest reference estate operates on well under half the board.
Estates missing a whole form of maneuver6 of 10A capability gap, not a procurement gap — no product closes it.
Estates that can perform M10 Exploitation & Pursuit4 of 10The rest cannot convert contact into durable advantage, and fight the same intrusion twice.
Cells no estate occupies31 of 75Whole forms of maneuver unavailable on whole layers of terrain.
CSF 2.0 Respond outcomes covered (pre-v5.0)2 of 13A framework whose signature metric is detect → decide → contain barely specified the fight.
D3FEND tactics reached (pre-v5.0)6 of 7Deception, the cheapest high-confidence detection available, was unassessed.

These measurements have repeatedly condemned the framework rather than the agencies. Version 1.0 was scored the same way and produced a finding about itself: no archetype could evidence M10, forty-two of 111 techniques were evidenced by none of them, and the 35 controls reached five of six CSF 2.0 Functions with Recover empty. Version 3.0 declared three new terrain layers that, on first measurement, no reference estate stood on at all. Version 6.1 found that the framework specified how to prepare for a fight in considerable detail and barely specified the fight. Each was a defect in the framework, found by running it rather than by reading it, and each is recorded in §7 rather than quietly corrected.

An adopter should weigh how a framework handles being wrong at least as heavily as what it claims when it is right.

1.2 Background and history

ASOM-Fed fuses two mature bodies of U.S. Army doctrine that are rarely combined, and grounds them on the federal zero-trust terrain defined by civilian policy:

The single most consequential idea taken from Allen is that categories of maneuver are durable while the techniques that realize them are perishable. Leaders can therefore direct a defense in terms of intent without being engineers, and engineers can re-tool without invalidating the plan. Everything about the framework's shape follows from taking that distinction seriously — and it is, not coincidentally, the same separation ATT&CK draws between a tactic and a technique.


2. Use cases

ASOM-Fed is built to be used in seven ways. Each is a real workflow, not an aspiration.

1 · Cyber Preparation of the Environment. Map the estate as terrain — key terrain, avenues of approach, mobility corridors, decisive points — and build most-likely and most-dangerous threat courses of action against it. Arraying the matrix against two courses of action makes the difference between them the planning problem, and the cells demanded by both are where a single investment answers two threats.

2 · Defensive campaign planning. Choose a sequence of forms with one designated main effort, phase it, and pre-authorize which responses the SOC may execute without escalation. This turns 24/7 monitoring into a campaign with a stated objective per phase.

3 · Gap analysis that names the right gap. Score coverage cell by cell. A whole column that comes up empty is not a missing product — it is a form of maneuver the agency cannot perform. That finding survives contact with a budget conversation in a way an open POA&M item does not.

4 · Assessment and red teaming. Every technique carries a success indicator, so the matrix doubles as a test plan: give a red team a form of maneuver to defeat, and the cell's indicator is the pass/fail condition. This is why the indicator field is mandatory.

5 · Governance and audit evidence. Every technique cites ASOM-Fed controls, each of which inherits from SP 800-53 Rev. 5 and maps to CSF 2.0. An agency that maneuvers well produces its FISMA evidence as a by-product. Compliance is exhaust, not the objective.

6 · Capability planning and procurement. Because forms are intent-first and technology-neutral, a requirement can be written as "we must be able to perform M5 Ambush across the data layer" rather than as a product category. The requirement outlives the vendor.

7 · Degraded-posture planning. New in v5.0. Determine what still defends the estate when staffing is thinnest — nights, holidays, handovers, hiring gaps, contract transitions — and compare it against the windows adversaries actually select. See §3.8.


3. The ASOM-Fed model

3.1 The maneuver matrix

The matrix is the framework's primary presentation. Its columns are the eleven forms of defensive maneuver; the cells beneath each column are the techniques that give that form effect. Reading down a column tells you how a form is actually performed; reading across the top tells you what a defense is capable of at all.

The layout convention is borrowed openly from the ATT&CK Enterprise matrix, for a reason that is structural rather than aesthetic: both models separate a small set of durable, intent-level categories from a large, churning set of concrete behaviors. Where the two differ is in whose behavior is cataloged — ATT&CK describes what an adversary does to you, ASOM-Fed describes how you array against it.

3.2 Terrain layers

ASOM-Fed models the enterprise as nine terrain layers plus one cross-cutting domain. Five of the nine are the CISA ZTMM v2.0 pillars, taken unchanged and renamed as terrain because terrain is what a scheme of maneuver is drawn on. The other four — operational technology, workforce, facilities and supply chain — are ASOM-Fed's own, and each was added because a measurable part of a federal estate had no ground to stand on without it. Each carries a metaphor that is load-bearing, not decorative: it tells a planner what kind of ground they are defending.

IDDomainTerrain character and what it implies
T1IdentityHigh ground. Whoever holds it controls movement everywhere else. Contested first, and the reason M3 Envelopment carries the largest single risk weighting.
T2DevicesEntry fords. Where forces cross into the estate. Few crossings, heavily used, worth watching.
T3NetworksCorridors. Routes of movement. The only layer where you can meaningfully canalize an adversary onto ground you own.
T4Applications and WorkloadsUrban terrain. Dense, complex, close-quarters — the hardest ground to defend and the easiest to lose track of.
T5DataThe objective. The reason the campaign exists. Everything else is defended because it leads here.
T6Operational TechnologyContested ground. Systems that often cannot be patched or restarted on the defender's schedule, where loss has a physical consequence. Added v2.0; not a ZTMM pillar.
T7WorkforceThe operating workforce. The people who operate the estate can be reconnoitred, targeted, turned and lost. Added v3.0; the only terrain that is simultaneously the operating workforce.
T8FacilitiesThe ground you stand on. Buildings, zones, badge systems, and the vendor maintenance paths that reach through them. The oldest terrain there is, and the one most often left off a cyber overlay. Added v3.0.
T9Supply ChainLines of communication. The routes by which the estate is resupplied, and therefore the routes by which it is reached. Doctrinally the rear area; in federal practice, frequently the actual intrusion path. Added v3.0.
TXCross-CuttingEnablers. Visibility is reconnaissance, automation is mobility, governance is command authority. Not ground, but what lets you move on it.

Where this departs from CISA, and why it matters. The five pillars are ZTMM's, verbatim. TX and T6T9 are not. ZTMM defines three cross-cutting capabilities (Visibility and Analytics, Automation and Orchestration, Governance) and ASOM-Fed consolidates them into one terrain layer, because as terrain they are not ground an adversary moves across; they are what lets you move. That is a deliberate simplification and it is lossy: an agency reporting ZTMM maturity per cross-cutting capability cannot map those three onto TX one-to-one, and should report them separately. The tower IDs and every terrain metaphor above are ASOM-Fed's own; CISA neither numbers its pillars nor describes them as terrain.

Why these IDs and not the pillar names. T1T9/TX are the Defense Tower Model's tower IDs, already used by the Studio canvas, the Asset Register and the posture model. Reusing them means a canvas node, a control, a register row and a matrix cell share one key, so linking them is a lookup rather than a translation table — and a translation table is exactly the thing that silently rots.

The finding this layer used to carry, now closed. Every terrain layer ASOM-Fed added has dedicated controls: T6 has FO-4, T7 has the WF family, T8 has FC, T9 has LC. Of the five inherited ZTMM pillars, T1 has had one since v5.0. T2 Devices held no dedicated control at all through v5.0, recorded then as a v6.1 input rather than resolved in v5.0, because a third denominator change in one release would have made every trend line unreadable. v6.1 is that input: the DV (Devices Terrain) family closes the gap, by the same completeness test that produced T7 and the ID family.

3.3 Forms of maneuver

The eleven forms are the framework's durable layer. They are defensive recastings of classical forms of maneuver, chosen to be exhaustive at their level of abstraction: any defensive action an agency takes should be recognizable as an instance of one of them.

FieldTypeMeaning
idstringM1M11. Stable for the life of the framework; never reused.
namestringThe doctrinal name, e.g. Envelopment, Ambush, Spoiling Attack.
intentstringOne clause stating what the form is for. This is what the CISO or Authorizing Official issues; it must be comprehensible without technical knowledge.
towerenumThe terrain layer the form is principally concerned with. Advisory — techniques within a form may sit on other layers.
riskReductionintegerResidual-risk reduction attributed to the form when fully operational, used by the Tower Model's allocation arithmetic.
postureenumNew in v5.0. Passive, active or reactive — see §3.8.

Open defect. The eleven riskReduction weights sum to 117, not 100. The distribution summed to 100 across ten forms before M11 was added in v2.0 at weight 8, and nothing rebalanced it. The Studio's verify() multiplies each weight by that form's coverage percentage, so a design evidencing everything reports 117% residual risk reduction. Rebalancing changes every historical posture score — a denominator change requiring a major version and a visible break in the trend line. It is recorded here rather than silently normalized.

3.4 Techniques

Techniques are the perishable layer: the concrete, observable things an agency does to make a form real on specific ground. There are 154, up from 125 in v2.0 and 111 in v1.0.

FieldTypeMeaning
idstringM<form>.<nn>, e.g. M5.01. The prefix encodes the column, so an ID alone locates a technique without the header.
namestringNames the action, not a product.
towerenumThe terrain layer this technique acts on. Exactly one.
phaseslistThe campaign phases in which this technique is a dominant effort — not every phase in which it is merely running.
doesstringOne sentence: what the technique does, phrased as defensive intent rather than configuration.
indicatorstringMandatory. What observable state proves the technique is working. This field is the framework's assessability guarantee.
controlslistASOM-Fed control IDs making the technique assessable, and optionally a cross-reference to a sibling technique.

3.5 Controls

The 78 ASOM-Fed controls across fourteen families are the assessment layer. They exist because SP 800-53 Rev. 5 — roughly 1,196 controls across twenty families — has no family that specifies the maneuver layer: nothing in it requires you to know your terrain, designate a main effort, measure your decision tempo, reconstruct an engagement, or prove you can perform a form of maneuver at all. ASOM-Fed neither replaces nor duplicates 800-53; it adds the missing family and inherits everywhere else.

FamilyControlsGoverns
TM Terrain Management7Inventory, classification, weighting, zones, connections, currency, ownership
KT Key Terrain and Decisive Points5What must not be lost, and whether it can be reached
ID Identity Terrain5The identity plane as ground — planes, credentials, assurance, assertions, authorization integrity
DV Devices Terrain5The entry fords — device identification, posture as an access precondition, sensor liveness, execution control, lifecycle and sanitization
SM Scheme of Maneuver7Choosing moves, assigning them to ground, honest states, deception emplacement
TA Tempo and Temporal Advantage5Speed of decision, measured and governed
EN Engagement and Pursuit6Declaration, reconstruction, evidence, escalation, eradication, communication
CE Cycle Execution and Assurance7Running the loop and producing the evidentiary record
CG Command and Governance5Intent, phase, rules of engagement, disposition, inheritance
RC Reconstitution and Recovery5Recovery outside the blast radius, proven by exercise
FO Federal Obligations7Terrain that exists because the organization is federal
WF Workforce Terrain5The people who operate the estate, held as ground
FC Facilities Terrain4Buildings, zones, maintenance paths
LC Lines of Communication5Suppliers, components, the routes they arrive on

Each control carries 734 capability-leveled activities in total, plus a seven-component treatment, metrics, and mappings. The depth model is described in §4.7.

Prefix note. ID is also the CSF 2.0 Identify function prefix. The formats are distinguishable — ASOM-Fed controls are ID-1, CSF subcategories are ID.AM-01 — but every document should use the hyphen-number form without exception, and tooling must not pattern-match on the two letters alone.

3.6 Campaign phases

Six phases, adapted from joint phasing, each with a stated objective and a dominant set of forms. Phasing is what lets leadership see cyber defense as a campaign with a main effort per phase rather than an undifferentiated grind — and it is what makes "we are in Phase III" a sentence that changes behavior, because pre-authorized responses and session lifetimes are keyed to it.

IDPhaseObjectiveDominant forms
0ShapeSet the conditionsM1 · M2 · M3 · M9
IDeterRaise the adversary's costM3 · M4 · M5
IISeize InitiativeContest first contactM1 · M4 · M6
IIIDominateDefeat the attemptM7 · M8 · M5
IVStabilizeRestore secure operationsM8 · M10 · M11
VRestoreHand back to steady stateM11 · M10 · M2

CG-2 requires at least one consequential control to be keyed to phase, and its assessment tests what materially changed at the last transition. A phase declaration that changes no authorization, no allocation and no configuration is a status field.

3.7 Object model relationships

The model is deliberately small. Seven object types, and every relationship is a single hop.

Form of Maneuver ──is realized by──▶ Technique ──acts on──▶ Terrain Layer
   M1 … M11 · durable                M3.04 · perishable        T1 … T9, TX
        │                                 │                         ▲
        │                                 │                         │
        │                          assessed by                   occupied by
        │                                 ▼                         │
        └────── dominant in ──▶ Campaign Phase        Control ◀── allocated to
                               0 · I · II · III · IV · V   TM KT ID SM TA EN
                                                           CE CG RC FO WF FC LC
                                        Studio Asset / Register Row
                                                    │
                                             evidences (dashed)

Figure 1. A form of maneuver is realized by techniques; each technique acts on exactly one terrain layer, is made assessable by controls, and is dominant in one or more campaign phases. Controls are themselves allocated to a terrain layer and carry a posture. The dashed path is the Studio and Asset Register integration: an asset tagged with a form, sitting on a terrain layer, evidences the techniques at that intersection — which is how a drawn architecture becomes a coverage claim.

3.8 Posture — the axis added in v5.0

The framework already grouped forms into Shaping, In contact and Consolidation. That is a temporal axis: when in the campaign a form does its work. Posture is orthogonal to it and answers a different question: who initiates, and must a human be present for it to work?

PostureDefinitionBehavior under tempo degradation
PassiveOperates without human action once emplaced.Unchanged
ActiveDefender-initiated, on the defender's timeline.Deferred, not lost
ReactiveTriggered by adversary action, human in the loop under time pressure.Degrades
DirectingSets the conditions the other three operate under.

Why four rather than three. Passive, active and reactive describe defensive effects. Thirty of the seventy-eight controls do none of those things: they state intent, set priority, measure tempo, run the cycle and grant authority. Forcing those into one of the three would distort the ratio that makes the model useful.

What it found. Only 16 of 78 controls (22%) assure a defense that operates without a human. That is the proportion an adversary meets on a federal holiday, during a shift handover, or through a hiring gap — precisely the conditions TA-5 requires an agency to identify, and precisely the windows adversaries select. The recommended metric is passive coverage of decisive points: an estate whose decisive points are defended entirely by reactive controls has a defense with operating hours.

M2, M3 and M4 are the passive spine. An agency under-invested in depth, envelopment and canalization has bought a defense that works only while someone is watching.

3.9 Machine-readable form and the build pipeline

The framework ships as a script, framework.js, which is the single source of truth for the technique layer and is loaded by both the matrix and the Studio canvas.

Version 6.1 made the one-source-of-truth claim real rather than aspirational. Prior releases asserted that the artifacts could not disagree; they demonstrably had. The control catalog is now the only hand-maintained content, and the Word Control Guide, the Maneuver Matrix document, the Asset Register, the CSV and JSON exports and the changelog are all generated from it by build tooling that fails on:

A design rule worth stating explicitly. There is exactly one copy of any given fact. A published framework whose website and whose tooling disagree about its own contents has failed at the only thing a reference framework is for — and the way that happens is not carelessness but duplication, so the remedy is generation rather than diligence.


4. The methodology

4.1 The defender's perspective

ATT&CK is built from the adversary's perspective, which is what makes it honest: it describes what is actually done to networks rather than what defenders wish were true. ASOM-Fed inverts the vantage point but keeps the discipline. Every entry is written from the perspective of the force that owns the ground — which is the defender's one structural advantage, and the thing control catalogs consistently fail to exploit.

Owning the ground means a defender may do things an attacker cannot: emplace obstacles, choose which corridors to leave open and instrument them, seed decoys, trade space for time, and fail secure by design. Seven of the eleven forms have no offensive analogue at all. A framework organized around controls cannot express any of them, because none of them is a control.

4.2 Doctrinal derivation, and how it differs from ATT&CK

The most important limitation in this document. ATT&CK's authority is empirical. Its techniques are admitted because they were observed in real intrusions, and each carries references to the reporting that observed them. ASOM-Fed's technique layer is doctrinal and analytic: entries are derived from maneuver doctrine, federal zero-trust guidance and established defensive practice — not from a corpus of incidents in which each was measured to work. These are different kinds of claim and should not be confused.

Two consequences follow, and adopters should hold ASOM-Fed to them:

4.3 Abstraction

ATT&CK's foundational argument is that a mid-level model is necessary: high-level lifecycle models describe goals but not actions, and low-level databases describe artifacts stripped of context, so something in between is needed to connect behavior to defenses. ASOM-Fed makes the identical argument on the defensive side.

HIGH   Outcome and maturity models        NIST CSF 2.0 · CISA ZTMM · OMB M-22-09
       "what should be true?"
──────────────────────────────────────────────────────────────────────────────
MID    ASOM-Fed — forms of maneuver and techniques
       How defensive capability is arrayed and moved on cyber terrain, over
       time, against an adversary who is also moving.
──────────────────────────────────────────────────────────────────────────────
LOW    Control catalogs and configuration   SP 800-53 Rev. 5 · CIS Benchmarks
       "what must be installed?"

What the maneuver abstraction provides that neither neighbor does:

4.4 What makes a form of maneuver

Forms are the framework's stable spine, so the bar for adding one is deliberately very high. In practice the set is closed; the framework expects to add techniques indefinitely and forms almost never. A candidate form must satisfy all five:

  1. It is durable. It would have been recognizable to a planner twenty years ago and should still be in twenty years' time. If it names a technology, it is a technique.
  2. It is expressible as intent. It can be stated in one clause a non-engineer can act on. "Force the adversary onto ground you own" is a form; "deploy microsegmentation" is not.
  3. It is distinct in effect, not in mechanism. Two forms must differ in what they achieve. M4 Obstacle / Canalization and M2 Defense in Depth both use segmentation; they are separate forms because one shapes where an adversary goes and the other ensures no single failure is decisive.
  4. It has techniques. A form with no concrete way to perform it is a slogan. Each admitted form must support at least five distinct techniques.
  5. It can be absent. It must be possible for an agency to genuinely not have it. A form every organization trivially satisfies carries no information and cannot produce a gap finding.

The v3.0 result worth restating. Adding three terrain layers required no new forms. If the eleven are genuinely exhaustive at their level of abstraction, adding ground should be defensible with the moves already named — and it was. A version that had needed a twelfth form would have been evidence against the durability claim rather than for it. Version 6.1 repeated the test: thirteen new controls and fifty-two new technique citations, no new forms.

4.5 What makes a technique

Naming. A technique is named for the action, in a form that stays true across implementations: Phishing-Resistant Authentication, not FIDO2 rollout; Estate-Wide Session Revocation, not the name of the console you do it from. If a name cannot survive its vendor being replaced, it is the wrong name.

Levels of abstraction. Techniques sit at three levels, and all three are legitimate: general across terrain (M2.14 Control Failure Detection); general with layer-specific expression (M5.01M5.08, one deception intent expressed across data, identity, network, endpoint, application and cloud terrain); and specific to one layer (M4.09 Removable Media Control).

Intent before mechanism. The does field states what the technique accomplishes defensively, not how a product is configured. This is the rule that keeps the framework from decaying into a settings guide, and it is the one most often broken by well-meaning contributions.

The success-indicator requirement. Every technique must state what observable state proves it is working — and the indicator must be falsifiable. "MFA is deployed" is not an indicator; "credential phishing yields no usable authentication" is, because it can be tested and can fail. A proposed technique with no falsifiable indicator is rejected, not deferred, because an entry nobody can fail is an entry that measures nothing.

Technique distinction. Two techniques are distinct when they differ in the terrain they act on, the form they serve, or what proves them. If two candidates would share an indicator exactly, they are one technique. Each technique carries exactly one terrain layer; where it plausibly spans layers, it is assigned to the layer whose loss would defeat it and cross-referenced from the others. This keeps the matrix partitionable — forTower across all ten domains must sum to 154, a property the test suite asserts.

4.6 What makes a control

New in v5.0, because the control layer had no stated admission criteria.

  1. It specifies the maneuver layer. If SP 800-53 already requires it, it is inherited and cited, not restated. CG-5 enforces this.
  2. It is testable. The assessment procedure must name what an assessor examines, whom they interview, and what they test. "Examine the policy" alone is not an assessment.
  3. It produces its evidence as a by-product. A control satisfied only by writing a document about it has failed the compliance-is-exhaust principle.
  4. It can fail. A control every agency trivially satisfies carries no information — the same absence test the forms must pass.
  5. It states how it fails socially. Most controls in this catalog are defeated by incentive rather than by technology, and the culture component is where that is written down. SM-3 is defeated by optimistic self-declaration; CG-4 by anonymous risk acceptance; TA-4 by second-guessing an operator who acted within authority.

4.7 Control depth — the COBIT 2019 component model

Introduced in v4.0. Each control carries the component treatment COBIT 2019 applies to a governance or management objective, adapted to defensive maneuver: purpose, goals cascade, discussion, activities graded by capability level 2–5, RACI against six roles, information flows, people and skills, policies, culture and behavior, services and infrastructure, metrics, and mappings.

Capability levelCriterionActivities
2 PerformedAchieves its purpose, possibly ad hoc219
3 DefinedStandardized and documented300
4 PredictableQuantitatively managed against thresholds142
5 OptimisingContinuously improved from measured outcomes73

Four generic activities apply to every control and are stated once rather than seventy-eight times: approach, accountability, communication, and — added in v5.0 — threshold approval provenance, which requires any control defining a threshold, floor, period or target to record when it was approved relative to first measurement. A threshold set after the first measurement will be set where the organization already passes, producing a governed-looking metric that has never once reported a problem.

Parameters derived rather than chosen. A property that emerged during the v4.0 depth work and is worth naming: several controls take their parameter from a measurement held elsewhere in the framework rather than from a locally chosen constant. LC-4's staging soak period derives from TA-1's measured detection segment — a ring protects only if the soak exceeds time-to-notice. RC-4's restore point derives from EN-2's reconstruction, falling back to TA-2's dwell estimate. FC-2's physical crossing-log retention derives from the same dwell estimate. This is what a maneuver framework should do and what a control catalog structurally cannot.

4.8 Reverse coverage as a discipline

New in v5.0. Checking that every ASOM-Fed control carries mappings is the easy direction. The useful direction is checking that every referenced outcome has a control pointing at it — and the three references require different answers.

ReferenceReverse coverage a goal?Why
CSF 2.0Yes106 outcome-level subcategories. A legitimate completeness claim; every gap should be a recorded decision.
D3FENDAt tactic level only7 tactics. Technique level would make ASOM-Fed a countermeasure ontology with different labels rather than a planning model.
SP 800-53No — and pursuing it would break the framework~1,196 controls ASOM-Fed inherits. CG-5 exists to prevent duplicate assessment; a control-for-control mapping creates the parallel compliance burden that guarantees non-adoption. Family reach, currently 20/20, is the right measure.

Current position: 93 of 106 CSF subcategories covered, 13 excluded by recorded policy, 0 unaccounted. Every subcategory is either covered or excluded with a written reason and the build fails if a third state appears.

4.9 Creating and changing entries

Creating a technique. Name the defensive effect in one sentence without naming a product; identify the form; assign one terrain layer — the layer whose loss defeats it; write a falsifiable indicator, and if you cannot, stop, the entry is not ready; bind controls, and if none fits, that signals the control set needs extending, which is a separate and heavier change; assign dominant phases; check distinction against every existing technique in the form.

Enhancing and deprecating. Sharpening a description, strengthening an indicator, or adding a control binding is always preferred to adding a near-duplicate. The catalog's value degrades faster from redundancy than from omission: a matrix with two cells that mean the same thing quietly double-counts coverage. This is not hypothetical. FO-6 and LC-1 both required suppliers with a path into the estate to be registered on the overlay with their access recorded — the same requirement in two families, double-counting supply chain coverage in every scored estate, from v2.0 until v5.0 narrowed FO-6 to the SCRM obligation. IDs are never reused; a technique that stops being meaningful is marked deprecated and keeps its ID, so historical coverage scores stay interpretable.

4.10 Worked examples

Accepted — M5.03 Decoy Credentials. Effect: credential material that is valid-looking, monitored and powerless, seeded where harvesting would find it. Form: M5 Ambush — it trades space for information and time. Terrain: T1 Identity; the credentials live in the identity plane and its compromise is what defeats them. Indicator: "credential harvesting is detected on use of a planted credential" — falsifiable, and testable by a red team in an afternoon. Distinct from M5.01 Decoy Records (different terrain, different indicator) and from the M3 techniques (different intent: this one is not trying to prevent movement, it is trying to hear it).

Rejected — "Deploy an EDR agent". It names a product category, not a defensive effect, and its natural indicator — "the agent is installed" — cannot fail in any interesting way. What it became: M2.05 Endpoint Detection and Response Coverage, whose indicator is "coverage is reconciled to the inventory, not to the console", and M2.14 Control Failure Detection for the silent-agent problem.

Rejected as a form, admitted as techniques — "Zero Trust". It is an architectural philosophy, not a form of maneuver: it fails the distinctness test because it describes almost everything the framework already contains, and it fails the absence test because every agency claims it. Where it went: distributed across M2, M3 and M4 as the techniques that actually constitute it.

Accepted as a control after a reverse-coverage finding — SM-7 Deception Emplacement. Why it was needed: D3FEND's Deceive tactic was reached by zero controls while M5 carried thirteen techniques. Why it is a control and not a form: deception is already a form, M5; what was missing was the assessment layer. The design decision worth noting: the alert-to-human period is derived from TA-1's decide segment rather than chosen, because a deception alert routed into a queue triaged tomorrow discards the no-false-positive property that made it worth emplacing.

4.11 Agency instantiation

ASOM-Fed is published against a generic Federal Reference Agency archetype and contains no agency-specific information by design. Adopting it means substituting your own systems, boundaries and mission threads into the terrain overlay and the Asset Register while leaving the forms, techniques and controls untouched. An agency that finds itself editing the framework rather than the overlay has usually mis-modeled its terrain.


5. Relationship to other frameworks

MITRE ATT&CK. Complementary, and the cleanest relationship here: ATT&CK catalogs adversary behavior; ASOM-Fed catalogs defensive maneuver. A threat course of action expressed in ATT&CK techniques is the natural input to the MAP step of the ASOM cycle, and the output is a scheme of maneuver expressed in ASOM-Fed forms. The two overlays answer different questions about the same estate.

MITRE D3FEND. The closest neighbor and it deserves a direct answer. D3FEND is a knowledge graph of defensive countermeasures across seven tactics, with rigorous semantic relationships to the artifacts they operate on. It is excellent at what it does and more semantically precise than ASOM-Fed. The difference is operational art: D3FEND tells you what a countermeasure is and what it acts on; it does not express sequence, main effort, phase, terrain ownership, tempo or posture. ASOM-Fed's unit is not the countermeasure but the maneuver — an intent applied to specific ground at a specific point in a campaign. They compose, and D3FEND is a natural source of rigor for the technique layer.

COBIT 2019. New relationship in v4.0. COBIT governs enterprise I&T: whether it is directed, accountable and delivering value. It is deliberately not an operational defense method — it tells you risk should be optimised, not where to put your sensors this quarter. What ASOM-Fed borrows is structural, not substantive: the component model for expressing an objective, and capability levels for grading activities. An agency running COBIT will find ASOM-Fed's control presentation familiar by construction.

NIST CSF 2.0, RMF and SP 800-53. Subordinate by design — ASOM-Fed produces compliance rather than consuming it. The cycle's outputs map onto CSF 2.0's functions; the terrain overlay feeds RMF Categorize and Select; the cycle itself is continuous monitoring. Every ASOM-Fed control inherits from named 800-53 Rev. 5 controls, so nothing here creates a parallel compliance burden.

CISA ZTMM and NIST SP 800-207. ZTMM supplies the terrain. ASOM-Fed's five inherited layers are the ZTMM pillars, and the maturity vector remains the right zero-trust progress report. What ASOM-Fed adds is movement: ZTMM tells an agency how mature each pillar is, not what to do with the pillars when something is happening.

TBM and the Defense Tower Model. The Tower Model mirrors the TBM Council taxonomy one layer at a time, substituting defensive coverage and residual risk for cost: Asset Pools → Defense Towers → Maneuver Solutions → Mission Consumers. This is what gives ASOM-Fed bidirectional traceability — pick a mission and see everything defending it, or pick an asset and see every mission it protects — in a form a CFO already understands.


6. Scope and deliberate exclusions

Things ASOM-Fed does not do, on purpose:


7. Versioning and change management

Version 2.0 — the framework failed its own test

Scoring ten representative federal agency architectures against v1.0 produced a finding about ASOM-Fed rather than about the agencies: no architecture could evidence M10, forty-two of 111 techniques were evidenced by none of them, and the 35 controls reached five of six CSF 2.0 Functions with Recover empty. Added: T6 Operational Technology; M11 Reconstitution; the RC and FO families, taking the catalog from 35 to 46 and CSF reach to all six Functions; and per-agency obligation profiles.

Version 3.0 — the completeness test

Every ASOM-Fed control cites the 800-53 controls it inherits from, so the families it never cites measure the estate the framework does not reach. Against v2.0 that returned four families at zero — AT, PS at a single citation, PE and MA — with SR and SA thin. Stated as terrain: the framework modeled the machines and not the people, the buildings, or the suppliers. Added: T7 Workforce with the WF family, T8 Facilities with FC, T9 Supply Chain with LC, and twenty-five techniques, taking the matrix to 150 and the catalog to 60 across eleven families. No new forms were required, which is the most load-bearing result in that release.

Version 4.0 — depth

No roster change. Every control was rebuilt to the COBIT 2019 component model: 734 capability-leveled activities, RACI, information flows, people, policies, culture, services, metrics and mappings — approximately 2,300 authored elements. The build pipeline was introduced, and with it the first machine-checked guarantees about the catalog's internal consistency.

Version 6.1 — the fight, the high ground, and the artifacts

Three independent measurements produced three findings, and a fourth emerged from checking the artifacts against each other.

Roster: 60 → 78 controls across 14 families. Denominators changed; v4.0 and v5.0 coverage scores are not comparable, and the trend must break here.

Resolved at v6.1

Recorded but not resolved


8. Summary

ASOM-Fed occupies a level of abstraction that federal cyber defense currently leaves empty. Above it, maturity and outcome models say what should be true. Below it, control catalogs say what must be present. Neither can express the thing that decides engagements: how a defense is arrayed, what it does first, what it gives up, whether it can act faster than the adversary can adapt, and whether any of it holds when nobody is watching.

The framework's shape follows from one borrowed idea taken seriously — that durable categories of maneuver must be separated from the perishable techniques that realize them — and from disciplines imposed throughout: every technique must state what would prove it is working, and that statement must be capable of being false; every control must be able to fail, and must say how it fails socially as well as technically; every referenced outcome must be covered or excluded on the record; and no two artifacts may hold the same fact.

The result is a defender's knowledge base that a CISO can direct, an engineer can implement, a red team can attack, and an auditor can accept as evidence.

It is offered as a public reference framework: unclassified, agency-agnostic, free to use, free to extend, and built to be argued with.


9. The rest of the suite

Each artifact is derived from the same source, so they cannot disagree about what the framework contains.

ArtifactRole
FrameworkThe doctrine: why defense is a maneuver problem
Application and Control Guide78 controls with activities, components, evidence and assessment procedures
Defensive Maneuver Matrix11 forms, 154 techniques, 77 cells, and the controls that assess each
Asset Register and Tower AllocationAssets on terrain, defensive weight, mission bill of defense
Posture and Tower ModelWhich controls hold when nobody is watching
Control Catalog (CSV / JSON)Machine-readable, for GRC import
ChangelogPer-control version history, generated
Diagram StudioWhere the work is done and the control set evaluates live
The BriefThe cycle record, citing the controls each section evidences

The chain: Framework states why · Control Guide states what must be true · Studio does it · Brief proves it · cycle history proves it over time.


10. References

  1. Strom et al., MITRE ATT&CK: Design and Philosophy, The MITRE Corporation, MP180360R1, 2018 (rev. 2020). The structural model for this document.
  2. Allen, Cyber Maneuver and Schemes of Maneuver, The Cyber Defense Review,
  3. Source of the positional/temporal advantage definition and the durability-of-categories argument.
  4. Headquarters, Department of the Army, ATP 2-33.4, Intelligence Analysis. Source of the Screen→Analyze→Integrate→Produce cycle, structured analytic techniques, IPB and confidence levels.
  5. CISA, Zero Trust Maturity Model, v2.0 (April 2023).
  6. NIST, SP 800-207, Zero Trust Architecture.
  7. NIST, Cybersecurity Framework (CSF) 2.0. 6 functions, 22 categories, 106 subcategories.
  8. NIST, SP 800-53 Rev. 5, SP 800-53A and SP 800-37 Rev. 2 (RMF).
  9. OMB, M-22-09, Moving the U.S. Government Toward Zero Trust Cybersecurity Principles.
  10. The MITRE Corporation, D3FEND.
  11. ISACA, COBIT 2019 Framework: Governance and Management Objectives. Source of the component model and capability levels used for control depth.
  12. TBM Council, Technology Business Management Taxonomy.

ASOM-Fed is published by threatDefendr as a public reference framework. Unclassified and illustrative; built from public sources only; contains no agency-specific information. ATT&CK® and D3FEND™ are trademarks of The MITRE Corporation and COBIT® is a trademark of ISACA; neither organization endorses this framework.