DOCTRINE

The Framework

Why federal network defense is a maneuver problem, and the model that follows from taking that seriously. Start here.

ASOM-Fed v6.1 · Unclassified / Illustrative · agency-agnostic reference framework · built from public sources only

The Analytic Scheme of Maneuver for Federal Network Defense

Version 6.1 · Unclassified / Illustrative

A recommended reference framework applying an analytic scheme of maneuver to any U.S. federal agency network, built against a generic Federal Reference Agency model. Agency-agnostic by construction; adopters substitute their own systems, boundaries and mission threads.


Executive summary

The problem. Federal network defense is still run as garrison security — static controls, perimeter guards, compliance checklists, and reaction. The unit of planning is the control, and controls do not move. Meanwhile the adversaries that matter behave like a maneuvering force: nation-state collectors after sensitive case records, fraud rings working public service portals, and ransomware crews exploiting deadline-sensitive availability. They seek positional and temporal advantage, mass at a decisive point, and exploit whichever side has the slower decision loop.

The reframe. ASOM-Fed treats cyber defense as a maneuver problem led by intelligence analysis. It combines two mature analytic bodies rarely brought together: the scheme of maneuver, which describes how a defense is arrayed and moved to gain positional advantage, and the structured analytic process of Screen → Analyze → Integrate → Produce, which supplies confidence levels, priority intelligence requirements and disciplined course-of-action development.

The result. An intent-driven, intelligence-led plan that arrays defensive analytic and response capability across cyber terrain to seize and hold positional and temporal advantage, then continuously re-arrays as the situation develops. The agency stops being a wall that reacts and becomes a thinking defense that holds ground it has chosen.

What version 6.1 contains.

11 forms of maneuverDurable categories that outlive tool churn
154 cataloged techniquesEach with a falsifiable success indicator
78 assessable controlsAcross 14 families, inheriting all 20 SP 800-53 Rev. 5 families
784 capability-leveled activitiesGraded 2–5 on the process capability scale
10 terrain layersFive CISA ZTMM pillars plus four ASOM-Fed additions, plus cross-cutting
77 terrain × form cellsThe board coverage is actually scored on
4 defensive posturesPassive, active, reactive, directing

1. What this framework borrows, and what it deliberately does not

ASOM-Fed applies maneuver concepts to a civilian federal mission. That combination needs stating precisely, because the value is in the analytic structure and the risk is in importing organizational assumptions that do not belong in a federal agency.

What is borrowed — analytic and planning concepts:

What is deliberately not borrowed:

An agency adopting ASOM-Fed adopts a planning method, not a posture toward the world.


2. Doctrinal and policy foundations

2.1 Maneuver and positional advantage

Cyber maneuver is defined in the source literature as actions taken within and through cyberspace to achieve physical, technical and cognitive positional and temporal advantage over an adversary. A scheme of maneuver specifies which categories of maneuver apply and in what sequence.

The consequential idea is that categories of maneuver are durable while the techniques that realize them are perishable. Leaders therefore need intent, not tool mastery; engineers can re-tool without invalidating the plan. Every structural decision in this framework follows from taking that seriously.

2.2 The analytic process

The analytic engine is Screen → Analyze → Integrate → Produce, supported by structured analytic techniques, systematic preparation of the environment, and products that carry explicit confidence levels and are driven by priority intelligence requirements. Control CE-3 makes confidence mandatory and measures whether the scale is actually used; a function that never publishes a low-confidence assessment is unfalsifiable rather than careful.

2.3 The federal terrain

The ground ASOM-Fed maneuvers on is the federal zero-trust stack: the CISA Zero Trust Maturity Model (five pillars, three cross-cutting capabilities, maturity Traditional → Initial → Advanced → Optimal); NIST SP 800-207 Zero Trust Architecture (policy decision and enforcement points); Trusted Internet Connections 3.0; Continuous Diagnostics and Mitigation; FISMA with the NIST Risk Management Framework, SP 800-53 Rev. 5 and CSF 2.0; and OMB M-22-09.


3. The core translation

This crosswalk is the framework's reference point. Every later section uses it to keep operational intent legible to both agency leadership and engineers.

Analytic termFederal-network meaningReference-agency instantiation
Accountable authorityAuthorizing Official or CISO who owns risk and intentAgency CISO / Authorizing Official
Defensive intentDefensive end-state plus acceptable risk, in one paragraph"Protect mission-transaction integrity and sensitive mission records; degrade gracefully, never fail open"
Scheme of maneuverThe defensive campaign plan — which maneuvers, where, in what sequenceCampaign for the public service portal and case-processing systems
Key terrainSystems and data whose control confers decisive advantagePublic Service Portal, sensitive records, ICAM identity plane, mission-staff workflow
Decisive pointWhere control unhinges the adversary's planIdentity policy decision point; the CI/CD pipeline
Avenues of approachAttack paths and exploitable surfacePublic portals, external-user accounts, cloud APIs, contractor supply chain, maintenance paths
Mobility corridorsLateral-movement pathsFlat segments, over-permissioned service accounts, shared cloud roles
Main effortWhere defensive priority is concentratedSensitive records and the identity plane
Preparation of the environmentCyber Preparation of the Environment (CPE)Map the portal attack surface and threat courses of action
Priority intelligence requirementsPriority Cyber Intelligence Requirements (PCIR)"Are external-user accounts being taken over?"
Defensive actionsActive response — block, isolate, deceive, disrupt, evictAuto-revoke session; quarantine; deploy decoy
Running estimateCyber Running Estimate — living situational pictureFused SOC and hunt board
TempoRate of decision and action relative to the adversaryMean time to detect, decide and contain, against adversary dwell

4. The cyber terrain model

You cannot have a scheme of maneuver without terrain. ASOM-Fed models the federal enterprise as nine terrain layers plus one cross-cutting domain. Five layers are the CISA ZTMM pillars taken unchanged; four are ASOM-Fed's own, each added because a measurable part of a federal estate had nowhere to stand without it.

Each layer carries a metaphor that is load-bearing rather than decorative: it tells a planner what kind of ground they are defending, and therefore which moves are available on it.

IDTerrain layerCharacterKey terrain / decisive point in the reference agency
T1IdentityThe high groundICAM and policy decision point; privileged, external-user and mission-staff identities. Whoever holds it controls movement everywhere else.
T2DevicesThe entry fordsManaged and unmanaged endpoints; mission-staff and contractor devices; privileged access workstations.
T3NetworksThe corridorsSegmentation, TIC 3.0 trust zones, east-west and cloud peering paths. The only layer where an adversary can meaningfully be canalized.
T4Applications and WorkloadsUrban terrainPublic Service Portal, Case Processing System, APIs; the CI/CD pipeline as a decisive point. Dense, complex, easiest to lose track of.
T5DataThe objectiveSensitive case records, PII, financial data, audit logs. The reason the campaign exists.
T6Operational TechnologyContested groundBuilding management, physical access control, engineering workstations. Cannot be patched or restarted on the defender's schedule; loss has physical consequence. Added v2.0.
T7WorkforceThe people who operate the estatePrivileged administrators, caseworkers, approval authorities, contract support. The only terrain that is simultaneously the workforce operating it. Added v3.0.
T8FacilitiesThe ground you stand onData centers, field offices, alternate recovery sites, and the vendor maintenance paths reaching through them. Added v3.0.
T9Supply ChainLines of communicationCloud and managed service providers, build dependencies, hardware and firmware vendors. Frequently the actual intrusion path. Added v3.0.
TXCross-CuttingThe enablersVisibility and analytics is reconnaissance; automation and orchestration is mobility; governance is decision authority. Not ground, but what lets you move on it.

Deliberate divergence from CISA. The five pillars are ZTMM's, verbatim. T6 through T9 and the consolidation of ZTMM's three cross-cutting capabilities into a single TX domain are ASOM-Fed's own. The consolidation is lossy: an agency reporting ZTMM maturity per cross-cutting capability cannot map those three onto TX one-to-one and should continue reporting them separately.

The deliverable of this step is a one-page Cyber Terrain Overlay, refreshed at a defined cadence and on material architectural change. Controls TM-1 through TM-7 specify it; TM-6 requires both triggers, because a program honoring only the calendar will plan from a map that a deployment invalidated the week after it was drawn.

Standing finding. Every terrain layer ASOM-Fed added has dedicated controls. Of the five inherited ZTMM pillars, only T1 does, added in v5.0. T2 Devices holds no dedicated control and is the only layer with none — recorded as a v6.1 input rather than resolved here.


5. The ASOM cycle

A repeatable, intelligence-led loop fusing the structured analytic process with maneuver planning. Six steps; the loop turns continuously, and the objective is to run it faster and at higher confidence than the adversary can adapt.

#StepAnalytic rootWhat happensOutput
1FRAMEScreen; analytic designState the defensive intent; set priority cyber intelligence requirements; define what positional advantage means this cycleIntent paragraph and PCIR list
2MAPPreparation of the environmentRefresh the terrain overlay; enumerate avenues; build most-likely and most-dangerous threat courses of actionTerrain overlay and threat COA sketch
3ARRAYScheme designChoose forms of maneuver, main and supporting effort, decisive points, branches and sequelsThe scheme of maneuver
4MANEUVERExecutionEmplace obstacles, reposition sensors, execute pre-authorized defensive actions per the schemeExecuted actions and change record
5FUSEAnalyze; integrateApply structured analytic techniques; assign confidence levelsFused assessment
6ASSESSProduce; re-frameMeasure advantage; continue, exploit or transition; publish the Brief; loop to 1Cycle record and posture result

Ownership is split deliberately. Steps 1, 2 and 5 belong to the threat intelligence function; step 4 to the SOC; steps 3 and 6 to the accountable authority. Splitting ownership this way is what stops the loop degrading into a status meeting. Control CE-1 requires the cadence to hold and records a lapse as a finding — the cycle is otherwise sacrificed exactly when it is most needed, because the SOC is busy precisely when it would be most valuable.


6. The maneuver catalog

The durable categories of maneuver, recast as defensive forms for a federal network. Each is intent-first: leadership picks the intent and mechanism; engineers pick the technique. A scheme of maneuver names a sequence of these with one designated main effort.

IDFormIntentMechanism in the reference agency
M1Screen / GuardEarly warning and reaction timeExternal attack-surface monitoring, threat intelligence, perimeter canaries, external-login geography
M2Defense in DepthNo single failure is decisiveLayered controls across all terrain; TIC 3.0 zones; sensitive records behind their own enforcement point
M3EnvelopmentMake identity the decisive planePhishing-resistant MFA, continuous authorization, conditional access, just-in-time privilege
M4Obstacle / CanalizationForce the adversary onto ground you ownMicrosegmentation, egress control, allow-listing, denied east-west between tiers
M5AmbushTrade space for information and timeHoneypots, decoy credentials and documents, honeytokens in the data layer
M6DelayBuy decision time; prevent culminationRate limiting, step-up authentication, session throttling, bulk-download throttling
M7CounterattackSeize initiative; evict earlyHypothesis-driven hunting from FUSE; automated containment playbooks
M8Isolation / RetrogradeFail secure; give ground to preserve the missionAutomated segment severing, session revocation, graceful degradation preserving transaction integrity
M9Spoiling AttackDisrupt adversary staging pre-attackAct on CISA, sector and law-enforcement reporting to pre-block infrastructure and pre-patch targeted weaknesses
M10Exploitation & PursuitConvert contact into durable advantageHarvest indicators into detections; close the avenue; update overlay and requirements; share to the community
M11ReconstitutionRestore the mission on evidence, not on hopeDeclare recovery objectives; hold recovery outside the production identity plane; test the rebuild path including identity; verify restored data

Principal ground, posture and allocation weight. Ground is the terrain layer the form is principally concerned with — advisory, since techniques within a form may sit on other layers. Posture is defined in §7. Weight is the residual-risk reduction attributed to the form when fully operational, used by the Tower Model's allocation arithmetic.

IDFormPrincipal groundPostureWeight
M1Screen / GuardT3Reactive7
M2Defense in DepthT3Passive12
M3EnvelopmentT1Passive15
M4Obstacle / CanalizationT3Passive10
M5AmbushT5Active9
M6DelayT4Reactive8
M7CounterattackTXActive11
M8Isolation / RetrogradeT3Reactive10
M9Spoiling AttackTXActive6
M10Exploitation & PursuitTXActive5
M11ReconstitutionTXReactive7

Rebalanced in v6.1. The weights previously summed to 117, not 100 — the distribution summed to 100 across the original ten before M11 was added in v2.0 at weight 8, and nothing rebalanced it, so a design evidencing everything reported 117% residual risk reduction. The weights above are a proportional rescale to 100 preserving the original order. This is a denominator change: coverage and residual-risk figures computed against v6.1 and earlier are not comparable, and control CE-6 requires the trend line to break here.


7. Posture — what holds when nobody is watching

Introduced in v5.0. The bands above — shaping, in contact, consolidation — describe when a form does its work. Posture is orthogonal and answers a different question: who initiates, and must a person be present for it to work?

PostureDefinitionUnder degraded tempo
PassiveOperates without human action once emplacedUnchanged
ActiveDefender-initiated, on the agency's own timelineDeferred, not lost
ReactiveTriggered by adversary action, person in the loop under time pressureDegrades
DirectingSets the conditions the other three operate under

Why this matters operationally. Only 16 of 78 controls (22%) assure a defense that operates without a person. That is the proportion an adversary meets on a federal holiday, during a shift handover, through a hiring gap or across a contract transition — precisely the conditions control TA-5 requires an agency to identify, and precisely the windows adversaries select.

M2, M3 and M4 are the passive spine. An agency under-invested in depth, envelopment and canalization has bought a defense that works only while somebody is watching. The recommended measure is passive coverage of decisive points, because it is a resilience argument that does not depend on headcount.


8. Phasing the campaign

Phasing lets agency leadership see cyber defense as a campaign with a main effort per phase, rather than an undifferentiated round-the-clock grind.

PhaseObjectiveWhat it means operationallyDominant forms
0 — ShapeSet conditionsContinuous preparation of the environment, zero-trust hardening, partnerships, threat intelligenceM1 · M2 · M3 · M9
I — DeterRaise adversary costVisible hardening, a deception grid, a stated attribution postureM3 · M4 · M5
II — Seize InitiativeContest first contactDetect early, canalize movement, buy decision timeM1 · M4 · M6
III — DominateDefeat the attemptHunt, contain, evictM7 · M8 · M5
IV — StabilizeRestore secure operationsEradicate, verify, preserve availability through recoveryM8 · M10 · M11
V — RestoreHand back to steady stateRecover, harden, update doctrine and intelligence requirementsM11 · M10 · M2

Declaration must change behavior. Control CG-2 requires at least one consequential control to be keyed to phase — pre-authorized response scope, session lifetime, or cycle cadence — and its assessment tests what materially changed at the last transition. A phase declaration that alters no authorization, no allocation and no configuration is a status field, not a campaign.


9. Roles, authority and rules of engagement

9.1 Roles

Six roles, all of them federal. There is no military structure in this model.

CodeRoleOwns
AOAuthorizing Official / CISODefensive intent, risk acceptance, the scheme of maneuver, phase declaration
CTICyber threat intelligence functionFRAME, MAP and FUSE; priority cyber intelligence requirements; threat courses of action; confidence levels
SOCSecurity operationsMANEUVER; execution of pre-authorized defensive actions; declaration and triage
HTHunt teamHypothesis-driven hunting, engagement reconstruction, eradication verification, effectiveness validation
TOTerrain owners — system, data and platform ownersEmplacing moves on their own ground; recovery objectives; asset ownership
GOVGovernance, RMF and ISSO functionRules of engagement, findings disposition, control inheritance, obligation profile

Every control in the catalog carries a RACI against these six. Two assignments are deliberate and worth stating: SM-6 effectiveness validation is the hunt team's rather than the terrain owner's, because the party that emplaced a move is the wrong party to certify it; and WF-4 insider risk is governance's rather than the SOC's, because it is the one control where the operational instinct to investigate first is the wrong instinct.

9.2 Pre-authorized defensive actions

Define in advance which actions the SOC may execute without escalation — for example, revoking a session on confirmed account takeover — and which require the Authorizing Official, such as degrading a public service. This is the single highest-leverage and cheapest control in the framework, because it costs no technology: control TA-1's segment measurement typically shows the decide segment dominating the decision loop, and decide latency is mostly the time spent locating somebody with authority.

Authorizations must be bounded by condition, scope and duration, and keyed to campaign phase. An authority so broad it permits degrading a public service without reference will not survive its first use; one so narrow that every real action falls outside it changes nothing.

Rules of engagement carry a constraint the rest of the framework does not: some defensive actions have statutory consequences. Degrading a service where statute sets a deadline, or acting on a system holding regulated records, is not purely a security decision. Control FO-5 requires those availability floors to be identified, legally confirmed, and carried into the rules of engagement and the pre-authorized set, so an operator at three in the morning knows which degradations are unavailable. Control CG-3 requires the boundary limit — no action outside the agency's own authorization boundary — to be written rather than inferred.


10. Assessment — measuring advantage

10.1 Measures of performance — are we doing the maneuvers right?

Percentage of key terrain behind a policy enforcement point; deception coverage of the data layer; percentage of defensive actions pre-authorized; terrain-overlay freshness; priority intelligence requirements answered per cycle; percentage of decisive points meeting the protection floor.

10.2 Measures of effectiveness — are we winning?

The signature metric is temporal advantage: defender decision tempo — mean time to detect, decide and contain — measured against adversary dwell time. A cycle is won when temporal advantage is positive at the required confidence.

Supporting measures: positional advantage (share of attempts canalized into instrumented terrain; attempts stopped before the data layer); cost imposition (decoy interactions; forced re-tooling); resilience (incidents contained without loss of statutory availability); passive coverage of decisive points; and the ZTMM maturity vector per pillar per quarter.

10.3 Honesty conditions

Temporal advantage is offered as the signature metric precisely because, unlike a maturity score, it can be lost. A program can be well-governed, fully staffed and still behind. Three controls exist to stop the metric flattering its owner:


11. Governance mapping — compliance as a by-product

ASOM-Fed outputs map onto federal obligations, so the agency earns compliance while actually defending.

ObligationHow ASOM-Fed satisfies it
NIST CSF 2.0FRAME feeds Govern; CPE feeds Identify; M2–M4 and M8 feed Protect; M1, M5 and FUSE feed Detect; M6–M8 and the EN family feed Respond; M8, M10 and M11 feed Recover. 93 of 106 subcategories are covered; the remaining 13 are excluded on the record with stated reasons.
NIST RMFThe terrain overlay informs Categorize and Select; maneuvers are Implement; FUSE and ASSESS constitute continuous Monitor and ongoing authorization.
SP 800-53 Rev. 5Every control cites the baseline controls it inherits from. All twenty families are reached. CG-5 requires inheritance to be verified against the specific assessment cited, not asserted at family level.
FISMAThe Cyber Running Estimate and the cycle Brief series become audit evidence of a functioning, continuously monitored program.
OMB M-22-09The ZTMM maturity vector is the zero-trust progress report.
Privacy and CUIFO-1 and FO-2 place privacy terrain and controlled unclassified information on the overlay with the authority under which each is held.

Compliance is exhaust, not the objective. Because every control produces its evidence by being performed, the marginal assessment burden is low: the terrain overlay, asset register, findings list, posture computation and cycle history are generated rather than authored.


12. The control set

SP 800-53 Rev. 5 provides roughly 1,196 controls across twenty families and is the established language of federal control assessment. ASOM-Fed neither replaces nor duplicates it. What has never existed is an assessable specification for the maneuver layer: nothing in the baseline requires an agency to know its terrain, designate a main effort, measure its decision tempo, reconstruct an engagement, or prove it can perform a form of maneuver at all.

Seventy-eight controls across fourteen families fill that gap. Family prefixes are deliberately distinct from the twenty SP 800-53 identifiers so references remain unambiguous when both catalogs appear together.

IDFamilyNWhat it governs
TMTerrain Management7Inventory, classification, weighting, zones, connections, currency, ownership
KTKey Terrain and Decisive Points5What must not be lost, and whether an adversary can reach it
IDIdentity Terrain5The identity plane as ground: planes, credentials, assurance, assertions, authorization integrity
DVDevices Terrain5The entry fords: device identification, posture as an access precondition, sensor liveness, execution control, lifecycle and sanitization
SMScheme of Maneuver7Choosing moves, assigning them to ground, honest implementation states, deception emplacement
TATempo and Temporal Advantage5Making speed of decision measurable, governed and pre-authorized
ENEngagement and Pursuit6Declaration, triage, reconstruction, evidence, escalation, eradication, communication
CECycle Execution and Assurance7Cadence, intelligence requirements, posture computation, the evidentiary record
CGCommand and Governance5Intent, phase, rules of engagement, findings disposition, inheritance
RCReconstitution and Recovery5Recovery held outside the blast radius and proven by exercise
FOFederal Obligations7Terrain that exists because the organization is a federal one
WFWorkforce Terrain5The people who operate the estate, held as ground
FCFacilities Terrain4Buildings, zones, and the maintenance paths reaching through them
LCLines of Communication5Suppliers, components, and the routes they reach the estate on

Note on the CG family name. "Command and Governance" retains command in the sense the federal Incident Command System uses it — a defined decision authority during an incident — not in a military sense. The family concerns the Authorizing Official's intent, phase declaration, rules of engagement and findings disposition. Agencies preferring "Direction and Governance" may rename it locally; the CG prefix and control IDs are stable either way.

Control depth. Each control carries a purpose, a goals cascade, a discussion of the failure mode it addresses, capability-leveled activities graded 2 to 5, a RACI, information flows, people and skills, policies, culture and behavior, services and infrastructure, metrics, mappings, evidence and an examine/interview/test procedure. There are 784 activities in total.

Assessed once, not twice. Every control declares whether it is inherited, extended or net new. Genuinely net new — assess in full: KT-1, KT-4, SM-3, SM-4, SM-7, the entire TA family, CE-4 and CE-6.

Where controls fail socially. Most controls in this catalog are defeated by incentive rather than technology, and each states how. SM-3 is defeated by optimistic self-declaration of implementation state; CG-4 by anonymous, permanent risk acceptance; TA-4 by second-guessing an operator who acted within written authority; WF-3 by sanctioning individuals for failing a phishing simulation, which trains concealment of real incidents.


13. Implementation roadmap

The catalog is not intended to be adopted wholesale on day one. This sequence delivers assessable value at each step.

StepWindowControlsExit criteria
Establish the ground0–60 daysTM-1 … TM-7, CG-1An authoritative, owned, weighted terrain overlay and a signed defensive intent
Name what matters60–120 daysKT-1 … KT-5Decisive points designated with justifications; reachability computed for the first time
Hold the high ground2–5 monthsID-1 … ID-5Identity planes and trust edges mapped; assurance matched to terrain; M3's indicator tested with a captured credential
Hold the fords3–6 monthsDV-1 … DV-5Devices identified as terrain; posture enforced as an access precondition; sensor coverage and liveness measured rather than assumed
Array the defense3–6 monthsSM-1 … SM-7, CG-2, CG-3Moves assigned to ground with honest implementation states; deception emplaced; approved rules of engagement
Achieve tempo6–12 monthsTA-1 … TA-5Decision loop measured by segment; threshold approved and governed; response pre-authorized
Fight and pursue6–12 monthsEN-1 … EN-6Declaration criteria; reconstruction before closure; evidence preserved against dwell; verified eradication
Run the loopContinuousCE-1 … CE-7, CG-4, CG-5Cadenced cycles producing a trended, evidence-bearing record
Hold the wider ground6–12 monthsWF, FC, LC familiesWorkforce, facilities and supply-chain terrain on the overlay with access recorded
Prove you can come backContinuousRC-1 … RC-5, FO-1 … FO-7Recovery held outside the blast radius and demonstrated, against a declared obligation profile

Sequencing note. Identity moves early because everything downstream depends on it: KT-4 reachability computes over authorization paths, EN-5 eradication requires identity-plane revocation, and M3 is the usual main effort. An agency deferring the ID family will find several later controls unassessable.

Success at eighteen months: measurable positive temporal advantage on the main effort; demonstrable to the agency Inspector General as continuous monitoring; a stated degraded posture; and a self-improving practice in which each engagement updates the terrain, the intelligence requirements and the maneuver catalog.


14. Why this is different

ASOM-Fed prioritizes intent over tools, so it survives tool churn and lets leadership direct without being engineers. It is intelligence-led, so every maneuver is driven by analysis with explicit confidence rather than by alerts alone. It is terrain-anchored, forcing prioritization onto what actually matters. It treats compliance as exhaust, satisfying FISMA, zero-trust and RMF obligations as a by-product of real defense. It is measurable through one honest scoreboard that can be lost. And it is falsifiable: every release has been scored against real architectures and against its own crosswalk, and the findings have repeatedly condemned the framework rather than the agencies.


15. The product suite

Each artifact is generated from one source, so they cannot disagree about what the framework contains.

#ArtifactFormatRole in the chain
1ASOM-Fed FrameworkWordThis document. The doctrine: why defense is a maneuver problem
2Design and PhilosophyWordWhy the framework is shaped as it is, and the criteria for extending it
3Application and Control GuideWord78 controls with activities, components, evidence, assessment
4Defensive Maneuver MatrixWord11 forms, 154 techniques, 77 cells, and the controls assessing each
5Asset Register and Tower AllocationWordAssets on terrain, defensive weight, mission bill of defense
6Posture and Tower ModelMarkdownWhich controls hold when nobody is watching
7Control CatalogCSV / JSONMachine-readable, for GRC ingestion
8ChangelogMarkdownPer-control version history, generated
9Diagram StudioHTMLThe working tool; the control set evaluates live against the drawing
10The BriefGeneratedThe cycle record, citing the controls each section evidences

The chain in one line. Framework states why · Design and Philosophy states how it was built · Control Guide states what must be true · Studio does it · Brief proves it · cycle history proves it over time.


16. Version history

VersionWhat changed and why
1.0Initial release. 111 techniques, 35 controls across six families.
2.0Scored against ten agency archetypes and failed its own test: no architecture could evidence M10 and Recover was empty. Added T6, M11, the RC and FO families, and obligation profiles.
3.0Completeness test against the 800-53 crosswalk found AT, PS, PE and MA unreached — the framework modeled the machines, not the people, buildings or suppliers. Added T7, T8, T9 with the WF, FC and LC families and 25 techniques. No new forms required.
4.0Depth. Every control rebuilt to a capability-leveled component model — 734 activities plus components, metrics and mappings. Build tooling introduced.
5.0IA cited once across sixty controls on the declared high ground → the ID family. Respond at 2 of 13 CSF outcomes → the EN family. D3FEND Deceive at zero controls → SM-7. Obligation profiles undeclarable → FO-7. FO-6 narrowed after duplicating LC-1. Retired CSF 1.1 identifiers corrected. 60 → 78 controls.
5.1Terminology audit: military organizational vocabulary removed throughout in favor of federal roles. This document rebuilt in full — its v3.0 predecessor stated sixty controls in prose while its adjacent table listed thirty-five, and its terrain table carried five of nine layers.

Denominator warning. Coverage scores computed against v4.0, v5.0 and v6.1 are not comparable to v6.1 scores — the roster grew and the risk weights were rebalanced. Control CE-6 requires the framework version to be recorded against every computed figure and the trend line to break visibly at the boundary.


17. Sources

Analytic and planning literature. Allen, "Cyber Maneuver and Schemes of Maneuver," The Cyber Defense Review, Vol. 5 No. 3 (2020) — source of the positional and temporal advantage definition and the durability-of-categories argument. ATP 2-33.4, Intelligence Analysis (2020) — source of the Screen → Analyze → Integrate → Produce process, structured analytic techniques, preparation of the environment, and confidence levels. Concepts are adopted; organizational structure is not.

Federal frameworks. NIST SP 800-53 Rev. 5 (20 families, ~1,196 controls); NIST SP 800-53A (assessment procedures); NIST SP 800-53B (baselines); NIST SP 800-37 Rev. 2 (RMF); NIST CSF 2.0 (6 functions, 22 categories, 106 subcategories); CISA Zero Trust Maturity Model v2.0; NIST SP 800-207; CISA TIC 3.0 Program Guidebook; FISMA; OMB M-22-09.

Structural models. ISACA COBIT 2019 — the component model and capability levels used for control depth. MITRE ATT&CK — the matrix layout convention. MITRE D3FEND — defensive countermeasure reference. TBM Council Technology Business Management Taxonomy — the allocation model mirrored by the Defense Tower Model. Structure only; no text from these works is reproduced.

Federal Reference Agency archetype. A generic public-facing U.S. civilian agency: public service portals, internal case-processing systems, sensitive mission records with PII and financial data, public open-data APIs, a cloud-forward multi-VPC estate delivered through modern software practice, ICAM and zero-trust adoption under OMB M-22-09, and FISMA governance with annual Inspector General audits. Any agency adopts the framework by substituting its own systems into this archetype.


Prepared as an original synthesis. Unclassified and illustrative; built from public sources only; contains no agency-specific information. ATT&CK® and D3FEND™ are trademarks of The MITRE Corporation and COBIT® is a trademark of ISACA; neither organization endorses this framework.