The Analytic Scheme of Maneuver for Federal Network Defense
Version 6.1 · Unclassified / Illustrative
A recommended reference framework applying an analytic scheme of maneuver to any U.S. federal agency network, built against a generic Federal Reference Agency model. Agency-agnostic by construction; adopters substitute their own systems, boundaries and mission threads.
Executive summary
The problem. Federal network defense is still run as garrison security — static controls, perimeter guards, compliance checklists, and reaction. The unit of planning is the control, and controls do not move. Meanwhile the adversaries that matter behave like a maneuvering force: nation-state collectors after sensitive case records, fraud rings working public service portals, and ransomware crews exploiting deadline-sensitive availability. They seek positional and temporal advantage, mass at a decisive point, and exploit whichever side has the slower decision loop.
The reframe. ASOM-Fed treats cyber defense as a maneuver problem led by intelligence analysis. It combines two mature analytic bodies rarely brought together: the scheme of maneuver, which describes how a defense is arrayed and moved to gain positional advantage, and the structured analytic process of Screen → Analyze → Integrate → Produce, which supplies confidence levels, priority intelligence requirements and disciplined course-of-action development.
The result. An intent-driven, intelligence-led plan that arrays defensive analytic and response capability across cyber terrain to seize and hold positional and temporal advantage, then continuously re-arrays as the situation develops. The agency stops being a wall that reacts and becomes a thinking defense that holds ground it has chosen.
What version 6.1 contains.
| 11 forms of maneuver | Durable categories that outlive tool churn |
| 154 cataloged techniques | Each with a falsifiable success indicator |
| 78 assessable controls | Across 14 families, inheriting all 20 SP 800-53 Rev. 5 families |
| 784 capability-leveled activities | Graded 2–5 on the process capability scale |
| 10 terrain layers | Five CISA ZTMM pillars plus four ASOM-Fed additions, plus cross-cutting |
| 77 terrain × form cells | The board coverage is actually scored on |
| 4 defensive postures | Passive, active, reactive, directing |
1. What this framework borrows, and what it deliberately does not
ASOM-Fed applies maneuver concepts to a civilian federal mission. That combination needs stating precisely, because the value is in the analytic structure and the risk is in importing organizational assumptions that do not belong in a federal agency.
What is borrowed — analytic and planning concepts:
- Terrain. That a defense is emplaced on ground with characteristics, and that position determines how an adversary moves.
- Key terrain and decisive points. That a small number of elements confer disproportionate control, and that identifying them is a judgment leadership must make and justify.
- Forms of maneuver. That there is a small, durable set of things a defense can do, distinct from the perishable techniques that realize them.
- Main effort. That priority must be concentrated somewhere and subordinated elsewhere, and that this is a decision rather than an emergent property.
- Tempo. That the rate of decision relative to the adversary is the measure that decides engagements.
- Campaign phasing. That a defense has phases with different objectives, and that declaring a phase should change what happens.
- Structured analysis. Explicit confidence levels, priority intelligence requirements, and course-of-action development.
What is deliberately not borrowed:
- Rank, chain of command and military organizational structure. ASOM-Fed uses federal roles — Authorizing Official, CISO, ISSO, SOC, threat intelligence function, system and data owners. There is no commander, no staff-section numbering, and no military hierarchy anywhere in the model. Authority in this framework is the authority a federal agency actually has, exercised through the instruments it actually uses.
- Offensive operations of any kind. "Spoiling attack" and "counterattack" are named from the analytic vocabulary but are strictly defensive in content — pre-emptive blocking, patching, hunting and eviction inside the agency's own authorization boundary. Nothing in ASOM-Fed contemplates action outside it. Control CG-3 requires that limit to be written down rather than inferred.
- Kinetic or physical-harm framing. The vocabulary describes information systems. Where physical consequence is genuinely in scope — operational technology, facilities — it is treated as a safety and continuity concern under FO-4 and FC-4.
- Unilateral action. Every response authority in the framework is bounded by approved rules of engagement, statutory availability floors, privacy authority and the agency's own disclosure obligations.
An agency adopting ASOM-Fed adopts a planning method, not a posture toward the world.
2. Doctrinal and policy foundations
2.1 Maneuver and positional advantage
Cyber maneuver is defined in the source literature as actions taken within and through cyberspace to achieve physical, technical and cognitive positional and temporal advantage over an adversary. A scheme of maneuver specifies which categories of maneuver apply and in what sequence.
The consequential idea is that categories of maneuver are durable while the techniques that realize them are perishable. Leaders therefore need intent, not tool mastery; engineers can re-tool without invalidating the plan. Every structural decision in this framework follows from taking that seriously.
2.2 The analytic process
The analytic engine is Screen → Analyze → Integrate → Produce, supported by structured analytic techniques, systematic preparation of the environment, and products that carry explicit confidence levels and are driven by priority intelligence requirements. Control CE-3 makes confidence mandatory and measures whether the scale is actually used; a function that never publishes a low-confidence assessment is unfalsifiable rather than careful.
2.3 The federal terrain
The ground ASOM-Fed maneuvers on is the federal zero-trust stack: the CISA Zero Trust Maturity Model (five pillars, three cross-cutting capabilities, maturity Traditional → Initial → Advanced → Optimal); NIST SP 800-207 Zero Trust Architecture (policy decision and enforcement points); Trusted Internet Connections 3.0; Continuous Diagnostics and Mitigation; FISMA with the NIST Risk Management Framework, SP 800-53 Rev. 5 and CSF 2.0; and OMB M-22-09.
3. The core translation
This crosswalk is the framework's reference point. Every later section uses it to keep operational intent legible to both agency leadership and engineers.
| Analytic term | Federal-network meaning | Reference-agency instantiation |
|---|---|---|
| Accountable authority | Authorizing Official or CISO who owns risk and intent | Agency CISO / Authorizing Official |
| Defensive intent | Defensive end-state plus acceptable risk, in one paragraph | "Protect mission-transaction integrity and sensitive mission records; degrade gracefully, never fail open" |
| Scheme of maneuver | The defensive campaign plan — which maneuvers, where, in what sequence | Campaign for the public service portal and case-processing systems |
| Key terrain | Systems and data whose control confers decisive advantage | Public Service Portal, sensitive records, ICAM identity plane, mission-staff workflow |
| Decisive point | Where control unhinges the adversary's plan | Identity policy decision point; the CI/CD pipeline |
| Avenues of approach | Attack paths and exploitable surface | Public portals, external-user accounts, cloud APIs, contractor supply chain, maintenance paths |
| Mobility corridors | Lateral-movement paths | Flat segments, over-permissioned service accounts, shared cloud roles |
| Main effort | Where defensive priority is concentrated | Sensitive records and the identity plane |
| Preparation of the environment | Cyber Preparation of the Environment (CPE) | Map the portal attack surface and threat courses of action |
| Priority intelligence requirements | Priority Cyber Intelligence Requirements (PCIR) | "Are external-user accounts being taken over?" |
| Defensive actions | Active response — block, isolate, deceive, disrupt, evict | Auto-revoke session; quarantine; deploy decoy |
| Running estimate | Cyber Running Estimate — living situational picture | Fused SOC and hunt board |
| Tempo | Rate of decision and action relative to the adversary | Mean time to detect, decide and contain, against adversary dwell |
4. The cyber terrain model
You cannot have a scheme of maneuver without terrain. ASOM-Fed models the federal enterprise as nine terrain layers plus one cross-cutting domain. Five layers are the CISA ZTMM pillars taken unchanged; four are ASOM-Fed's own, each added because a measurable part of a federal estate had nowhere to stand without it.
Each layer carries a metaphor that is load-bearing rather than decorative: it tells a planner what kind of ground they are defending, and therefore which moves are available on it.
| ID | Terrain layer | Character | Key terrain / decisive point in the reference agency |
|---|---|---|---|
T1 | Identity | The high ground | ICAM and policy decision point; privileged, external-user and mission-staff identities. Whoever holds it controls movement everywhere else. |
T2 | Devices | The entry fords | Managed and unmanaged endpoints; mission-staff and contractor devices; privileged access workstations. |
T3 | Networks | The corridors | Segmentation, TIC 3.0 trust zones, east-west and cloud peering paths. The only layer where an adversary can meaningfully be canalized. |
T4 | Applications and Workloads | Urban terrain | Public Service Portal, Case Processing System, APIs; the CI/CD pipeline as a decisive point. Dense, complex, easiest to lose track of. |
T5 | Data | The objective | Sensitive case records, PII, financial data, audit logs. The reason the campaign exists. |
T6 | Operational Technology | Contested ground | Building management, physical access control, engineering workstations. Cannot be patched or restarted on the defender's schedule; loss has physical consequence. Added v2.0. |
T7 | Workforce | The people who operate the estate | Privileged administrators, caseworkers, approval authorities, contract support. The only terrain that is simultaneously the workforce operating it. Added v3.0. |
T8 | Facilities | The ground you stand on | Data centers, field offices, alternate recovery sites, and the vendor maintenance paths reaching through them. Added v3.0. |
T9 | Supply Chain | Lines of communication | Cloud and managed service providers, build dependencies, hardware and firmware vendors. Frequently the actual intrusion path. Added v3.0. |
TX | Cross-Cutting | The enablers | Visibility and analytics is reconnaissance; automation and orchestration is mobility; governance is decision authority. Not ground, but what lets you move on it. |
Deliberate divergence from CISA. The five pillars are ZTMM's, verbatim. T6 through T9 and the consolidation of ZTMM's three cross-cutting capabilities into a single TX domain are ASOM-Fed's own. The consolidation is lossy: an agency reporting ZTMM maturity per cross-cutting capability cannot map those three onto TX one-to-one and should continue reporting them separately.
The deliverable of this step is a one-page Cyber Terrain Overlay, refreshed at a defined cadence and on material architectural change. Controls TM-1 through TM-7 specify it; TM-6 requires both triggers, because a program honoring only the calendar will plan from a map that a deployment invalidated the week after it was drawn.
Standing finding. Every terrain layer ASOM-Fed added has dedicated controls. Of the five inherited ZTMM pillars, only T1 does, added in v5.0. T2 Devices holds no dedicated control and is the only layer with none — recorded as a v6.1 input rather than resolved here.
5. The ASOM cycle
A repeatable, intelligence-led loop fusing the structured analytic process with maneuver planning. Six steps; the loop turns continuously, and the objective is to run it faster and at higher confidence than the adversary can adapt.
| # | Step | Analytic root | What happens | Output |
|---|---|---|---|---|
| 1 | FRAME | Screen; analytic design | State the defensive intent; set priority cyber intelligence requirements; define what positional advantage means this cycle | Intent paragraph and PCIR list |
| 2 | MAP | Preparation of the environment | Refresh the terrain overlay; enumerate avenues; build most-likely and most-dangerous threat courses of action | Terrain overlay and threat COA sketch |
| 3 | ARRAY | Scheme design | Choose forms of maneuver, main and supporting effort, decisive points, branches and sequels | The scheme of maneuver |
| 4 | MANEUVER | Execution | Emplace obstacles, reposition sensors, execute pre-authorized defensive actions per the scheme | Executed actions and change record |
| 5 | FUSE | Analyze; integrate | Apply structured analytic techniques; assign confidence levels | Fused assessment |
| 6 | ASSESS | Produce; re-frame | Measure advantage; continue, exploit or transition; publish the Brief; loop to 1 | Cycle record and posture result |
Ownership is split deliberately. Steps 1, 2 and 5 belong to the threat intelligence function; step 4 to the SOC; steps 3 and 6 to the accountable authority. Splitting ownership this way is what stops the loop degrading into a status meeting. Control CE-1 requires the cadence to hold and records a lapse as a finding — the cycle is otherwise sacrificed exactly when it is most needed, because the SOC is busy precisely when it would be most valuable.
6. The maneuver catalog
The durable categories of maneuver, recast as defensive forms for a federal network. Each is intent-first: leadership picks the intent and mechanism; engineers pick the technique. A scheme of maneuver names a sequence of these with one designated main effort.
| ID | Form | Intent | Mechanism in the reference agency |
|---|---|---|---|
M1 | Screen / Guard | Early warning and reaction time | External attack-surface monitoring, threat intelligence, perimeter canaries, external-login geography |
M2 | Defense in Depth | No single failure is decisive | Layered controls across all terrain; TIC 3.0 zones; sensitive records behind their own enforcement point |
M3 | Envelopment | Make identity the decisive plane | Phishing-resistant MFA, continuous authorization, conditional access, just-in-time privilege |
M4 | Obstacle / Canalization | Force the adversary onto ground you own | Microsegmentation, egress control, allow-listing, denied east-west between tiers |
M5 | Ambush | Trade space for information and time | Honeypots, decoy credentials and documents, honeytokens in the data layer |
M6 | Delay | Buy decision time; prevent culmination | Rate limiting, step-up authentication, session throttling, bulk-download throttling |
M7 | Counterattack | Seize initiative; evict early | Hypothesis-driven hunting from FUSE; automated containment playbooks |
M8 | Isolation / Retrograde | Fail secure; give ground to preserve the mission | Automated segment severing, session revocation, graceful degradation preserving transaction integrity |
M9 | Spoiling Attack | Disrupt adversary staging pre-attack | Act on CISA, sector and law-enforcement reporting to pre-block infrastructure and pre-patch targeted weaknesses |
M10 | Exploitation & Pursuit | Convert contact into durable advantage | Harvest indicators into detections; close the avenue; update overlay and requirements; share to the community |
M11 | Reconstitution | Restore the mission on evidence, not on hope | Declare recovery objectives; hold recovery outside the production identity plane; test the rebuild path including identity; verify restored data |
Principal ground, posture and allocation weight. Ground is the terrain layer the form is principally concerned with — advisory, since techniques within a form may sit on other layers. Posture is defined in §7. Weight is the residual-risk reduction attributed to the form when fully operational, used by the Tower Model's allocation arithmetic.
| ID | Form | Principal ground | Posture | Weight |
|---|---|---|---|---|
M1 | Screen / Guard | T3 | Reactive | 7 |
M2 | Defense in Depth | T3 | Passive | 12 |
M3 | Envelopment | T1 | Passive | 15 |
M4 | Obstacle / Canalization | T3 | Passive | 10 |
M5 | Ambush | T5 | Active | 9 |
M6 | Delay | T4 | Reactive | 8 |
M7 | Counterattack | TX | Active | 11 |
M8 | Isolation / Retrograde | T3 | Reactive | 10 |
M9 | Spoiling Attack | TX | Active | 6 |
M10 | Exploitation & Pursuit | TX | Active | 5 |
M11 | Reconstitution | TX | Reactive | 7 |
Rebalanced in v6.1. The weights previously summed to 117, not 100 — the distribution summed to 100 across the original ten before
M11was added in v2.0 at weight 8, and nothing rebalanced it, so a design evidencing everything reported 117% residual risk reduction. The weights above are a proportional rescale to 100 preserving the original order. This is a denominator change: coverage and residual-risk figures computed against v6.1 and earlier are not comparable, and control CE-6 requires the trend line to break here.
7. Posture — what holds when nobody is watching
Introduced in v5.0. The bands above — shaping, in contact, consolidation — describe when a form does its work. Posture is orthogonal and answers a different question: who initiates, and must a person be present for it to work?
| Posture | Definition | Under degraded tempo |
|---|---|---|
| Passive | Operates without human action once emplaced | Unchanged |
| Active | Defender-initiated, on the agency's own timeline | Deferred, not lost |
| Reactive | Triggered by adversary action, person in the loop under time pressure | Degrades |
| Directing | Sets the conditions the other three operate under | — |
Why this matters operationally. Only 16 of 78 controls (22%) assure a defense that operates without a person. That is the proportion an adversary meets on a federal holiday, during a shift handover, through a hiring gap or across a contract transition — precisely the conditions control TA-5 requires an agency to identify, and precisely the windows adversaries select.
M2, M3 and M4 are the passive spine. An agency under-invested in depth, envelopment and canalization has bought a defense that works only while somebody is watching. The recommended measure is passive coverage of decisive points, because it is a resilience argument that does not depend on headcount.
8. Phasing the campaign
Phasing lets agency leadership see cyber defense as a campaign with a main effort per phase, rather than an undifferentiated round-the-clock grind.
| Phase | Objective | What it means operationally | Dominant forms |
|---|---|---|---|
| 0 — Shape | Set conditions | Continuous preparation of the environment, zero-trust hardening, partnerships, threat intelligence | M1 · M2 · M3 · M9 |
| I — Deter | Raise adversary cost | Visible hardening, a deception grid, a stated attribution posture | M3 · M4 · M5 |
| II — Seize Initiative | Contest first contact | Detect early, canalize movement, buy decision time | M1 · M4 · M6 |
| III — Dominate | Defeat the attempt | Hunt, contain, evict | M7 · M8 · M5 |
| IV — Stabilize | Restore secure operations | Eradicate, verify, preserve availability through recovery | M8 · M10 · M11 |
| V — Restore | Hand back to steady state | Recover, harden, update doctrine and intelligence requirements | M11 · M10 · M2 |
Declaration must change behavior. Control CG-2 requires at least one consequential control to be keyed to phase — pre-authorized response scope, session lifetime, or cycle cadence — and its assessment tests what materially changed at the last transition. A phase declaration that alters no authorization, no allocation and no configuration is a status field, not a campaign.
9. Roles, authority and rules of engagement
9.1 Roles
Six roles, all of them federal. There is no military structure in this model.
| Code | Role | Owns |
|---|---|---|
AO | Authorizing Official / CISO | Defensive intent, risk acceptance, the scheme of maneuver, phase declaration |
CTI | Cyber threat intelligence function | FRAME, MAP and FUSE; priority cyber intelligence requirements; threat courses of action; confidence levels |
SOC | Security operations | MANEUVER; execution of pre-authorized defensive actions; declaration and triage |
HT | Hunt team | Hypothesis-driven hunting, engagement reconstruction, eradication verification, effectiveness validation |
TO | Terrain owners — system, data and platform owners | Emplacing moves on their own ground; recovery objectives; asset ownership |
GOV | Governance, RMF and ISSO function | Rules of engagement, findings disposition, control inheritance, obligation profile |
Every control in the catalog carries a RACI against these six. Two assignments are deliberate and worth stating: SM-6 effectiveness validation is the hunt team's rather than the terrain owner's, because the party that emplaced a move is the wrong party to certify it; and WF-4 insider risk is governance's rather than the SOC's, because it is the one control where the operational instinct to investigate first is the wrong instinct.
9.2 Pre-authorized defensive actions
Define in advance which actions the SOC may execute without escalation — for example, revoking a session on confirmed account takeover — and which require the Authorizing Official, such as degrading a public service. This is the single highest-leverage and cheapest control in the framework, because it costs no technology: control TA-1's segment measurement typically shows the decide segment dominating the decision loop, and decide latency is mostly the time spent locating somebody with authority.
Authorizations must be bounded by condition, scope and duration, and keyed to campaign phase. An authority so broad it permits degrading a public service without reference will not survive its first use; one so narrow that every real action falls outside it changes nothing.
9.3 Legal and statutory bounds
Rules of engagement carry a constraint the rest of the framework does not: some defensive actions have statutory consequences. Degrading a service where statute sets a deadline, or acting on a system holding regulated records, is not purely a security decision. Control FO-5 requires those availability floors to be identified, legally confirmed, and carried into the rules of engagement and the pre-authorized set, so an operator at three in the morning knows which degradations are unavailable. Control CG-3 requires the boundary limit — no action outside the agency's own authorization boundary — to be written rather than inferred.
10. Assessment — measuring advantage
10.1 Measures of performance — are we doing the maneuvers right?
Percentage of key terrain behind a policy enforcement point; deception coverage of the data layer; percentage of defensive actions pre-authorized; terrain-overlay freshness; priority intelligence requirements answered per cycle; percentage of decisive points meeting the protection floor.
10.2 Measures of effectiveness — are we winning?
The signature metric is temporal advantage: defender decision tempo — mean time to detect, decide and contain — measured against adversary dwell time. A cycle is won when temporal advantage is positive at the required confidence.
Supporting measures: positional advantage (share of attempts canalized into instrumented terrain; attempts stopped before the data layer); cost imposition (decoy interactions; forced re-tooling); resilience (incidents contained without loss of statutory availability); passive coverage of decisive points; and the ZTMM maturity vector per pillar per quarter.
10.3 Honesty conditions
Temporal advantage is offered as the signature metric precisely because, unlike a maturity score, it can be lost. A program can be well-governed, fully staffed and still behind. Three controls exist to stop the metric flattering its owner:
- TA-1 requires the loop to be measured in three segments — detect, decide, contain — because they fail for different reasons and the binding constraint is usually the middle one, which no detection investment shortens.
- TA-2 requires the adversary dwell estimate to carry its stated bias. Dwell is observable only in intrusions that were eventually found, which is a sample biased toward slow adversaries. The signature metric therefore rests half on measurement and half on a cited assumption, and that should be visible in the result rather than concealed inside a ratio.
- TA-3 requires the threshold's approval date to be recorded relative to first measurement. A threshold set after the first measurement will be set where the agency already passes, producing a governed-looking metric that has never once reported a problem.
11. Governance mapping — compliance as a by-product
ASOM-Fed outputs map onto federal obligations, so the agency earns compliance while actually defending.
| Obligation | How ASOM-Fed satisfies it |
|---|---|
| NIST CSF 2.0 | FRAME feeds Govern; CPE feeds Identify; M2–M4 and M8 feed Protect; M1, M5 and FUSE feed Detect; M6–M8 and the EN family feed Respond; M8, M10 and M11 feed Recover. 93 of 106 subcategories are covered; the remaining 13 are excluded on the record with stated reasons. |
| NIST RMF | The terrain overlay informs Categorize and Select; maneuvers are Implement; FUSE and ASSESS constitute continuous Monitor and ongoing authorization. |
| SP 800-53 Rev. 5 | Every control cites the baseline controls it inherits from. All twenty families are reached. CG-5 requires inheritance to be verified against the specific assessment cited, not asserted at family level. |
| FISMA | The Cyber Running Estimate and the cycle Brief series become audit evidence of a functioning, continuously monitored program. |
| OMB M-22-09 | The ZTMM maturity vector is the zero-trust progress report. |
| Privacy and CUI | FO-1 and FO-2 place privacy terrain and controlled unclassified information on the overlay with the authority under which each is held. |
Compliance is exhaust, not the objective. Because every control produces its evidence by being performed, the marginal assessment burden is low: the terrain overlay, asset register, findings list, posture computation and cycle history are generated rather than authored.
12. The control set
SP 800-53 Rev. 5 provides roughly 1,196 controls across twenty families and is the established language of federal control assessment. ASOM-Fed neither replaces nor duplicates it. What has never existed is an assessable specification for the maneuver layer: nothing in the baseline requires an agency to know its terrain, designate a main effort, measure its decision tempo, reconstruct an engagement, or prove it can perform a form of maneuver at all.
Seventy-eight controls across fourteen families fill that gap. Family prefixes are deliberately distinct from the twenty SP 800-53 identifiers so references remain unambiguous when both catalogs appear together.
| ID | Family | N | What it governs |
|---|---|---|---|
TM | Terrain Management | 7 | Inventory, classification, weighting, zones, connections, currency, ownership |
KT | Key Terrain and Decisive Points | 5 | What must not be lost, and whether an adversary can reach it |
ID | Identity Terrain | 5 | The identity plane as ground: planes, credentials, assurance, assertions, authorization integrity |
DV | Devices Terrain | 5 | The entry fords: device identification, posture as an access precondition, sensor liveness, execution control, lifecycle and sanitization |
SM | Scheme of Maneuver | 7 | Choosing moves, assigning them to ground, honest implementation states, deception emplacement |
TA | Tempo and Temporal Advantage | 5 | Making speed of decision measurable, governed and pre-authorized |
EN | Engagement and Pursuit | 6 | Declaration, triage, reconstruction, evidence, escalation, eradication, communication |
CE | Cycle Execution and Assurance | 7 | Cadence, intelligence requirements, posture computation, the evidentiary record |
CG | Command and Governance | 5 | Intent, phase, rules of engagement, findings disposition, inheritance |
RC | Reconstitution and Recovery | 5 | Recovery held outside the blast radius and proven by exercise |
FO | Federal Obligations | 7 | Terrain that exists because the organization is a federal one |
WF | Workforce Terrain | 5 | The people who operate the estate, held as ground |
FC | Facilities Terrain | 4 | Buildings, zones, and the maintenance paths reaching through them |
LC | Lines of Communication | 5 | Suppliers, components, and the routes they reach the estate on |
Note on the
CGfamily name. "Command and Governance" retains command in the sense the federal Incident Command System uses it — a defined decision authority during an incident — not in a military sense. The family concerns the Authorizing Official's intent, phase declaration, rules of engagement and findings disposition. Agencies preferring "Direction and Governance" may rename it locally; theCGprefix and control IDs are stable either way.
Control depth. Each control carries a purpose, a goals cascade, a discussion of the failure mode it addresses, capability-leveled activities graded 2 to 5, a RACI, information flows, people and skills, policies, culture and behavior, services and infrastructure, metrics, mappings, evidence and an examine/interview/test procedure. There are 784 activities in total.
Assessed once, not twice. Every control declares whether it is inherited, extended or net new. Genuinely net new — assess in full: KT-1, KT-4, SM-3, SM-4, SM-7, the entire TA family, CE-4 and CE-6.
Where controls fail socially. Most controls in this catalog are defeated by incentive rather than technology, and each states how. SM-3 is defeated by optimistic self-declaration of implementation state; CG-4 by anonymous, permanent risk acceptance; TA-4 by second-guessing an operator who acted within written authority; WF-3 by sanctioning individuals for failing a phishing simulation, which trains concealment of real incidents.
13. Implementation roadmap
The catalog is not intended to be adopted wholesale on day one. This sequence delivers assessable value at each step.
| Step | Window | Controls | Exit criteria |
|---|---|---|---|
| Establish the ground | 0–60 days | TM-1 … TM-7, CG-1 | An authoritative, owned, weighted terrain overlay and a signed defensive intent |
| Name what matters | 60–120 days | KT-1 … KT-5 | Decisive points designated with justifications; reachability computed for the first time |
| Hold the high ground | 2–5 months | ID-1 … ID-5 | Identity planes and trust edges mapped; assurance matched to terrain; M3's indicator tested with a captured credential |
| Hold the fords | 3–6 months | DV-1 … DV-5 | Devices identified as terrain; posture enforced as an access precondition; sensor coverage and liveness measured rather than assumed |
| Array the defense | 3–6 months | SM-1 … SM-7, CG-2, CG-3 | Moves assigned to ground with honest implementation states; deception emplaced; approved rules of engagement |
| Achieve tempo | 6–12 months | TA-1 … TA-5 | Decision loop measured by segment; threshold approved and governed; response pre-authorized |
| Fight and pursue | 6–12 months | EN-1 … EN-6 | Declaration criteria; reconstruction before closure; evidence preserved against dwell; verified eradication |
| Run the loop | Continuous | CE-1 … CE-7, CG-4, CG-5 | Cadenced cycles producing a trended, evidence-bearing record |
| Hold the wider ground | 6–12 months | WF, FC, LC families | Workforce, facilities and supply-chain terrain on the overlay with access recorded |
| Prove you can come back | Continuous | RC-1 … RC-5, FO-1 … FO-7 | Recovery held outside the blast radius and demonstrated, against a declared obligation profile |
Sequencing note. Identity moves early because everything downstream depends on it: KT-4 reachability computes over authorization paths, EN-5 eradication requires identity-plane revocation, and M3 is the usual main effort. An agency deferring the ID family will find several later controls unassessable.
Success at eighteen months: measurable positive temporal advantage on the main effort; demonstrable to the agency Inspector General as continuous monitoring; a stated degraded posture; and a self-improving practice in which each engagement updates the terrain, the intelligence requirements and the maneuver catalog.
14. Why this is different
ASOM-Fed prioritizes intent over tools, so it survives tool churn and lets leadership direct without being engineers. It is intelligence-led, so every maneuver is driven by analysis with explicit confidence rather than by alerts alone. It is terrain-anchored, forcing prioritization onto what actually matters. It treats compliance as exhaust, satisfying FISMA, zero-trust and RMF obligations as a by-product of real defense. It is measurable through one honest scoreboard that can be lost. And it is falsifiable: every release has been scored against real architectures and against its own crosswalk, and the findings have repeatedly condemned the framework rather than the agencies.
15. The product suite
Each artifact is generated from one source, so they cannot disagree about what the framework contains.
| # | Artifact | Format | Role in the chain |
|---|---|---|---|
| 1 | ASOM-Fed Framework | Word | This document. The doctrine: why defense is a maneuver problem |
| 2 | Design and Philosophy | Word | Why the framework is shaped as it is, and the criteria for extending it |
| 3 | Application and Control Guide | Word | 78 controls with activities, components, evidence, assessment |
| 4 | Defensive Maneuver Matrix | Word | 11 forms, 154 techniques, 77 cells, and the controls assessing each |
| 5 | Asset Register and Tower Allocation | Word | Assets on terrain, defensive weight, mission bill of defense |
| 6 | Posture and Tower Model | Markdown | Which controls hold when nobody is watching |
| 7 | Control Catalog | CSV / JSON | Machine-readable, for GRC ingestion |
| 8 | Changelog | Markdown | Per-control version history, generated |
| 9 | Diagram Studio | HTML | The working tool; the control set evaluates live against the drawing |
| 10 | The Brief | Generated | The cycle record, citing the controls each section evidences |
The chain in one line. Framework states why · Design and Philosophy states how it was built · Control Guide states what must be true · Studio does it · Brief proves it · cycle history proves it over time.
16. Version history
| Version | What changed and why |
|---|---|
| 1.0 | Initial release. 111 techniques, 35 controls across six families. |
| 2.0 | Scored against ten agency archetypes and failed its own test: no architecture could evidence M10 and Recover was empty. Added T6, M11, the RC and FO families, and obligation profiles. |
| 3.0 | Completeness test against the 800-53 crosswalk found AT, PS, PE and MA unreached — the framework modeled the machines, not the people, buildings or suppliers. Added T7, T8, T9 with the WF, FC and LC families and 25 techniques. No new forms required. |
| 4.0 | Depth. Every control rebuilt to a capability-leveled component model — 734 activities plus components, metrics and mappings. Build tooling introduced. |
| 5.0 | IA cited once across sixty controls on the declared high ground → the ID family. Respond at 2 of 13 CSF outcomes → the EN family. D3FEND Deceive at zero controls → SM-7. Obligation profiles undeclarable → FO-7. FO-6 narrowed after duplicating LC-1. Retired CSF 1.1 identifiers corrected. 60 → 78 controls. |
| 5.1 | Terminology audit: military organizational vocabulary removed throughout in favor of federal roles. This document rebuilt in full — its v3.0 predecessor stated sixty controls in prose while its adjacent table listed thirty-five, and its terrain table carried five of nine layers. |
Denominator warning. Coverage scores computed against v4.0, v5.0 and v6.1 are not comparable to v6.1 scores — the roster grew and the risk weights were rebalanced. Control CE-6 requires the framework version to be recorded against every computed figure and the trend line to break visibly at the boundary.
17. Sources
Analytic and planning literature. Allen, "Cyber Maneuver and Schemes of Maneuver," The Cyber Defense Review, Vol. 5 No. 3 (2020) — source of the positional and temporal advantage definition and the durability-of-categories argument. ATP 2-33.4, Intelligence Analysis (2020) — source of the Screen → Analyze → Integrate → Produce process, structured analytic techniques, preparation of the environment, and confidence levels. Concepts are adopted; organizational structure is not.
Federal frameworks. NIST SP 800-53 Rev. 5 (20 families, ~1,196 controls); NIST SP 800-53A (assessment procedures); NIST SP 800-53B (baselines); NIST SP 800-37 Rev. 2 (RMF); NIST CSF 2.0 (6 functions, 22 categories, 106 subcategories); CISA Zero Trust Maturity Model v2.0; NIST SP 800-207; CISA TIC 3.0 Program Guidebook; FISMA; OMB M-22-09.
Structural models. ISACA COBIT 2019 — the component model and capability levels used for control depth. MITRE ATT&CK — the matrix layout convention. MITRE D3FEND — defensive countermeasure reference. TBM Council Technology Business Management Taxonomy — the allocation model mirrored by the Defense Tower Model. Structure only; no text from these works is reproduced.
Federal Reference Agency archetype. A generic public-facing U.S. civilian agency: public service portals, internal case-processing systems, sensitive mission records with PII and financial data, public open-data APIs, a cloud-forward multi-VPC estate delivered through modern software practice, ICAM and zero-trust adoption under OMB M-22-09, and FISMA governance with annual Inspector General audits. Any agency adopts the framework by substituting its own systems into this archetype.
Prepared as an original synthesis. Unclassified and illustrative; built from public sources only; contains no agency-specific information. ATT&CK® and D3FEND™ are trademarks of The MITRE Corporation and COBIT® is a trademark of ISACA; neither organization endorses this framework.