Generated from coverage.py against references.json and the v4.0 catalog.
build.py validates the forward direction: every ASOM-Fed control carries mappings. This document covers the reverse: which referenced outcomes have no ASOM-Fed control pointing at them.
0. The three references need different answers
The proposition "we should have a control for every outcome" is right for one reference, right at one level for a second, and would break the framework if applied to the third.
| Reference | Reverse coverage a goal? | Why |
|---|---|---|
| CSF 2.0 | Yes | 106 outcome-level subcategories. Reverse coverage is a legitimate completeness claim and every gap should be a recorded decision. |
| D3FEND | At tactic level only | 7 tactics — reverse coverage is meaningful. Technique level is not: D3FEND holds hundreds of countermeasures, and mapping each would make ASOM-Fed a countermeasure ontology with different labels rather than a planning model. |
| SP 800-53 | No — and pursuing it would break the framework | ~1,196 controls that ASOM-Fed explicitly inherits rather than duplicates. CG-5 exists solely to prevent duplicate assessment, and the design documentation states that a framework creating a parallel compliance burden will not be adopted. Family reach (20/20) is the right measure here, not control-level reverse coverage. |
1. Two invalid identifiers — corrected
Both were inherited from the published v3.0 catalog and both cite retired CSF 1.1 identifiers in a CSF 2.0 mapping:
| Control | Was | Problem | Now |
|---|---|---|---|
RC-1 | ID.BE-05 | ID.BE Business Environment does not exist in CSF 2.0; the category was absorbed into GV.OC | GV.OC-04 |
RC-4 | PR.DS-06 | Retired in CSF 2.0; PR.DS retains only 01, 02, 10, 11 | RC.RP-03 |
The RC-4 correction is doubly useful: RC.RP-03 is integrity of restoration assets verified before use, which is precisely that control's subject, so the fix simultaneously closes an uncovered subcategory.
These are live defects in the shipped v3.0 CSV and DOCX. The forward validator did not catch them because it checked only that the function prefix was valid — ID and PR both are. Validity is now checked against the full subcategory list.
Confidence note.
references.jsonreconstructs the CSF 2.0 subcategory list to the published 6 / 22 / 106 structure. TheID.BEfinding is high confidence — the whole category moved in 2.0. ThePR.DS-06finding depends on my reconstruction being right at the margins. Verify against the authoritative NIST Core before this drives a published claim.
2. CSF 2.0 reverse coverage — 58 / 106 (55%)
| Category | Name | Covered |
|---|---|---|
| GV.OC | Organizational Context | 3/5 |
| GV.RM | Risk Management Strategy | 3/7 |
| GV.RR | Roles, Responsibilities, Authorities | 3/4 |
| GV.PO | Policy | 1/2 |
| GV.OV | Oversight | 3/3 |
| GV.SC | Supply Chain Risk Management | 4/10 |
| ID.AM | Asset Management | 6/7 |
| ID.RA | Risk Assessment | 7/10 |
| ID.IM | Improvement | 3/4 |
| PR.AA | Identity, Authentication, Access Control | 3/6 |
| PR.AT | Awareness and Training | 2/2 |
| PR.DS | Data Security | 2/4 |
| PR.PS | Platform Security | 3/6 |
| PR.IR | Infrastructure Resilience | 3/4 |
| DE.CM | Continuous Monitoring | 2/5 |
| DE.AE | Adverse Event Analysis | 3/6 |
| RS.MA | Incident Management | 1/5 |
| RS.AN | Incident Analysis | 0/4 |
| RS.CO | Incident Response Reporting | 0/2 |
| RS.MI | Incident Mitigation | 1/2 |
| RC.RP | Incident Recovery Plan Execution | 5/6 |
| RC.CO | Incident Recovery Communication | 0/2 |
The headline: Respond is 2 of 13
Three categories are entirely uncovered, and all three sit in the second half of the incident lifecycle. Aggregated: Respond 2/13, Detect 5/11, Recover 5/8.
This is the same structural finding raised at the start of the v4.0 work, arriving from a third independent direction. The first two were the technique layer (M7, M9, M10 and M11 all parked on TX Cross-Cutting rather than on real ground) and the CSF function distribution (ID 42 citations against DE 6). Reverse coverage now says it in outcome terms: a framework whose signature metric is detect → decide → contain covers two of thirteen Respond outcomes.
3. Triage of the 48 uncovered subcategories
Proposed classification. Class A = genuine gap, a control should exist. Class B = legitimately out of scope, inherited from the baseline, should be recorded as a deliberate exclusion rather than left silent.
Class A — genuine gaps (24)
| Subcategory | Outcome | Why it belongs in ASOM-Fed |
|---|---|---|
RS.AN-03 | Analysis establishes what took place | M10's precondition is a dwell reconstruction; nothing assesses it |
RS.AN-06 | Investigation actions recorded | Required for M10.02 avenue closure verification |
RS.AN-07 | Incident data and metadata preserved | Feeds RC-4 restore point selection and TA-2 local dwell |
RS.AN-08 | Incident magnitude estimated | Feeds CE-4 posture and CG-4 disposition |
RS.MA-02 | Incident reports triaged and validated | This is the decide segment TA-1 measures |
RS.MA-03 | Incidents categorized and prioritized | Determines which maneuver applies |
RS.MA-04 | Incidents escalated or elevated | The escalation path TA-4 exists to shorten |
RS.MA-05 | Recovery criteria applied | The M8 → M11 transition decision |
RS.MI-02 | Incidents eradicated | M7 Counterattack eviction |
RS.CO-02 | Reporting to designated stakeholders | M10.05 exists as a technique with no assessing control |
RS.CO-03 | Information shared with stakeholders | Same |
RC.CO-03 | Recovery activities communicated | CE-7 covers internal briefing only |
RC.CO-04 | Public updates on recovery | Federal availability obligations make this material |
RC.RP-02 | Recovery actions selected and scoped | RC-3 sequences; nothing selects |
DE.AE-03 | Information correlated from multiple sources | CE-3 Fusion should map here |
DE.AE-04 | Impact and scope understood | Pairs with RS.AN-08 |
DE.AE-08 | Incidents declared against criteria | Declaration criteria feed CG-2 phase transition |
DE.CM-02 | Physical environment monitored | FC-2 crossing logs should map here |
DE.CM-06 | External provider activities monitored | LC-3 brokered access should map here |
DE.CM-09 | Computing hardware and software monitored | Core detection coverage |
PR.AA-02 | Identities proofed and bound to credentials | Proposed ID family |
PR.AA-03 | Users, services, hardware authenticated | Proposed ID family |
PR.AA-04 | Identity assertions protected | Proposed ID family |
GV.SC-09 | Supply chain practices integrated into programs | FO-6 scope adjacent |
Class B — out of scope, inherit and record (24)
GV.OC-02, GV.OC-05, GV.PO-02, GV.RM-04, GV.RM-05, GV.RM-06, GV.RM-07, GV.RR-03, GV.SC-01, GV.SC-02, GV.SC-03, GV.SC-05, GV.SC-06, ID.AM-02, ID.IM-04, ID.RA-07, ID.RA-08, ID.RA-10, PR.DS-02, PR.DS-10, PR.IR-03, PR.PS-04, PR.PS-05, PR.PS-06
These are enterprise risk management, policy lifecycle, procurement governance and platform hygiene outcomes that the 800-53 baseline already addresses and that carry no maneuver dimension. The recommendation is not to write controls for them but to record the exclusion, so that 55% reverse coverage reads as a stated scope rather than as an unexamined shortfall.
4. D3FEND reverse coverage — 6 of 7 tactics
| Tactic | Controls |
|---|---|
| Model | 20 |
| Isolate | 16 |
| Detect | 14 |
| Harden | 6 |
| Evict | 6 |
| Restore | 6 |
| Deceive | 0 |
Deception is unassessed
M5 Ambush is a full form of maneuver with 13 techniques, described in the framework's own reference material as the cheapest high-confidence detection available, and carrying a deception grid as the dominant effort of Phase I Deter. No control in the sixty assesses it.
An agency could stand up a complete deception grid, or none at all, and the control set would score identically. This is the sharpest single reverse-coverage finding in this analysis, and it compounds the Detect and Respond thinness rather than being independent of it — deception is precisely the cheap detection that would improve both.
14 controls carry no D3FEND tactic
SM-1, SM-3, SM-4, SM-6, TA-3, TA-5, CE-5, CE-6, CE-7, CG-1, CG-2, CG-4, CG-5, FO-5.
These are planning and governance controls, and D3FEND is a countermeasure ontology with nothing to map to for most of them. That is defensible — but it should be recorded as an explicit not applicable, planning layer rather than as an em-dash, so an absent mapping is distinguishable from a forgotten one.
5. SP 800-53 — reach, not coverage
20/20 families reached. Thinnest citations:
| Family | Citations | Controls |
|---|---|---|
MP Media Protection | 1 | FO-2 |
IA Identification and Authentication | 1 | WF-2 |
PT PII Processing and Transparency | 2 | FO-1 |
AT Awareness and Training | 3 | WF-1, WF-3 |
MA Maintenance | 3 | FC-3 |
IA at a single citation remains the standing finding: identity is T1, the declared high ground and the plane M3 Envelopment makes decisive, and the catalog reaches its 800-53 family once, incidentally, through a workforce control. The PR.AA-02/03/04 gaps above are the same finding expressed in CSF terms.
6. Recommendations
- Ratify the two CSF corrections and reissue the published CSV and DOCX — they currently ship retired CSF 1.1 identifiers.
- Record the 24 Class B exclusions as a scope statement, so 55% reverse coverage is a position rather than a shortfall.
- Add a deception control, or extend an existing one, so
M5is assessable. Zero of seven D3FEND tactics is the least defensible number in this report. - Address the Respond cluster.
RS.AN0/4 andRS.MA1/5 are the largest coherent gap, and they map onto M7 and M10 — the forms the reference estates were already least able to perform. - Decide the
IDfamily, which resolvesPR.AA-02/03/04and theIAsingle-citation finding together. - Replace D3FEND em-dashes with explicit N/A reasons so absence is distinguishable from omission.
Items 3, 4 and 5 are roster changes and belong to the framework owner. Items 1, 2 and 6 can proceed immediately.