COVERAGE

Reverse Coverage Analysis

The completeness test run backwards: which referenced outcomes have no control pointing at them, and why each gap is a decision.

ASOM-Fed v6.1 · Unclassified / Illustrative · agency-agnostic reference framework · built from public sources only

Generated from coverage.py against references.json and the v4.0 catalog.

build.py validates the forward direction: every ASOM-Fed control carries mappings. This document covers the reverse: which referenced outcomes have no ASOM-Fed control pointing at them.


0. The three references need different answers

The proposition "we should have a control for every outcome" is right for one reference, right at one level for a second, and would break the framework if applied to the third.

ReferenceReverse coverage a goal?Why
CSF 2.0Yes106 outcome-level subcategories. Reverse coverage is a legitimate completeness claim and every gap should be a recorded decision.
D3FENDAt tactic level only7 tactics — reverse coverage is meaningful. Technique level is not: D3FEND holds hundreds of countermeasures, and mapping each would make ASOM-Fed a countermeasure ontology with different labels rather than a planning model.
SP 800-53No — and pursuing it would break the framework~1,196 controls that ASOM-Fed explicitly inherits rather than duplicates. CG-5 exists solely to prevent duplicate assessment, and the design documentation states that a framework creating a parallel compliance burden will not be adopted. Family reach (20/20) is the right measure here, not control-level reverse coverage.

1. Two invalid identifiers — corrected

Both were inherited from the published v3.0 catalog and both cite retired CSF 1.1 identifiers in a CSF 2.0 mapping:

ControlWasProblemNow
RC-1ID.BE-05ID.BE Business Environment does not exist in CSF 2.0; the category was absorbed into GV.OCGV.OC-04
RC-4PR.DS-06Retired in CSF 2.0; PR.DS retains only 01, 02, 10, 11RC.RP-03

The RC-4 correction is doubly useful: RC.RP-03 is integrity of restoration assets verified before use, which is precisely that control's subject, so the fix simultaneously closes an uncovered subcategory.

These are live defects in the shipped v3.0 CSV and DOCX. The forward validator did not catch them because it checked only that the function prefix was valid — ID and PR both are. Validity is now checked against the full subcategory list.

Confidence note. references.json reconstructs the CSF 2.0 subcategory list to the published 6 / 22 / 106 structure. The ID.BE finding is high confidence — the whole category moved in 2.0. The PR.DS-06 finding depends on my reconstruction being right at the margins. Verify against the authoritative NIST Core before this drives a published claim.


2. CSF 2.0 reverse coverage — 58 / 106 (55%)

CategoryNameCovered
GV.OCOrganizational Context3/5
GV.RMRisk Management Strategy3/7
GV.RRRoles, Responsibilities, Authorities3/4
GV.POPolicy1/2
GV.OVOversight3/3
GV.SCSupply Chain Risk Management4/10
ID.AMAsset Management6/7
ID.RARisk Assessment7/10
ID.IMImprovement3/4
PR.AAIdentity, Authentication, Access Control3/6
PR.ATAwareness and Training2/2
PR.DSData Security2/4
PR.PSPlatform Security3/6
PR.IRInfrastructure Resilience3/4
DE.CMContinuous Monitoring2/5
DE.AEAdverse Event Analysis3/6
RS.MAIncident Management1/5
RS.ANIncident Analysis0/4
RS.COIncident Response Reporting0/2
RS.MIIncident Mitigation1/2
RC.RPIncident Recovery Plan Execution5/6
RC.COIncident Recovery Communication0/2

The headline: Respond is 2 of 13

Three categories are entirely uncovered, and all three sit in the second half of the incident lifecycle. Aggregated: Respond 2/13, Detect 5/11, Recover 5/8.

This is the same structural finding raised at the start of the v4.0 work, arriving from a third independent direction. The first two were the technique layer (M7, M9, M10 and M11 all parked on TX Cross-Cutting rather than on real ground) and the CSF function distribution (ID 42 citations against DE 6). Reverse coverage now says it in outcome terms: a framework whose signature metric is detect → decide → contain covers two of thirteen Respond outcomes.


3. Triage of the 48 uncovered subcategories

Proposed classification. Class A = genuine gap, a control should exist. Class B = legitimately out of scope, inherited from the baseline, should be recorded as a deliberate exclusion rather than left silent.

Class A — genuine gaps (24)

SubcategoryOutcomeWhy it belongs in ASOM-Fed
RS.AN-03Analysis establishes what took placeM10's precondition is a dwell reconstruction; nothing assesses it
RS.AN-06Investigation actions recordedRequired for M10.02 avenue closure verification
RS.AN-07Incident data and metadata preservedFeeds RC-4 restore point selection and TA-2 local dwell
RS.AN-08Incident magnitude estimatedFeeds CE-4 posture and CG-4 disposition
RS.MA-02Incident reports triaged and validatedThis is the decide segment TA-1 measures
RS.MA-03Incidents categorized and prioritizedDetermines which maneuver applies
RS.MA-04Incidents escalated or elevatedThe escalation path TA-4 exists to shorten
RS.MA-05Recovery criteria appliedThe M8 → M11 transition decision
RS.MI-02Incidents eradicatedM7 Counterattack eviction
RS.CO-02Reporting to designated stakeholdersM10.05 exists as a technique with no assessing control
RS.CO-03Information shared with stakeholdersSame
RC.CO-03Recovery activities communicatedCE-7 covers internal briefing only
RC.CO-04Public updates on recoveryFederal availability obligations make this material
RC.RP-02Recovery actions selected and scopedRC-3 sequences; nothing selects
DE.AE-03Information correlated from multiple sourcesCE-3 Fusion should map here
DE.AE-04Impact and scope understoodPairs with RS.AN-08
DE.AE-08Incidents declared against criteriaDeclaration criteria feed CG-2 phase transition
DE.CM-02Physical environment monitoredFC-2 crossing logs should map here
DE.CM-06External provider activities monitoredLC-3 brokered access should map here
DE.CM-09Computing hardware and software monitoredCore detection coverage
PR.AA-02Identities proofed and bound to credentialsProposed ID family
PR.AA-03Users, services, hardware authenticatedProposed ID family
PR.AA-04Identity assertions protectedProposed ID family
GV.SC-09Supply chain practices integrated into programsFO-6 scope adjacent

Class B — out of scope, inherit and record (24)

GV.OC-02, GV.OC-05, GV.PO-02, GV.RM-04, GV.RM-05, GV.RM-06, GV.RM-07, GV.RR-03, GV.SC-01, GV.SC-02, GV.SC-03, GV.SC-05, GV.SC-06, ID.AM-02, ID.IM-04, ID.RA-07, ID.RA-08, ID.RA-10, PR.DS-02, PR.DS-10, PR.IR-03, PR.PS-04, PR.PS-05, PR.PS-06

These are enterprise risk management, policy lifecycle, procurement governance and platform hygiene outcomes that the 800-53 baseline already addresses and that carry no maneuver dimension. The recommendation is not to write controls for them but to record the exclusion, so that 55% reverse coverage reads as a stated scope rather than as an unexamined shortfall.


4. D3FEND reverse coverage — 6 of 7 tactics

TacticControls
Model20
Isolate16
Detect14
Harden6
Evict6
Restore6
Deceive0

Deception is unassessed

M5 Ambush is a full form of maneuver with 13 techniques, described in the framework's own reference material as the cheapest high-confidence detection available, and carrying a deception grid as the dominant effort of Phase I Deter. No control in the sixty assesses it.

An agency could stand up a complete deception grid, or none at all, and the control set would score identically. This is the sharpest single reverse-coverage finding in this analysis, and it compounds the Detect and Respond thinness rather than being independent of it — deception is precisely the cheap detection that would improve both.

14 controls carry no D3FEND tactic

SM-1, SM-3, SM-4, SM-6, TA-3, TA-5, CE-5, CE-6, CE-7, CG-1, CG-2, CG-4, CG-5, FO-5.

These are planning and governance controls, and D3FEND is a countermeasure ontology with nothing to map to for most of them. That is defensible — but it should be recorded as an explicit not applicable, planning layer rather than as an em-dash, so an absent mapping is distinguishable from a forgotten one.


5. SP 800-53 — reach, not coverage

20/20 families reached. Thinnest citations:

FamilyCitationsControls
MP Media Protection1FO-2
IA Identification and Authentication1WF-2
PT PII Processing and Transparency2FO-1
AT Awareness and Training3WF-1, WF-3
MA Maintenance3FC-3

IA at a single citation remains the standing finding: identity is T1, the declared high ground and the plane M3 Envelopment makes decisive, and the catalog reaches its 800-53 family once, incidentally, through a workforce control. The PR.AA-02/03/04 gaps above are the same finding expressed in CSF terms.


6. Recommendations

  1. Ratify the two CSF corrections and reissue the published CSV and DOCX — they currently ship retired CSF 1.1 identifiers.
  2. Record the 24 Class B exclusions as a scope statement, so 55% reverse coverage is a position rather than a shortfall.
  3. Add a deception control, or extend an existing one, so M5 is assessable. Zero of seven D3FEND tactics is the least defensible number in this report.
  4. Address the Respond cluster. RS.AN 0/4 and RS.MA 1/5 are the largest coherent gap, and they map onto M7 and M10 — the forms the reference estates were already least able to perform.
  5. Decide the ID family, which resolves PR.AA-02/03/04 and the IA single-citation finding together.
  6. Replace D3FEND em-dashes with explicit N/A reasons so absence is distinguishable from omission.

Items 3, 4 and 5 are roster changes and belong to the framework owner. Items 1, 2 and 6 can proceed immediately.