{
  "_note": "Subcategories deliberately NOT covered by an ASOM-Fed control, after the v5.2 recovery pass. Each is an enterprise governance outcome that the SP 800-53 baseline already addresses and that carries no maneuver dimension. Writing an ASOM-Fed control for these would duplicate the baseline and create the parallel compliance burden CG-5 exists to prevent \u2014 which is the one thing that reliably prevents adoption. This list is the framework's stated scope boundary, reviewed at each release.",
  "csf_2_0_excluded": {
    "GV.OC-02": "Stakeholder determination is enterprise governance, not maneuver. Inherited from the 800-53 PM family.",
    "GV.PO-02": "Policy lifecycle management. Inherited; ASOM-Fed states policy requirements per control rather than governing the policy estate.",
    "GV.RM-04": "Risk response option strategy is enterprise risk management. ASOM-Fed consumes the risk appetite via CG-1 rather than setting it.",
    "GV.RM-05": "Risk communication lines are enterprise governance. Inherited.",
    "GV.RM-07": "Strategic opportunity management. Out of scope for a defensive framework.",
    "GV.RR-03": "Resource allocation is an enterprise budgeting outcome. SM-4 requires resourcing to follow main effort but does not govern allocation itself.",
    "GV.SC-02": "Supply chain roles and responsibilities. Inherited.",
    "GV.SC-03": "Integration of SCRM into risk management processes at enterprise level. Inherited.",
    "GV.SC-05": "Contractual security requirements are an acquisition outcome. LC-3 requires brokering; it does not govern contract drafting.",
    "ID.RA-07": "Change management. Inherited from CM; TM-6 consumes change events rather than governing them.",
    "ID.RA-08": "Vulnerability disclosure process. Inherited; M9 consumes disclosures rather than operating the receiving process.",
    "PR.DS-10": "Data-in-use protection is a platform control. Inherited.",
    "PR.PS-06": "Secure software development lifecycle. Inherited from SA-15; out of scope for a defensive maneuver layer."
  },
  "d3fend_not_applicable": {
    "reason": "D3FEND is a countermeasure knowledge graph. Controls in the planning, governance, assessment and campaign layers have no countermeasure equivalent and are recorded as N/A with the layer named, so an absent mapping is distinguishable from a forgotten one.",
    "controls": [
      "SM-1",
      "SM-3",
      "SM-4",
      "SM-6",
      "TA-3",
      "TA-5",
      "CE-5",
      "CE-6",
      "CE-7",
      "CG-1",
      "CG-2",
      "CG-4",
      "CG-5",
      "FO-5",
      "FO-7",
      "EN-4",
      "EN-6"
    ]
  },
  "nist_800_53_position": "Reverse coverage against the ~1,196 SP 800-53 Rev. 5 controls is explicitly NOT a goal. ASOM-Fed specifies the maneuver layer and inherits everywhere else; CG-5 exists to prevent duplicate assessment. Family reach (20/20) is the correct completeness measure. A control-for-control mapping would create the parallel compliance burden the framework was designed to avoid."
}