id|form|tower|phases|name|does|indicator|controls|added_v5 M1.01|M1|T3|0,I|External Attack Surface Enumeration|Continuously enumerate everything the agency exposes to the internet, from the outside in, on the same cadence an adversary would.|New exposure appears in the terrain register before it appears in an alert.|TM-1, TM-6, KT-3| M1.02|M1|T3|0|Shadow and Forgotten Asset Discovery|Reconcile discovered internet-facing assets against the authoritative inventory and drive the difference to zero.|The unreconciled-asset count trends to zero and stays there.|TM-1, TM-6, TM-7, FO-3, DV-1| M1.03|M1|T3|0,I|Certificate and Domain Watch|Watch certificate transparency and registration feeds for lookalike domains and unsanctioned certificates issued in the agency name.|Impersonation infrastructure is identified while it is still being staged.|TM-1, KT-3| M1.04|M1|T5|0,I|Perimeter Canary Tokens|Seed uniquely identifying tokens in externally reachable surfaces so that reconnaissance touching them is unambiguous.|A token fires before any production system records the actor.|KT-3, CE-2| M1.05|M1|T1|0,II|Authentication Geography Baseline|Baseline where, when and from what the population legitimately authenticates, so deviation is measurable rather than anecdotal.|Account-takeover precursors are detected on deviation, not on damage.|CE-2, TA-1| M1.06|M1|T1|0,I|Credential Exposure Monitoring|Monitor public and criminal sources for agency credentials, session artifacts and tokens offered for sale or dumped.|Exposed credentials are invalidated before they are used against the estate.|CE-2, TA-4| M1.07|M1|TX|0,I|Partner and Advisory Intake|Operate a named, timed intake path for CISA, sector and law-enforcement reporting that ends in a decision rather than a mailbox.|Every advisory reaches a disposition within its stated intake window.|CE-2, CG-4| M1.08|M1|T4|0,II|Public Service Abuse Telemetry|Instrument public-facing services for abuse patterns — enumeration, scripted submission, credential stuffing — distinct from application errors.|Abuse is distinguished from load, and named, before it becomes an incident.|CE-2, TA-1, EN-1|EN-1 M1.09|M1|TX|0|Supply Chain and Vendor Watch|Track the security posture and incident disclosures of vendors and integrators whose products sit on key terrain.|A vendor compromise reaches the terrain owner before it reaches the news.|TM-7, CG-5| M1.10|M1|TX|0,I|Named-Campaign Indicator Watch|Maintain standing collection against the specific campaigns the intelligence requirements name, not against indicators in general.|Every priority intelligence requirement has live collection against it.|CE-2, CE-3| M1.11|M1|T6|0|Operational Technology Asset Discovery|Discover control-system assets passively, because active scanning of a safety-instrumented network is itself an availability risk.|The OT inventory is built without a scan-induced outage.|TM-1, TM-2, FO-4| M1.12|M1|T7|0,I|Workforce Credential Exposure Monitoring|Watch the outside world for agency credentials and staff identities appearing where they should not, on the same cadence you watch the network perimeter.|Exposed staff credentials are found and revoked before they are used.|WF-1, WF-2, TM-6| M1.13|M1|T8|0,II|Physical Access Anomaly Detection|Read badge and access-control telemetry as an intelligence source rather than an audit artifact, and correlate it with logical access.|Impossible-travel and after-hours physical anomalies raise a finding.|FC-1, FC-2, CE-3| M1.14|M1|T9|0,I|Supplier Exposure Monitoring|Monitor the suppliers and components that reach into the estate for breach disclosure, advisory and exposure, because their compromise is your compromise.|A supplier incident reaches the agency from monitoring, not from the news.|LC-1, LC-2, TM-6, FO-6| M2.01|M2|T3|0|Trust Zone Architecture|Define trust zones that reflect real boundaries and assurance differences, and record which elements sit in which.|Every element on the terrain resolves to exactly one declared zone.|TM-4, TM-5| M2.02|M2|T3|0|Policy Enforcement Point Placement|Place an enforcement point at every zone boundary so that crossing is a decision, not a route.|No path reaches a higher-trust zone without transiting an enforcement point.|TM-4, KT-2, ID-5|ID-5 M2.03|M2|T5|0,I|Crown-Jewel Enclave|Isolate the decisive data behind its own enforcement point, with its own authorization policy and its own telemetry.|Reaching the data layer requires defeating controls nothing else shares.|KT-1, KT-2| M2.04|M2|TX|0|Independent Control Redundancy|Ensure the controls guarding key terrain fail independently — no shared agent, identity, console or vendor across a protection floor.|No single control, credential or vendor failure exposes a decisive point.|KT-2, KT-5| M2.05|M2|T2|0|Endpoint Detection and Response Coverage|Achieve and prove sensor coverage across the managed fleet, with unmanaged devices treated as a measured gap rather than an assumption.|Coverage is reconciled to the inventory, not to the console.|TM-2, TM-6, DV-1, DV-3| M2.06|M2|T2|0,I|Device Posture Gating|Make device health a precondition of access, so a compromised or non-compliant endpoint cannot spend a valid credential.|Failing posture denies access rather than raising a ticket.|KT-2, SM-2, DV-2| M2.07|M2|T4|0|Web Application Protection|Front public applications with request-level inspection tuned to the application, not to a generic ruleset.|Application-layer attacks are stopped at the edge and counted.|KT-2, SM-2| M2.08|M2|T4|0|API Authorization Enforcement|Enforce per-call authorization at an API gateway rather than trusting network position or a shared key.|No API path authorizes on network location alone.|KT-2, SM-2| M2.09|M2|T5|0|Data-at-Rest Encryption and Key Separation|Encrypt decisive data with keys held outside the system that reads it, so storage compromise is not data compromise.|Exfiltrating storage does not yield readable records.|KT-2, TM-3, FO-2| M2.10|M2|T5|0,III|Egress Data Loss Prevention|Inspect and constrain outbound movement of the record types the campaign exists to protect.|Bulk movement of protected records is blocked or alerted at egress.|KT-2, KT-5| M2.11|M2|T2|0|Workload Hardening Baseline|Hold servers, images and containers to a declared baseline, and treat drift from it as a finding.|Baseline drift is detected on a stated cadence and dispositioned.|TM-6, CG-4, DV-4| M2.12|M2|T4|0|Secrets Management|Remove long-lived secrets from code, images and configuration into brokered, rotated, audited storage.|No decisive system authenticates with a static embedded secret.|KT-2, SM-3, ID-2|ID-2 M2.13|M2|T5|0,IV|Backup Isolation and Immutability|Hold recovery data outside the blast radius of the production identity plane and make it immutable for its retention window.|Recovery is possible after full compromise of production identity.|KT-2, SM-5| M2.14|M2|TX|0|Control Failure Detection|Detect when a control stops working — sensor silent, policy unapplied, agent removed — as a security event in its own right.|A silent control is detected in hours, not at the next assessment.|SM-3, SM-6, CE-6, DV-3| M2.15|M2|T6|0|Safety Instrumented Layer Integrity|Keep the safety layer independent of the control layer, so a compromise of operations cannot defeat the function that prevents harm.|Safety functions hold when the control network is assumed hostile.|KT-2, FO-4| M2.16|M2|T7|0|Role-Based Privilege Minimization|Give each role the least authority its work requires, so a compromised person yields the least ground.|No role holds authority its documented duties do not require.|WF-2, WF-3| M2.17|M2|T8|0|Facility Defense in Depth|Layer physical controls so that defeating one barrier does not deliver the floor, the rack or the media inside it.|Reaching a decisive asset physically requires defeating three independent controls.|FC-2, FC-1| M2.18|M2|T9|0|Component Provenance Verification|Know what is inside what you deploy, and verify it came from who it claims, before it runs on your ground.|Every deployed component resolves to a verified origin and a current inventory.|LC-2, LC-4| M3.01|M3|T1|0,I|Phishing-Resistant Authentication|Move the population to authenticators that cannot be relayed or replayed by a proxy.|Credential phishing yields no usable authentication.|KT-2, SM-2, ID-2, ID-3|ID-2, ID-3 M3.02|M3|T1|0,I|Conditional Access Policy Engine|Concentrate access decisions in one policy decision point that sees identity, device, network and behavior together.|Access decisions are made in one place and are inspectable.|KT-1, SM-2, ID-1|ID-1 M3.03|M3|T1|0,II|Continuous Authorization|Re-evaluate authorization during a session on changed signal, rather than only at sign-in.|A session that becomes risky is downgraded mid-flight.|SM-2, TA-4, ID-5|ID-5 M3.04|M3|T1|0,I|Just-in-Time Privilege|Grant privilege for a bounded task and window, with the grant itself recorded as an event.|Standing privileged sessions approach zero.|KT-2, SM-2| M3.05|M3|T2|0,I|Privileged Access Workstations|Require administration of decisive systems from dedicated, hardened, separately governed endpoints.|No decisive system is administered from a general-purpose desktop.|KT-2, TM-2, DV-2| M3.06|M3|T1|0|Machine and Service Identity Governance|Give non-human identities owners, expiry and scope on the same terms as human ones.|Every service account has a named owner and an expiry date.|TM-7, SM-3, ID-2|ID-2 M3.07|M3|T1|0,I|Standing Privilege Elimination|Systematically remove permanent administrative rights, replacing them with request-and-grant paths.|Permanent privileged entitlements trend to a declared floor.|KT-2, SM-3| M3.08|M3|T1|0|Identity Lifecycle Enforcement|Bind joiner, mover and leaver events to authoritative sources so access follows the person, not the ticket.|Departure removes access within the stated interval, provably.|SM-3, TM-6| M3.09|M3|T1|0,I|External-User Identity Assurance|Apply proportionate identity assurance to public and partner users of mission services without denying access to the public.|Account takeover of external users falls while service access holds.|KT-2, SM-2, ID-3|ID-3 M3.10|M3|T2|0,I|Device-Bound Credentials|Bind credentials cryptographically to hardware so that stolen material cannot be spent elsewhere.|Exported credential material is unusable off its device.|KT-2, SM-2, ID-2, DV-2|ID-2 M3.11|M3|T1|0,III|Session and Token Revocation Path|Maintain a tested path to invalidate sessions and tokens estate-wide within a stated interval.|Revocation completes inside the interval the rules of engagement assume.|TA-4, TA-1, ID-4|ID-4 M3.12|M3|T1|0|Authorization Policy as Code|Express access policy as reviewed, version-controlled, testable code rather than console state.|Policy change is reviewable and revertible like any other change.|SM-2, SM-3, ID-5|ID-5 M3.13|M3|T1|0,I|Federation Trust Boundary Control|Enumerate every federated trust into the estate, own each one, and constrain what it may assert.|Every inbound trust has an owner, a scope and a suspension path.|TM-5, CG-5, ID-1|ID-1 M3.14|M3|T1|0|Entitlement Recertification|Review entitlements on a cadence against actual use, and remove what is not used.|Unused entitlements are removed rather than recertified.|SM-3, CG-4| M3.15|M3|T1|0,IV|Break-Glass Account Control|Hold emergency accounts under split control with alerting on any use, so the last resort is not the soft target.|Break-glass use is always deliberate and always noticed.|KT-2, CG-3| M3.16|M3|T1|0,II|Token Replay Protection|Bind issued tokens to sender and context so a captured token cannot be replayed from elsewhere.|Replayed tokens fail outside their issuing context.|SM-2, KT-5, ID-4|ID-4 M3.17|M3|T1|0,II|Authentication Anomaly Scoring|Score authentication against the behavioral baseline and feed the score back into the policy decision point.|Anomalous authentication changes the access decision automatically.|CE-2, SM-2, ID-3|ID-3 M3.18|M3|T1|0,III|Identity Provider Tamper Detection|Treat the identity provider as decisive terrain: alert on federation, policy, key and admin changes independently of the provider itself.|Changes to the identity plane are detected out-of-band.|KT-1, CE-2, ID-1, ID-5|ID-1, ID-5 M3.19|M3|T7|0,I|Human-to-Account Binding|Bind every privileged account to a named, current, cleared human, so an orphaned credential has nowhere to hide.|No privileged account exists without a named accountable holder.|WF-2, WF-5| M3.20|M3|T9|0,I|Supplier Identity Federation|Bring supplier access under the agency's own identity plane rather than standing local accounts the agency cannot see or revoke.|Supplier access is revocable by the agency in one action.|LC-3, WF-2| M4.01|M4|T3|0,I|Microsegmentation|Reduce reachability between workloads to what is declared, so lateral movement requires defeating policy rather than finding a route.|Reachable-neighbor counts fall against a declared target.|TM-4, KT-5| M4.02|M4|T3|0,I|East-West Deny by Default|"Make the default answer between segments ""no"", with exceptions declared, owned and expiring."|New east-west paths exist only where they are declared.|TM-5, KT-5| M4.03|M4|T3|0,I|Egress Filtering and Allow-Listing|Constrain outbound destinations so command channels must use paths you inspect.|Outbound connections resolve to an allow-listed destination or fail.|KT-5, TM-5| M4.04|M4|T3|0,I|DNS Control and Sinkholing|Route resolution through controlled resolvers, log it, and sinkhole known-bad and newly registered domains.|Resolution to staged infrastructure fails and alerts.|KT-5, CE-2| M4.05|M4|T2|0,I|Application Allow-Listing|Constrain what may execute on decisive endpoints to what is approved and signed.|Unapproved executables do not run on decisive endpoints.|KT-2, TM-2, DV-4| M4.06|M4|T3|0,I|Administrative Path Restriction|Confine administrative protocols to declared corridors from declared sources.|Administrative access from outside the corridor fails and alerts.|TM-5, KT-2| M4.07|M4|T3|0|Cloud Boundary Enforcement|Enforce account, VPC and role boundaries in the cloud with the same rigor as network segments on the ground.|Cross-account reachability matches the declared design exactly.|TM-4, TM-5| M4.08|M4|T3|I,II|Instrumented Corridor Design|Deliberately leave the paths you want an adversary to take, and instrument them heavily.|Observed lateral attempts land in instrumented segments.|KT-5, CE-2| M4.09|M4|T2|0|Removable Media Control|Constrain and log removable media on endpoints holding or reaching decisive data.|Media use on decisive endpoints is either denied or recorded.|KT-2, TM-2, DV-5| M4.10|M4|T3|0,I|Bastion and Jump-Host Enforcement|Force privileged access to decisive systems through recorded, brokered hosts.|Privileged sessions to decisive systems are recorded without exception.|KT-2, CG-3| M4.11|M4|T3|0|Protocol and Port Restriction|Permit only the protocols the design requires, and treat the rest as a canalization opportunity.|Non-design protocols are denied at the boundary and counted.|TM-5, KT-5| M4.12|M4|T3|0|Denied-Path Register Enforcement|Maintain the explicit register of paths that must never exist, and test continuously that they do not.|Every denied path is tested on a stated cadence and holds.|TM-5, SM-6| M4.13|M4|T6|0,I|Operational Technology Segregation|Separate control-system networks from the enterprise with an enforced, inspectable boundary rather than a documented intention.|No route exists from an office endpoint to a controller without transiting an enforcement point.|TM-4, KT-5, FO-4| M4.14|M4|T6|0,I|Control Protocol Constraint|Permit only the industrial protocols and function codes the process requires, and deny engineering commands from outside the corridor.|Write and program commands originate only from declared engineering stations.|KT-5, FO-4| M4.15|M4|T8|0,I|Physical Zone Segregation|Divide facilities into zones whose boundaries are enforced and logged, so physical movement is as canalised as network movement.|Movement between physical zones is enforced and recorded.|FC-2, FC-1| M4.16|M4|T8|I,II|Maintenance Access Constraint|Force vendor and remote maintenance onto a supervised, time-boxed path instead of standing access into the estate.|No maintenance path is available outside an approved, supervised window.|FC-3, LC-3| M4.17|M4|T9|I,II|Supplier Access Canalisation|Route every supplier into a defined broker rather than directly onto mission systems, so their traffic crosses ground you instrument.|No supplier reaches a mission system except through the brokered path.|LC-3, TM-5| M5.01|M5|T5|I,II|Decoy Records in the Data Layer|Seed the record stores with realistic decoy records whose only purpose is to be accessed by someone who should not.|Access to a decoy produces a high-confidence detection with no false-positive tail.|KT-2, CE-2, SM-7|SM-7 M5.02|M5|T5|I,II|Honeytokens in Document Stores|Place tokenized documents in collaboration and file estate where staged collection would find them.|Staging for exfiltration is detected during collection, not after.|CE-2, TA-1, SM-7|SM-7 M5.03|M5|T1|I,II|Decoy Credentials|Seed credential stores, memory and configuration with credentials that are valid-looking and monitored but powerless.|Credential harvesting is detected on use of a planted credential.|CE-2, KT-4, FO-1, SM-7, ID-2|SM-7, ID-2 M5.04|M5|T3|I,II|Honeypot Services in Corridors|Place responsive services in the lateral corridors so that scanning and movement produce contact rather than silence.|Lateral reconnaissance produces an alert on first contact.|KT-5, CE-2, SM-7|SM-7 M5.05|M5|T2|I,II|Canary Files on Endpoints|Distribute monitored files across the endpoint fleet to detect mass encryption and mass collection early.|Mass file operations are detected within the first affected hosts.|CE-2, TA-1, SM-7|SM-7 M5.06|M5|T4|I,II|Decoy Service Endpoints|Publish plausible but unused API and administrative endpoints that only enumeration would find.|Enumeration of the application surface produces contact.|CE-2, KT-3, SM-7|SM-7 M5.07|M5|T1|I,II|Identity-Plane Deception|Plant privileged-looking accounts and group memberships that no legitimate process ever touches.|Directory reconnaissance is detected at the enumeration stage.|CE-2, KT-4, SM-7|SM-7 M5.08|M5|T4|I,II|Decoy Cloud Resources|Stand up monitored buckets, roles and secrets that legitimate workloads never call.|Cloud credential abuse is detected on first exploratory call.|CE-2, KT-4, SM-7|SM-7 M5.09|M5|TX|I,III|Deception Alert Routing|Route deception alerts on a separate, high-trust path that bypasses ordinary triage queues.|Deception alerts reach a decision-maker without queueing.|CE-3, TA-4, SM-7, EN-1|SM-7, EN-1 M5.10|M5|T5|0,I|Deception Coverage Measurement|Measure what share of the data layer is actually seeded, and treat the unseeded remainder as a gap.|Deception coverage is a reported number, not an impression.|CE-4, SM-6, SM-7|SM-7 M5.11|M5|T6|I,II|Control Network Deception|Place decoy controllers and engineering workstations on the control network, where legitimate traffic is narrow and predictable.|Any interaction with a decoy controller is unambiguous.|CE-2, FO-4, SM-7|SM-7 M5.12|M5|T7|0,I|Phishing Deception and Reporting|Exercise the workforce against realistic lures and treat the reporting rate, not the click rate, as the measure that matters.|Reporting rate exceeds click rate and the first report arrives within minutes.|WF-3, CE-2, SM-7|SM-7 M5.13|M5|T8|I|Physical Deception|Seed facilities with tokens whose only plausible use is by someone who should not have them — dropped media, decoy badges, decoy racks.|Physical decoy interaction produces findings with no false-positive tail.|FC-1, CE-3, SM-7|SM-7 M6.01|M6|T4|II,III|Adaptive Rate Limiting|Slow request rates as risk rises, so automation loses its advantage while humans keep service.|Automated abuse degrades while legitimate service holds.|TA-5, SM-2| M6.02|M6|T1|II,III|Step-Up Authentication on Anomaly|Demand stronger proof at the moment behavior deviates, rather than uniformly at sign-in.|Anomalous sessions must re-prove before continuing.|SM-2, TA-4, ID-3|ID-3 M6.03|M6|T5|II,III|Bulk Export Throttling|Cap the rate and volume of bulk retrieval so a successful intrusion cannot become a successful exfiltration in one pass.|Bulk collection takes long enough to be detected and stopped.|KT-2, TA-5| M6.04|M6|T1|II,III|Session Duration Reduction Under Alert|Shorten session and token lifetimes automatically while the estate is in contact.|Session lifetimes contract on phase change without an outage.|TA-4, CG-2, ID-4|ID-4 M6.05|M6|TX|II,III|Approval Gates on High-Impact Actions|Require a second, human authorization for the small set of actions that would be decisive if abused.|Decisive actions cannot be completed by one compromised identity.|CG-3, TA-4, EN-4|EN-4 M6.06|M6|T3|II|Tarpitting and Response Delay|Introduce deliberate latency on suspicious paths, so an adversary spends time you are spending on decision.|Adversary tempo drops below defender decision tempo.|TA-1, TA-5| M6.07|M6|T1|II|Progressive Lockout|Escalate friction against an identity under attack without handing an attacker a denial-of-service lever.|Guessing is defeated without locking the population out.|SM-2, TA-5| M6.08|M6|T4|III|Change and Deploy Freeze Under Contact|Suspend routine change into decisive systems while in contact, so the adversary cannot hide in the noise of normal deployment.|Change into decisive systems stops on phase declaration.|CG-2, TA-5| M6.09|M6|T4|II,III|Query Complexity Limits|Bound the cost and breadth of a single query against mission data stores.|No single query can enumerate the corpus.|KT-2, TA-5| M6.10|M6|T9|II,III|Update Staging and Soak|Hold vendor updates in a staging ring long enough to observe them, trading a little currency for the ability to not deploy a compromised build estate-wide.|No supplier update reaches the whole estate without a stated soak period.|LC-4, LC-2| M7.01|M7|TX|II,III|Hypothesis-Driven Hunting|Hunt against stated hypotheses drawn from the intelligence requirements, not against whatever the queue surfaced.|Every hunt traces to a priority intelligence requirement.|CE-2, CE-3| M7.02|M7|TX|II,III|Fusion-Fed Hunt Backlog|Convert fused assessments into a ranked, worked hunt backlog with explicit confidence on each entry.|Fusion output becomes hunt work rather than a report.|CE-3, CE-5, EN-1|EN-1 M7.03|M7|TX|III|Automated Containment Playbooks|Encode containment as tested automation so the decision, not the execution, is the slow step.|Containment executes in seconds once the decision is made.|TA-4, SM-5, EN-4|EN-4 M7.04|M7|T2|III|Host Isolation on Confirmation|Sever a host from the network on confirmed compromise while preserving it for analysis.|Confirmed hosts are isolated inside the stated interval.|TA-4, TA-1, SM-4| M7.05|M7|T1|III|Credential Reset Sweep|Execute a scoped, ordered reset of credentials and tokens across the compromised blast radius.|The reset completes without leaving a re-entry credential.|TA-4, SM-5| M7.06|M7|T4|III|Build Pipeline Integrity Hunt|Hunt the build pipeline specifically, because poisoning it envelops everything downstream.|Pipeline integrity is verified rather than assumed after contact.|KT-1, SM-6| M7.07|M7|T2|III,IV|Persistence Sweep|Sweep systematically for persistence across identity, endpoint, cloud and application layers before declaring eradication.|Eradication is declared on evidence across every layer.|SM-6, CG-4, EN-5|EN-5 M7.08|M7|T3|II,III|Lateral Path Audit|Recompute what the adversary could reach from where they stand, and close the paths ahead of them.|Reachability from the foothold is reduced during the engagement.|KT-4, KT-5| M7.09|M7|TX|III,V|Detection Engineering from Hunt|Convert every hunt finding into a durable detection with an owner and a test.|No hunt finding is left as tribal knowledge.|SM-6, CE-5| M7.10|M7|TX|0,V|Purple-Team Validation|Test whether each emplaced maneuver actually performs, using the cell success indicator as the pass condition.|Every claimed maneuver has been demonstrated, not asserted.|SM-6, CE-4| M7.11|M7|TX|III|Eviction Sequencing|Plan eviction as a single sequenced action, so the adversary cannot re-enter through what is evicted last.|Eviction happens once, not in rounds.|SM-5, TA-3, EN-5|EN-5 M7.12|M7|TX|III,IV|Adversary Dwell Reconstruction|Reconstruct how long the adversary held the ground, so temporal advantage is computed rather than estimated.|Dwell is measured from evidence for every engagement.|TA-2, CE-6, EN-2|EN-2 M7.13|M7|TX|V|Hunt Coverage Accounting|Track which terrain has been hunted, how recently, and against which hypotheses.|Unhunted terrain is visible and dispositioned.|CE-4, CE-6| M7.14|M7|T6|II,III|Process Anomaly Hunting|Hunt for deviation in the physical process itself, not only in the network, because a competent adversary will look correct on the wire.|Process behavior outside its engineering envelope is investigated as a security event.|CE-2, FO-4| M7.15|M7|T7|III|Insider Risk Investigation|Run a defined, rights-respecting process to resolve an insider indication, rather than improvising one under pressure.|Insider indications reach a documented disposition within a stated period.|WF-4, CG-4| M7.16|M7|T9|III|Supply Chain Compromise Hunting|Hunt for the specific behaviors a compromised supplier or component would produce, on the assumption that it is already inside.|Supplier-origin behaviors are hunted on a stated cadence, not only on advisory.|LC-2, LC-4, CE-2| M8.01|M8|T3|III|Automated Segment Severing|Hold a tested capability to sever a segment or zone on decision, without an unplanned outage of everything else.|A zone can be severed inside the interval the plan assumes.|TA-4, SM-5, EN-4|EN-4 M8.02|M8|T1|III|Estate-Wide Session Revocation|Invalidate every session and token across the estate as one action when the identity plane is in doubt.|Estate-wide revocation is exercised and timed, not theoretical.|TA-4, SM-5, ID-4|ID-4 M8.03|M8|T4|III,IV|Read-Only Service Degradation|Degrade mission services to read-only or queued operation rather than exposing or losing the corpus.|Service degrades gracefully instead of failing open or dark.|SM-5, TA-5| M8.04|M8|TX|0,III|Fail-Secure Default Posture|Ensure that when a control fails, the estate denies rather than permits — including under load and during recovery.|Control failure denies access rather than bypassing the control.|KT-2, CG-3| M8.05|M8|T1|III|Federation Trust Suspension|Suspend an inbound federated trust independently, without dismantling the identity plane around it.|A compromised trust is suspended without an estate outage.|TM-5, TA-4| M8.06|M8|T4|III|Cloud Account Quarantine|Quarantine a cloud account or subscription — revoking roles and cutting peering — as one rehearsed action.|A cloud account is isolated inside the stated interval.|TA-4, TM-4| M8.07|M8|T3|III|Egress Blackhole|Cut outbound reachability for a defined scope to stop exfiltration and command channels while analysis continues.|Exfiltration stops without severing the whole estate.|KT-5, TA-4| M8.08|M8|TX|III,IV|Statutory Availability Floor|Declare in advance which mission functions may never be taken offline, and design containment around them.|Containment never breaches the declared availability floor.|CG-1, CG-3| M8.09|M8|T5|III,IV|Contained Forensic Preservation|Preserve evidence in a way that survives containment and recovery, on storage the adversary could not reach.|Evidence survives the response intact and admissible.|KT-2, CE-6, EN-3|EN-3 M8.10|M8|T3|III|Third-Party Connection Cutout|Cut a specific partner or vendor connection on decision without taking down the shared boundary.|A single external connection can be cut in isolation.|TM-5, CG-5| M8.11|M8|TX|IV|Restoration Preconditions|Define what must be true before anything comes back — no restoration on hope.|Nothing is restored until its preconditions are evidenced.|SM-5, CG-4, EN-5|EN-5 M8.12|M8|TX|0,IV|Degradation Rehearsal|Rehearse degradation and severing on the real estate, because an untested retrograde is a plan, not a capability.|Every severing action has been exercised within its stated period.|SM-6, CE-1| M8.13|M8|T6|III|Safe-State Isolation|Sever the control network to a defined safe state that preserves the physical process, rather than a network state that abandons it.|Isolation leaves the process safe, not merely disconnected.|SM-5, FO-4, RC-1| M8.14|M8|T7|III,IV|Rapid Offboarding and Revocation|Remove all access from a departing or suspended person in one action, in a time measured against the tempo an insider needs.|Full revocation completes within the stated tempo, evidenced by exercise.|WF-5, TA-1, DV-5| M8.15|M8|T8|III|Facility Isolation|Be able to sever a building or floor from the estate without severing the mission, and know in advance what that costs.|A facility can be isolated on a rehearsed procedure without an unplanned outage.|FC-2, FC-4, SM-5| M8.16|M8|T9|III,IV|Supplier Severance|Be able to cut a supplier's access immediately and continue the mission, because the alternative is negotiating with an intrusion.|A supplier can be severed within a stated period without halting the mission.|LC-5, SM-5| M9.01|M9|TX|0,I|Advisory-Driven Pre-Blocking|Block infrastructure named in partner reporting before it is used against you, on a stated clock.|Named infrastructure is blocked within the intake window.|CE-2, TA-4| M9.02|M9|T4|0,I|Targeted Emergency Patching|Patch out of cycle when intelligence — not the calendar — says a specific weakness is being used now.|Actively exploited weaknesses are closed ahead of the routine cycle.|CE-5, CG-4| M9.03|M9|T3|0,I|Staged Infrastructure Denial|Deny resolution and reachability to infrastructure observed staging against the sector, not only against you.|Sector-staged infrastructure never reaches an avenue of approach.|KT-3, CE-2| M9.04|M9|TX|0,V|Sector Intelligence Exchange|Contribute and consume in the sector and federal exchanges so pre-emption is possible at all.|The agency both receives and contributes actionable reporting.|CE-7, CG-5, EN-6|EN-6 M9.05|M9|T1|0,I|Pre-Emptive Credential Invalidation|Invalidate credentials on exposure intelligence, before misuse, accepting the friction.|Exposed credentials are dead before they are tried.|TA-4, CE-2| M9.06|M9|TX|0,I|Vendor Compromise Response|Hold a rehearsed path to constrain a compromised vendor or integrator connection on disclosure.|A vendor disclosure produces a constraint, not a meeting.|CG-5, TM-5| M9.07|M9|T4|0|Exploited-Vulnerability Catalog Enforcement|Treat authoritative known-exploited catalogs as a directive with an owner and a due date on the terrain register.|Catalog entries are closed on their due dates, with exceptions owned.|CE-5, CG-4| M9.08|M9|T7|0,I|Workforce Threat Briefing|Tell the workforce what is actually being attempted against agencies like yours, so recognition happens before the click.|Briefings cite current campaigns and reach the roles those campaigns target.|WF-3, CE-2| M9.09|M9|T9|0,I|Supplier Advisory Pre-emption|Act on supplier and component advisories before exploitation reaches you, including by staging the update or constraining the access.|Advisories affecting named suppliers are dispositioned within the stated window.|LC-1, LC-4, CE-2| M10.01|M10|TX|IV,V|Indicator-to-Detection Conversion|Convert every indicator observed in contact into a durable, tested detection rather than a one-time block.|Contact leaves behind detection, not just a blocklist entry.|SM-6, CE-5| M10.02|M10|TX|IV,V|Avenue Closure Verification|Verify by test that the avenue actually used is closed — not that a change was made.|The used avenue fails a deliberate re-test.|SM-6, CE-4, EN-2|EN-2 M10.03|M10|TX|V|Terrain Overlay Update|Update the terrain overlay with what contact revealed, including everything the map got wrong.|The overlay reflects the estate as contact proved it to be.|TM-1, TM-6, EN-2|EN-2 M10.04|M10|TX|V|Intelligence Requirement Revision|Revise the priority intelligence requirements from what the engagement showed you could not see.|Requirements change after contact rather than persisting by inertia.|CE-2, CE-6, EN-2|EN-2 M10.05|M10|TX|V|Community Reporting|Report to CISA and sector partners so the next agency starts from your contact.|Findings are shared within the stated reporting window.|CE-7, CG-5, EN-6|EN-6 M10.06|M10|TX|V|Doctrine and Catalog Update|Fold what was learned back into the maneuver catalog, the control set and the rules of engagement.|Each engagement changes the doctrine that governs the next.|SM-1, CG-3| M10.07|M10|T9|V|Supply Chain Lesson Propagation|Feed what a supplier incident taught you back into acquisition and into the terrain register, so the next contract starts from it.|Supplier incidents change the acquisition record, not only the ticket.|LC-1, CG-5, TM-1| M11.01|M11|T4|0|Recovery Objective Declaration|Declare, per mission service, how quickly it must return and how much data loss is survivable — before an incident forces the answer.|Every mission service has a stated recovery objective its owner has signed.|RC-1, FO-5, FO-7|FO-7 M11.02|M11|T5|0,IV|Isolated Recovery Environment|Hold the means of recovery outside the blast radius of the production identity plane, so compromise cannot reach what rebuilds you.|Recovery is possible after total compromise of production identity.|RC-2, KT-2| M11.03|M11|T2|0,IV|Golden Image and Rebuild Path|Maintain a trusted, tested build path so rebuilding is a procedure rather than an improvisation under pressure.|A decisive system can be rebuilt from trusted media within its recovery objective.|RC-3, DV-5| M11.04|M11|T1|IV|Identity Plane Reconstitution|Rehearse rebuilding the identity plane itself, the one system every other recovery depends on.|The identity plane can be re-established without trusting the compromised one.|RC-3, KT-1, ID-1|ID-1 M11.05|M11|T5|IV|Recovery Data Integrity Verification|Prove restored data is what it was before contact, rather than restoring the adversary's edits along with it.|Restored records are verified against an independent integrity record.|RC-4| M11.06|M11|T4|IV,V|Service Restoration Sequencing|Restore in a declared order that respects dependency and statutory priority, so the first service back is the one that must be.|Restoration follows the declared sequence under exercise conditions.|RC-1, RC-5, FO-5, FO-7|FO-7 M11.07|M11|TX|0,V|Reconstitution Exercise|Exercise recovery against a real failure scenario on a stated cadence, because an untested recovery plan is a document.|Every recovery objective has been demonstrated within its stated period.|RC-5, CE-1| M11.08|M11|T7|0,V|Key Personnel Continuity|Name the roles without which recovery cannot proceed, and make sure none of them is one person deep.|Every recovery-critical role has a rehearsed alternate.|WF-1, RC-5| M11.09|M11|T8|IV,V|Alternate Facility Activation|Be able to run the mission from somewhere else, and prove it by doing so rather than by documenting it.|The alternate facility has carried the mission within its stated period.|FC-4, RC-1, RC-5| M11.10|M11|T9|IV|Supplier-Independent Rebuild|Ensure recovery does not depend on the availability or the integrity of the supplier who may be the reason you are recovering.|A decisive system can be rebuilt without supplier assistance.|LC-5, RC-3| M1.15|M1|T2|0|Device Estate Discovery|Discover devices reaching the estate from the identity plane outward rather than from the management console, because the console can only report what it already manages.|Devices authenticating to the estate but absent from the inventory trend to zero.|TM-1, TM-6, DV-1|DV-1 M7.17|M7|T4|III|Malicious Message Eviction|Remove a delivered malicious message from every mailbox it reached, including forwards and delegated copies, rather than only from the originally reported one.|A reported message is removed estate-wide, not only where it was reported.|EN-5, TA-4, DV-3|EN-5 M8.17|M8|T2|0,V|Device Decommissioning and Sanitization|Remove a retired, lost or reassigned device from the estate's trust and sanitize its media within a period derived from what its retained trust could do.|No device holds estate trust without a current accountable holder.|DV-5, WF-5, TM-7|DV-5 M11.11|M11|T4|IV,V|Mailbox and Message Restoration|Restore mailboxes and messages removed during eviction or lost in the incident, verified against an integrity record, before returning the service to use.|Legitimate messages removed during response are restored and verified.|RC-4, EN-5, RC-3|EN-5