{
  "framework_version": "6.1",
  "scheme": "Each control carries an independent semantic version. MAJOR changes the control statement or its scope. MINOR adds or removes activities, components or mappings. PATCH is editorial. A control's version is bumped whenever its content changes, including when the change is prompted by a later family.",
  "baseline": "4.0.0 = first authoring at COBIT 2019 depth. Controls not listed below remain at 4.0.0 with no changes since first authoring.",
  "controls": {
    "TM-1": {
      "version": "4.0.0",
      "changes": [
        {
          "v": "4.0.0",
          "note": "First authoring at 2019 depth. Retrofitted from the 4.1 Control Practices pilot: numbered practices became capability-leveled activities; value and risk drivers absorbed into purpose, discussion and the culture component."
        }
      ]
    },
    "TM-2": {
      "version": "4.1.0",
      "changes": [
        {
          "v": "4.1.0",
          "note": "MAJOR-adjacent scope correction. v3.0 statement enumerated five defensive layers, making every element on T6-T9 and TX unclassifiable under the control mandating classification, while FO-4, WF-1, FC-1 and LC-1 all require that classification. Statement now carries the full v3.0 ten-layer model. Added L4 activity requiring escalation where a declared terrain layer holds no classified elements. Added PM-5 to inheritance and ID.AM-01 to CSF mapping."
        }
      ]
    },
    "TM-3": {
      "version": "4.0.0",
      "changes": [
        {
          "v": "4.0.0",
          "note": "First authoring at 2019 depth."
        }
      ]
    },
    "TM-4": {
      "version": "4.0.0",
      "changes": [
        {
          "v": "4.0.0",
          "note": "First authoring at 2019 depth."
        }
      ]
    },
    "TM-5": {
      "version": "4.1.0",
      "changes": [
        {
          "v": "4.1.0",
          "note": "MINOR. Added an explicit third connectivity state (unknown), distinguished from absence. v3.0 recorded permitted and denied only, which caused unknown connectivity to be treated as absent and produced confidently wrong reachability results downstream in KT-4."
        }
      ]
    },
    "TM-6": {
      "version": "4.0.0",
      "changes": [
        {
          "v": "4.0.0",
          "note": "First authoring at 2019 depth."
        }
      ]
    },
    "TM-7": {
      "version": "4.0.0",
      "changes": [
        {
          "v": "4.0.0",
          "note": "First authoring at 2019 depth."
        }
      ]
    },
    "KT-1": {
      "version": "4.0.1",
      "changes": [
        {
          "v": "4.0.1",
          "note": "PATCH. Backfill after CG authoring: designation criteria now derived from the defensive intent (CG-1) rather than from an unsourced standard. Decisiveness is a judgment about purpose, and CG-1 is where purpose is stated."
        },
        {
          "v": "4.0.0",
          "note": "First authoring at 2019 depth."
        }
      ]
    },
    "KT-2": {
      "version": "4.2.0",
      "changes": [
        {
          "v": "4.2.0",
          "note": "MINOR. Backfill after FO-4 and SM-3: constrained moves are excluded from the effective coverage denominator, so a decisive point on operational technology is scored against achievable coverage rather than against a floor it cannot reach."
        },
        {
          "v": "4.1.0",
          "note": "MINOR. Backfill after TA-3 and GA4: the coverage floor now requires accountable-authority approval with the date recorded relative to first measurement. Without this, the floor is set wherever the program already passes and can never report a deficit."
        },
        {
          "v": "4.0.0",
          "note": "First authoring at 2019 depth."
        }
      ]
    },
    "KT-3": {
      "version": "4.1.0",
      "changes": [
        {
          "v": "4.1.0",
          "note": "MINOR, scope-widening. Activity 5 now requires enumeration of approach routes through workforce, facility and supplier terrain, not only network paths. v3.0 read as network path analysis while declaring T7-T9 as terrain; those are three of the most-used federal intrusion paths."
        }
      ]
    },
    "KT-4": {
      "version": "4.0.1",
      "changes": [
        {
          "v": "4.0.1",
          "note": "PATCH. Added mandatory joint assessment with KT-5. A negative reachability result holds only while KT-5 barriers remain enforced, so KT-4 assessed alone can certify a conclusion a later barrier change has already invalidated."
        },
        {
          "v": "4.0.0",
          "note": "First authoring at 2019 depth."
        }
      ]
    },
    "KT-5": {
      "version": "4.0.1",
      "changes": [
        {
          "v": "4.0.1",
          "note": "PATCH. Mirror of the KT-4 joint assessment requirement."
        },
        {
          "v": "4.0.0",
          "note": "First authoring at 2019 depth."
        }
      ]
    },
    "SM-1": {
      "version": "4.1.0",
      "changes": [
        {
          "v": "4.1.0",
          "note": "MINOR. Corrects the published CSV, which recorded 'the ten-move catalog' against a v3.0 framework carrying eleven forms; the DOCX was already correct. Added the five admission criteria for locally defined moves, which v3.0 referenced only implicitly."
        }
      ]
    },
    "SM-2": {
      "version": "4.0.0",
      "changes": [
        {
          "v": "4.0.0",
          "note": "First authoring at 2019 depth."
        }
      ]
    },
    "SM-3": {
      "version": "4.2.0",
      "changes": [
        {
          "v": "4.2.0",
          "note": "MINOR. Backfill after FO-4: adds a fourth implementation state, constrained, for moves made genuinely unavailable by a recorded terrain constraint. Without it an OT element that cannot be patched or restarted on the defender's schedule sits permanently as planned and depresses coverage forever, which trains OT owners to disengage from the program."
        },
        {
          "v": "4.1.0",
          "note": "MINOR. Added state definitions tied to observable conditions, an evidence requirement for transition to operational, and a false-operational rate metric derived from sampling. SM-3 carries the entire posture computation and was the framework's most fragile control: defeasible by optimistic self-declaration with no downstream detection."
        }
      ]
    },
    "SM-4": {
      "version": "4.1.0",
      "changes": [
        {
          "v": "4.1.0",
          "note": "MINOR. Added an explicit subordination requirement (state what is deprioritized) and a resourcing evidence test. A main effort that subordinates nothing and moved no allocation is a label, and the v3.0 assessment could not distinguish the two."
        }
      ]
    },
    "SM-5": {
      "version": "4.0.1",
      "changes": [
        {
          "v": "4.0.1",
          "note": "PATCH. CSF recovery: adds ID.IM-04 (incident response plans established) \u2014 branches and sequels with linked response procedures constitute the plan."
        },
        {
          "v": "4.0.0",
          "note": "First authoring at 2019 depth."
        }
      ]
    },
    "SM-6": {
      "version": "4.1.0",
      "changes": [
        {
          "v": "4.1.0",
          "note": "MINOR. RACI responsibility assigned to the hunt team rather than terrain owners, on independence grounds: the party that emplaced a move is the wrong party to certify it. Added an assessment step examining whether any effectiveness weighting has ever been reduced."
        }
      ]
    },
    "TA-1": {
      "version": "4.2.0",
      "changes": [
        {
          "v": "4.2.0",
          "note": "MINOR. Backfill after EN: the decide segment is constituted by EN-1 triage and EN-4 escalation, and time should be attributed between them \u2014 a slow triage and an unreachable authority are different problems with different remedies."
        },
        {
          "v": "4.1.0",
          "note": "MINOR. Requires segment-level measurement (detect / decide / contain) reported separately. The segments fail for different reasons and the binding constraint is usually decide latency, which no detection investment shortens. v3.0 reported the total only."
        }
      ]
    },
    "TA-2": {
      "version": "4.1.1",
      "changes": [
        {
          "v": "4.1.1",
          "note": "PATCH. Backfill after EN: the local dwell series is built from EN-2 reconstructions, which is now a control rather than an M10 intention."
        },
        {
          "v": "4.1.0",
          "note": "MINOR. Requires explicit statement of the estimate's known bias: dwell is observable only in discovered intrusions, biasing the sample toward slow adversaries. The signature metric rests half on an imported figure and that should be visible in the result rather than concealed in the ratio."
        }
      ]
    },
    "TA-3": {
      "version": "4.1.0",
      "changes": [
        {
          "v": "4.1.0",
          "note": "MINOR. Records threshold approval date relative to first measurement, closing the post-hoc threshold problem. Generalised framework-wide as GA4."
        }
      ]
    },
    "TA-4": {
      "version": "4.1.0",
      "changes": [
        {
          "v": "4.1.0",
          "note": "MINOR. Added RS.MI-01 to the CSF mapping; pre-authorized containment genuinely supports the Respond/Mitigate outcome. First deliberate step against the Detect/Respond thinness identified in the v3.0 catalog analysis. Authorizations now bounded by condition, scope and duration, and keyed to campaign phase."
        }
      ]
    },
    "TA-5": {
      "version": "4.1.0",
      "changes": [
        {
          "v": "4.1.0",
          "note": "MINOR. Degradation conditions widened to organizational causes: contract transition, key-person absence, hiring gaps, handover windows. v3.0 read as out-of-hours coverage only. Added incident-timing correlation against degraded windows."
        }
      ]
    },
    "CE-1": {
      "version": "4.1.0",
      "changes": [
        {
          "v": "4.1.0",
          "note": "MINOR. Added definition of which cycle steps may be abbreviated under load, and correlation of lapses against incident volume. The cycle is sacrificed exactly when it is most needed, and a cadence holding only in quiet periods is not a cadence."
        }
      ]
    },
    "CE-2": {
      "version": "4.1.0",
      "changes": [
        {
          "v": "4.1.0",
          "note": "MINOR. Added closure as 'unanswerable with current collection', raised as a visibility finding. Converts a perpetually open requirement into a finding about collection rather than an item carried forward indefinitely."
        }
      ]
    },
    "CE-3": {
      "version": "4.1.0",
      "changes": [
        {
          "v": "4.1.0",
          "note": "MINOR. Added measurement of the distribution of issued confidence levels and calibration review against subsequent evidence. A function that never publishes low confidence is unfalsifiable rather than careful."
        }
      ]
    },
    "CE-4": {
      "version": "4.1.0",
      "changes": [
        {
          "v": "4.1.0",
          "note": "MINOR. Requires the denominator to be stated wherever the figure is published, including the ground-held versus techniques-evidenced choice and its rationale; requires framework version recorded against every computed figure; adds sensitivity analysis against the most uncertain input."
        }
      ]
    },
    "CE-5": {
      "version": "4.1.1",
      "changes": [
        {
          "v": "4.1.1",
          "note": "PATCH. CSF recovery: adds GV.RM-06 (risk response prioritization) \u2014 CE-5 ranks by risk retired per unit effort."
        },
        {
          "v": "4.1.0",
          "note": "MINOR. Requires effort estimates on a defined scale so the risk-per-effort ratio can be computed rather than intuited. A backlog with risk scores and no effort estimates has not implemented this control."
        }
      ]
    },
    "CE-6": {
      "version": "4.1.0",
      "changes": [
        {
          "v": "4.1.0",
          "note": "MINOR, correctness-critical. Requires the framework version against every point and a visible break in the trend line at any version boundary. The framework's own versioning rules make cross-version coverage scores incomparable; a series plotted across a boundary shows movement that is a denominator artifact. Two structural releases have already occurred, so existing multi-cycle series in the field are likely affected."
        }
      ]
    },
    "CE-7": {
      "version": "4.1.0",
      "changes": [
        {
          "v": "4.1.0",
          "note": "MINOR. Requires decisions taken from each Brief to be recorded, so use is evidenced rather than assumed. Generation and distribution satisfy the literal requirement while delivering nothing."
        }
      ]
    },
    "CG-1": {
      "version": "4.1.0",
      "changes": [
        {
          "v": "4.1.0",
          "note": "MINOR. Requires the intent to state what may be traded and in what order. An intent that subordinates nothing cannot resolve the decision it exists for, and the operator escalates, which is the decide latency TA-1 measures. Added comprehension testing against a decision the intent should resolve."
        }
      ]
    },
    "CG-2": {
      "version": "4.2.0",
      "changes": [
        {
          "v": "4.2.0",
          "note": "MINOR. Backfill after EN-1: phase entry conditions bound to declaration criteria, so a declared incident meeting a phase entry condition routes to the transition decision rather than being handled locally."
        },
        {
          "v": "4.1.0",
          "note": "MINOR. Requires at least one consequential control to be keyed to phase, and the assessment now tests what materially changed at the last transition rather than that a declaration exists."
        }
      ]
    },
    "CG-3": {
      "version": "4.1.0",
      "changes": [
        {
          "v": "4.1.0",
          "note": "MINOR. Requires the boundary limit (no action outside the agency's own terrain) to be written rather than inferred from doctrine; requires statutory constraints recorded with reference to FO-5 availability floors; requires out-of-hours authority reachability to be tested rather than assumed."
        }
      ]
    },
    "CG-4": {
      "version": "4.1.0",
      "changes": [
        {
          "v": "4.1.0",
          "note": "MINOR. Requires acceptance by a named person whose risk authority covers the exposure, and an expiry forcing re-decision. Adds trending of accepted alongside open. Closes the route by which a program reports a shrinking open set while the accepted set grows without limit."
        }
      ]
    },
    "CG-5": {
      "version": "4.1.1",
      "changes": [
        {
          "v": "4.1.1",
          "note": "PATCH. Backfill after FO-3: names FO-3 as the provider-scope sibling. CG-5 verifies inheritance from a control baseline, FO-3 from a service provider, and a requirement can fall between the two if neither is checked."
        },
        {
          "v": "4.1.0",
          "note": "MINOR. Requires inheritance claims to be verified against the specific assessment result cited rather than asserted at family level, and a failed verification to be recorded as an unassessed requirement. Adds measurement of ASOM-Fed's true marginal assessment cost over the existing baseline."
        }
      ]
    },
    "RC-1": {
      "version": "4.1.1",
      "changes": [
        {
          "v": "4.1.1",
          "note": "PATCH. CSF recovery: adds GV.OC-05 (dependencies determined) \u2014 RC-1 already requires the dependency chain per mission service."
        },
        {
          "v": "4.1.0",
          "note": "MINOR. Requires objectives to satisfy any statutory availability floor under FO-5, and to be approved by the service owner with provenance per GA4. Adds the distinction between a declared objective and a demonstrated one, which is RC-5's object."
        }
      ]
    },
    "RC-2": {
      "version": "4.1.1",
      "changes": [
        {
          "v": "4.1.1",
          "note": "PATCH. CSF recovery: adds PR.IR-03 (resilience mechanisms) \u2014 isolated recovery capability is a resilience mechanism in the CSF sense."
        },
        {
          "v": "4.1.0",
          "note": "MINOR. Adds explicit authentication-path independence testing. v3.0 required the recovery store to sit outside the production trust boundary; the operative test is whether a production administrator credential can reach it, which is narrower and testable."
        }
      ]
    },
    "RC-3": {
      "version": "4.2.0",
      "changes": [
        {
          "v": "4.2.0",
          "note": "MINOR. Backfill after LC-2: trusted rebuild media must also carry verified component provenance. Media independent of the compromised environment but built from a compromised supply chain reconstitutes the intrusion with the system, which media-source independence alone does not catch."
        },
        {
          "v": "4.1.0",
          "note": "MINOR. Requires the rebuild path for the identity plane itself to be tested. Most rebuild plans assume a working identity plane; where identity is what was compromised, the plan carries a circular dependency that only surfaces during recovery."
        }
      ]
    },
    "RC-4": {
      "version": "4.2.0",
      "changes": [
        {
          "v": "4.2.0",
          "note": "MINOR. Backfill after EN-2: restore point selected against the engagement reconstruction where one exists, falling back to the TA-2 dwell estimate otherwise. A reconstruction gives the actual entry time; the estimate is only a bound."
        },
        {
          "v": "4.1.0",
          "note": "MINOR. Requires the integrity record to predate the earliest plausible compromise, not merely to be independently maintained. Restoring from a point after intrusion reinstates the adversary with the data."
        }
      ]
    },
    "RC-5": {
      "version": "4.1.0",
      "changes": [
        {
          "v": "4.1.0",
          "note": "MINOR. Requires every declared objective to have been demonstrated within its stated period, and scenario realism to include loss of the identity plane. Adds exercise cadence provenance per GA4."
        }
      ]
    },
    "FO-1": {
      "version": "4.1.0",
      "changes": [
        {
          "v": "4.1.0",
          "note": "MINOR. Requires derived and incidental holdings (logs, caches, analytics stores, backups) to be included, and unauthorized holdings to be dispositioned as removal rather than protection where the mission permits. Adds two-way reconciliation against privacy impact assessments and systems of records notices. Adds trending on the count and weight of privacy terrain, which a defensible program should see fall."
        }
      ]
    },
    "FO-2": {
      "version": "4.1.0",
      "changes": [
        {
          "v": "4.1.0",
          "note": "MINOR. Requires declared boundaries to be instrumented, not only prohibited: an undeclared flow across an uninstrumented boundary is an absence rather than a finding. Extends flow declaration to flows leaving the authorization boundary, and requires declaration by CUI category where handling requirements differ."
        }
      ]
    },
    "FO-3": {
      "version": "4.1.0",
      "changes": [
        {
          "v": "4.1.0",
          "note": "MINOR. Requires each customer responsibility to carry both an owner and an operational move, since an owned but unimplemented responsibility reports as assigned. Adds recording of cases where agency usage falls outside the provider's authorized scope, in which inheritance does not apply."
        }
      ]
    },
    "FO-4": {
      "version": "4.1.0",
      "changes": [
        {
          "v": "4.1.0",
          "note": "MINOR. Requires the unavailable-move set to be recorded per OT element with its cause (patch window, restart constraint, vendor certification, safety interlock), so coverage is scored against what is achievable rather than carrying permanent unactionable findings. Requires reconciliation against the engineering or facilities operational inventory rather than the IT asset inventory, and testing of declared connections against observed traffic."
        }
      ]
    },
    "FO-5": {
      "version": "4.1.0",
      "changes": [
        {
          "v": "4.1.0",
          "note": "MINOR. Requires floors to be carried into the rules of engagement (CG-3) and the pre-authorized response set (TA-4), so an operator knows at incident time which degradations are legally unavailable. Requires seasonal and cyclical floors to be recorded distinctly, since many federal deadlines bind only in defined periods. Requires legal confirmation rather than operational derivation."
        }
      ]
    },
    "FO-6": {
      "version": "5.1.0",
      "changes": [
        {
          "v": "5.1.0",
          "note": "MINOR. CSF recovery: adds GV.SC-01 (SCRM program established), GV.SC-06 (pre-contract due diligence) and ID.RA-10 (critical supplier assessment). FO-6 is the SCRM program control and requires pre-award assessment, so these were excluded in error rather than by scope."
        },
        {
          "v": "5.0.0",
          "note": "MAJOR, scope change. The v3.0 statement duplicated LC-1 Supplier Terrain Register: both required suppliers with a path into the estate to be represented on the overlay with access recorded. Duplicate controls double-count supply chain coverage in every scored estate, which the framework's own design rules identify as the failure mode degrading a catalog fastest. FO-6 is narrowed to the federal SCRM obligation and its recorded scope; LC-1 retains the operational terrain register. Retitled from 'Supply Chain Terrain' to 'Supply Chain Obligation'. Requires framework owner ratification before publication."
        },
        {
          "v": "4.0.0",
          "note": "First authoring at 2019 depth, prior to the duplication being identified."
        }
      ]
    },
    "WF-1": {
      "version": "4.1.0",
      "changes": [
        {
          "v": "4.1.0",
          "note": "MINOR. Requires roles with indirect access to be included (helpdesk, delegated administration, approval authorities, equivalent-reach contractor roles), exclusion justifications to be recorded, and population size to be trended. Population growth in a high-value role is an expansion of terrain no asset inventory reports."
        }
      ]
    },
    "WF-2": {
      "version": "4.1.0",
      "changes": [
        {
          "v": "4.1.0",
          "note": "MINOR. Requires vetting to be verified against access currently held rather than access held when vetted; requires shared, service and non-human accounts to be recorded distinctly with a named accountable human rather than treated as register exceptions; adds measurement of accumulated privilege per holder, entitlement growth around a correctly vetted person being the common failure."
        }
      ]
    },
    "WF-3": {
      "version": "4.1.0",
      "changes": [
        {
          "v": "4.1.0",
          "note": "MINOR. Requires explicit rules on how individual results may and may not be used, and correlation of measured readiness against real incidents involving those roles. A program that sanctions individuals for simulation failure trains concealment of real incidents. Adds threshold provenance per GA4."
        }
      ]
    },
    "WF-4": {
      "version": "4.1.0",
      "changes": [
        {
          "v": "4.1.0",
          "note": "MINOR. Rights safeguards made assessable rather than advisory: legal and privacy review recorded before use, staged access rules so escalation of access follows escalation of evidence, explicit residue rules for unsubstantiated closures, and defined handoff to HR, counsel or law enforcement. Adds measurement of the unsubstantiated closure rate as a two-sided indicator of whether the initiation threshold is set correctly. RACI responsibility assigned to governance rather than the SOC."
        }
      ]
    },
    "WF-5": {
      "version": "4.2.0",
      "changes": [
        {
          "v": "4.2.0",
          "note": "MINOR. Backfill after FC-2: physical access (badge and facility credentials) made explicit in the enumeration of access outside the primary identity provider. Revocation processes routinely disable the identity-provider account and leave the badge live, which satisfies the single-action property on paper while leaving the person able to enter the building."
        },
        {
          "v": "4.1.0",
          "note": "MINOR. Requires the period to be derived from the tempo at which access could be misused rather than from current process capability; requires enumeration of access outside the primary identity provider; distinguishes planned departure, immediate separation and suspension; requires revocation verified by testing access rather than by ticket closure."
        }
      ]
    },
    "FC-1": {
      "version": "4.1.0",
      "changes": [
        {
          "v": "4.1.0",
          "note": "MINOR. Requires every designated decisive point to resolve to a named facility or a recorded provider region. An agency that cannot say which building its identity provider's hardware occupies cannot defend it physically, plan its rebuild under RC-3, or compare its environmental sustain period against dependent recovery objectives. Adds physical verification of sampled facility contents and concentration findings for siting."
        }
      ]
    },
    "FC-2": {
      "version": "4.1.0",
      "changes": [
        {
          "v": "4.1.0",
          "note": "MINOR. Requires individual attribution at boundaries protecting decisive points, addressing unattributed entry (tailgating): a log recording which badge opened a door rather than who passed through cannot answer an investigation's question. Requires crossing log retention matched to the dwell estimate (TA-2) rather than to a fixed period. Distinguishes physical zones from TM-4 logical trust zones explicitly."
        }
      ]
    },
    "FC-3": {
      "version": "4.1.0",
      "changes": [
        {
          "v": "4.1.0",
          "note": "MINOR. Requires maintenance access to be technically absent outside its window rather than merely unused, with the achieving mechanism recorded; requires session activity logged to agency-held storage so the record survives the vendor relationship; requires scoping to the task rather than to the privilege the vendor requests. States the boundary with LC-3 explicitly to prevent the FO-6/LC-1 duplication pattern recurring."
        }
      ]
    },
    "FC-4": {
      "version": "4.1.0",
      "changes": [
        {
          "v": "4.1.0",
          "note": "MINOR. Requires sustain periods to be tested rather than taken from design specification or vendor rating, and compared against the recovery objectives (RC-1) of services housed in the facility, raising a finding on every contradiction. A four-hour supply under a twenty-four-hour objective is invisible while the two figures live in separate documents. Adds the degradation sequence so loss order is planned rather than discovered."
        }
      ]
    },
    "LC-1": {
      "version": "4.2.0",
      "changes": [
        {
          "v": "4.2.0",
          "note": "MINOR. Confirmed as sole owner of the supplier terrain register following the FO-6 narrowing. Requires reconciliation against provisioned access rather than the acquisition record, since contracts describe intent and entitlements describe capability; requires transitive reach to be recorded; requires reconciliation against SCRM scope under FO-6 so an access-holding supplier outside scope is a recorded position rather than an oversight."
        },
        {
          "v": "4.0.0",
          "note": "First authoring at 2019 depth."
        }
      ]
    },
    "LC-2": {
      "version": "4.1.0",
      "changes": [
        {
          "v": "4.1.0",
          "note": "MINOR. Separates provenance from contents explicitly: a correctly signed package containing a vulnerable transitive dependency has verified provenance and unknown content. Requires the inventory to extend to transitive dependencies and to be current at deployment rather than reconstructed under disclosure pressure. Outcome metric changed to time-to-answer whether a named component is deployed and where, which is the control's real capability."
        }
      ]
    },
    "LC-3": {
      "version": "4.1.0",
      "changes": [
        {
          "v": "4.1.0",
          "note": "MINOR. Requires verification that revocation is technically within the agency's control rather than dependent on supplier action, which is the precondition for LC-5 severance. Requires an expiry on every grant rather than only where obvious, and application to supplier-managed infrastructure where the identity plane is the supplier's by default. States the FC-3 boundary explicitly."
        }
      ]
    },
    "LC-4": {
      "version": "4.1.0",
      "changes": [
        {
          "v": "4.1.0",
          "note": "MINOR. Soak period derived from the measured detection segment under TA-1 with provenance per GA4, rather than chosen from a release calendar: a ring protects only if soak exceeds time-to-notice. Requires the ring to be representative of the estate rather than of the systems most tolerant of disruption, behavioral instrumentation rather than functional testing alone, and a defined emergency bypass path with named authority."
        }
      ]
    },
    "LC-5": {
      "version": "4.1.0",
      "changes": [
        {
          "v": "4.1.0",
          "note": "MINOR. Requires mission continuity assessment following severance, recorded as a finding where the mission cannot continue rather than accepted silently. Requires the period derived from what the access could do if turned hostile rather than from contractual notice terms; requires demonstration for suppliers reaching decisive points rather than for the easiest supplier to test; distinguishes severance from termination."
        }
      ]
    },
    "SM-7": {
      "version": "5.0.0",
      "changes": [
        {
          "v": "5.0.0",
          "note": "NEW in v5.0. Closes the Deceive tactic, which reverse coverage found at zero of D3FEND's seven despite M5 Ambush carrying thirteen techniques and being the dominant effort of Phase I. Alert-to-human period derived from the TA-1 decide segment: a deception alert routed to a queue triaged tomorrow discards the no-false-positive property that made it worth emplacing."
        }
      ]
    },
    "FO-7": {
      "version": "5.0.0",
      "changes": [
        {
          "v": "5.0.0",
          "note": "NEW in v5.0. Declares the per-agency obligation profile the v2.0 design assumed but never required. Makes the FO denominator an approved, published position so coverage figures are comparable between agencies and exclusions are recorded decisions rather than silences."
        }
      ]
    },
    "ID-1": {
      "version": "5.0.0",
      "changes": [
        {
          "v": "5.0.0",
          "note": "NEW in v5.0. Identity plane, enforcement point and trust edge mapping. Trust edges between planes are the highest-value terrain in the estate and are invisible on a network diagram."
        }
      ]
    },
    "ID-2": {
      "version": "5.0.0",
      "changes": [
        {
          "v": "5.0.0",
          "note": "NEW in v5.0. Proofing and credential strength matched to conferred access, extended to non-human identities where long-lived secrets are the dominant failure."
        }
      ]
    },
    "ID-3": {
      "version": "5.0.0",
      "changes": [
        {
          "v": "5.0.0",
          "note": "NEW in v5.0. Authentication assurance carried into the authorization decision, with direct captured-credential testing. Makes M3 Envelopment's stated indicator assessable for the first time."
        }
      ]
    },
    "ID-4": {
      "version": "5.0.0",
      "changes": [
        {
          "v": "5.0.0",
          "note": "NEW in v5.0. Assertion, token and session protection with lifetime keyed to campaign phase and verified estate-wide revocation. Strong authentication is routinely defeated downstream by long-lived bearer tokens."
        }
      ]
    },
    "ID-5": {
      "version": "5.0.0",
      "changes": [
        {
          "v": "5.0.0",
          "note": "NEW in v5.0. Authorization decision point coverage and policy change integrity. An adversary who can add a policy rule authorizes themselves without defeating any other control in the family."
        }
      ]
    },
    "EN-1": {
      "version": "5.0.0",
      "changes": [
        {
          "v": "5.0.0",
          "note": "NEW in v5.0. Event declaration, triage, validation, categorization and prioritization. Declaration criteria fix the threshold so it does not move with analyst judgment or workload, which is what makes cross-cycle tempo comparison valid."
        }
      ]
    },
    "EN-2": {
      "version": "5.0.0",
      "changes": [
        {
          "v": "5.0.0",
          "note": "NEW in v5.0. Engagement reconstruction \u2014 entry, movement, dwell, scope, magnitude and investigation record. M10's stated precondition, previously an intention with no control behind it. RC-4, TA-2, CE-2 and M10.02 all depend on it."
        }
      ]
    },
    "EN-3": {
      "version": "5.0.0",
      "changes": [
        {
          "v": "5.0.0",
          "note": "NEW in v5.0. Evidence preservation with retention derived from the dwell estimate and chain of custody. Retention is the one failure that cannot be remediated afterwards."
        }
      ]
    },
    "EN-4": {
      "version": "5.0.0",
      "changes": [
        {
          "v": "5.0.0",
          "note": "NEW in v5.0. Escalation criteria and reachable authority. With TA-4 this constitutes the decide segment; the binding constraint is usually locating a decision-maker, which is an availability problem rather than a judgment one."
        }
      ]
    },
    "EN-5": {
      "version": "5.0.0",
      "changes": [
        {
          "v": "5.0.0",
          "note": "NEW in v5.0. Eradication verified by hunting against reconstructed tradecraft rather than inferred from absence of observation, including identity-plane eradication, plus the decided transition to recovery with scoped actions."
        }
      ]
    },
    "EN-6": {
      "version": "5.0.0",
      "changes": [
        {
          "v": "5.0.0",
          "note": "NEW in v5.0. Engagement communication across internal, federal community and public audiences, with statutory reporting windows and designated authority per audience."
        }
      ]
    },
    "DV-1": {
      "version": "6.0.0",
      "changes": [
        {
          "v": "6.0.0",
          "note": "PATCH. Technique back-references added so the control is reachable from the maneuver matrix, closing the orphan condition the suite auditor now fails the build on."
        },
        {
          "v": "5.2.0",
          "note": "NEW in v5.2. Device terrain identification with management state, population and reach, reconciled against the identity plane rather than the endpoint console \u2014 the console can only report devices it already manages. Recovers ID.AM-02 software inventory."
        }
      ]
    },
    "DV-2": {
      "version": "6.0.0",
      "changes": [
        {
          "v": "6.0.0",
          "note": "PATCH. Technique back-references added so the control is reachable from the maneuver matrix, closing the orphan condition the suite auditor now fails the build on."
        },
        {
          "v": "5.2.0",
          "note": "NEW in v5.2. Device posture as an access precondition, feeding device assurance into the ID-5 authorization decision. Failing posture must deny, not notify. Recovers PR.PS-01."
        }
      ]
    },
    "DV-3": {
      "version": "6.0.0",
      "changes": [
        {
          "v": "6.0.0",
          "note": "PATCH. Technique back-references added so the control is reachable from the maneuver matrix, closing the orphan condition the suite auditor now fails the build on."
        },
        {
          "v": "5.2.0",
          "note": "NEW in v5.2. Sensor coverage reconciled to the device inventory rather than the sensor console, and sensor liveness treated as a security event. Endpoint retention derived from the dwell estimate so EN-2 reconstruction can reach the entry point. Recovers PR.PS-04 and DE.CM-09."
        }
      ]
    },
    "DV-4": {
      "version": "6.0.0",
      "changes": [
        {
          "v": "6.0.0",
          "note": "PATCH. Technique back-references added so the control is reachable from the maneuver matrix, closing the orphan condition the suite auditor now fails the build on."
        },
        {
          "v": "5.2.0",
          "note": "NEW in v5.2. Execution control scoped to designated terrain rather than universally, with the approved set derived from LC-2 provenance. Recovers PR.PS-05."
        }
      ]
    },
    "DV-5": {
      "version": "6.0.0",
      "changes": [
        {
          "v": "6.0.0",
          "note": "PATCH. Technique back-references added so the control is reachable from the maneuver matrix, closing the orphan condition the suite auditor now fails the build on."
        },
        {
          "v": "5.2.0",
          "note": "NEW in v5.2. Device lifecycle: trusted provisioning and, critically, trust removal and sanitization on retirement, loss or reassignment within a period derived from what retained trust could do."
        }
      ]
    }
  },
  "proposed": {
    "FO-7": {
      "title": "Obligation Profile Declaration",
      "status": "proposed, not in roster",
      "rationale": "The v2.0 design introduced per-agency obligation profiles but no control requires the profile to be declared. Without one, 'out of scope' is an unrecorded judgment, coverage denominators differ between agencies without either recording why, and an assessor cannot distinguish a deliberately excluded obligation from an overlooked one. Adoption would take the roster from 60 to 61 and change every FO-family denominator."
    },
    "ID-family": {
      "title": "Identity Terrain family",
      "status": "proposed, not in roster",
      "rationale": "IA is reached exactly once across the sixty-control catalog, incidentally, via WF-2. Identity is T1, the declared high ground and the plane M3 Envelopment makes decisive. Structural cause: every terrain layer added in v2.0/v3.0 gained dedicated controls (T6/FO-4, T7/WF, T8/FC, T9/LC) while the inherited ZTMM pillars T1-T5 gained none. By the same completeness test that justified T7 in v3.0 (PS at a single citation), IA at a single citation is the finding."
    },
    "T2-devices-family": {
      "title": "Devices Terrain family",
      "status": "RESOLVED in v5.2 as the DV family",
      "rationale": "T2 Devices was the last terrain layer with no dedicated control. Five controls added; every terrain layer inherited or added now has a family specifying it."
    },
    "technique-control-reconciliation": {
      "title": "framework.js technique to control back-references",
      "status": "ANALYZED \u2014 patch spec issued, awaiting application",
      "rationale": "Verified against the supplied connector: 150 techniques and 75 occupied cells confirmed exactly as published, no dangling citations, but 13 orphan controls (all of ID, all of EN, SM-7, FO-7) cited by no technique. Also found: retired CSF 1.1 identifiers ID.BE-05 and PR.DS-06 present in the connector's own CONTROLS block, a header docblock still declaring T1..T5 and M1..M10 against T1..T9/TX and M1..M11 data, and riskReduction weights summing to 117 rather than 100 so a fully-covered design reports 117% risk reduction. Root cause is that CONTROLS duplicates catalog data; the patch generates it instead. See framework_js_patch.md."
    },
    "riskreduction-rebalance": {
      "title": "riskReduction rebalanced to 100",
      "status": "RESOLVED in v5.2",
      "rationale": "Weights rescaled proportionally from the 117 total to 100, order preserved: M1 7, M2 12, M3 15, M4 10, M5 9, M6 8, M7 11, M8 10, M9 6, M10 5, M11 7. A design evidencing every technique now reports 100% rather than 117%. This is a denominator change: coverage and residual-risk figures computed against v5.1 and earlier are not comparable, and CE-6 requires the trend to break here."
    },
    "tower-model-page-refresh": {
      "title": "ASOM-Fed_Tower_Model.html refresh",
      "status": "proposed, stale published artifact",
      "rationale": "The published Tower Model page states v3.0, '60 assessable controls' and 'one of seven interlocking artifacts'. All three are now wrong: v5.0, 73 controls, and the suite has grown. Its topology also carries assets on T1-T5 and TX only, with nothing on T6 Operational Technology, T7 Workforce, T8 Facilities or T9 Supply Chain \u2014 so four terrain layers declared in v2.0/v3.0 have control families and no ground to score them on, and the reference agency reports no posture at all for any of them. Fourteen assets added in the v5.0 Asset Register close this; the page needs regenerating from assets.json."
    },
    "design-philosophy-page-refresh": {
      "title": "asom/design-philosophy page superseded",
      "status": "rebuilt at v5.0 \u2014 page needs replacing",
      "rationale": "The published page carried v1.0 prose against v3.0 data: it stated 'The 35 ASOM-Fed controls' and listed six families against a 60-control eleven-family catalog; its object-model figure enumerated terrain as T1..T5 and TX against a ten-layer model; the forms table gave M1-M10 and described riskReduction as 'the ten values' against eleven forms; and the technique-distinction rule asserted that forTower 'across all six domains' must sum to the total. Rebuilt in full for v5.0 with the posture axis (3.8), the build pipeline (3.9), control admission criteria (4.6), COBIT 2019 depth (4.7), reverse coverage as a discipline (4.8), the FO-6/LC-1 duplication as a worked example of redundancy (4.9), and the v4.0/v5.0 version histories."
    },
    "suite-audit": {
      "title": "audit.py \u2014 permanent suite auditor",
      "status": "ADDED in v6.0",
      "rationale": "Three independent checks, all failing the build: cross-reference (every ID resolves, every entity reachable), language (American English), capitalization (proper nouns and reference terms). First run found 5 orphan DV controls, 726 British spellings across 25 files and 11 capitalization errors. The orphan check is the one that matters: it is the same class of defect that let 13 controls ship uncited by any technique in v5.0. v6.1 adds six model-integrity checks: form technique floor, phase population, role participation in RACI, mission asset coverage, riskReduction sum, and D3FEND mapping-or-recorded-N/A per technique."
    },
    "v6-technique-gaps": {
      "title": "Email response and device sanitization techniques",
      "status": "RESOLVED in v6.1",
      "rationale": "Four techniques added: M1.15 Device Estate Discovery, M7.17 Malicious Message Eviction, M8.17 Device Decommissioning and Sanitization, M11.11 Mailbox and Message Restoration. These give purpose-built homes to D3-ER, D3-RE, D3-DKE, D3-DKF and D3-DKP, which had been attached to techniques that were not their natural home, and fill two previously empty T2 Devices cells. Matrix 150 to 154 techniques, 75 to 77 cells \u2014 a denominator change requiring the trend to break under CE-6."
    }
  }
}