Four Good Frameworks, and the Question None of Them Was Built to Answer.
COBIT, ITIL, ATT&CK and CSF are not obstacles to adopting ASOM-Fed — they are its inputs. Each answers a real question well. This page states what each one is for, and then the narrow gap that is left over.
What Each Framework Was Built to Answer.
A positioning page that describes the incumbents badly fails with exactly the reader who matters: the one who has run a COBIT capability assessment and mapped a SOC to ATT&CK. So each is credited with what it genuinely does well, and its limits are stated as scope rather than as fault.
Is enterprise IT governed, accountable, and delivering value against stakeholder needs?
Unmatched at establishing accountability. It answers who decides, who is answerable, and how mature that decision-making is — with a tailoring method that survives audit.
Unit of workGovernance and management objectives, tailored by design factors and scored by capability level.Does not attemptIt is deliberately not an operational defense method. COBIT tells you that risk should be optimized and security managed; it does not tell you where to put your sensors this quarter.Is the service reliably delivered, changed, and restored?
The strongest available model of service continuity and change discipline. Incident, problem and change practice from ITIL is what keeps a restoration from becoming a second outage.
Unit of workValue streams and management practices across the service value chain.Does not attemptITIL models a service under stress, not a service under attack. Its incident practice is agnostic to whether the disruption is a failed change or an adversary who is still present and adapting.What does the adversary actually do, and can I name it precisely?
The common language of the field, and rightly so. It made detection coverage measurable and gave defenders and vendors a shared vocabulary that is grounded in observed behavior rather than theory.
Unit of workTactics, techniques and sub-techniques observed in real intrusions.Does not attemptATT&CK is descriptive by design — a knowledge base of adversary behavior, not a scheme for arraying a defense. It tells you what may be done to you; it does not designate your main effort or sequence your response.What security outcomes should we be achieving, and how do we talk about them across an organization?
The best outcome taxonomy in existence, and the one a federal reader is already reporting against. Its Govern function closed the framework’s biggest historical gap.
Unit of workFunctions, categories and subcategories — Govern, Identify, Protect, Detect, Respond, Recover.Does not attemptCSF is a taxonomy of outcomes, not a plan. It states that assets should be protected commensurate with risk; deciding which asset is the main effort this quarter is left to the reader.How do I array — and continuously re-array — my defense across my own terrain to hold positional and temporal advantage over a thinking adversary?
It supplies the missing verb. Where the others describe state, outcomes, or adversary behavior, ASOM-Fed describes movement: what to do first, where to concentrate, what to give up, and when to transition.
Unit of workForms of maneuver sequenced across terrain layers, with one designated main effort per phase.Does not attemptIt is not a governance framework and does not try to be one. ASOM-Fed inherits NIST SP 800-53 Rev. 5 and maps its outputs onto CSF 2.0 and the RMF rather than competing with them.The Same Eight Questions, Asked of All Five.
Comparison Matrix — Scope, Clock and Scoreboard
| Dimension | COBIT 2019 | ITIL 4 | MITRE ATT&CK Enterprise | NIST CSF 2.0 | ASOM-Fed 6.1 |
|---|---|---|---|---|---|
| Primary questionWhat the framework was built to answer. | Is IT governed? | Is the service delivered? | What does the adversary do? | What outcomes do we owe? | How do we hold the advantage? |
| PostureWhat the framework assumes about the opponent. | No opponent modeled | Disruption, not adversary | Adversary, observed | Risk, not opponent | Adversary, adapting |
| Unit of workThe thing you actually produce when you use it. | Objective and capability score | Value stream and practice | Technique coverage | Subcategory outcome | A scheme of maneuver |
| SequencingDoes it tell you what to do first, and what next? | Priority, not sequence | Process order within a stream | Adversary order, not yours | None — outcomes are unordered | Explicit: sequence plus main effort |
| ClockThe rate at which the framework expects to be re-run. | Annual to multi-year | Per change, per incident | Per release | Annual to quarterly | Continuous — the loop is the point |
| Success measured byThe scoreboard the framework hands leadership. | Capability level attained | Service levels met | Detection coverage of techniques | Outcomes achieved, tier reached | Temporal advantage over adversary dwell |
| Assessable controlsWhether it ships something an assessor can test against. | Yes — 40 objectives | Practices, not controls | No — a knowledge base | Informative references only | Yes — 78 controls, 14 families |
| Relationship to ASOM-FedHow the two compose in a real program. | Supplies the command authority | Supplies the restoration discipline | Supplies the threat courses of action | Receives ASOM-Fed’s outputs | — |
Primary question
What the framework was built to answer.
- COBIT 2019
- Is IT governed?
- ITIL 4
- Is the service delivered?
- MITRE ATT&CK Enterprise
- What does the adversary do?
- NIST CSF 2.0
- What outcomes do we owe?
- ASOM-Fed 6.1
- How do we hold the advantage?
Posture
What the framework assumes about the opponent.
- COBIT 2019
- No opponent modeled
- ITIL 4
- Disruption, not adversary
- MITRE ATT&CK Enterprise
- Adversary, observed
- NIST CSF 2.0
- Risk, not opponent
- ASOM-Fed 6.1
- Adversary, adapting
Unit of work
The thing you actually produce when you use it.
- COBIT 2019
- Objective and capability score
- ITIL 4
- Value stream and practice
- MITRE ATT&CK Enterprise
- Technique coverage
- NIST CSF 2.0
- Subcategory outcome
- ASOM-Fed 6.1
- A scheme of maneuver
Sequencing
Does it tell you what to do first, and what next?
- COBIT 2019
- Priority, not sequence
- ITIL 4
- Process order within a stream
- MITRE ATT&CK Enterprise
- Adversary order, not yours
- NIST CSF 2.0
- None — outcomes are unordered
- ASOM-Fed 6.1
- Explicit: sequence plus main effort
Clock
The rate at which the framework expects to be re-run.
- COBIT 2019
- Annual to multi-year
- ITIL 4
- Per change, per incident
- MITRE ATT&CK Enterprise
- Per release
- NIST CSF 2.0
- Annual to quarterly
- ASOM-Fed 6.1
- Continuous — the loop is the point
Success measured by
The scoreboard the framework hands leadership.
- COBIT 2019
- Capability level attained
- ITIL 4
- Service levels met
- MITRE ATT&CK Enterprise
- Detection coverage of techniques
- NIST CSF 2.0
- Outcomes achieved, tier reached
- ASOM-Fed 6.1
- Temporal advantage over adversary dwell
Assessable controls
Whether it ships something an assessor can test against.
- COBIT 2019
- Yes — 40 objectives
- ITIL 4
- Practices, not controls
- MITRE ATT&CK Enterprise
- No — a knowledge base
- NIST CSF 2.0
- Informative references only
- ASOM-Fed 6.1
- Yes — 78 controls, 14 families
Relationship to ASOM-Fed
How the two compose in a real program.
- COBIT 2019
- Supplies the command authority
- ITIL 4
- Supplies the restoration discipline
- MITRE ATT&CK Enterprise
- Supplies the threat courses of action
- NIST CSF 2.0
- Receives ASOM-Fed’s outputs
- ASOM-Fed 6.1
- —
The others describe state. ASOM-Fed describes movement.
It supplies the missing verb. Where the others describe state, outcomes, or adversary behavior, ASOM-Fed describes movement: what to do first, where to concentrate, what to give up, and when to transition.
And the limit, stated as plainly: it is not a governance framework and does not try to be one. ASOM-Fed inherits NIST SP 800-53 Rev. 5 and maps its outputs onto CSF 2.0 and the RMF rather than competing with them.
How They Compose.
Nobody is retiring COBIT to adopt this. The realistic end state is an agency running all of them, with each doing the job it is best at — and this page is only useful if it says which job that is.
A scheme of maneuver is worthless without engagement authority — the standing answer to which defensive fires the SOC may execute without escalation, and which need the Authorizing Official. That authority is a governance artifact, and COBIT is how a federal agency establishes and evidences it. Run them together: COBIT sets the rules of engagement, ASOM-Fed operates inside them.
The Isolation / Retrograde maneuver deliberately degrades a service to preserve the mission — read-only rather than exposed. That is a service-impacting change made under contact, and it lands squarely in ITIL’s change and incident practice. ASOM-Fed makes the call; ITIL executes it without turning the containment into a second outage.
The MAP step of the cycle builds threat courses of action — most likely and most dangerous — and ATT&CK is the best available source for what those courses of action actually consist of. Technique coverage then becomes an input to the scheme rather than the scoreboard: not "how many techniques do we detect", but "do we detect the ones on the avenue of approach to our main effort".
Every cycle output maps onto a CSF 2.0 function: framing to Govern, terrain preparation to Identify, the protective maneuvers to Protect, screening and deception to Detect, delay and counterattack to Respond, reconstitution to Recover. The agency earns its compliance narrative as exhaust from defending, rather than as a separate exercise in the spring.
ASOM-Fed inherits NIST SP 800-53 Rev. 5. Every control in its catalog carries the 800-53 controls it derives from and the CSF 2.0 subcategories it satisfies, so an assessor can trace any ASOM-Fed finding back to the baseline the agency is already authorized against. D3FEND™ and ATT&CK® are trademarks of The MITRE Corporation. This mapping is published by threatDefendr and is neither produced nor endorsed by MITRE.
The Gap Is Only Worth Closing If It Is Assessable.
Seventy-eight controls across fourteen families, each with a statement, a discussion, an evidence expectation and an assessment procedure — shipped as machine-readable data, not as a diagram.