ASOM-Fedv6.1Open the explorer
Positioning

Four Good Frameworks, and the Question None of Them Was Built to Answer.

COBIT, ITIL, ATT&CK and CSF are not obstacles to adopting ASOM-Fed — they are its inputs. Each answers a real question well. This page states what each one is for, and then the narrow gap that is left over.

Scope, Stated Fairly

What Each Framework Was Built to Answer.

A positioning page that describes the incumbents badly fails with exactly the reader who matters: the one who has run a COBIT capability assessment and mapped a SOC to ATT&CK. So each is credited with what it genuinely does well, and its limits are stated as scope rather than as fault.

2019
COBIT 2019ISACA

Is enterprise IT governed, accountable, and delivering value against stakeholder needs?

Unmatched at establishing accountability. It answers who decides, who is answerable, and how mature that decision-making is — with a tailoring method that survives audit.

Unit of workGovernance and management objectives, tailored by design factors and scored by capability level.Does not attemptIt is deliberately not an operational defense method. COBIT tells you that risk should be optimized and security managed; it does not tell you where to put your sensors this quarter.
4
ITIL 4PeopleCert / AXELOS

Is the service reliably delivered, changed, and restored?

The strongest available model of service continuity and change discipline. Incident, problem and change practice from ITIL is what keeps a restoration from becoming a second outage.

Unit of workValue streams and management practices across the service value chain.Does not attemptITIL models a service under stress, not a service under attack. Its incident practice is agnostic to whether the disruption is a failed change or an adversary who is still present and adapting.
Enterprise
MITRE ATT&CK EnterpriseMITRE

What does the adversary actually do, and can I name it precisely?

The common language of the field, and rightly so. It made detection coverage measurable and gave defenders and vendors a shared vocabulary that is grounded in observed behavior rather than theory.

Unit of workTactics, techniques and sub-techniques observed in real intrusions.Does not attemptATT&CK is descriptive by design — a knowledge base of adversary behavior, not a scheme for arraying a defense. It tells you what may be done to you; it does not designate your main effort or sequence your response.
2.0
NIST CSF 2.0NIST

What security outcomes should we be achieving, and how do we talk about them across an organization?

The best outcome taxonomy in existence, and the one a federal reader is already reporting against. Its Govern function closed the framework’s biggest historical gap.

Unit of workFunctions, categories and subcategories — Govern, Identify, Protect, Detect, Respond, Recover.Does not attemptCSF is a taxonomy of outcomes, not a plan. It states that assets should be protected commensurate with risk; deciding which asset is the main effort this quarter is left to the reader.
This one
ASOM-Fed 6.1threatDefendr

How do I array — and continuously re-array — my defense across my own terrain to hold positional and temporal advantage over a thinking adversary?

It supplies the missing verb. Where the others describe state, outcomes, or adversary behavior, ASOM-Fed describes movement: what to do first, where to concentrate, what to give up, and when to transition.

Unit of workForms of maneuver sequenced across terrain layers, with one designated main effort per phase.Does not attemptIt is not a governance framework and does not try to be one. ASOM-Fed inherits NIST SP 800-53 Rev. 5 and maps its outputs onto CSF 2.0 and the RMF rather than competing with them.
Head to Head

The Same Eight Questions, Asked of All Five.

Exhibit 1

Comparison Matrix — Scope, Clock and Scoreboard

DimensionCOBIT 2019ITIL 4MITRE ATT&CK EnterpriseNIST CSF 2.0ASOM-Fed 6.1
Primary questionWhat the framework was built to answer.Is IT governed?Is the service delivered?What does the adversary do?What outcomes do we owe?How do we hold the advantage?
PostureWhat the framework assumes about the opponent.No opponent modeledDisruption, not adversaryAdversary, observedRisk, not opponentAdversary, adapting
Unit of workThe thing you actually produce when you use it.Objective and capability scoreValue stream and practiceTechnique coverageSubcategory outcomeA scheme of maneuver
SequencingDoes it tell you what to do first, and what next?Priority, not sequenceProcess order within a streamAdversary order, not yoursNone — outcomes are unorderedExplicit: sequence plus main effort
ClockThe rate at which the framework expects to be re-run.Annual to multi-yearPer change, per incidentPer releaseAnnual to quarterlyContinuous — the loop is the point
Success measured byThe scoreboard the framework hands leadership.Capability level attainedService levels metDetection coverage of techniquesOutcomes achieved, tier reachedTemporal advantage over adversary dwell
Assessable controlsWhether it ships something an assessor can test against.Yes — 40 objectivesPractices, not controlsNo — a knowledge baseInformative references onlyYes — 78 controls, 14 families
Relationship to ASOM-FedHow the two compose in a real program.Supplies the command authoritySupplies the restoration disciplineSupplies the threat courses of actionReceives ASOM-Fed’s outputs

Primary question

What the framework was built to answer.

COBIT 2019
Is IT governed?
ITIL 4
Is the service delivered?
MITRE ATT&CK Enterprise
What does the adversary do?
NIST CSF 2.0
What outcomes do we owe?
ASOM-Fed 6.1
How do we hold the advantage?

Posture

What the framework assumes about the opponent.

COBIT 2019
No opponent modeled
ITIL 4
Disruption, not adversary
MITRE ATT&CK Enterprise
Adversary, observed
NIST CSF 2.0
Risk, not opponent
ASOM-Fed 6.1
Adversary, adapting

Unit of work

The thing you actually produce when you use it.

COBIT 2019
Objective and capability score
ITIL 4
Value stream and practice
MITRE ATT&CK Enterprise
Technique coverage
NIST CSF 2.0
Subcategory outcome
ASOM-Fed 6.1
A scheme of maneuver

Sequencing

Does it tell you what to do first, and what next?

COBIT 2019
Priority, not sequence
ITIL 4
Process order within a stream
MITRE ATT&CK Enterprise
Adversary order, not yours
NIST CSF 2.0
None — outcomes are unordered
ASOM-Fed 6.1
Explicit: sequence plus main effort

Clock

The rate at which the framework expects to be re-run.

COBIT 2019
Annual to multi-year
ITIL 4
Per change, per incident
MITRE ATT&CK Enterprise
Per release
NIST CSF 2.0
Annual to quarterly
ASOM-Fed 6.1
Continuous — the loop is the point

Success measured by

The scoreboard the framework hands leadership.

COBIT 2019
Capability level attained
ITIL 4
Service levels met
MITRE ATT&CK Enterprise
Detection coverage of techniques
NIST CSF 2.0
Outcomes achieved, tier reached
ASOM-Fed 6.1
Temporal advantage over adversary dwell

Assessable controls

Whether it ships something an assessor can test against.

COBIT 2019
Yes — 40 objectives
ITIL 4
Practices, not controls
MITRE ATT&CK Enterprise
No — a knowledge base
NIST CSF 2.0
Informative references only
ASOM-Fed 6.1
Yes — 78 controls, 14 families

Relationship to ASOM-Fed

How the two compose in a real program.

COBIT 2019
Supplies the command authority
ITIL 4
Supplies the restoration discipline
MITRE ATT&CK Enterprise
Supplies the threat courses of action
NIST CSF 2.0
Receives ASOM-Fed’s outputs
ASOM-Fed 6.1
Read the Clock row first. It is the row that explains all the others: a framework re-run annually cannot arbitrate a decision that has to be made in an afternoon, and was never meant to.
The claim, in one sentence

The others describe state. ASOM-Fed describes movement.

It supplies the missing verb. Where the others describe state, outcomes, or adversary behavior, ASOM-Fed describes movement: what to do first, where to concentrate, what to give up, and when to transition.

And the limit, stated as plainly: it is not a governance framework and does not try to be one. ASOM-Fed inherits NIST SP 800-53 Rev. 5 and maps its outputs onto CSF 2.0 and the RMF rather than competing with them.

In Practice

How They Compose.

Nobody is retiring COBIT to adopt this. The realistic end state is an agency running all of them, with each doing the job it is best at — and this page is only useful if it says which job that is.

COBIT
COBIT says who may decide. ASOM-Fed says what they decide.

A scheme of maneuver is worthless without engagement authority — the standing answer to which defensive fires the SOC may execute without escalation, and which need the Authorizing Official. That authority is a governance artifact, and COBIT is how a federal agency establishes and evidences it. Run them together: COBIT sets the rules of engagement, ASOM-Fed operates inside them.

ITIL
ITIL restores the service. ASOM-Fed decides what to give up first.

The Isolation / Retrograde maneuver deliberately degrades a service to preserve the mission — read-only rather than exposed. That is a service-impacting change made under contact, and it lands squarely in ITIL’s change and incident practice. ASOM-Fed makes the call; ITIL executes it without turning the containment into a second outage.

MITRE ATT&CK
ATT&CK names the threat. ASOM-Fed arrays against it.

The MAP step of the cycle builds threat courses of action — most likely and most dangerous — and ATT&CK is the best available source for what those courses of action actually consist of. Technique coverage then becomes an input to the scheme rather than the scoreboard: not "how many techniques do we detect", but "do we detect the ones on the avenue of approach to our main effort".

NIST CSF
CSF states the outcome. ASOM-Fed produces the evidence.

Every cycle output maps onto a CSF 2.0 function: framing to Govern, terrain preparation to Identify, the protective maneuvers to Protect, screening and deception to Detect, delay and counterattack to Respond, reconstitution to Recover. The agency earns its compliance narrative as exhaust from defending, rather than as a separate exercise in the spring.

ASOM-Fed inherits NIST SP 800-53 Rev. 5. Every control in its catalog carries the 800-53 controls it derives from and the CSF 2.0 subcategories it satisfies, so an assessor can trace any ASOM-Fed finding back to the baseline the agency is already authorized against. D3FEND™ and ATT&CK® are trademarks of The MITRE Corporation. This mapping is published by threatDefendr and is neither produced nor endorsed by MITRE.

Next

The Gap Is Only Worth Closing If It Is Assessable.

Seventy-eight controls across fourteen families, each with a statement, a discussion, an evidence expectation and an assessment procedure — shipped as machine-readable data, not as a diagram.