Design and Philosophy
Why the framework is shaped the way it is — the object model, the level of abstraction it deliberately occupies, the criteria every form of maneuver and technique must meet to be admitted, and where it sits among the frameworks a federal agency already runs.
What this document is. Not the framework itself — the framework ships as the reference manual, the control catalog and the maneuver matrix. This explains the object model, the abstraction level, and the admission criteria for new entries, so an adopter can extend ASOM-Fed correctly and a reviewer can argue with it precisely. Its structure follows the convention MITRE established for ATT&CK: Design and Philosophy, because a framework that asks to be adopted owes its adopters an account of how it was built.
Introduction
Federal network defense is still largely run as garrison security: a boundary, a control catalog, an assessment calendar, and a queue of alerts worked in the order they arrive. The posture is static by construction — its unit of planning is the control, and controls do not move.
The adversaries that matter do not operate that way. Nation-state collectors, fraud rings working public service portals, and ransomware crews exploiting deadline-sensitive availability all behave like a maneuvering force: they seek positional advantage, mass at a decisive point, and win by operating inside the defender’s decision cycle. A defense whose only vocabulary is the control cannot describe what is happening to it, let alone respond in kind.
ASOM-Fed supplies the missing vocabulary. It reframes defense as a maneuver problem led by intelligence analysis, in a form that is assessable, machine-readable, and mappable onto the compliance obligations an agency already carries.
What the Framework Measures, and What It Measured
A framework that cannot be wrong is not worth adopting. ASOM-Fed is falsifiable in two directions, and both have returned uncomfortable answers about the framework itself — including about how it scores.
Against the control baseline. Every ASOM-Fed control cites the SP 800-53 Rev. 5 controls it inherits from, which makes the families it never cites a direct measure of the federal estate it fails to reach. That test drove the last structural release: version 2.0 inherited from sixteen of the twenty families and never once from AT, IA, MA or PE, which said plainly that the framework modeled the machines of a federal estate and not the people who operate it, the buildings it sits in, or the suppliers who reach into it. Version 3.0 added those as terrain. The 78 controls now inherit from all twenty families.
Against real architectures. The ten agency archetypes in the Studio are scored on every release. Coverage is deliberately measured as ground held rather than techniques touched: the framework is 77 terrain×form cells holding 154 techniques, and a node tagged with one form evidences every technique in its cell at once — sixteen of them, in the largest. Counting techniques therefore rewards tagging a crowded cell over a sparse one for identical effort, and lets a design be driven toward 100% without doing anything more. Cells are the unit the model can defend.
| Measure | Result | What it says |
|---|---|---|
| Ground held, best to worst estate | 7–44% | Even the strongest reference estate operates on well under half the board. |
| Estates missing a whole form of maneuver | 6 of 10 | A capability gap, not a procurement gap — no product closes it. |
Estates that can perform M10 Exploitation & Pursuit | 4 of 10 | The rest cannot convert contact into durable advantage, and so fight the same intrusion twice. |
Estates that can perform M9 Spoiling Attack | 5 of 10 | Half cannot act on an advisory before exploitation reaches them. |
| Cells no estate occupies | 31 of 75 | Whole forms of maneuver unavailable on whole layers of terrain. |
M10, forty-two of 111 techniques were evidenced by none of them, and the 35 controls reached five of the six CSF 2.0 Functions with Recover empty. Version 3.0 declared three new terrain layers that, on first measurement, no reference estate stood on at all. Both were defects in the framework, found by running it rather than by reading it, and both are recorded in §7 rather than quietly corrected. An adopter should weigh how a framework handles being wrong at least as heavily as what it claims when it is right.Background and History
ASOM-Fed fuses two mature bodies of U.S. Army doctrine that are rarely combined, and grounds them on the federal zero-trust terrain defined by civilian policy:
- Scheme of maneuver, from operational art. Allen’s Cyber Maneuver and Schemes of Maneuver supplies the definition ASOM-Fed builds on: cyber maneuver is action taken within and through cyberspace to achieve positional and temporal advantage, and a scheme of maneuver names which categories of maneuver apply and in what sequence.
- Intelligence analysis, from ATP 2-33.4 — the analytic engine (Screen → Analyze → Integrate → Produce), structured analytic techniques, Intelligence Preparation of the Battlefield, explicit confidence levels, and priority intelligence requirements.
- The federal terrain — the CISA Zero Trust Maturity Model, NIST SP 800-207, TIC 3.0, NIST CSF 2.0, the NIST RMF and SP 800-53, and OMB M-22-09.
The single most consequential idea taken from Allen is that categories of maneuver are durable while the techniques that realize them are perishable. Leaders can therefore direct a defense in terms of intent without being engineers, and engineers can re-tool without invalidating the plan. Everything about the framework’s shape follows from taking that distinction seriously — and it is, not coincidentally, the same separation ATT&CK draws between a tactic and a technique.
Use Cases
ASOM-Fed is built to be used in six ways. Each is a real workflow, not an aspiration.
The ASOM-Fed Model
The Maneuver Matrix
The matrix is the framework’s primary presentation. Its columns are the eleven forms of defensive maneuver; the cells beneath each column are the techniques that give that form effect. Reading down a column tells you how a form is actually performed; reading across the top tells you what a defense is capable of at all.
The layout convention is borrowed openly from the ATT&CK Enterprise matrix, for a reason that is structural rather than aesthetic: both models separate a small set of durable, intent-level categories from a large, churning set of concrete behaviors. Where the two differ is in whose behavior is cataloged — ATT&CK describes what an adversary does to you, ASOM-Fed describes how you array against it.
Terrain Layers
ASOM-Fed models the enterprise as nine terrain layers plus one cross-cutting domain. Five of the nine are the CISA ZTMM v2.0 pillars, taken unchanged and renamed as terrain because terrain is what a scheme of maneuver is drawn on. The other four — operational technology, workforce, facilities and supply chain — are ASOM-Fed’s own, and each was added because a measurable part of a federal estate had no ground to stand on without it. Each carries a metaphor that is load-bearing, not decorative: it tells a planner what kind of ground they are defending.
TX and T6 are not. ZTMM defines three cross-cutting capabilities (Visibility and Analytics, Automation and Orchestration, Governance) and ASOM-Fed consolidates them into one terrain layer, because as terrain they are not ground an adversary moves across; they are what lets you move. T6 Operational Technology is an addition of ours in version 2.0, introduced because a federal estate that runs dams, clinical devices, laboratory instruments or building systems was otherwise being scored as though it were a server estate — the moves available on that ground are narrower and the consequence of loss is physical. ZTMM has no equivalent pillar; agencies reporting ZTMM maturity should read T6 as terrain they hold that the maturity model does not ask about. That is a deliberate simplification and it is lossy: an agency reporting ZTMM maturity per cross-cutting capability cannot map those three onto TX one-to-one, and should report them separately. The tower IDs (T1–T9, TX) and every terrain metaphor in the table below are ASOM-Fed’s own; CISA neither numbers its pillars nor describes them as terrain.| ID | Domain | Terrain character and what it implies |
|---|---|---|
T1 | Identity | HIGH GROUND Whoever holds it controls movement everywhere else. Contested first, and the reason M3 Envelopment carries the largest single risk weighting. |
T2 | Devices | ENTRY FORDS Where forces cross into the estate. Few crossings, heavily used, worth watching. |
T3 | Networks | CORRIDORS Routes of movement. The only layer where you can meaningfully canalize an adversary onto ground you own. |
T4 | Applications and Workloads | URBAN TERRAIN Dense, complex, close-quarters — the hardest ground to defend and the easiest to lose track of. |
T5 | Data | THE OBJECTIVE The reason the campaign exists. Everything else is defended because it leads here. |
T6 | Operational Technology | CONTESTED GROUND Ground you cannot freely maneuver on: systems that often cannot be patched or restarted on the defender’s schedule, where loss has a physical consequence. Added in v2.0; not a ZTMM pillar. |
T7 | Workforce | THE FORCE ITSELF The people who operate the estate can be reconnoitred, targeted, turned and lost. Added in v3.0; the only terrain that is simultaneously the defending force. |
T8 | Facilities | THE GROUND YOU STAND ON Buildings, zones, badge systems, and the vendor maintenance paths that reach through them. The oldest terrain there is, and the one most often left off a cyber overlay. Added in v3.0. |
T9 | Supply Chain | LINES OF COMMUNICATION The routes by which the estate is resupplied, and therefore the routes by which it is reached. Doctrinally the rear area; in federal practice, frequently the actual intrusion path. Added in v3.0. |
TX | Cross-Cutting | ENABLERS Visibility is reconnaissance, automation is mobility, governance is command authority. Not ground, but what lets you move on it. |
T1–T9/TX are the Defense Tower Model’s tower IDs, already used by the Studio canvas. Reusing them means a canvas node and a matrix cell share one key, so linking them is a lookup rather than a translation table — and a translation table is exactly the thing that silently rots.Forms of Maneuver
The eleven forms are the framework’s durable layer. They are defensive recastings of classical forms of maneuver, chosen to be exhaustive at their level of abstraction: any defensive action an agency takes should be recognizable as an instance of one of them.
| Field | Type | Meaning |
|---|---|---|
id | string | M1–M10. Stable for the life of the framework; never reused. |
name | string | The doctrinal name, e.g. Envelopment, Ambush, Spoiling Attack. |
intent | string | One clause stating what the form is for. This is what the CISO or Authorizing Official issues; it must be comprehensible without technical knowledge. |
tower | enum | The terrain layer the form is principally concerned with. Advisory — techniques within a form may sit on other layers. |
riskReduction | integer | Percentage residual-risk reduction attributed to the form when fully operational, used by the Tower Model’s allocation arithmetic. |
Techniques
Techniques are the perishable layer: the concrete, observable things an agency does to make a form real on specific ground. Version 6.1 catalogs 154 of them — the count has risen at every release, from 111 at v1.0 through 125 at v2.0 and 150 at v3.0, and it is expected to keep rising, because this is the layer that tracks tooling. The forms above it have not changed since v1.0, which is the point of separating them.
| Field | Type | Meaning |
|---|---|---|
id | string | M<form>.<nn>, e.g. M5.01. The prefix encodes the column, so an ID alone locates a technique without the header. |
name | string | Names the action, not a product. |
tower | enum | The terrain layer this technique acts on. Exactly one. |
phases | list | The campaign phases in which this technique is a dominant effort — not every phase in which it is merely running. |
does | string | One sentence: what the technique does, phrased as defensive intent rather than configuration. |
indicator | string | Mandatory. What observable state proves the technique is working. This field is the framework’s assessability guarantee. |
controls | list | ASOM-Fed control IDs making the technique assessable, and optionally a cross-reference to a sibling technique. |
Controls
The 78 ASOM-Fed controls are the assessment layer. They exist because SP 800-53 Rev. 5 — roughly 1,196 controls across twenty families — has no family that specifies the maneuver layer: nothing in it requires you to know your terrain, designate a main effort, measure your decision tempo, or prove you can perform a form of maneuver at all. ASOM-Fed neither replaces nor duplicates 800-53; it adds the missing family and inherits everywhere else.
| Field | Meaning |
|---|---|
id | Family prefix plus number, e.g. KT-2. |
title | Short requirement name. |
nist80053 | The 800-53 Rev. 5 controls this inherits from — the crosswalk that keeps ASOM-Fed additive. |
csf20 | CSF 2.0 subcategories satisfied. |
| Families (14) | TM Terrain Management · KT Key Terrain and Decisive Points · ID Identity Terrain · DV Devices Terrain · SM Scheme of Maneuver · TA Tempo and Temporal Advantage · EN Engagement and Pursuit · CE Cycle Execution and Assurance · CG Command and Governance · RC Reconstitution and Recovery · FO Federal Obligations · WF Workforce Terrain · FC Facilities Terrain · LC Lines of Communication |
Campaign Phases
Six phases, adapted from joint phasing, each with a stated objective and a dominant set of forms. Phasing is what lets leadership see cyber defense as a campaign with a main effort per phase rather than an undifferentiated grind — and it is what makes “we are in Phase III” a sentence that changes behavior, because pre-authorized responses and session lifetimes are keyed to it.
| ID | Phase | Objective | Dominant forms |
|---|---|---|---|
0 | Shape | Set the conditions | M1 · M2 · M3 · M9 |
I | Deter | Raise the adversary’s cost | M3 · M4 · M5 |
II | Seize Initiative | Contest first contact | M1 · M4 · M6 |
III | Dominate | Defeat the attempt | M7 · M8 · M5 |
IV | Stabilize | Restore secure operations | M8 · M10 · M11 |
V | Restore | Hand back to steady state | M11 · M10 · M7 |
Object Model Relationships
The model is deliberately small, and every relationship in it is a single hop. Ten object classes resolve into two sentences: an agency builds the first, and the framework fixes the second. The full object model states each class with the question it answers and the class it is most often mistaken for.
Machine-Readable Form
The framework ships as a script, framework.js, which is the single source of truth for the technique layer and is loaded by both the matrix and the Studio canvas. It exposes byId, forTower, forForm, link and verify, and it self-checks against the Studio’s own tables at load time rather than letting the two drift apart silently.
The Methodology
The Loop the Whole Framework Serves
Everything above is machinery. This is what the machinery is for: six steps that turn continuously, each consuming the previous step’s output and producing the next one’s input. The framework is a scheme of maneuver rather than a checklist precisely because those handoffs exist — a checklist has items, and a scheme has a sequence in which each move creates the conditions for the next.
The Defender’s Perspective
ATT&CK is built from the adversary’s perspective, which is what makes it honest: it describes what is actually done to networks rather than what defenders wish were true. ASOM-Fed inverts the vantage point but keeps the discipline. Every entry is written from the perspective of the force that owns the ground — which is the defender’s one structural advantage, and the thing control catalogs consistently fail to exploit.
Owning the ground means a defender may do things an attacker cannot: emplace obstacles, choose which corridors to leave open and instrument them, seed decoys, trade space for time, and fail secure by design. Seven of the eleven forms have no offensive analogue at all. A framework organized around controls cannot express any of them, because none of them is a control.
Doctrinal Derivation, and How It Differs from ATT&CK
Two consequences follow, and adopters should hold ASOM-Fed to them:
- ASOM-Fed does not claim measured efficacy. The
riskReductionweightings are an allocation model for prioritization — a defensible way to rank where the next control dollar goes — not an empirical finding about how much risk a form removes. They should be re-based against an agency’s own incident history once it has one. - Contact is the correcting mechanism. Form M10 (Exploitation & Pursuit) exists partly to feed the framework itself: every engagement is meant to update the terrain overlay, the intelligence requirements, and this catalog. A doctrinal framework that never meets evidence stays a theory.
What ASOM-Fed gains in exchange is coverage of the defensive design space independent of what has happened to any particular agency yet — which is the right trade for a planning framework and the wrong one for a threat-intelligence framework. Use ATT&CK for the latter.
Abstraction
ATT&CK’s foundational argument is that a mid-level model is necessary: high-level lifecycle models describe goals but not actions, and low-level databases describe artifacts stripped of context, so something in between is needed to connect behavior to defenses. ASOM-Fed makes the identical argument on the defensive side.
What the maneuver abstraction provides that neither neighbor does:
- A common vocabulary in which a CISO and an engineer can describe the same defense at their own altitudes.
- A unit of planning — the form — that survives re-tooling, reorganization and vendor change.
- A way to express sequence and main effort, which no control catalog can represent.
- A gap finding that is actionable: an absent column names a capability, not a purchase.
- A place to attach tempo, which is the only measure that says whether you are winning.
What Makes a Form of Maneuver
Forms are the framework’s stable spine, so the bar for adding one is deliberately very high. In practice the set is closed; version 1.0 expects to add techniques indefinitely and forms almost never. A candidate form must satisfy all five:
The riskReduction weighting is assigned relative to the others rather than independently — the ten values are a distribution expressing which forms matter most on federal terrain, which is why M3 Envelopment carries the largest and M10 the smallest. As above, these are planning weights, not measurements.
What Makes a Technique
Naming
A technique is named for the action, in a form that stays true across implementations: Phishing-Resistant Authentication, not FIDO2 rollout; Estate-Wide Session Revocation, not the name of the console you do it from. If a name cannot survive its vendor being replaced, it is the wrong name.
Levels of abstraction
Techniques sit at three levels, and all three are legitimate:
- General across terrain — the behavior is the same wherever it applies, e.g.
M2.14Control Failure Detection. - General with layer-specific expression — one intent realized differently per layer, e.g.
M5.01–M5.08, the same deception intent expressed in data, identity, network, endpoint, application and cloud terrain. - Specific to one layer — e.g.
M4.09Removable Media Control, meaningful only on device terrain.
Where a technique has several steps that resemble other techniques, the deciding question is the same one ATT&CK asks: what is the distinguishing attribute? Describe that, and cross-reference the rest.
Intent before mechanism
The does field states what the technique accomplishes defensively, not how a product is configured. This is the rule that keeps the framework from decaying into a settings guide, and it is the one most often broken by well-meaning contributions.
The success-indicator requirement
Every technique must state what observable state proves it is working — and the indicator must be falsifiable. “MFA is deployed” is not an indicator; “credential phishing yields no usable authentication” is, because it can be tested and can fail.
Technique distinction
Two techniques are distinct when they differ in at least one of:
- The terrain they act on. Deception in the data layer and deception in the identity plane are separate techniques because they are emplaced, owned and evaded differently.
- The form they serve. The same mechanism can serve different intents; session revocation appears under M3 as a standing capability and under M8 as an estate-wide retrograde action, and those are genuinely different defensive acts.
- What proves them. If two candidates would share an indicator exactly, they are one technique.
Each technique carries exactly one terrain layer. Where a technique plausibly spans layers, it is assigned to the layer whose loss would defeat it, and cross-referenced from the others. This keeps the matrix partitionable — forTower across all six domains must sum to the total, a property the test suite asserts.
Creating and Changing Entries
Creating a technique
- Name the defensive effect in one sentence, without naming a product.
- Identify the form. Which intent does it serve? If it serves two, it is probably two techniques.
- Assign one terrain layer — the layer whose loss defeats it.
- Write a falsifiable indicator. If you cannot, stop: the entry is not ready.
- Bind controls. Cite the ASOM-Fed controls that make it assessable; if none fits, that is a signal the control set needs extending, which is a separate and heavier change.
- Assign dominant phases — where it carries the main effort, not everywhere it runs.
- Check distinction against every existing technique in the form.
Enhancing and deprecating
Sharpening a description, strengthening an indicator, or adding a control binding is always preferred to adding a near-duplicate. The catalog’s value degrades faster from redundancy than from omission: a matrix with two cells that mean the same thing quietly double-counts coverage. IDs are never reused — a technique that stops being meaningful is marked deprecated and keeps its ID, so historical coverage scores stay interpretable.
Worked Examples
M5.03 Decoy Credentials. Effect: credential material that is valid-looking, monitored and powerless, seeded where harvesting would find it. Form: M5 Ambush — it trades space for information and time. Terrain: T1 Identity; the credentials live in the identity plane and its compromise is what defeats them. Indicator: “credential harvesting is detected on use of a planted credential” — falsifiable, and testable by a red team in an afternoon. Distinct from M5.01 Decoy Records (different terrain, different indicator) and from the M3 techniques (different intent: this one is not trying to prevent movement, it is trying to hear it).M2.05 Endpoint Detection and Response Coverage, whose indicator is “coverage is reconciled to the inventory, not to the console” — deliberately targeting the failure mode where a console reports 100% of the hosts it knows about. And M2.14 Control Failure Detection, for the silent-agent problem, which is a different defensive effect and therefore a different technique.Agency Instantiation
ASOM-Fed is published against a generic Federal Reference Agency archetype and contains no agency-specific information by design. Adopting it means substituting your own systems, boundaries and mission threads into the terrain overlay while leaving the forms, techniques and controls untouched. An agency that finds itself editing the framework rather than the overlay has usually mis-modeled its terrain.
Relationship to Other Frameworks
MITRE ATT&CK
Complementary, not competing, and the cleanest relationship here: ATT&CK catalogs adversary behavior; ASOM-Fed catalogs defensive maneuver. A threat course of action expressed in ATT&CK techniques is the natural input to the MAP step of the ASOM cycle, and the output is a scheme of maneuver expressed in ASOM-Fed forms. Agencies already running ATT&CK Navigator layers — or this platform’s own ATT&CK coverage map — lose nothing by adopting ASOM-Fed; the two overlays answer different questions about the same estate.
MITRE D3FEND
D3FEND is the closest neighbor and deserves a direct answer. It is a knowledge graph of defensive countermeasures, organized as a taxonomy of seven tactics (Model, Harden, Detect, Isolate, Deceive, Evict, Restore) with rigorous semantic relationships to the artifacts they operate on. It is excellent at what it does, and it is more semantically precise than ASOM-Fed.
The difference is operational art. D3FEND tells you what a countermeasure is and what it acts on; it is deliberately not a planning model, and it does not express sequence, main effort, phase, terrain ownership, or tempo. ASOM-Fed is organized around exactly those: its unit is not the countermeasure but the maneuver — an intent applied to specific ground at a specific point in a campaign. An agency wanting a precise ontology of defensive functions should use D3FEND. An agency wanting to decide what to do first, where, and what to give up needs something like ASOM-Fed. They compose: D3FEND is a natural source of rigour for the technique layer, and the worked example crosswalks all eleven forms to its seven tactics.
NIST CSF 2.0, RMF and SP 800-53
Subordinate by design — ASOM-Fed produces compliance rather than consuming it. The cycle’s outputs map onto CSF 2.0’s functions (FRAME → Govern, CPE → Identify, M2–M4/M8 → Protect, M1/M5 → Detect, M6–M8 → Respond, M8/M10 → Recover); the terrain overlay feeds RMF Categorize and Select; the cycle itself is continuous monitoring. Every ASOM-Fed control inherits from named 800-53 Rev. 5 controls, so nothing here creates a parallel compliance burden.
CISA ZTMM and NIST SP 800-207
ZTMM supplies the terrain. ASOM-Fed’s five layers are the ZTMM pillars, and the maturity vector (Traditional → Optimal, per pillar, per quarter) remains the right zero-trust progress report. What ASOM-Fed adds is movement: ZTMM tells an agency how mature each pillar is, not what to do with the pillars when something is happening.
TBM and the Defense Tower Model
The Defense Tower Model mirrors the TBM Council taxonomy one layer at a time, substituting defensive coverage and residual risk for cost: Asset Pools → Defense Towers → Maneuver Solutions → Mission Consumers. This is what gives ASOM-Fed bidirectional traceability — pick a mission and see everything defending it, or pick an asset and see every mission it protects — in a form a CFO already understands.
Scope and Deliberate Exclusions
Things ASOM-Fed does not do, on purpose:
- It is not a threat-intelligence source. No named adversary groups, no malware, no indicators. Those belong in ATT&CK and in an agency’s own reporting.
- It is not a control catalog. The 78 controls specify the maneuver layer only, and inherit everywhere else. Replacing 800-53 is neither possible nor desirable.
- It does not offer offensive operations. “Spoiling attack” and “counterattack” are named from doctrine but are strictly defensive in content — pre-emptive blocking, patching, hunting and eviction inside one’s own boundary. Nothing in ASOM-Fed contemplates action outside an agency’s own terrain, which would be a legal and authority question, not a framework question.
- It does not score vendors. Forms are technology-neutral, and no technique names a product.
- It does not claim measured efficacy.
- It is not classified, and holds no agency-specific information. The published surface is tested for this.
Versioning and Change Management
- IDs are permanent. Form, technique and control IDs are never reused or renumbered, so an exported assessment stays interpretable against later versions.
- Additive by default. New techniques take the next number in their form. Existing entries are sharpened rather than replaced.
- Structural change is a major version. Adding or removing a form, a terrain layer or a phase changes the matrix’s shape and every coverage score computed against it.
- One source of truth. Changes are made in
framework.js; the matrix, the Studio and any exported assessment follow from it. - Contact updates doctrine. M10 exists so that engagements feed the framework. No version is a finished artifact.
Version 2.0 is the first structural change, and it was made because the framework failed its own test. Scoring ten representative federal agency architectures against version 1.0 produced a finding about ASOM-Fed rather than about the agencies: no architecture could evidence M10, forty-two of the 111 techniques were evidenced by none of them, and the 35 controls reached five of the six CSF 2.0 Functions — Recover was empty. A framework whose pitch is that compliance should be exhaust cannot leave a whole Function unreachable. Version 2.0 therefore adds:
T6Operational Technology — a sixth terrain layer, because OT was being scored as though it were a server estate.M11Reconstitution — an eleventh form, with seven techniques, covering recovery objectives, isolated recovery capability, trusted rebuild paths, integrity verification, restoration sequencing and exercise.- Two control families —
RC-1–RC-5(Reconstitution and Recovery) andFO-1–FO-6(Federal Obligations: privacy, CUI, tenancy and inheritance, operational technology, statutory availability, supply chain), taking the catalog from 35 to 46 and CSF reach to all six Functions. - Per-agency obligation profiles — the
FOfamily is not universal. An agency declares which federal obligations it stands on, and obligations outside that profile are scored out of scope rather than counted against it.
Every version-1.0 ID kept its number and its meaning. Coverage scores computed against version 1.0 are not comparable to version 2.0 scores, because the denominator changed — which is what “structural change is a major version” is there to signal.
Version 3.0 was driven by a completeness test rather than by a coverage finding. Every ASOM-Fed control cites the NIST SP 800-53 Rev. 5 controls it inherits from, so the families it never cites are a direct measure of the federal estate the framework does not reach. Against version 2.0 that measure returned four families at zero — AT (Awareness and Training), PS at a single citation (Personnel Security), PE (Physical and Environmental Protection) and MA (Maintenance) — with SR and SA thin. Stated as terrain rather than as paperwork: the framework modeled the machines of a federal estate, and not the people who operate it, the buildings it sits in, or the suppliers who reach into it. Those are three of the most-used federal intrusion paths. Version 3.0 adds:
T7Workforce — with theWFfamily (workforce terrain, privileged human register, role-based readiness, insider risk position, revocation tempo).T8Facilities — with theFCfamily (facility terrain, physical zone boundary, maintenance access control, environmental continuity).T9Supply Chain — with theLCfamily (supplier register, component provenance, access constraint, update staging, severance capability).- Twenty-five new techniques, taking the matrix from 125 to 150, and the catalog from 46 controls to 60 across eleven families.
No new forms of maneuver were required, and that is the most load-bearing result in this release. If the eleven forms are genuinely exhaustive at their level of abstraction, then adding three terrain layers should be defensible with the moves already named — and it was. Every one of the twenty-five new techniques falls under an existing form. A version that had needed a twelfth form would have been evidence against the durability claim in §3.2 rather than for it.
The framework now inherits from all twenty SP 800-53 Rev. 5 control families. That is a statement about reach, not about sufficiency: ASOM-Fed specifies the maneuver layer on that ground and inherits the rest, exactly as CG-5 requires.
Summary
ASOM-Fed occupies a level of abstraction that federal cyber defense currently leaves empty. Above it, maturity and outcome models say what should be true. Below it, control catalogs say what must be present. Neither can express the thing that decides engagements: how a defense is arrayed, what it does first, what it gives up, and whether it can act faster than the adversary can adapt.
The framework’s shape follows from one borrowed idea taken seriously — that durable categories of maneuver must be separated from the perishable techniques that realize them — and from one discipline imposed throughout: every technique must state what would prove it is working, and that statement must be capable of being false. The result is a defender’s knowledge base that a CISO can direct, an engineer can implement, a red team can attack, and an auditor can accept as evidence.
It is offered as a public reference framework: unclassified, agency-agnostic, free to use, free to extend, and built to be argued with.
The Rest of the Suite
This document states the reasoning. Seven companion artifacts carry the rest of it, and each is derived from the same connector so they cannot disagree about what the framework contains:
- The reference manual — terrain layers, forms of maneuver, controls and the adoption path, argued in full and kept in step with the published catalog. It holds the half of the framework that is identical at every agency.
- Framework (Word) — the doctrine: why defense is a maneuver problem.
- Application and Control Guide (Word, plus JSON and CSV) — every control with its statement, discussion, evidence and assessment procedure.
- Playbook — the browsable reference for practitioners.
- Tower Model — assets allocated to terrain layers, maneuvers and missions.
- Diagram Studio — where the work is done and the control set evaluates live against what you have drawn.
- Maneuver Matrix — the framework laid out as a matrix, and the connector both it and the Studio read.
The Studio generates the Brief, which is the cycle record: it cites the controls each section evidences, so successive editions form a dated, evidence-bearing account of how the estate is defended over time.
References
- Strom et al., MITRE ATT&CK: Design and Philosophy, The MITRE Corporation, MP180360R1, 2018 (rev. 2020). The structural model for this document.
- Allen, Cyber Maneuver and Schemes of Maneuver, The Cyber Defense Review, 2020. Source of the positional/temporal advantage definition and the durability-of-categories argument.
- Headquarters, Department of the Army, ATP 2-33.4, Intelligence Analysis. Source of the Screen→Analyze→Integrate→Produce cycle, structured analytic techniques, IPB and confidence levels.
- CISA, Zero Trust Maturity Model, v2.0 (April 2023). Source of the five pillars used verbatim as terrain layers (
T6is ASOM-Fed’s own and has no ZTMM equivalent), of the three cross-cutting capabilities that ASOM-Fed consolidates intoTX(§3.2), and of the Traditional → Initial → Advanced → Optimal maturity stages. - NIST, SP 800-207, Zero Trust Architecture. Source of the policy decision point / policy enforcement point model.
- NIST, Cybersecurity Framework (CSF) 2.0. Govern/Identify/Protect/Detect/Respond/Recover mapping.
- NIST, SP 800-53 Rev. 5 and SP 800-37 Rev. 2 (RMF). The control baseline ASOM-Fed inherits from.
- OMB, M-22-09, Moving the U.S. Government Toward Zero Trust Cybersecurity Principles.
- The MITRE Corporation, D3FEND. The defensive-countermeasure knowledge graph discussed above.
- TBM Council, Technology Business Management Taxonomy. The allocation model mirrored by the Defense Tower Model.
ASOM-Fed is published by threatDefendr as a public reference framework. Unclassified and illustrative; built from public sources only; contains no agency-specific information. ATT&CK® and D3FEND™ are trademarks of The MITRE Corporation, which does not endorse this framework.