ASOM-Fedv6.1Open the explorer
ASOM-Fed · Design document

Design and Philosophy

Why the framework is shaped the way it is — the object model, the level of abstraction it deliberately occupies, the criteria every form of maneuver and technique must meet to be admitted, and where it sits among the frameworks a federal agency already runs.

25 min readAgency-agnosticPublic sources onlyASOM-Fed v6.1

What this document is. Not the framework itself — the framework ships as the reference manual, the control catalog and the maneuver matrix. This explains the object model, the abstraction level, and the admission criteria for new entries, so an adopter can extend ASOM-Fed correctly and a reviewer can argue with it precisely. Its structure follows the convention MITRE established for ATT&CK: Design and Philosophy, because a framework that asks to be adopted owes its adopters an account of how it was built.

Introduction

Federal network defense is still largely run as garrison security: a boundary, a control catalog, an assessment calendar, and a queue of alerts worked in the order they arrive. The posture is static by construction — its unit of planning is the control, and controls do not move.

The adversaries that matter do not operate that way. Nation-state collectors, fraud rings working public service portals, and ransomware crews exploiting deadline-sensitive availability all behave like a maneuvering force: they seek positional advantage, mass at a decisive point, and win by operating inside the defender’s decision cycle. A defense whose only vocabulary is the control cannot describe what is happening to it, let alone respond in kind.

ASOM-Fed supplies the missing vocabulary. It reframes defense as a maneuver problem led by intelligence analysis, in a form that is assessable, machine-readable, and mappable onto the compliance obligations an agency already carries.

What the Framework Measures, and What It Measured

A framework that cannot be wrong is not worth adopting. ASOM-Fed is falsifiable in two directions, and both have returned uncomfortable answers about the framework itself — including about how it scores.

Against the control baseline. Every ASOM-Fed control cites the SP 800-53 Rev. 5 controls it inherits from, which makes the families it never cites a direct measure of the federal estate it fails to reach. That test drove the last structural release: version 2.0 inherited from sixteen of the twenty families and never once from AT, IA, MA or PE, which said plainly that the framework modeled the machines of a federal estate and not the people who operate it, the buildings it sits in, or the suppliers who reach into it. Version 3.0 added those as terrain. The 78 controls now inherit from all twenty families.

Against real architectures. The ten agency archetypes in the Studio are scored on every release. Coverage is deliberately measured as ground held rather than techniques touched: the framework is 77 terrain×form cells holding 154 techniques, and a node tagged with one form evidences every technique in its cell at once — sixteen of them, in the largest. Counting techniques therefore rewards tagging a crowded cell over a sparse one for identical effort, and lets a design be driven toward 100% without doing anything more. Cells are the unit the model can defend.

MeasureResultWhat it says
Ground held, best to worst estate7–44%Even the strongest reference estate operates on well under half the board.
Estates missing a whole form of maneuver6 of 10A capability gap, not a procurement gap — no product closes it.
Estates that can perform M10 Exploitation & Pursuit4 of 10The rest cannot convert contact into durable advantage, and so fight the same intrusion twice.
Estates that can perform M9 Spoiling Attack5 of 10Half cannot act on an advisory before exploitation reaches them.
Cells no estate occupies31 of 75Whole forms of maneuver unavailable on whole layers of terrain.
These measurements have twice condemned the framework rather than the agencies. Version 1.0 was scored the same way and produced a finding about itself: no archetype could evidence M10, forty-two of 111 techniques were evidenced by none of them, and the 35 controls reached five of the six CSF 2.0 Functions with Recover empty. Version 3.0 declared three new terrain layers that, on first measurement, no reference estate stood on at all. Both were defects in the framework, found by running it rather than by reading it, and both are recorded in §7 rather than quietly corrected. An adopter should weigh how a framework handles being wrong at least as heavily as what it claims when it is right.

Background and History

ASOM-Fed fuses two mature bodies of U.S. Army doctrine that are rarely combined, and grounds them on the federal zero-trust terrain defined by civilian policy:

The single most consequential idea taken from Allen is that categories of maneuver are durable while the techniques that realize them are perishable. Leaders can therefore direct a defense in terms of intent without being engineers, and engineers can re-tool without invalidating the plan. Everything about the framework’s shape follows from taking that distinction seriously — and it is, not coincidentally, the same separation ATT&CK draws between a tactic and a technique.

Use Cases

ASOM-Fed is built to be used in six ways. Each is a real workflow, not an aspiration.

1
Cyber Preparation of the Environment
Map the estate as terrain — key terrain, avenues of approach, mobility corridors, decisive points — and build most-likely and most-dangerous threat courses of action against it. Arraying the matrix against two courses of action makes the difference between them the planning problem, and the cells demanded by both are where a single investment answers two threats.
2
Defensive campaign planning
Choose a sequence of forms with one designated main effort, phase it, and pre-authorize which responses the SOC may execute without escalation. This turns 24/7 monitoring into a campaign with a stated objective per phase.
3
Gap analysis that names the right gap
Score coverage cell by cell. A whole column that comes up empty is not a missing product — it is a form of maneuver the agency cannot perform. That finding survives contact with a budget conversation in a way an open POA&M item does not.
4
Assessment and red teaming
Every technique carries a success indicator, so the matrix doubles as a test plan: give a red team a form of maneuver to defeat, and the cell’s indicator is the pass/fail condition. This is why the indicator field is mandatory.
5
Governance and audit evidence
Every technique cites ASOM-Fed controls, each of which inherits from SP 800-53 Rev. 5 and maps to CSF 2.0. An agency that maneuvers well produces its FISMA evidence as a by-product. Compliance is exhaust, not the objective.
6
Capability planning and procurement
Because forms are intent-first and technology-neutral, a requirement can be written as “we must be able to perform M5 Ambush across the data layer” rather than as a product category. The requirement outlives the vendor.

The ASOM-Fed Model

The Maneuver Matrix

The matrix is the framework’s primary presentation. Its columns are the eleven forms of defensive maneuver; the cells beneath each column are the techniques that give that form effect. Reading down a column tells you how a form is actually performed; reading across the top tells you what a defense is capable of at all.

The layout convention is borrowed openly from the ATT&CK Enterprise matrix, for a reason that is structural rather than aesthetic: both models separate a small set of durable, intent-level categories from a large, churning set of concrete behaviors. Where the two differ is in whose behavior is cataloged — ATT&CK describes what an adversary does to you, ASOM-Fed describes how you array against it.

Terrain Layers

ASOM-Fed models the enterprise as nine terrain layers plus one cross-cutting domain. Five of the nine are the CISA ZTMM v2.0 pillars, taken unchanged and renamed as terrain because terrain is what a scheme of maneuver is drawn on. The other four — operational technology, workforce, facilities and supply chain — are ASOM-Fed’s own, and each was added because a measurable part of a federal estate had no ground to stand on without it. Each carries a metaphor that is load-bearing, not decorative: it tells a planner what kind of ground they are defending.

Where this departs from CISA, and why it matters. The five pillars are ZTMM’s, verbatim. TX and T6 are not. ZTMM defines three cross-cutting capabilities (Visibility and Analytics, Automation and Orchestration, Governance) and ASOM-Fed consolidates them into one terrain layer, because as terrain they are not ground an adversary moves across; they are what lets you move. T6 Operational Technology is an addition of ours in version 2.0, introduced because a federal estate that runs dams, clinical devices, laboratory instruments or building systems was otherwise being scored as though it were a server estate — the moves available on that ground are narrower and the consequence of loss is physical. ZTMM has no equivalent pillar; agencies reporting ZTMM maturity should read T6 as terrain they hold that the maturity model does not ask about. That is a deliberate simplification and it is lossy: an agency reporting ZTMM maturity per cross-cutting capability cannot map those three onto TX one-to-one, and should report them separately. The tower IDs (T1T9, TX) and every terrain metaphor in the table below are ASOM-Fed’s own; CISA neither numbers its pillars nor describes them as terrain.
IDDomainTerrain character and what it implies
T1IdentityHIGH GROUND Whoever holds it controls movement everywhere else. Contested first, and the reason M3 Envelopment carries the largest single risk weighting.
T2DevicesENTRY FORDS Where forces cross into the estate. Few crossings, heavily used, worth watching.
T3NetworksCORRIDORS Routes of movement. The only layer where you can meaningfully canalize an adversary onto ground you own.
T4Applications and WorkloadsURBAN TERRAIN Dense, complex, close-quarters — the hardest ground to defend and the easiest to lose track of.
T5DataTHE OBJECTIVE The reason the campaign exists. Everything else is defended because it leads here.
T6Operational TechnologyCONTESTED GROUND Ground you cannot freely maneuver on: systems that often cannot be patched or restarted on the defender’s schedule, where loss has a physical consequence. Added in v2.0; not a ZTMM pillar.
T7WorkforceTHE FORCE ITSELF The people who operate the estate can be reconnoitred, targeted, turned and lost. Added in v3.0; the only terrain that is simultaneously the defending force.
T8FacilitiesTHE GROUND YOU STAND ON Buildings, zones, badge systems, and the vendor maintenance paths that reach through them. The oldest terrain there is, and the one most often left off a cyber overlay. Added in v3.0.
T9Supply ChainLINES OF COMMUNICATION The routes by which the estate is resupplied, and therefore the routes by which it is reached. Doctrinally the rear area; in federal practice, frequently the actual intrusion path. Added in v3.0.
TXCross-CuttingENABLERS Visibility is reconnaissance, automation is mobility, governance is command authority. Not ground, but what lets you move on it.
Why these IDs and not the pillar names. T1T9/TX are the Defense Tower Model’s tower IDs, already used by the Studio canvas. Reusing them means a canvas node and a matrix cell share one key, so linking them is a lookup rather than a translation table — and a translation table is exactly the thing that silently rots.

Forms of Maneuver

The eleven forms are the framework’s durable layer. They are defensive recastings of classical forms of maneuver, chosen to be exhaustive at their level of abstraction: any defensive action an agency takes should be recognizable as an instance of one of them.

FieldTypeMeaning
idstringM1M10. Stable for the life of the framework; never reused.
namestringThe doctrinal name, e.g. Envelopment, Ambush, Spoiling Attack.
intentstringOne clause stating what the form is for. This is what the CISO or Authorizing Official issues; it must be comprehensible without technical knowledge.
towerenumThe terrain layer the form is principally concerned with. Advisory — techniques within a form may sit on other layers.
riskReductionintegerPercentage residual-risk reduction attributed to the form when fully operational, used by the Tower Model’s allocation arithmetic.
Where the framework puts its weight — the eleven forms, ranked Read from the connector; the numbers are the framework's own residual-risk weighting. M3 Envelopment 15 M3 Envelopment — Make identity the decisive plane. 15% residual-risk reduction, principally on T1 Identity. M2 Defense in Depth 12 M2 Defense in Depth — No single failure is decisive. 12% residual-risk reduction, principally on T3 Networks. M7 Counterattack 11 M7 Counterattack — Seize initiative; evict early. 11% residual-risk reduction, principally on TX Cross-Cutting. M4 Obstacle / Canalization 10 M4 Obstacle / Canalization — Force the adversary onto ground you own. 10% residual-risk reduction, principally on T3 Networks. M8 Isolation / Retrograde 10 M8 Isolation / Retrograde — Fail secure; give ground to preserve the mission. 10% residual-risk reduction, principally on T3 Networks. M5 Ambush 9 M5 Ambush — Trade space for information and time. 9% residual-risk reduction, principally on T5 Data. M6 Delay 8 M6 Delay — Buy decision time; prevent culmination. 8% residual-risk reduction, principally on T4 Applications and Workloads. M1 Screen / Guard 7 M1 Screen / Guard — Early warning and reaction time. 7% residual-risk reduction, principally on T3 Networks. M11 Reconstitution 7 M11 Reconstitution — Restore the mission on evidence, not on hope. 7% residual-risk reduction, principally on TX Cross-Cutting. M9 Spoiling Attack 6 M9 Spoiling Attack — Disrupt adversary staging pre-attack. 6% residual-risk reduction, principally on TX Cross-Cutting. M10 Exploitation & Pursuit 5 M10 Exploitation & Pursuit — Convert contact into durable advantage. 5% residual-risk reduction, principally on TX Cross-Cutting. Weights sum to 100 — residual-risk reduction per form, colored by the layer it is principally concerned with.
Figure 1. Where the framework puts its weight. The eleven forms ranked by the residual-risk reduction the framework attributes to each, colored by the terrain layer it is principally concerned with. The weights sum to 100 by construction, so the bar is a whole rather than a scale — and it is read from the connector, so no figure here can disagree with the number the studio scores a design against. Envelopment carries the most because making identity the decisive plane is the single largest lever a federal defender has.

Techniques

Techniques are the perishable layer: the concrete, observable things an agency does to make a form real on specific ground. Version 6.1 catalogs 154 of them — the count has risen at every release, from 111 at v1.0 through 125 at v2.0 and 150 at v3.0, and it is expected to keep rising, because this is the layer that tracks tooling. The forms above it have not changed since v1.0, which is the point of separating them.

FieldTypeMeaning
idstringM<form>.<nn>, e.g. M5.01. The prefix encodes the column, so an ID alone locates a technique without the header.
namestringNames the action, not a product.
towerenumThe terrain layer this technique acts on. Exactly one.
phaseslistThe campaign phases in which this technique is a dominant effort — not every phase in which it is merely running.
doesstringOne sentence: what the technique does, phrased as defensive intent rather than configuration.
indicatorstringMandatory. What observable state proves the technique is working. This field is the framework’s assessability guarantee.
controlslistASOM-Fed control IDs making the technique assessable, and optionally a cross-reference to a sibling technique.
The catalog as a grid — forms of maneuver against the ground they act on Counted from the published connector at build time, not transcribed. M1M1 Screen / Guard M2M2 Defense in Depth M3M3 Envelopment M4M4 Obstacle / Canalization M5M5 Ambush M6M6 Delay M7M7 Counterattack M8M8 Isolation / Retrograde M9M9 Spoiling Attack M10M10 Exploitation & Pursuit M11M11 Reconstitution T1 Identity 2 M1 Screen / Guard on T1 Identity — 2 techniques M2 Defense in Depth on T1 Identity — 0 techniques 16 M3 Envelopment on T1 Identity — 16 techniques M4 Obstacle / Canalization on T1 Identity — 0 techniques 2 M5 Ambush on T1 Identity — 2 techniques 3 M6 Delay on T1 Identity — 3 techniques 1 M7 Counterattack on T1 Identity — 1 technique 2 M8 Isolation / Retrograde on T1 Identity — 2 techniques 1 M9 Spoiling Attack on T1 Identity — 1 technique M10 Exploitation & Pursuit on T1 Identity — 0 techniques 1 M11 Reconstitution on T1 Identity — 1 technique T2 Devices 1 M1 Screen / Guard on T2 Devices — 1 technique 3 M2 Defense in Depth on T2 Devices — 3 techniques 2 M3 Envelopment on T2 Devices — 2 techniques 2 M4 Obstacle / Canalization on T2 Devices — 2 techniques 1 M5 Ambush on T2 Devices — 1 technique M6 Delay on T2 Devices — 0 techniques 2 M7 Counterattack on T2 Devices — 2 techniques 1 M8 Isolation / Retrograde on T2 Devices — 1 technique M9 Spoiling Attack on T2 Devices — 0 techniques M10 Exploitation & Pursuit on T2 Devices — 0 techniques 1 M11 Reconstitution on T2 Devices — 1 technique T3 Networks 3 M1 Screen / Guard on T3 Networks — 3 techniques 2 M2 Defense in Depth on T3 Networks — 2 techniques M3 Envelopment on T3 Networks — 0 techniques 10 M4 Obstacle / Canalization on T3 Networks — 10 techniques 1 M5 Ambush on T3 Networks — 1 technique 1 M6 Delay on T3 Networks — 1 technique 1 M7 Counterattack on T3 Networks — 1 technique 3 M8 Isolation / Retrograde on T3 Networks — 3 techniques 1 M9 Spoiling Attack on T3 Networks — 1 technique M10 Exploitation & Pursuit on T3 Networks — 0 techniques M11 Reconstitution on T3 Networks — 0 techniques T4 Applications and Workloads 1 M1 Screen / Guard on T4 Applications and Workloads — 1 technique 3 M2 Defense in Depth on T4 Applications and Workloads — 3 techniques M3 Envelopment on T4 Applications and Workloads — 0 techniques M4 Obstacle / Canalization on T4 Applications and Workloads — 0 techniques 2 M5 Ambush on T4 Applications and Workloads — 2 techniques 3 M6 Delay on T4 Applications and Workloads — 3 techniques 2 M7 Counterattack on T4 Applications and Workloads — 2 techniques 2 M8 Isolation / Retrograde on T4 Applications and Workloads — 2 techniques 2 M9 Spoiling Attack on T4 Applications and Workloads — 2 techniques M10 Exploitation & Pursuit on T4 Applications and Workloads — 0 techniques 3 M11 Reconstitution on T4 Applications and Workloads — 3 techniques T5 Data 1 M1 Screen / Guard on T5 Data — 1 technique 4 M2 Defense in Depth on T5 Data — 4 techniques M3 Envelopment on T5 Data — 0 techniques M4 Obstacle / Canalization on T5 Data — 0 techniques 3 M5 Ambush on T5 Data — 3 techniques 1 M6 Delay on T5 Data — 1 technique M7 Counterattack on T5 Data — 0 techniques 1 M8 Isolation / Retrograde on T5 Data — 1 technique M9 Spoiling Attack on T5 Data — 0 techniques M10 Exploitation & Pursuit on T5 Data — 0 techniques 2 M11 Reconstitution on T5 Data — 2 techniques T6 Operational Technology 1 M1 Screen / Guard on T6 Operational Technology — 1 technique 1 M2 Defense in Depth on T6 Operational Technology — 1 technique M3 Envelopment on T6 Operational Technology — 0 techniques 2 M4 Obstacle / Canalization on T6 Operational Technology — 2 techniques 1 M5 Ambush on T6 Operational Technology — 1 technique M6 Delay on T6 Operational Technology — 0 techniques 1 M7 Counterattack on T6 Operational Technology — 1 technique 1 M8 Isolation / Retrograde on T6 Operational Technology — 1 technique M9 Spoiling Attack on T6 Operational Technology — 0 techniques M10 Exploitation & Pursuit on T6 Operational Technology — 0 techniques M11 Reconstitution on T6 Operational Technology — 0 techniques T7 Workforce 1 M1 Screen / Guard on T7 Workforce — 1 technique 1 M2 Defense in Depth on T7 Workforce — 1 technique 1 M3 Envelopment on T7 Workforce — 1 technique M4 Obstacle / Canalization on T7 Workforce — 0 techniques 1 M5 Ambush on T7 Workforce — 1 technique M6 Delay on T7 Workforce — 0 techniques 1 M7 Counterattack on T7 Workforce — 1 technique 1 M8 Isolation / Retrograde on T7 Workforce — 1 technique 1 M9 Spoiling Attack on T7 Workforce — 1 technique M10 Exploitation & Pursuit on T7 Workforce — 0 techniques 1 M11 Reconstitution on T7 Workforce — 1 technique T8 Facilities 1 M1 Screen / Guard on T8 Facilities — 1 technique 1 M2 Defense in Depth on T8 Facilities — 1 technique M3 Envelopment on T8 Facilities — 0 techniques 2 M4 Obstacle / Canalization on T8 Facilities — 2 techniques 1 M5 Ambush on T8 Facilities — 1 technique M6 Delay on T8 Facilities — 0 techniques M7 Counterattack on T8 Facilities — 0 techniques 1 M8 Isolation / Retrograde on T8 Facilities — 1 technique M9 Spoiling Attack on T8 Facilities — 0 techniques M10 Exploitation & Pursuit on T8 Facilities — 0 techniques 1 M11 Reconstitution on T8 Facilities — 1 technique T9 Supply Chain 1 M1 Screen / Guard on T9 Supply Chain — 1 technique 1 M2 Defense in Depth on T9 Supply Chain — 1 technique 1 M3 Envelopment on T9 Supply Chain — 1 technique 1 M4 Obstacle / Canalization on T9 Supply Chain — 1 technique M5 Ambush on T9 Supply Chain — 0 techniques 1 M6 Delay on T9 Supply Chain — 1 technique 1 M7 Counterattack on T9 Supply Chain — 1 technique 1 M8 Isolation / Retrograde on T9 Supply Chain — 1 technique 1 M9 Spoiling Attack on T9 Supply Chain — 1 technique 1 M10 Exploitation & Pursuit on T9 Supply Chain — 1 technique 1 M11 Reconstitution on T9 Supply Chain — 1 technique TX Cross-Cutting 3 M1 Screen / Guard on TX Cross-Cutting — 3 techniques 2 M2 Defense in Depth on TX Cross-Cutting — 2 techniques M3 Envelopment on TX Cross-Cutting — 0 techniques M4 Obstacle / Canalization on TX Cross-Cutting — 0 techniques 1 M5 Ambush on TX Cross-Cutting — 1 technique 1 M6 Delay on TX Cross-Cutting — 1 technique 8 M7 Counterattack on TX Cross-Cutting — 8 techniques 4 M8 Isolation / Retrograde on TX Cross-Cutting — 4 techniques 3 M9 Spoiling Attack on TX Cross-Cutting — 3 techniques 6 M10 Exploitation & Pursuit on TX Cross-Cutting — 6 techniques 1 M11 Reconstitution on TX Cross-Cutting — 1 technique FORMS OF MANEUVER M1 Screen / Guard M2 Defense in Depth M3 Envelopment M4 Obstacle / Canalization M5 Ambush M6 Delay M7 Counterattack M8 Isolation / Retrograde M9 Spoiling Attack M10 Exploitation & Pursuit M11 Reconstitution 77 of 110 cells occupied by 154 techniques. Shade is technique density; a dashed cell is ground the framework does not yet reach on that form. Read a column and you have what one form of maneuver can do across the estate. Read a row and you have every move available on one layer of ground.
Figure 2. The catalog as a grid. Every cataloged technique placed at the intersection of the form it realizes and the terrain layer it acts on. The occupied-cell count is the framework’s own measure of size — the number an estate is scored against as ground held — and it is counted here from the published connector rather than transcribed, so this figure and the sentences that quote it cannot drift apart. The dashed cells are the honest part: they are ground the framework does not yet reach with that form, published rather than hidden.

Controls

The 78 ASOM-Fed controls are the assessment layer. They exist because SP 800-53 Rev. 5 — roughly 1,196 controls across twenty families — has no family that specifies the maneuver layer: nothing in it requires you to know your terrain, designate a main effort, measure your decision tempo, or prove you can perform a form of maneuver at all. ASOM-Fed neither replaces nor duplicates 800-53; it adds the missing family and inherits everywhere else.

FieldMeaning
idFamily prefix plus number, e.g. KT-2.
titleShort requirement name.
nist80053The 800-53 Rev. 5 controls this inherits from — the crosswalk that keeps ASOM-Fed additive.
csf20CSF 2.0 subcategories satisfied.
Families (14)TM Terrain Management · KT Key Terrain and Decisive Points · ID Identity Terrain · DV Devices Terrain · SM Scheme of Maneuver · TA Tempo and Temporal Advantage · EN Engagement and Pursuit · CE Cycle Execution and Assurance · CG Command and Governance · RC Reconstitution and Recovery · FO Federal Obligations · WF Workforce Terrain · FC Facilities Terrain · LC Lines of Communication

Campaign Phases

Six phases, adapted from joint phasing, each with a stated objective and a dominant set of forms. Phasing is what lets leadership see cyber defense as a campaign with a main effort per phase rather than an undifferentiated grind — and it is what makes “we are in Phase III” a sentence that changes behavior, because pre-authorized responses and session lifetimes are keyed to it.

IDPhaseObjectiveDominant forms
0ShapeSet the conditionsM1 · M2 · M3 · M9
IDeterRaise the adversary’s costM3 · M4 · M5
IISeize InitiativeContest first contactM1 · M4 · M6
IIIDominateDefeat the attemptM7 · M8 · M5
IVStabilizeRestore secure operationsM8 · M10 · M11
VRestoreHand back to steady stateM11 · M10 · M7
The campaign, as six phases — and the forms that carry each Phases from the connector; the forms under each are counted from the techniques dominant there. 0 Shape Set the conditions M3 20 M3 Envelopment — 20 techniques dominant in Shape M2 18 M2 Defense in Depth — 18 techniques dominant in Shape M1 15 M1 Screen / Guard — 15 techniques dominant in Shape M4 14 M4 Obstacle / Canalization — 14 techniques dominant in Shape I Deter Raise the adversary'scost M4 13 M4 Obstacle / Canalization — 13 techniques dominant in Deter M5 13 M5 Ambush — 13 techniques dominant in Deter M3 10 M3 Envelopment — 10 techniques dominant in Deter M1 8 M1 Screen / Guard — 8 techniques dominant in Deter II Seize Initiative Contest first contact M5 9 M5 Ambush — 9 techniques dominant in Seize Initiative M6 9 M6 Delay — 9 techniques dominant in Seize Initiative M7 4 M7 Counterattack — 4 techniques dominant in Seize Initiative M1 3 M1 Screen / Guard — 3 techniques dominant in Seize Initiative III Dominate Defeat the attempt M7 15 M7 Counterattack — 15 techniques dominant in Dominate M8 14 M8 Isolation / Retrograde — 14 techniques dominant in Dominate M6 8 M6 Delay — 8 techniques dominant in Dominate M3 2 M3 Envelopment — 2 techniques dominant in Dominate IV Stabilize Restore secureoperations M11 8 M11 Reconstitution — 8 techniques dominant in Stabilize M8 7 M8 Isolation / Retrograde — 7 techniques dominant in Stabilize M10 2 M10 Exploitation & Pursuit — 2 techniques dominant in Stabilize M7 2 M7 Counterattack — 2 techniques dominant in Stabilize V Restore Hand back to steadystate M10 7 M10 Exploitation & Pursuit — 7 techniques dominant in Restore M11 5 M11 Reconstitution — 5 techniques dominant in Restore M7 3 M7 Counterattack — 3 techniques dominant in Restore M8 1 M8 Isolation / Retrograde — 1 techniques dominant in Restore Forms are counted from the catalog — the count is on the right. Shaping forms give way to contact forms, then to reconstitution.
Figure 3. The campaign, phase by phase. The six phases run left to right, and under each are the forms of maneuver whose techniques are dominant in it — not asserted, but counted from the catalog, since every technique declares the phases it dominates. This is the join the two tables above cannot show on their own: how the durable forms flow through the campaign over time, from the shaping forms that set conditions, through the contact forms that defeat the attempt, to reconstitution.

Object Model Relationships

The model is deliberately small, and every relationship in it is a single hop. Ten object classes resolve into two sentences: an agency builds the first, and the framework fixes the second. The full object model states each class with the question it answers and the class it is most often mistaken for.

WHAT AN AGENCY BUILDS Asset Register entry Asset — What do I actually own? The concrete things on your estate — a directory, a boundary device, a records store. Each lands on exactly one terrain layer, sits inside one tier, carries a weight, and serves at least one mission. sits in a Tier Public · Mission · Data · Support Tier — Where does this sit on my diagram? The bands you draw across your own overlay to separate exposure from consequence. They belong to one estate’s architecture, and a differently shaped agency may reasonably draw different ones. on a Terrain layer T1 – T10 Terrain layer — What kind of ground is this? The ten kinds of ground a federal estate is defended on — identity, devices, networks, applications, data, operational technology, workforce, facilities, supply chain, and the cross-cutting layer. Five are the CISA zero-trust pillars carried verbatim; four are ASOM-Fed’s own. rolls up through its Tower T1 – T10 Tower — How much cover does this ground carry? The same ten layers used as accounting buckets. Coverage and residual risk roll up through a tower to the missions that consume it, the way a cost-transparency model rolls spend up from a pool to a consumer. to a Mission Mission service Mission — Why is any of this defended? The service the agency exists to deliver. Every asset serves one, and the Bill of Defense states — per mission — what protects it, how much coverage rolls up, and what risk is left over. WHAT THE FRAMEWORK FIXES Form of maneuver M1 – M11 Form of maneuver — What am I going to do? The eleven durable moves a defender can make. A form names an intent — deny movement, trade space for information, hand the ground back deliberately — at the level a commander can direct without knowing which product implements it. is realized by a Technique M5.03 Technique — How, exactly, on this ground? One form of maneuver realized on one terrain layer, with a falsifiable indicator. The ID names its parent form, so M5.03 is the third cataloged way to perform M5 Ambush. made assessable by a Control KT-4 Control — What will an assessor test? The assessable requirement — statement, activities, one accountable role, the evidence it produces and the procedure an assessor follows. Each inherits from NIST SP 800-53 and maps onto CSF 2.0. AXES — TRUE OF EVERY CONTROL AT ONCE, NOT A STEP IN EITHER CHAIN Posture 4 postures Does it still hold when nobody is watching? Whether a control keeps working unattended. It is an axis across the whole catalog rather than a group of controls, so every control has one. Campaign phase 6 phases Where are we in the campaign? Six phases, each with a declared main effort and stated conditions for moving to the next. Declaring one is what makes a scheme of maneuver a plan rather than a list of capabilities. Every control carries a posture; every scheme declares a phase. 10 classes · 6 fixed · 3 yours · 1 on the seam
Figure 4. The object model, as two sentences. An asset sits in a tier on a terrain layer, and rolls up through its tower to a mission — the top chain, and the half an agency authors. A form of maneuver is realized by a technique and made assessable by a control — the bottom chain, identical at every agency in the country. Posture and campaign phase are drawn apart because they are axes true of the whole catalog at once rather than steps in either chain. Generated from the same taxonomy the object model renders from, so the figure cannot disagree with the table.

Machine-Readable Form

The framework ships as a script, framework.js, which is the single source of truth for the technique layer and is loaded by both the matrix and the Studio canvas. It exposes byId, forTower, forForm, link and verify, and it self-checks against the Studio’s own tables at load time rather than letting the two drift apart silently.

A design rule worth stating explicitly. There is exactly one copy of the framework data. A published framework whose website and whose tooling disagree about its own contents has failed at the only thing a reference framework is for. Any future consumer should load this module rather than transcribe it.

The Methodology

The Loop the Whole Framework Serves

Everything above is machinery. This is what the machinery is for: six steps that turn continuously, each consuming the previous step’s output and producing the next one’s input. The framework is a scheme of maneuver rather than a checklist precisely because those handoffs exist — a checklist has items, and a scheme has a sequence in which each move creates the conditions for the next.

How you run it — the operating cycle, and the artifact each step hands the next Six steps that turn continuously. The label on every arrow is the output the step produces and the next one consumes. Intent + PCIRs Overlay + threat COAs Scheme of maneuver Actions + change record Fused assessment 1 Frame INTEL State the intent Analytic Design Frame — Intelligence cell. Publish the defensive intent, set Priority Cyber Intelligence Requirements, and define what positional advantage means this cycle. Output: Intent + PCIRs. 2 Map INTEL Read the ground Cyber Preparation of the Environment Map — Intelligence cell. Refresh the terrain overlay, enumerate avenues of approach, and build the most-likely and most-dangerous threat courses of action. Output: Overlay + threat COAs. 3 Array COMMAND Choose the forms Design the scheme Array — Commander / AO. Choose the forms of maneuver, designate the main effort, site obstacles at decisive points, and pre-plan branches and sequels. Output: Scheme of maneuver. 4 Maneuver OPS Execute the moves Execute Maneuver — SOC / operations. Emplace obstacles, reposition sensors, and execute defensive fires — block, isolate, deceive, disrupt — under the standing rules of engagement. Output: Actions + change record. 5 Fuse INTEL Weigh what came back Analyze · Integrate Fuse — Intelligence cell. Run competing hypotheses on adversary intent, a key-assumptions check, and indicators — and assign explicit confidence to each. Output: Fused assessment. 6 Assess COMMAND Score and decide Produce · re-frame Assess — Commander / AO. Measure positional and temporal advantage, then decide: continue, exploit, or transition to a branch. Publish, and turn the loop. Output: Product + next framing. THE LOOP CLOSES close faster than the adversary can adapt OWNERSHIP ROTATES — NO ROLE TURNS THE LOOP ALONE Intelligence cell — steps 1, 2, 5 Commander / AO — steps 3, 6 SOC / operations — steps 4
Figure 5. The cycle, with the artifact on every arrow. Ownership rotates deliberately across three roles — intelligence, command, operations — and no role turns the loop alone, which is the structural defense against the loop degrading into one team’s status meeting. To see the same six steps run at segment scope, many times per cycle, see clearing operations.

The Defender’s Perspective

ATT&CK is built from the adversary’s perspective, which is what makes it honest: it describes what is actually done to networks rather than what defenders wish were true. ASOM-Fed inverts the vantage point but keeps the discipline. Every entry is written from the perspective of the force that owns the ground — which is the defender’s one structural advantage, and the thing control catalogs consistently fail to exploit.

Owning the ground means a defender may do things an attacker cannot: emplace obstacles, choose which corridors to leave open and instrument them, seed decoys, trade space for time, and fail secure by design. Seven of the eleven forms have no offensive analogue at all. A framework organized around controls cannot express any of them, because none of them is a control.

Doctrinal Derivation, and How It Differs from ATT&CK

The most important limitation in this document. ATT&CK’s authority is empirical. Its techniques are admitted because they were observed in real intrusions, and each carries references to the reporting that observed them. ASOM-Fed’s technique layer is doctrinal and analytic: entries are derived from maneuver doctrine, federal zero-trust guidance and established defensive practice — not from a corpus of incidents in which each was measured to work. These are different kinds of claim and should not be confused.

Two consequences follow, and adopters should hold ASOM-Fed to them:

What ASOM-Fed gains in exchange is coverage of the defensive design space independent of what has happened to any particular agency yet — which is the right trade for a planning framework and the wrong one for a threat-intelligence framework. Use ATT&CK for the latter.

Abstraction

ATT&CK’s foundational argument is that a mid-level model is necessary: high-level lifecycle models describe goals but not actions, and low-level databases describe artifacts stripped of context, so something in between is needed to connect behavior to defenses. ASOM-Fed makes the identical argument on the defensive side.

HIGHMIDLOWOutcome and maturity modelsControl catalogs and configurationNIST CSF 2.0 · CISA Zero Trust Maturity Model · OMB M-22-09NIST SP 800-53 Rev. 5 · CIS Benchmarks · product settings“what should be true?”“what must be installed?”ASOM-Fed — forms of maneuver and techniquesHow defensive capability is arrayed and moved on cyber terrain, over time,against an adversary who is also moving.
Figure 6. Abstraction comparison. Maturity and outcome models state what should be true but not how to array a defense; control catalogs state what must be present but say nothing about sequence, main effort, or tempo. ASOM-Fed occupies the level between them — the level at which defensive movement can be described, planned and assessed.

What the maneuver abstraction provides that neither neighbor does:

What Makes a Form of Maneuver

Forms are the framework’s stable spine, so the bar for adding one is deliberately very high. In practice the set is closed; version 1.0 expects to add techniques indefinitely and forms almost never. A candidate form must satisfy all five:

1
It is durable
It would have been recognizable to a planner twenty years ago and should still be in twenty years’ time. If it names a technology, it is a technique.
2
It is expressible as intent
It can be stated in one clause a non-engineer can act on. “Force the adversary onto ground you own” is a form; “deploy microsegmentation” is not.
3
It is distinct in effect, not in mechanism
Two forms must differ in what they achieve. M4 Obstacle / Canalization and M2 Defense in Depth both use segmentation; they are separate forms because one shapes where an adversary goes and the other ensures no single failure is decisive.
4
It has techniques
A form with no concrete way to perform it is a slogan. Each admitted form must support at least five distinct techniques.
5
It can be absent
It must be possible for an agency to genuinely not have it. A form every organization trivially satisfies carries no information and cannot produce a gap finding.

The riskReduction weighting is assigned relative to the others rather than independently — the ten values are a distribution expressing which forms matter most on federal terrain, which is why M3 Envelopment carries the largest and M10 the smallest. As above, these are planning weights, not measurements.

What Makes a Technique

Naming

A technique is named for the action, in a form that stays true across implementations: Phishing-Resistant Authentication, not FIDO2 rollout; Estate-Wide Session Revocation, not the name of the console you do it from. If a name cannot survive its vendor being replaced, it is the wrong name.

Levels of abstraction

Techniques sit at three levels, and all three are legitimate:

  1. General across terrain — the behavior is the same wherever it applies, e.g. M2.14 Control Failure Detection.
  2. General with layer-specific expression — one intent realized differently per layer, e.g. M5.01M5.08, the same deception intent expressed in data, identity, network, endpoint, application and cloud terrain.
  3. Specific to one layer — e.g. M4.09 Removable Media Control, meaningful only on device terrain.

Where a technique has several steps that resemble other techniques, the deciding question is the same one ATT&CK asks: what is the distinguishing attribute? Describe that, and cross-reference the rest.

Intent before mechanism

The does field states what the technique accomplishes defensively, not how a product is configured. This is the rule that keeps the framework from decaying into a settings guide, and it is the one most often broken by well-meaning contributions.

The success-indicator requirement

Every technique must state what observable state proves it is working — and the indicator must be falsifiable. “MFA is deployed” is not an indicator; “credential phishing yields no usable authentication” is, because it can be tested and can fail.

Why this field is mandatory. It is what makes the framework assessable rather than aspirational, and it is what lets the matrix double as a red-team test plan. A proposed technique with no falsifiable indicator is rejected — not deferred — because an entry nobody can fail is an entry that measures nothing.

Technique distinction

Two techniques are distinct when they differ in at least one of:

Each technique carries exactly one terrain layer. Where a technique plausibly spans layers, it is assigned to the layer whose loss would defeat it, and cross-referenced from the others. This keeps the matrix partitionable — forTower across all six domains must sum to the total, a property the test suite asserts.

Creating and Changing Entries

Creating a technique

  1. Name the defensive effect in one sentence, without naming a product.
  2. Identify the form. Which intent does it serve? If it serves two, it is probably two techniques.
  3. Assign one terrain layer — the layer whose loss defeats it.
  4. Write a falsifiable indicator. If you cannot, stop: the entry is not ready.
  5. Bind controls. Cite the ASOM-Fed controls that make it assessable; if none fits, that is a signal the control set needs extending, which is a separate and heavier change.
  6. Assign dominant phases — where it carries the main effort, not everywhere it runs.
  7. Check distinction against every existing technique in the form.

Enhancing and deprecating

Sharpening a description, strengthening an indicator, or adding a control binding is always preferred to adding a near-duplicate. The catalog’s value degrades faster from redundancy than from omission: a matrix with two cells that mean the same thing quietly double-counts coverage. IDs are never reused — a technique that stops being meaningful is marked deprecated and keeps its ID, so historical coverage scores stay interpretable.

Worked Examples

Accepted — M5.03 Decoy Credentials. Effect: credential material that is valid-looking, monitored and powerless, seeded where harvesting would find it. Form: M5 Ambush — it trades space for information and time. Terrain: T1 Identity; the credentials live in the identity plane and its compromise is what defeats them. Indicator: “credential harvesting is detected on use of a planted credential” — falsifiable, and testable by a red team in an afternoon. Distinct from M5.01 Decoy Records (different terrain, different indicator) and from the M3 techniques (different intent: this one is not trying to prevent movement, it is trying to hear it).
Rejected — “Deploy an EDR agent”. It names a product category, not a defensive effect, and its natural indicator — “the agent is installed” — cannot fail in any interesting way. What it became: two admitted techniques. M2.05 Endpoint Detection and Response Coverage, whose indicator is “coverage is reconciled to the inventory, not to the console” — deliberately targeting the failure mode where a console reports 100% of the hosts it knows about. And M2.14 Control Failure Detection, for the silent-agent problem, which is a different defensive effect and therefore a different technique.
Rejected as a form, admitted as techniques — “Zero Trust”. It is an architectural philosophy, not a form of maneuver: it fails the distinctness test because it describes almost everything the framework already contains, and it fails the absence test because every agency claims it. Where it went: distributed across M2, M3 and M4 as the techniques that actually constitute it. This is the framework working as intended — an umbrella term decomposed into things that can individually be absent, and therefore individually be found missing.

Agency Instantiation

ASOM-Fed is published against a generic Federal Reference Agency archetype and contains no agency-specific information by design. Adopting it means substituting your own systems, boundaries and mission threads into the terrain overlay while leaving the forms, techniques and controls untouched. An agency that finds itself editing the framework rather than the overlay has usually mis-modeled its terrain.

Relationship to Other Frameworks

MITRE ATT&CK

Complementary, not competing, and the cleanest relationship here: ATT&CK catalogs adversary behavior; ASOM-Fed catalogs defensive maneuver. A threat course of action expressed in ATT&CK techniques is the natural input to the MAP step of the ASOM cycle, and the output is a scheme of maneuver expressed in ASOM-Fed forms. Agencies already running ATT&CK Navigator layers — or this platform’s own ATT&CK coverage map — lose nothing by adopting ASOM-Fed; the two overlays answer different questions about the same estate.

MITRE D3FEND

D3FEND is the closest neighbor and deserves a direct answer. It is a knowledge graph of defensive countermeasures, organized as a taxonomy of seven tactics (Model, Harden, Detect, Isolate, Deceive, Evict, Restore) with rigorous semantic relationships to the artifacts they operate on. It is excellent at what it does, and it is more semantically precise than ASOM-Fed.

The difference is operational art. D3FEND tells you what a countermeasure is and what it acts on; it is deliberately not a planning model, and it does not express sequence, main effort, phase, terrain ownership, or tempo. ASOM-Fed is organized around exactly those: its unit is not the countermeasure but the maneuver — an intent applied to specific ground at a specific point in a campaign. An agency wanting a precise ontology of defensive functions should use D3FEND. An agency wanting to decide what to do first, where, and what to give up needs something like ASOM-Fed. They compose: D3FEND is a natural source of rigour for the technique layer, and the worked example crosswalks all eleven forms to its seven tactics.

NIST CSF 2.0, RMF and SP 800-53

Subordinate by design — ASOM-Fed produces compliance rather than consuming it. The cycle’s outputs map onto CSF 2.0’s functions (FRAME → Govern, CPE → Identify, M2–M4/M8 → Protect, M1/M5 → Detect, M6–M8 → Respond, M8/M10 → Recover); the terrain overlay feeds RMF Categorize and Select; the cycle itself is continuous monitoring. Every ASOM-Fed control inherits from named 800-53 Rev. 5 controls, so nothing here creates a parallel compliance burden.

CISA ZTMM and NIST SP 800-207

ZTMM supplies the terrain. ASOM-Fed’s five layers are the ZTMM pillars, and the maturity vector (Traditional → Optimal, per pillar, per quarter) remains the right zero-trust progress report. What ASOM-Fed adds is movement: ZTMM tells an agency how mature each pillar is, not what to do with the pillars when something is happening.

TBM and the Defense Tower Model

The Defense Tower Model mirrors the TBM Council taxonomy one layer at a time, substituting defensive coverage and residual risk for cost: Asset Pools → Defense Towers → Maneuver Solutions → Mission Consumers. This is what gives ASOM-Fed bidirectional traceability — pick a mission and see everything defending it, or pick an asset and see every mission it protects — in a form a CFO already understands.

Scope and Deliberate Exclusions

Things ASOM-Fed does not do, on purpose:

Versioning and Change Management

Version 2.0 is the first structural change, and it was made because the framework failed its own test. Scoring ten representative federal agency architectures against version 1.0 produced a finding about ASOM-Fed rather than about the agencies: no architecture could evidence M10, forty-two of the 111 techniques were evidenced by none of them, and the 35 controls reached five of the six CSF 2.0 Functions — Recover was empty. A framework whose pitch is that compliance should be exhaust cannot leave a whole Function unreachable. Version 2.0 therefore adds:

Every version-1.0 ID kept its number and its meaning. Coverage scores computed against version 1.0 are not comparable to version 2.0 scores, because the denominator changed — which is what “structural change is a major version” is there to signal.

Version 3.0 was driven by a completeness test rather than by a coverage finding. Every ASOM-Fed control cites the NIST SP 800-53 Rev. 5 controls it inherits from, so the families it never cites are a direct measure of the federal estate the framework does not reach. Against version 2.0 that measure returned four families at zero — AT (Awareness and Training), PS at a single citation (Personnel Security), PE (Physical and Environmental Protection) and MA (Maintenance) — with SR and SA thin. Stated as terrain rather than as paperwork: the framework modeled the machines of a federal estate, and not the people who operate it, the buildings it sits in, or the suppliers who reach into it. Those are three of the most-used federal intrusion paths. Version 3.0 adds:

No new forms of maneuver were required, and that is the most load-bearing result in this release. If the eleven forms are genuinely exhaustive at their level of abstraction, then adding three terrain layers should be defensible with the moves already named — and it was. Every one of the twenty-five new techniques falls under an existing form. A version that had needed a twelfth form would have been evidence against the durability claim in §3.2 rather than for it.

The framework now inherits from all twenty SP 800-53 Rev. 5 control families. That is a statement about reach, not about sufficiency: ASOM-Fed specifies the maneuver layer on that ground and inherits the rest, exactly as CG-5 requires.

Summary

ASOM-Fed occupies a level of abstraction that federal cyber defense currently leaves empty. Above it, maturity and outcome models say what should be true. Below it, control catalogs say what must be present. Neither can express the thing that decides engagements: how a defense is arrayed, what it does first, what it gives up, and whether it can act faster than the adversary can adapt.

The framework’s shape follows from one borrowed idea taken seriously — that durable categories of maneuver must be separated from the perishable techniques that realize them — and from one discipline imposed throughout: every technique must state what would prove it is working, and that statement must be capable of being false. The result is a defender’s knowledge base that a CISO can direct, an engineer can implement, a red team can attack, and an auditor can accept as evidence.

It is offered as a public reference framework: unclassified, agency-agnostic, free to use, free to extend, and built to be argued with.

The Rest of the Suite

This document states the reasoning. Seven companion artifacts carry the rest of it, and each is derived from the same connector so they cannot disagree about what the framework contains:

The Studio generates the Brief, which is the cycle record: it cites the controls each section evidences, so successive editions form a dated, evidence-bearing account of how the estate is defended over time.

References

  1. Strom et al., MITRE ATT&CK: Design and Philosophy, The MITRE Corporation, MP180360R1, 2018 (rev. 2020). The structural model for this document.
  2. Allen, Cyber Maneuver and Schemes of Maneuver, The Cyber Defense Review, 2020. Source of the positional/temporal advantage definition and the durability-of-categories argument.
  3. Headquarters, Department of the Army, ATP 2-33.4, Intelligence Analysis. Source of the Screen→Analyze→Integrate→Produce cycle, structured analytic techniques, IPB and confidence levels.
  4. CISA, Zero Trust Maturity Model, v2.0 (April 2023). Source of the five pillars used verbatim as terrain layers (T6 is ASOM-Fed’s own and has no ZTMM equivalent), of the three cross-cutting capabilities that ASOM-Fed consolidates into TX (§3.2), and of the Traditional → Initial → Advanced → Optimal maturity stages.
  5. NIST, SP 800-207, Zero Trust Architecture. Source of the policy decision point / policy enforcement point model.
  6. NIST, Cybersecurity Framework (CSF) 2.0. Govern/Identify/Protect/Detect/Respond/Recover mapping.
  7. NIST, SP 800-53 Rev. 5 and SP 800-37 Rev. 2 (RMF). The control baseline ASOM-Fed inherits from.
  8. OMB, M-22-09, Moving the U.S. Government Toward Zero Trust Cybersecurity Principles.
  9. The MITRE Corporation, D3FEND. The defensive-countermeasure knowledge graph discussed above.
  10. TBM Council, Technology Business Management Taxonomy. The allocation model mirrored by the Defense Tower Model.

ASOM-Fed is published by threatDefendr as a public reference framework. Unclassified and illustrative; built from public sources only; contains no agency-specific information. ATT&CK® and D3FEND™ are trademarks of The MITRE Corporation, which does not endorse this framework.

← PREVIOUSATT&CK CoverageNEXT →The Maneuver Matrix