A Commander’s-Intent-Driven, Intelligence-Led Plan for Ground You Own.
ASOM-Fed fuses two mature Army doctrines that are rarely combined: the scheme of maneuver, which is how a force arrays itself to gain positional advantage, and intelligence analysis, which is the engine that decides where the advantage is. The union is a defense that thinks before it moves, and keeps moving.
The Loop Is the Framework.
Everything else on this site is an input to, or an output of, these six steps. A program that adopts the terrain model and the maneuver catalog but never actually turns the loop has bought a vocabulary, not a defense.
The ASOM Cycle
Frame
Screen · Analytic Design step 1
Map
Cyber Preparation of the Environment — the IPB analog
Array
Design the scheme
Maneuver
Execute
Fuse
Analyze · Integrate
Assess
Produce · re-frame
↺ Re-frame — the loop turns faster than the adversary adapts
State the defensive intent, set Priority Cyber Intelligence Requirements, and define what positional advantage means for this cycle.
OutputAn intent paragraph and a PCIR list.Refresh the terrain overlay, enumerate avenues of approach, and build threat courses of action: most likely and most dangerous.
OutputA terrain overlay and a threat COA sketch.Choose the forms of maneuver, designate the main and supporting efforts, site obstacles at decisive points, and pre-plan branches and sequels.
OutputThe scheme of maneuver — one graphic and one narrative.Emplace obstacles, reposition sensors, and execute defensive fires — block, isolate, deceive, disrupt — under the standing rules of engagement.
OutputExecuted defensive actions and a change record.Apply structured analytic techniques to what came back: competing hypotheses on adversary intent, a key-assumptions check, indicators and signposts. Assign explicit confidence.
OutputA fused assessment feeding the Cyber Running Estimate.Measure positional and temporal advantage, then decide: continue, exploit, or transition to a branch. Publish the product and turn the loop.
OutputA confidence-tagged product, and the next cycle’s framing.A Scheme Names a Sequence and One Main Effort. It Is Not a Checklist of All Eleven.
Credential-stuffing against external accounts on a public service portal, ahead of a statutory filing deadline.
Worked Scheme — Credential Stuffing Against a Public Service Portal
M3 · Envelopment
Identity is the main effort because the adversary’s entire plan runs through a credential. Everything in the sequence is buying time for the envelopment to hold.
- 1 · M1Screen / GuardThreats are detected before they reach key terrain.
- 2 · M5AmbushThe adversary interacts with a decoy, producing a detection with no false-positive budget.
- 3 · M6DelayAdversary tempo drops below defender decision tempo.
- 4 · M7CounterattackMean time to evict is inside the adversary’s dwell budget.
- 5 · M10Exploitation & PursuitThe same avenue of approach is never successfully used twice.
6 of the 11 forms named, and nothing else — this is a scheme, not a campaign. Two worked cases run the same cycle end to end instead: a proactive campaign, planned before contact and judged on whether the adversary’s approach was ever viable, and a reactive one, run under contact and judged on whether the defender’s loop turned inside the adversary’s. Both are indexed in the case studies.
Six Phases, Each with Its Own Main Effort.
The cycle turns in days. The campaign moves over months. Keeping them apart is what lets leadership see cyber defense as a campaign with a designated priority per phase, rather than as an undifferentiated round-the-clock grind.
Campaign Phasing — Joint Phases Mapped to Defensive Objectives
| Phase | Defensive objective | Dominant maneuvers |
|---|---|---|
| 0 — ShapeSet conditions | Continuous terrain preparation, zero-trust hardening, partnerships, threat intelligence. | |
| I — DeterRaise adversary cost | Visible hardening, a deception grid, and a stated attribution posture. | |
| II — Seize InitiativeContest first contact | Detect early, canalize movement, and buy decision time. | |
| III — DominateDefeat the attempt | Hunt, contain, evict. | |
| IV — StabilizeRestore secure operations | Eradicate, verify, and preserve availability through the recovery. | |
| V — Enable / RestoreHand back to garrison | Recover, harden, and update the doctrine and the intelligence requirements. |
0 — Shape
Set conditions
- Defensive objective
- Continuous terrain preparation, zero-trust hardening, partnerships, threat intelligence.
- Dominant maneuvers
I — Deter
Raise adversary cost
- Defensive objective
- Visible hardening, a deception grid, and a stated attribution posture.
- Dominant maneuvers
II — Seize Initiative
Contest first contact
- Defensive objective
- Detect early, canalize movement, and buy decision time.
- Dominant maneuvers
III — Dominate
Defeat the attempt
- Defensive objective
- Hunt, contain, evict.
- Dominant maneuvers
IV — Stabilize
Restore secure operations
- Defensive objective
- Eradicate, verify, and preserve availability through the recovery.
- Dominant maneuvers
V — Enable / Restore
Hand back to garrison
- Defensive objective
- Recover, harden, and update the doctrine and the intelligence requirements.
- Dominant maneuvers
Tempo Dies in an Escalation Queue.
The single highest-leverage governance decision in the framework is settling, in advance, which defensive fires the SOC may execute without approval. It is the cyber analog of engagement authority, and it is usually the difference between a nine-minute containment and a nine-hour one.
Intent, risk acceptance, and the scheme itself.
Frame, Map and Fuse. Owns the intelligence requirements, the threat courses of action, and the confidence levels.
Maneuver. Executes fires and emplaces obstacles inside the standing rules of engagement.
Counterattack. Works the hypotheses that Fuse raises.
Their own terrain. Obstacles get emplaced on their ground, so they site them.
Translating cycle outputs into FISMA and RMF artifacts, and owning the rules of engagement.
Two Questions, and Only One of Them Is Comfortable.
A cycle is won when temporal advantage is positive — the defender’s decision loop closes faster than the adversary can adapt — at a stated confidence level.
Are We Doing the Maneuvers Right?
- Key terrain behind a policy enforcement point. Percentage of declared key terrain sitting behind a PEP rather than a network boundary alone.
- Deception coverage of data terrain. Proportion of crown-jewel record sets carrying at least one seeded decoy.
- Fires pre-authorized. Percentage of containment actions the SOC may execute without escalation.
- Overlay freshness. Age of the current Cyber Terrain Overlay against its stated refresh cadence.
- Intelligence requirements answered. PCIRs closed per cycle, against those set at Frame.
Are We Winning?
- Temporal advantage. Defender decision tempo — detect to decide to contain — against adversary dwell time. The signature ASOM-Fed metric, and the one that can be honestly lost.
- Positional advantage. Share of adversary attempts canalized into instrumented terrain, and share stopped before data terrain.
- Cost imposition. Decoy interactions, and adversary re-tooling forced by the defense.
- Resilience. Incidents contained without loss of statutory availability or transaction integrity.
- Maturity vector. Zero-trust movement per pillar, per quarter — the ZT progress report as a by-product.
A program reporting only measures of performance can be busy and losing — which is the failure mode most security dashboards are, unintentionally, optimized to conceal. See how the two are scored against a declared agency profile in the control catalog, and how the loop is timed against adversary dwell in the tempo reference.
This Page States the Loop. the Manual Runs It.
6 steps and 6 phases, each with entry and exit criteria, the participants, the products it produces and consumes, and the ways it fails while still being reported as performed.
The Operating Cycle
Each step with what has to be true to enter it, what has to exist to leave it, who is in the room, and the failure mode that lets it be reported as done when it was not.
6 phasesCampaign Phases
The main effort per phase, the conditions for moving between them, and what changes in cadence and in pre-authorized engagement authority when you do.
ArtifactsWhat the Loop Leaves Behind
Every artifact the framework emits, with the controls that produce it, the roles that own it, the controls that consume it, and the cadence it goes stale at.
At ArrayCourse-Of-Action Development
How a scheme is actually built at step three: generating courses of action, comparing them against stated criteria, and recording the one chosen with the reason it beat the others.
The signature metricTempo and Temporal Advantage
The defender’s decision loop measured against adversary dwell — the framework’s one metric that can be honestly lost, and the arithmetic behind it.
Worked end to endCase Studies
The whole cycle run twice on one estate — once before contact and once under it — so the difference between the two postures is visible rather than asserted.
Straight to a case: the proactive campaign or the reactive one.
New to this vocabulary? Form of maneuver, technique and control are different classes of thing, and swapping two of them produces work that looks correct and decides nothing. The object model states each one with the question it answers and the class it is most often mistaken for.
The Cycle Needs Ground to Run On.
Every step above assumes a terrain overlay exists — an authoritative, positional picture of what you hold and what it is worth. Building the first one is Phase A, and it is the step most programs skip.