ASOM-Fedv6.1Open the explorer
Reference manual · assessment

How to Assess This, and What a Score Means.

Every control in the manual carries its own examine / interview / test procedure. What that leaves out is the method around them: how to scope an engagement against a loop rather than a snapshot, what evidence has to look like, how to score a capability without inventing a single flattering number, what counts as a finding, and what has to happen to one afterwards.

78Assessable controlsEach with a published procedure
14FamiliesAssess along the chain, not the alphabet
103Procedures requiring a testNot examination alone
0–5Capability scalePer control, never averaged into one number
Scope

Decide What You Are Assessing Before You Ask for Anything.

ASOM-Fed is a loop, so an assessment is always of a period rather than a moment. Most controls are assessed on whether they ran, on their cadence, with their outputs consumed — not on whether an artifact exists today.

  1. Fix the boundary

    The assessment boundary is the authorization boundary, or a stated subset of it. Where they differ, say which elements were excluded and why — an assessment of a favorable subset is not wrong, it is just not what its title claims.

  2. Fix the cycle window

    ASOM-Fed is a loop, so an assessment is always of a period rather than a moment. Name the cycles in scope. Most controls are assessed on whether they ran, not on whether an artifact exists today.

  3. Establish inheritance first

    CG-5 requires the crosswalk between these controls and the existing 800-53 baseline. Read it before planning fieldwork: where an existing assessment already satisfies a requirement, it is cited, not re-performed. Skipping this step is how the framework acquires a reputation for doubling assessment cost.

  4. Select for dependency, not for family

    A time-boxed assessment should follow the chain rather than the alphabet. TM-1 feeds decisive-point identification, reachability and coverage at once; assessing it badly costs four other judgments. The families that terminate chains can wait.

  5. Name the roles you will need

    Every control carries exactly one accountable role and its responsible parties. Build the interview list from the RACI rather than from the org chart, and expect platform owners to carry the largest share — they are Responsible for 36 of the 78 controls.

  6. State what is out of scope

    This framework does not assess the implementation quality of the inherited 800-53 baseline, and it does not establish whether the estate is currently compromised. Both are routinely assumed by readers of an assessment report that does not say otherwise.

Method

Examine, Interview, Test.

Across the 78 published procedures the three verbs appear examine 105, test 103, interview 16, compare 7, verify 2 times. Examination is the most common and the least conclusive; the 103 procedures that require a test are the ones that separate a program from a binder.

Examine

Read the artifact the control is supposed to produce — the overlay, the register, the declared threshold, the findings list, the cycle record.

Establishes. That the artifact exists, is current against its stated cadence, and is internally complete.

Done badly. Examination alone establishes existence, never function. An overlay can be immaculate and eighteen months stale; a register can be complete and describe an estate that no longer exists.

Interview

Ask the accountable or responsible role how the artifact was produced, and what judgment is encoded in it.

Establishes. Whether the numbers in the artifact reflect a decision someone actually made, or a value that was inherited, copied or defaulted.

Done badly. Interviews drift toward the articulate. Ask for the reasoning behind one specific entry rather than for the process in general — a recovery objective, a criticality score, a designated decisive point.

Test

Re-perform the work: recompute a figure from its source inputs, trace a path, trigger a playbook in a controlled way, or reconstruct a timeline from raw records.

Establishes. That the control functions, and that the reported result is reproducible by someone who did not produce it.

Done badly. Testing is the step that gets dropped under time pressure, and it is the only one that distinguishes a program from a binder. Where a schedule forces a cut, cut coverage — assess fewer controls, and test the ones you assess.

Only 16 of the 78 procedures call for an interview, and they cluster where a number could plausibly have been inherited rather than decided — recovery objectives, criticality scores, declared phases. Those are the controls where the artifact is easy to produce and the judgment behind it is the thing actually being assessed.

Evidence

What an Assessor Should Be Handed.

Each control names the artifact it expects. These five properties are what make any of them assessable — an artifact failing one of them can still be read, but it cannot be tested, and the test is the point.

Dated

An artifact with no date cannot be assessed for currency, and currency is the requirement in TM-6, CE-1 and every control with a cadence.

Attributable

Produced by an identifiable role. Anonymous evidence cannot be corroborated by interview, which removes one of the three methods.

Reproducible

Someone other than the author can regenerate or re-derive it from stated sources. This is what makes the test step possible at all.

Native

The artifact itself, not a rendering of it. A screenshot of a dashboard is evidence that a dashboard existed on a Tuesday; the underlying query and its result are evidence of a method.

Serial where the control is a loop

For anything with a cadence, one instance is not evidence. The series is the evidence, which is why the cycle record (CE-6) is the single most valuable artifact in an assessment.

Capability

A Six-Level Scale, Written Against This Framework’s Failure Modes.

This scale is ASOM-Fed’s own rather than an adopted one, because the failures worth distinguishing here are specific: an artifact that is current but disconnected, and a metric that has never once been allowed to report a problem.

Level 0Absent

The control is not performed. No artifact exists, and no role would claim it.

What an assessor has to seeNothing to examine. Record it as absent rather than as a low score — the difference matters when the control is a prerequisite for four others.

CounterfeitA tool that could produce the artifact if configured. Capability is what is performed, not what is licensed.

Level 1Performed

The control has been performed at least once, by an individual, with no defined method.

What an assessor has to seeThe artifact exists and is attributable to a person. Ask how it would be reproduced; at level 1 the honest answer is “ask them”.

CounterfeitA one-off produced for an audit and never used. Check whether anything downstream consumed it.

Level 2Defined

A written method exists, an accountable role is named, and the artifact is produced on a stated trigger or cadence.

What an assessor has to seeExamine the method; interview the named role; confirm the trigger is written down rather than remembered. Currency is not yet required.

CounterfeitA procedure document with no evidence of having been followed. Level 2 is about the method existing; it says nothing about whether anyone runs it.

Level 3Operating

The control runs on its declared cadence, its output is current, and the controls downstream that declare it as an input are actually consuming it.

What an assessor has to seeTest the chain, not the artifact. Take one output of this control and find it inside the control that names it as an input. A current overlay nobody reads is level 2 with better paperwork.

CounterfeitAn artifact refreshed on schedule but disconnected — the classic terrain overlay that is regenerated quarterly and never changes a decision. This is the level most programs believe they are at, and the chain test is what separates the ones that are.

Level 4Measured

The control’s own metrics are computed and reported, findings arising from them are dispositioned, and at least one metric has reported a bad result without the metric being changed.

What an assessor has to seeExamine the metric series across cycles; test one computation from source; check the findings register for a finding this control raised and how it was dispositioned.

CounterfeitA metric that has been green since it was created. That is either a perfect control or an unmeasured one, and the base rate is not close. The clause about a metric having come out badly is the whole substance of this level.

Level 5Adaptive

The control’s output changes decisions, and the control’s own method has been revised on evidence rather than on reorganization.

What an assessor has to seeTrace one change: a metric moved, a decision was taken because it moved, and the cycle record shows both. Separately, find one revision to the method with the evidence that prompted it.

CounterfeitContinuous improvement asserted in a governance document. Level 5 is a claim about two specific traceable events, and if they cannot be pointed at, the level is 4.

Scoring Rules

What This Method Produces, Worked Through

The illustrative coverage baseline applies this scoring to the Federal Reference Agency end to end: every cataloged technique graded, rolled up per form of maneuver and per terrain layer, with the residual risk that follows — including the four forms it scores with nothing validated at all. It is deliberately unflattering, it is not an assessment of any real agency, and it is what a finished grading looks like before anybody has softened it.

From there the same grading is read against what an adversary is expected to do, on threat courses of action, and against the clock, on temporal advantage.

Program Tier

Six Levels for One Control. One Tier for the Whole Program.

A contracting officer cannot put “capability 3 on KT-4” in a solicitation, and an Authorizing Official cannot brief seventy-eight numbers. The tier is the reading of the scale that those conversations need — and it is a floor plus a gate, never an average.

Exhibit 1

The Six Tiers, and the Two Gates That Came from the Framework Being Wrong.

A tier is a floor and a gate — not an average, and not a badge Each step is the lowest score every control in scope must reach. A single unmet gate holds the program below. TIER 0 Unassessed Unassessed — We do not have a denominator. No current terrain overlay, or assets not classified to a layer. TIER 1 Mapped ≥ 1 Mapped — We know what ground we hold. Terrain overlay current against its stated refresh cadence (TM-1, TM-6). Every asset classified to exactly one layer (TM-2). An owner named for every element (TM-7). TIER 2 Arrayed ≥ 2 Arrayed — We have decided what we are defending and how. Key terrain and decisive points declared (KT-1). A scheme of maneuver exists, with a designated main effort (SM-2, SM-4). Rules of engagement written, with a pre-authorized set (CG-3, TA-4). TIER 3 Maneuvering ≥ 3 Maneuvering — The loop turns, and we can perform every form of maneuver. The cycle runs on its declared cadence and produces its artifacts (CE-1, CE-6). No form of maneuver absent — every one of the eleven at least partially operational (SM-3). Hunt results recorded, including negative results, with scope and window. TIER 4 Measured ≥ 4 Measured — We know whether it is working, and we have been wrong. Temporal advantage computed per cycle against adversary dwell (TA-1, TA-2, TA-3). Coverage published with its denominator and its unreachable remainder (CE-4). At least one measure has reported a problem, and the finding was dispositioned (CG-4). TIER 5 Adaptive ≥ 5 Adaptive — The scheme changes because the measurement said to. A traceable chain: a metric moved, a decision cites it, the cycle record holds both. At least one revision to the method itself, with the evidence that prompted it. Branches and sequels pre-planned and exercised (SM-5, RC-5). CAPABILITY FLOOR — EVERY CONTROL IN SCOPE, NOT THE AVERAGE Two gates are the framework's own findings. Reaching Maneuvering requires no empty maneuver column — a program strong only in the forms money already buys does not pass. Reaching Measured requires that a measure has actually reported a problem: a metric that never comes out badly is either perfect or unmeasured.

Height is the capability floor every control in scope must reach — the lowest score, not the mean. The amber marks are the gates a program cannot argue past.

Tier 0
Unassessedno floor

We do not have a denominator.

  • No current terrain overlay, or assets not classified to a layer.

Nothing, and that is the useful part. A program at tier 0 cannot be scored at all, which is a more accurate public statement than a coverage percentage computed over whatever the tooling happened to see.

Not this. Not a judgment about how well the estate is defended. Plenty of tier-0 programs are defended competently by people who would pass an interview. It says the defense cannot be measured, not that it is bad.

Tier 1
Mappedevery control ≥ 1

We know what ground we hold.

  • Terrain overlay current against its stated refresh cadence (TM-1, TM-6).
  • Every asset classified to exactly one layer (TM-2).
  • An owner named for every element (TM-7).

A denominator. Every later figure this program publishes is computed over a population somebody can inspect, which is the difference between a coverage number and a coverage claim.

Not this. Not a defensive posture. A complete map with nothing arrayed on it is a very good description of ground you are about to lose.

Tier 2
Arrayedevery control ≥ 2

We have decided what we are defending and how.

  • Key terrain and decisive points declared (KT-1).
  • A scheme of maneuver exists, with a designated main effort (SM-2, SM-4).
  • Rules of engagement written, with a pre-authorized set (CG-3, TA-4).

Direction. Somebody can be told what the defense is trying to achieve this cycle and answer without improvising, and a containment action has a stated authority rather than a phone call.

Not this. Not evidence that any of it works. A scheme of maneuver is a plan, and tier 2 is the tier at which a program is most likely to describe itself in the present tense about things it has never performed.

Tier 3
Maneuveringevery control ≥ 3

The loop turns, and we can perform every form of maneuver.

  • The cycle runs on its declared cadence and produces its artifacts (CE-1, CE-6).
  • No form of maneuver absent — every one of the eleven at least partially operational (SM-3).
  • Hunt results recorded, including negative results, with scope and window.

The claim that the defense can actually move. An adversary who defeats one control meets a defense that can deceive, delay, isolate and reconstitute rather than one that can only be hardened further.

Not this. Not proof of effectiveness. Performing all eleven forms says the capability exists, not that employing it changed an outcome — which is the whole reason tier 4 is a separate tier rather than more of this one.

Tier 4
Measuredevery control ≥ 4

We know whether it is working, and we have been wrong.

  • Temporal advantage computed per cycle against adversary dwell (TA-1, TA-2, TA-3).
  • Coverage published with its denominator and its unreachable remainder (CE-4).
  • At least one measure has reported a problem, and the finding was dispositioned (CG-4).

Trend, and an argument. A program at tier 4 can say what a marginal analyst or a marginal sensor is worth, because it has the series to compute it against.

Not this. Not a guarantee of any outcome. Measurement establishes that the program can tell when it is losing — which is a precondition for improving and not a substitute for it.

Tier 5
Adaptiveevery control ≥ 5

The scheme changes because the measurement said to.

  • A traceable chain: a metric moved, a decision cites it, the cycle record holds both.
  • At least one revision to the method itself, with the evidence that prompted it.
  • Branches and sequels pre-planned and exercised (SM-5, RC-5).

The only claim in this table an adversary would find inconvenient: that the defense re-arrays faster than they can re-tool, and that it does so on evidence rather than on an annual planning cycle.

Not this. Not a terminal state, and not a reason to stop assessing. Tier 5 is a description of how a program handles being wrong, so it is the tier most easily lost — one quarter of not acting on a metric and the chain is broken.

How a Tier Is Determined

  1. Score every control in scope on the capability scale, 0 to 5.
  2. Take the LOWEST score, not the average. The tier floor is a floor.
  3. Then test each gate for that tier and every tier below it.
  4. A single unmet gate holds the program at the tier below, however strong the rest is.
  5. Publish the tier with the control and the gate that bound it — the binding constraint is the only actionable part of the result.

Why the lowest score and not the mean. An average is how a program with one catastrophic gap reports 3.2. Two of the gates above exist because the framework found the failure itself: tier 3 refuses to certify a program with an empty column, because being strong in the two forms money already buys while unable to perform four others is the exact posture this framework was built to expose. And tier 4 requires that a measure has actually come out badly, because a metric that has never once reported a problem is either perfect or unmeasured.

A requirement reads “ASOM-Fed tier 3 within eighteen months, tier 4 within thirty, assessed against the published catalog, with the binding constraint reported each cycle.” It is checkable by someone who does not work for you, it names a date, and it cannot be satisfied by buying anything in particular — which is what makes it a capability requirement rather than a product list.

Findings

What a Finding Is, and What It Is Not.

A finding is a statement of fact about a requirement that was not met. It is not advice, and it is not a score somebody is disappointed by. Keeping that line sharp is what makes a register worth dispositioning.

Control reference

The control whose requirement was not met, by id. A finding with no control reference is an opinion.

Expected

What the control requires, quoted from the statement rather than paraphrased into something easier to argue with.

Observed

What was actually found, stated as fact, with the date and the method that found it.

Evidence

The artifact, sample or record that supports the observation, identified well enough for someone else to retrieve it.

Consequence

What this costs the defense — usually expressed through the chain: which downstream controls are starved, and which decisive points are affected.

Owner

The named individual accountable for the affected terrain, from TM-7. A finding routed to a team mailbox will age.

Not Findings

Disposition

Three Outcomes. There Is No Fourth.

CG-4 Findings Disposition requires every finding to be dispositioned as remediated, accepted with justification, or transferred, within a defined period. “Open” is not a disposition; it is the absence of one.

Remediated

The gap is closed and the closure is evidenced by re-performing the test that found it.

Where it goes wrong. Closure asserted by the owner is not closure. The re-test is the artifact, and its absence is the most common way a findings register becomes optimistic.

Accepted

The risk is carried deliberately, with a written justification, by the Authorizing Official — the only role that can accept it — and with a review date.

Where it goes wrong. Governance can document an acceptance; only the Authorizing Official can make one. An acceptance in the register with no identifiable decider is worse than an open finding, because it stops the clock.

Transferred

Responsibility moves to another party — a service provider, a shared-service tenant boundary, an insurer — and the instrument that carries it is cited.

Where it goes wrong. Transfer requires the receiving party to have agreed. FO-3 exists because tenancy boundaries are the place organizations most often believe a risk was transferred when only the workload was.

Findings that accumulate without disposition are the clearest single indicator of a governance failure. Explicit acceptance is a legitimate outcome; silence is not. Measure the age of open findings against the defined period, and report the oldest rather than the mean — a mean age is dragged down by every trivial finding closed quickly.

Measurement

A Program Reporting Only Performance Can Be Busy and Losing.

This is the single most load-bearing distinction in the framework’s measurement layer, and the one a security dashboard is most reliably optimised to obscure.

Measures of performance ask whether the maneuvers were executed correctly. They are cheap to collect, comfortable to present, and every one of them can be excellent while the adversary is still moving faster than the defense. Measures of effectiveness ask whether executing the maneuvers changed the outcome — and they are capable of coming out badly, which is exactly why they are the ones that quietly disappear from a dashboard between one reorganization and the next.

Measures of performance

Are we doing the maneuvers right?

  • Key terrain behind a policy enforcement pointPercentage of declared key terrain sitting behind a PEP rather than a network boundary alone.
  • Deception coverage of data terrainProportion of crown-jewel record sets carrying at least one seeded decoy.
  • Fires pre-authorizedPercentage of containment actions the SOC may execute without escalation.
  • Overlay freshnessAge of the current Cyber Terrain Overlay against its stated refresh cadence.
  • Intelligence requirements answeredPCIRs closed per cycle, against those set at Frame.

Measures of effectiveness

Are we winning?

  • Temporal advantageDefender decision tempo — detect to decide to contain — against adversary dwell time. The signature ASOM-Fed metric, and the one that can be honestly lost.
  • Positional advantageShare of adversary attempts canalized into instrumented terrain, and share stopped before data terrain.
  • Cost impositionDecoy interactions, and adversary re-tooling forced by the defense.
  • ResilienceIncidents contained without loss of statutory availability or transaction integrity.
  • Maturity vectorZero-trust movement per pillar, per quarter — the ZT progress report as a by-product.

The win condition. A cycle is won when temporal advantage is positive — the defender’s decision loop closes faster than the adversary can adapt — at a stated confidence level.

Two Questions

How to Tell, in Ten Minutes, Which Kind of Program You Are Looking At.

Ask for a metric that came out badly

Not a finding — a metric. Ask which measure reported a worse result this cycle than last, and what was decided because of it. A program that cannot produce one either has a perfect defense or has no effectiveness measures, and the base rate is not close.

Ask for both sides of the tempo comparison

Temporal advantage is a comparison. A program reporting mean time to detect, with no estimate of adversary dwell to set it against, has reported a number rather than an advantage — and it is the defender-side number that is easiest to improve without changing any outcome.

Fieldwork

The Day-One Request List.

Every evidence expectation in the catalog, by family, generated from the controls themselves. Send it before fieldwork; the gaps in what comes back are usually the assessment’s first three findings.

TMTerrain Management

  • TM-1Cyber Terrain Overlay (Figure 1 of the Brief); exported diagram source; derivation and reconciliation record.
  • TM-2Asset Register, "Defensive layer" column; reconciliation record.
  • TM-3Asset Register weight column; total defensive weight in the Brief; calibration record.
  • TM-4Terrain overlay showing zone membership; boundary enforcement record.
  • TM-5Connection register; denied paths rendered distinctly on the overlay; change-detection coverage record.
  • TM-6Cycle history with dates; snapshot series; change-trigger record.
  • TM-7Asset Register owner column; open findings list; acceptance record.

KTKey Terrain and Decisive Points

  • KT-1Key Terrain section of the Brief with justification per element; exclusion record; approval record.
  • KT-2Findings list; per-asset maneuver assignment in the Register; sampling record.
  • KT-3Adversary reach analysis; traced route figures; coverage classification per avenue.
  • KT-4Adversary Reach section of the Brief; per-cycle result series; barrier dependency list.
  • KT-5Barrier list from route analysis; supporting configuration evidence; change-detection coverage record.

SMScheme of Maneuver

  • SM-1Adopted catalog with intent, mechanism and effectiveness weighting per move; local extension record.
  • SM-2Per-asset maneuver assignment; unprotected-asset report; sampling record.
  • SM-3Implementation state per assignment with transition dates; effective coverage computation; sampling record.
  • SM-4Phase declaration and main-effort statement in the Brief; subordination record; resourcing allocation record.
  • SM-5Branch and sequel register with triggers; linked response procedures; exercise records.
  • SM-6Validation results; adjusted weightings with justification and supporting evidence.
  • SM-7Emplacement record by terrain layer; interaction alerts with response times; exclusion configuration; exercise encounter records.

TATempo and Temporal Advantage

  • TA-1Temporal advantage assessment; supporting incident timing records; segment breakdown.
  • TA-2Dwell estimate with cited basis, stated bias and confidence level.
  • TA-3Declared threshold with approval date; scoreboard result per cycle; escalation records.
  • TA-4Approved rules of engagement with bounds; escalation matrix; rehearsal records; action logs referencing authorization.
  • TA-5Degradation register with compensating measures and owners; degraded-condition tempo figures; incident-timing correlation.

CECycle Execution and Assurance

  • CE-1Cycle history with dates and phase; lapse justifications with named acceptor.
  • CE-2Intelligence requirement register with status and closure dispositions; visibility findings raised from unanswerable requirements.
  • CE-3Findings with stated confidence and basis; structured technique records; assumption register.
  • CE-4Posture computation in the Brief; documented method with denominator; retained inputs; recomputation record.
  • CE-5Ranked backlog with owners, target dates, effort estimates and ranking basis.
  • CE-6Cycle history table; movement-over-time section of the Brief; version stamps; attribution records.
  • CE-7Generated Briefs, dated and retained, with control citations; decision records.

CGCommand and Governance

  • CG-1Signed intent statement with date; publication record; comprehension test results.
  • CG-2Declared phase with trigger and date; phase readiness score; record of what changed on transition.
  • CG-3Approved rules of engagement with legal bounds; reachability test records; incident action logs referencing authority.
  • CG-4Findings register with disposition, dates, named acceptors and expiries; transfer acknowledgments.
  • CG-5Maintained crosswalk with inheritance decisions and verification status; cited assessment results; unassessed-requirement findings.

RCReconstitution and Recovery

  • RC-1Recovery objectives table with owner approval and dates; statutory floor verification; dependency chains.
  • RC-2Terrain overlay showing the recovery zone and its trust boundary; credential separation record; independence test results.
  • RC-3Rebuild procedure per decisive point; record of the most recent rebuild test and its elapsed time; media provenance verification; dependency sequence.
  • RC-4Integrity verification results for the most recent restoration or exercise; restore point rationale; retention window record.
  • RC-5Exercise record: scenario, participants, measured recovery times, findings raised and their disposition.

FOFederal Obligations

  • FO-1Terrain overlay with privacy elements marked; authority recorded per element; reconciliation record against assessments and notices.
  • FO-2Terrain overlay with marked elements and declared flows; the flow declaration itself; divergence findings.
  • FO-3Inheritance record per hosted element; customer responsibility matrix reconciled to assigned maneuvers; scope exceptions recorded.
  • FO-4Terrain overlay showing the OT layer and its declared connections; constraint record per element; reconciliation against the operational inventory.
  • FO-5Statutory availability register: service, instrument, deadline, resulting recovery objective; legal confirmation records.
  • FO-6SCRM program record with scope and recorded exclusions; pre-award assessments; reconciliation against the supplier terrain register.
  • FO-7Approved obligation profile with inclusion and exclusion bases and approval date; legal confirmations for exclusions; published denominator.

WFWorkforce Terrain

  • WF-1Workforce terrain section of the Brief; role-to-population record; exclusion justifications; ownership record.
  • WF-2Privileged human register with reconciliation dates; exception list with justification and expiry; vetting adequacy records.
  • WF-3Exercise results by role; content mapped to the campaigns it prepares for; threshold definitions with provenance.
  • WF-4Documented process with legal and privacy review; disposition record for closed indications; scenario test record.
  • WF-5Measured revocation times from exercise or real separations; exception register; post-revocation verification results.

FCFacilities Terrain

  • FC-1Terrain overlay showing facilities and their contents; real property reconciliation; decisive-point location resolution record.
  • FC-2Zone declaration with enforcement mechanism; access logs per boundary; traversal test records; retention configuration.
  • FC-3Maintenance window record with approver and supervision evidence; agency-side session logs; path inventory.
  • FC-4Environmental dependency record; ride-through test results; comparison against recovery objectives; degradation sequence.

LCLines of Communication

  • LC-1Supplier terrain register reconciled to provisioned access; standing-access findings; FO-6 scope reconciliation.
  • LC-2Component inventory per artifact; signature and origin verification results; unverifiable-artifact findings with authorization.
  • LC-3Supplier access records showing broker, scope and expiry; revocability verification results.
  • LC-4Staging records with soak periods; integrity verification results per update; bypass records with authority and compensating measures.
  • LC-5Severance exercise record: supplier, elapsed time, mission impact observed; continuity assessment per supplier; findings where continuity fails.

IDIdentity Terrain

  • ID-1Overlay showing identity planes, enforcement points and trust edges; plane dependency record.
  • ID-2Proofing and credential record per identity; mismatch findings; non-human secret inventory with ages.
  • ID-3Assurance requirements per terrain; achieved-assurance records; bypass register; credential resistance test results.
  • ID-4Assertion protection configuration; lifetime and scope records; signing key protection record; revocation test results.
  • ID-5Path coverage record; policy change log with review results; bypass findings; change detection coverage on the policy store.

ENEngagement and Pursuit

  • EN-1Declaration criteria; declared incidents with category, priority and ranking basis; non-declaration record; triage timing.
  • EN-2Reconstruction per incident with dwell, scope, magnitude and confidence; investigation action record; visibility gap findings; overlay corrections.
  • EN-3Preserved evidence inventory with custody records; retention configuration by terrain; integrity verification results.
  • EN-4Escalation criteria and tiers; escalation records with authority and response times; reachability test records; missed-escalation record.
  • EN-5Eradication verification results including identity-plane revocation; recovery action selection with basis; transition decision record with authority; recurrence findings.
  • EN-6Communication records with recipients, content, authority and timing; reporting window register; community contribution records; missed-window findings.

DVDevices Terrain

  • DV-1Terrain overlay showing device classes with management state, population and reach; reconciliation record; software inventory.
  • DV-2Posture requirements per terrain; grant records showing posture state; exception register with expiry.
  • DV-3Reconciled coverage figure with its denominator stated; silent-sensor event records; uncovered device class register with compensations.
  • DV-4Approved execution set with provenance linkage; enforcement scope record distinguishing enforced from audit mode; exception register.
  • DV-5Provisioning baseline with provenance record; trust removal times; sanitization records with method and verification; orphaned-trust findings.
Limits

What This Assessment Does Not Tell You.

Stated here rather than buried in a caveat, because every one of these is routinely assumed by a reader of an assessment report that does not say otherwise.

Elsewhere in the Apparatus

The Rest of the Reference Layer.