ASOM-Fedv6.1Open the explorer
Reference manual · analytic overlays

What the Framework Says About One Agency.

Every page in this manual describes machinery. This one runs it. The published coverage overlay grades all 154 cataloged techniques against the Federal Reference Agency archetype — 24 validated, 51 partial, 79 absent — and everything below is that grading rolled up: per form of maneuver, per terrain layer, and into a residual the agency is carrying whether or not it has been written down.

Illustrative · not an assessment

There is no agency here. These scores describe an archetype, and they are not a measurement of anybody.

The Federal Reference Agency is a plausible mid-adoption civilian estate used throughout this manual so the model can be shown working end to end. Nothing on this page was produced by assessing a real organization, no agency’s data was used to derive it, and no part of it should be quoted as evidence about any real estate — including as a benchmark to be measured against.

  • The grades come from the published framework, not from an engagement. They are the artifact’s own illustrative overlay, transcribed and rolled up.
  • The scores are deliberately unflattering in places. Four forms of maneuver score with nothing validated at all. That is the archetype being useful, not an agency being criticised.
  • An adopter replaces every number here with their own grading, produced by the method in the assessment guide. This page is what that method produces, not a result to inherit.
32.4%Maneuver capability realizedWeighted by the framework’s own form weights
67.6Residual, in weight pointsOf 100 the eleven forms are worth in total
79Techniques it cannot performOf 154 cataloged — 24 are validated
4Forms with nothing validatedM5, M6, M8, M11
How This Is Scored

Three Grades, One Convention, and Weights That Are Not Technique Counts.

The grading is the framework’s. The arithmetic on top of it is this manual’s, and it is small enough to state in full — a coverage figure whose derivation cannot be written down in four lines is a figure nobody can argue with.

The three grades

As published, with the framework’s own wording. A partial counts half — that is the one judgment in the arithmetic, it is stated here rather than buried, and moving it moves every number on this page.

  • ValidatedImplemented and validated — counts in full
  • PartialPartial — emplaced but unproven or incomplete — counts half
  • AbsentAbsent — the maneuver cannot currently be performed — counts nothing
Capability, per form

(validated + ½ partial) ÷ techniques in the form. A form scores what it can actually do, not what it has bought. M11 is the extreme case: 11 techniques, 0 validated, 4.5%.

Weights, and the number 117

Each form carries a risk-reduction weight from the framework contract. They sum to 100, and that is not a count of anything. The catalog holds 154 techniques; 100 is what the eleven forms are worth when all of them are performed. This site once printed the weight sum as a technique count, which is why the two are now derived from different columns and tested against each other.

Residual

weight − (weight × capability), summed. The reference agency realizes 32.4 of 100 available points, so it carries 67.6 points67.6% of the risk reduction the framework says is available to it.

Computed per technique instead of per weighted form, the same baseline reads 32.1%. The two agreeing this closely is a coincidence of this particular estate, not a corroboration: they would diverge the moment a heavy form improved and a light one did not.

By Form of Maneuver

Read It by Column. A Missing Form Is Not a Missing Control.

A control gap is a finding an assessor writes up. A form the agency cannot perform is a move it cannot make while an adversary is making theirs — and it will not appear in any control-by-control report, because each individual control in it may well be satisfied.

Exhibit 1

Capability and Residual Risk, per Form of Maneuver

FormGradedRisk-reduction weightUnrealized
M1 Screen / GuardGain early warning and buy reaction time before the adversary touches key terrain.
33.3%2 validated, 6 partial, 7 absent
7 of 1004.7 points
M2 Defense in DepthEnsure no single failure is decisive.
58.3%7 validated, 7 partial, 4 absent
12 of 1005 points
M3 EnvelopmentMake identity, not network location, the decisive plane — surround the adversary with policy.
60%7 validated, 10 partial, 3 absent
15 of 1006 points
M4 Obstacle / CanalizationForce the adversary onto ground you own and watch.
50%5 validated, 7 partial, 5 absent
10 of 1005 points
M5 AmbushTrade space for information and time, and impose cost.
11.5%0 validated, 3 partial, 10 absent
9 of 1008 points
M6 DelayBuy decision time and prevent the adversary culminating on the objective.
10%0 validated, 2 partial, 8 absent
8 of 1007.2 points
M7 CounterattackSeize the initiative and evict before the adversary reaches the objective.
20.6%1 validated, 5 partial, 11 absent
11 of 1008.7 points
M8 Isolation / RetrogradeGive ground deliberately to preserve the force. Degrade gracefully; never fail open.
11.8%0 validated, 4 partial, 13 absent
10 of 1008.8 points
M9 Spoiling AttackDisrupt adversary staging before the attack is launched.
33.3%1 validated, 4 partial, 4 absent
6 of 1004 points
M10 Exploitation & PursuitConvert contact into durable advantage rather than closing the ticket.
28.6%1 validated, 2 partial, 4 absent
5 of 1003.6 points
M11 ReconstitutionRestore the mission on evidence, not on hope — and prove it before you need it.
4.5%0 validated, 1 partial, 10 absent
7 of 1006.7 points

M1 Screen / Guard

Gain early warning and buy reaction time before the adversary touches key terrain.

Graded
33.3%2 validated, 6 partial, 7 absent
Risk-reduction weight
7 of 100
Unrealized
4.7 points

M2 Defense in Depth

Ensure no single failure is decisive.

Graded
58.3%7 validated, 7 partial, 4 absent
Risk-reduction weight
12 of 100
Unrealized
5 points

M3 Envelopment

Make identity, not network location, the decisive plane — surround the adversary with policy.

Graded
60%7 validated, 10 partial, 3 absent
Risk-reduction weight
15 of 100
Unrealized
6 points

M4 Obstacle / Canalization

Force the adversary onto ground you own and watch.

Graded
50%5 validated, 7 partial, 5 absent
Risk-reduction weight
10 of 100
Unrealized
5 points

M5 Ambush

Trade space for information and time, and impose cost.

Graded
11.5%0 validated, 3 partial, 10 absent
Risk-reduction weight
9 of 100
Unrealized
8 points

M6 Delay

Buy decision time and prevent the adversary culminating on the objective.

Graded
10%0 validated, 2 partial, 8 absent
Risk-reduction weight
8 of 100
Unrealized
7.2 points

M7 Counterattack

Seize the initiative and evict before the adversary reaches the objective.

Graded
20.6%1 validated, 5 partial, 11 absent
Risk-reduction weight
11 of 100
Unrealized
8.7 points

M8 Isolation / Retrograde

Give ground deliberately to preserve the force. Degrade gracefully; never fail open.

Graded
11.8%0 validated, 4 partial, 13 absent
Risk-reduction weight
10 of 100
Unrealized
8.8 points

M9 Spoiling Attack

Disrupt adversary staging before the attack is launched.

Graded
33.3%1 validated, 4 partial, 4 absent
Risk-reduction weight
6 of 100
Unrealized
4 points

M10 Exploitation & Pursuit

Convert contact into durable advantage rather than closing the ticket.

Graded
28.6%1 validated, 2 partial, 4 absent
Risk-reduction weight
5 of 100
Unrealized
3.6 points

M11 Reconstitution

Restore the mission on evidence, not on hope — and prove it before you need it.

Graded
4.5%0 validated, 1 partial, 10 absent
Risk-reduction weight
7 of 100
Unrealized
6.7 points
Illustrative Graded by the published ASOM-Fed Defensive Maneuver Framework v6.1 coverage overlay; capability and residual computed from that grading and the contract’s risk-reduction weights. Forms in catalog order.

The heaviest single residual is M8 Isolation / Retrograde at 8.8 points — not because it is the thinnest, but because it is thin and heavy at once. That is what the weighting is for: M11 scores lower and costs less, because the contract values it less.

The Four It Cannot Perform

Nothing Validated. Not Thin — Absent.

These four are stated plainly rather than softened, because the tension is the point: the agency can harden, and it cannot deceive, delay, fail secure or reconstitute. Every one of them is a form whose absence only becomes visible under contact.

4.5%M11 · Reconstitution

0 validated, 1 partial, 10 absent of 11. Carries 7 weight points and realizes 0.3.

What this form is for

10%M6 · Delay

0 validated, 2 partial, 8 absent of 10. Carries 8 weight points and realizes 0.8.

What this form is for

11.5%M5 · Ambush

0 validated, 3 partial, 10 absent of 13. Carries 9 weight points and realizes 1.

What this form is for

11.8%M8 · Isolation / Retrograde

0 validated, 4 partial, 13 absent of 17. Carries 10 weight points and realizes 1.2.

What this form is for

The Case Studies Exercise Exactly These Four.

The worked cases at /cases/ depict the same archetype at the same maturity as this page — not a better-resourced cousin of it. Where this baseline scores M11, M6, M5, M8 thin or absent, the cases put the agency in a position where it needs them, and they are required to show it failing or degrading rather than improvising a save.

That is not a limitation of the cases. A hunt narrative in which every capability is available when it is wanted is a product demonstration; the value of a worked example is in watching a real deficit cost something. The two documents are the same agency, and they are meant to be read against each other.

The proactive hunt · The reactive hunt

By Terrain Layer

Two Measurements of the Same Ground, and They Disagree.

The tower model scores how well a layer is held — sub-tower maturity weighted by criticality and exposure. The overlay scores which moves can be made from it. A layer can be held to a respectable maturity and support almost no maneuver, and that difference is the most useful thing in this table.

Exhibit 2

Maneuver Capability Against Tower-Model Coverage, per Layer

LayerManeuver capabilityTower-model coverageTower-model residual
T1 IdentityThe high ground · 28 techniques emplaced
42.9%6 validated, 12 partial, 10 absent
58.1%32.3 of 77 weight points
T2 DevicesThe entry fords · 13 techniques emplaced
61.5%4 validated, 8 partial, 1 absent
57.9%26.5 of 63 weight points
T3 NetworksThe corridors · 22 techniques emplaced
50%8 validated, 6 partial, 8 absent
63.2%28 of 76 weight points
T4 Applications and WorkloadsThe urban terrain · 18 techniques emplaced
30.6%3 validated, 5 partial, 10 absent
50%34 of 68 weight points
T5 DataThe objective · 12 techniques emplaced
29.2%1 validated, 5 partial, 6 absent
49.6%33.3 of 66 weight points
T6 Operational TechnologyGround you cannot maneuver freely on · 7 techniques emplaced
7.1%0 validated, 1 partial, 6 absent
33.5%39.3 of 59 weight points
T7 WorkforceTerrain that is also the force · 8 techniques emplaced
25%0 validated, 4 partial, 4 absent
44.9%32.5 of 59 weight points
T8 FacilitiesThe physical boundary · 7 techniques emplaced
14.3%0 validated, 2 partial, 5 absent
40.5%25 of 42 weight points
T9 Supply ChainThe lines of communication · 10 techniques emplaced
5%0 validated, 1 partial, 9 absent
44.4%40 of 72 weight points
TX Cross-CuttingThe enablers of movement · 29 techniques emplaced
19%2 validated, 7 partial, 20 absent
56.8%16 of 37 weight points

T1 Identity

The high ground · 28 techniques emplaced

Maneuver capability
42.9%6 validated, 12 partial, 10 absent
Tower-model coverage
58.1%
Tower-model residual
32.3 of 77 weight points

T2 Devices

The entry fords · 13 techniques emplaced

Maneuver capability
61.5%4 validated, 8 partial, 1 absent
Tower-model coverage
57.9%
Tower-model residual
26.5 of 63 weight points

T3 Networks

The corridors · 22 techniques emplaced

Maneuver capability
50%8 validated, 6 partial, 8 absent
Tower-model coverage
63.2%
Tower-model residual
28 of 76 weight points

T4 Applications and Workloads

The urban terrain · 18 techniques emplaced

Maneuver capability
30.6%3 validated, 5 partial, 10 absent
Tower-model coverage
50%
Tower-model residual
34 of 68 weight points

T5 Data

The objective · 12 techniques emplaced

Maneuver capability
29.2%1 validated, 5 partial, 6 absent
Tower-model coverage
49.6%
Tower-model residual
33.3 of 66 weight points

T6 Operational Technology

Ground you cannot maneuver freely on · 7 techniques emplaced

Maneuver capability
7.1%0 validated, 1 partial, 6 absent
Tower-model coverage
33.5%
Tower-model residual
39.3 of 59 weight points

T7 Workforce

Terrain that is also the force · 8 techniques emplaced

Maneuver capability
25%0 validated, 4 partial, 4 absent
Tower-model coverage
44.9%
Tower-model residual
32.5 of 59 weight points

T8 Facilities

The physical boundary · 7 techniques emplaced

Maneuver capability
14.3%0 validated, 2 partial, 5 absent
Tower-model coverage
40.5%
Tower-model residual
25 of 42 weight points

T9 Supply Chain

The lines of communication · 10 techniques emplaced

Maneuver capability
5%0 validated, 1 partial, 9 absent
Tower-model coverage
44.4%
Tower-model residual
40 of 72 weight points

TX Cross-Cutting

The enablers of movement · 29 techniques emplaced

Maneuver capability
19%2 validated, 7 partial, 20 absent
Tower-model coverage
56.8%
Tower-model residual
16 of 37 weight points
Illustrative Maneuver capability from the coverage overlay; tower-model coverage and residual from the same Federal Reference Agency sub-tower profile used on the terrain pages — the two are computed from different data about one estate, which is why they can be compared.

Across the whole estate the tower model reads 50.4% covered with 306.9 residual weight points, while the maneuver overlay reads 32.4%. The widest single disagreement is T9 Supply Chain, held at 44.4% and able to support 5% of the maneuver emplaced on it. Neither number is wrong. They answer different questions, and a program that reports only the first will be surprised by the second.

The Source

What the Framework Itself Says About This Baseline.

Quoted rather than paraphrased, and tested against the artifact so it stays quoted. Where the computed figures are more precise than the prose, the figures are what this manual reports.

An illustrative baseline for the Federal Reference Agency archetype. Read it by column, not by cell: M2 and M3 are largely emplaced because they are what compliance programs fund, while M5, M6 and M8 are thin — the agency can harden but cannot deceive, delay or fail secure — and M11 is absent outright: the agency holds backups its own production credentials can reach, which makes them part of the objective rather than the means of recovery. Its only T6 ground is building systems, and those are not in the inventory. The three layers added in v3.0 read the way a real federal estate reads: annual training and badge readers exist, but the workforce is not held as terrain, the facility maintenance path is standing rather than time-boxed, and the managed-service provider reaches production with access the agency cannot revoke on its own. Those are missing forms of maneuver, not missing controls. Read this overlay against the families added since it was first scored: the identity ground it calls thin is now specified by the ID family, the eviction and pursuit gaps behind M7 and M8 by the EN family, and the device layer — the archetype discovers endpoints from the management console, which can only report what it already manages — by DV. The scoring is unchanged, because a control family being specified is not the same as an agency having emplaced it; what changed is that each of these gaps now has somewhere to be assessed.

ASOM-Fed Defensive Maneuver Framework v6.1 · overlay “Reference-agency coverage

One place the arithmetic is sharper than the sentence: the note calls M11 absent outright, and the grading actually leaves it at 4.5% — 1 of 11 techniques partial and the rest absent. The difference matters to a reader deciding where to start, so the table states the grading and this paragraph states the discrepancy rather than either one being quietly adjusted to match the other.

The overlay grades every technique exactly once — full, partial, none — which is what allows a share of the catalog and a residual to be stated at all. The other two overlays in this section are selections rather than partitions, and say so.

Where This Goes

A Baseline Is an Input, Not a Report.

Coverage on its own ranks nothing. It becomes a plan when it is read against what the adversary is expected to do, and against the clock both sides are running.