What the Framework Says About One Agency.
Every page in this manual describes machinery. This one runs it. The published coverage overlay grades all 154 cataloged techniques against the Federal Reference Agency archetype — 24 validated, 51 partial, 79 absent — and everything below is that grading rolled up: per form of maneuver, per terrain layer, and into a residual the agency is carrying whether or not it has been written down.
There is no agency here. These scores describe an archetype, and they are not a measurement of anybody.
The Federal Reference Agency is a plausible mid-adoption civilian estate used throughout this manual so the model can be shown working end to end. Nothing on this page was produced by assessing a real organization, no agency’s data was used to derive it, and no part of it should be quoted as evidence about any real estate — including as a benchmark to be measured against.
- The grades come from the published framework, not from an engagement. They are the artifact’s own illustrative overlay, transcribed and rolled up.
- The scores are deliberately unflattering in places. Four forms of maneuver score with nothing validated at all. That is the archetype being useful, not an agency being criticised.
- An adopter replaces every number here with their own grading, produced by the method in the assessment guide. This page is what that method produces, not a result to inherit.
Three Grades, One Convention, and Weights That Are Not Technique Counts.
The grading is the framework’s. The arithmetic on top of it is this manual’s, and it is small enough to state in full — a coverage figure whose derivation cannot be written down in four lines is a figure nobody can argue with.
As published, with the framework’s own wording. A partial counts half — that is the one judgment in the arithmetic, it is stated here rather than buried, and moving it moves every number on this page.
- ValidatedImplemented and validated — counts in full
- PartialPartial — emplaced but unproven or incomplete — counts half
- AbsentAbsent — the maneuver cannot currently be performed — counts nothing
(validated + ½ partial) ÷ techniques in the form. A form scores what it can actually do, not what it has bought. M11 is the extreme case: 11 techniques, 0 validated, 4.5%.
Each form carries a risk-reduction weight from the framework contract. They sum to 100, and that is not a count of anything. The catalog holds 154 techniques; 100 is what the eleven forms are worth when all of them are performed. This site once printed the weight sum as a technique count, which is why the two are now derived from different columns and tested against each other.
weight − (weight × capability), summed. The reference agency realizes 32.4 of 100 available points, so it carries 67.6 points — 67.6% of the risk reduction the framework says is available to it.
Computed per technique instead of per weighted form, the same baseline reads 32.1%. The two agreeing this closely is a coincidence of this particular estate, not a corroboration: they would diverge the moment a heavy form improved and a light one did not.
Read It by Column. A Missing Form Is Not a Missing Control.
A control gap is a finding an assessor writes up. A form the agency cannot perform is a move it cannot make while an adversary is making theirs — and it will not appear in any control-by-control report, because each individual control in it may well be satisfied.
Capability and Residual Risk, per Form of Maneuver
| Form | Graded | Risk-reduction weight | Unrealized |
|---|---|---|---|
| M1 Screen / GuardGain early warning and buy reaction time before the adversary touches key terrain. | 33.3% — 2 validated, 6 partial, 7 absent | 7 of 100 | 4.7 points |
| M2 Defense in DepthEnsure no single failure is decisive. | 58.3% — 7 validated, 7 partial, 4 absent | 12 of 100 | 5 points |
| M3 EnvelopmentMake identity, not network location, the decisive plane — surround the adversary with policy. | 60% — 7 validated, 10 partial, 3 absent | 15 of 100 | 6 points |
| M4 Obstacle / CanalizationForce the adversary onto ground you own and watch. | 50% — 5 validated, 7 partial, 5 absent | 10 of 100 | 5 points |
| M5 AmbushTrade space for information and time, and impose cost. | 11.5% — 0 validated, 3 partial, 10 absent | 9 of 100 | 8 points |
| M6 DelayBuy decision time and prevent the adversary culminating on the objective. | 10% — 0 validated, 2 partial, 8 absent | 8 of 100 | 7.2 points |
| M7 CounterattackSeize the initiative and evict before the adversary reaches the objective. | 20.6% — 1 validated, 5 partial, 11 absent | 11 of 100 | 8.7 points |
| M8 Isolation / RetrogradeGive ground deliberately to preserve the force. Degrade gracefully; never fail open. | 11.8% — 0 validated, 4 partial, 13 absent | 10 of 100 | 8.8 points |
| M9 Spoiling AttackDisrupt adversary staging before the attack is launched. | 33.3% — 1 validated, 4 partial, 4 absent | 6 of 100 | 4 points |
| M10 Exploitation & PursuitConvert contact into durable advantage rather than closing the ticket. | 28.6% — 1 validated, 2 partial, 4 absent | 5 of 100 | 3.6 points |
| M11 ReconstitutionRestore the mission on evidence, not on hope — and prove it before you need it. | 4.5% — 0 validated, 1 partial, 10 absent | 7 of 100 | 6.7 points |
M1 Screen / Guard
Gain early warning and buy reaction time before the adversary touches key terrain.
- Graded
- 33.3% — 2 validated, 6 partial, 7 absent
- Risk-reduction weight
- 7 of 100
- Unrealized
- 4.7 points
M2 Defense in Depth
Ensure no single failure is decisive.
- Graded
- 58.3% — 7 validated, 7 partial, 4 absent
- Risk-reduction weight
- 12 of 100
- Unrealized
- 5 points
M3 Envelopment
Make identity, not network location, the decisive plane — surround the adversary with policy.
- Graded
- 60% — 7 validated, 10 partial, 3 absent
- Risk-reduction weight
- 15 of 100
- Unrealized
- 6 points
M4 Obstacle / Canalization
Force the adversary onto ground you own and watch.
- Graded
- 50% — 5 validated, 7 partial, 5 absent
- Risk-reduction weight
- 10 of 100
- Unrealized
- 5 points
M5 Ambush
Trade space for information and time, and impose cost.
- Graded
- 11.5% — 0 validated, 3 partial, 10 absent
- Risk-reduction weight
- 9 of 100
- Unrealized
- 8 points
M6 Delay
Buy decision time and prevent the adversary culminating on the objective.
- Graded
- 10% — 0 validated, 2 partial, 8 absent
- Risk-reduction weight
- 8 of 100
- Unrealized
- 7.2 points
M7 Counterattack
Seize the initiative and evict before the adversary reaches the objective.
- Graded
- 20.6% — 1 validated, 5 partial, 11 absent
- Risk-reduction weight
- 11 of 100
- Unrealized
- 8.7 points
M8 Isolation / Retrograde
Give ground deliberately to preserve the force. Degrade gracefully; never fail open.
- Graded
- 11.8% — 0 validated, 4 partial, 13 absent
- Risk-reduction weight
- 10 of 100
- Unrealized
- 8.8 points
M9 Spoiling Attack
Disrupt adversary staging before the attack is launched.
- Graded
- 33.3% — 1 validated, 4 partial, 4 absent
- Risk-reduction weight
- 6 of 100
- Unrealized
- 4 points
M10 Exploitation & Pursuit
Convert contact into durable advantage rather than closing the ticket.
- Graded
- 28.6% — 1 validated, 2 partial, 4 absent
- Risk-reduction weight
- 5 of 100
- Unrealized
- 3.6 points
M11 Reconstitution
Restore the mission on evidence, not on hope — and prove it before you need it.
- Graded
- 4.5% — 0 validated, 1 partial, 10 absent
- Risk-reduction weight
- 7 of 100
- Unrealized
- 6.7 points
The heaviest single residual is M8 Isolation / Retrograde at 8.8 points — not because it is the thinnest, but because it is thin and heavy at once. That is what the weighting is for: M11 scores lower and costs less, because the contract values it less.
Nothing Validated. Not Thin — Absent.
These four are stated plainly rather than softened, because the tension is the point: the agency can harden, and it cannot deceive, delay, fail secure or reconstitute. Every one of them is a form whose absence only becomes visible under contact.
0 validated, 1 partial, 10 absent of 11. Carries 7 weight points and realizes 0.3.
0 validated, 2 partial, 8 absent of 10. Carries 8 weight points and realizes 0.8.
0 validated, 3 partial, 10 absent of 13. Carries 9 weight points and realizes 1.
0 validated, 4 partial, 13 absent of 17. Carries 10 weight points and realizes 1.2.
The Case Studies Exercise Exactly These Four.
The worked cases at /cases/ depict the same archetype at the same maturity as this page — not a better-resourced cousin of it. Where this baseline scores M11, M6, M5, M8 thin or absent, the cases put the agency in a position where it needs them, and they are required to show it failing or degrading rather than improvising a save.
That is not a limitation of the cases. A hunt narrative in which every capability is available when it is wanted is a product demonstration; the value of a worked example is in watching a real deficit cost something. The two documents are the same agency, and they are meant to be read against each other.
Two Measurements of the Same Ground, and They Disagree.
The tower model scores how well a layer is held — sub-tower maturity weighted by criticality and exposure. The overlay scores which moves can be made from it. A layer can be held to a respectable maturity and support almost no maneuver, and that difference is the most useful thing in this table.
Maneuver Capability Against Tower-Model Coverage, per Layer
| Layer | Maneuver capability | Tower-model coverage | Tower-model residual |
|---|---|---|---|
| T1 IdentityThe high ground · 28 techniques emplaced | 42.9% — 6 validated, 12 partial, 10 absent | 58.1% | 32.3 of 77 weight points |
| T2 DevicesThe entry fords · 13 techniques emplaced | 61.5% — 4 validated, 8 partial, 1 absent | 57.9% | 26.5 of 63 weight points |
| T3 NetworksThe corridors · 22 techniques emplaced | 50% — 8 validated, 6 partial, 8 absent | 63.2% | 28 of 76 weight points |
| T4 Applications and WorkloadsThe urban terrain · 18 techniques emplaced | 30.6% — 3 validated, 5 partial, 10 absent | 50% | 34 of 68 weight points |
| T5 DataThe objective · 12 techniques emplaced | 29.2% — 1 validated, 5 partial, 6 absent | 49.6% | 33.3 of 66 weight points |
| T6 Operational TechnologyGround you cannot maneuver freely on · 7 techniques emplaced | 7.1% — 0 validated, 1 partial, 6 absent | 33.5% | 39.3 of 59 weight points |
| T7 WorkforceTerrain that is also the force · 8 techniques emplaced | 25% — 0 validated, 4 partial, 4 absent | 44.9% | 32.5 of 59 weight points |
| T8 FacilitiesThe physical boundary · 7 techniques emplaced | 14.3% — 0 validated, 2 partial, 5 absent | 40.5% | 25 of 42 weight points |
| T9 Supply ChainThe lines of communication · 10 techniques emplaced | 5% — 0 validated, 1 partial, 9 absent | 44.4% | 40 of 72 weight points |
| TX Cross-CuttingThe enablers of movement · 29 techniques emplaced | 19% — 2 validated, 7 partial, 20 absent | 56.8% | 16 of 37 weight points |
T1 Identity
The high ground · 28 techniques emplaced
- Maneuver capability
- 42.9% — 6 validated, 12 partial, 10 absent
- Tower-model coverage
- 58.1%
- Tower-model residual
- 32.3 of 77 weight points
T2 Devices
The entry fords · 13 techniques emplaced
- Maneuver capability
- 61.5% — 4 validated, 8 partial, 1 absent
- Tower-model coverage
- 57.9%
- Tower-model residual
- 26.5 of 63 weight points
T3 Networks
The corridors · 22 techniques emplaced
- Maneuver capability
- 50% — 8 validated, 6 partial, 8 absent
- Tower-model coverage
- 63.2%
- Tower-model residual
- 28 of 76 weight points
T4 Applications and Workloads
The urban terrain · 18 techniques emplaced
- Maneuver capability
- 30.6% — 3 validated, 5 partial, 10 absent
- Tower-model coverage
- 50%
- Tower-model residual
- 34 of 68 weight points
T5 Data
The objective · 12 techniques emplaced
- Maneuver capability
- 29.2% — 1 validated, 5 partial, 6 absent
- Tower-model coverage
- 49.6%
- Tower-model residual
- 33.3 of 66 weight points
T6 Operational Technology
Ground you cannot maneuver freely on · 7 techniques emplaced
- Maneuver capability
- 7.1% — 0 validated, 1 partial, 6 absent
- Tower-model coverage
- 33.5%
- Tower-model residual
- 39.3 of 59 weight points
T7 Workforce
Terrain that is also the force · 8 techniques emplaced
- Maneuver capability
- 25% — 0 validated, 4 partial, 4 absent
- Tower-model coverage
- 44.9%
- Tower-model residual
- 32.5 of 59 weight points
T8 Facilities
The physical boundary · 7 techniques emplaced
- Maneuver capability
- 14.3% — 0 validated, 2 partial, 5 absent
- Tower-model coverage
- 40.5%
- Tower-model residual
- 25 of 42 weight points
T9 Supply Chain
The lines of communication · 10 techniques emplaced
- Maneuver capability
- 5% — 0 validated, 1 partial, 9 absent
- Tower-model coverage
- 44.4%
- Tower-model residual
- 40 of 72 weight points
TX Cross-Cutting
The enablers of movement · 29 techniques emplaced
- Maneuver capability
- 19% — 2 validated, 7 partial, 20 absent
- Tower-model coverage
- 56.8%
- Tower-model residual
- 16 of 37 weight points
Across the whole estate the tower model reads 50.4% covered with 306.9 residual weight points, while the maneuver overlay reads 32.4%. The widest single disagreement is T9 Supply Chain, held at 44.4% and able to support 5% of the maneuver emplaced on it. Neither number is wrong. They answer different questions, and a program that reports only the first will be surprised by the second.
What the Framework Itself Says About This Baseline.
Quoted rather than paraphrased, and tested against the artifact so it stays quoted. Where the computed figures are more precise than the prose, the figures are what this manual reports.
An illustrative baseline for the Federal Reference Agency archetype. Read it by column, not by cell: M2 and M3 are largely emplaced because they are what compliance programs fund, while M5, M6 and M8 are thin — the agency can harden but cannot deceive, delay or fail secure — and M11 is absent outright: the agency holds backups its own production credentials can reach, which makes them part of the objective rather than the means of recovery. Its only T6 ground is building systems, and those are not in the inventory. The three layers added in v3.0 read the way a real federal estate reads: annual training and badge readers exist, but the workforce is not held as terrain, the facility maintenance path is standing rather than time-boxed, and the managed-service provider reaches production with access the agency cannot revoke on its own. Those are missing forms of maneuver, not missing controls. Read this overlay against the families added since it was first scored: the identity ground it calls thin is now specified by the ID family, the eviction and pursuit gaps behind M7 and M8 by the EN family, and the device layer — the archetype discovers endpoints from the management console, which can only report what it already manages — by DV. The scoring is unchanged, because a control family being specified is not the same as an agency having emplaced it; what changed is that each of these gaps now has somewhere to be assessed.
ASOM-Fed Defensive Maneuver Framework v6.1 · overlay “Reference-agency coverage”
One place the arithmetic is sharper than the sentence: the note calls M11 absent outright, and the grading actually leaves it at 4.5% — 1 of 11 techniques partial and the rest absent. The difference matters to a reader deciding where to start, so the table states the grading and this paragraph states the discrepancy rather than either one being quietly adjusted to match the other.
The overlay grades every technique exactly once — full, partial, none — which is what allows a share of the catalog and a residual to be stated at all. The other two overlays in this section are selections rather than partitions, and say so.
A Baseline Is an Input, Not a Report.
Coverage on its own ranks nothing. It becomes a plan when it is read against what the adversary is expected to do, and against the clock both sides are running.