Control Statement
Defensive coverage and residual risk shall be computed from asset weighting, layer maturity, and operational move mitigation, using a documented method.
Purpose. To produce a posture figure that can be reproduced and challenged rather than asserted, so that the number carries authority beyond the tool that generated it.
Discussion
The denominator determines the answer, and the choice of denominator is a judgment that must be published rather than embedded. Counting techniques evidenced rewards tagging a crowded intersection over a sparse one for identical effort; counting ground held — terrain × form cells occupied — does not, which is why the framework scores that way. But the reasoning is only defensible if it is stated where the figure appears. A coverage percentage whose denominator is undisclosed is not a measurement, and an adopter who cannot reproduce it cannot argue with it.
Goals and Metrics
A metric that cannot come out badly is not a metric. Each of these is capable of reporting that the control is not working.
- Whether the computation method is documented and version-controlled
- Difference between computed coverage and any separately reported figure
- Proportion of mitigation credit derived from moves in an operational state
Accountability
Exactly one role is accountable, and every other role carries at least Informed — no control in the published catalog leaves a role with zero relationship to it. That is a stated property of how these were authored, not a coincidence, and not a claim that every role's work is worth equal attention here.
| AO | CTI | SOC | HUNT | PLAT | ISSO |
|---|---|---|---|---|---|
| Authorizing Official / CISO: Accountable | Cyber Threat Intelligence cell: Consulted | SOC / Defensive Operations: Informed | Hunt team: Informed | Platform and product owners: Consulted | Governance / RMF / ISSO: Responsible |
AO Authorizing Official / CISOCTI Cyber Threat Intelligence cellSOC SOC / Defensive OperationsHUNT Hunt teamPLAT Platform and product ownersISSO Governance / RMF / ISSO
- AccountableAuthorizing Official / CISO
- ConsultedCyber Threat Intelligence cell
- InformedSOC / Defensive Operations
- InformedHunt team
- ConsultedPlatform and product owners
- ResponsibleGovernance / RMF / ISSO
Inputs and Outputs
Consumes
- TM-3 Asset WeightingDefensive weight per element
- TM-2 Defensive Layer ClassificationDefensive layer assignment for aggregation
- SM-3 Implementation State TrackingImplementation state discounting planned and partial work
- SM-6 Maneuver Effectiveness ValidationValidated effectiveness values
- KT-4 Adversary Reachability AssessmentReachability result
- TM-1 Terrain Inventory and OverlayThe population over which coverage and residual risk are computed
- SM-2 Maneuver AssignmentMitigation input to the coverage computation
- SM-7 Deception EmplacementEmplacement coverage feeding the posture computation
- FO-3 Tenancy and Inheritance BoundaryInherited mitigation counted correctly in coverage
- FO-7 Obligation Profile DeclarationThe scoped FO denominator posture is computed against
- DV-2 Device Posture as an Access PreconditionGated-access figures feeding coverage computation
- DV-4 Execution ControlEnforcement scope feeding coverage computation
Produces
- CE-5 Remediation Backlog PrioritizationResidual risk per element, ranked into the backlog
- CE-6 Cycle Record and TrendPosture result recorded for the cycle
- CE-7 Brief Generation and DistributionCoverage and residual risk reported in the brief
Activities
- L2Compute defensive coverage from asset weighting, layer maturity and operational move mitigation.
- L2Compute residual risk from the same inputs.
- L2Report both figures for the cycle.
- L3Document the method in sufficient detail that an assessor can recompute the figure from the recorded inputs without access to the tool.
- L3State the denominator explicitly wherever the figure is published, including the choice between ground held and techniques evidenced and the reason for it.
- L3Weight mitigation by implementation state (SM-3), so planned and partial moves do not count in full.
- L3Record the framework version against every computed figure, since a change in the framework's shape changes the denominator.
- L4Recompute at least one prior cycle's figure from its recorded inputs each cycle, confirming the method is stable and the inputs were preserved.
- L4Measure the sensitivity of the figure to its most uncertain input, so the reported precision does not exceed the underlying certainty.
- L5Revise the method where sensitivity analysis shows the figure is dominated by an input the organization cannot measure well.
Measurement
Coverage and residual risk for the cycle, with denominator stated.
Percentage of prior-cycle figures reproducible from retained inputs.
Evidence and Assessment
Posture computation in the Brief; documented method with denominator; retained inputs; recomputation record.
Examine the method; test the computation by recomputing from source inputs; examine whether the framework version is recorded against each figure.
Related Guidance
- RA-3
- CA-2
- PM-9
- ID.RA-05
- GV.RM-02
Position in the Chain
Derived from the other controls’ own declarations, so the two directions cannot disagree.
Fed By
- TM-1 Terrain Inventory and Overlay
- TM-2 Defensive Layer Classification
- TM-3 Asset Weighting
- KT-4 Adversary Reachability Assessment
- SM-2 Maneuver Assignment
- SM-3 Implementation State Tracking
- SM-6 Maneuver Effectiveness Validation
- SM-7 Deception Emplacement
- FO-3 Tenancy and Inheritance Boundary
- FO-7 Obligation Profile Declaration
- DV-2 Device Posture as an Access Precondition
- DV-4 Execution Control
Where This Control Is Used
Derived, in every case, from the declaration at the other end: the forms whose techniques name this control, the artifacts whose producing and consuming controls include it, the layers whose control lists name it, and the roles its own accountability chart puts to work. Nothing here is authored on this page, so the sheet cannot claim an edge the other end does not.
Forms of Maneuver It Assesses
- M7CounterattackSeize the initiative and evict before the adversary reaches the objective.2 of 17 techniques — M7.10, M7.13
- M5AmbushTrade space for information and time, and impose cost.1 of 13 techniques — M5.10
- M10Exploitation & PursuitConvert contact into durable advantage rather than closing the ticket.1 of 7 techniques — M10.02
Terrain It Is Named On
Applies to all ten layersPerforms the coverage and residual-risk computation described below, on the cycle cadence.
Artifacts It Stands On
- producesCyber Running EstimateThe living situational picture the SOC, hunt and intelligence cell share: current posture, current assessments and their confidence, open requirements, and what has moved since the last look.
- producesCoverage and residual risk resultCoverage and residual risk computed over the whole overlay population, weighted by consequence, discounted by implementation state and corrected by validated effectiveness — with the denominator stated.
- producesBill of DefensePer mission service: the maneuvers and assets protecting it, its rolled-up coverage, and its residual risk. The view that lets a mission owner see their own defense rather than the enterprise average.
- consumesCyber Terrain OverlayThe positional map of the estate: every element with a defensive layer, a defensive weight, a named accountable owner and its adjacencies. Not an asset inventory — an inventory enumerates, an overlay positions.
- consumesAdversary reachability assessmentThe formal result: from each entry point, which decisive points are reachable over the permitted-path graph. The framework’s hardest single finding, and the headline of the brief when it changes.
- consumesScheme of maneuverOne graphic and one narrative: which forms of maneuver are sited where, in what sequence. The assignment record behind it carries the element, the avenue and the implementation state for every move.
- consumesChange recordEvery defensive action carried out, stamped twice — at the decision and at the effect. A thin, unglamorous table, and the one the headline metric is computed from.
- consumesImplementation state recordPlanned, partial or operational, per maneuver assignment. The mechanism that stops intended work being counted as deployed protection.
- consumesManeuver effectiveness validation recordWhether the moves claiming operational status produced the effect the catalog assumed — from exercise results, control testing, and observed incident performance.
- consumesHunt results, including negative resultsWhat was hunted, how, and what was not found. Negative results are the half most often discarded, and they are the half that says what has actually been cleared.
Roles It Puts to Work
- AccountableAuthorizing Official / CISOIntent, risk acceptance, and the scheme itself.
- ResponsibleGovernance / RMF / ISSOTranslating cycle outputs into FISMA and RMF artifacts, and owning the rules of engagement.
- ConsultedCyber Threat Intelligence cellFrame, Map and Fuse. The intelligence requirements, the threat courses of action, and the confidence levels.
- ConsultedPlatform and product ownersTheir own terrain. Obstacles get emplaced on their ground, so they site them.
- InformedSOC / Defensive OperationsManeuver. Executes fires and emplaces obstacles inside the standing rules of engagement.
- InformedHunt teamCounterattack. Works the hypotheses that Fuse raises.