ASOM-Fedv6.1Open the explorer
CE-4 · Cycle Execution and Assurance

Coverage and Residual Risk Computation

Control Statement

Defensive coverage and residual risk shall be computed from asset weighting, layer maturity, and operational move mitigation, using a documented method.

Purpose. To produce a posture figure that can be reproduced and challenged rather than asserted, so that the number carries authority beyond the tool that generated it.

Discussion

The denominator determines the answer, and the choice of denominator is a judgment that must be published rather than embedded. Counting techniques evidenced rewards tagging a crowded intersection over a sparse one for identical effort; counting ground held — terrain × form cells occupied — does not, which is why the framework scores that way. But the reasoning is only defensible if it is stated where the figure appears. A coverage percentage whose denominator is undisclosed is not a measurement, and an adopter who cannot reproduce it cannot argue with it.

Goals and Metrics

A metric that cannot come out badly is not a metric. Each of these is capable of reporting that the control is not working.

Coverage and residual risk are computed, not estimated.
  • Whether the computation method is documented and version-controlled
  • Difference between computed coverage and any separately reported figure
The computation reflects implementation reality.
  • Proportion of mitigation credit derived from moves in an operational state

Accountability

Exactly one role is accountable, and every other role carries at least Informed — no control in the published catalog leaves a role with zero relationship to it. That is a stated property of how these were authored, not a coincidence, and not a claim that every role's work is worth equal attention here.

AOCTISOCHUNTPLATISSO
Authorizing Official / CISO: AccountableCyber Threat Intelligence cell: ConsultedSOC / Defensive Operations: InformedHunt team: InformedPlatform and product owners: ConsultedGovernance / RMF / ISSO: Responsible

AO Authorizing Official / CISOCTI Cyber Threat Intelligence cellSOC SOC / Defensive OperationsHUNT Hunt teamPLAT Platform and product ownersISSO Governance / RMF / ISSO

  • AccountableAuthorizing Official / CISO
  • ConsultedCyber Threat Intelligence cell
  • InformedSOC / Defensive Operations
  • InformedHunt team
  • ConsultedPlatform and product owners
  • ResponsibleGovernance / RMF / ISSO

Inputs and Outputs

Consumes

Produces

Activities

  1. L2Compute defensive coverage from asset weighting, layer maturity and operational move mitigation.
  2. L2Compute residual risk from the same inputs.
  3. L2Report both figures for the cycle.
  4. L3Document the method in sufficient detail that an assessor can recompute the figure from the recorded inputs without access to the tool.
  5. L3State the denominator explicitly wherever the figure is published, including the choice between ground held and techniques evidenced and the reason for it.
  6. L3Weight mitigation by implementation state (SM-3), so planned and partial moves do not count in full.
  7. L3Record the framework version against every computed figure, since a change in the framework's shape changes the denominator.
  8. L4Recompute at least one prior cycle's figure from its recorded inputs each cycle, confirming the method is stable and the inputs were preserved.
  9. L4Measure the sensitivity of the figure to its most uncertain input, so the reported precision does not exceed the underlying certainty.
  10. L5Revise the method where sensitivity analysis shows the figure is dominated by an input the organization cannot measure well.

Measurement

Outcome

Coverage and residual risk for the cycle, with denominator stated.

Performance

Percentage of prior-cycle figures reproducible from retained inputs.

Evidence and Assessment

Evidence expected

Posture computation in the Brief; documented method with denominator; retained inputs; recomputation record.

Assessment procedure

Examine the method; test the computation by recomputing from source inputs; examine whether the framework version is recorded against each figure.

Related Guidance

Inherits
  • RA-3
  • CA-2
  • PM-9
Satisfies
  • ID.RA-05
  • GV.RM-02

Position in the Chain

Derived from the other controls’ own declarations, so the two directions cannot disagree.

Where This Control Is Used

Derived, in every case, from the declaration at the other end: the forms whose techniques name this control, the artifacts whose producing and consuming controls include it, the layers whose control lists name it, and the roles its own accountability chart puts to work. Nothing here is authored on this page, so the sheet cannot claim an edge the other end does not.

Forms of Maneuver It Assesses

  • M7CounterattackSeize the initiative and evict before the adversary reaches the objective.2 of 17 techniques — M7.10, M7.13
  • M5AmbushTrade space for information and time, and impose cost.1 of 13 techniques — M5.10
  • M10Exploitation & PursuitConvert contact into durable advantage rather than closing the ticket.1 of 7 techniques — M10.02

Terrain It Is Named On

Applies to all ten layersPerforms the coverage and residual-risk computation described below, on the cycle cadence.

Artifacts It Stands On

  • producesCyber Running EstimateThe living situational picture the SOC, hunt and intelligence cell share: current posture, current assessments and their confidence, open requirements, and what has moved since the last look.
  • producesCoverage and residual risk resultCoverage and residual risk computed over the whole overlay population, weighted by consequence, discounted by implementation state and corrected by validated effectiveness — with the denominator stated.
  • producesBill of DefensePer mission service: the maneuvers and assets protecting it, its rolled-up coverage, and its residual risk. The view that lets a mission owner see their own defense rather than the enterprise average.
  • consumesCyber Terrain OverlayThe positional map of the estate: every element with a defensive layer, a defensive weight, a named accountable owner and its adjacencies. Not an asset inventory — an inventory enumerates, an overlay positions.
  • consumesAdversary reachability assessmentThe formal result: from each entry point, which decisive points are reachable over the permitted-path graph. The framework’s hardest single finding, and the headline of the brief when it changes.
  • consumesScheme of maneuverOne graphic and one narrative: which forms of maneuver are sited where, in what sequence. The assignment record behind it carries the element, the avenue and the implementation state for every move.
  • consumesChange recordEvery defensive action carried out, stamped twice — at the decision and at the effect. A thin, unglamorous table, and the one the headline metric is computed from.
  • consumesImplementation state recordPlanned, partial or operational, per maneuver assignment. The mechanism that stops intended work being counted as deployed protection.
  • consumesManeuver effectiveness validation recordWhether the moves claiming operational status produced the effect the catalog assumed — from exercise results, control testing, and observed incident performance.
  • consumesHunt results, including negative resultsWhat was hunted, how, and what was not found. Negative results are the half most often discarded, and they are the half that says what has actually been cleared.

Roles It Puts to Work