Control Statement
Identified gaps shall be ranked by the residual risk they retire per unit of effort, and shall be assigned owners and target dates.
Purpose. To make the backlog answer where the next hour of work goes, rather than enumerate everything wrong.
Discussion
Ranking by risk alone produces a backlog headed by items nobody can afford; ranking by effort alone produces a quarter of completed busywork with the risk position unchanged. The ratio is the whole point, and it is also the part most often dropped in implementation, because effort estimates are uncomfortable to produce and easy to omit. A backlog with risk scores and no effort estimates has not implemented this control.
Goals and Metrics
A metric that cannot come out badly is not a metric. Each of these is capable of reporting that the control is not working.
- Percentage of backlog items with a named owner and a target date
- Residual risk retired per cycle
- Correlation between item rank and the order in which items were actually completed
Accountability
Exactly one role is accountable, and every other role carries at least Informed — no control in the published catalog leaves a role with zero relationship to it. That is a stated property of how these were authored, not a coincidence, and not a claim that every role's work is worth equal attention here.
| AO | CTI | SOC | HUNT | PLAT | ISSO |
|---|---|---|---|---|---|
| Authorizing Official / CISO: Accountable | Cyber Threat Intelligence cell: Informed | SOC / Defensive Operations: Consulted | Hunt team: Informed | Platform and product owners: Consulted | Governance / RMF / ISSO: Responsible |
AO Authorizing Official / CISOCTI Cyber Threat Intelligence cellSOC SOC / Defensive OperationsHUNT Hunt teamPLAT Platform and product ownersISSO Governance / RMF / ISSO
- AccountableAuthorizing Official / CISO
- InformedCyber Threat Intelligence cell
- ConsultedSOC / Defensive Operations
- InformedHunt team
- ConsultedPlatform and product owners
- ResponsibleGovernance / RMF / ISSO
Inputs and Outputs
Consumes
- CE-4 Coverage and Residual Risk ComputationResidual risk per element
- KT-2 Decisive Point Protection FloorDecisive-point floor breaches, ranked ahead of lower-weighted work
- SM-3 Implementation State TrackingPlanned and partial assignments
- SM-4 Main Effort DesignationMain effort weighting
- TM-3 Asset WeightingWeight component of the ranked remediation backlog
- SM-6 Maneuver Effectiveness ValidationMoves that failed validation, entering the backlog
- TA-3 Temporal Advantage ThresholdTempo-driven items entering the remediation backlog
- RC-3 Trusted Rebuild PathUntested or over-budget paths entering the backlog
- RC-5 Reconstitution ExerciseObjectives missed in exercise, entering the backlog
- WF-2 Privileged Human RegisterUnresolved accounts entering the backlog
- WF-3 Role-Based ReadinessReadiness shortfalls entering the backlog
- WF-5 Separation and Revocation TempoSystems outside single-action revocation entering the backlog
- FC-3 Maintenance Access ControlStanding maintenance paths entering the backlog
- FC-4 Environmental ContinuityFacilities whose endurance is shorter than the objectives they must support
- LC-2 Component ProvenanceComponents with unverifiable origin entering the backlog
- LC-4 Update Integrity and StagingUnverifiable or unstaged update paths entering the backlog
- LC-5 Supplier Severance CapabilitySuppliers that cannot be severed within the period entering the backlog
Produces
- CG-4 Findings DispositionItems requiring formal disposition
- CE-6 Cycle Record and TrendBacklog movement recorded across cycles
- CE-7 Brief Generation and DistributionTop-ranked items reported in the brief
Activities
- L2Record identified gaps as a backlog.
- L2Estimate the residual risk each gap retires if closed.
- L2Assign an owner and a target date to each item.
- L3Estimate the effort each item requires, on a defined scale, so the ratio can be computed rather than intuited.
- L3Rank by risk retired per unit of effort and publish the ranking basis.
- L3Reconcile ownership against terrain ownership (TM-7), so backlog items land on people who already hold the ground.
- L3Re-rank each cycle from current figures rather than preserving a stale order.
- L4Measure realized risk retirement against estimate for completed items, and correct the estimation method where it is systematically optimistic.
- L4Trend backlog age by rank band; high-ranked items ageing indicates the ranking is not driving allocation.
- L5Feed completion data back into effort estimation, so the ratio improves in accuracy as the program accumulates history.
Measurement
Residual risk retired per cycle.
Median age of items in the top rank band.
Evidence and Assessment
Ranked backlog with owners, target dates, effort estimates and ranking basis.
Examine the ranking basis; test progress against target dates; examine whether effort estimates exist at all for the top-ranked items.
Related Guidance
- CA-5
- RA-7
- PM-4
- ID.RA-06
- ID.IM-02
- GV.RM-06
Position in the Chain
Derived from the other controls’ own declarations, so the two directions cannot disagree.
Fed By
- TM-3 Asset Weighting
- KT-2 Decisive Point Protection Floor
- SM-3 Implementation State Tracking
- SM-4 Main Effort Designation
- SM-6 Maneuver Effectiveness Validation
- TA-3 Temporal Advantage Threshold
- CE-4 Coverage and Residual Risk Computation
- RC-3 Trusted Rebuild Path
- RC-5 Reconstitution Exercise
- WF-2 Privileged Human Register
- WF-3 Role-Based Readiness
- WF-5 Separation and Revocation Tempo
- FC-3 Maintenance Access Control
- FC-4 Environmental Continuity
- LC-2 Component Provenance
- LC-4 Update Integrity and Staging
- LC-5 Supplier Severance Capability
Where This Control Is Used
Derived, in every case, from the declaration at the other end: the forms whose techniques name this control, the artifacts whose producing and consuming controls include it, the layers whose control lists name it, and the roles its own accountability chart puts to work. Nothing here is authored on this page, so the sheet cannot claim an edge the other end does not.
Forms of Maneuver It Assesses
- M7CounterattackSeize the initiative and evict before the adversary reaches the objective.2 of 17 techniques — M7.02, M7.09
- M9Spoiling AttackDisrupt adversary staging before the attack is launched.2 of 9 techniques — M9.02, M9.07
- M10Exploitation & PursuitConvert contact into durable advantage rather than closing the ticket.1 of 7 techniques — M10.01
Terrain It Is Named On
Applies to all ten layersTurns weight multiplied by coverage gap into a ranked backlog, which is what the layer’s numbers are for.
Artifacts It Stands On
- producesRemediation backlogThe ranked list of what to fix, ordered by residual risk, main-effort weighting, and decisive-point floor breaches — which sit above higher-volume, lower-weight work regardless of count.
- consumesDecisive point registerThe elements whose control confers decisive advantage — each carrying the evidence that raised it above merely important, and the protection floor it owes as a result.
- consumesScheme of maneuverOne graphic and one narrative: which forms of maneuver are sited where, in what sequence. The assignment record behind it carries the element, the avenue and the implementation state for every move.
- consumesMain effort designationThe single designated main effort for the cycle, and the sentence citing the decisive point that justifies it. The answer to which work wins when two things need the same engineer.
- consumesChange recordEvery defensive action carried out, stamped twice — at the decision and at the effect. A thin, unglamorous table, and the one the headline metric is computed from.
- consumesImplementation state recordPlanned, partial or operational, per maneuver assignment. The mechanism that stops intended work being counted as deployed protection.
- consumesCyber Running EstimateThe living situational picture the SOC, hunt and intelligence cell share: current posture, current assessments and their confidence, open requirements, and what has moved since the last look.
- consumesCoverage and residual risk resultCoverage and residual risk computed over the whole overlay population, weighted by consequence, discounted by implementation state and corrected by validated effectiveness — with the denominator stated.
- consumesBill of DefensePer mission service: the maneuvers and assets protecting it, its rolled-up coverage, and its residual risk. The view that lets a mission owner see their own defense rather than the enterprise average.
Roles It Puts to Work
- AccountableAuthorizing Official / CISOIntent, risk acceptance, and the scheme itself.
- ResponsibleGovernance / RMF / ISSOTranslating cycle outputs into FISMA and RMF artifacts, and owning the rules of engagement.
- ConsultedSOC / Defensive OperationsManeuver. Executes fires and emplaces obstacles inside the standing rules of engagement.
- ConsultedPlatform and product ownersTheir own terrain. Obstacles get emplaced on their ground, so they site them.
- InformedCyber Threat Intelligence cellFrame, Map and Fuse. The intelligence requirements, the threat courses of action, and the confidence levels.
- InformedHunt teamCounterattack. Works the hypotheses that Fuse raises.