Control Statement
Each cycle shall be recorded with its posture result, and the trend across cycles shall be reported.
Purpose. To answer whether the program is improving — a question no point-in-time assessment can address.
Discussion
A trend is only interpretable if the denominator did not change between its points, and the framework's own versioning rules make this concrete: a structural change adds or removes a form, a terrain layer or a phase, and every coverage score computed against the prior version becomes incomparable. A series that silently spans a version boundary is not a trend, it is two trends drawn as one — and it will show improvement or decline that is an artifact of the denominator rather than of the estate. Recording the framework version against each point is what makes the series honest.
Goals and Metrics
A metric that cannot come out badly is not a metric. Each of these is capable of reporting that the control is not working.
- Number of consecutive cycles with a complete record
- Direction of coverage, residual risk and temporal advantage across the last several cycles
Accountability
Exactly one role is accountable, and every other role carries at least Informed — no control in the published catalog leaves a role with zero relationship to it. That is a stated property of how these were authored, not a coincidence, and not a claim that every role's work is worth equal attention here.
| AO | CTI | SOC | HUNT | PLAT | ISSO |
|---|---|---|---|---|---|
| Authorizing Official / CISO: Accountable | Cyber Threat Intelligence cell: Consulted | SOC / Defensive Operations: Informed | Hunt team: Informed | Platform and product owners: Informed | Governance / RMF / ISSO: Responsible |
AO Authorizing Official / CISOCTI Cyber Threat Intelligence cellSOC SOC / Defensive OperationsHUNT Hunt teamPLAT Platform and product ownersISSO Governance / RMF / ISSO
- AccountableAuthorizing Official / CISO
- ConsultedCyber Threat Intelligence cell
- InformedSOC / Defensive Operations
- InformedHunt team
- InformedPlatform and product owners
- ResponsibleGovernance / RMF / ISSO
Inputs and Outputs
Consumes
- CE-4 Coverage and Residual Risk ComputationComputed posture for the cycle
- TA-1 Decision Loop MeasurementMeasured decision loop
- CE-3 Fusion and ConfidenceAnalytic conclusions and their confidence
- CE-5 Remediation Backlog PrioritizationBacklog state at cycle close
- KT-5 Barrier SufficiencyBarrier inventory tracked across cycles for silent erosion
- CE-1 Cycle CadenceCycle boundary for the record and trend
- CG-4 Findings DispositionDisposition outcomes recorded in the cycle record
- RC-5 Reconstitution ExerciseExercise results recorded across cycles
- LC-5 Supplier Severance CapabilityDemonstration results recorded across cycles
- EN-6 Engagement CommunicationCommunication record forming part of the cycle history
Produces
- CE-7 Brief Generation and DistributionTrend content for the brief
- CG-5 Control Inheritance MappingContinuous-monitoring evidence for the control baseline
- KT-5 Barrier SufficiencyBarrier inventory tracked for erosion across cycles
Activities
- L2Record each cycle's posture result.
- L2Report the change since the prior cycle.
- L2Preserve the series rather than overwriting the current position.
- L3Record the framework version against every point in the series.
- L3Break the trend line visibly at any version boundary that changed the denominator, rather than plotting across it.
- L3Preserve the inputs to each figure, not only the figure, so a point can be recomputed under CE-4.
- L3Record alongside each point the material events of that cycle — incidents, architectural changes, staffing changes — so a movement can be attributed.
- L4Distinguish movement caused by estate change from movement caused by measurement change, and report the two separately.
- L4Measure the proportion of cycle-over-cycle movement that can be attributed to a recorded cause.
- L5Use the series to test the framework's own assumptions — a weighting that never moves the aggregate is a weighting carrying no information.
Measurement
Direction and magnitude of posture movement across the current series.
Percentage of movement attributable to a recorded cause.
Evidence and Assessment
Cycle history table; movement-over-time section of the Brief; version stamps; attribution records.
Examine the series for completeness; test two entries against their source computations; examine whether any version boundary is plotted across without a break.
Related Guidance
- CA-7(3)
- AU-6
- PM-31
- ID.IM-03
- GV.OV-01
Position in the Chain
Derived from the other controls’ own declarations, so the two directions cannot disagree.
Fed By
Where This Control Is Used
Derived, in every case, from the declaration at the other end: the forms whose techniques name this control, the artifacts whose producing and consuming controls include it, the layers whose control lists name it, and the roles its own accountability chart puts to work. Nothing here is authored on this page, so the sheet cannot claim an edge the other end does not.
Forms of Maneuver It Assesses
- M7CounterattackSeize the initiative and evict before the adversary reaches the objective.2 of 17 techniques — M7.12, M7.13
- M2Defense in DepthEnsure no single failure is decisive.1 of 18 techniques — M2.14
- M8Isolation / RetrogradeGive ground deliberately to preserve the force. Degrade gracefully; never fail open.1 of 17 techniques — M8.09
- M10Exploitation & PursuitConvert contact into durable advantage rather than closing the ticket.1 of 7 techniques — M10.04
Terrain It Is Named On
- T5DataThe cycle record depends on audit data that lives on this layer, so its integrity is a precondition for the framework’s own evidence.
- TXCross-CuttingThe cycle record and trend is the evidentiary product the governance enabler exists to produce.
Artifacts It Stands On
- producesCyber Running EstimateThe living situational picture the SOC, hunt and intelligence cell share: current posture, current assessments and their confidence, open requirements, and what has moved since the last look.
- producesCycle record and trendThe closed record of the cycle — posture, loop measurement, conclusions and their confidence, backlog state at close — and the trend across cycles that makes a second cycle worth more than a first.
- consumesDefender decision loop measurementDetect to decide to contain, measured per incident from the change record’s timestamps and reported as a distribution rather than as a mean.
- consumesFused assessmentWhat the cycle’s intelligence requirements returned: each answer graded for confidence and showing its working, and each requirement left unanswered recorded against the collection gap responsible.
- consumesIndicators and signpostsFor each surviving hypothesis, the observable events that would confirm or kill it, handed to collection. The mechanism that makes this cycle’s analysis into next cycle’s requirements.
- consumesHunt results, including negative resultsWhat was hunted, how, and what was not found. Negative results are the half most often discarded, and they are the half that says what has actually been cleared.
- consumesCoverage and residual risk resultCoverage and residual risk computed over the whole overlay population, weighted by consequence, discounted by implementation state and corrected by validated effectiveness — with the denominator stated.
- consumesBill of DefensePer mission service: the maneuvers and assets protecting it, its rolled-up coverage, and its residual risk. The view that lets a mission owner see their own defense rather than the enterprise average.
- consumesTemporal advantage resultDefender decision loop against adversary dwell, reported as a ratio against the threshold set at Frame, with the result written as a word: met, or not met. The framework’s single honest scoreboard.
- consumesRemediation backlogThe ranked list of what to fix, ordered by residual risk, main-effort weighting, and decisive-point floor breaches — which sit above higher-volume, lower-weight work regardless of count.
Roles It Puts to Work
- AccountableAuthorizing Official / CISOIntent, risk acceptance, and the scheme itself.
- ResponsibleGovernance / RMF / ISSOTranslating cycle outputs into FISMA and RMF artifacts, and owning the rules of engagement.
- ConsultedCyber Threat Intelligence cellFrame, Map and Fuse. The intelligence requirements, the threat courses of action, and the confidence levels.
- InformedSOC / Defensive OperationsManeuver. Executes fires and emplaces obstacles inside the standing rules of engagement.
- InformedHunt teamCounterattack. Works the hypotheses that Fuse raises.
- InformedPlatform and product ownersTheir own terrain. Obstacles get emplaced on their ground, so they site them.