ASOM-Fedv6.1Open the explorer
CG · 5 controls

Command and Governance

Intent, phase, rules of engagement, findings disposition, inheritance

CG-1
Defensive IntentAccountable: Authorizing Official / CISO

The accountable authority shall issue a defensive intent stating the end-state to be protected and the risk that is acceptable, expressed in plain language.

PurposeTo give subordinate decisions a reference point, so that people can act correctly without referring upward.Activities10 · Metrics2
CG-2
Phase DeclarationAccountable: Authorizing Official / CISO

The organization shall declare its current campaign phase, and shall align main effort and resourcing to it.

PurposeTo make "we are in Phase III" a sentence that changes behavior, rather than a label applied to a state of affairs.Activities10 · Metrics2
CG-3
Rules of EngagementAccountable: Authorizing Official / CISO

The organization shall maintain approved rules of engagement defining which defensive actions may be executed at which authority level.

PurposeTo let operators act inside a known mandate rather than guessing at one, and to make the boundaries of that mandate legally and operationally sound.Activities10 · Metrics2
CG-4
Findings DispositionAccountable: Authorizing Official / CISO

Findings raised by architectural review shall be dispositioned as remediated, accepted with justification, or transferred, within a defined period.

PurposeTo ensure every finding reaches a decision, so that the open set reflects work in progress rather than accumulated neglect.Activities10 · Metrics3
CG-5
Control Inheritance MappingAccountable: Authorizing Official / CISO

The organization shall maintain the mapping between these controls and its existing control baseline, and shall assess inherited controls once rather than twice.

PurposeTo keep the framework additive, so that adopting it adds assessment effort only where it adds assessable content.Activities10 · Metrics2