Control Statement
The accountable authority shall issue a defensive intent stating the end-state to be protected and the risk that is acceptable, expressed in plain language.
Purpose. To give subordinate decisions a reference point, so that people can act correctly without referring upward.
Discussion
The test of an intent is operational, not literary: can someone two levels down, at three in the morning, make a decision from it without calling? Most published intents fail that test because they state aspiration rather than acceptable risk. "Protect mission-transaction integrity and sensitive records; degrade gracefully, never fail open" tells an operator what to trade when they must trade something. A statement that lists everything as important tells them nothing, and they will escalate — which is the decide-segment latency TA-1 measures.
Goals and Metrics
A metric that cannot come out badly is not a metric. Each of these is capable of reporting that the control is not working.
- Age of the defensive intent and date of last reaffirmation
- Proportion of defensive staff who can state the intent without reference to the document
Accountability
Exactly one role is accountable, and every other role carries at least Informed — no control in the published catalog leaves a role with zero relationship to it. That is a stated property of how these were authored, not a coincidence, and not a claim that every role's work is worth equal attention here.
| AO | CTI | SOC | HUNT | PLAT | ISSO |
|---|---|---|---|---|---|
| Authorizing Official / CISO: Accountable | Cyber Threat Intelligence cell: Consulted | SOC / Defensive Operations: Informed | Hunt team: Informed | Platform and product owners: Informed | Governance / RMF / ISSO: Consulted |
AO Authorizing Official / CISOCTI Cyber Threat Intelligence cellSOC SOC / Defensive OperationsHUNT Hunt teamPLAT Platform and product ownersISSO Governance / RMF / ISSO
- AccountableAuthorizing Official / CISO
- ConsultedCyber Threat Intelligence cell
- InformedSOC / Defensive Operations
- InformedHunt team
- InformedPlatform and product owners
- ConsultedGovernance / RMF / ISSO
Inputs and Outputs
Consumes
- Outside the frameworkMission, statutory obligations and organizational risk appetite
- CE-7 Brief Generation and DistributionPrior cycle evidence informing revision
Produces
- KT-1 Decisive Point IdentificationBasis for decisive-point designation
- SM-4 Main Effort DesignationBasis for main-effort designation
- CE-2 Priority Intelligence RequirementsDirection for intelligence requirements
- TA-3 Temporal Advantage ThresholdAcceptable risk informing the temporal advantage threshold
- SM-1 Maneuver Catalog AdoptionDefensive intent constraining which forms are relevant
- CE-1 Cycle CadenceDefensive intent establishing why the cycle exists
- CG-2 Phase DeclarationDefensive intent
Activities
- L2Issue a defensive intent stating the end-state to be protected.
- L2State the risk that is acceptable in pursuit of it.
- L2Publish the intent where those executing it can reach it.
- L3Express the intent in plain language, without technology or product terms, so it survives re-tooling and is legible to mission staff.
- L3State explicitly what may be traded and in what order, since an intent that subordinates nothing cannot resolve a conflict.
- L3Obtain the accountable authority's signature and record the date.
- L3Head every generated Brief with the current intent, so posture is always read against purpose.
- L4Test comprehension by interviewing operators on a decision the intent should resolve, and measure whether they resolve it consistently.
- L4Review the intent on material change to mission or threat, and record the review even where no change results.
- L5Revise the intent where recorded escalations show a recurring decision the intent does not resolve.
Measurement
Consistency of operator decisions on a test case the intent should resolve.
Currency of the intent in cycles since last review.
Evidence and Assessment
Signed intent statement with date; publication record; comprehension test results.
Examine the statement and its approval; interview operators on whether they can act on it unaided; test comprehension against a decision the intent should resolve.
Related Guidance
- PM-1
- PL-1
- PM-29
- GV.OC-01
- GV.PO-01
Position in the Chain
Derived from the other controls’ own declarations, so the two directions cannot disagree.
Where This Control Is Used
Derived, in every case, from the declaration at the other end: the forms whose techniques name this control, the artifacts whose producing and consuming controls include it, the layers whose control lists name it, and the roles its own accountability chart puts to work. Nothing here is authored on this page, so the sheet cannot claim an edge the other end does not.
Forms of Maneuver It Assesses
- M8Isolation / RetrogradeGive ground deliberately to preserve the force. Degrade gracefully; never fail open.1 of 17 techniques — M8.08
Terrain It Is Named On
- TXCross-CuttingDefensive intent — the single artifact from which every scheme of maneuver is derived.
Artifacts It Stands On
- producesDefensive intent paragraphOne signed paragraph stating what the defense exists to protect, what may be degraded to protect it, and the acceptable risk. The commander’s-intent analog, and the citation every downstream designation rests on.
- consumesCycle briefThe published product: terrain, reachability, main effort, temporal advantage, coverage, trend, and the top-ranked backlog items — each confidence-tagged. Also the evidence that feeds the next intent.
Roles It Puts to Work
- AccountableAuthorizing Official / CISOIntent, risk acceptance, and the scheme itself.
- ConsultedCyber Threat Intelligence cellFrame, Map and Fuse. The intelligence requirements, the threat courses of action, and the confidence levels.
- ConsultedGovernance / RMF / ISSOTranslating cycle outputs into FISMA and RMF artifacts, and owning the rules of engagement.
- InformedSOC / Defensive OperationsManeuver. Executes fires and emplaces obstacles inside the standing rules of engagement.
- InformedHunt teamCounterattack. Works the hypotheses that Fuse raises.
- InformedPlatform and product ownersTheir own terrain. Obstacles get emplaced on their ground, so they site them.