ASOM-Fedv6.1Open the explorer
CG-1 · Command and Governance

Defensive Intent

Control Statement

The accountable authority shall issue a defensive intent stating the end-state to be protected and the risk that is acceptable, expressed in plain language.

Purpose. To give subordinate decisions a reference point, so that people can act correctly without referring upward.

Discussion

The test of an intent is operational, not literary: can someone two levels down, at three in the morning, make a decision from it without calling? Most published intents fail that test because they state aspiration rather than acceptable risk. "Protect mission-transaction integrity and sensitive records; degrade gracefully, never fail open" tells an operator what to trade when they must trade something. A statement that lists everything as important tells them nothing, and they will escalate — which is the decide-segment latency TA-1 measures.

Goals and Metrics

A metric that cannot come out badly is not a metric. Each of these is capable of reporting that the control is not working.

A current, plain-language intent exists and is known.
  • Age of the defensive intent and date of last reaffirmation
  • Proportion of defensive staff who can state the intent without reference to the document

Accountability

Exactly one role is accountable, and every other role carries at least Informed — no control in the published catalog leaves a role with zero relationship to it. That is a stated property of how these were authored, not a coincidence, and not a claim that every role's work is worth equal attention here.

AOCTISOCHUNTPLATISSO
Authorizing Official / CISO: AccountableCyber Threat Intelligence cell: ConsultedSOC / Defensive Operations: InformedHunt team: InformedPlatform and product owners: InformedGovernance / RMF / ISSO: Consulted

AO Authorizing Official / CISOCTI Cyber Threat Intelligence cellSOC SOC / Defensive OperationsHUNT Hunt teamPLAT Platform and product ownersISSO Governance / RMF / ISSO

  • AccountableAuthorizing Official / CISO
  • ConsultedCyber Threat Intelligence cell
  • InformedSOC / Defensive Operations
  • InformedHunt team
  • InformedPlatform and product owners
  • ConsultedGovernance / RMF / ISSO

Inputs and Outputs

Consumes

Produces

Activities

  1. L2Issue a defensive intent stating the end-state to be protected.
  2. L2State the risk that is acceptable in pursuit of it.
  3. L2Publish the intent where those executing it can reach it.
  4. L3Express the intent in plain language, without technology or product terms, so it survives re-tooling and is legible to mission staff.
  5. L3State explicitly what may be traded and in what order, since an intent that subordinates nothing cannot resolve a conflict.
  6. L3Obtain the accountable authority's signature and record the date.
  7. L3Head every generated Brief with the current intent, so posture is always read against purpose.
  8. L4Test comprehension by interviewing operators on a decision the intent should resolve, and measure whether they resolve it consistently.
  9. L4Review the intent on material change to mission or threat, and record the review even where no change results.
  10. L5Revise the intent where recorded escalations show a recurring decision the intent does not resolve.

Measurement

Outcome

Consistency of operator decisions on a test case the intent should resolve.

Performance

Currency of the intent in cycles since last review.

Evidence and Assessment

Evidence expected

Signed intent statement with date; publication record; comprehension test results.

Assessment procedure

Examine the statement and its approval; interview operators on whether they can act on it unaided; test comprehension against a decision the intent should resolve.

Related Guidance

Inherits
  • PM-1
  • PL-1
  • PM-29
Satisfies
  • GV.OC-01
  • GV.PO-01

Position in the Chain

Derived from the other controls’ own declarations, so the two directions cannot disagree.

Where This Control Is Used

Derived, in every case, from the declaration at the other end: the forms whose techniques name this control, the artifacts whose producing and consuming controls include it, the layers whose control lists name it, and the roles its own accountability chart puts to work. Nothing here is authored on this page, so the sheet cannot claim an edge the other end does not.

Forms of Maneuver It Assesses

  • M8Isolation / RetrogradeGive ground deliberately to preserve the force. Degrade gracefully; never fail open.1 of 17 techniques — M8.08

Terrain It Is Named On

  • TXCross-CuttingDefensive intent — the single artifact from which every scheme of maneuver is derived.

Artifacts It Stands On

  • producesDefensive intent paragraphOne signed paragraph stating what the defense exists to protect, what may be degraded to protect it, and the acceptable risk. The commander’s-intent analog, and the citation every downstream designation rests on.
  • consumesCycle briefThe published product: terrain, reachability, main effort, temporal advantage, coverage, trend, and the top-ranked backlog items — each confidence-tagged. Also the evidence that feeds the next intent.

Roles It Puts to Work