Control Statement
The organization shall maintain approved rules of engagement defining which defensive actions may be executed at which authority level.
Purpose. To let operators act inside a known mandate rather than guessing at one, and to make the boundaries of that mandate legally and operationally sound.
Discussion
Rules of engagement carry a constraint the rest of the framework does not: some defensive actions have statutory consequences. Degrading a public service where a statute sets a deadline, or acting on a system holding regulated records, is not purely a security decision. The ROE is where those limits are recorded, and it is also where the framework's boundary sits — nothing in ASOM-Fed contemplates action outside the agency's own terrain, and the ROE should say so explicitly rather than leaving it to inference from doctrine.
Goals and Metrics
A metric that cannot come out badly is not a metric. Each of these is capable of reporting that the control is not working.
- Date of last approval by the accountable authority
- Number of actions executed outside the recorded authority level
Accountability
Exactly one role is accountable, and every other role carries at least Informed — no control in the published catalog leaves a role with zero relationship to it. That is a stated property of how these were authored, not a coincidence, and not a claim that every role's work is worth equal attention here.
| AO | CTI | SOC | HUNT | PLAT | ISSO |
|---|---|---|---|---|---|
| Authorizing Official / CISO: Accountable | Cyber Threat Intelligence cell: Informed | SOC / Defensive Operations: Consulted | Hunt team: Informed | Platform and product owners: Consulted | Governance / RMF / ISSO: Responsible |
AO Authorizing Official / CISOCTI Cyber Threat Intelligence cellSOC SOC / Defensive OperationsHUNT Hunt teamPLAT Platform and product ownersISSO Governance / RMF / ISSO
- AccountableAuthorizing Official / CISO
- InformedCyber Threat Intelligence cell
- ConsultedSOC / Defensive Operations
- InformedHunt team
- ConsultedPlatform and product owners
- ResponsibleGovernance / RMF / ISSO
Inputs and Outputs
Consumes
- TA-4 Pre-authorized ResponseThe approved pre-authorization set
- SM-5 Branches and SequelsBranch actions requiring an authority level
- FO-5 Statutory Availability FloorStatutory availability constraints bounding what may be degraded
- CG-2 Phase DeclarationPhase-dependent authority levels
- WF-4 Insider Risk PositionAuthority levels for actions affecting an individual
Produces
- TA-4 Pre-authorized ResponseAuthority framework within which pre-authorization sits
- CE-7 Brief Generation and DistributionAuthority exceptions reported in the brief
- EN-4 Escalation and Engagement AuthorityRules of engagement defining the limits of authority
Activities
- L2Define which defensive actions may be executed at which authority level.
- L2Obtain approval from the accountable authority.
- L2Link the rules to the maneuvers and pre-authorized actions they govern.
- L3Record the statutory and regulatory constraints bounding specific actions, referencing the availability floors under FO-5 where they apply.
- L3State explicitly that no action extends outside the agency's own boundary, so the limit is written rather than inferred.
- L3Ensure the authority named for each escalation level is reachable at any hour, and record the path.
- L3Review the rules on phase transition, on legal change, and at cadence.
- L4Measure adherence during recorded incidents — actions taken outside authority, and actions not taken because authority could not be reached.
- L4Test reachability of each named authority out of hours rather than assuming it.
- L5Revise authority levels where measured adherence shows the rules are routinely worked around rather than followed.
Measurement
Percentage of recorded incident actions taken within written authority.
Percentage of named authorities verified reachable out of hours.
Evidence and Assessment
Approved rules of engagement with legal bounds; reachability test records; incident action logs referencing authority.
Examine approval and currency; test adherence in a recorded incident; test whether a named out-of-hours authority is in fact reachable.
Related Guidance
- IR-4
- AC-2
- PM-1
- GV.RR-01
- RS.MA-01
Position in the Chain
Derived from the other controls’ own declarations, so the two directions cannot disagree.
Where This Control Is Used
Derived, in every case, from the declaration at the other end: the forms whose techniques name this control, the artifacts whose producing and consuming controls include it, the layers whose control lists name it, and the roles its own accountability chart puts to work. Nothing here is authored on this page, so the sheet cannot claim an edge the other end does not.
Forms of Maneuver It Assesses
- M8Isolation / RetrogradeGive ground deliberately to preserve the force. Degrade gracefully; never fail open.2 of 17 techniques — M8.04, M8.08
- M3EnvelopmentMake identity, not network location, the decisive plane — surround the adversary with policy.1 of 20 techniques — M3.15
- M4Obstacle / CanalizationForce the adversary onto ground you own and watch.1 of 17 techniques — M4.10
- M6DelayBuy decision time and prevent the adversary culminating on the objective.1 of 10 techniques — M6.05
- M10Exploitation & PursuitConvert contact into durable advantage rather than closing the ticket.1 of 7 techniques — M10.06
Terrain It Is Named On
- T6Operational TechnologyRules of engagement must state which responses are forbidden on OT. This is the only layer where the ROE’s prohibitions matter more than its authorizations.
- T7WorkforceMonitoring one’s own workforce requires an explicit authority and explicit limits; the rules of engagement are where both are written.
- TXCross-CuttingRules of engagement: the decisive point on this layer, stated as a control.
Artifacts It Stands On
- producesRules of engagementWhich defensive actions may be taken by whom without escalation, which need the Authorizing Official, and what is prohibited outright. The cyber analog of engagement authority, and the single largest determinant of tempo.
- producesChange recordEvery defensive action carried out, stamped twice — at the decision and at the effect. A thin, unglamorous table, and the one the headline metric is computed from.
- producesAuthority exception logActions taken outside the standing rules of engagement, with who approved them and why. Exceptions are not failures; unrecorded exceptions are.
- consumesThreat course-of-action sketchTwo courses of action, most likely and most dangerous, drawn against the decisive points already designated. Each is a route across ground the estate really has, not a category of threat.
- consumesBranch and sequel planThe branches answer the most-dangerous course of action; the sequels answer success. Every one names the authority it needs, and any expected to run inside the decision window is pre-authorized when it is written.
- consumesPre-authorized response setThe specific containment and response actions the SOC may execute at machine speed, bounded by the statutory availability floor. Directly measurable: it shortens the decision segment of the defender loop.
- consumesStatutory availability floorThe mission services whose availability is set by statute or regulation, and the floor below which degradation stops being a defensive choice. Bounds what may be pre-authorized and what may be degraded under contact.
Roles It Puts to Work
- AccountableAuthorizing Official / CISOIntent, risk acceptance, and the scheme itself.
- ResponsibleGovernance / RMF / ISSOTranslating cycle outputs into FISMA and RMF artifacts, and owning the rules of engagement.
- ConsultedSOC / Defensive OperationsManeuver. Executes fires and emplaces obstacles inside the standing rules of engagement.
- ConsultedPlatform and product ownersTheir own terrain. Obstacles get emplaced on their ground, so they site them.
- InformedCyber Threat Intelligence cellFrame, Map and Fuse. The intelligence requirements, the threat courses of action, and the confidence levels.
- InformedHunt teamCounterattack. Works the hypotheses that Fuse raises.