Control Statement
The organization shall maintain the mapping between these controls and its existing control baseline, and shall assess inherited controls once rather than twice.
Purpose. To keep the framework additive, so that adopting it adds assessment effort only where it adds assessable content.
Discussion
This is the control adoption depends on. A framework layered onto SP 800-53 that re-assesses what 800-53 already covers doubles the assessment burden and will be declined regardless of merit — and the decline will be correct. The mapping has to be maintained rather than published once: control baselines are tailored, overlays change, and an inheritance claim citing an assessment that no longer covers the requirement is worse than no claim, because it retires a requirement that nothing is actually testing. FO-3 applies the same discipline at a different scope: CG-5 verifies inheritance from a control baseline, FO-3 verifies it from a service provider, and a requirement can fall between the two if neither is checked.
Goals and Metrics
A metric that cannot come out badly is not a metric. Each of these is capable of reporting that the control is not working.
- Percentage of controls with a recorded mapping to the existing baseline
- Number of controls assessed twice under both frameworks in the period
Accountability
Exactly one role is accountable, and every other role carries at least Informed — no control in the published catalog leaves a role with zero relationship to it. That is a stated property of how these were authored, not a coincidence, and not a claim that every role's work is worth equal attention here.
| AO | CTI | SOC | HUNT | PLAT | ISSO |
|---|---|---|---|---|---|
| Authorizing Official / CISO: Accountable | Cyber Threat Intelligence cell: Consulted | SOC / Defensive Operations: Informed | Hunt team: Informed | Platform and product owners: Consulted | Governance / RMF / ISSO: Responsible |
AO Authorizing Official / CISOCTI Cyber Threat Intelligence cellSOC SOC / Defensive OperationsHUNT Hunt teamPLAT Platform and product ownersISSO Governance / RMF / ISSO
- AccountableAuthorizing Official / CISO
- ConsultedCyber Threat Intelligence cell
- InformedSOC / Defensive Operations
- InformedHunt team
- ConsultedPlatform and product owners
- ResponsibleGovernance / RMF / ISSO
Inputs and Outputs
Consumes
- Outside the frameworkThe organization’s existing control baseline and assessment results
- CE-6 Cycle Record and TrendCycle records serving as continuous-monitoring evidence
- CG-4 Findings DispositionAccepted risks to be reflected in the baseline
- FO-1 Privacy Terrain IdentificationPrivacy control inheritance mapping
- FO-2 Controlled Unclassified Information HandlingControlled-information control inheritance
- FO-3 Tenancy and Inheritance BoundaryInheritance feeding the control baseline mapping
- FO-7 Obligation Profile DeclarationObligation scope the inheritance mapping is verified within
Produces
- Outside the frameworkAssessment and authorization evidence for the existing baseline
- CE-7 Brief Generation and DistributionInheritance status reported to the accountable authority
Activities
- L2Maintain the mapping between ASOM-Fed controls and the existing baseline.
- L2Declare for each control whether it is inherited, extended, or net new.
- L2Cite existing assessment results as evidence where inheritance applies.
- L3Verify that each cited assessment actually covers the requirement claimed, rather than covering the control family it belongs to.
- L3Assess only the delta for extended controls, and state what that delta is.
- L3Re-verify inheritance claims when the baseline is tailored, an overlay is applied, or a cited assessment expires.
- L3Record where an inheritance claim fails verification, since that requirement is then unassessed by anything.
- L4Measure the assessment effort attributable to ASOM-Fed over and above the existing baseline, which is the framework's true marginal cost.
- L4Measure the proportion of inheritance claims that survive verification, since a low rate means the mapping is aspirational.
- L5Feed verification failures back to the framework steward, since a claim that fails at multiple agencies is a defect in the published crosswalk rather than in the adopter.
Measurement
Percentage of inheritance claims verified against a current assessment result.
Assessment effort attributable to ASOM-Fed beyond the baseline.
Evidence and Assessment
Maintained crosswalk with inheritance decisions and verification status; cited assessment results; unassessed-requirement findings.
Examine the crosswalk; test two inherited controls to confirm the cited assessment covers the requirement; examine whether any claim has ever failed verification.
Related Guidance
- PM-10
- CA-2
- SA-4
- GV.SC-07
- GV.OV-02
Position in the Chain
Derived from the other controls’ own declarations, so the two directions cannot disagree.
Fed By
Feeds
Nothing downstream — this control terminates a chain.
Where This Control Is Used
Derived, in every case, from the declaration at the other end: the forms whose techniques name this control, the artifacts whose producing and consuming controls include it, the layers whose control lists name it, and the roles its own accountability chart puts to work. Nothing here is authored on this page, so the sheet cannot claim an edge the other end does not.
Forms of Maneuver It Assesses
- M9Spoiling AttackDisrupt adversary staging before the attack is launched.2 of 9 techniques — M9.04, M9.06
- M10Exploitation & PursuitConvert contact into durable advantage rather than closing the ticket.2 of 7 techniques — M10.05, M10.07
- M1Screen / GuardGain early warning and buy reaction time before the adversary touches key terrain.1 of 15 techniques — M1.09
- M3EnvelopmentMake identity, not network location, the decisive plane — surround the adversary with policy.1 of 20 techniques — M3.13
- M8Isolation / RetrogradeGive ground deliberately to preserve the force. Degrade gracefully; never fail open.1 of 17 techniques — M8.10
Terrain It Is Named On
- T1IdentityIdentity controls carry the heaviest 800-53 inheritance (AC, IA), so the inheritance mapping matters most here.
Artifacts It Stands On
- producesControl inheritance mappingHow the cycle’s output maps onto the organization’s existing control baseline and assessment results, so that federal obligations are satisfied as a by-product of defending rather than as a parallel program.
- consumesCyber Running EstimateThe living situational picture the SOC, hunt and intelligence cell share: current posture, current assessments and their confidence, open requirements, and what has moved since the last look.
- consumesFindings disposition recordEvery finding with an outcome: remediate with an owner and a date, accept with a named accepter and an expiry, or transfer with the party named. “Under review” is not a disposition.
- consumesCycle record and trendThe closed record of the cycle — posture, loop measurement, conclusions and their confidence, backlog state at close — and the trend across cycles that makes a second cycle worth more than a first.
Roles It Puts to Work
- AccountableAuthorizing Official / CISOIntent, risk acceptance, and the scheme itself.
- ResponsibleGovernance / RMF / ISSOTranslating cycle outputs into FISMA and RMF artifacts, and owning the rules of engagement.
- ConsultedCyber Threat Intelligence cellFrame, Map and Fuse. The intelligence requirements, the threat courses of action, and the confidence levels.
- ConsultedPlatform and product ownersTheir own terrain. Obstacles get emplaced on their ground, so they site them.
- InformedSOC / Defensive OperationsManeuver. Executes fires and emplaces obstacles inside the standing rules of engagement.
- InformedHunt teamCounterattack. Works the hypotheses that Fuse raises.