ASOM-Fedv6.1Open the explorer
Step 05 of 6 · Analyze · Integrate

Fuse

Purpose

Apply structured analytic techniques to what came back: competing hypotheses on adversary intent, a key-assumptions check, indicators and signposts. Assign explicit confidence.

Output. A fused assessment feeding the Cyber Running Estimate.

The Doctrinal Step It Corresponds To

Analyze · Integrate

Analyze and Integrate, in ATP 2-33.4’s sequence. This is the step that structured analytic techniques exist for. Analysis without them tends to converge on the first plausible explanation and then accumulate support for it; the techniques are all, in one way or another, mechanisms for making that harder.

Discussion

Fuse is where a defense stops reporting what happened and starts saying what it means, with a confidence level attached and a stated basis for that confidence. Everything before this step generates observations. This step generates assessments, and an assessment is a claim someone can be wrong about in public.

The change record from Maneuver is a required input, not a courtesy one. Without it, effects cannot be attributed to actions, and the program cannot distinguish a maneuver that worked from a quiet month. This is the specific mechanism by which security programs come to believe in controls that do nothing.

Confidence has to be assigned against a stated basis — source reliability, corroboration, recency — and it has to be capable of being low. A program whose every product for a year has been "moderate confidence" is not calibrating; it is using the middle of the scale as a way of never being wrong.

Fuse also produces next cycle’s collection. Indicators and signposts derived here become the intelligence requirements set at the next Frame, which is the mechanism that makes the loop a loop rather than six activities in sequence.

Entry and Exit Criteria

Authored for this manual. A step you cannot tell you have finished is not a step, and every criterion below is written so that it can be answered no.

Do Not Start Until

  • The cycle’s intelligence requirements exist and have not been rewritten mid-cycle to match what was collected.
  • Collection has run: telemetry, threat reporting, partner and government intelligence, and hunt results — including hunt results that found nothing.
  • The change record from Maneuver is available, so observed effects can be attributed to actions rather than to the passage of time.
  • Someone who did not execute the maneuvers is available to fuse, or to challenge the fusion.

The Step Is Finished When

  • Every intelligence requirement is answered, or is explicitly recorded as unanswered with the collection gap named. A requirement that quietly disappears between Frame and Assess is the most common way a cycle lies to itself.
  • Every conclusion carries a confidence level and the basis for that level.
  • The adversary dwell estimate is restated with its basis. If the basis is sector reporting rather than measured dwell in this estate, that is written down — it is a defensible basis and an indefensible thing to leave implicit.
  • Every maneuver claiming operational status has been validated or flagged as unvalidated. An unvalidated control is not a failing control; it is an unmeasured one, and it should be visible as such.
  • Where the fused picture indicates a phase change, it has been put to the Authorizing Official as a recommendation rather than assumed into effect.
  • Indicators and signposts for the surviving hypotheses are written and handed to collection for the next cycle.

Beyond repair. Fuse has failed irrecoverably when the assessment is confident, well-written, and contains nothing that would have been unwelcome to the people who commissioned it.

Who Takes Part

Leads: Cyber Threat Intelligence cell

The intelligence cell is accountable for fusion and confidence, and it is the one step in the loop where accountability does not sit with the Authorizing Official. Analytic judgment cannot be delegated upward without becoming a management opinion.

Participation below is derived from the RACI of this step’s own governing controls, not authored — a role appears at the strongest assignment it holds on any of them. The manual therefore cannot claim a role is uninvolved in a step whose controls give it work.

  • AccountableAuthorizing Official / CISO CE-3 · CE-2 · TA-2 · KT-4 · SM-6 · CG-2
  • ResponsibleCyber Threat Intelligence cell CE-3 · CE-2 · TA-2 · KT-4
  • ConsultedSOC / Defensive Operations CE-2 · KT-4 · SM-6 · CG-2
  • ResponsibleHunt team SM-6
  • ConsultedPlatform and product owners KT-4
  • ConsultedGovernance / RMF / ISSO SM-6 · CG-2

Inputs and Outputs

Every artifact links to its entry in the products index, where its owner, its consumers and its refresh cadence are set out.

Consumes

  • Priority Cyber Intelligence RequirementsThree to seven questions the cycle will try to answer, each naming the decision it informs, the collection source expected to answer it, and an individual owner.
  • Change recordEvery defensive action carried out, stamped twice — at the decision and at the effect. A thin, unglamorous table, and the one the headline metric is computed from.
  • Implementation state recordPlanned, partial or operational, per maneuver assignment. The mechanism that stops intended work being counted as deployed protection.
  • Adversary reachability assessmentThe formal result: from each entry point, which decisive points are reachable over the permitted-path graph. The framework’s hardest single finding, and the headline of the brief when it changes.
  • Threat course-of-action sketchTwo courses of action, most likely and most dangerous, drawn against the decisive points already designated. Each is a route across ground the estate really has, not a category of threat.
  • Hunt results, including negative resultsWhat was hunted, how, and what was not found. Negative results are the half most often discarded, and they are the half that says what has actually been cleared.

Produces or Refreshes

  • Fused assessmentWhat the cycle’s intelligence requirements returned: each answer graded for confidence and showing its working, and each requirement left unanswered recorded against the collection gap responsible.
  • Adversary dwell estimateThe estimated time an adversary could operate undetected in this estate, with its basis stated — measured dwell, sector reporting, or partner intelligence — and its bias acknowledged.
  • Maneuver effectiveness validation recordWhether the moves claiming operational status produced the effect the catalog assumed — from exercise results, control testing, and observed incident performance.
  • Cyber Running EstimateThe living situational picture the SOC, hunt and intelligence cell share: current posture, current assessments and their confidence, open requirements, and what has moved since the last look.
  • Indicators and signpostsFor each surviving hypothesis, the observable events that would confirm or kill it, handed to collection. The mechanism that makes this cycle’s analysis into next cycle’s requirements.
  • Adopted maneuver catalogThe forms of defensive maneuver the organization has adopted, each with the effectiveness it is assumed to deliver — recorded so the assumption can later be validated rather than believed indefinitely.
  • Engagement recordThe record of one engagement end to end: what was declared and on what criteria, the reconstruction with its dwell, scope and confidence, the evidence preserved and its custody, the authority exercised, and the verification that eradication actually happened before recovery began.

The Controls That Govern This Step

A control may govern more than one step. Where it does, the note says which job it is doing here — the temporal-advantage control sets a threshold at Frame and reports against it at Assess, and they are not the same activity.

Analytic Method

Analysis of Competing Hypotheses

ATP 2-33.4 · diagnostic technique

Enumerate hypotheses for adversary intent, list the evidence, and score each item by how strongly it *disconfirms* each hypothesis rather than how well it supports one. The output is the hypothesis least contradicted by the evidence, which is a different and more durable claim than the hypothesis best supported.

Key assumptions check

ATP 2-33.4 · diagnostic technique

List what the assessment requires to be true. For each: what would it take for this to be false, and would we notice? In most federal estates the load-bearing assumption is that a denied path is denied, and it is usually held on the strength of a configuration.

Indicators and signposts

ATP 2-33.4 · diagnostic technique

For each surviving hypothesis, name observable events that would confirm or kill it, and hand them to collection. This is the mechanism that turns this cycle’s fusion into next cycle’s intelligence requirements.

Quality-of-information check

ATP 2-33.4 · diagnostic technique

Rate reliability and recency separately for every source. A highly reliable source reporting a six-month-old fact is strong evidence about six months ago and weak evidence about now, and collapsing the two into one score hides that.

Devil’s advocacy

ATP 2-33.4 · contrarian technique

Nominate someone to argue the assessment is wrong, and give them the change record and the raw telemetry. Without the underlying material the exercise becomes a rhetorical one and stops finding anything.

Confidence assignment

ATP 2-33.4

High, moderate or low, tied explicitly to source quality and corroboration, and stated on the product rather than in the analyst’s head. The scale is only useful if the low end gets used.

Common Failure Modes

Authored, and each one carries the observable tell that separates it from a step that is working. A list of failure modes with no tells is a list of anxieties.

Confidence is assigned as a mood.

The tell
Every product for a year has been moderate confidence.
The correction
Require the basis to be stated next to the level. A level with a written basis is hard to set to the middle out of habit.

Competing hypotheses are variants of one hypothesis.

The tell
The same evidence supports all of them, and no evidence disconfirms any.
The correction
Include at least one hypothesis in which the observed activity is not hostile, and one in which the adversary’s objective is different from the obvious one. If neither survives contact with the evidence, that is a finding.

Negative hunt results are discarded.

The tell
The same ground is hunted every cycle with no record that it was cleared last time.
The correction
Record what was searched, how, and what was not found. Absence of evidence is evidence about coverage even when it is not evidence about the adversary.

Fusion is done by the people who executed the maneuvers.

The tell
Effectiveness validation never invalidates anything.
The correction
Separate the roles, or at minimum give the devil’s advocate role to someone with no stake in the scheme.

Dwell is estimated from the incidents where dwell was measurable.

The tell
The estimate is flattering and its basis is a single historical case.
The correction
The cases where dwell is measurable are the cases that were detected, which is the population least representative of dwell. State the bias in the basis rather than correcting for it silently.