Purpose
Refresh the terrain overlay, enumerate avenues of approach, and build threat courses of action: most likely and most dangerous.
Output. A terrain overlay and a threat COA sketch.
The Doctrinal Step It Corresponds To
Cyber Preparation of the Environment — the IPB analog
Cyber Preparation of the Environment is the framework’s Intelligence Preparation of the Battlefield analog, and it keeps all four IPB steps: define the operational environment, describe its effects, evaluate the threat, and determine threat courses of action. The ground is the estate rather than the ground, and the substitution is less lossy than it sounds — an estate has position, corridors, high ground and dead space, all of which are observable and none of which appear on an asset inventory.
Discussion
Map is the step most programs believe they have already done, on the strength of owning an asset inventory. An inventory enumerates; a terrain overlay positions. The difference is testable in one question: does the artifact say what is adjacent to what, and which of those adjacencies an adversary can actually traverse? An inventory cannot answer either.
The overlay is built from imperfect sources — architecture diagrams that lag reality, configuration that describes intent rather than effect, and an asset register that is authoritative only about what was procured. The framework’s answer is not to wait for better sources; it is to record the gap as a gap. An avenue of approach that has not been assessed is an intelligence requirement, not an absence of risk, and the difference between those two readings is most of the value of this step.
Map also produces the pair of threat courses of action the rest of the cycle is planned against: most likely and most dangerous. They must differ materially. When the most-dangerous course of action is the most-likely one with more severe adjectives, the step has produced one course of action and a mood.
Entry and Exit Criteria
Authored for this manual. A step you cannot tell you have finished is not a step, and every criterion below is written so that it can be answered no.
Do Not Start Until
- Frame is closed, so the map has a purpose and knows which decisive points it is being drawn to serve.
- The sources the overlay is built from are identified by name, with their known staleness recorded. An overlay built from unnamed sources cannot be re-derived and therefore cannot be corrected.
- Terrain currency triggers accumulated since the last cycle — material architectural change, deployments, acquisitions — have been collected rather than assumed absent.
- Flow telemetry is available for the segments whose denied paths the overlay will assert. Asserting a denied path with no telemetry is asserting a configuration, not a fact.
The Step Is Finished When
- Every element on the overlay carries a defensive layer, a defensive weight, and a named accountable owner. An element with no owner is on a list, not on a map.
- Decisive points are designated, and each designation carries the weighting evidence that made it decisive rather than merely important.
- Avenues of approach to each decisive point are enumerated, and each is either traced to a reachability result or recorded as an explicit intelligence gap.
- The permitted- and denied-path register reconciles against observed flow telemetry, and every discrepancy between intended and observed is written down rather than resolved in favor of the configuration.
- Two threat courses of action exist, they differ materially, and the most dangerous one is one the current scheme would not obviously survive.
- Terrain outside the five zero-trust pillars — workforce, facilities, supply chain, operational technology — has entries, or the decision not to model it this cycle is recorded with a reason.
Beyond repair. Map has failed irrecoverably when the overlay is refreshed on schedule and no one can state, from it, which single element’s compromise would be worst.
Who Takes Part
The intelligence cell runs Cyber Preparation of the Environment with the hunt team; platform and product owners supply the ground truth for their own terrain, because they are the only people who reliably know what is actually deployed on it.
Participation below is derived from the RACI of this step’s own governing controls, not authored — a role appears at the strongest assignment it holds on any of them. The manual therefore cannot claim a role is uninvolved in a step whose controls give it work.
- AccountableAuthorizing Official / CISO TM-1 · TM-2 · TM-3 · TM-4 · TM-5 · TM-6 · TM-7 · KT-1 · KT-3 · KT-4 · FO-4 · FO-6 · WF-1 · FC-1 · LC-1
- ResponsibleCyber Threat Intelligence cell KT-1 · KT-3 · KT-4
- ConsultedSOC / Defensive Operations TM-1 · TM-4 · TM-5 · KT-1 · KT-4 · FO-4 · FC-1 · LC-1
- ConsultedHunt team KT-3
- ResponsiblePlatform and product owners TM-1 · TM-2 · TM-3 · TM-4 · TM-5 · TM-6 · FO-4 · WF-1 · FC-1 · LC-1
- ResponsibleGovernance / RMF / ISSO TM-7 · FO-6
Inputs and Outputs
Every artifact links to its entry in the products index, where its owner, its consumers and its refresh cadence are set out.
Consumes
- Defensive intent paragraphOne signed paragraph stating what the defense exists to protect, what may be degraded to protect it, and the acceptable risk. The commander’s-intent analog, and the citation every downstream designation rests on.
- Priority Cyber Intelligence RequirementsThree to seven questions the cycle will try to answer, each naming the decision it informs, the collection source expected to answer it, and an individual owner.
- Supplier terrain registerSuppliers as external actors on the overlay, with the access each holds, the paths that access implies, and the contract behind it.
- Privacy and controlled-information terrain registerWhere privacy holdings and controlled unclassified information sit, the authorities under which they are held, and the boundaries their handling requires — expressed as denied paths, not as policy statements.
- Workforce terrain registerThe roles whose compromise is equivalent to compromising a decisive point — the operators of decisive points, and the roles with standing access to them.
- Facility terrain registerWhere elements physically are, which personnel populations are associated with each site, and which facilities carry mission services.
Produces or Refreshes
- Cyber Terrain OverlayThe positional map of the estate: every element with a defensive layer, a defensive weight, a named accountable owner and its adjacencies. Not an asset inventory — an inventory enumerates, an overlay positions.
- Trust zones and the connection registerThe zone boundaries and the permitted- and denied-path register — the graph reachability is actually walked over, reconciled against observed flow telemetry rather than against intended configuration.
- Decisive point registerThe elements whose control confers decisive advantage — each carrying the evidence that raised it above merely important, and the protection floor it owes as a result.
- Avenue-of-approach analysisThe enumerated routes an adversary could take toward each decisive point, including physical, supplier and maintenance routes, with unassessed routes recorded as intelligence gaps rather than as absence of risk.
- Adversary reachability assessmentThe formal result: from each entry point, which decisive points are reachable over the permitted-path graph. The framework’s hardest single finding, and the headline of the brief when it changes.
- Threat course-of-action sketchTwo courses of action, most likely and most dangerous, drawn against the decisive points already designated. Each is a route across ground the estate really has, not a category of threat.
- Barrier sufficiency registerThe specific barriers holding the line where reachability is prevented, each with a named enforcing owner. What the reachability result depends on, made explicit so its erosion is visible.
The Controls That Govern This Step
A control may govern more than one step. Where it does, the note says which job it is doing here — the temporal-advantage control sets a threshold at Frame and reports against it at Assess, and they are not the same activity.
- TM-1 Terrain Inventory and OverlayBuilds the overlay itself: the positional artifact everything downstream is computed over.
- TM-2 Defensive Layer ClassificationAssigns each element a defensive layer, which is what lets coverage be aggregated meaningfully rather than as one flat average.
- TM-3 Asset WeightingWeights elements by consequence, so that “covered” is weighted by what is worth covering.
- TM-4 Trust Zone DefinitionDefines the trust zones an avenue of approach has to cross.
- TM-5 Connection and Denied-Path RegisterRecords permitted and denied paths — the graph reachability is actually walked over.
- TM-6 Terrain CurrencyTriggers the refresh. Without it the overlay ages silently and every derived number ages with it.
- TM-7 Terrain OwnershipAttaches an accountable owner to each element, which is what makes a finding routable at Assess.
- KT-1 Decisive Point IdentificationDesignates decisive points from the overlay and the intent, with evidence.
- KT-3 Avenue of Approach AnalysisEnumerates the avenues of approach to those points, including physical, supplier and maintenance routes.
- KT-4 Adversary Reachability AssessmentTests reachability formally over the permitted-path graph rather than by expert opinion.
- FO-4 Operational Technology TerrainBrings operational technology onto the map as its own layer, including the enterprise-to-operational crossings.
- FO-6 Supply Chain ObligationPlaces suppliers on the overlay as external actors with real paths.
- WF-1 Workforce Terrain IdentificationIdentifies workforce terrain — the roles whose compromise is equivalent to compromising a decisive point.
- FC-1 Facility Terrain IdentificationGives elements a physical location, which is where several avenues of approach begin.
- LC-1 Supplier Terrain RegisterRegisters supplier access in enough detail to be traced, constrained and later severed.
Analytic Method
Threat course-of-action development
ATP 2-33.4 · IPB step 4Develop the most-likely and most-dangerous adversary courses of action against the designated decisive points, each expressed as a route through real terrain rather than as a threat category.
Attack-path traversal
AuthoredWalk the permitted-path graph from every external entry point toward each decisive point. Denied paths are excluded by definition, which is exactly why the denied-path register has to be evidenced rather than asserted.
Structured brainstorming
ATP 2-33.4 · basic techniqueRun a divergent pass specifically for avenues nobody owns — maintenance windows, supplier tooling, out-of-band management, physical access. These are systematically under-represented because no team’s day job is to notice them.
Terrain currency check
AuthoredReconcile the overlay against change-management records for the period. The output is not a corrected overlay; it is a measured staleness, which is a reportable metric and a refresh trigger.
Common Failure Modes
Authored, and each one carries the observable tell that separates it from a step that is working. A list of failure modes with no tells is a list of anxieties.
The overlay is an asset inventory with a border drawn around it.
- The tell
- It has no avenues, no decisive points and no denied paths — it enumerates but does not position.
- The correction
- Require every element to have at least one recorded adjacency. An element with no relationships has not been placed on terrain.
The most-dangerous course of action is the most-likely one, restated.
- The tell
- Both courses of action defeat the same controls in the same order.
- The correction
- Constrain the most-dangerous course of action to route through terrain the current scheme does not cover. If no such route can be constructed, either the coverage claim or the analysis is wrong, and both are worth knowing.
Denied paths are asserted from configuration and never tested.
- The tell
- The connection register has no telemetry input recorded against it.
- The correction
- Treat an untested denial as permitted for the purposes of reachability. It is a harsher assumption and it is the only safe one.
Only the five zero-trust pillars are mapped.
- The tell
- Workforce, facility, supply-chain and operational-technology layers are empty across consecutive cycles.
- The correction
- These layers were added to the terrain model because measurable parts of a federal estate had no ground to stand on without them. An empty layer is a decision and should be recorded as one.
Ownership is recorded against a team that no longer exists.
- The tell
- Findings routed to an owner bounce, or sit undispositioned across two cycles.
- The correction
- Separation and revocation feeds ownership for exactly this reason. Reconcile owners against the identity system, not against the last version of the org chart.