ASOM-Fedv6.1Open the explorer
EN-4 · Engagement and Pursuit

Escalation and Engagement Authority

Control Statement

Incidents shall be escalated against defined criteria to an authority that is reachable within a stated period, and the authority exercised shall be recorded against the action taken.

Purpose. To remove the search for a decision-maker from the decision loop, which is where the decide segment is usually spent.

Discussion

TA-4 defines what may be done without escalation; this control governs what happens when escalation is required, and the two together constitute the decide segment. The binding constraint in most programs is not deliberation but locating someone with authority, and that is an availability problem rather than a judgment problem. Recording authority against action closes the loop in the other direction: an operator who acted correctly under written authority and is later questioned needs the record more than the organization does, and without it the practical effect is that the next operator escalates instead.

Goals and Metrics

A metric that cannot come out badly is not a metric. Each of these is capable of reporting that the control is not working.

Nobody spends the decision loop looking for a decision-maker.
  • Time from escalation trigger to authority response
  • Percentage of named authorities verified reachable out of hours
Authority actually exercised is recorded against the authority granted.
  • Percentage of escalations recording the authority exercised
  • Count of actions taken outside the pre-authorized set

Accountability

Exactly one role is accountable, and every other role carries at least Informed — no control in the published catalog leaves a role with zero relationship to it. That is a stated property of how these were authored, not a coincidence, and not a claim that every role's work is worth equal attention here.

AOCTISOCHUNTPLATISSO
Authorizing Official / CISO: AccountableCyber Threat Intelligence cell: InformedSOC / Defensive Operations: ResponsibleHunt team: InformedPlatform and product owners: InformedGovernance / RMF / ISSO: Consulted

AO Authorizing Official / CISOCTI Cyber Threat Intelligence cellSOC SOC / Defensive OperationsHUNT Hunt teamPLAT Platform and product ownersISSO Governance / RMF / ISSO

  • AccountableAuthorizing Official / CISO
  • InformedCyber Threat Intelligence cell
  • ResponsibleSOC / Defensive Operations
  • InformedHunt team
  • InformedPlatform and product owners
  • ConsultedGovernance / RMF / ISSO

Inputs and Outputs

Consumes

Produces

Activities

  1. L2Define the criteria at which an incident escalates.
  2. L2Define the authority level required at each escalation tier.
  3. L2Record the authority exercised against each action taken.
  4. L3State the period within which each named authority must be reachable, and maintain an out-of-hours path consistent with CG-3.
  5. L3Define escalation for the case where the named authority is unreachable, including who may act in their absence and under what constraint.
  6. L3Escalate on terrain rather than on severity alone — an incident touching a decisive point escalates regardless of apparent magnitude.
  7. L3Record escalations that were required by criteria and did not occur, so the gap between criteria and practice is visible.
  8. L4Measure time from escalation trigger to authority response, separately from total decide-segment time, since these fail for different reasons.
  9. L4Test reachability of each named authority out of hours rather than assuming it, at a defined cadence.
  10. L5Move recurring escalations that are always approved into the pre-authorized set under TA-4, since a decision made identically every time is a policy rather than a decision.

Measurement

Outcome

Time from escalation trigger to authority response.

Performance

Percentage of named authorities verified reachable out of hours.

Evidence and Assessment

Evidence expected

Escalation criteria and tiers; escalation records with authority and response times; reachability test records; missed-escalation record.

Assessment procedure

Examine criteria against a sample of incidents; test out-of-hours reachability; examine whether authority was recorded against actions taken.

Related Guidance

Inherits
  • IR-4
  • IR-6
  • IR-7
Satisfies
  • RS.MA-04

Position in the Chain

Derived from the other controls’ own declarations, so the two directions cannot disagree.

Where This Control Is Used

Derived, in every case, from the declaration at the other end: the forms whose techniques name this control, the artifacts whose producing and consuming controls include it, the layers whose control lists name it, and the roles its own accountability chart puts to work. Nothing here is authored on this page, so the sheet cannot claim an edge the other end does not.

Forms of Maneuver It Assesses

  • M6DelayBuy decision time and prevent the adversary culminating on the objective.1 of 10 techniques — M6.05
  • M7CounterattackSeize the initiative and evict before the adversary reaches the objective.1 of 17 techniques — M7.03
  • M8Isolation / RetrogradeGive ground deliberately to preserve the force. Degrade gracefully; never fail open.1 of 17 techniques — M8.01

Terrain It Is Named On

Applies to all ten layersNames who may authorize action on this layer out of hours, which is where the decide segment is usually spent.

Artifacts It Stands On

  • producesEngagement recordThe record of one engagement end to end: what was declared and on what criteria, the reconstruction with its dwell, scope and confidence, the evidence preserved and its custody, the authority exercised, and the verification that eradication actually happened before recovery began.
  • consumesPhase declarationThe declared campaign phase and the scope it is declared against. Sets cadence, dominant forms of maneuver, and how wide the pre-authorization set runs.
  • consumesRules of engagementWhich defensive actions may be taken by whom without escalation, which need the Authorizing Official, and what is prohibited outright. The cyber analog of engagement authority, and the single largest determinant of tempo.
  • consumesPre-authorized response setThe specific containment and response actions the SOC may execute at machine speed, bounded by the statutory availability floor. Directly measurable: it shortens the decision segment of the defender loop.
  • consumesChange recordEvery defensive action carried out, stamped twice — at the decision and at the effect. A thin, unglamorous table, and the one the headline metric is computed from.
  • consumesAuthority exception logActions taken outside the standing rules of engagement, with who approved them and why. Exceptions are not failures; unrecorded exceptions are.

Roles It Puts to Work