Intent, Mechanism and Indicator
Gain early warning and buy reaction time before the adversary touches key terrain.
Role. The form that opens the campaign
Forward reconnaissance: external attack-surface monitoring, threat intelligence, canary tokens at the perimeter.
Threats are detected before they reach key terrain.
Terrain It Consumes
Derived from where the form’s techniques are actually emplaced. The highlighted layer is the one the catalog names as its principal ground — the rest is terrain the form still has to touch, and that spread is how much of the estate employing it implicates.
- T1IdentityThe high ground2 techniques
- T2DevicesThe entry fords1 technique
- T3NetworksThe corridors3 techniques · principal ground
- T4Applications and WorkloadsThe urban terrain1 technique
- T5DataThe objective1 technique
- T6Operational TechnologyGround you cannot maneuver freely on1 technique
- T7WorkforceTerrain that is also the force1 technique
- T8FacilitiesThe physical boundary1 technique
- T9Supply ChainThe lines of communication1 technique
- TXCross-CuttingThe enablers of movement3 techniques
Campaign Phasing
Dominance is taken from the campaign model; participation is derived from the techniques themselves. A form is usually present in more phases than it leads, and confusing the two is how a scheme ends up with no main effort.
| Phase | Role | Phase objective | Techniques employed |
|---|---|---|---|
| Phase 0 — ShapeSet conditions | Dominant — main effort | Continuous terrain preparation, zero-trust hardening, partnerships, threat intelligence. | 15 of 15 |
| Phase I — DeterRaise adversary cost | Supporting | Visible hardening, a deception grid, and a stated attribution posture. | 8 of 15 |
| Phase II — Seize InitiativeContest first contact | Dominant — main effort | Detect early, canalize movement, and buy decision time. | 3 of 15 |
Phase 0 — Shape
Set conditions
- Role
- Dominant — main effort
- Phase objective
- Continuous terrain preparation, zero-trust hardening, partnerships, threat intelligence.
- Techniques employed
- 15 of 15
Phase I — Deter
Raise adversary cost
- Role
- Supporting
- Phase objective
- Visible hardening, a deception grid, and a stated attribution posture.
- Techniques employed
- 8 of 15
Phase II — Seize Initiative
Contest first contact
- Role
- Dominant — main effort
- Phase objective
- Detect early, canalize movement, and buy decision time.
- Techniques employed
- 3 of 15
Employment
When to Choose It
Choose screening first, and choose it again whenever the terrain overlay is thin. It is the only form that produces the information the other ten are planned from: avenues of approach, exposure that nobody registered, the campaigns actually pointed at this agency. A program that cannot say what it looks like from the outside is planning its defense from its own assumptions, and those assumptions are exactly what an adversary enumerates first.
Precondition
Something on the far side of the screen must be able to act inside the warning’s useful life. Warning delivered to an organization that cannot move is not early warning; it is anxiety with a timestamp.
What It Costs
Paid in attention, not licenses. Collection is cheap and reading it is not. Every feed added without a named consumer and a named disposition is a standing draw on the analytic cell, and screening is the form most likely to be scaled up by procurement and never staffed.
Rules of Engagement
Collection, enumeration and advisory intake are standing SOC activity and need no authorization. Acting on what the screen returns is a different form — pre-blocking belongs to M9, and takes M9’s authorities.
How It Fails
Not whether it fails — how. Each of these is a state in which the form is still reported as implemented and has stopped producing the advantage it was chosen for.
- The screen reports into a mailbox rather than into a decision. Intake exists, disposition does not, and the advisory that named your ground is found during the incident review.
- Collection is run against indicators in general instead of against stated intelligence requirements, so volume rises while warning does not.
- Enumeration is run from the inside out — from the asset register — and therefore reproduces the defender’s picture rather than the adversary’s. Anything the register never knew about stays invisible.
- Warning arrives with no rehearsed action behind it, so the same exposure is reported cycle after cycle and the reporting itself becomes the deliverable.
Techniques (15)
Grouped by the terrain layer each is emplaced on. Techniques are the perishable layer of the framework — they churn, the form does not — so each is stated as what it does and the observable that shows it is working, never as a product.
T1 · Identity — 2 techniques
- M1.05
Authentication Geography Baseline
Baseline where, when and from what the population legitimately authenticates, so deviation is measurable rather than anecdotal.
IndicatorAccount-takeover precursors are detected on deviation, not on damage.
Phases- 0
- II
- M1.06
Credential Exposure Monitoring
Monitor public and criminal sources for agency credentials, session artifacts and tokens offered for sale or dumped.
IndicatorExposed credentials are invalidated before they are used against the estate.
Phases- 0
- I
T2 · Devices — 1 technique
- M1.15
Device Estate Discovery
Discover devices reaching the estate from the identity plane outward rather than from the management console, because the console can only report what it already manages.
IndicatorDevices authenticating to the estate but absent from the inventory trend to zero.
Phases- 0
T3 · Networks — 3 techniques
- M1.01
External Attack Surface Enumeration
Continuously enumerate everything the agency exposes to the internet, from the outside in, on the same cadence an adversary would.
IndicatorNew exposure appears in the terrain register before it appears in an alert.
Phases- 0
- I
- M1.02
Shadow and Forgotten Asset Discovery
Reconcile discovered internet-facing assets against the authoritative inventory and drive the difference to zero.
IndicatorThe unreconciled-asset count trends to zero and stays there.
Phases- 0
- M1.03
Certificate and Domain Watch
Watch certificate transparency and registration feeds for lookalike domains and unsanctioned certificates issued in the agency name.
IndicatorImpersonation infrastructure is identified while it is still being staged.
Phases- 0
- I
T4 · Applications and Workloads — 1 technique
- M1.08
Public Service Abuse Telemetry
Instrument public-facing services for abuse patterns — enumeration, scripted submission, credential stuffing — distinct from application errors.
IndicatorAbuse is distinguished from load, and named, before it becomes an incident.
Phases- 0
- II
T5 · Data — 1 technique
- M1.04
Perimeter Canary Tokens
Seed uniquely identifying tokens in externally reachable surfaces so that reconnaissance touching them is unambiguous.
IndicatorA token fires before any production system records the actor.
Phases- 0
- I
T6 · Operational Technology — 1 technique
- M1.11
Operational Technology Asset Discovery
Discover control-system assets passively, because active scanning of a safety-instrumented network is itself an availability risk.
IndicatorThe OT inventory is built without a scan-induced outage.
Phases- 0
T7 · Workforce — 1 technique
- M1.12
Workforce Credential Exposure Monitoring
Watch the outside world for agency credentials and staff identities appearing where they should not, on the same cadence you watch the network perimeter.
IndicatorExposed staff credentials are found and revoked before they are used.
Phases- 0
- I
T8 · Facilities — 1 technique
- M1.13
Physical Access Anomaly Detection
Read badge and access-control telemetry as an intelligence source rather than an audit artifact, and correlate it with logical access.
IndicatorImpossible-travel and after-hours physical anomalies raise a finding.
Phases- 0
- II
T9 · Supply Chain — 1 technique
- M1.14
Supplier Exposure Monitoring
Monitor the suppliers and components that reach into the estate for breach disclosure, advisory and exposure, because their compromise is your compromise.
IndicatorA supplier incident reaches the agency from monitoring, not from the news.
Phases- 0
- I
TX · Cross-Cutting — 3 techniques
- M1.07
Partner and Advisory Intake
Operate a named, timed intake path for CISA, sector and law-enforcement reporting that ends in a decision rather than a mailbox.
IndicatorEvery advisory reaches a disposition within its stated intake window.
Phases- 0
- I
- M1.09
Supply Chain and Vendor Watch
Track the security posture and incident disclosures of vendors and integrators whose products sit on key terrain.
IndicatorA vendor compromise reaches the terrain owner before it reaches the news.
Phases- 0
- M1.10
Named-Campaign Indicator Watch
Maintain standing collection against the specific campaigns the intelligence requirements name, not against indicators in general.
IndicatorEvery priority intelligence requirement has live collection against it.
Phases- 0
- I
Controls That Assess It
Derived from the controls the form’s own techniques name, so the assessment surface cannot disagree with the catalog. A control reached by many techniques is load-bearing for this form; one reached by a single technique is not, and an assessor sampling it will learn very little.
By Family
- TMTerrain Management4 controls · reaches 8 of 15 techniques
- CECycle Execution and Assurance2 controls · reaches 7 of 15 techniques
- FOFederal Obligations3 controls · reaches 3 of 15 techniques
- KTKey Terrain and Decisive Points1 control · reaches 3 of 15 techniques
- TATempo and Temporal Advantage2 controls · reaches 3 of 15 techniques
- CGCommand and Governance2 controls · reaches 2 of 15 techniques
- DVDevices Terrain1 control · reaches 2 of 15 techniques
- ENEngagement and Pursuit1 control · reaches 1 of 15 techniques
- FCFacilities Terrain2 controls · reaches 1 of 15 techniques
- LCLines of Communication2 controls · reaches 1 of 15 techniques
- WFWorkforce Terrain2 controls · reaches 1 of 15 techniques
By Control
- CE-2 Priority Intelligence Requirements6 techniques — To direct analytic effort at named questions, so that collection and hunting answer what the accountable authority needs rather than processing what arrives.
- TM-1 Terrain Inventory and Overlay5 techniques — To establish one authoritative positional picture of the estate, so that every later judgment about priority, reachability and risk is made against the same ground.
- TM-6 Terrain Currency5 techniques — To keep the overlay current against both the clock and the change, so that planning is conducted against ground as it currently is.
- KT-3 Avenue of Approach Analysis3 techniques — To convert the estate's connectivity into a set of named approach routes, so that defense can be emplaced on the routes that exist rather than distributed evenly across ground.
- CE-3 Fusion and Confidence2 techniques — To distinguish assessment from assertion, so that decisions taken on analytic conclusions carry the uncertainty of those conclusions with them.
- DV-1 Device Terrain Identification2 techniques — To make devices positional, so that the crossings into the estate are known and can be defended rather than merely counted.
- TA-1 Decision Loop Measurement2 techniques — To make the defender's tempo a measured quantity rather than an impression, so that the numerator of temporal advantage exists at all.
- TM-7 Terrain Ownership2 techniques — To attach every element to a person who can be asked to act, so that findings convert into work rather than accumulating.
- CG-4 Findings Disposition1 technique — To ensure every finding reaches a decision, so that the open set reflects work in progress rather than accumulated neglect.
- CG-5 Control Inheritance Mapping1 technique — To keep the framework additive, so that adopting it adds assessment effort only where it adds assessable content.
- EN-1 Event Declaration and Triage1 technique — To convert raw events into a decided position quickly, since this is the segment of the decision loop that most often binds.
- FC-1 Facility Terrain Identification1 technique — To resolve the estate to physical locations, so that defense, recovery and continuity can be reasoned about in the place things actually are.
- FC-2 Physical Zone Boundary1 technique — To establish physical boundaries that constrain movement and produce a record of crossing, so that physical terrain can be defended in depth rather than at a perimeter.
- FO-3 Tenancy and Inheritance Boundary1 technique — To ensure that the customer half of a shared responsibility model is owned by someone, so that inherited controls do not become nobody's job.
- FO-4 Operational Technology Terrain1 technique — To stop operational technology being scored as though it were a server estate, and to make the connections between the two declarable.
- FO-6 Supply Chain Obligation1 technique — To discharge the statutory supply chain risk obligation, and to make the boundary of its scope explicit rather than assumed.
- LC-1 Supplier Terrain Register1 technique — To make third parties positional, so that supplier risk is assessed against what a supplier can reach rather than against what they were contracted to do.
- LC-2 Component Provenance1 technique — To know where deployed components came from and what is inside them, so that a compromise disclosed anywhere can be located here.
- TA-4 Pre-authorized Response1 technique — To remove authority latency from the decision loop, so that the segment most programs cannot shorten with tooling is shortened by governance.
- TM-2 Defensive Layer Classification1 technique — To make posture summable and comparable by layer, and to force an explicit ownership decision for every element.
- WF-1 Workforce Terrain Identification1 technique — To make the workforce positional, so that defensive effort concentrates on the roles an adversary would actually target.
- WF-2 Privileged Human Register1 technique — To ensure privilege is held by accountable people, so that every privileged action has a person behind it.
The terrain-management controls test whether what the screen found reached the authoritative register; the exposure controls test whether it was reachable; the cycle-execution controls test whether it was collected against a stated requirement and dispositioned. What no control will catch is a screen that is technically complete and analytically idle — for that, read the disposition times rather than the coverage figure.
Sequencing
A scheme names a sequence, not a set. These are the ordinary neighbors of this form — not a mandatory order, but the order in which each one’s preconditions are usually met.
Typically Preceded By
Nothing. This is the form that opens the campaign — everything else is planned from what it returns.
Typically Followed By
- M2 Defense in DepthExposure the screen found is layered before it is used.
- M9 Spoiling AttackNamed infrastructure and named vulnerabilities are pre-empted rather than filed.
- M4 Obstacle / CanalizationAvenues of approach the screen enumerates are the ones worth canalizing.
Named as a successor by M10 Exploitation & Pursuit. Derived from those forms’ own declarations, so the two directions of the sequence cannot disagree.
Named as a predecessor by M2 Defense in Depth, M3 Envelopment, M5 Ambush, M7 Counterattack, M9 Spoiling Attack. Derived the same way, from the other direction.