ASOM-Fedv6.1Open the explorer
M2 · Shaping · 18 techniques

Defense in Depth

Ensure no single failure is decisive.

Intent, Mechanism and Indicator

Ensure no single failure is decisive.

Role. The form that makes no single failure decisive

Mechanism

Layered controls across every terrain layer; TIC 3.0 trust zones; zero-trust segmentation.

Observable indicator

An adversary must defeat three or more independent controls to reach data terrain.

Terrain It Consumes

Derived from where the form’s techniques are actually emplaced. The highlighted layer is the one the catalog names as its principal ground — the rest is terrain the form still has to touch, and that spread is how much of the estate employing it implicates.

Campaign Phasing

Dominance is taken from the campaign model; participation is derived from the techniques themselves. A form is usually present in more phases than it leads, and confusing the two is how a scheme ends up with no main effort.

PhaseRolePhase objectiveTechniques employed
Phase 0 — ShapeSet conditionsDominant — main effortContinuous terrain preparation, zero-trust hardening, partnerships, threat intelligence.18 of 18
Phase I — DeterRaise adversary costSupportingVisible hardening, a deception grid, and a stated attribution posture.2 of 18
Phase III — DominateDefeat the attemptSupportingHunt, contain, evict.1 of 18
Phase IV — StabilizeRestore secure operationsSupportingEradicate, verify, and preserve availability through the recovery.1 of 18

Phase 0 — Shape

Set conditions

Role
Dominant — main effort
Phase objective
Continuous terrain preparation, zero-trust hardening, partnerships, threat intelligence.
Techniques employed
18 of 18

Phase I — Deter

Raise adversary cost

Role
Supporting
Phase objective
Visible hardening, a deception grid, and a stated attribution posture.
Techniques employed
2 of 18

Phase III — Dominate

Defeat the attempt

Role
Supporting
Phase objective
Hunt, contain, evict.
Techniques employed
1 of 18

Phase IV — Stabilize

Restore secure operations

Role
Supporting
Phase objective
Eradicate, verify, and preserve availability through the recovery.
Techniques employed
1 of 18

Employment

When to Choose It

Choose depth when the estate cannot state how many independent controls stand between an internet-facing surface and its most sensitive records, or when the answer turns out to be one. It is the form to reach for after a near miss in which a single control held and nobody can explain what would have happened had it not.

Precondition

A terrain overlay that names the crown-jewel record set. Depth is measured toward something; layering applied uniformly across an estate is not depth, it is spend.

What It Costs

The highest sustained cost of the eleven, and the least visible. Each layer is a license, an integration, an owner, an upgrade path and a failure mode of its own. Depth also imposes a permanent tax on change: every new service must be threaded through every layer, and the layers are where delivery teams learn to route around security.

Rules of Engagement

Emplacement and maintenance are terrain-owner work under standing authority. Removing a layer — decommissioning a control, granting a permanent exception — is a risk-acceptance decision and belongs to the Authorizing Official.

How It Fails

Not whether it fails — how. Each of these is a state in which the form is still reported as implemented and has stopped producing the advantage it was chosen for.

  1. The layers share a dependency. Three controls that all trust the same identity plane, the same endpoint agent, or the same vendor are one control wearing three badges, and they fail on the same afternoon.
  2. Depth is counted in products rather than in independence, so the metric rises while the adversary’s path length does not.
  3. A layer is defeated silently. Depth without instrumentation on each layer means the defender learns the outer two failed only when the third one does.
  4. Depth is applied evenly across the estate, which is the same as designating no main effort — the crown jewels end up defended exactly as hard as the cafeteria menu.

Techniques (18)

Grouped by the terrain layer each is emplaced on. Techniques are the perishable layer of the framework — they churn, the form does not — so each is stated as what it does and the observable that shows it is working, never as a product.

T2 · Devices3 techniques

  • M2.05

    Endpoint Detection and Response Coverage

    Achieve and prove sensor coverage across the managed fleet, with unmanaged devices treated as a measured gap rather than an assumption.

    IndicatorCoverage is reconciled to the inventory, not to the console.

    Phases
    • 0
    Assessed by
  • M2.06

    Device Posture Gating

    Make device health a precondition of access, so a compromised or non-compliant endpoint cannot spend a valid credential.

    IndicatorFailing posture denies access rather than raising a ticket.

    Phases
    • 0
    • I
    Assessed by
  • M2.11

    Workload Hardening Baseline

    Hold servers, images and containers to a declared baseline, and treat drift from it as a finding.

    IndicatorBaseline drift is detected on a stated cadence and dispositioned.

    Phases
    • 0
    Assessed by

T3 · Networks2 techniques

  • M2.01

    Trust Zone Architecture

    Define trust zones that reflect real boundaries and assurance differences, and record which elements sit in which.

    IndicatorEvery element on the terrain resolves to exactly one declared zone.

    Phases
    • 0
    Assessed by
  • M2.02

    Policy Enforcement Point Placement

    Place an enforcement point at every zone boundary so that crossing is a decision, not a route.

    IndicatorNo path reaches a higher-trust zone without transiting an enforcement point.

    Phases
    • 0
    Assessed by

T4 · Applications and Workloads3 techniques

  • M2.07

    Web Application Protection

    Front public applications with request-level inspection tuned to the application, not to a generic ruleset.

    IndicatorApplication-layer attacks are stopped at the edge and counted.

    Phases
    • 0
    Assessed by
  • M2.08

    API Authorization Enforcement

    Enforce per-call authorization at an API gateway rather than trusting network position or a shared key.

    IndicatorNo API path authorizes on network location alone.

    Phases
    • 0
    Assessed by
  • M2.12

    Secrets Management

    Remove long-lived secrets from code, images and configuration into brokered, rotated, audited storage.

    IndicatorNo decisive system authenticates with a static embedded secret.

    Phases
    • 0
    Assessed by

T5 · Data4 techniques

  • M2.03

    Crown-Jewel Enclave

    Isolate the decisive data behind its own enforcement point, with its own authorization policy and its own telemetry.

    IndicatorReaching the data layer requires defeating controls nothing else shares.

    Phases
    • 0
    • I
    Assessed by
  • M2.09

    Data-at-Rest Encryption and Key Separation

    Encrypt decisive data with keys held outside the system that reads it, so storage compromise is not data compromise.

    IndicatorExfiltrating storage does not yield readable records.

    Phases
    • 0
    Assessed by
  • M2.10

    Egress Data Loss Prevention

    Inspect and constrain outbound movement of the record types the campaign exists to protect.

    IndicatorBulk movement of protected records is blocked or alerted at egress.

    Phases
    • 0
    • III
    Assessed by
  • M2.13

    Backup Isolation and Immutability

    Hold recovery data outside the blast radius of the production identity plane and make it immutable for its retention window.

    IndicatorRecovery is possible after full compromise of production identity.

    Phases
    • 0
    • IV
    Assessed by

T6 · Operational Technology1 technique

  • M2.15

    Safety Instrumented Layer Integrity

    Keep the safety layer independent of the control layer, so a compromise of operations cannot defeat the function that prevents harm.

    IndicatorSafety functions hold when the control network is assumed hostile.

    Phases
    • 0
    Assessed by

T7 · Workforce1 technique

  • M2.16

    Role-Based Privilege Minimization

    Give each role the least authority its work requires, so a compromised person yields the least ground.

    IndicatorNo role holds authority its documented duties do not require.

    Phases
    • 0
    Assessed by

T8 · Facilities1 technique

  • M2.17

    Facility Defense in Depth

    Layer physical controls so that defeating one barrier does not deliver the floor, the rack or the media inside it.

    IndicatorReaching a decisive asset physically requires defeating three independent controls.

    Phases
    • 0
    Assessed by

T9 · Supply Chain1 technique

  • M2.18

    Component Provenance Verification

    Know what is inside what you deploy, and verify it came from who it claims, before it runs on your ground.

    IndicatorEvery deployed component resolves to a verified origin and a current inventory.

    Phases
    • 0
    Assessed by

TX · Cross-Cutting2 techniques

  • M2.04

    Independent Control Redundancy

    Ensure the controls guarding key terrain fail independently — no shared agent, identity, console or vendor across a protection floor.

    IndicatorNo single control, credential or vendor failure exposes a decisive point.

    Phases
    • 0
    Assessed by
  • M2.14

    Control Failure Detection

    Detect when a control stops working — sensor silent, policy unapplied, agent removed — as a security event in its own right.

    IndicatorA silent control is detected in hours, not at the next assessment.

    Phases
    • 0
    Assessed by

Controls That Assess It

Derived from the controls the form’s own techniques name, so the assessment surface cannot disagree with the catalog. A control reached by many techniques is load-bearing for this form; one reached by a single technique is not, and an assessor sampling it will learn very little.

By Family

By Control

  • KT-2 Decisive Point Protection Floor11 techniquesTo ensure designation produces protection, so that identifying a decisive point is an act with consequences rather than an annotation.
  • SM-2 Maneuver Assignment3 techniquesTo bind defensive intent to specific ground, so that coverage reflects what protects which element rather than what the program has bought.
  • DV-3 Endpoint Sensor Coverage and Liveness2 techniquesTo know what the estate can actually see, and to detect the loss of that visibility as an event rather than at the next assessment.
  • KT-5 Barrier Sufficiency2 techniquesTo make the barriers on which negative reachability results depend into named, owned, monitored controls, so that the assurance KT-4 provides cannot be silently withdrawn.
  • SM-3 Implementation State Tracking2 techniquesTo make the coverage figure reflect what is defending the estate rather than what is intended to, by weighting mitigation by implementation state.
  • TM-4 Trust Zone Definition2 techniquesTo establish boundaries that something enforces, so that reachability and denied-path analysis rest on configuration rather than on design intent.
  • TM-6 Terrain Currency2 techniquesTo keep the overlay current against both the clock and the change, so that planning is conducted against ground as it currently is.
  • CE-6 Cycle Record and Trend1 techniqueTo answer whether the program is improving — a question no point-in-time assessment can address.
  • CG-4 Findings Disposition1 techniqueTo ensure every finding reaches a decision, so that the open set reflects work in progress rather than accumulated neglect.
  • DV-1 Device Terrain Identification1 techniqueTo make devices positional, so that the crossings into the estate are known and can be defended rather than merely counted.
  • DV-2 Device Posture as an Access Precondition1 techniqueTo ensure a compromised or non-compliant device cannot spend a valid credential, closing the gap `M3` Envelopment leaves when identity alone is enforced.
  • DV-4 Execution Control1 techniqueTo deny the adversary the ability to run code on the ground they cross into, which is the cheapest point at which most engagements can be stopped.
  • FC-1 Facility Terrain Identification1 techniqueTo resolve the estate to physical locations, so that defense, recovery and continuity can be reasoned about in the place things actually are.
  • FC-2 Physical Zone Boundary1 techniqueTo establish physical boundaries that constrain movement and produce a record of crossing, so that physical terrain can be defended in depth rather than at a perimeter.
  • FO-2 Controlled Unclassified Information Handling1 techniqueTo make CUI movement declarable and therefore detectable, so that handling obligations attach to information rather than to systems.
  • FO-4 Operational Technology Terrain1 techniqueTo stop operational technology being scored as though it were a server estate, and to make the connections between the two declarable.
  • ID-2 Credential Strength and Binding1 techniqueTo ensure the credential is as strong as the access behind it, so that proofing and authentication assurance are matched rather than assumed.
  • ID-5 Authorization Decision Integrity1 techniqueTo ensure the policy that governs movement is actually consulted and cannot be altered without trace.
  • KT-1 Decisive Point Identification1 techniqueTo concentrate defensive effort on the small number of elements whose loss is decisive, so that priority is a stated judgment rather than an emergent property of the asset register.
  • LC-2 Component Provenance1 techniqueTo know where deployed components came from and what is inside them, so that a compromise disclosed anywhere can be located here.
  • LC-4 Update Integrity and Staging1 techniqueTo limit the blast radius of a compromised trusted update, so that supply chain compromise reaches a ring rather than the estate.
  • SM-5 Branches and Sequels1 techniqueTo decide contingency responses before contact, so that the decision loop under pressure is a selection rather than a design exercise.
  • SM-6 Maneuver Effectiveness Validation1 techniqueTo replace assumed effectiveness with demonstrated effectiveness, so the coverage figure reflects what controls do rather than what was assumed of them.
  • TM-2 Defensive Layer Classification1 techniqueTo make posture summable and comparable by layer, and to force an explicit ownership decision for every element.
  • TM-3 Asset Weighting1 techniqueTo convert an undifferentiated inventory into a priority order, so that coverage figures carry meaning and investment can be argued from mission consequence.
  • TM-5 Connection and Denied-Path Register1 techniqueTo record connectivity as three distinct states — permitted, denied, unknown — so that reachability conclusions rest on tested denials rather than on absence of evidence.
  • WF-2 Privileged Human Register1 techniqueTo ensure privilege is held by accountable people, so that every privileged action has a person behind it.
  • WF-3 Role-Based Readiness1 techniqueTo prepare people for the attacks their role attracts, and to know whether the preparation worked.

Reachability analysis is the honest test: not how many controls exist, but how many independent ones an adversary must defeat to touch the objective. The control-failure and coverage controls test whether a defeated layer is detectable. No control tests for correlated failure across layers; that has to be argued in the scheme and reviewed by a human.

Sequencing

A scheme names a sequence, not a set. These are the ordinary neighbors of this form — not a mandatory order, but the order in which each one’s preconditions are usually met.

Typically Preceded By

Typically Followed By

Named as a successor by M1 Screen / Guard, M9 Spoiling Attack, M10 Exploitation & Pursuit, M11 Reconstitution. Derived from those forms’ own declarations, so the two directions of the sequence cannot disagree.

Named as a predecessor by M3 Envelopment, M4 Obstacle / Canalization. Derived the same way, from the other direction.