ASOM-Fedv6.1Open the explorer
Policy · Office of Management and Budget · 2022

Moving the U.S. Government Toward Zero Trust Cybersecurity Principles

The federal zero-trust strategy memorandum: specific end states across identity, devices, networks, applications and data, with dates attached and an agency implementation plan required against them.

5/5Obligations addressedEvery one of them carries a stated gap; none of them is claimed as satisfied.
20Controls carrying itEach with an evidence artifact and an assessment procedure
3Stated boundariesWhat this framework does not do for this regime
The Claim

What This Framework Contributes.

The memorandum states end states; this framework states whether you are positioned to reach them. It produces no implementation plan and meets no deadline.

The Boundary

What it does not do for OMB M-22-09.

Read this before the crosswalk, not after it. A reader who takes the mappings below as coverage of OMB M-22-09 will be wrong in a way that is expensive to discover later.

Obligation by Obligation

5 elements, each with what is missing.

OMB M-22-09 publishes no control-level index for a catalog to be turned round against, so these edges are authored rather than derived. Each one is stated as a citation and resolved against the real catalog when the site is built: the prose can go stale, the links cannot go dead.

Identity

4 controls · T1 Identity

Agency staff use enterprise-managed identities to access the applications they use in their work, and phishing-resistant multifactor authentication protects them from sophisticated online attacks.

What the framework supplies

Phishing-resistant authentication is a rung on a sub-tower ladder with an observable attached, and the policy decision point that enforces it is designated as key terrain with a protection floor.

What it does not

The memorandum requires an enterprise identity system and a plan to reach it. The framework measures the position; it does not procure, deploy or plan the migration.

Devices

4 controls · T2 Devices

The agency maintains a complete inventory of every device it operates and authorizes for government use, and can prevent, detect and respond to incidents on those devices.

What the framework supplies

Managed and unmanaged devices are scored as different ground rather than averaged together, and terrain currency is what stops the inventory being complete only on the day it was built.

What it does not

Endpoint detection deployment, and the visibility the memorandum asks agencies to give CISA, are outside the framework entirely.

Networks

4 controls · T3 Networks

Agencies encrypt DNS and HTTP traffic, and work toward breaking down perimeters into isolated environments.

What the framework supplies

Segmentation is assigned to specific ground and tracked to an implementation state, and barrier sufficiency asks the question that matters — whether the segment actually stops the movement it was built to stop.

What it does not

Encryption of DNS and HTTP traffic is an engineering program with a deadline. The framework can say what is exposed and what it costs positionally; it cannot deliver the encryption.

Applications and workloads

4 controls · T4 Applications and Workloads

Agencies treat all applications as internet-connected, routinely subject them to rigorous empirical testing, and welcome external vulnerability reports.

What the framework supplies

Reachability assessment is empirical testing aimed at the question the memorandum is really asking — whether the application can be reached from outside the assumption that protects it.

What it does not

A vulnerability disclosure policy, an external reporting channel and the requirement to expose an internal application to the public internet are all agency actions the framework neither performs nor tracks.

Data

4 controls · T5 Data

Agencies are on a clear, shared path to deploy protections that make use of thorough data categorization, and take advantage of cloud security services to monitor access to their sensitive data.

What the framework supplies

Data is weighted rather than merely classified, and privacy and controlled-unclassified holdings are put on the map as terrain with an authority attached rather than tracked as a register.

What it does not

Enterprise data categorization, logging maturity against the logging memorandum, and the cloud monitoring services themselves are outside the framework’s scope.

Authored edges, derived resolution. Each goal area cites a terrain layer and control ids; the sub-towers, their maturity ladders and the controls are read from the terrain reference and the catalog. What the framework takes from this source and what it declines to take is set out in sources and provenance; the controls named on this page each carry their full lineage on their own sheet.