ASOM-Fedv6.1Open the explorer
Reference manual · intelligence requirements

A Question with No Decision Attached Is Not a Requirement.

The cycle opens with Priority Cyber Intelligence Requirements. The Frame step produces an intent paragraph and a PCIR list and nothing else; hunts are triggered by them; the fused assessment at the end of the loop is confidence about one. Everything downstream of Frame is shaped by what was asked at the top of it — and a program handed “set your intelligence requirements” with no worked examples will write topics. This is the library that was missing: 23 requirements written out in full, the four ways the practice fails, and a bad one rewritten into a good one in front of you.

23Worked requirementsEach with a decision, two branches, and a retirement test
10/10Terrain layers touchedCounted from the requirements, not asserted above them
70Controls cross-referencedAcross all 14 control families
6On the worked cycle slateBecause 23 in one cycle is a wish list
What a Requirement Is

The Rule Is One Sentence, and Almost Every Bad PCIR Fails It.

The governing control states it plainly: set requirements as questions with a decision attached, and if no decision changes on the answer, it is not a requirement. It is easy to agree with and hard to apply, because the questions that fail it are usually the most interesting ones in the room.

If no decision changes on the answer, it is not a requirement.

The practical test is to write both branches before the requirement is accepted: what is done if the answer comes back one way, and what is done if it comes back the other. If the two branches end in the same action, the question is a topic wearing a question mark. Every entry in this library carries both branches for exactly that reason — the claim is checkable rather than asserted, and the data module refuses to build if a requirement’s two branches ever say the same thing.

Exhibit 1

The Anatomy of a Requirement: Seven Parts, Each with the Test It Has to Pass

  1. 01

    The question

    It is interrogative, bounded in scope and time, and could be answered with evidence you could put on a slide.

    Arrives as

    Ransomware risk to the agency.

    Should read

    Is any host in the mission tier showing the pre-encryption sequence in the last seven days?

  2. 02

    The decision

    A named choice that changes on the answer, with both branches written out. If both branches say the same thing, delete the requirement.

    Arrives as

    To improve our understanding of the threat.

    Should read

    Whether to declare Phase III on the affected service and open the wider pre-authorized fire set, or hold at Phase II.

  3. 03

    The decision-maker

    One role, named, who is actually in a position to take that decision this cycle.

    Arrives as

    Leadership.

    Should read

    The Authorizing Official, who is the only role that can widen the pre-authorized set.

  4. 04

    The indicators

    Observables specific enough that a collector could recognize one at 03:00 without asking what was meant.

    Arrives as

    Suspicious activity.

    Should read

    Shadow-copy deletion, backup-agent service stops, and mass credential access clustered within one hour on one host.

  5. 05

    The collection

    Named sources with owners. If no source you have can produce the indicator, the honest output is a collection gap, not a requirement.

    Arrives as

    Threat intelligence.

    Should read

    EDR process telemetry, backup platform audit log, identity provider sign-in log.

  6. 06

    The assignment

    Exactly one named collector or hunter owns it. Two owners is zero owners, and "the SOC" is not a name.

    Arrives as

    SOC and CTI.

    Should read

    The hunt lead, with the SOC duty analyst as the collector of record for the EDR pull.

  7. 07

    The retirement test

    A condition, not a date. State what would have to be true for this to stop being asked.

    Arrives as

    Ongoing.

    Should read

    Retires on the phase decision — answered when the phase is declared or the sequence is attributed to an administrative action.

The bad column is not a straw man. Each of those is a real shape a requirement arrives in, and each one passes a casual read.
Single cycle13 in this library

Asked once, answered once, retired. The default, and the shape a requirement should be forced into unless there is a reason it cannot be.

Re-asked each cycle7 in this library

The same question, a fresh answer, a fresh record every cycle. This is NOT standing monitoring: a decision is taken on each answer, and the answer is written down whichever way it comes out. Reachability is the archetype — the control that governs it requires the result recorded each cycle, including when the result is bad.

Runs past this cycle3 in this library

Expected to take more than one cycle to answer. Must be carried forward explicitly at cycle close, with the reason it is still open. A multi-cycle requirement that is never re-stated is how a list silently doubles in length.

The library · 23 requirements

Worked Requirements, Grouped by the Kind of Decision They Serve.

Grouped by decision rather than by the team that answers them. Grouping by team is how one requirements list becomes six parallel backlogs that never meet; grouping by decision keeps the commander’s question in front of the collector.

Threat and intent

Who is working against this estate, what can they do, and what are they about to do?

4 requirements

The band most likely to be written as a topic, because the subject matter is genuinely interesting and interest is not a decision.

PCIR-01

Which actor sets currently naming our mission sector have demonstrated, in the last 90 days, tradecraft that defeats phishing-resistant MFA — and against which of our identity paths?

The decision it informs

Whether to close the conditional-access exception list this cycle, which will break at least two legacy integrations, or hold it open and carry the residual explicitly.

  • If: Demonstrated against a path we run.Close the exception list this cycle, accept the integration breakage, and designate Envelopment the main effort.
  • If: Demonstrated only against paths we do not run.Hold the exception list open, record the residual against the identity decisive point, and re-ask next cycle.

Decided by Authorizing Official / CISO · answered by Cyber Threat Intelligence cell

Indicators that would answer it
  • Token replay from a session bound to no known device
  • Adversary-registered OAuth application consent grants on mission-staff accounts
  • Helpdesk-mediated authenticator resets on privileged accounts outside the normal rate
  • Sector reporting naming an adversary-in-the-middle proxy kit against a provider we use
Collection
  • Identity provider sign-in and token-issuance telemetry
  • Identity provider risk detections
  • Sector ISAC reporting
  • CISA advisories and joint cybersecurity advisories
Retires when Single cycle

Retires when the exception list is closed or the residual is formally dispositioned. The decision retires it whichever way it goes — that is the point of attaching one.

PCIR-02

Which of our suppliers holding production access has had a credential or build-system compromise disclosed since the last cycle, and does that supplier’s update path reach production without passing a staging gate?

The decision it informs

Whether to sever or constrain that supplier’s access now, at the cost of a release slip, or to route their updates through the staging gate and keep the release date.

  • If: Compromised, and the path is ungated.Exercise the severance capability on that supplier, and treat the ungated path itself as a finding rather than an incident detail.
  • If: Compromised, but the path is gated.Hold access, raise the staging scrutiny for that supplier’s artifacts, and record the gate as the reason the answer did not force a severance.

Decided by Authorizing Official / CISO · answered by Cyber Threat Intelligence cell

Indicators that would answer it
  • Supplier breach notification received under the contract clause
  • Signed artifacts arriving from a publisher certificate not previously seen
  • Update packages delivered outside the agreed change window
  • Bill-of-materials diff showing components with changed provenance
Collection
  • Contractual supplier notification returns
  • Vendor and CISA advisories
  • Software bill-of-materials differencing
  • Update staging and artifact registry logs
Retires when Single cycle

Retires when the named supplier’s update path is recorded as either gated or severed. Retire on the register entry, not on the vendor’s reassurance.

PCIR-03

Is any host in the mission tier showing the pre-encryption sequence — shadow-copy deletion, backup-agent tampering, mass credential access — and has it touched a system inside the statutory availability set?

The decision it informs

Whether to declare Phase III on the affected mission service and open the wider pre-authorized fire set, or hold at Phase II and contain quietly without the service-affecting authorities.

  • If: Sequence present and it has touched the availability set.Declare Phase III against that service’s scope, open the wider pre-authorized set, and shift the cycle cadence to the contact tempo.
  • If: Sequence present but confined outside the availability set.Hold at Phase II, contain under the standing authorities, and keep the statutory floor out of the decision entirely.

Decided by Authorizing Official / CISO · answered by SOC / Defensive Operations

Indicators that would answer it
  • Volume shadow copy deletion, or backup agent services stopped on a production host
  • Sudden single-host spike in SMB share enumeration across the mission tier
  • Credential-access detections clustered within one hour on one host
  • Backup job failures that begin at the same host and spread
Collection
  • EDR process and command-line telemetry
  • Backup platform audit logs
  • Identity provider authentication logs
  • Host and file-share access logs on the availability set
Retires when Single cycle

Retires on the phase decision — answered when the phase is declared, or when the sequence is attributed to an administrative action and that attribution is recorded. It must not survive the cycle unanswered.

PCIR-04

Which domains, certificates and public accounts impersonating this agency appeared in the last cycle, and is any of them already sending mail to our workforce or to the public we serve?

The decision it informs

Whether this cycle’s takedown and pre-emptive-block effort goes to the impersonation set, or stays on the phishing infrastructure already in contact. The team can work one at a time.

  • If: Impersonation infrastructure is live and already delivering.Spoil it — pre-emptively block and pursue takedown, and warn the public channel before the first report arrives.
  • If: Registered but dormant.Watchlist it, keep the effort on infrastructure in contact, and record the dormant set so the next cycle does not rediscover it.

Decided by Cyber Threat Intelligence cell · answered by Cyber Threat Intelligence cell

Indicators that would answer it
  • Newly registered lookalike domains that resolve to live hosts
  • Certificate transparency entries for names resembling agency services
  • Inbound mail from a lookalike domain reaching a mailbox
  • Public reports of impersonation through the agency contact channel
Collection
  • Certificate transparency logs
  • Domain registration feeds
  • Mail gateway telemetry
  • The public contact channel’s report queue
Retires when Re-asked each cycle

Retires each cycle on a dispositioned list: every live impersonation taken down, pre-emptively blocked, or accepted with a stated reason. Retire on the disposition, never on the takedown request being filed.

Terrain truth

Is the ground where we think it is, and do we hold what the register says we hold?

5 requirements

Unglamorous, and consistently the band that changes the most decisions. A scheme arrayed on a stale overlay is arrayed on fiction.

PCIR-05

Which internet-reachable services do we own that are absent from the terrain register, and which of them terminate inside the mission tier?

The decision it informs

Whether this cycle’s main effort is terrain currency rather than any form of maneuver at all — you cannot array a scheme against ground you have not mapped.

  • If: Unregistered services exist and terminate in the mission tier.Make terrain currency the main effort, stand the scheme down to holding, and do not array until the register closes.
  • If: Unregistered services exist only in the public tier.Assign them owners inside the cycle, keep the planned main effort, and raise the discovery rate as a currency metric rather than an incident.

Decided by Authorizing Official / CISO · answered by Platform and product owners

Indicators that would answer it
  • External enumeration results with no matching entry in the terrain register
  • Certificate transparency entries for agency domains with no recorded owner
  • Cloud accounts or subscriptions outside the declared tenancy boundary
  • DNS records pointing at hosts nobody in the platform group claims
Collection
  • External attack-surface enumeration
  • Certificate transparency logs
  • Cloud provider inventory APIs
  • Authoritative DNS zone exports
Retires when Runs past this cycle

Retires when every discovered service has a recorded owner or has been withdrawn. The retirement test is a count reaching zero, not a count reducing — "fewer unowned services" is a status update, not an answer.

PCIR-06

Which accounts can cross the OT/IT boundary today, and which of those are also used for routine IT work?

The decision it informs

Whether to split the crossing accounts this cycle, which costs an engineering change window, or to accept them and compensate with passive monitoring on the boundary.

  • If: Crossing accounts are shared with routine IT use.Split them this cycle and take the change window; a shared crossing account makes the boundary a formality.
  • If: Crossing accounts are dedicated and time-bounded.Accept, and spend the cycle instead on the passive monitoring that would show the boundary being used unexpectedly.

Decided by Platform and product owners · answered by Platform and product owners

Indicators that would answer it
  • One account authenticating to an engineering workstation and a general IT service within the same window
  • Shared service accounts holding rights on both sides of the boundary
  • Local accounts on OT assets that appear in no register
  • Remote access sessions into the OT segment originating from general user subnets
Collection
  • OT asset inventory
  • Passive OT network monitoring
  • Identity provider sign-in logs
  • Engineering workstation authentication logs
Retires when Single cycle

Retires when the crossing set is fully enumerated and every account in it is split, time-bounded, or recorded as an accepted exception with a named owner.

PCIR-07

Do the humans holding privilege today match the privileged human register, and how long does the gap persist after a separation?

The decision it informs

Whether separation tempo is recorded as an assessed gap that gates the next authorization decision, or reported as within threshold and left alone.

  • If: The gap persists beyond the stated revocation window.Record it as an assessed gap, gate the next authorization on it, and put the remediation on the backlog with a date.
  • If: Reconciliation is clean and revocation is inside the window.Report within threshold and stop collecting — a clean answer should reduce the next cycle’s load, not become a standing report.

Decided by Governance / RMF / ISSO · answered by Governance / RMF / ISSO

Indicators that would answer it
  • Accounts still authenticating after the recorded separation date
  • Privilege grants with no corresponding register entry
  • Elapsed time between the HR separation record and the last successful authentication
  • Privileged access checkouts by identities not on the register
Collection
  • HR separation feed
  • Identity provider entitlement export
  • Privileged access management checkout logs
  • The privileged human register itself
Retires when Re-asked each cycle

Retires when the reconciliation runs clean twice in succession. One clean run is a coincidence; the second is the evidence.

PCIR-08

Which vendor and maintenance identities held physical access to space containing production systems in the last quarter, and was any of that access unescorted or unlogged?

The decision it informs

Whether to re-badge and re-scope maintenance access before the next scheduled data-center work order, or proceed under the current arrangements.

  • If: Access occurred outside a work order, or with no escort record.Re-badge and re-scope before the next work order, and treat the missing escort records as a control failure rather than an administrative lapse.
  • If: Every access event reconciles to a work order with a named escort.Proceed as arranged, and reduce the review to sampling rather than a full quarter.

Decided by Platform and product owners · answered by Governance / RMF / ISSO

Indicators that would answer it
  • Badge events in production zones outside work-order windows
  • Work orders with no corresponding escort sign-in
  • Door-held-open events in zones containing production systems
  • Contractor badges active past the contract end date
Collection
  • Physical access control system logs
  • The work-order and change system
  • Escort sign-in records
  • Facility zone definitions in the terrain register
Retires when Single cycle

Retires when every access event in the review window reconciles to a work order with a named escort, or the exceptions are dispositioned with a decision recorded against each.

PCIR-09

Of the record sets we designate crown jewels, which can be read today by an identity outside the data-access governance boundary?

The decision it informs

Whether to tighten the governance boundary this cycle — which will break at least one reporting workflow the mission depends on — or accept it and instrument the out-of-boundary reads.

  • If: Out-of-boundary identities can read a crown-jewel set.Tighten the boundary, take the reporting breakage, and give the affected workflow a sanctioned path inside the boundary.
  • If: Only sanctioned identities can read it.Accept, and spend the effort instead on detecting a change to the boundary rather than re-proving its current state.

Decided by Authorizing Official / CISO · answered by Platform and product owners

Indicators that would answer it
  • Read events on sensitive stores from principals outside the governance boundary
  • Service accounts holding standing read on a crown-jewel set
  • Export or reporting jobs writing to destinations of lower classification
  • Records leaving the boundary in volumes inconsistent with the workflow that requested them
Collection
  • Data platform audit logs
  • The data-access governance catalog
  • Data loss prevention telemetry
  • Controlled unclassified information handling attestations
Retires when Runs past this cycle

Retires when the out-of-boundary principal list is empty, or every entry on it carries a dated exception with an owner. Retire on the list, not on the remediation project reaching a milestone.

Reachability

From where an adversary can stand today, can they get to what matters — and by which route?

3 requirements

These are the requirements that decide where the next barrier goes. They compete for one engineering budget, so the answer has to be comparative.

PCIR-10

From the declared threat-actor positions, can any of them reach the build and deployment pipeline on permitted paths — and if so, what is the shortest such path?

The decision it informs

Whether the next barrier investment goes to the pipeline or to the identity plane. Both are decisive points, both are asking, and only one can be funded this quarter.

  • If: Reachable, and the shortest path is short.Fund the pipeline barrier, and make the shortest path itself the named remediation target rather than "pipeline hardening".
  • If: Not reachable on permitted paths.Fund the identity plane instead, and record precisely which denied paths are carrying the result so barrier sufficiency can test them.

Decided by Authorizing Official / CISO · answered by Platform and product owners

Indicators that would answer it
  • A permitted path from a declared actor position to a pipeline component
  • Service principals holding both repository write and deployment rights
  • Build runners reachable from a general user segment
  • Pipeline secrets retrievable by an identity that is not itself a pipeline component
Collection
  • The connection and denied-path register
  • Pipeline platform IAM export
  • Segmentation and firewall policy export
  • Reachability analysis output
Retires when Re-asked each cycle

Retires each cycle on the recorded result. This one is re-asked by construction — the governing control requires the answer written down every cycle, including when the answer is that the point is reachable.

PCIR-11

Which paths cross from the public tier into the mission tier without traversing a policy enforcement point, and which of those carry management protocols?

The decision it informs

Whether the next segmentation obstacle is emplaced at the east–west boundary or at the egress boundary. One can be funded and staffed this cycle.

  • If: Unenforced crossings exist and carry management protocols.Emplace at the east–west boundary; a management protocol crossing an unenforced tier boundary is the shortest route an adversary will ever be handed.
  • If: Crossings exist but carry only application traffic already brokered elsewhere.Emplace at the egress boundary instead, and add the crossings to the register so the next cycle does not re-discover them as new.

Decided by Platform and product owners · answered by SOC / Defensive Operations

Indicators that would answer it
  • Flows observed between tiers that appear in no permitted-path register entry
  • RDP, SSH or WinRM sessions crossing the tier boundary
  • Cloud peering or route table entries added outside change control
  • Enforcement points bypassed by a route with a longer prefix match
Collection
  • Flow telemetry — NetFlow and cloud VPC flow logs
  • Firewall and microsegmentation policy exports
  • Cloud routing tables
  • Change records for network configuration
Retires when Single cycle

Retires when the unregistered crossing set is either registered with an owner or blocked, with management protocols specifically at zero. Partial closure does not retire it.

PCIR-12

Can a self-registered public-portal identity reach any internal service other than the portal’s own API, directly or by chaining through it?

The decision it informs

Whether the portal’s trust boundary stands as drawn in the next authorization package, or is re-scoped before that package is signed.

  • If: A chain exists to an internal service.Re-scope the boundary before signature, and treat the chain as the authorization package’s central finding rather than an appendix item.
  • If: No chain exists on permitted paths.Hold the boundary as drawn, and record the specific denials that are carrying it so a future change cannot remove one silently.

Decided by Governance / RMF / ISSO · answered by Platform and product owners

Indicators that would answer it
  • Portal service accounts holding scope beyond the portal API
  • Gateway routes reaching internal services without an authorization decision
  • A session or token store shared between the public and internal tiers
  • Internal service calls whose caller identity resolves to a self-registered principal
Collection
  • API gateway configuration export
  • Portal platform IAM export
  • Reachability analysis output
  • The current authorization boundary description
Retires when Single cycle

Retires on a recorded reachability result plus a signed boundary statement in the authorization package. The reachability answer alone does not retire it — the package has to carry it.

Tempo and decision time

Are we deciding and acting faster than the adversary is adapting?

4 requirements

The band a SOC finds most uncomfortable, because the answer is usually about the defender rather than the adversary.

PCIR-13

Across the last three contacts, how long did it take from first detection to first containment action — and which part of that interval consumed the time?

The decision it informs

Whether the next tempo investment goes to detection engineering or to widening the pre-authorized set. They buy different halves of the same interval, and buying the wrong half changes nothing.

  • If: Most of the interval was spent before triage began.Invest in detection engineering and alert routing; pre-authorization cannot help with time spent before anyone is looking.
  • If: Most of the interval was spent waiting for an approver.Widen the pre-authorized set with bounds, and record the blast radius accepted in exchange for the time bought.

Decided by Authorizing Official / CISO · answered by SOC / Defensive Operations

Indicators that would answer it
  • Timestamps at detect, triage, decision and act for each contact
  • Count of actions in each contact that waited on a named approver
  • Number of hand-offs between teams per contact
  • Elapsed time between the approval request and the approval, by hour of day
Collection
  • Case management timestamps
  • Orchestration and automation execution logs
  • Approval records in ticketing and chat
  • After-action reviews for the three contacts
Retires when Single cycle

Retires when the interval decomposition is recorded for three consecutive contacts. The requirement is about the measurement existing — not about the number being good, which is a different question with a different owner.

PCIR-14

What is our current estimate of adversary dwell before detection on the mission tier, and what is that estimate based on other than the intrusions we happened to find?

The decision it informs

Whether to fund a hunt campaign aimed specifically at the blind interval, or to carry the current estimate into the running estimate as stated.

  • If: The estimate rests only on closed cases.Fund the hunt campaign against the interval the telemetry cannot see, because an estimate built from found intrusions cannot describe unfound ones.
  • If: The estimate rests on retention-bounded retro-hunting as well.Carry it into the running estimate with its stated confidence, and put the effort on extending retention where the horizon is shortest.

Decided by Authorizing Official / CISO · answered by Hunt team

Indicators that would answer it
  • Earliest evidence timestamp against detection timestamp across closed cases
  • Retention horizon per log source, against the estimated dwell
  • Hunt findings older than the detection horizon
  • Telemetry coverage gaps on the mission tier by asset class
Collection
  • Closed case records
  • Log retention configuration by source
  • Hunt case results
  • The telemetry coverage map
Retires when Runs past this cycle

Retires when the estimate carries a stated confidence and a stated basis under the fusion control. An estimate with no basis is not an answer, so this stays open until it has one.

PCIR-15

In the last cycle, which defensive actions did an operator want to take and not take, and what stopped them?

The decision it informs

Whether to extend the pre-authorized set and accept the blast radius, or keep the action behind an approver and fix the approver’s availability instead.

  • If: The operator was unsure of their mandate.Fix the rules of engagement and where they are published — this is a documentation failure appearing as a tempo failure.
  • If: The operator knew the mandate and could not reach the approver.Either pre-authorize with bounds, or name a deputy and test reaching them out of hours. Do not do both and call it defense in depth.

Decided by Authorizing Official / CISO · answered by SOC / Defensive Operations

Indicators that would answer it
  • Actions proposed and not executed, recorded in case notes
  • Time to reach an approver, by hour of day
  • Operator statements in after-action review naming a mandate question
  • Actions executed after the window in which they would have mattered
Collection
  • Case management records
  • After-action reviews
  • The rules-of-engagement record and its publication location
  • On-call roster and escalation test results
Retires when Re-asked each cycle

Retires each cycle when every hesitation is dispositioned — pre-authorized, bounded, or explicitly left behind an approval — and the rules-of-engagement record carries the date of that disposition.

PCIR-16

Has anything touched the deception grid this cycle — and if nothing has, is that because nothing is here, or because the grid is sited where nobody walks?

The decision it informs

Whether to re-site the deception grid onto the avenues that reachability analysis says are live, or to leave it in place and read the silence as evidence of absence.

  • If: The grid does not sit on the enumerated avenues.Re-site it, and stop treating its silence as a negative result until it does.
  • If: The grid sits on the avenues and is still silent.Record the silence as a genuine negative with its coverage stated, and let it raise confidence in the absence of contact.

Decided by Hunt team · answered by Hunt team

Indicators that would answer it
  • Canary token triggers by location and by decoy type
  • Grid coverage measured against the current avenue-of-approach list
  • Time since the last grid interaction, per decoy
  • Ratio of decoys that would look plausible to an adversary who had already read the estate
Collection
  • Canary and decoy telemetry
  • Avenue of approach analysis output
  • Hunt case results
  • The deception grid inventory
Retires when Re-asked each cycle

Retires each cycle when the grid’s siting has been reconciled against the current avenue list. Silence with no siting check is not an answer, and recording it as one is how a deception program quietly stops working.

Consequence and reconstitution

If they reach the objective, what breaks, and can we rebuild it on evidence rather than hope?

3 requirements

Answered by exercise results, never by policy statements. A recovery requirement satisfied by a document has not been answered.

PCIR-17

For the mission service with the shortest statutory availability floor, can we rebuild it from an isolated copy inside its stated recovery objective — measured, not asserted?

The decision it informs

Whether to declare the recovery objective met in the next authorization package, or to restate the objective to a number we can actually hit.

  • If: The measured rebuild fits inside the objective.Declare it met, and cite the exercise record rather than the policy statement.
  • If: The measured rebuild exceeds the objective.Restate the objective to the measured figure and record the gap against the statutory floor. An objective nobody can meet protects nothing.

Decided by Authorizing Official / CISO · answered by Platform and product owners

Indicators that would answer it
  • Measured rebuild time in the last reconstitution exercise
  • Integrity verification result on the restored copy
  • Count of dependencies unavailable during the rebuild
  • Whether the isolated copy was reachable from the environment being rebuilt
Collection
  • Reconstitution exercise records
  • Backup integrity verification logs
  • The service dependency map
  • The statutory availability determination for the service
Retires when Single cycle

Retires on a completed exercise with a measured time and a verified integrity result. An untested assertion, however senior the person making it, does not retire this.

PCIR-18

If the build pipeline is the thing that is compromised, what do we rebuild from — and has that path been exercised without the pipeline?

The decision it informs

Whether to stand up an out-of-band build path this cycle, or accept a rebuild dependency on the one system we may specifically have to distrust.

  • If: No path exists that does not traverse the pipeline.Stand up the out-of-band path this cycle; every other recovery number on the page is conditional on it.
  • If: A signed, pipeline-independent path exists and has been exercised.Accept, and move the effort to the provenance of the base images that path depends on.

Decided by Platform and product owners · answered by Platform and product owners

Indicators that would answer it
  • Existence of a signed golden image held outside the pipeline
  • Date of the last rebuild exercised without the pipeline
  • Provenance records for the base images used in that rebuild
  • Whether the signing keys are recoverable independently of the pipeline
Collection
  • Reconstitution exercise records
  • Artifact registry provenance data
  • Image and package signing records
  • Key management system records
Retires when Single cycle

Retires when a rebuild has been completed once without the pipeline and the artifacts’ provenance is recorded. Once is enough to retire it; zero is not.

PCIR-19

Have we evicted this intrusion set, or only interrupted it — and what evidence would distinguish the two?

The decision it informs

Whether to transition from Dominate to Stabilize, or hold the phase and keep the wider authorities open at the cost of continued disruption.

  • If: Persistence or re-entry is found after the containment action.Hold the phase, keep the authorities open, and treat the containment as the start of the eviction rather than the end.
  • If: A stated observation window passes with no new indicators against the set’s tradecraft.Transition to Stabilize with the confidence level and the window length both recorded.

Decided by Authorizing Official / CISO · answered by Hunt team

Indicators that would answer it
  • Persistence mechanisms found after the containment action
  • Re-authentication from infrastructure previously attributed to the set
  • Identical tradecraft appearing on a host not in the original scope
  • Absence of new indicators across a stated, bounded observation window
Collection
  • Hunt sweeps against the intrusion set’s tradecraft
  • EDR retrospective search across the retention horizon
  • Identity provider telemetry
  • Egress and DNS resolution records
Retires when Single cycle

Retires on the phase transition decision, recorded with an explicit confidence. Retiring it on the absence of alerts alone is precisely the failure this requirement exists to prevent.

Obligation and authority

What are we required to do, what may we do without asking, and who says so?

4 requirements

These gate maneuver. An unanswered authority requirement shows up later as an operator hesitating under contact.

PCIR-20

Which record sets inside the affected scope hold personally identifiable or controlled unclassified information, and does the current containment plan create a notification obligation its authors have not seen?

The decision it informs

Whether containment proceeds as designed, or is re-sequenced to preserve evidence and bound exposure — and whether the privacy function is brought in now rather than at the end.

  • If: Regulated records are in scope and an export is evidenced.Re-sequence containment to preserve the evidence the determination will need, and start the obligation clock deliberately rather than discovering it later.
  • If: Regulated records are in scope but only access, not export, is evidenced.Proceed with containment as designed, and record the access-versus-export distinction with the evidence that supports it.

Decided by Governance / RMF / ISSO · answered by Governance / RMF / ISSO

Indicators that would answer it
  • Classification of the data stores inside the affected scope
  • Volume of records accessible from the compromised position
  • Evidence of export or staging versus evidence of access alone
  • Handling attestations for controlled unclassified information in scope
Collection
  • The data catalog and its classification
  • Data loss prevention and data-access logs
  • The privacy terrain register
  • Egress records for the affected period
Retires when Single cycle

Retires when the affected scope’s classification is recorded and the obligation determination is made and dated by the accountable authority. The determination retires it; the incident closing does not.

PCIR-21

For the mission services running in shared tenancy, which controls are we inheriting rather than operating, and has the provider’s latest attestation actually changed scope?

The decision it informs

Whether to keep claiming inheritance in the authorization package, or to stand up a compensating control before the next authorization decision.

  • If: The attestation no longer covers our deployment as configured.Stand up the compensating control before the package is signed, and record the inheritance claim as withdrawn rather than quietly unchanged.
  • If: The attestation covers the deployment as configured.Keep the claim, and record the attestation date so the next cycle checks the date rather than re-reading the report.

Decided by Governance / RMF / ISSO · answered by Governance / RMF / ISSO

Indicators that would answer it
  • Attestation date and scope against our actual deployment configuration
  • Delta between the attested service boundary and the services we consume
  • Controls marked inherited with no evidence artifact behind them
  • Provider-side changes announced but not assessed on our side
Collection
  • Provider attestations and third-party audit reports
  • The control inheritance mapping
  • Tenancy configuration export
  • Provider change notifications
Retires when Re-asked each cycle

Retires each cycle when every inherited control carries a dated attestation covering the actual deployment, or a compensating control is recorded against it.

PCIR-22

If we had to take a public-facing mission service offline to contain an intrusion, who can order that today, how long would reaching them take out of hours, and is that written where operators work?

The decision it informs

Whether to pre-authorize the service-degrading action with explicit bounds, or to build an out-of-hours escalation path with a stated ceiling on time-to-decision.

  • If: No named approver is reachable inside the containment window out of hours.Pre-authorize with bounds — scope, duration, and the conditions under which it does not apply — and require after-the-fact review of every use.
  • If: A named approver and deputy are reachable inside the window.Keep the approval, publish the names where operators work, and re-test reachability rather than re-litigating the authority.

Decided by Authorizing Official / CISO · answered by SOC / Defensive Operations

Indicators that would answer it
  • A named approver and a named deputy in the rules-of-engagement record
  • Measured time to reach either in the last out-of-hours escalation test
  • Whether operators can find the record without asking a colleague
  • Cases where an out-of-hours contact waited on an authority question
Collection
  • The rules-of-engagement record
  • On-call roster and escalation test results
  • Operator interviews and after-action reviews
  • Case records from out-of-hours contacts
Retires when Single cycle

Retires when the record names an approver and a deputy, a timed out-of-hours test has been run, and the record is reachable from the operator’s console. All three, because any two of them fail under contact.

PCIR-23

Which of the threat courses of action carried into this cycle is still the most dangerous — or has a change in our own estate made the most likely one worse?

The decision it informs

Whether to re-array the scheme against a different course of action, or hold the current array and spend the cycle executing rather than replanning.

  • If: An estate change has shortened the most likely path.Re-array against it, re-designate the main effort, and record what changed in the estate rather than in the intelligence.
  • If: Neither course of action has moved.Hold the array and spend the cycle executing. Replanning against unchanged conditions is the most expensive way to look busy.

Decided by Authorizing Official / CISO · answered by Cyber Threat Intelligence cell

Indicators that would answer it
  • A newly exposed service in the terrain register that shortens the most likely path
  • A decisive point whose independent barrier count has fallen since last cycle
  • Sector reporting showing a shift in actor objectives against this mission type
  • Hunt findings inconsistent with the assumptions the current array rests on
Collection
  • Terrain overlay differences since the last cycle
  • The connection and denied-path register
  • Hunt case results
  • Sector and commercial threat reporting
Retires when Re-asked each cycle

Retires at the close of the Array step when the scheme is signed. It is re-asked next cycle from scratch — which is a different thing from being carried forward unanswered.

Coverage

Whether the Library Really Spans the Ground, Computed from the Library.

“Spanning the terrain layers and the campaign phases” is a claim, and a claim on this site has to be computed from the thing it describes. If a layer or a phase ever falls to zero, this section prints the gap instead of the boast.

Exhibit 2

Terrain Layers, and the Requirements Standing on Each

All 10 layers carry at least one requirement. Counts are the number of requirements that name the layer, so they sum past 23 — most requirements stand on more than one.
Exhibit 3

Campaign Phases

  • 0Shape15
  • IDeter13
  • IISeize Initiative11
  • IIIDominate7
  • IVStabilize4
  • VEnable / Restore4
Every phase is represented. A phase with no requirement is a phase nobody is collecting against.
Exhibit 4

Forms of Maneuver the Answers Select

Every form appears. A requirement names a form when the answer commits to it or chooses between it and another — not merely when the form is topically related.
Control families drawn on
  • TM · 6
  • KT · 5
  • SM · 5
  • TA · 5
  • CE · 5
  • CG · 5
  • RC · 5
  • FO · 5
  • WF · 4
  • FC · 4
  • LC · 5
  • ID · 5
  • EN · 6
  • DV · 5

70 distinct controls across all 14 families. The requirements were written first and the distribution counted afterwards, which is why it is uneven: the terrain families carry the most, because most decisions turn on whether the ground is where the register says it is.

Sizing

This Is a Library. A Cycle Takes Six of It.

The most common way a PCIR practice dies is not a bad question — it is twenty good ones. Publishing a long library without publishing the sizing rule would be handing over the failure mode alongside the cure.

The whole library, run at once, puts 7 requirements on Platform and product owners alone. That is not a heavy quarter; it is an unanswerable fortnight. The rule below sizes against the collectors who exist rather than the questions that are interesting, and the worked slate shows what survives it.

Exhibit 5

A worked Phase II slate: 6 requirements, 4 collectors

On the slate
  1. PCIR-03Is any host in the mission tier showing the pre-encryption sequence — shadow-copy deletion, backup-agent tampering, mass credential access — and has it touched a system inside the statutory availability set?Answered by SOC
  2. PCIR-10From the declared threat-actor positions, can any of them reach the build and deployment pipeline on permitted paths — and if so, what is the shortest such path?Answered by PLAT
  3. PCIR-12Can a self-registered public-portal identity reach any internal service other than the portal’s own API, directly or by chaining through it?Answered by PLAT
  4. PCIR-13Across the last three contacts, how long did it take from first detection to first containment action — and which part of that interval consumed the time?Answered by SOC
  5. PCIR-16Has anything touched the deception grid this cycle — and if nothing has, is that because nothing is here, or because the grid is sited where nobody walks?Answered by HUNT
  6. PCIR-23Which of the threat courses of action carried into this cycle is still the most dangerous — or has a change in our own estate made the most likely one worse?Answered by CTI

Six requirements, four distinct collectors, two apiece at most, one cycle. The slate is built around one decision the Authorizing Official has to take this cycle — where the next barrier goes — plus the contact questions that would override it. Every item can be answered from telemetry the agency already holds, which is the test that keeps a slate from quietly becoming a research program.

  • CTI · 1
  • SOC · 2
  • HUNT · 1
  • PLAT · 2
Deliberately left off, and why
  • PCIR-05Which internet-reachable services do we own that are absent from the terrain register, and which of them terminate inside the mission tier?The unregistered-service question is genuinely important and cannot be answered inside one cycle. It runs as a multi-cycle requirement with its own carry-forward, not as a slate item that will be reported "in progress" six times.
  • PCIR-17For the mission service with the shortest statutory availability floor, can we rebuild it from an isolated copy inside its stated recovery objective — measured, not asserted?The recovery objective can only be answered by an exercise, and no exercise is scheduled inside this cycle. Putting it on the slate would guarantee an unanswered requirement, which is worse than not asking.
  • PCIR-08Which vendor and maintenance identities held physical access to space containing production systems in the last quarter, and was any of that access unescorted or unlogged?Facilities access is on a quarterly review rhythm. Asking it here would collect an answer nobody is positioned to act on until the next work order.
  • PCIR-14What is our current estimate of adversary dwell before detection on the mission tier, and what is that estimate based on other than the intrusions we happened to find?Dwell estimation and the deception-grid question compete for the same hunt capacity, and the grid question decides whether this cycle can read silence as evidence at all. One of the two has to wait, and the slate says which rather than leaving the hunt lead to decide it by triage at week two.
  • PCIR-22If we had to take a public-facing mission service offline to contain an intrusion, who can order that today, how long would reaching them take out of hours, and is that written where operators work?The out-of-hours escalation test this depends on is scheduled after the cycle closes. Asking now would produce a partial answer that would be read as a full one, which is worse than not asking.
Scope: The public service portal and the case processing system it feeds.

The sizing rule

A slate is sized against collectors, not against ambition: no collector carries more than two, and nothing goes on it that cannot be answered from sources the agency already has. If the list is longer than the collectors can answer inside the cycle length, it is a wish list with a cover sheet.

Exhibit 6

Who Carries the Library, and Who Decides on It

Two different columns on purpose. The Authorizing Official decides on 13 of these and collects none of them, which is the correct shape: the role that can act on an answer is rarely the role that can obtain it.
How This Goes Wrong

Six Failures, and None of Them Is Caused by Carelessness.

Every failure below is produced by a reasonable act: adding a good question, wanting good monitoring seen, running out of time in the planning meeting. That is what makes them durable — nobody in the room is doing anything obviously wrong.

  1. Too many to answer in a cycle

    A list of twenty or thirty requirements opening a two-week cycle, most of them reported at close as "in progress" or "no update".

    Why it happens

    Nothing on the list is wrong, individually. Each was proposed by someone who cared about it, and there is no natural moment at which a good question gets refused. Lists grow by addition and shrink only by deliberate act.

    What it costs

    Collection is spread evenly instead of being concentrated, which is the exact failure the framework exists to correct on terrain and reproduces here on effort. The commander stops reading the list, and once it is unread the list stops steering anything.

    The test that catches it

    Divide the list by the number of named collectors. If any collector holds more than two, the list will not be answered.

    The fix

    Size against collectors, not ambition. Move what cannot be answered this cycle to a multi-cycle requirement with an explicit carry-forward, and delete what cannot be answered at all.

  2. A question with no decision attached

    "What is the current threat landscape for our sector?" — reasonable, answerable, and nothing changes when it is answered.

    Why it happens

    The question is genuinely interesting, and interest is easy to mistake for priority. It is also the easiest kind of requirement to write, because writing it costs nothing: no decision has to be identified and no one has to own the consequence.

    What it costs

    Collection effort is consumed producing material that is read and filed. Worse, the list now contains items that cannot be judged answered or unanswered, so the cycle-close review stops being a real review.

    The test that catches it

    Write both branches. If the action is the same whichever way the answer comes back, it is not a requirement.

    The fix

    Find the decision underneath the interest and ask about that instead. If there genuinely is not one, the material belongs in standing reporting, not on the requirements list.

  3. A requirement that is really standing monitoring

    "Monitor privileged account activity for anomalies." It has a subject, an owner, and no end. It will be on the list next year.

    Why it happens

    Monitoring and collection use the same verbs and the same telemetry, so the boundary is genuinely blurry from the inside. A team that has just built good monitoring naturally wants it visible somewhere that leadership reads.

    What it costs

    The list stops being a set of open questions and becomes an inventory of ongoing activity, which cannot be closed, cannot be sized, and cannot be prioritized. Every real requirement on the list is then judged against items that can never be answered.

    The test that catches it

    Ask for the retirement condition. Standing monitoring has none — and if you invent one to satisfy the question, you have just discovered the requirement hiding inside it.

    The fix

    Send the monitoring to where it belongs, then carve the bounded question out of it: not "monitor privileged activity", but "do the humans holding privilege match the register, and how long does the gap persist after a separation?"

  4. A requirement nobody was assigned

    The requirement is on the list, everyone agrees it matters, and at cycle close there is no answer and no one who was expected to have one.

    Why it happens

    Assignment happens last, in the part of the planning meeting where time has run out. Naming a team — "SOC", "CTI" — feels like assignment and is not, because a team cannot be asked what happened to a question.

    What it costs

    The most important requirement on the list is often the one most likely to be left unassigned, because it spans teams. It then goes unanswered for several cycles while appearing, on the list, to be handled.

    The test that catches it

    Read the assignment aloud. If it is a team name, a pair of teams, or a role that does not sit in the cycle, it is not assigned.

    The fix

    One named collector or hunter per requirement, agreed in the meeting rather than after it. Where the answer genuinely needs two functions, one of them owns it and the other is a source.

  5. A question the register already answers

    A requirement that comes back in three days with an answer the terrain register or the connection register held all along.

    Why it happens

    It is faster to ask than to look, particularly when the register is stale and nobody trusts it. Over time the requirements list quietly becomes the interface to data the program already owns.

    What it costs

    Collection capacity is spent re-deriving known facts, and the register decays further because nothing forces anyone to fix it. The two failures reinforce each other.

    The test that catches it

    Before adding it, ask which existing record would answer it. If one would, the requirement is really about that record being untrusted.

    The fix

    Convert it into a currency question about the record, which is answerable once and retires, rather than a collection question that will recur forever.

  6. A question no source can answer

    A requirement that stays open for cycle after cycle with progress notes but no answer, and no one can quite say what evidence would close it.

    Why it happens

    The question was written from the decision backwards, which is correct, but nobody checked forward from the sources. Requirements are written by people who know what they need and not always by people who know what is collected.

    What it costs

    It occupies a slot on a sized list indefinitely, and it hides a real finding: the absence of the collection is itself the thing leadership should have been told about.

    The test that catches it

    Name the source and the field before the requirement is accepted. "Threat intelligence" is not a source; a feed with an owner is.

    The fix

    Raise the collection gap as the output — that is a legitimate and useful cycle product — and hold the requirement until the collection exists.

Not a Requirement

Things That Arrive on PCIR Lists and Belong Somewhere Else.

None of these is a bad idea. Each is a good thing filed in the wrong place, and each has a real requirement hiding inside it that can be carved out and asked properly.

As it arrivesWhich failure it isWhere it actually belongsThe requirement hiding inside it
Alert on impossible-travel sign-ins.A requirement that is really standing monitoringThe detection content backlog. It is a rule with an owner and a tuning history, not a question with an answer.Which privileged accounts produced an impossible-travel signal this cycle that was NOT explained by a known VPN egress, and does that change who we treat as compromised?
Achieve full endpoint detection coverage on the server fleet.A question with no decision attachedThe remediation backlog. It is a task with a date and an owner; a requirements list is not a work tracker.Which servers on the mission tier have no endpoint telemetry today, and does that gap sit on any enumerated avenue of approach?
What is the threat landscape for our sector?A question with no decision attachedStanding intelligence reporting. Useful, worth reading, and not a requirement — nothing about the estate changes on the answer.Of the actor sets named in sector reporting this quarter, which have used tradecraft against a control we currently rely on as a barrier?
Are we compliant with the federal zero trust deadlines?A question the register already answersThe assessment and authorization activity, which already holds the answer and the evidence. Collection cannot tell you what your own program has done.Which of the milestones we have reported as met rest on an inherited control whose attestation has since changed scope?
Track APT-nn.A question with no decision attachedA collection focus, which is a different artifact. Naming an adversary says where to look; it does not say what you will do differently.Has the tradecraft attributed to that set changed in a way that defeats a control we are currently counting as a barrier on a decisive point?
Monitor for agency credentials appearing in public dumps.A requirement that is really standing monitoringStanding monitoring with a routing rule. It runs continuously and has no end state.Which credentials for privileged accounts appeared in the last 30 days, and do any of them still authenticate today? The answer sets the scope of the forced reset.
Understand our exposure to supply chain risk.A question no source can answerNowhere, as written. "Exposure" names no evidence, so no source can close it and no one can be assigned to it.Which suppliers hold production access, and which of their update paths reach production without passing a staging gate?

Alert on impossible-travel sign-ins.

Which failure it is
A requirement that is really standing monitoring
Where it actually belongs
The detection content backlog. It is a rule with an owner and a tuning history, not a question with an answer.
The requirement hiding inside it
Which privileged accounts produced an impossible-travel signal this cycle that was NOT explained by a known VPN egress, and does that change who we treat as compromised?

Achieve full endpoint detection coverage on the server fleet.

Which failure it is
A question with no decision attached
Where it actually belongs
The remediation backlog. It is a task with a date and an owner; a requirements list is not a work tracker.
The requirement hiding inside it
Which servers on the mission tier have no endpoint telemetry today, and does that gap sit on any enumerated avenue of approach?

What is the threat landscape for our sector?

Which failure it is
A question with no decision attached
Where it actually belongs
Standing intelligence reporting. Useful, worth reading, and not a requirement — nothing about the estate changes on the answer.
The requirement hiding inside it
Of the actor sets named in sector reporting this quarter, which have used tradecraft against a control we currently rely on as a barrier?

Are we compliant with the federal zero trust deadlines?

Which failure it is
A question the register already answers
Where it actually belongs
The assessment and authorization activity, which already holds the answer and the evidence. Collection cannot tell you what your own program has done.
The requirement hiding inside it
Which of the milestones we have reported as met rest on an inherited control whose attestation has since changed scope?

Track APT-nn.

Which failure it is
A question with no decision attached
Where it actually belongs
A collection focus, which is a different artifact. Naming an adversary says where to look; it does not say what you will do differently.
The requirement hiding inside it
Has the tradecraft attributed to that set changed in a way that defeats a control we are currently counting as a barrier on a decisive point?

Monitor for agency credentials appearing in public dumps.

Which failure it is
A requirement that is really standing monitoring
Where it actually belongs
Standing monitoring with a routing rule. It runs continuously and has no end state.
The requirement hiding inside it
Which credentials for privileged accounts appeared in the last 30 days, and do any of them still authenticate today? The answer sets the scope of the forced reset.

Understand our exposure to supply chain risk.

Which failure it is
A question no source can answer
Where it actually belongs
Nowhere, as written. "Exposure" names no evidence, so no source can close it and no one can be assigned to it.
The requirement hiding inside it
Which suppliers hold production access, and which of their update paths reach production without passing a staging gate?
Before and After

Two Bad Requirements, Rewritten in Front of You.

The destination of each rewrite is a real entry in the library above, not a tidied-up version invented for the demonstration. Follow the link and it has to pass the same tests every other entry does.

Before

What is our exposure to ransomware?

After

Is any host in the mission tier showing the pre-encryption sequence — shadow-copy deletion, backup-agent tampering, mass credential access — and has it touched a system inside the statutory availability set?

Decision: Whether to declare Phase III on the affected mission service and open the wider pre-authorized fire set, or hold at Phase II and contain quietly without the service-affecting authorities.

PCIR-03 in the library above
What changed, and what each change bought
  1. 01

    Attach a decision: declare Phase III on the affected service and open the wider pre-authorized fire set, or hold at Phase II.

    The requirement now has two branches that lead to different actions, which is the test that separates a requirement from a topic.

  2. 02

    Bound the scope: hosts on the mission tier, and specifically whether they have touched the statutory availability set.

    A collector can now say where to look and when to stop looking. The unbounded version implied the whole estate, which is why it was never answered.

  3. 03

    Replace "exposure" with the pre-encryption sequence — shadow-copy deletion, backup-agent tampering, mass credential access.

    Named observables a duty analyst can recognize at 03:00 without asking what was meant, each mapped to a source that already exists.

  4. 04

    Assign it to one owner — the SOC duty function — with the hunt team as a source rather than a co-owner.

    Someone can be asked at cycle close what the answer was, which is the only mechanism that makes a list real.

  5. 05

    State the retirement test: it retires on the phase decision, or on the sequence being attributed to an administrative action.

    It cannot silently become permanent. A requirement that retires on a decision is retired whichever way the decision goes.

Where the rest of it wentThe genuine ransomware concern that produced the original question does not disappear — it becomes two other things. The recovery half becomes a reconstitution requirement answered by exercise, and the rest becomes standing monitoring with a routing rule. What it stops being is one unanswerable line at the top of every cycle.


Before

Monitor all privileged account activity for anomalies.

After

Do the humans holding privilege today match the privileged human register, and how long does the gap persist after a separation?

Decision: Whether separation tempo is recorded as an assessed gap that gates the next authorization decision, or reported as within threshold and left alone.

PCIR-07 in the library above
What changed, and what each change bought
  1. 01

    Send the monitoring itself to the detection backlog, where it is governed as a control rather than as a question.

    The requirements list stops doubling as a work tracker, and the monitoring gets an owner who tunes it.

  2. 02

    Carve out the bounded question: do the humans holding privilege today match the register, and how long does the gap persist after a separation?

    A question with an answer that can be wrong — which the original, by construction, could not be.

  3. 03

    Attach the decision: whether separation tempo becomes an assessed gap that gates the next authorization.

    The answer now lands somewhere with consequences, rather than in a monthly report that circulates and changes nothing.

  4. 04

    State the retirement test: two consecutive clean reconciliations.

    A path off the list. One clean run is a coincidence, and requiring the second is what stops a good answer being taken as permanent.

Where the rest of it wentThe monitoring keeps running. That was never the problem — the problem was that running it was being reported as an intelligence requirement, which meant the cycle had one fewer slot for a question that could have come back badly.

Elsewhere in the Apparatus

Where Requirements Come from and Where They Go.