ASOM-Fedv6.1Open the explorer
Reference manual · the artifacts

What the Framework Actually Leaves Behind.

A framework is judged on its output. This is the full index of artifacts ASOM-Fed produces — 61 of them — each with what produces it, who is accountable for it, which controls consume it, and how often it has to be refreshed before it stops being true. It is also the honest answer to a fair question: if a program adopts this, what will there be to show for it?

61ProductsArtifacts the framework leaves behind
54Derived from the chainNamed as a control’s declared output
66Controls producing themOf 78 in the catalog
4Facts per entryProducer, owner, consumers, cadence
How This Index Was Built

Mostly Derived. Where It Is Not, It Says So.

Every control in the catalog declares what it consumes and what it produces. Those declarations are the framework’s own statement of the chain, and they are the source for most of this page.

Derived from the Control Chain

54 of 61 entries name an artifact that appears as a declared output in the controls’ own input and output flows. The producing controls are read from those declarations, not restated here.

Derived a Second Time Over

Owner and maintainer come from the producing controls’ accountability chart. Consumers come from the other controls’ declared inputs. Neither can be softened by editing this page, and the two directions of the chain cannot disagree.

Composed, and Marked as Such

A handful of artifacts are named in the framework’s doctrine but assembled from several controls rather than emitted by one — the Cyber Running Estimate and the Bill of Defense are the clear cases. Each is marked Composed and says how it is assembled.

Authored: Names and Cadence

The artifact’s name, the sentence describing it, its refresh cadence and the reason for that cadence are written for this manual. The catalog states that currency must be maintained — which is the right thing for a control to say and an unhelpful place for a reference manual to stop.

5 products

Produced at Frame

The artifacts that give a cycle its direction. All five are short by design; none of them survives being long.

Derived
Defensive intent paragraphProduced at Frame · read at Map, Array

One signed paragraph stating what the defense exists to protect, what may be degraded to protect it, and the acceptable risk. The commander’s-intent analog, and the citation every downstream designation rests on.

Produced by
CG-1
Owned by · maintained by
Authorizing Official / CISO ·
Consumed by
KT-1 · SM-1 · SM-4 · TA-3 · CE-1 · CE-2 · CG-2AO, CTI, ISSO
Refresh cadence
Reviewed every cycle; revised when the brief gives a reason. Why — The brief feeds the intent by design. A deliberate no-change is a valid outcome and is recorded as one; an unreviewed intent is not.
Derived
Priority Cyber Intelligence RequirementsProduced at Frame · read at Map, Fuse

Three to seven questions the cycle will try to answer, each naming the decision it informs, the collection source expected to answer it, and an individual owner.

Produced by
CE-2
Owned by · maintained by
Authorizing Official / CISO · Cyber Threat Intelligence cell
Consumed by
SM-5 · CE-3AO, CTI
Refresh cadence
Set at each Frame; carried-forward items marked with the reason they survived. Why — A requirement that silently persists across cycles has stopped being a priority and become a standing wish.
Derived
Phase declarationProduced at Frame · read at Array

The declared campaign phase and the scope it is declared against. Sets cadence, dominant forms of maneuver, and how wide the pre-authorization set runs.

Produced by
CG-2
Owned by · maintained by
Authorizing Official / CISO ·
Consumed by
SM-4 · CE-1 · ID-4 · EN-4AO, CTI, SOC, PLAT
Refresh cadence
Reviewed every cycle; declared out of band whenever the situation changes. Why — Phase is the one artifact that must be able to change between cycles — contact does not wait for a framing meeting.
Derived
Cycle cadence and calendarProduced at Frame

The declared length of a cycle, its close date, and the refresh intervals that inherit from it. Makes “per cycle” a measurable unit rather than a figure of speech.

Produced by
CE-1
Owned by · maintained by
Authorizing Official / CISO · Cyber Threat Intelligence cell
Consumed by
TM-6 · TA-1 · CE-2AO, CTI, SOC, PLAT
Refresh cadence
Set at Frame, adjusted on phase change. Why — Cadence is derived from phase. A campaign in contact that is still running a monthly cycle has a cadence artifact that is describing last quarter.
Derived
Temporal advantage thresholdProduced at Frame

The number the cycle will be judged against: defender decision loop versus adversary dwell, stated with units before the cycle runs.

Produced by
TA-3
Owned by · maintained by
Authorizing Official / CISO · Governance / RMF / ISSO
Consumed by
CE-7 · CG-4AO, CTI, ISSO
Refresh cadence
Set at Frame, reported against at Assess. Why — A threshold chosen once the result is in will be met every time, which is the point at which the number stops carrying information.
7 products

Produced at Map

Cyber Preparation of the Environment. These are the positional artifacts — everything computed later is computed over them.

Derived
Cyber Terrain OverlayProduced at Map · read at Array, Assess

The positional map of the estate: every element with a defensive layer, a defensive weight, a named accountable owner and its adjacencies. Not an asset inventory — an inventory enumerates, an overlay positions.

Produced by
TM-1 · TM-2 · TM-3 · TM-6 · TM-7
Owned by · maintained by
Authorizing Official / CISO · Platform and product owners, Governance / RMF / ISSO
Consumed by
TM-4 · KT-1 · CE-7 · RC-1 · FO-1 · FO-2 · FO-3 · FO-4 · FO-5 · FO-6 · WF-1 · FC-1 · ID-1 · EN-2 · DV-1 · SM-2 · SM-7 · CE-4 · ID-3 · ID-5 · EN-3 · EN-1 · KT-5 · CG-4AO, CTI, SOC, HUNT, PLAT, ISSO
Refresh cadence
Quarterly at the outside, and immediately on material architectural change. Why — Overlay freshness is itself a reported performance measure. Every number computed downstream inherits the overlay’s age, so its staleness is the program’s staleness.
Derived
Trust zones and the connection registerProduced at Map

The zone boundaries and the permitted- and denied-path register — the graph reachability is actually walked over, reconciled against observed flow telemetry rather than against intended configuration.

Produced by
TM-4 · TM-5
Owned by · maintained by
Authorizing Official / CISO · Platform and product owners
Consumed by
KT-3 · RC-2 · FO-2 · FC-2 · KT-4 · EN-2AO, CTI, HUNT, PLAT, ISSO
Refresh cadence
With the overlay, and on any change to segmentation or policy. Why — A denied path asserted from a configuration that changed last week is the single most load-bearing stale fact in the framework.
Derived
Decisive point registerProduced at Map · read at Array

The elements whose control confers decisive advantage — each carrying the evidence that raised it above merely important, and the protection floor it owes as a result.

Produced by
KT-1 · KT-2
Owned by · maintained by
Authorizing Official / CISO · Cyber Threat Intelligence cell, Platform and product owners
Consumed by
KT-3 · SM-4 · SM-7 · RC-3 · WF-1 · FC-2 · LC-3 · ID-2 · ID-3 · DV-2 · DV-4 · CE-5 · CG-4AO, CTI, SOC, PLAT, ISSO
Refresh cadence
Reviewed every cycle; changed only with evidence. Why — Decisive points should be stable. A register that churns every cycle is tracking attention rather than terrain.
Derived
Avenue-of-approach analysisProduced at Map · read at Array

The enumerated routes an adversary could take toward each decisive point, including physical, supplier and maintenance routes, with unassessed routes recorded as intelligence gaps rather than as absence of risk.

Produced by
KT-3
Owned by · maintained by
Authorizing Official / CISO · Cyber Threat Intelligence cell
Consumed by
KT-4 · SM-2 · SM-5 · SM-7 · CE-2AO, CTI, SOC, PLAT
Refresh cadence
Every cycle, and on any change to the connection register. Why — Avenues are derived from permitted paths. When the paths move, the avenues have already moved whether or not anyone re-derived them.
Derived
Adversary reachability assessmentProduced at Map · read at Array, Fuse, Assess

The formal result: from each entry point, which decisive points are reachable over the permitted-path graph. The framework’s hardest single finding, and the headline of the brief when it changes.

Produced by
KT-4
Owned by · maintained by
Authorizing Official / CISO · Cyber Threat Intelligence cell
Consumed by
KT-5 · CE-4 · CE-7 · CG-2AO, CTI, PLAT, ISSO
Refresh cadence
Every cycle. Why — Reachability is the one map product that changes without anyone deciding to change it — a single permissive rule is enough.
Derived
Barrier sufficiency registerProduced at Map

The specific barriers holding the line where reachability is prevented, each with a named enforcing owner. What the reachability result depends on, made explicit so its erosion is visible.

Produced by
KT-5
Owned by · maintained by
Authorizing Official / CISO · Platform and product owners
Consumed by
SM-2 · TA-5AO, SOC, PLAT
Refresh cadence
Every cycle, tracked across cycles for silent erosion. Why — Barriers fail quietly and by accumulation — an exception here, a temporary rule there. Only the cross-cycle view catches it.
Composed
Threat course-of-action sketchProduced at Map · read at Array, Fuse

Two courses of action, most likely and most dangerous, drawn against the decisive points already designated. Each is a route across ground the estate really has, not a category of threat.

The catalog does not carry a single control that emits "the threat COA sketch". It is assembled from the avenue analysis, the intelligence requirements that direct collection against it, and the branch planning that consumes it. Named here because the cycle doctrine names it as Map’s output and a products index that omitted it would be describing a different framework.

Produced by
KT-3 · CE-2 · SM-5
Owned by · maintained by
Authorizing Official / CISO · Cyber Threat Intelligence cell
Consumed by
KT-4 · SM-2 · SM-7 · CE-3 · TA-4 · CG-3AO, CTI, SOC, PLAT, ISSO
Refresh cadence
Every cycle. Why — The scheme is planned against these two. Planning this cycle’s scheme against last cycle’s courses of action is the definition of fighting the last engagement.
7 products

Produced at Array

The scheme and the authority to execute it. An artifact here that has no authority level attached is a plan, not a scheme.

Derived
Adopted maneuver catalogProduced at Array and Fuse · read at Array

The forms of defensive maneuver the organization has adopted, each with the effectiveness it is assumed to deliver — recorded so the assumption can later be validated rather than believed indefinitely.

Produced by
SM-1
Owned by · maintained by
Authorizing Official / CISO · Governance / RMF / ISSO
Consumed by
SM-2AO, PLAT
Refresh cadence
Annually, and whenever validation proves an assumed indicator wrong. Why — The forms are durable; the assumed effectiveness values are not, and they are the part that feeds the coverage computation.
Composed
Scheme of maneuverProduced at Array · read at Maneuver

One graphic and one narrative: which forms of maneuver are sited where, in what sequence. The assignment record behind it carries the element, the avenue and the implementation state for every move.

The assignment and implementation-state records are declared control outputs. The one-page graphic and narrative are doctrine — the framework requires the scheme to be drawable on a page, and no control emits a drawing. Both halves are the artifact.

Produced by
SM-2 · SM-3
Owned by · maintained by
Authorizing Official / CISO · Platform and product owners
Consumed by
KT-2 · SM-6 · CE-4 · CE-5AO, HUNT, PLAT, ISSO
Refresh cadence
Every cycle. Why — The scheme is the cycle’s commitment. Carrying one forward unchanged is a decision that should be visible as one.
Derived
Main effort designationProduced at Array · read at Maneuver

The single designated main effort for the cycle, and the sentence citing the decisive point that justifies it. The answer to which work wins when two things need the same engineer.

Produced by
SM-4
Owned by · maintained by
Authorizing Official / CISO ·
Consumed by
CE-5 · CE-7AO, CTI, ISSO
Refresh cadence
Every cycle; reconsidered on phase change. Why — Phase determines what the main effort should be. Declaring a new phase without revisiting the main effort leaves the campaign pointed at the last situation.
Derived
Branch and sequel planProduced at Array · read at Maneuver

The branches answer the most-dangerous course of action; the sequels answer success. Every one names the authority it needs, and any expected to run inside the decision window is pre-authorized when it is written.

Produced by
SM-5
Owned by · maintained by
Authorizing Official / CISO · Cyber Threat Intelligence cell
Consumed by
TA-4 · CG-3AO, ISSO
Refresh cadence
Every cycle; rehearsed at least once per campaign phase. Why — A branch that has never been rehearsed is a paragraph. Its execution time under contact is unknown, which makes the whole tempo claim unknown.
Derived
Rules of engagementProduced at Array · read at Maneuver

Which defensive actions may be taken by whom without escalation, which need the Authorizing Official, and what is prohibited outright. The cyber analog of engagement authority, and the single largest determinant of tempo.

Produced by
CG-3
Owned by · maintained by
Authorizing Official / CISO · Governance / RMF / ISSO
Consumed by
TA-4 · EN-4AO, SOC
Refresh cadence
Reviewed on phase change; revised after any incident that surfaced an authority the responders did not have. Why — The most useful revisions are written by people who have just discovered a gap in them. Reviewing only on an annual calendar throws that away.
Derived
Pre-authorized response setProduced at Array · read at Maneuver

The specific containment and response actions the SOC may execute at machine speed, bounded by the statutory availability floor. Directly measurable: it shortens the decision segment of the defender loop.

Produced by
TA-4
Owned by · maintained by
Authorizing Official / CISO ·
Consumed by
CG-3 · EN-4AO, SOC, ISSO
Refresh cadence
Reviewed on phase change; widened deliberately, never by drift. Why — The set widens in contested phases and narrows during recovery. Both directions are deliberate decisions with different risks.
Derived
Trusted rebuild pathProduced at Array

A documented, walked path to rebuild each decisive point inside its recovery time budget, from media held outside the production identity plane — including a path for the identity plane itself.

Produced by
RC-2 · RC-3
Owned by · maintained by
Authorizing Official / CISO · Platform and product owners
Consumed by
RC-4 · RC-5AO, SOC, PLAT
Refresh cadence
Reviewed per cycle; walked at least annually, and after any material change to the systems it rebuilds. Why — A rebuild path documented and never walked has an unknown duration, which means the recovery time objective it supports is also unknown.
7 products

Produced at Maneuver

The evidence of execution. Thin artifacts, and the ones whose absence is most expensive — the headline metric is computed from them.

Composed
Change recordProduced at Maneuver · read at Fuse

Every defensive action carried out, stamped twice — at the decision and at the effect. A thin, unglamorous table, and the one the headline metric is computed from.

Assembled from the implementation-state updates, the terrain refresh triggers material change raises, and the authority exceptions recorded against the rules of engagement. The cycle doctrine names it as Maneuver’s output; no single control emits it whole.

Produced by
SM-3 · TM-6 · CG-3
Owned by · maintained by
Authorizing Official / CISO · Platform and product owners, Governance / RMF / ISSO
Consumed by
SM-6 · CE-4 · CE-5 · TM-1 · TA-4 · EN-4AO, SOC, HUNT, PLAT, ISSO
Refresh cadence
Continuous, at the point of action. Why — Reconstructed after the fact, the record measures when someone had a moment to write it down — which is a measurement of workload rather than of tempo.
Derived
Implementation state recordProduced at Maneuver · read at Fuse, Assess

Planned, partial or operational, per maneuver assignment. The mechanism that stops intended work being counted as deployed protection.

Produced by
SM-3
Owned by · maintained by
Authorizing Official / CISO · Platform and product owners
Consumed by
SM-6 · CE-4 · CE-5AO, HUNT, ISSO
Refresh cadence
Updated at execution, not at reconciliation. Why — A weekly reconciliation catches divergence one cycle late, and work that was done but never recorded is indistinguishable from work that was never done.
Derived
Authority exception logProduced at Maneuver

Actions taken outside the standing rules of engagement, with who approved them and why. Exceptions are not failures; unrecorded exceptions are.

Produced by
CG-3
Owned by · maintained by
Authorizing Official / CISO · Governance / RMF / ISSO
Consumed by
TA-4 · EN-4AO, SOC
Refresh cadence
At the time of the exception; reported in the cycle brief. Why — A pattern of exceptions is the clearest available evidence that the pre-authorized set is too narrow, and it is only visible if the exceptions are counted.
Derived
Defender decision loop measurementProduced at Maneuver · read at Assess

Detect to decide to contain, measured per incident from the change record’s timestamps and reported as a distribution rather than as a mean.

Produced by
TA-1
Owned by · maintained by
Authorizing Official / CISO · SOC / Defensive Operations
Consumed by
SM-7 · TA-3 · TA-5 · CE-6 · EN-1AO, SOC, ISSO
Refresh cadence
Continuous; reported per cycle. Why — It is the denominator of the temporal advantage ratio, so a hole in it is a hole in the one figure that can report a program is losing.
Composed
Hunt results, including negative resultsProduced at Maneuver · read at Fuse

What was hunted, how, and what was not found. Negative results are the half most often discarded, and they are the half that says what has actually been cleared.

Declared in the chain only as an external input to fusion. Named here because the framework treats hunt as the counterattack force and its output as a first-class product, not as telemetry.

Produced by
CE-3 · KT-4
Owned by · maintained by
Authorizing Official / CISO · Cyber Threat Intelligence cell
Consumed by
TA-2 · CE-6 · CG-2 · KT-5 · CE-4 · CE-7AO, CTI, PLAT, ISSO
Refresh cadence
Continuous; consolidated per cycle. Why — Without a record of what was cleared, the same ground is hunted every cycle and the coverage of the hunt itself is unmeasurable.
Derived
Engagement recordProduced at Maneuver and Fuse

The record of one engagement end to end: what was declared and on what criteria, the reconstruction with its dwell, scope and confidence, the evidence preserved and its custody, the authority exercised, and the verification that eradication actually happened before recovery began.

Produced by
EN-1 · EN-2 · EN-3 · EN-4 · EN-5
Owned by · maintained by
Authorizing Official / CISO · SOC / Defensive Operations, Hunt team
Consumed by
EN-6 · DV-3AO, SOC, ISSO
Refresh cadence
One per declared engagement; closed only when the reconstruction is complete. Why — EN-2 exists to stop an incident being closed on containment alone. An engagement closed without a reconstruction has corrected no estimate and taught the agency nothing, so completeness of the record is the close criterion rather than a formality after it.
Derived
Engagement communication recordProduced at Maneuver

Who was told what, and when, against the window that bound each obligation — inside the agency, to the federal community, and to those the mission serves. Includes the contribution made back to the community, or the recorded reason there was none.

Produced by
EN-6
Owned by · maintained by
Authorizing Official / CISO · Governance / RMF / ISSO
Consumed by
Nothing downstream inside the framework. This artifact terminates a chain and its audience is external.
Refresh cadence
Per engagement, against the statutory windows the obligation profile declares. Why — The windows are set by instruments outside the framework, which is why FO-7 has to have declared which of them bind before this artifact can be assessed as timely or late.
5 products

Produced at Fuse

Assessments rather than observations. Every one of these carries a confidence level and a stated basis for it.

Derived
Fused assessmentProduced at Fuse · read at Assess

What the cycle’s intelligence requirements returned: each answer graded for confidence and showing its working, and each requirement left unanswered recorded against the collection gap responsible.

Produced by
CE-3
Owned by · maintained by
Authorizing Official / CISO · Cyber Threat Intelligence cell
Consumed by
TA-2 · CE-6 · CG-2AO, CTI, ISSO
Refresh cadence
Every cycle. Why — The requirements were set for this cycle. Answering them next cycle answers a question that has stopped gating a decision.
Derived
Adversary dwell estimateProduced at Fuse · read at Assess

The estimated time an adversary could operate undetected in this estate, with its basis stated — measured dwell, sector reporting, or partner intelligence — and its bias acknowledged.

Produced by
TA-2
Owned by · maintained by
Authorizing Official / CISO · Cyber Threat Intelligence cell
Consumed by
TA-3 · EN-3 · DV-3AO, SOC, ISSO
Refresh cadence
Every cycle; the basis restated rather than carried silently. Why — It is the numerator of the temporal advantage ratio. Carried forward without restatement, it turns a measured claim into an inherited one.
Derived
Maneuver effectiveness validation recordProduced at Fuse · read at Assess

Whether the moves claiming operational status produced the effect the catalog assumed — from exercise results, control testing, and observed incident performance.

Produced by
SM-6
Owned by · maintained by
Authorizing Official / CISO · Hunt team
Consumed by
CE-4AO, ISSO
Refresh cadence
Every cycle for the main effort; annually across the full assignment set. Why — Validating everything every cycle is not affordable, and validating nothing means the coverage number is an assumption compounded over time.
Composed
Cyber Running EstimateProduced at Fuse

The living situational picture the SOC, hunt and intelligence cell share: current posture, current assessments and their confidence, open requirements, and what has moved since the last look.

Assembled from fusion output, the computed posture, and the cycle record’s trend. Named in the framework’s doctrine as the running-estimate analog; no control emits it, because it is a view rather than a document.

Produced by
CE-3 · CE-4 · CE-6
Owned by · maintained by
Authorizing Official / CISO · Cyber Threat Intelligence cell, Governance / RMF / ISSO
Consumed by
TA-2 · CG-2 · CE-5 · CE-7 · CG-5AO, CTI, ISSO
Refresh cadence
Continuous. It is the one artifact that is never “as of last cycle”. Why — A running estimate that updates on the cycle boundary is a cycle report. Its whole purpose is to be current between the boundaries.
Composed
Indicators and signpostsProduced at Fuse

For each surviving hypothesis, the observable events that would confirm or kill it, handed to collection. The mechanism that makes this cycle’s analysis into next cycle’s requirements.

A structured analytic technique’s output rather than a control’s. It appears in the chain as the collection direction fusion returns to the intelligence requirements, which is the edge the catalog does declare.

Produced by
CE-3 · CE-2
Owned by · maintained by
Authorizing Official / CISO · Cyber Threat Intelligence cell
Consumed by
TA-2 · CE-6 · CG-2 · SM-5AO, CTI, ISSO
Refresh cadence
Every cycle; reviewed at Assess for which fired and which never could. Why — An indicator that has never fired in six cycles is either extraordinary good news or a badly written indicator, and the review is what tells them apart.
8 products

Produced at Assess

The published output and the record behind it. These are also what an oversight body reads as continuous-monitoring evidence.

Derived
Coverage and residual risk resultProduced at Assess

Coverage and residual risk computed over the whole overlay population, weighted by consequence, discounted by implementation state and corrected by validated effectiveness — with the denominator stated.

Produced by
CE-4
Owned by · maintained by
Authorizing Official / CISO · Governance / RMF / ISSO
Consumed by
CE-5 · CE-6 · CE-7AO, CTI, ISSO
Refresh cadence
Every cycle. Why — It is the cycle’s posture. Computed less often than the cycle turns, it stops being able to show trend, which is most of its value.
Composed
Bill of DefenseProduced at Assess

Per mission service: the maneuvers and assets protecting it, its rolled-up coverage, and its residual risk. The view that lets a mission owner see their own defense rather than the enterprise average.

A rollup view over the coverage computation and the asset weighting, defined in the framework’s tower model rather than as a control output. The underlying numbers are entirely derived; the per-mission cut is the authored part.

Produced by
CE-4 · TM-3
Owned by · maintained by
Authorizing Official / CISO · Platform and product owners, Governance / RMF / ISSO
Consumed by
CE-5 · CE-6 · CE-7 · KT-1 · EN-1AO, CTI, SOC, ISSO
Refresh cadence
Every cycle, per mission service. Why — Its audience is the mission owner, who reads it on their own rhythm. An annual one is a report; a per-cycle one is a conversation.
Derived
Temporal advantage resultProduced at Assess

Defender decision loop against adversary dwell, reported as a ratio against the threshold set at Frame, with the result written as a word: met, or not met. The framework’s single honest scoreboard.

Produced by
TA-3 · TA-1 · TA-2 · TA-5
Owned by · maintained by
Authorizing Official / CISO · Cyber Threat Intelligence cell, SOC / Defensive Operations, Governance / RMF / ISSO
Consumed by
CE-7 · CG-4 · SM-7 · CE-6 · EN-1 · EN-3 · DV-3AO, CTI, SOC, ISSO
Refresh cadence
Every cycle. Why — It is the measure that can come out badly, which is the reason it is reported on the same cadence as everything designed to come out well.
Derived
Remediation backlogProduced at Assess

The ranked list of what to fix, ordered by residual risk, main-effort weighting, and decisive-point floor breaches — which sit above higher-volume, lower-weight work regardless of count.

Produced by
CE-5
Owned by · maintained by
Authorizing Official / CISO · Governance / RMF / ISSO
Consumed by
CE-6 · CG-4AO, ISSO
Refresh cadence
Re-ranked every cycle. Why — A backlog ranked once and worked forever is ordered by the situation that existed when it was written.
Derived
Findings disposition recordProduced at Assess · read at Frame

Every finding with an outcome: remediate with an owner and a date, accept with a named accepter and an expiry, or transfer with the party named. “Under review” is not a disposition.

Produced by
CG-4
Owned by · maintained by
Authorizing Official / CISO · Governance / RMF / ISSO
Consumed by
CG-5AO, ISSO
Refresh cadence
Every cycle; acceptances expire and return to the backlog. Why — Acceptance without expiry is an amnesty, and it is discovered years later by someone who was not in the room.
Derived
Cycle record and trendProduced at Assess · read at Frame

The closed record of the cycle — posture, loop measurement, conclusions and their confidence, backlog state at close — and the trend across cycles that makes a second cycle worth more than a first.

Produced by
CE-6
Owned by · maintained by
Authorizing Official / CISO · Governance / RMF / ISSO
Consumed by
CE-7 · CG-5AO, CTI, ISSO
Refresh cadence
Closed at the end of every cycle. Why — It is the continuous-monitoring evidence. A record closed irregularly produces a trend line with gaps in it, and gaps are what an assessor asks about.
Derived
Cycle briefProduced at Assess · read at Frame

The published product: terrain, reachability, main effort, temporal advantage, coverage, trend, and the top-ranked backlog items — each confidence-tagged. Also the evidence that feeds the next intent.

Produced by
CE-7
Owned by · maintained by
Authorizing Official / CISO · Cyber Threat Intelligence cell
Consumed by
CG-1AO
Refresh cadence
Every cycle, distributed. Why — It is the loop’s closing move. A brief produced and not distributed has not closed anything.
Derived
Control inheritance mappingProduced at Assess

How the cycle’s output maps onto the organization’s existing control baseline and assessment results, so that federal obligations are satisfied as a by-product of defending rather than as a parallel program.

Produced by
CG-5
Owned by · maintained by
Authorizing Official / CISO · Governance / RMF / ISSO
Consumed by
Nothing downstream inside the framework. This artifact terminates a chain and its audience is external.
Refresh cadence
Every cycle; formally reconciled at authorization milestones. Why — The mapping is what makes the cycle record usable as continuous-monitoring evidence. Reconciled only at milestones, the evidence arrives after the decision it was meant to inform.
4 products

Standing — resilience

Held continuously rather than produced per cycle. Their failure mode is age, not absence.

Derived
Recovery objectives registerHeld standing · read at Array

A declared recovery time and recovery point objective per mission service, agreed with the service owner and constrained by statutory deadlines rather than by what is currently achievable.

Produced by
RC-1
Owned by · maintained by
Authorizing Official / CISO · Platform and product owners
Consumed by
RC-2 · RC-3 · RC-5 · FC-4 · EN-5AO, SOC, HUNT, PLAT
Refresh cadence
Annually, and whenever a mission service is added or its statutory position changes. Why — The objective is a commitment, not a measurement. Revising it because it was missed is how a recovery program grades its own homework.
Derived
Isolated recovery capability recordHeld standing

The means of recovery held outside the production identity plane, and the isolation boundary that keeps it there — itself a load-bearing barrier that has to be monitored.

Produced by
RC-2
Owned by · maintained by
Authorizing Official / CISO · Platform and product owners
Consumed by
RC-3 · RC-4AO, PLAT
Refresh cadence
Verified per cycle; the boundary monitored continuously. Why — The isolation is the entire value. It erodes through ordinary convenience — one integration, one service account — and only continuous monitoring catches that.
Derived
Recovery integrity verification recordHeld standing

Restored data verified against an independently held integrity record, so that recovery is a demonstrated claim rather than an assumption that the backup was clean.

Produced by
RC-4
Owned by · maintained by
Authorizing Official / CISO · Platform and product owners
Consumed by
RC-5AO, SOC
Refresh cadence
Exercised at each reconstitution exercise; performed after any real recovery. Why — Verification first attempted during a real recovery is being attempted at the worst possible time by people with no practice at it.
Derived
Reconstitution exercise reportHeld standing · read at Assess

What was rebuilt, from what media, in what time, verified how — and which recovery objectives were missed. Includes supplier severance scenarios.

Produced by
RC-5
Owned by · maintained by
Authorizing Official / CISO · SOC / Defensive Operations
Consumed by
Nothing downstream inside the framework. This artifact terminates a chain and its audience is external.
Refresh cadence
At the stated exercise cadence — annually at minimum, per decisive point. Why — The framework’s claim is that every recovery objective has been demonstrated within its stated period. That claim expires on a schedule.
4 products

Standing — federal obligations

The terrain the framework had to add because a federal estate has ground that the five zero-trust pillars do not cover.

Derived
Statutory availability floorHeld standing · read at Frame, Maneuver

The mission services whose availability is set by statute or regulation, and the floor below which degradation stops being a defensive choice. Bounds what may be pre-authorized and what may be degraded under contact.

Produced by
FO-5
Owned by · maintained by
Authorizing Official / CISO · Governance / RMF / ISSO
Consumed by
TA-4 · CG-3 · RC-1 · FO-7 · LC-5AO, PLAT, ISSO
Refresh cadence
Annually, and on any change to the authorizing instruments. Why — It is the pre-agreed statement made when nobody was under pressure. Its whole value is being settled before the moment it is needed.
Derived
Privacy and controlled-information terrain registerHeld standing · read at Map

Where privacy holdings and controlled unclassified information sit, the authorities under which they are held, and the boundaries their handling requires — expressed as denied paths, not as policy statements.

Produced by
FO-1 · FO-2
Owned by · maintained by
Authorizing Official / CISO · Governance / RMF / ISSO
Consumed by
LC-3AO, PLAT
Refresh cadence
Annually, and on any new collection or new system of records. Why — The register feeds asset weighting and decisive-point designation. Out of date, it under-weights exactly the holdings that carry the heaviest obligations.
Derived
Tenancy and inheritance boundary recordHeld standing

What is inherited from a provider and what remains the agency’s, drawn from provider authorization packages and responsibility matrices, so inherited mitigation is counted once and correctly.

Produced by
FO-3
Owned by · maintained by
Authorizing Official / CISO · Governance / RMF / ISSO
Consumed by
Nothing downstream inside the framework. This artifact terminates a chain and its audience is external.
Refresh cadence
On each provider authorization change, reviewed annually. Why — Miscounted inheritance is the most common source of coverage that exists on paper and nowhere else.
Derived
Operational technology terrain registerHeld standing

Engineering and facilities systems as their own defensive layer, with the enterprise-to-operational crossings enumerated as avenues of approach.

Produced by
FO-4
Owned by · maintained by
Authorizing Official / CISO · Platform and product owners
Consumed by
FC-1AO, PLAT
Refresh cadence
Annually, and on any new crossing between enterprise and operational networks. Why — Crossings are added for maintenance convenience and are rarely announced. An annual register with no change-triggered refresh will not see them.
5 products

Standing — workforce

People as terrain. Modeled because the compromise of certain roles is equivalent to the compromise of a decisive point.

Derived
Workforce terrain registerHeld standing · read at Map

The roles whose compromise is equivalent to compromising a decisive point — the operators of decisive points, and the roles with standing access to them.

Produced by
WF-1
Owned by · maintained by
Authorizing Official / CISO · Platform and product owners
Consumed by
WF-2 · WF-3 · FC-1AO, PLAT, ISSO
Refresh cadence
Reviewed per cycle against the decisive point register; reconciled with HR data quarterly. Why — Roles change faster than systems do, and a role register reconciled annually describes an organization that has since reorganized.
Derived
Privileged human registerHeld standing

Which individuals hold which high-consequence access, reconciled against the identity system rather than against the last access review spreadsheet.

Produced by
WF-2
Owned by · maintained by
Authorizing Official / CISO · Platform and product owners
Consumed by
WF-4 · WF-5 · ID-2AO, PLAT, ISSO
Refresh cadence
Continuous, reconciled per cycle. Why — It is what revocation is executed against. A stale register makes separation tempo unmeasurable and revocation incomplete.
Derived
Role-based readiness recordHeld standing

Preparation targeted at the tradecraft that actually targets each role, and the gaps that would slow the decision loop if the role were needed under contact.

Produced by
WF-3
Owned by · maintained by
Authorizing Official / CISO · Governance / RMF / ISSO
Consumed by
TA-5AO, SOC
Refresh cadence
Annually per role; re-targeted whenever intelligence changes what a role is being attacked with. Why — Readiness aimed at last year’s tradecraft is training, not readiness, and it reports the same either way.
Derived
Insider risk positionHeld standing

The stated position on insider risk: what may be done, by whom, under what legal, privacy and labor-relations constraints, and how a case is dispositioned.

Produced by
WF-4
Owned by · maintained by
Authorizing Official / CISO · Governance / RMF / ISSO
Consumed by
WF-5 · EN-3AO, SOC, PLAT
Refresh cadence
Annually, and on any change to the legal or labor framework. Why — The constraints here are external and non-negotiable. Discovering them during a case is the failure this artifact prevents.
Derived
Separation and revocation recordHeld standing

How long it takes to remove everything an individual holds, per system, and which systems cannot be revoked in a single action. Feeds terrain ownership so revocation does not orphan an element.

Produced by
WF-5
Owned by · maintained by
Authorizing Official / CISO · Platform and product owners
Consumed by
TM-7 · DV-5AO, PLAT, ISSO
Refresh cadence
Measured on every separation; reported per cycle. Why — Revocation tempo is a defensive fire measured in the same units as the rest of the loop, and it is measurable on every ordinary departure.
4 products

Standing — facilities

Physical ground. Several avenues of approach begin here, and none of them appear on a network diagram.

Derived
Facility terrain registerHeld standing · read at Map

Where elements physically are, which personnel populations are associated with each site, and which facilities carry mission services.

Produced by
FC-1
Owned by · maintained by
Authorizing Official / CISO · Platform and product owners
Consumed by
FC-2 · FC-4AO, PLAT
Refresh cadence
Annually, and on any site change. Why — Physical location changes rarely and consequentially. The refresh cost is low and the omission cost — an unmapped site carrying a mission service — is not.
Derived
Physical zone boundary recordHeld standing

Zone divisions inside facilities, reconciled against the logical trust zones, with physical approach routes to decisive points enumerated as avenues.

Produced by
FC-2
Owned by · maintained by
Authorizing Official / CISO · Platform and product owners
Consumed by
FC-3AO, PLAT
Refresh cadence
Annually, reconciled against the logical zones each cycle. Why — The reconciliation is where the finding lives: a logical boundary that no physical boundary supports is a barrier that only exists in configuration.
Derived
Maintenance access recordHeld standing

Who may perform maintenance in which zone, under what escort and in what window — including supplier maintenance, which is where standing physical access usually hides.

Produced by
FC-3
Owned by · maintained by
Authorizing Official / CISO · Platform and product owners
Consumed by
Nothing downstream inside the framework. This artifact terminates a chain and its audience is external.
Refresh cadence
Per maintenance window; the standing-access set reviewed per cycle. Why — Standing maintenance access accumulates. Reviewing it per cycle is the only thing that stops a temporary arrangement becoming a permanent path.
Derived
Environmental continuity recordHeld standing

How long each facility can carry the mission services housed in it — power, cooling, connectivity — measured against the recovery objectives those services must meet.

Produced by
FC-4
Owned by · maintained by
Authorizing Official / CISO · Platform and product owners
Consumed by
Nothing downstream inside the framework. This artifact terminates a chain and its audience is external.
Refresh cadence
Annually, and whenever a service’s recovery objective is tightened. Why — A facility whose endurance is shorter than the objective it supports makes that objective unachievable, and the finding only appears when the two are compared.
5 products

Standing — supply chain

Suppliers as external actors with real paths onto real terrain, and the ability to remove them.

Derived
Supplier terrain registerHeld standing · read at Map

Suppliers as external actors on the overlay, with the access each holds, the paths that access implies, and the contract behind it.

Produced by
FO-6 · LC-1
Owned by · maintained by
Authorizing Official / CISO · Platform and product owners, Governance / RMF / ISSO
Consumed by
FC-3 · LC-2 · LC-3 · LC-4 · LC-5AO, PLAT
Refresh cadence
On each contract change; reconciled against procurement records quarterly. Why — Supplier access is created by contract and removed by nobody. Only a reconciliation against procurement finds the access that outlived its engagement.
Derived
Component provenance recordHeld standing

Where components came from, from inventories, build manifests and supplier attestations — and which components have an origin that cannot be verified.

Produced by
LC-2
Owned by · maintained by
Authorizing Official / CISO · Platform and product owners
Consumed by
LC-4 · DV-4 · DV-5AO, PLAT
Refresh cadence
At each build or release; reviewed per cycle for unverifiable components. Why — Provenance recorded at build time is cheap. Reconstructed later it is archaeology, and it is usually incomplete.
Derived
Supplier access constraint recordHeld standing

How supplier access is brokered, time-bounded and constrained — and the prohibition on standing supplier access to designated decisive points.

Produced by
LC-3
Owned by · maintained by
Authorizing Official / CISO · Platform and product owners
Consumed by
FC-3 · LC-5AO, PLAT
Refresh cadence
Per engagement; the standing set reviewed per cycle. Why — Brokered access is also the severance point. If the constraint record is stale, so is the ability to cut the supplier off.
Derived
Update integrity and staging recordHeld standing

How updates arriving from suppliers are verified and staged before reaching production. The staging gate is a barrier in its own right and is monitored as one.

Produced by
LC-4
Owned by · maintained by
Authorizing Official / CISO · Platform and product owners
Consumed by
Nothing downstream inside the framework. This artifact terminates a chain and its audience is external.
Refresh cadence
Per update path; the gate monitored continuously. Why — An update path that bypasses staging is a path onto every element the update touches, and it is usually created for a good operational reason.
Derived
Supplier severance demonstrationHeld standing

Evidence that each supplier’s access can actually be cut inside a stated period, without breaching the statutory availability floor — demonstrated, not asserted.

Produced by
LC-5
Owned by · maintained by
Authorizing Official / CISO · Platform and product owners
Consumed by
Nothing downstream inside the framework. This artifact terminates a chain and its audience is external.
Refresh cadence
Demonstrated at least annually, and included in reconstitution exercises. Why — Severance is a maneuver. Its execution time is unknown until someone has executed it, and the moment it is needed is the wrong moment to find out.
Where These Come From

Every Artifact Is Produced at a Step of the Loop, or Held Standing Between Them.