What the Framework Actually Leaves Behind.
A framework is judged on its output. This is the full index of artifacts ASOM-Fed produces — 61 of them — each with what produces it, who is accountable for it, which controls consume it, and how often it has to be refreshed before it stops being true. It is also the honest answer to a fair question: if a program adopts this, what will there be to show for it?
Mostly Derived. Where It Is Not, It Says So.
Every control in the catalog declares what it consumes and what it produces. Those declarations are the framework’s own statement of the chain, and they are the source for most of this page.
Derived from the Control Chain
54 of 61 entries name an artifact that appears as a declared output in the controls’ own input and output flows. The producing controls are read from those declarations, not restated here.
Derived a Second Time Over
Owner and maintainer come from the producing controls’ accountability chart. Consumers come from the other controls’ declared inputs. Neither can be softened by editing this page, and the two directions of the chain cannot disagree.
Composed, and Marked as Such
A handful of artifacts are named in the framework’s doctrine but assembled from several controls rather than emitted by one — the Cyber Running Estimate and the Bill of Defense are the clear cases. Each is marked Composed and says how it is assembled.
Authored: Names and Cadence
The artifact’s name, the sentence describing it, its refresh cadence and the reason for that cadence are written for this manual. The catalog states that currency must be maintained — which is the right thing for a control to say and an unhelpful place for a reference manual to stop.
Produced at Frame
The artifacts that give a cycle its direction. All five are short by design; none of them survives being long.
One signed paragraph stating what the defense exists to protect, what may be degraded to protect it, and the acceptable risk. The commander’s-intent analog, and the citation every downstream designation rests on.
- Produced by
- CG-1
- Owned by · maintained by
- Authorizing Official / CISO ·
- Refresh cadence
- Reviewed every cycle; revised when the brief gives a reason. Why — The brief feeds the intent by design. A deliberate no-change is a valid outcome and is recorded as one; an unreviewed intent is not.
Three to seven questions the cycle will try to answer, each naming the decision it informs, the collection source expected to answer it, and an individual owner.
- Produced by
- CE-2
- Owned by · maintained by
- Authorizing Official / CISO · Cyber Threat Intelligence cell
- Refresh cadence
- Set at each Frame; carried-forward items marked with the reason they survived. Why — A requirement that silently persists across cycles has stopped being a priority and become a standing wish.
The declared campaign phase and the scope it is declared against. Sets cadence, dominant forms of maneuver, and how wide the pre-authorization set runs.
- Produced by
- CG-2
- Owned by · maintained by
- Authorizing Official / CISO ·
- Refresh cadence
- Reviewed every cycle; declared out of band whenever the situation changes. Why — Phase is the one artifact that must be able to change between cycles — contact does not wait for a framing meeting.
The declared length of a cycle, its close date, and the refresh intervals that inherit from it. Makes “per cycle” a measurable unit rather than a figure of speech.
- Produced by
- CE-1
- Owned by · maintained by
- Authorizing Official / CISO · Cyber Threat Intelligence cell
- Refresh cadence
- Set at Frame, adjusted on phase change. Why — Cadence is derived from phase. A campaign in contact that is still running a monthly cycle has a cadence artifact that is describing last quarter.
The number the cycle will be judged against: defender decision loop versus adversary dwell, stated with units before the cycle runs.
- Produced by
- TA-3
- Owned by · maintained by
- Authorizing Official / CISO · Governance / RMF / ISSO
- Refresh cadence
- Set at Frame, reported against at Assess. Why — A threshold chosen once the result is in will be met every time, which is the point at which the number stops carrying information.
Produced at Map
Cyber Preparation of the Environment. These are the positional artifacts — everything computed later is computed over them.
The positional map of the estate: every element with a defensive layer, a defensive weight, a named accountable owner and its adjacencies. Not an asset inventory — an inventory enumerates, an overlay positions.
- Owned by · maintained by
- Authorizing Official / CISO · Platform and product owners, Governance / RMF / ISSO
- Consumed by
- TM-4 · KT-1 · CE-7 · RC-1 · FO-1 · FO-2 · FO-3 · FO-4 · FO-5 · FO-6 · WF-1 · FC-1 · ID-1 · EN-2 · DV-1 · SM-2 · SM-7 · CE-4 · ID-3 · ID-5 · EN-3 · EN-1 · KT-5 · CG-4 — AO, CTI, SOC, HUNT, PLAT, ISSO
- Refresh cadence
- Quarterly at the outside, and immediately on material architectural change. Why — Overlay freshness is itself a reported performance measure. Every number computed downstream inherits the overlay’s age, so its staleness is the program’s staleness.
The zone boundaries and the permitted- and denied-path register — the graph reachability is actually walked over, reconciled against observed flow telemetry rather than against intended configuration.
- Owned by · maintained by
- Authorizing Official / CISO · Platform and product owners
- Refresh cadence
- With the overlay, and on any change to segmentation or policy. Why — A denied path asserted from a configuration that changed last week is the single most load-bearing stale fact in the framework.
The elements whose control confers decisive advantage — each carrying the evidence that raised it above merely important, and the protection floor it owes as a result.
- Owned by · maintained by
- Authorizing Official / CISO · Cyber Threat Intelligence cell, Platform and product owners
- Consumed by
- KT-3 · SM-4 · SM-7 · RC-3 · WF-1 · FC-2 · LC-3 · ID-2 · ID-3 · DV-2 · DV-4 · CE-5 · CG-4 — AO, CTI, SOC, PLAT, ISSO
- Refresh cadence
- Reviewed every cycle; changed only with evidence. Why — Decisive points should be stable. A register that churns every cycle is tracking attention rather than terrain.
The enumerated routes an adversary could take toward each decisive point, including physical, supplier and maintenance routes, with unassessed routes recorded as intelligence gaps rather than as absence of risk.
- Produced by
- KT-3
- Owned by · maintained by
- Authorizing Official / CISO · Cyber Threat Intelligence cell
- Refresh cadence
- Every cycle, and on any change to the connection register. Why — Avenues are derived from permitted paths. When the paths move, the avenues have already moved whether or not anyone re-derived them.
The formal result: from each entry point, which decisive points are reachable over the permitted-path graph. The framework’s hardest single finding, and the headline of the brief when it changes.
- Produced by
- KT-4
- Owned by · maintained by
- Authorizing Official / CISO · Cyber Threat Intelligence cell
- Refresh cadence
- Every cycle. Why — Reachability is the one map product that changes without anyone deciding to change it — a single permissive rule is enough.
The specific barriers holding the line where reachability is prevented, each with a named enforcing owner. What the reachability result depends on, made explicit so its erosion is visible.
- Produced by
- KT-5
- Owned by · maintained by
- Authorizing Official / CISO · Platform and product owners
- Refresh cadence
- Every cycle, tracked across cycles for silent erosion. Why — Barriers fail quietly and by accumulation — an exception here, a temporary rule there. Only the cross-cycle view catches it.
Two courses of action, most likely and most dangerous, drawn against the decisive points already designated. Each is a route across ground the estate really has, not a category of threat.
The catalog does not carry a single control that emits "the threat COA sketch". It is assembled from the avenue analysis, the intelligence requirements that direct collection against it, and the branch planning that consumes it. Named here because the cycle doctrine names it as Map’s output and a products index that omitted it would be describing a different framework.
- Owned by · maintained by
- Authorizing Official / CISO · Cyber Threat Intelligence cell
- Refresh cadence
- Every cycle. Why — The scheme is planned against these two. Planning this cycle’s scheme against last cycle’s courses of action is the definition of fighting the last engagement.
Produced at Array
The scheme and the authority to execute it. An artifact here that has no authority level attached is a plan, not a scheme.
The forms of defensive maneuver the organization has adopted, each with the effectiveness it is assumed to deliver — recorded so the assumption can later be validated rather than believed indefinitely.
- Produced by
- SM-1
- Owned by · maintained by
- Authorizing Official / CISO · Governance / RMF / ISSO
- Consumed by
- SM-2 — AO, PLAT
- Refresh cadence
- Annually, and whenever validation proves an assumed indicator wrong. Why — The forms are durable; the assumed effectiveness values are not, and they are the part that feeds the coverage computation.
One graphic and one narrative: which forms of maneuver are sited where, in what sequence. The assignment record behind it carries the element, the avenue and the implementation state for every move.
The assignment and implementation-state records are declared control outputs. The one-page graphic and narrative are doctrine — the framework requires the scheme to be drawable on a page, and no control emits a drawing. Both halves are the artifact.
- Owned by · maintained by
- Authorizing Official / CISO · Platform and product owners
- Refresh cadence
- Every cycle. Why — The scheme is the cycle’s commitment. Carrying one forward unchanged is a decision that should be visible as one.
The single designated main effort for the cycle, and the sentence citing the decisive point that justifies it. The answer to which work wins when two things need the same engineer.
- Produced by
- SM-4
- Owned by · maintained by
- Authorizing Official / CISO ·
- Refresh cadence
- Every cycle; reconsidered on phase change. Why — Phase determines what the main effort should be. Declaring a new phase without revisiting the main effort leaves the campaign pointed at the last situation.
The branches answer the most-dangerous course of action; the sequels answer success. Every one names the authority it needs, and any expected to run inside the decision window is pre-authorized when it is written.
- Produced by
- SM-5
- Owned by · maintained by
- Authorizing Official / CISO · Cyber Threat Intelligence cell
- Refresh cadence
- Every cycle; rehearsed at least once per campaign phase. Why — A branch that has never been rehearsed is a paragraph. Its execution time under contact is unknown, which makes the whole tempo claim unknown.
Which defensive actions may be taken by whom without escalation, which need the Authorizing Official, and what is prohibited outright. The cyber analog of engagement authority, and the single largest determinant of tempo.
- Produced by
- CG-3
- Owned by · maintained by
- Authorizing Official / CISO · Governance / RMF / ISSO
- Refresh cadence
- Reviewed on phase change; revised after any incident that surfaced an authority the responders did not have. Why — The most useful revisions are written by people who have just discovered a gap in them. Reviewing only on an annual calendar throws that away.
The specific containment and response actions the SOC may execute at machine speed, bounded by the statutory availability floor. Directly measurable: it shortens the decision segment of the defender loop.
- Produced by
- TA-4
- Owned by · maintained by
- Authorizing Official / CISO ·
- Refresh cadence
- Reviewed on phase change; widened deliberately, never by drift. Why — The set widens in contested phases and narrows during recovery. Both directions are deliberate decisions with different risks.
A documented, walked path to rebuild each decisive point inside its recovery time budget, from media held outside the production identity plane — including a path for the identity plane itself.
- Owned by · maintained by
- Authorizing Official / CISO · Platform and product owners
- Refresh cadence
- Reviewed per cycle; walked at least annually, and after any material change to the systems it rebuilds. Why — A rebuild path documented and never walked has an unknown duration, which means the recovery time objective it supports is also unknown.
Produced at Maneuver
The evidence of execution. Thin artifacts, and the ones whose absence is most expensive — the headline metric is computed from them.
Every defensive action carried out, stamped twice — at the decision and at the effect. A thin, unglamorous table, and the one the headline metric is computed from.
Assembled from the implementation-state updates, the terrain refresh triggers material change raises, and the authority exceptions recorded against the rules of engagement. The cycle doctrine names it as Maneuver’s output; no single control emits it whole.
- Owned by · maintained by
- Authorizing Official / CISO · Platform and product owners, Governance / RMF / ISSO
- Refresh cadence
- Continuous, at the point of action. Why — Reconstructed after the fact, the record measures when someone had a moment to write it down — which is a measurement of workload rather than of tempo.
Planned, partial or operational, per maneuver assignment. The mechanism that stops intended work being counted as deployed protection.
- Produced by
- SM-3
- Owned by · maintained by
- Authorizing Official / CISO · Platform and product owners
- Refresh cadence
- Updated at execution, not at reconciliation. Why — A weekly reconciliation catches divergence one cycle late, and work that was done but never recorded is indistinguishable from work that was never done.
Actions taken outside the standing rules of engagement, with who approved them and why. Exceptions are not failures; unrecorded exceptions are.
- Produced by
- CG-3
- Owned by · maintained by
- Authorizing Official / CISO · Governance / RMF / ISSO
- Refresh cadence
- At the time of the exception; reported in the cycle brief. Why — A pattern of exceptions is the clearest available evidence that the pre-authorized set is too narrow, and it is only visible if the exceptions are counted.
Detect to decide to contain, measured per incident from the change record’s timestamps and reported as a distribution rather than as a mean.
- Produced by
- TA-1
- Owned by · maintained by
- Authorizing Official / CISO · SOC / Defensive Operations
- Refresh cadence
- Continuous; reported per cycle. Why — It is the denominator of the temporal advantage ratio, so a hole in it is a hole in the one figure that can report a program is losing.
What was hunted, how, and what was not found. Negative results are the half most often discarded, and they are the half that says what has actually been cleared.
Declared in the chain only as an external input to fusion. Named here because the framework treats hunt as the counterattack force and its output as a first-class product, not as telemetry.
- Owned by · maintained by
- Authorizing Official / CISO · Cyber Threat Intelligence cell
- Refresh cadence
- Continuous; consolidated per cycle. Why — Without a record of what was cleared, the same ground is hunted every cycle and the coverage of the hunt itself is unmeasurable.
The record of one engagement end to end: what was declared and on what criteria, the reconstruction with its dwell, scope and confidence, the evidence preserved and its custody, the authority exercised, and the verification that eradication actually happened before recovery began.
- Owned by · maintained by
- Authorizing Official / CISO · SOC / Defensive Operations, Hunt team
- Refresh cadence
- One per declared engagement; closed only when the reconstruction is complete. Why — EN-2 exists to stop an incident being closed on containment alone. An engagement closed without a reconstruction has corrected no estimate and taught the agency nothing, so completeness of the record is the close criterion rather than a formality after it.
Who was told what, and when, against the window that bound each obligation — inside the agency, to the federal community, and to those the mission serves. Includes the contribution made back to the community, or the recorded reason there was none.
- Produced by
- EN-6
- Owned by · maintained by
- Authorizing Official / CISO · Governance / RMF / ISSO
- Consumed by
- Nothing downstream inside the framework. This artifact terminates a chain and its audience is external.
- Refresh cadence
- Per engagement, against the statutory windows the obligation profile declares. Why — The windows are set by instruments outside the framework, which is why FO-7 has to have declared which of them bind before this artifact can be assessed as timely or late.
Produced at Fuse
Assessments rather than observations. Every one of these carries a confidence level and a stated basis for it.
What the cycle’s intelligence requirements returned: each answer graded for confidence and showing its working, and each requirement left unanswered recorded against the collection gap responsible.
- Produced by
- CE-3
- Owned by · maintained by
- Authorizing Official / CISO · Cyber Threat Intelligence cell
- Refresh cadence
- Every cycle. Why — The requirements were set for this cycle. Answering them next cycle answers a question that has stopped gating a decision.
The estimated time an adversary could operate undetected in this estate, with its basis stated — measured dwell, sector reporting, or partner intelligence — and its bias acknowledged.
- Produced by
- TA-2
- Owned by · maintained by
- Authorizing Official / CISO · Cyber Threat Intelligence cell
- Refresh cadence
- Every cycle; the basis restated rather than carried silently. Why — It is the numerator of the temporal advantage ratio. Carried forward without restatement, it turns a measured claim into an inherited one.
Whether the moves claiming operational status produced the effect the catalog assumed — from exercise results, control testing, and observed incident performance.
- Produced by
- SM-6
- Owned by · maintained by
- Authorizing Official / CISO · Hunt team
- Consumed by
- CE-4 — AO, ISSO
- Refresh cadence
- Every cycle for the main effort; annually across the full assignment set. Why — Validating everything every cycle is not affordable, and validating nothing means the coverage number is an assumption compounded over time.
The living situational picture the SOC, hunt and intelligence cell share: current posture, current assessments and their confidence, open requirements, and what has moved since the last look.
Assembled from fusion output, the computed posture, and the cycle record’s trend. Named in the framework’s doctrine as the running-estimate analog; no control emits it, because it is a view rather than a document.
- Owned by · maintained by
- Authorizing Official / CISO · Cyber Threat Intelligence cell, Governance / RMF / ISSO
- Refresh cadence
- Continuous. It is the one artifact that is never “as of last cycle”. Why — A running estimate that updates on the cycle boundary is a cycle report. Its whole purpose is to be current between the boundaries.
For each surviving hypothesis, the observable events that would confirm or kill it, handed to collection. The mechanism that makes this cycle’s analysis into next cycle’s requirements.
A structured analytic technique’s output rather than a control’s. It appears in the chain as the collection direction fusion returns to the intelligence requirements, which is the edge the catalog does declare.
- Owned by · maintained by
- Authorizing Official / CISO · Cyber Threat Intelligence cell
- Refresh cadence
- Every cycle; reviewed at Assess for which fired and which never could. Why — An indicator that has never fired in six cycles is either extraordinary good news or a badly written indicator, and the review is what tells them apart.
Produced at Assess
The published output and the record behind it. These are also what an oversight body reads as continuous-monitoring evidence.
Coverage and residual risk computed over the whole overlay population, weighted by consequence, discounted by implementation state and corrected by validated effectiveness — with the denominator stated.
- Produced by
- CE-4
- Owned by · maintained by
- Authorizing Official / CISO · Governance / RMF / ISSO
- Refresh cadence
- Every cycle. Why — It is the cycle’s posture. Computed less often than the cycle turns, it stops being able to show trend, which is most of its value.
Per mission service: the maneuvers and assets protecting it, its rolled-up coverage, and its residual risk. The view that lets a mission owner see their own defense rather than the enterprise average.
A rollup view over the coverage computation and the asset weighting, defined in the framework’s tower model rather than as a control output. The underlying numbers are entirely derived; the per-mission cut is the authored part.
- Owned by · maintained by
- Authorizing Official / CISO · Platform and product owners, Governance / RMF / ISSO
- Refresh cadence
- Every cycle, per mission service. Why — Its audience is the mission owner, who reads it on their own rhythm. An annual one is a report; a per-cycle one is a conversation.
Defender decision loop against adversary dwell, reported as a ratio against the threshold set at Frame, with the result written as a word: met, or not met. The framework’s single honest scoreboard.
- Owned by · maintained by
- Authorizing Official / CISO · Cyber Threat Intelligence cell, SOC / Defensive Operations, Governance / RMF / ISSO
- Refresh cadence
- Every cycle. Why — It is the measure that can come out badly, which is the reason it is reported on the same cadence as everything designed to come out well.
The ranked list of what to fix, ordered by residual risk, main-effort weighting, and decisive-point floor breaches — which sit above higher-volume, lower-weight work regardless of count.
- Produced by
- CE-5
- Owned by · maintained by
- Authorizing Official / CISO · Governance / RMF / ISSO
- Refresh cadence
- Re-ranked every cycle. Why — A backlog ranked once and worked forever is ordered by the situation that existed when it was written.
Every finding with an outcome: remediate with an owner and a date, accept with a named accepter and an expiry, or transfer with the party named. “Under review” is not a disposition.
- Produced by
- CG-4
- Owned by · maintained by
- Authorizing Official / CISO · Governance / RMF / ISSO
- Consumed by
- CG-5 — AO, ISSO
- Refresh cadence
- Every cycle; acceptances expire and return to the backlog. Why — Acceptance without expiry is an amnesty, and it is discovered years later by someone who was not in the room.
The closed record of the cycle — posture, loop measurement, conclusions and their confidence, backlog state at close — and the trend across cycles that makes a second cycle worth more than a first.
- Produced by
- CE-6
- Owned by · maintained by
- Authorizing Official / CISO · Governance / RMF / ISSO
- Refresh cadence
- Closed at the end of every cycle. Why — It is the continuous-monitoring evidence. A record closed irregularly produces a trend line with gaps in it, and gaps are what an assessor asks about.
The published product: terrain, reachability, main effort, temporal advantage, coverage, trend, and the top-ranked backlog items — each confidence-tagged. Also the evidence that feeds the next intent.
How the cycle’s output maps onto the organization’s existing control baseline and assessment results, so that federal obligations are satisfied as a by-product of defending rather than as a parallel program.
- Produced by
- CG-5
- Owned by · maintained by
- Authorizing Official / CISO · Governance / RMF / ISSO
- Consumed by
- Nothing downstream inside the framework. This artifact terminates a chain and its audience is external.
- Refresh cadence
- Every cycle; formally reconciled at authorization milestones. Why — The mapping is what makes the cycle record usable as continuous-monitoring evidence. Reconciled only at milestones, the evidence arrives after the decision it was meant to inform.
Standing — resilience
Held continuously rather than produced per cycle. Their failure mode is age, not absence.
A declared recovery time and recovery point objective per mission service, agreed with the service owner and constrained by statutory deadlines rather than by what is currently achievable.
- Produced by
- RC-1
- Owned by · maintained by
- Authorizing Official / CISO · Platform and product owners
- Refresh cadence
- Annually, and whenever a mission service is added or its statutory position changes. Why — The objective is a commitment, not a measurement. Revising it because it was missed is how a recovery program grades its own homework.
The means of recovery held outside the production identity plane, and the isolation boundary that keeps it there — itself a load-bearing barrier that has to be monitored.
- Produced by
- RC-2
- Owned by · maintained by
- Authorizing Official / CISO · Platform and product owners
- Refresh cadence
- Verified per cycle; the boundary monitored continuously. Why — The isolation is the entire value. It erodes through ordinary convenience — one integration, one service account — and only continuous monitoring catches that.
Restored data verified against an independently held integrity record, so that recovery is a demonstrated claim rather than an assumption that the backup was clean.
- Produced by
- RC-4
- Owned by · maintained by
- Authorizing Official / CISO · Platform and product owners
- Consumed by
- RC-5 — AO, SOC
- Refresh cadence
- Exercised at each reconstitution exercise; performed after any real recovery. Why — Verification first attempted during a real recovery is being attempted at the worst possible time by people with no practice at it.
What was rebuilt, from what media, in what time, verified how — and which recovery objectives were missed. Includes supplier severance scenarios.
- Produced by
- RC-5
- Owned by · maintained by
- Authorizing Official / CISO · SOC / Defensive Operations
- Consumed by
- Nothing downstream inside the framework. This artifact terminates a chain and its audience is external.
- Refresh cadence
- At the stated exercise cadence — annually at minimum, per decisive point. Why — The framework’s claim is that every recovery objective has been demonstrated within its stated period. That claim expires on a schedule.
Standing — federal obligations
The terrain the framework had to add because a federal estate has ground that the five zero-trust pillars do not cover.
The mission services whose availability is set by statute or regulation, and the floor below which degradation stops being a defensive choice. Bounds what may be pre-authorized and what may be degraded under contact.
- Produced by
- FO-5
- Owned by · maintained by
- Authorizing Official / CISO · Governance / RMF / ISSO
- Refresh cadence
- Annually, and on any change to the authorizing instruments. Why — It is the pre-agreed statement made when nobody was under pressure. Its whole value is being settled before the moment it is needed.
Where privacy holdings and controlled unclassified information sit, the authorities under which they are held, and the boundaries their handling requires — expressed as denied paths, not as policy statements.
- Owned by · maintained by
- Authorizing Official / CISO · Governance / RMF / ISSO
- Consumed by
- LC-3 — AO, PLAT
- Refresh cadence
- Annually, and on any new collection or new system of records. Why — The register feeds asset weighting and decisive-point designation. Out of date, it under-weights exactly the holdings that carry the heaviest obligations.
What is inherited from a provider and what remains the agency’s, drawn from provider authorization packages and responsibility matrices, so inherited mitigation is counted once and correctly.
- Produced by
- FO-3
- Owned by · maintained by
- Authorizing Official / CISO · Governance / RMF / ISSO
- Consumed by
- Nothing downstream inside the framework. This artifact terminates a chain and its audience is external.
- Refresh cadence
- On each provider authorization change, reviewed annually. Why — Miscounted inheritance is the most common source of coverage that exists on paper and nowhere else.
Engineering and facilities systems as their own defensive layer, with the enterprise-to-operational crossings enumerated as avenues of approach.
- Produced by
- FO-4
- Owned by · maintained by
- Authorizing Official / CISO · Platform and product owners
- Consumed by
- FC-1 — AO, PLAT
- Refresh cadence
- Annually, and on any new crossing between enterprise and operational networks. Why — Crossings are added for maintenance convenience and are rarely announced. An annual register with no change-triggered refresh will not see them.
Standing — workforce
People as terrain. Modeled because the compromise of certain roles is equivalent to the compromise of a decisive point.
The roles whose compromise is equivalent to compromising a decisive point — the operators of decisive points, and the roles with standing access to them.
- Produced by
- WF-1
- Owned by · maintained by
- Authorizing Official / CISO · Platform and product owners
- Refresh cadence
- Reviewed per cycle against the decisive point register; reconciled with HR data quarterly. Why — Roles change faster than systems do, and a role register reconciled annually describes an organization that has since reorganized.
Which individuals hold which high-consequence access, reconciled against the identity system rather than against the last access review spreadsheet.
- Produced by
- WF-2
- Owned by · maintained by
- Authorizing Official / CISO · Platform and product owners
- Refresh cadence
- Continuous, reconciled per cycle. Why — It is what revocation is executed against. A stale register makes separation tempo unmeasurable and revocation incomplete.
Preparation targeted at the tradecraft that actually targets each role, and the gaps that would slow the decision loop if the role were needed under contact.
- Produced by
- WF-3
- Owned by · maintained by
- Authorizing Official / CISO · Governance / RMF / ISSO
- Consumed by
- TA-5 — AO, SOC
- Refresh cadence
- Annually per role; re-targeted whenever intelligence changes what a role is being attacked with. Why — Readiness aimed at last year’s tradecraft is training, not readiness, and it reports the same either way.
The stated position on insider risk: what may be done, by whom, under what legal, privacy and labor-relations constraints, and how a case is dispositioned.
- Produced by
- WF-4
- Owned by · maintained by
- Authorizing Official / CISO · Governance / RMF / ISSO
- Refresh cadence
- Annually, and on any change to the legal or labor framework. Why — The constraints here are external and non-negotiable. Discovering them during a case is the failure this artifact prevents.
How long it takes to remove everything an individual holds, per system, and which systems cannot be revoked in a single action. Feeds terrain ownership so revocation does not orphan an element.
- Produced by
- WF-5
- Owned by · maintained by
- Authorizing Official / CISO · Platform and product owners
- Refresh cadence
- Measured on every separation; reported per cycle. Why — Revocation tempo is a defensive fire measured in the same units as the rest of the loop, and it is measurable on every ordinary departure.
Standing — facilities
Physical ground. Several avenues of approach begin here, and none of them appear on a network diagram.
Where elements physically are, which personnel populations are associated with each site, and which facilities carry mission services.
- Produced by
- FC-1
- Owned by · maintained by
- Authorizing Official / CISO · Platform and product owners
- Refresh cadence
- Annually, and on any site change. Why — Physical location changes rarely and consequentially. The refresh cost is low and the omission cost — an unmapped site carrying a mission service — is not.
Zone divisions inside facilities, reconciled against the logical trust zones, with physical approach routes to decisive points enumerated as avenues.
- Produced by
- FC-2
- Owned by · maintained by
- Authorizing Official / CISO · Platform and product owners
- Consumed by
- FC-3 — AO, PLAT
- Refresh cadence
- Annually, reconciled against the logical zones each cycle. Why — The reconciliation is where the finding lives: a logical boundary that no physical boundary supports is a barrier that only exists in configuration.
Who may perform maintenance in which zone, under what escort and in what window — including supplier maintenance, which is where standing physical access usually hides.
- Produced by
- FC-3
- Owned by · maintained by
- Authorizing Official / CISO · Platform and product owners
- Consumed by
- Nothing downstream inside the framework. This artifact terminates a chain and its audience is external.
- Refresh cadence
- Per maintenance window; the standing-access set reviewed per cycle. Why — Standing maintenance access accumulates. Reviewing it per cycle is the only thing that stops a temporary arrangement becoming a permanent path.
How long each facility can carry the mission services housed in it — power, cooling, connectivity — measured against the recovery objectives those services must meet.
- Produced by
- FC-4
- Owned by · maintained by
- Authorizing Official / CISO · Platform and product owners
- Consumed by
- Nothing downstream inside the framework. This artifact terminates a chain and its audience is external.
- Refresh cadence
- Annually, and whenever a service’s recovery objective is tightened. Why — A facility whose endurance is shorter than the objective it supports makes that objective unachievable, and the finding only appears when the two are compared.
Standing — supply chain
Suppliers as external actors with real paths onto real terrain, and the ability to remove them.
Suppliers as external actors on the overlay, with the access each holds, the paths that access implies, and the contract behind it.
- Owned by · maintained by
- Authorizing Official / CISO · Platform and product owners, Governance / RMF / ISSO
- Refresh cadence
- On each contract change; reconciled against procurement records quarterly. Why — Supplier access is created by contract and removed by nobody. Only a reconciliation against procurement finds the access that outlived its engagement.
Where components came from, from inventories, build manifests and supplier attestations — and which components have an origin that cannot be verified.
- Produced by
- LC-2
- Owned by · maintained by
- Authorizing Official / CISO · Platform and product owners
- Refresh cadence
- At each build or release; reviewed per cycle for unverifiable components. Why — Provenance recorded at build time is cheap. Reconstructed later it is archaeology, and it is usually incomplete.
How supplier access is brokered, time-bounded and constrained — and the prohibition on standing supplier access to designated decisive points.
- Produced by
- LC-3
- Owned by · maintained by
- Authorizing Official / CISO · Platform and product owners
- Refresh cadence
- Per engagement; the standing set reviewed per cycle. Why — Brokered access is also the severance point. If the constraint record is stale, so is the ability to cut the supplier off.
How updates arriving from suppliers are verified and staged before reaching production. The staging gate is a barrier in its own right and is monitored as one.
- Produced by
- LC-4
- Owned by · maintained by
- Authorizing Official / CISO · Platform and product owners
- Consumed by
- Nothing downstream inside the framework. This artifact terminates a chain and its audience is external.
- Refresh cadence
- Per update path; the gate monitored continuously. Why — An update path that bypasses staging is a path onto every element the update touches, and it is usually created for a good operational reason.
Evidence that each supplier’s access can actually be cut inside a stated period, without breaching the statutory availability floor — demonstrated, not asserted.
- Produced by
- LC-5
- Owned by · maintained by
- Authorizing Official / CISO · Platform and product owners
- Consumed by
- Nothing downstream inside the framework. This artifact terminates a chain and its audience is external.
- Refresh cadence
- Demonstrated at least annually, and included in reconstitution exercises. Why — Severance is a maneuver. Its execution time is unknown until someone has executed it, and the moment it is needed is the wrong moment to find out.