Eighteen Months, Three Phases, and One of Them Needs No Money at All.
The adoption summary gives each phase a goal, a work list and a sentence of exit criteria. A program actually attempting this needs more: which controls come into force when, which artifacts have to exist by the end of each phase and which are knowingly left half-built, who has to be staffed and how heavily, what the Authorizing Official personally has to decide, what it costs, and how to test that a phase is finished rather than assert it. All of that is here, along with the part the summary cannot carry — the first ninety days at week granularity.
One Authored Premise. Everything Else Is Computed from It.
A roadmap is the easiest artifact in a framework to write dishonestly, because nothing in it is checkable until eighteen months have passed. This one is built so that most of it is checkable now. Its three phases are this rollout's own A/B/C — a different thing from the framework's six campaign phases, which outlive adoption.
Authored: Which Phase Each Control Belongs To
All 78 controls are assigned to A, B or C, each with the reason. This is the single judgment the page rests on and the first thing an adopter should argue with — a program with an operational-technology estate has an excellent case for pulling four controls forward.
Derived: What Each Phase Produces
Every artifact in the framework declares which controls produce it. An artifact is whole at the phase where the last of those comes into force, and partial before that. Nothing about the artifact list is written here twice — the completeness of each is read off the chain.
Derived: Who Has to Be Staffed
Which roles a phase puts to work is read from the accountability chart of the controls entering it, not from a list of job titles. A phase cannot quietly staff a role that has no work in it, and cannot quietly omit one that does.
Derived: The Phase Boundaries
What a phase inherits comes from the controls’ own declared inputs. So does the more uncomfortable figure: what a phase runs without, because an input it depends on will not exist until later. Phase A carries 13 such edges and the page names every one.
Authored: Effort, Decisions, Exit Tests
Person-days, the Authorizing Official’s decisions, the exit tests and the ninety-day plan are written rather than computed — no data could produce them. Each is pinned to a control that has to exist by then, and the pinning is validated.
Joined, Not Copied
The window, name, goal and work list of each phase come from the same source the adoption summary renders. There is one copy. If that changes, this page changes with it rather than disagreeing with it quietly.
If You Can Only Do One Thing.
Most programs will not get three phases of runway. The honest question is which single piece of work survives a budget that disappears in month four — and the framework’s own chain answers it without needing an opinion.
Build one honest terrain overlay of one mission service.
The framework’s own chain picks this, and it still picks it after the catalog grew. Eighteen of the seventy-eight controls declare the terrain overlay’s output as an input — half again as many as the next-highest, decisive-point identification at twelve. The margin narrowed at v6.1 rather than widened, and the reason is worth stating: the identity, devices and engagement families all consume decisive points directly, so KT-1 gained more new consumers than TM-1 did. First place did not change; the gap did.
It is also the only high-degree control that can start from outside the framework. Almost every other control’s inputs are other controls; the overlay’s are the estate itself. A program with nothing in place can begin here on a Monday and cannot begin anywhere else without first inventing an input.
And it is the one piece of work whose absence is invisible. A missing rules-of-engagement document announces itself the first time somebody needs approval at 2am. A missing overlay produces coverage percentages, reachability answers and residual-risk figures that all look fine and are computed over ground nobody has checked.
Controls declaring another control’s output as an input
- TM-1Terrain Inventory and Overlay
- KT-1Decisive Point Identification
- CG-1Defensive Intent
- TM-2Defensive Layer Classification
- FO-5Statutory Availability Floor
- ID-1Identity Plane Definition
Direct consumption, not transitive influence. The framework is a loop, so its control chain is a cycle: follow the edges far enough from almost anywhere and you arrive everywhere. Transitive reach therefore ranks nothing, and direct consumption is the only measure that discriminates.
What “one honest overlay” actually means
- One mission service, not the estate. Depth beats breadth: an overlay a hunt team could work from is worth more than an inventory nobody trusts.
- Every element carries a defensive layer, a criticality and exposure weight, and a named individual — not a team mailbox.
- The connections between those elements, including the paths that are deliberately denied, each with the control that denies it.
- A refresh interval, with the same named individual attached to it. An overlay without a currency owner is a snapshot, and a snapshot ages into a confident lie.
The stronger objection is that the defensive intent should come first, because the overlay’s scope is a command decision and building the wrong overlay wastes a quarter.
Half true, and the resolution is cheap. The scope sentence — which mission service, and what is knowingly left unmapped — takes an hour and does need the Authorizing Official. The full intent paragraph does not have to come first, and is better written second: an intent drafted before anyone has seen the ground names things to protect that turn out not to exist, and omits the one that does.
And specifically not these, however tempting
Eleven forms with nowhere to site them is vocabulary. Maneuver assignment consumes the overlay’s elements; without them an assignment can only name a product.
Coverage is computed over the overlay, weighted by the overlay, and bounded by implementation state that does not exist yet. A first coverage figure without terrain is a number with no denominator anyone can inspect.
Automated execution of fires nobody has yet authorized, against terrain nobody has yet mapped, is a faster way to do nothing. The wiring is a Phase B item and it is the only one.
Useful, and not this. An exercise tests decisions against a scenario; the overlay is what makes any of those decisions checkable afterwards.
TM-1 Terrain Inventory and Overlay — the full control entry →
Establish doctrine
Twenty controls, no procurement, and six decisions that only one person can make. Phase A is writing, deciding, and discovery over an estate that already exists.
Phase A is the phase adopters skip, and it is skipped for an understandable reason: none of it looks like defense. Nothing is deployed, nothing is blocked, and at the end of ninety days the estate is exactly as exposed as it was at the start. What has changed is that the program can now say what it is defending, on what ground, under what authority, and on what clock — and every number the framework produces afterwards is computed over those four answers.
The work divides cleanly. Roughly half is discovery: walking an estate that already exists and writing down what is on it, who owns each piece, what connects to what, and which paths are deliberately denied. That half is tedious, unglamorous and cannot be bought. The other half is decision: a paragraph, a phase, a cadence, a set of rules of engagement, and a statement of what may be degraded. That half is fast and expensive in a different currency — it needs the Authorizing Official in the room, arguing, twice.
The scope is one mission service. Not the estate. An adopter who scopes Phase A to the whole agency will produce an overlay that is broad, shallow and wrong in ways nobody can detect, and will spend the ninety days in reconciliation meetings. One service, mapped to a depth where a hunt team could work from it, is worth more than an estate-wide inventory nobody trusts — and it establishes the standard the second service is built to.
Phase A also runs knowingly incomplete, and the framework’s own data says exactly how. Thirteen input edges declared by Phase A controls point at controls that will not exist until Phase B or C. The reporting controls at the end of the loop are the worst affected: the cycle brief declares six inputs and will have two. That is not a defect in the roadmap, it is what “cycle 1 is thin” means when stated precisely, and recording it as a finding at the first Assess is the correct behavior.
Platform-owner availability. Every discovery control depends on somebody who does not report to the CISO answering a question about their own system, and those answers arrive at the speed of other people’s calendars. Book the sessions in week 1, not week 5.
Nothing. Phase A has no procurement dependency of any kind, and that is the reason it is where an adopter starts. A program that believes it needs to buy something to begin has misread which phase it is in.
The 21 controls that come into force in Phase A
Grouped by catalog family. Every control in the framework enters in exactly one phase, so the three lists together are the whole of it — a control missing from all three would fail the build rather than quietly never appearing.
CG-2 Phase Declaration — Declared first, because cadence and authority both resolve against it. For nearly every adopter the first declaration is Phase 0, Shape — and saying so out loud is the point. A phase that is never declared can never be changed.
CG-1 Defensive Intent — One paragraph, signed. It has to name something that may be degraded; a paragraph that only protects has designated nothing, and the main effort control downstream then has nothing to consume.
CG-3 Rules of Engagement — Split by reversibility rather than by severity. The first version will be narrow; writing down how narrow is more useful than widening it before anyone has operated inside it.
CG-5 Control Inheritance Mapping — Inherit the assessments you already hold. Programs that re-test what 800-53 has already tested, out of caution, are the ones that conclude this framework is expensive.
FO-7 Obligation Profile Declaration — Declared before FO-5, because it is what makes FO-5 answerable: until the obligation profile names which instruments bind this agency, "statutory availability floor" has no denominator and the FO coverage figure means nothing. An hour of legal review, and every later FO number becomes comparable.
FO-5 Statutory Availability Floor — Traced to the instrument that creates the obligation, not to a service-level target somebody wrote into a contract. It bounds what the intent may offer up, so it has to land before the intent is signed rather than after.
FO-1 Privacy Terrain Identification — Which elements hold personally identifiable information. Asset weighting is dishonest without it, which is why it lands alongside TM-3 rather than in the federal-obligations sweep later.
CE-1 Cycle Cadence — A cadence and a close date on a calendar other people can see. Monthly is the honest starting point and the one most adopters should not beat.
CE-2 Priority Intelligence Requirements — Between three and seven requirements, each naming the decision it informs and carrying a named owner inside the cell. Twenty requirements is a wish list — a cycle closes a handful and the rest become permanent.
CE-3 Fusion and Confidence — The first fusion will be thin. Publishing a moderate or low confidence in cycle 1 is what sets the norm that makes the confidence field mean anything in cycle 12.
CE-6 Cycle Record and Trend — Opened in cycle 1 with a single row. Its entire value is in the series, and a record started in month nine has already lost the baseline it exists to establish.
CE-7 Brief Generation and Distribution — Cycle 1’s brief is short, and it should name what the cycle could not answer. A brief with no unanswered requirement in it means the requirements were written to be answerable.
TM-1 Terrain Inventory and Overlay — The highest-leverage control in the framework: 18 of the 78 name its output as a declared input, 1.5× the next. Scoped in Phase A to one mission service, deliberately.
TM-2 Defensive Layer Classification — Every element carries a defensive layer. An unlayered element cannot be counted, weighted, or covered — it is simply absent from every number the framework later produces.
TM-3 Asset Weighting — Criticality and exposure per element, set by the mission owner rather than by the security function. Weighting is the step at which an overlay stops being an inventory.
TM-7 Terrain Ownership — A named individual per element. A mailbox is not an owner, and a first overlay full of them is the most common way Phase A finishes looking complete while owning nothing.
TM-6 Terrain Currency — A refresh interval with an owner. The failure this prevents is silent by construction — a stale overlay produces confident decisions about ground that has moved.
TM-4 Trust Zone Definition — A trust zone is defined by the control that enforces it. Zones that exist only on a diagram get recorded as findings in Phase A, not as zones. That distinction is most of the value of doing this early.
TM-5 Connection and Denied-Path Register — Connections, and the paths deliberately blocked, each with the control that blocks it. This is the graph Phase B’s avenue and reachability analysis runs over; building it later means rebuilding it.
KT-1 Decisive Point Identification — Short enough to argue about. Phase A names what must not fall; the protection floor that goes with it is Phase B work. Naming and defending are different activities and conflating them stalls both.
RC-1 Recovery Objectives — Recovery time and recovery point per mission service, declared by the service owner. Cheap to argue about now, impossible to argue about during a recovery, and a precondition for the rebuild work in Phase B.
What Phase A inherits
Nothing. Phase A is the entry point: every control in it consumes either the estate itself or another Phase A control. That is the property that makes it startable by a program with nothing in place, and it is why it is first.
What Phase A runs without
13 declared inputs across 7 controls point at something that will not exist until a later phase. The control chain is a loop, so some forward reference is unavoidable in any ordering — but a phase that does not know which of its inputs are missing will read its own thin output as a result.
Waiting on KT-4 (Phase B).
Waiting on WF-5 (Phase B).
Waiting on TA-4 (Phase B), SM-5 (Phase B).
Waiting on KT-3 (Phase B).
Waiting on CG-4 (Phase B).
Waiting on CE-4 (Phase B), TA-1 (Phase B), CE-5 (Phase B).
Waiting on KT-4 (Phase B), SM-4 (Phase B), TA-3 (Phase C), CE-4 (Phase B).
The 15 artifacts that must exist, whole, by the end of Phase A
Derived: an artifact is whole when every control that declares it as an output is in force. Nothing here is a separate list to be maintained — change a control’s outputs and this changes with it.
- Defensive intent paragraphFrom CG-1
- Priority Cyber Intelligence RequirementsFrom CE-2
- Phase declarationFrom CG-2
- Cycle cadence and calendarFrom CE-1
- Cyber Terrain OverlayFrom TM-1 + TM-2 + TM-3 + TM-6 + TM-7
- Trust zones and the connection registerFrom TM-4 + TM-5
- Rules of engagementFrom CG-3
- Authority exception logFrom CG-3
- Fused assessmentFrom CE-3
- Indicators and signpostsFrom CE-3 + CE-2
- Cycle record and trendFrom CE-6
- Cycle briefFrom CE-7
- Control inheritance mappingFrom CG-5
- Recovery objectives registerFrom RC-1
- Statutory availability floorFrom FO-5
And 7 artifacts exist in part — one producing control is in force and another is not. A program that reports these as delivered is reporting a fragment, so each is named with what it is waiting for.
- Decisive point registerWaits on KT-2 (Phase B)
- Threat course-of-action sketchWaits on KT-3 (Phase B) · SM-5 (Phase B)
- Change recordWaits on SM-3 (Phase B)
- Cyber Running EstimateWaits on CE-4 (Phase B)
- Hunt results, including negative resultsWaits on KT-4 (Phase B)
- Bill of DefenseWaits on CE-4 (Phase B)
- Privacy and controlled-information terrain registerWaits on FO-2 (Phase B)
Who Has to Be Staffed
The counts are derived from the accountability chart of the controls entering this phase. The commitment beside each is authored — a count of controls says a role is needed, not how much of a person it needs.
One analyst at roughly 0.7 FTE for the quarter.
The role Phase A cannot be run without. It is Responsible for five of the twenty-one controls entering here — fewer than platform owners carry, and more consequential, because it drafts all three of the governance artifacts the Authorizing Official then decides. Where no intelligence cell exists, this is the hire — before any tool.
Six to ten owners, three to five days each, spread across the quarter.
Not a full-time commitment, and the one most often mis-scoped as a meeting invitation. Platform owners supply the ground truth for the inventory, the zones, the connections and the recovery objectives; none of those four is answerable by the security function alone.
Roughly 0.3 FTE.
Accountable for the cycle record from cycle 1, responsible for the inheritance mapping, and co-drafting the rules of engagement. The inheritance work is the single largest cost saving available anywhere in the roadmap and it is available in the first quarter.
Two to three days.
The SOC is Responsible for nothing entering in Phase A and consulted throughout it, and that is correct — there is nothing sited yet to execute against. Its Phase A job is to be consulted on the rules of engagement it will later operate under, which is a reading-and-negotiating task rather than an operational one. A phase that gives the SOC work to do this early has sited something before it mapped the ground.
Two to three days, consulted.
Denied paths and decisive-point lists want checking by someone whose job is to falsify them, which in this framework is hunt. Where there is no hunt function, leave the role vacant on the chart rather than relabeling the SOC to fill it.
Four half-days across the quarter.
Accountable for all twenty-one controls entering here and Responsible for none — the correct shape for command, and safe only if the six decisions below are genuinely made rather than approved.
What it costs: 117 person-days, about 1.8 full-time equivalents
Spread over six roles and never concentrated in one. The person-day figures are authored from the shape of the work rather than derived — but they are bounded below by the fact that no line item here is a purchase, and bounded above by the plain observation that a program which cannot find this much for one quarter cannot run the loop afterwards either.
| Role | Person-days | On what |
|---|---|---|
| Cyber Threat Intelligence cell | 45 | Overlay construction, requirements, the first fusion and the brief. |
| Platform and product owners | 32 | Ground truth: inventory, ownership, zones, connections, recovery objectives. Spread across six to ten people. |
| Governance / RMF / ISSO | 20 | Inheritance mapping, rules-of-engagement drafting, opening the cycle record. |
| SOC / Defensive Operations | 10 | Rules-of-engagement drafting and an inventory of what already executes without approval. |
| Hunt team | 6 | Consulted on denied paths and the decisive-point list. |
| Authorizing Official / CISO | 4 | Six decisions, one signature, and reading the material behind them. |
Cyber Threat Intelligence cell
- Person-days
- 45
- On what
- Overlay construction, requirements, the first fusion and the brief.
Platform and product owners
- Person-days
- 32
- On what
- Ground truth: inventory, ownership, zones, connections, recovery objectives. Spread across six to ten people.
Governance / RMF / ISSO
- Person-days
- 20
- On what
- Inheritance mapping, rules-of-engagement drafting, opening the cycle record.
SOC / Defensive Operations
- Person-days
- 10
- On what
- Rules-of-engagement drafting and an inventory of what already executes without approval.
Hunt team
- Person-days
- 6
- On what
- Consulted on denied paths and the decisive-point list.
Authorizing Official / CISO
- Person-days
- 4
- On what
- Six decisions, one signature, and reading the material behind them.
What the Authorizing Official personally decides — 6 decisions
Not artifacts to approve. Decisions that cannot be made by anyone else, each landing in a specific control, and each with the reason delegating it fails.
What may be degraded in order to protect the mission — written as a sentence, inside the intent paragraph.
CG-1 Staff will happily write the protective half. Only the accountable authority can offer something up, and an intent that offers nothing up has designated no main effort. This is the hardest hour the role spends in Phase A and the highest-leverage one.
Which mission service the first cycle is scoped to — and therefore what is deliberately left unmapped for now.
TM-1 Scope is a command decision because it is a decision about what will be knowingly undefended for the next quarter. Delegated to the security function it becomes “everything”, which produces an overlay nobody can act on.
The campaign phase, declared against that scope.
CG-2 The declaration sets cadence and the width of the pre-authorized set. Both are risk positions, and a risk position adopted by default at whatever level noticed it is the thing this control exists to prevent.
Which defensive fires may execute without a phone call — drawn on the reversibility line, not the severity line.
CG-3 Of everything an Authorizing Official controls, this moves tempo furthest — and it is the one setting that does not come back: a SOC that steps outside the rules once, even successfully, meets a narrower list at the next review.
The cadence the program will actually sustain — accepting that a slower honest cadence beats a faster aspirational one.
CE-1 A missed cadence and a lowered cadence look identical in the record six months later, and only one of them was a decision. Choosing the number is a command act precisely because the pressure runs toward choosing too fast.
Whether a contested inheritance claim stands — where the ISSO says an existing assessment already satisfies a requirement and an assessor may disagree.
CG-5 Inheritance is a risk acceptance wearing an administrative coat. Deciding it cautiously by default doubles the assessment burden and is the most common reason a program concludes the framework is expensive.
Exit Criteria, Written as Tests
The summary criterion for this phase is: A one-page overlay and a one-paragraph intent that the CISO will actually stand behind. That is the right size for a roadmap and it is not checkable. Below are 7 things you can actually do, with what a pass looks like from outside and what a failure means — which is never “the test failed”.
CG-1 Hand the defensive intent to a platform owner who was not in the room and ask what they would do differently on Monday.
They name one specific thing, without asking a clarifying question first.
The intent constrains nothing. “Protect the mission” names no main effort, which leaves every effort equally principal and therefore none of them principal at all.
TM-7 Pick three elements at random from the overlay and ask for the individual who owns each.
Three human names, each reachable this week, each of whom agrees they own it.
Terrain ownership is a mailbox. That is unowned ground with an address, and every finding routed to it will age instead of dispositioning.
TM-6 Ask the overlay’s owner when it was last reconciled against the real estate, and what changed.
A date inside the stated refresh interval, and a non-empty list of what moved.
The overlay is a snapshot, not a living artifact. It will produce confident decisions about ground that has already moved, which is worse than having no overlay at all.
TM-5 Take one denied path from the connection register and attempt it, in a change window, from the source it is denied from.
It is denied — and the control that denies it is the one the register names.
The zone is on the diagram and not in the estate. A paper zone should be recorded as a finding, which is the only reason paper zones ever get fixed.
CG-3 Read the rules of engagement and count the actions the SOC may take at two in the morning on a Sunday without a phone call.
The count is greater than zero, and every action on the list has a named reverse.
There is no engagement authority. The loop cannot close faster than the adversary adapts, and the rest of the framework is decoration.
CE-2 Open the first cycle brief and look for an intelligence requirement that was not answered.
At least one, stated plainly, with what would be needed to answer it.
The requirements were written to be answerable. They are describing collection that already happens rather than decisions the program needs to make.
CG-5 Ask the ISSO which existing assessments were cited as inheritance, then pick two and ask them to be defended.
Both citations hold up against the requirement they are claimed to satisfy.
Either the inheritance is over-claimed, which an assessor will find, or it was never claimed at all — in which case the program has signed up to assess the same thing twice.
The Work, as the Adoption Summary States It
Rendered from the same source the summary page uses. There is one copy of this list, so the two pages cannot come to disagree about what the phase involves.
- Publish the defensive intent paragraph, signed by the Authorizing Official.
- Stand up the intelligence cell that will own the Frame and Fuse steps.
- Build the first Cyber Terrain Overlay across the portal, the crown-jewel records and the identity plane.
- Set the initial Priority Cyber Intelligence Requirements.
- Define the rules of engagement: which defensive fires are pre-authorized, and which need the AO.
Emplace the maneuvers
Twenty-two controls, one procurement dependency, and the phase in which the framework stops being a description of the estate and starts changing what happens on it.
Phase B is where the moves go on the ground. It is also the phase with the highest failure rate, and the reason is structural rather than technical: twelve of its twenty-two controls are Responsible to platform and product owners, who typically report to a program executive on delivery rather than to the CISO on defense. Nothing in an accountability chart fixes that. What the framework does about it is narrower — every element carries a named individual from Phase A, every finding routes to that individual with a date, and the cycle record makes an unactioned route visible across cycles rather than only inside one.
The one thing that must be bought sits here: the orchestration wiring that lets a pre-authorized fire execute at machine speed. It is worth being precise about what that purchase does and does not do. It does not create engagement authority — that was decided in Phase A and costs nothing. It removes the human from the execution path for actions somebody has already agreed to. A program that buys the wiring before settling the authority has bought a faster way to do nothing.
Phase B is also where the first honest number arrives, and where most programs flinch. Coverage computed over a real overlay, against maneuvers whose implementation state reflects operation rather than procurement, comes out low — routinely under forty percent on a first pass. The correct response is to argue with the model: which elements are in the denominator, which maneuvers were marked implemented on the strength of a license, and which decisive points are carrying no floor. The incorrect response, and the common one, is to instruct someone to improve the number.
Twenty-two controls in six months is the densest stretch of the roadmap and it should be sequenced rather than parallelised. The order that works: avenues and reachability first, because they tell you where to site; then assignment and implementation state; then the loop measurement and the pre-authorized set; then coverage, which consumes all of it. Running coverage early produces a number over an empty scheme and teaches the program that the metric is meaningless.
The orchestration integration. Everything else in Phase B can proceed in parallel; the pre-authorized response set cannot be exercised until the wiring is in place, and the loop-measurement figures produced before it are baseline rather than result.
One item: the orchestration layer that executes pre-authorized fires without a human in the path. Most agencies already own something that can do this and have not connected it to a decision. Check before buying — the common finding is that the capability was licensed two renewals ago.
The 33 controls that come into force in Phase B
Grouped by catalog family. Every control in the framework enters in exactly one phase, so the three lists together are the whole of it — a control missing from all three would fail the build rather than quietly never appearing.
SM-1 Maneuver Catalog Adoption — Adopt the forms you will actually site, not all eleven. An adopted form with no assignment behind it is vocabulary, and vocabulary is the failure mode this whole phase exists to escape.
SM-2 Maneuver Assignment — Moves sited on named elements of the overlay. An assignment written against a product rather than against ground scores nothing, and expires the day the product is replaced.
SM-3 Implementation State Tracking — Operational, not purchased. This is the single control that decides whether the coverage figure computed downstream is a measurement or a fiction.
SM-4 Main Effort Designation — One designation. Naming a main effort is a decision to under-resource everything else, and that consequence is what makes it a decision rather than an announcement.
SM-5 Branches and Sequels — Pre-planned responses to the threat courses of action. The branch nobody planned is the branch that gets improvised under contact, at the worst possible tempo.
SM-7 Deception Emplacement — Deception emplaced on the approaches to decisive points. It belongs with the other scheme controls because it is a placement decision, and it is the one detection in the framework with no false-positive budget — so the response path matters as much as the emplacement.
KT-3 Avenue of Approach Analysis — A graph problem over the connection register built in Phase A. This is the first control that pays the terrain work back, and the first place a thin Phase A shows up as an unanswerable question.
KT-4 Adversary Reachability Assessment — Recorded whichever way it comes out. Publish only the comfortable answers and the number survives while the trend behind it quietly stops meaning anything.
KT-2 Decisive Point Protection Floor — The minimum protection each decisive point carries, and the breach of that floor as a finding. Phase A named the points; this is where they acquire a defense.
KT-5 Barrier Sufficiency — For each load-bearing barrier, the question is how you would know it had changed. An unmonitored barrier fails silently and every reachability answer that depended on it moves with it.
ID-1 Identity Plane Definition — The identity plane drawn as ground rather than assumed as a service. It sits at the head of Phase B because ID-2 through ID-5, both device gates and KT-4 reachability all name its output as an input — the same position TM-1 holds in Phase A.
ID-2 Credential Strength and Binding — Credential strength matched to the access behind it. The finding that motivates it is usually the non-human secret inventory, which most adopters have never assembled and which is where the long-lived credentials turn out to be.
ID-3 Authentication Assurance — Assurance that varies with the terrain being reached. The exit test is concrete: take a captured credential to decisive-point terrain and confirm it is not enough on its own.
ID-4 Identity Assertion Protection — Assertion lifetimes and revocation. Measured, not configured — the number that matters is how long estate-wide revocation actually takes when it is tried, and it is always longer than the documentation says.
ID-5 Authorization Decision Integrity — Every access path consulting the decision point, and policy changes leaving a trace. This is the control that converts identity from a login into an enforcement plane.
DV-1 Device Terrain Identification — Devices discovered from the identity plane outward. The console can only report what it already manages, so the unmanaged population is by definition invisible to it — and that population is the finding.
DV-2 Device Posture as an Access Precondition — Posture as a precondition of access. This closes the gap M3 Envelopment leaves when identity is enforced alone: a valid credential on a compromised device still spends.
DV-3 Endpoint Sensor Coverage and Liveness — Sensor coverage reconciled to the device inventory, and silent sensors detected as events. Placed here rather than in Phase C because EN-1 and EN-2 in the next phase cannot run on telemetry that was never collected.
DV-4 Execution Control — Execution control on the ground the adversary crosses into — the cheapest point at which most engagements stop. Scoped to designated terrain first; estate-wide allow-listing is a Phase C ambition at best.
DV-5 Device Lifecycle and Sanitization — Both ends of the device lifecycle. The metric that moves is the count of devices holding estate trust with no current holder, which is never zero on first measurement.
TA-4 Pre-authorized Response — The orchestration wiring is the procurement item of this roadmap. No fire enters the pre-authorized set without a named reverse action, an owner and a time bound — because it will execute with no human present.
TA-1 Decision Loop Measurement — Three timestamps, all taken by the party they judge. Sample the raw incident records behind them, or the figure measures how the SOC reports rather than how fast it decides.
CE-4 Coverage and Residual Risk Computation — The first honest coverage figure lands here and it will be low. It is a model to argue with, and the argument — not the percentage — is the deliverable.
CE-5 Remediation Backlog Prioritization — Ranked against residual risk, not against severity labels inherited from a scanner. A backlog ordered by someone else’s CVSS is not a defensive priority.
CG-4 Findings Disposition — Three dispositions: remediated, accepted with a signature, transferred. A finding left to age has not reached a fourth outcome — it has reached none.
RC-2 Isolated Recovery Capability — A recovery path that does not share a failure domain with the thing it recovers. Most estates discover they do not have one at the moment they need it.
RC-3 Trusted Rebuild Path — Walked, not documented. The objectives declared in Phase A become testable here, and the first walk usually falsifies at least one of them.
FO-2 Controlled Unclassified Information Handling — Controlled unclassified information located on the overlay, with its handling constraint attached to the element rather than to a policy document.
FO-3 Tenancy and Inheritance Boundary — Where the agency’s responsibility begins inside a shared service. Getting this boundary wrong produces a coverage figure that quietly counts somebody else’s controls as your own.
WF-1 Workforce Terrain Identification — People as terrain, identified the same way systems were: enumerated, weighted, owned. The workforce family exists because the five zero-trust pillars do not cover it.
WF-2 Privileged Human Register — Who actually holds privilege, as opposed to who is entitled to it. The register is almost always longer than the entitlement list, and the difference is the finding.
WF-4 Insider Risk Position — A stated position, including a deliberate decision not to run a program. Silence here reads to an assessor as absence, which is a worse answer than a bounded one.
WF-5 Separation and Revocation Tempo — Measured in hours from the human-resources event. It is the one workforce number that shows up unaltered in a real incident timeline.
What Phase B inherits
Read from the entering controls’ own declared inputs, ordered by how much of the phase rests on each. The descriptions are the framework’s, not this page’s.
KT-3 Decisive points to be approached · KT-2 Designated decisive points · SM-4 Decisive points as main-effort candidates · ID-2 Decisive points, which set the strength the credential must meet · ID-3 Decisive points requiring the highest assurance · DV-2 Decisive points setting the strictest posture requirement · DV-4 Decisive points where enforcement is mandatory · SM-7 Decisive points whose approaches are seeded first · RC-3 Designated decisive points requiring a rebuild path · WF-1 Decisive points whose operators constitute high-consequence roles
ID-1 Terrain overlay the identity planes are drawn onto · DV-1 Terrain overlay the device layer is placed on · FO-2 Terrain overlay · FO-3 Hosted elements on the overlay · WF-1 Terrain overlay
SM-2 Defensive layer constraining applicable forms · ID-3 Terrain classification that sets the required level · ID-5 Terrain classification the policy is written against · SM-7 Terrain classification, so decoys are plausible for their layer · CE-4 Defensive layer assignment for aggregation
KT-3 Zone boundaries a route must cross · RC-2 Trust zone boundaries defining what production credentials can reach · FO-2 Trust zone boundaries
KT-3 Permitted connections forming candidate routes · KT-4 Permitted-path graph — denied paths are excluded by definition · FO-2 Connection register showing where information can move
SM-1 Defensive intent constraining which forms are relevant · SM-4 Defensive intent identifying what must be protected
8 further inherited controls carry a single dependant each and are omitted here; every one appears on its own control entry.
What Phase B runs without
6 declared inputs across 5 controls point at something that will not exist until a later phase. The control chain is a loop, so some forward reference is unavoidable in any ordering — but a phase that does not know which of its inputs are missing will read its own thin output as a result.
Waiting on TA-2 (Phase C), EN-3 (Phase C).
Waiting on LC-2 (Phase C).
Waiting on LC-2 (Phase C).
Waiting on SM-6 (Phase C).
Waiting on TA-3 (Phase C).
The 27 artifacts that must exist, whole, by the end of Phase B
Derived: an artifact is whole when every control that declares it as an output is in force. Nothing here is a separate list to be maintained — change a control’s outputs and this changes with it.
- Decisive point registerFrom KT-1 + KT-2
- Avenue-of-approach analysisFrom KT-3
- Adversary reachability assessmentFrom KT-4
- Barrier sufficiency registerFrom KT-5
- Threat course-of-action sketchFrom KT-3 + CE-2 + SM-5
- Adopted maneuver catalogFrom SM-1
- Scheme of maneuverFrom SM-2 + SM-3
- Main effort designationFrom SM-4
- Branch and sequel planFrom SM-5
- Pre-authorized response setFrom TA-4
- Trusted rebuild pathFrom RC-2 + RC-3
- Change recordFrom SM-3 + TM-6 + CG-3
- Implementation state recordFrom SM-3
- Defender decision loop measurementFrom TA-1
- Cyber Running EstimateFrom CE-3 + CE-4 + CE-6
- Hunt results, including negative resultsFrom CE-3 + KT-4
- Coverage and residual risk resultFrom CE-4
- Bill of DefenseFrom CE-4 + TM-3
- Remediation backlogFrom CE-5
- Findings disposition recordFrom CG-4
- Isolated recovery capability recordFrom RC-2
- Privacy and controlled-information terrain registerFrom FO-1 + FO-2
- Tenancy and inheritance boundary recordFrom FO-3
- Workforce terrain registerFrom WF-1
- Privileged human registerFrom WF-2
- Insider risk positionFrom WF-4
- Separation and revocation recordFrom WF-5
And 1 artifact exist in part — one producing control is in force and another is not. A program that reports these as delivered is reporting a fragment, so each is named with what it is waiting for.
- Temporal advantage resultWaits on TA-3 (Phase C) · TA-2 (Phase C) · TA-5 (Phase C)
Who Has to Be Staffed
The counts are derived from the accountability chart of the controls entering this phase. The commitment beside each is authored — a count of controls says a role is needed, not how much of a person it needs.
The largest single commitment in the roadmap — eighteen controls, distributed across every system owner in scope, and half again what it was before the identity and devices families entered this phase.
Segmentation lands on ground someone else holds, and the holder is the one who has to live with what it does to movement. Where that commitment is not settled at executive level before the phase opens, it arrives instead as a series of individually reasonable refusals.
Roughly 0.5 FTE sustained, rising during the orchestration work.
Three controls enter here with the SOC Responsible, and the pre-authorized response set is the one to protect time for: every fire needs a reverse action designed before it is armed, and that design work is what gets cut when the phase runs late. The count is low because Phase B is mostly emplacement, which platform owners carry; the SOC’s load arrives in Phase C with the engagement family.
Sustained at Phase A levels; the work changes shape rather than volume.
Avenue-of-approach and reachability analysis are graph problems over the register built in Phase A. Traced by someone who cannot read a network and identity architecture, they return only the direct edges — a short list, a reassuring one, and wrong.
Roughly 0.35 FTE.
Findings disposition becomes real work the moment coverage is computed, because coverage generates findings faster than any other control in the framework. This is the phase in which a findings register either starts closing or starts only growing.
Part-time, and genuinely separate from the SOC.
Hunt is consulted on avenues and reachability rather than Responsible for them, and carries no Phase B responsibility of its own. Its independence does not matter yet — effectiveness validation and the engagement family are both Phase C — but the reporting line has to be established here, because it cannot be established credibly at the moment it first produces an unwelcome answer.
Roughly one half-day per month.
Accountable for every control entering the phase. The decisions below cluster around the widening of authority and the acceptance of the first honest numbers, and both are the kind that get made badly when made quickly.
What it costs: 323 person-days, about 2.5 full-time equivalents
The densest stretch of the roadmap, and the only phase where the number is a negotiation rather than a plan: well over a third of it belongs to platform owners who do not report to the accountable authority. Treat the platform line as the one to socialise at executive level before the phase opens, not after it slips.
| Role | Person-days | On what |
|---|---|---|
| Platform and product owners | 120 | Siting obstacles, zone enforcement, implementation state, rebuild paths. Distributed across every system owner in scope. |
| SOC / Defensive Operations | 70 | Maneuver assignment, the pre-authorized set and its reverse actions, loop instrumentation. |
| Cyber Threat Intelligence cell | 60 | Avenues, reachability, threat courses of action, and the fusion cadence rising with the loop. |
| Governance / RMF / ISSO | 45 | Findings disposition, the federal-obligation controls, and the authority record behind the widening. |
| Hunt team | 20 | Co-responsible on avenues and reachability; establishing the reporting line before it is tested. |
| Authorizing Official / CISO | 8 | Six decisions, monthly review, and the first coverage figure. |
Platform and product owners
- Person-days
- 120
- On what
- Siting obstacles, zone enforcement, implementation state, rebuild paths. Distributed across every system owner in scope.
SOC / Defensive Operations
- Person-days
- 70
- On what
- Maneuver assignment, the pre-authorized set and its reverse actions, loop instrumentation.
Cyber Threat Intelligence cell
- Person-days
- 60
- On what
- Avenues, reachability, threat courses of action, and the fusion cadence rising with the loop.
Governance / RMF / ISSO
- Person-days
- 45
- On what
- Findings disposition, the federal-obligation controls, and the authority record behind the widening.
Hunt team
- Person-days
- 20
- On what
- Co-responsible on avenues and reachability; establishing the reporting line before it is tested.
Authorizing Official / CISO
- Person-days
- 8
- On what
- Six decisions, monthly review, and the first coverage figure.
What the Authorizing Official personally decides — 6 decisions
Not artifacts to approve. Decisions that cannot be made by anyone else, each landing in a specific control, and each with the reason delegating it fails.
Which containment actions execute at machine speed, bounded by the statutory availability floor and nothing else.
TA-4 Widening pre-authorization is an acceptance that an automated action will sometimes be wrong. Only the authority that owns the risk can accept it, and the width chosen here is what the program’s tempo will be measured against for the next year.
The main effort — one designation, which by construction under-resources everything else.
SM-4 A main effort designated by consensus is not a main effort. The role of command here is to be the one party willing to say what is deliberately second, and to defend that when the second thing is the one that gets hit.
Accepting the first honest coverage figure without instructing anyone to improve it.
CE-4 Coverage rises whenever the denominator shrinks. An Authorizing Official who reacts to a low first number will get a higher second number produced by scoping rather than by defending, and will never see an honest one again.
The disposition of every finding that reaches the end of its defined period: remediated, accepted with a signature, or transferred.
CG-4 Documenting an acceptance and making one are different acts belonging to different people. Blur them and the register fills with risk nobody empowered to accept it ever saw — worse than leaving the finding open.
Which mission services will knowingly be rebuilt from an untrusted baseline, because no trusted rebuild path exists for them yet.
RC-3 The first honest walk of a rebuild path usually falsifies a recovery objective declared in Phase A. Restating the objective is the tempting response; accepting the gap in writing, with a date, is the defensible one.
Who comes off the privileged human register, against the operational objection that will follow.
WF-2 The register is always longer than the entitlement list, and every name on the difference has a reason. Removing them is a decision with a named individual on the other end of it, which is why it stops at this desk.
Exit Criteria, Written as Tests
The summary criterion for this phase is: A stolen credential, on its own, no longer yields movement — and you can show the telemetry that proves it. That is the right size for a roadmap and it is not checkable. Below are 6 things you can actually do, with what a pass looks like from outside and what a failure means — which is never “the test failed”.
KT-4 Take a valid credential for a mission-staff account and, in a controlled test, use it from an unmanaged device to reach a decisive point.
It fails, and the telemetry names which maneuver stopped it and at which step.
Envelopment is a license rather than a maneuver. A stolen credential still yields movement, which is the exact claim Phase B exists to falsify.
SM-3 Ask for the implementation state of five maneuvers, then ask what evidence puts each one in that state.
Every answer is operational — a rule in effect, a policy enforcing, a log line. None is a purchase order.
Implementation state records procurement. Every number computed downstream from it, coverage first, is fiction with a decimal point.
TA-1 Reconstruct the detect-to-contain timeline for one real incident from raw records, without the SOC’s summary.
It matches the reported figure within the stated tolerance, and the “decide” timestamp corresponds to a judgment rather than a ticket update.
The decision loop measures the SOC’s reporting, not its tempo. The scoreboard is precise and false, which is the most expensive kind.
TA-4 Pick a pre-authorized fire and walk through the case where the detection was mistaken.
A named reverse action, an owner, and a time bound — all three.
An irreversible automated action is armed. The first false positive will produce an outage, and the response will be to disarm the whole set rather than to fix one entry.
CE-4 Ask for the coverage figure, then ask what left the denominator this cycle.
A specific answer, or a specific “nothing”, from someone who checked.
The number is being managed rather than measured. Coverage that rises without an implementation is a scoping change wearing a result’s clothes.
CG-4 Find a finding recorded as accepted and ask who signed the acceptance.
A named individual with the authority to accept, and a dated rationale.
Acceptance by silence. The register contains a decision with no decider, and an assessor will treat every entry beside it with the same suspicion.
The Work, as the Adoption Summary States It
Rendered from the same source the summary page uses. There is one copy of this list, so the two pages cannot come to disagree about what the phase involves.
- Envelopment on the identity plane — continuous authorization and just-in-time privilege.
- Obstacle emplacement between the public filing tier and the mission tier.
- A deception grid seeded through the data terrain.
- Wire the orchestration layer so pre-authorized fires actually execute at machine speed.
- Run the cycle monthly, then weekly.
Achieve tempo
Eighteen controls, of which nine belong to the two families adopters most often never reach. Phase C is where the loop stops being run and starts being won on.
Phase C is the shortest list and the longest calendar, and the mismatch is the point. Nine of its eighteen controls belong to the facilities and lines-of-communication families, whose pacing item is not effort but access: another organization’s disclosure, another directorate’s site schedule, a supplier’s willingness to be tested. A program that plans Phase C by person-days will finish the numbers and miss the dates.
The controls that make this phase what it is, though, are the tempo three. Adversary dwell estimation gives the campaign a budget; the temporal-advantage threshold gives it a target set before the data arrives; the tempo degradation trigger says which of cadence, scope or authority gives way when the loop stops closing. Together they convert a program that runs a loop into one that can say whether it is winning on it, and they are the only metrics in the framework capable of coming out negative.
Maneuver effectiveness validation is the other structural change, and it is a governance decision disguised as a technical one. The control asks hunt to grade work the SOC performs. Where hunt reports up the same line that is measured on it, the grade is compromised — not because anyone is dishonest, but because the question stops being asked hard. Small agencies frequently cannot separate the two. Those that cannot should record it in the assessment rather than let a reader assume an independence that does not exist.
One honest prediction about this phase. The facilities and supply-chain families are the most predictable place this roadmap is not followed, and deferring them is often a defensible call — an agency with three offices and two suppliers has a genuinely small surface there. The distinction that matters is between deferring and drifting. A deferral is a dated decision with a named owner and a review point. Drift is nine controls that quietly never appear in a cycle record, and it is indistinguishable from the first until an assessor asks.
Third-party access. Component provenance, supplier access constraint and severance demonstration all depend on somebody outside the agency agreeing to participate. Start the contracting conversations in the first month of the phase, not the sixth.
Nothing new is strictly required. Dwell estimation and effectiveness validation are usually where an adversary-emulation capability gets bought, but both can be run with existing telemetry and a person who is allowed to be adversarial.
The 24 controls that come into force in Phase C
Grouped by catalog family. Every control in the framework enters in exactly one phase, so the three lists together are the whole of it — a control missing from all three would fail the build rather than quietly never appearing.
TA-2 Adversary Dwell Estimation — An estimate with a stated basis and a confidence level. It is the budget an eviction is racing, and a program that cannot state it is measuring only half of temporal advantage.
TA-3 Temporal Advantage Threshold — A number with units, set before the data arrives. This is the one Frame exit criterion Phase A knowingly cannot meet, and back-filling it later is how a program discovers it was always meeting its target.
TA-5 Tempo Degradation Trigger — What gives way when the loop stops closing — cadence, scope, or authority. Deciding which, in advance, is the difference between a degraded program and a collapsed one.
SM-6 Maneuver Effectiveness Validation — Executed tradecraft against the maneuver that claims to stop it. Its entire value is its capacity to come back negative, which is why the reporting line matters more than the tooling.
EN-1 Event Declaration and Triage — Declaration criteria and a triage clock. Phase C because the decide segment can only be targeted once TA-1 has measured it and DV-3 has established that the telemetry exists.
EN-2 Engagement Reconstruction — Reconstruction before closure. The discipline this imposes is uncomfortable and it is the point: an incident closed without a reconstruction has taught the agency nothing and corrected no estimate.
EN-3 Evidence Preservation — Evidence preserved against the dwell estimate rather than against a retention default. Where those two disagree — and they usually do — the dwell estimate wins.
EN-4 Escalation and Engagement Authority — Named authorities, verified reachable out of hours. The cheapest control in the family and the one that most often turns out to be untrue when tested.
EN-5 Eradication and Transition to Recovery — Eradication verified before recovery begins. Recurrence through a previously used avenue is the metric, and it is the one an Authorizing Official will actually ask about.
EN-6 Engagement Communication — Communication inside the agency, to the federal community, and to those the mission serves — each against the window that binds it, which FO-7 is what determines.
RC-4 Recovery Integrity Verification — Verified against an independently held integrity record. If that record shares a failure domain with what it verifies, the verification is decorative.
RC-5 Reconstitution Exercise — Run against the objectives declared in Phase A, on the rebuild path built in Phase B, with the vendor out of the room. It is the exercise that tells you which of the three was optimistic.
WF-3 Role-Based Readiness — Readiness per role rather than training hours per person. It feeds the tempo degradation trigger, which is why it lands in the same phase as it.
FO-4 Operational Technology Terrain — Operational technology as terrain in its own right. Agencies with dispersed sites usually find this is the largest unmapped surface they own.
FO-6 Supply Chain Obligation — Supply chain as terrain, which is the entry condition for the whole lines-of-communication family beneath it.
FC-1 Facility Terrain Identification — Facilities enumerated the way systems were. The overlay has been logical up to this point; this is where it acquires a physical dimension.
FC-2 Physical Zone Boundary — Physical zone boundaries, expressed the same way trust zones were — by the control that enforces them.
FC-3 Maintenance Access Control — Maintenance access is the path most often left out of an avenue-of-approach analysis, because it belongs to somebody who does not attend security meetings.
FC-4 Environmental Continuity — Environmental endurance becomes a live constraint the first time a recovery runs long, which is exactly when nobody has time to establish it.
LC-1 Supplier Terrain Register — The supplier register, and the entry point for the four controls beneath it. Everything in this family fails if the register is a procurement extract rather than an access-truth statement.
LC-2 Component Provenance — Provenance for the components that reach production. It is slow because it depends on other people’s disclosure, not because it is technically hard.
LC-3 Supplier Access Constraint — Supplier access constrained to the terrain the supplier actually needs. The constraint is usually available and simply never applied.
LC-4 Update Integrity and Staging — Update integrity and staging — the control that stands between a trusted supplier and an untrusted change arriving under its name.
LC-5 Supplier Severance Capability — Severance demonstrated rather than contracted. The demonstration has a commercial consequence, which is why it needs the Authorizing Official rather than the ISSO.
What Phase C inherits
Read from the entering controls’ own declared inputs, ordered by how much of the phase rests on each. The descriptions are the framework’s, not this page’s.
EN-2 Terrain overlay the movement is traced across · FO-4 Terrain overlay · FO-6 Terrain overlay · FC-1 Terrain overlay elements requiring a physical location
EN-5 Recovery objectives constraining how long eradication may take · RC-5 Objectives to be demonstrated · FC-4 Recovery objectives of the services housed
TA-3 Measured defender decision loop · TA-5 Baseline loop measurement to detect degradation against · EN-1 Decide-segment target the triage period is set against
FC-2 Decisive points requiring physical location · LC-3 Decisive points to which standing access is prohibited
RC-4 Rebuilt systems awaiting verification · RC-5 Rebuild paths to be walked
WF-3 Identified roles requiring preparation · FC-1 Personnel populations requiring facility association
19 further inherited controls carry a single dependant each and are omitted here; every one appears on its own control entry.
What Phase C runs without
Nothing. Every input declared by a control entering this phase is already in force, which is what it means for the roadmap to close: the framework is running whole for the first time.
The 19 artifacts that must exist, whole, by the end of Phase C
Derived: an artifact is whole when every control that declares it as an output is in force. Nothing here is a separate list to be maintained — change a control’s outputs and this changes with it.
- Temporal advantage thresholdFrom TA-3
- Adversary dwell estimateFrom TA-2
- Maneuver effectiveness validation recordFrom SM-6
- Temporal advantage resultFrom TA-3 + TA-1 + TA-2 + TA-5
- Engagement recordFrom EN-1 + EN-2 + EN-3 + EN-4 + EN-5
- Engagement communication recordFrom EN-6
- Recovery integrity verification recordFrom RC-4
- Reconstitution exercise reportFrom RC-5
- Operational technology terrain registerFrom FO-4
- Role-based readiness recordFrom WF-3
- Facility terrain registerFrom FC-1
- Physical zone boundary recordFrom FC-2
- Maintenance access recordFrom FC-3
- Environmental continuity recordFrom FC-4
- Supplier terrain registerFrom FO-6 + LC-1
- Component provenance recordFrom LC-2
- Supplier access constraint recordFrom LC-3
- Update integrity and staging recordFrom LC-4
- Supplier severance demonstrationFrom LC-5
Who Has to Be Staffed
The counts are derived from the accountability chart of the controls entering this phase. The commitment beside each is authored — a count of controls says a role is needed, not how much of a person it needs.
Sustained, and broadened to owners who were out of scope in Phases A and B.
The facilities and supplier controls reach people who have never attended a security meeting — site managers, contracting officers, maintenance leads. Their time is cheap and their calendars are not, which is why this phase is long.
Roughly 0.4 FTE, and the largest governance load of the three phases.
Supply-chain and facilities controls are overwhelmingly co-responsible with platform owners, and the ISSO is the half that knows the obligation. This is also the phase in which the cycle record has to become readable as continuous-monitoring evidence without a translation layer.
Operational for the first time, and reporting outside the chain it validates.
Hunt in this phase works hypotheses raised in fusion rather than a calendar of techniques. If the team is functioning as a third triage tier, effectiveness validation will produce only favorable findings and the phase’s central control is inert.
Roughly 0.4 FTE, shifting from building to measuring.
The tempo controls are instrumented and operated by the SOC, and the tempo degradation trigger is the one control the SOC is expected to fire against itself.
Reduced, and more analytic.
Dwell estimation is judgment with a stated basis rather than production. The cell’s volume of work falls in Phase C; the difficulty of it rises.
Roughly one half-day per month, plus the scoreboard.
The decisions here are the ones with external consequences — an independence line, a demonstrated severance, and whether a losing number reaches an oversight body unaltered.
What it costs: 340 person-days, about 1.7 full-time equivalents
The largest phase in total person-days and the lightest in intensity, because the pacing item here is access rather than effort — nine months of other people’s calendars. Do not read the lower intensity as an easier phase; read it as one where sequencing matters more than staffing.
| Role | Person-days | On what |
|---|---|---|
| Platform and product owners | 130 | Facilities, operational technology and supplier terrain, across owners new to the program. |
| Governance / RMF / ISSO | 60 | The supply-chain and facilities obligations, and making the cycle record read as continuous monitoring. |
| SOC / Defensive Operations | 55 | Tempo instrumentation, the degradation trigger, and recovery verification. |
| Hunt team | 45 | Effectiveness validation and hypothesis-driven hunts. The first phase in which hunt is a load rather than a consultation. |
| Cyber Threat Intelligence cell | 40 | Dwell estimation and the analytic half of the tempo scoreboard. |
| Authorizing Official / CISO | 10 | Five decisions and a monthly scoreboard that is allowed to be bad. |
Platform and product owners
- Person-days
- 130
- On what
- Facilities, operational technology and supplier terrain, across owners new to the program.
Governance / RMF / ISSO
- Person-days
- 60
- On what
- The supply-chain and facilities obligations, and making the cycle record read as continuous monitoring.
SOC / Defensive Operations
- Person-days
- 55
- On what
- Tempo instrumentation, the degradation trigger, and recovery verification.
Hunt team
- Person-days
- 45
- On what
- Effectiveness validation and hypothesis-driven hunts. The first phase in which hunt is a load rather than a consultation.
Cyber Threat Intelligence cell
- Person-days
- 40
- On what
- Dwell estimation and the analytic half of the tempo scoreboard.
Authorizing Official / CISO
- Person-days
- 10
- On what
- Five decisions and a monthly scoreboard that is allowed to be bad.
What the Authorizing Official personally decides — 5 decisions
Not artifacts to approve. Decisions that cannot be made by anyone else, each landing in a specific control, and each with the reason delegating it fails.
Whether the hunt function reports outside the chain of command it is validating — and if it cannot, recording that plainly.
SM-6 This is the only control in the framework whose value depends entirely on a reporting line. It cannot be fixed by tooling, it cannot be delegated to the parties concerned, and an undeclared dependency here silently invalidates every effectiveness claim the program makes.
The temporal-advantage threshold: a number, with units, set before the cycle’s data arrives.
TA-3 A threshold set afterwards is how a program discovers it was always meeting its target. Setting it in advance is a commitment to being able to miss it, and only the accountable authority can make that commitment credibly.
What gives way when the tempo degradation trigger fires — cadence, scope, or authority.
TA-5 All three are risk positions. Deciding under pressure means deciding by whoever is loudest in the room; deciding in advance means the trigger produces a controlled degradation rather than an argument.
Whether supplier severance is demonstrated against a real supplier, accepting the commercial consequence.
LC-5 A severance capability that has never been exercised is contractual language. Exercising it has a relationship cost with a vendor, which puts the decision above the ISSO and above the contracting officer.
Whether a losing scoreboard goes to the oversight body unaltered.
CE-7 Temporal advantage can come out negative. Soften it once and it stops being reported honestly — a quarter of comfort bought with the only measure in the framework that can tell you that you are losing.
Exit Criteria, Written as Tests
The summary criterion for this phase is: Measurable positive temporal advantage on the main effort, demonstrable to the agency OIG as continuous monitoring. That is the right size for a roadmap and it is not checkable. Below are 6 things you can actually do, with what a pass looks like from outside and what a failure means — which is never “the test failed”.
SM-6 Ask for a maneuver-effectiveness validation that came out negative.
At least one in the last two cycles, with a cost attached to fixing it.
The validation is validating its own chain of command. Every finding is favorable, and the control is producing reassurance rather than evidence.
TA-3 Compute temporal advantage for the last three cycles and put the trend in front of the Authorizing Official.
The number exists per cycle, is capable of being negative, and has been negative at least once.
Either the threshold was set after the data, or the measurement is not real. A metric that has never reported badly is either perfect or unmeasured, and the second is far more common.
RC-5 Run the reconstitution exercise against the recovery objective declared in Phase A, on the rebuild path built in Phase B, with the vendor out of the room.
The objective is met or missed, and either result is recorded with the elapsed time.
The exercise is a tabletop. A recovery objective that has never been tested against a real rebuild is a number chosen because it sounded achievable.
RC-4 Restore one system from backup and verify it against the independently held integrity record.
The verification succeeds, and the record it verified against does not share a failure domain with the backup system.
The integrity check is inside the blast radius of the thing it checks. In a real recovery it will confirm whatever the adversary left behind.
LC-5 Ask a supplier with standing access to demonstrate severance, and time it.
Access is gone inside the declared window, and the mission service is still running afterwards.
Severance is contractual language. The capability exists on paper and its first real use will be during an incident, untested.
CE-6 Put four consecutive cycle records in front of the agency’s oversight body and ask whether it reads as continuous monitoring.
Yes, without a translation layer, and the four entries differ materially from one another.
The record was written for the audit. There is no trend in it, and the trend is the one thing the control exists to produce.
The Work, as the Adoption Summary States It
Rendered from the same source the summary page uses. There is one copy of this list, so the two pages cannot come to disagree about what the phase involves.
- Hunt team operational against hypotheses raised in Fuse, not against a calendar.
- Containment pre-authorized and measured.
- Spoiling-attack integration with CISA, JCDC and the sector ISAC.
- The temporal-advantage scoreboard live in front of leadership.
- Zero-trust pillars advancing to Advanced and Optimal on the main effort.
The First Ninety Days, Week by Week.
Thirteen weeks, because ninety days is thirteen weeks and not twelve. The extra week goes at the end, where the first cycle actually closes — a plan that finishes on week twelve finishes before the brief is written.
Six gates, at the end of each fortnight. A gate states what exists — nouns, not activities — and the single question that decides whether to carry on. Every artifact Phase A completes is built in exactly one of these weeks, and the week loads sum to the phase’s effort figure rather than being estimated twice.
Scope and clock
Name six people and one service
Not a kickoff. Two artifacts: the six roles with a named individual against each — including “vacant”, written honestly — and a one-line statement of which mission service the first cycle covers and what is therefore knowingly unmapped.
- AODecides the scope sentence. One hour, and it is the most consequential hour of the quarter.
- ISSORecords the role assignments, including the vacancies, and books the platform-owner sessions for weeks 5 to 7 now rather than later.
Leaves behind no finished artifact — this week is input to one that lands later.
Declare the phase and fix the calendar
The campaign phase is declared against the scope — for almost every adopter, Phase 0, Shape. The cycle cadence and close date go on a calendar that people outside the security function can see. Monthly, unless there is a reason.
- AODeclares the phase and picks the cadence, accepting that a slower honest cadence beats a faster aspirational one.
- ISSOPublishes the calendar and the declaration where a platform owner will encounter them.
- CTIDrafts the declaration rationale — what would have to change to declare something else.
Leaves behind: Phase declaration, Cycle cadence and calendar.
- Six roles with a named individual against each, and the vacancies written down as vacancies.
- A one-line scope: which mission service, and what is knowingly unmapped this quarter.
- A declared campaign phase, with the rationale for it.
- A cycle calendar visible to people outside the security function.
Can somebody outside the program say what is being defended and when the next cycle closes?
Floor and intent
Find the floor
For each mission service in scope, trace the availability obligation to the instrument that creates it — statute, regulation, or a published commitment — rather than to a service-level target in a contract. Slow, unglamorous, and it bounds everything the intent is allowed to offer up.
- ISSOLeads the trace. This is the control where the ISSO’s statutory literacy is irreplaceable.
- PLATSupplies what the service actually promises today, which is frequently stricter than what the law requires.
Leaves behind: Statutory availability floor.
Write the intent and sign it
One paragraph. What must be protected, what may be degraded to protect it, and what must never happen. The intelligence cell drafts; the Authorizing Official argues with it and signs. A paragraph signed without argument has no author.
- CTIDrafts, and refuses to submit a version that names nothing degradable.
- AOArgues, amends, signs. Half a day, and the acceptable-risk sentence is the part that needs the argument.
- PLATReads it before it is signed and says whether it changes anything they would do.
Leaves behind: Defensive intent paragraph.
- An availability floor per mission service, each traced to the instrument that creates the obligation.
- A signed defensive intent paragraph naming something that may be degraded.
- At least one platform owner who has read it and said whether it changes what they would do.
Does the intent name a degradation the Authorizing Official is willing to defend in public?
The ground
Inventory the ground
The heaviest week of the quarter. Every element in the scoped service is enumerated and given a defensive layer and a named individual owner. Existing configuration-management data is a starting point and never the answer — it is reconciled against what the owners say is actually running.
- PLATThe ground truth. Six to ten owners, booked in week 1, each giving half a day.
- CTIBuilds the overlay as the sessions run, rather than collecting first and assembling later.
Leaves behind no finished artifact — this week is input to one that lands later.
Weight it, and mark what is sensitive
Criticality and exposure per element, set by the mission owner rather than by the security function. In the same pass, mark which elements hold personally identifiable information — asset weighting without that is dishonest. Then set the refresh interval and attach it to a person.
- PLATSets criticality against mission consequence, not against system tier.
- CTISets exposure, records the privacy terrain, and takes the currency owner’s name.
- ISSOChecks the privacy marking against what the agency has already declared elsewhere.
Leaves behind: Cyber Terrain Overlay, Privacy and controlled-information terrain register.
- Every element in scope carrying a defensive layer, a criticality and exposure weight, and a named individual.
- Privacy terrain marked on the same overlay rather than in a separate register.
- A refresh interval with the currency owner’s name attached to it.
Pick three elements at random — does each have a human owner who agrees they own it?
Boundaries and decisive points
Zones, connections, denied paths
Trust zones defined by the control that enforces them — anything enforced only by a diagram is written down as a finding, not as a zone. Then the connection register, including the paths deliberately blocked, each naming what blocks it. This is the graph Phase B runs over.
- PLATConfirms which boundaries are technically enforced and which are conventions.
- CTIBuilds the register and records every paper zone as a finding rather than smoothing it.
- HUNTPicks two denied paths and tries them, which is faster than arguing about them.
Leaves behind: Trust zones and the connection register.
Name what must not fall
The decisive points: the elements whose loss unhinges the defense of this service. Short enough to argue about — five is a list, thirty is an inventory. Phase A names them; the protection floor that goes with them is Phase B work.
- CTIProposes the list from the weighted overlay and defends each entry.
- AOConfirms it, because a decisive-point list is an implicit statement about what else is expendable.
- HUNTChallenges the list — the useful question is which point is reachable most cheaply, not which is most important.
Leaves behind: Decisive point register.
- Trust zones, each named against the control that enforces it, and every paper zone recorded as a finding.
- A connection register including denied paths, each naming what denies it.
- A decisive-point list short enough that the argument about it is worth having.
Take one denied path and try it. Is it denied, by the control the register names?
Authority and questions
Settle the engagement authority
The rules of engagement, drafted by the people who will operate under them and made defensible by the people who own the record. The pre-authorized list is split by reversibility, never by severity, and the exception log opens the day the rules are approved.
- SOCDrafts what it needs in order to act, and inventories what already executes without approval today.
- ISSOMakes it defensible and opens the exception log.
- AOApproves, and accepts that a narrow first list is a stated tempo ceiling rather than a gap.
Leaves behind: Rules of engagement, Authority exception log.
Ask three to seven questions
The Priority Cyber Intelligence Requirements. Each names the decision it informs, the collection source expected to answer it, and a named owner inside the cell. A requirement that informs no decision is a research topic and gets struck now rather than surviving to Assess as an open item.
- CTIWrites them, decomposes each into an observable indicator, and strikes the ones that decompose into nothing.
- HUNTTakes ownership of at least one, because a requirement nobody will go and test is a hope.
- AOConfirms each requirement maps to a decision they would actually make differently.
Leaves behind: Priority Cyber Intelligence Requirements.
- Approved rules of engagement with a non-empty pre-authorized list, split by reversibility.
- An open authority exception log, with nothing in it yet.
- Three to seven intelligence requirements, each with a decision, a source and a named owner.
How many actions may the SOC take at 2am on a Sunday without a phone call, and does each have a reverse?
Turn the loop once
Recovery objectives, and what you already assessed
Two independent strands. Service owners declare recovery time and recovery point objectives as mission judgments. In parallel, the ISSO maps which existing control assessments already satisfy an ASOM-Fed requirement — the largest single cost saving in the roadmap, available in the first quarter.
- PLATDeclares the objectives. Security can say what is achievable; only the service owner can say what is acceptable.
- ISSOBuilds the inheritance mapping and drafts the citations an assessor will test.
Leaves behind: Recovery objectives register, Control inheritance mapping.
Fuse
The first fusion. What does the program now believe about this service, with what confidence, and which requirements are unanswered. It will be thin — that is expected. Publishing a moderate or low confidence here is what makes the confidence field mean something in cycle twelve.
- CTIRuns the fusion, states a confidence per judgment, and lists the requirements that stayed open.
- HUNTReports the result of whatever was tested, including the null result and the coverage of it.
Leaves behind: Fused assessment, Indicators and signposts, Hunt results, including negative results, Cyber Running Estimate.
Close cycle one
The cycle record is opened with its first row, and the brief is written and delivered. The brief names what could not be answered, and records the artifacts that Phase A knowingly left partial — including the temporal-advantage threshold, which Phase A cannot set because there is nothing yet to measure.
- ISSOOpens the cycle record and the change record. Accountable for the trend from this row forward.
- CTIWrites the brief, including the unanswered requirements.
- AOUses the brief rather than receives it, and decides the scope of cycle two.
Leaves behind: Cycle record and trend, Cycle brief, Change record.
- Recovery objectives per mission service, declared by the service owner.
- An inheritance mapping citing the assessments that already satisfy a requirement.
- A fused assessment carrying a confidence level that is not “high”.
- A cycle record with one row, and a brief that names at least one unanswered requirement.
Did the loop close — and does the brief say what Phase A could not do, rather than reading as though it did everything?
What the Plan Deliberately Does Not Schedule
2 artifacts count as “started” in Phase A only because one of their producing controls comes into force here. Neither can genuinely begin until Phase B supplies the rest. Naming them is more useful than smoothing them into a plan that quietly cannot deliver them.
- Threat course-of-action sketchWaits on KT-3 (Phase B) · SM-5 (Phase B)
- Bill of DefenseWaits on CE-4 (Phase B)
The Five Ways Adoption Fails.
None of these is a tooling problem, which is why none can be bought around. Each is given the observable that distinguishes it from a program that is working — a failure mode with no tell is an anxiety.
The forms of maneuver are the interesting part and the terrain work is not, so the program adopts a catalog of moves and starts siting them against an estate nobody has mapped. It feels like progress because things are being deployed.
- The tell
- Maneuver assignments name products rather than elements. Ask for the element on the overlay that a given maneuver is sited on; if the answer is a vendor name, the assignment is unanchored.
- What it costs
- Every number the framework produces downstream is computed over ground that was never established. Coverage has a denominator nobody can inspect, reachability is traced through a graph that omits half the estate, and the residual-risk figure is arithmetic over guesses.
- The correction
- Refuse to run Array until every element in scope carries a layer, a weight and a named individual. The framework’s own chain agrees: eighteen of the seventy-eight controls declare the terrain overlay’s output as an input, half again any other control in the catalog.
Terrain, decisive point, main effort, temporal advantage — the words are excellent and they present well. A program can acquire all of them, put them in a strategy document, and never once run a cycle that changes a decision.
- The tell
- The cycle record has one entry, or several entries that do not materially differ. Two consecutive cycles that produced the same intent, the same requirements and the same findings mean the loop did not turn; it was described.
- What it costs
- The framework becomes a document set with a military accent. It survives an audit and produces no defensive change, and the second year is harder than the first because everyone now believes it has been tried.
- The correction
- Hold the program to the record rather than to the vocabulary. The cycle record exists precisely so that a series can be inspected, and the test is whether entry three says something entry two did not.
Weekly is declared in month one because it demonstrates seriousness. By month four the calendar carries three canceled framings, the last brief is six weeks old, and nobody has decided to slow down — it simply happened.
- The tell
- Compare the declared cadence to the dates on the last four briefs. A gap is not a scheduling problem; it is the cadence control failing silently, and it takes the trend down with it.
- What it costs
- A missed cadence and a lowered cadence are indistinguishable in the record six months later, and only one of them was a decision. The program loses the ability to say whether anything changed between cycles, which is the entire value of running cycles.
- The correction
- Start at the slowest defensible cadence — monthly for most adopters — and let the phase declaration compress it when a declaration justifies compression. Lowering a cadence deliberately, with a reason in the record, costs nothing. Missing one costs the trend.
The rules of engagement are written and approved, and the pre-authorized list is empty — or every entry ends with the words “with Authorizing Official approval”. The authority question was deferred because it was uncomfortable, and deferring it looked free.
- The tell
- The median decision segment of the defender loop is longer than the median execution segment. The delay is in approval, not in capability, and the measurement says so unambiguously.
- What it costs
- The loop cannot close faster than the adversary adapts, so everything built on top of it is decoration. Worse, the constraint is invisible in every report: the program looks well-tooled and loses on timing.
- The correction
- Pre-authorize by reversibility rather than by severity, and write the count down. If the count is genuinely zero, that is a legitimate risk position — but it has to be stated as one, because a tempo ceiling nobody has declared is a tempo ceiling nobody will fix.
Coverage is a percentage, percentages go up, and someone is asked to make it go up. The fastest way to raise coverage is to shrink the denominator, and nothing in the arithmetic distinguishes that from defending more ground.
- The tell
- Coverage rises in a cycle in which no maneuver moved to implemented. Ask what left the denominator; if nobody can answer, the number is being managed.
- What it costs
- The program loses its only model of its own posture, and replaces it with a number that goes up. By the time an incident falsifies it, two years of trend data are worthless because the denominator moved underneath them.
- The correction
- Report coverage next to what is in the denominator and what moved in or out this cycle, and pair it with a measure that can come out negative. A metric that has never once reported badly is either perfect or unmeasured, and the second is far more common.
A Roadmap Is Only as Good as the Things It Sequences.
One caution worth repeating, because the two are constantly confused. The A / B / C phases on this page are an adoption sequence: they run once, in order, and they end. The campaign phases — Shape, Deter, Seize Initiative, Dominate, Stabilize, Restore — are declared against a scope, repeat, and can go backwards. A program in adoption Phase B is usually in campaign Phase 0, and neither number tells you anything about the other.