ASOM-Fedv6.1Open the explorer
Reference manual · rules of engagement

Somebody Has to Have Already Decided.

The framework says, in three separate places, that engagement authority is the highest-leverage governance decision a defensive program makes — and then never shows one. This is the schedule it keeps referring to: 29 defensive actions for the Federal Reference Agency, each with the authority it requires, the scope and duration bounding it, the conditions under which the pre-authorization lapses, the record it owes afterwards, and what it costs in minutes. It is meant to be argued with. A schedule adopted without argument is a schedule nobody will follow at 03:00.

29Defensive actions scheduledAcross 8 of 10 terrain layers and 10 of 11 forms of maneuver
34% → 72%Pre-authorized, garrison to Phase IIIThe framework’s own measure of performance, counted from the schedule rather than asserted
2 h 46 minMean latency the phasing removesDecision plus execution, averaged across all 29 lines: 4 h 23 min in garrison, 1 h 37 min in Phase III
3Lines the statutory floor holdsAt the Authorizing Official in every phase. No tempo argument moves a deadline a statute fixed.
Definition

What the Framework Means by a Fire.

The word is borrowed on purpose. It brings engagement authority with it, and engagement authority is the thing federal defensive programs are usually missing.

A fire is an action, not a capability

Revoke a session. Quarantine a host. Block infrastructure. Sever a segment. Emplace a decoy. Each is a discrete thing done to a named piece of terrain at a moment in time — which is what makes it schedulable. A security product is not a fire; the actions it can take are.

Every fire has an authority

There is no such thing as an unauthorized fire that is merely fast. Either the action sits inside a standing authority somebody approved in advance, or it needs a decision now. Naming which is the entire content of a rules-of-engagement schedule.

Automation is not authorization

Automation is how a fire is delivered; authority is whether it may be. A fully automated response outside the schedule is faster and worse — it is the same unapproved decision, taken more often, by something that cannot be asked why.

A fire that needs a phone call is a fire you do not have

This is the test the schedule is built around. If the window in which an action matters is shorter than the time it takes to reach the person who may approve it, then the action is not in the program’s inventory, whatever the playbook says. Every line below states both numbers so the comparison is available rather than assumed.

The Bargain

Speed Is Bought with Accountability, Not Instead of It.

The objection to pre-authorization is always the same and it is always right: somebody is being allowed to act without asking. The answer is not to deny it. It is to price it.

A pre-authorized fire moves a decision from the moment of contact to a moment months earlier, when nobody was under pressure and everybody who should have been in the room was. That is a better moment to decide in. What it is not is a decision that stopped being made — the Authorizing Official still owns every execution, and the schedule is the instrument through which they own it.

Four things are what the agency gets in exchange for the standing authority, and all four are conditions on it rather than aspirations about it. A line missing any of them is not pre-authorized; it is unsupervised.

  1. A bound on scope

    How much may be touched under this authority — one account, ten endpoints, a /24, one declared trust zone. Fires rarely fail by firing on the wrong thing. They fail by reaching further than the finding justified.

  2. A bound on time

    How long the effect may stand before somebody re-decides, and what happens when nobody does. Defaults restore. An action with no expiry is an undocumented configuration change with a good reason attached.

  3. Conditions that void it

    The circumstances in which the standing authority does not apply and the fire escalates instead. There are 8 that bind every line and more on each one — stated below, once, rather than repeated 29 times where one of them would eventually go missing.

  4. A record that is not optional

    6 fields, completable in minutes, filed within a stated period. The record is what makes the assessment procedure in TA-4 possible at all: an assessor tests that operators executed within authority, and without a record there is nothing to test against.

21 of the 29 lines carry standing authority in at least one phase, and every one of them satisfies all four conditions — the schedule refuses to build otherwise. The corollary matters as much. A fire executed outside the schedule is an entry in the authority exception log — not a violation to be managed quietly. Exceptions are the evidence about whether the schedule was the right width, and Phase V is where that evidence gets used. A program with no exceptions logged has either a perfect schedule or an underreporting problem, and the second is far more common.

Authority

Four Levels, and What Each One Costs in Minutes.

Latency is the whole argument. A level is not “more careful” — it is slower by a stated number, and the schedule is the decision about which actions are worth that number.

Exhibit 1

The Four Authority Levels, Their Holders, and Their Expected Decision Latency

LevelWho holds itDecision latencyLines here
Pre-authorizedAny qualified SOC operator on shift, under standing authoritySOC / Defensive Operationsimmediateimmediate on the standing bridge1021 in Phase III
SOC leadThe duty SOC lead — one named person per shift, not a queueSOC / Defensive Operations20 min5 min on the standing bridge104 in Phase III
CISOThe CISO or the delegated deputy named in the scheduleAuthorizing Official / CISO4 h45 min on the standing bridge51 in Phase III
Authorizing OfficialThe Authorizing Official, or the agency head where the instrument requires itAuthorizing Official / CISO16 h2 h on the standing bridge43 in Phase III

Pre-authorized

Who holds it
Any qualified SOC operator on shift, under standing authoritySOC / Defensive Operations
Decision latency
immediateimmediate on the standing bridge
Lines here
1021 in Phase III

SOC lead

Who holds it
The duty SOC lead — one named person per shift, not a queueSOC / Defensive Operations
Decision latency
20 min5 min on the standing bridge
Lines here
104 in Phase III

CISO

Who holds it
The CISO or the delegated deputy named in the scheduleAuthorizing Official / CISO
Decision latency
4 h45 min on the standing bridge
Lines here
51 in Phase III

Authorizing Official

Who holds it
The Authorizing Official, or the agency head where the instrument requires itAuthorizing Official / CISO
Decision latency
16 h2 h on the standing bridge
Lines here
43 in Phase III
Latencies are authored estimates for the Federal Reference Agency, not measurements. An adopter replaces every number here with its own, taken from the decision-loop measurement TA-1 already requires — at which point the schedule stops being a proposal and becomes a statement about the agency. The standing bridge is what a declared contact phase buys: a duty officer with the CISO reachable and the Authorizing Official on a stated interval.
Pre-authorized

Buys The decision segment of the loop disappears. Detection to containment becomes detection plus execution, which is the only shape in which a defender loop can be shorter than an adversary one.

Costs Every execution is a decision the accountable authority did not make and still owns. The schedule pays for that with bounded scope, a duration that expires by default, and a record that is not optional.

SOC lead

Buys A second pair of eyes on scope. Most of what goes wrong with a fire is not the fire; it is that the operator hit a wider population than the signal justified.

Costs Twenty minutes in garrison, and a dependency on one person being awake and reachable. A SOC lead level that is really "whoever answers" is a pre-authorized level with worse records.

CISO

Buys A decision that can weigh mission impact against defensive benefit, and a person who can telephone a mission owner and be answered.

Costs Four hours in garrison. Any fire that has to be effective inside four hours and sits here is a fire the program does not actually have.

Authorizing Official

Buys Formal risk acceptance on behalf of the agency, which is the only thing that makes a deliberate degradation of public service defensible afterwards.

Costs Sixteen hours in garrison — realistically, the next business morning. This level is correct precisely for the decisions that should not be made at 03:00 by someone who cannot accept the risk.

What Binds Every Line

The Conditions Under Which a Pre-Authorization Is Not One.

These apply to all 29 lines. They are not caveats — each is a specific failure the schedule exists to prevent, and each is testable after the fact from the record the fire already owes.

  1. The target element is on the statutory availability register and sits inside its deadline window.

    FO-5 makes the deadline an external fact. An operator at 02:00 cannot weigh a filing window against a containment benefit, and should not be asked to: the register is consulted, and if the element is inside its window the fire escalates regardless of how obviously correct it looks.

  2. The action would take the last surviving instance of a mission service out of production.

    Isolating one of four application servers is a containment action. Isolating the fourth is an outage, and the operator is frequently the last person in the chain who knows which one it is. The rule is enforced against the terrain overlay, not against the operator’s memory.

  3. The signal sits below the confidence floor stated on the schedule line.

    The same action against the same element on a weaker signal is a different decision. Without this rule, a pre-authorization quietly becomes authority to act on anything that produced an alert, which is how a schedule loses the confidence of the mission side in a single incident.

  4. The target is the isolated recovery capability or any element of the trusted rebuild path.

    The recovery path is the defender’s alternative to negotiating. Nothing fires on it under standing authority, including — especially — a containment action that looks routine, because an operator who quarantines the recovery orchestrator during an intrusion has removed the one thing the agency was holding in reserve.

  5. The element is not terrain the agency owns: another tenancy, a shared service, a partner estate, a supplier’s own infrastructure.

    TM-7 exists because a federal CISO commands the scheme and only coordinates much of the terrain. A fire delivered onto ground the agency does not own is not a fast decision, it is an incident with a second agency in it.

  6. The action is being taken to preserve or capture evidence rather than to defend.

    Evidence handling has its own authority chain and its own counsel, and borrowing a defensive pre-authorization to do it is the fastest way to make the resulting evidence unusable. Preservation is a legitimate reason to act; it is not a fire.

  7. A recovery is open and the action would take a restored service back down.

    Phase IV narrows deliberately. A service that has just been restored is carrying the agency’s credibility as well as its traffic, and taking it down again is a decision the Authorizing Official re-enters the path for.

  8. It would be the second fire of the same class against the same element inside the duration window, without a renewal decision.

    A fire that has to be repeated is telling you the first one did not work, and repetition under standing authority is how a containment action becomes an unplanned outage by accumulation. The second one is a decision, and it is taken one level up.

The Record Every Fire Owes

Deliberately short. A record obligation an operator cannot complete in five minutes at 03:00 is one that gets completed badly the following week, from memory — which is worse than no obligation, because it produces evidence that looks like evidence.

  1. Who fired, under which schedule line, at what time

    The schedule line id is what makes the rest of the record checkable. "Contained the host" is not a record; "line 11, quarantine workstation" is.

  2. The element, by its identifier on the terrain overlay

    A hostname in a chat channel does not resolve to a piece of terrain six weeks later. The overlay identifier does, which is what lets the assessment procedure in TA-4 actually run.

  3. The signal and its confidence level

    CE-3 requires confidence on the assessment; this carries it onto the action taken because of it. It is also the field that makes the confidence-floor exclusion auditable.

  4. Scope authorized against scope actually touched

    The most common failure of a pre-authorized fire is not that it was wrong but that it was wide. Recording both numbers is how the schedule finds that out before an assessor does.

  5. Restoration time, or the renewal decision and who made it

    A fire with no recorded end is an undocumented configuration change. This is the field that turns the duration bound from an intention into a fact.

  6. Carried into the cycle record and the next brief

    CE-6 and CE-7. Fires that never reach the brief cannot inform the next argument about the width of the schedule, which is the only mechanism by which the schedule improves.

Exhibit

The Schedule, at Garrison Authority.

Phase 0 widths: 10 lines standing, 10 at the SOC lead, 5 at the CISO, 4 at the Authorizing Official. Every row links to its full entry below.

Exhibit 2

All 29 lines with their garrison authority, bounds and expected latency

LineAuthority in garrisonScope boundDuration boundExpected latency
01 Revoke an authenticated sessionT1 Identity · reversible · no service effectPre-authorizedA single named account. Never a group, an application registration, or a tenant-wide session policy.Instantaneous — the session ends; the account is not disabled.1 minimmediate to decide + 1 min to land
02 Force step-up authenticationT1 Identity · reversible · internal users feel itPre-authorizedUp to 250 internal accounts, or one application. Beyond that it is a change to the identity posture rather than a response, and it goes to the SOC lead.24 hours.5 minimmediate to decide + 5 min to land
03 Disable a standard internal accountT1 Identity · reversible · internal users feel itPre-authorizedOne account at a time, up to five in an hour. The sixth is a pattern rather than an incident and goes to the SOC lead.8 hours.2 minimmediate to decide + 2 min to land
04 Disable a privileged accountT1 Identity · costly to reverse · internal users feel itSOC leadOne named privileged account, bound to a named holder in the privileged human register. Never a service principal, and never a break-glass credential.4 hours.22 min20 min to decide + 2 min to land
05 Disable an executive or appointee accountT1 Identity · costly to reverse · internal users feel itCISOOne named account on the executive list, which is maintained in the privileged human register alongside the technical accounts.4 hours.4 h 2 min4 h to decide + 2 min to land
06 Force credential reset for external portal usersT1 Identity · costly to reverse · public service degradedPre-authorizedUp to 500 external accounts identified by a specific compromise indicator. A population defined by anything broader than an indicator — a whole state, a whole filing type — is not this line.Until reset. The account is not disabled and the service is not degraded.10 minimmediate to decide + 10 min to land
07 Suspend a federated trustT1 Identity · costly to reverse · internal users feel itCISOOne federation. Never the whole federation set, which is an identity-plane outage wearing a containment label.12 hours.4 h 15 min4 h to decide + 15 min to land
08 Disable a legacy authentication pathT1 Identity · reversible · internal users feel itSOC leadOne protocol path, agency-wide, or one application’s legacy endpoint.Standing until reversed — this one is intended to become permanent.50 min20 min to decide + 30 min to land
09 Rotate a service credentialT1 Identity · reversible · no service effectPre-authorizedCredentials with an automated rotation path registered in the secret store. A credential with no registered rotation path is a manual change and is not this line.Permanent — the new value stands.20 minimmediate to decide + 20 min to land
10 Activate the break-glass credentialT1 Identity · costly to reverse · no service effectCISOOne credential, for one stated purpose, for the duration of one action.2 hours, after which the credential is rotated and re-sealed whether or not it was used.4 h 10 min4 h to decide + 10 min to land
11 Quarantine a mission-staff workstationT2 Devices · reversible · internal users feel itPre-authorizedUp to ten endpoints per incident. The eleventh indicates a campaign rather than a compromise and goes to the SOC lead.12 hours.3 minimmediate to decide + 3 min to land
12 Isolate a production workloadT4 Applications and Workloads · costly to reverse · internal users feel itSOC leadOne workload, where the terrain overlay shows at least one healthy peer carrying the same service.6 hours.30 min20 min to decide + 10 min to land
13 Terminate a process and quarantine its artifactT2 Devices · reversible · no service effectPre-authorizedAny endpoint or server, excluding operational technology and anything on the recovery path.Instantaneous.2 minimmediate to decide + 2 min to land
14 Block named external infrastructureT3 Networks · reversible · no service effectPre-authorizedIndividual addresses, fully-qualified domains, and prefixes no larger than a /24. Autonomous-system-wide or provider-wide blocks are a different line.30 days, then reviewed.5 minimmediate to decide + 5 min to land
15 Block a source range carrying public trafficT3 Networks · reversible · public service degradedCISOOne service, one range, with the legitimate population inside the range estimated before firing rather than after.4 hours.4 h 10 min4 h to decide + 10 min to land
16 Isolate a network segmentT3 Networks · costly to reverse · internal users feel itCISOOne declared trust zone, from the zone definitions on the terrain overlay. Never an undeclared boundary invented during the incident.4 hours.4 h 25 min4 h to decide + 25 min to land
17 Throttle the public data APIT3 Networks · reversible · public service degradedSOC leadThe public API surface, down to a documented floor rate that keeps published service commitments satisfiable.8 hours.30 min20 min to decide + 10 min to land
18 Sinkhole a domain internallyT3 Networks · reversible · no service effectPre-authorizedAny external domain not on the partner or supplier integration list.30 days.5 minimmediate to decide + 5 min to land
19 Disable a function of a public service applicationT4 Applications and Workloads · reversible · public service degradedSOC leadOne named function, on one service, where a documented alternative path exists for the public.8 hours.50 min20 min to decide + 30 min to land
20 Degrade or withdraw a public mission serviceT4 Applications and Workloads · costly to reverse · touches a statutory deadlineAuthorizing OfficialOne named service, for a stated period, with the statutory register consulted and the affected deadline named in the decision.As stated in the authorization, and no longer.16 h 45 min16 h to decide + 45 min to land
21 Kill an in-flight bulk exportT5 Data · reversible · internal users feel itPre-authorizedAny export against a store marked as holding sensitive mission records, controlled unclassified information, or personal data.Instantaneous.5 minimmediate to decide + 5 min to land
22 Emplace decoys in the data terrainT5 Data · reversible · no service effectSOC leadDecoys drawn from the approved decoy set. Bespoke decoy content is authored outside the incident and reviewed before it enters the set.Standing.80 min20 min to decide + 60 min to land
23 Halt the build and release pipelineT9 Supply Chain · costly to reverse · internal users feel itSOC leadThe pipeline serving the affected product line. A halt across every product line is a CISO decision.12 hours.25 min20 min to decide + 5 min to land
24 Revoke a supplier’s access mid-engagementT9 Supply Chain · costly to reverse · internal users feel itSOC leadThe supplier’s access, through the agency’s own identity plane. Not the supplier’s connectivity, their data, or their contract — those are the severance line.24 hours.30 min20 min to decide + 10 min to land
25 Sever a supplier entirelyT9 Supply Chain · irreversible in the incident · internal users feel itAuthorizing OfficialOne supplier, across every path recorded in the supplier terrain register.Until reversed by decision — there is no expiry on this line.18 h16 h to decide + 2 h to land
26 Suspend all access for an individual under insider referralT7 Workforce · costly to reverse · internal users feel itSOC leadOne individual, through the single revocation path that WF-5 requires to exist.Standing until the referral is resolved.25 min20 min to decide + 5 min to land
27 Revoke physical access to a facility zoneT8 Facilities · reversible · no service effectSOC leadOne zone, from the declared physical zone boundaries. Individuals or a named maintenance group, not a whole workforce category.24 hours.40 min20 min to decide + 20 min to land
28 Restore a mission dataset over live dataT5 Data · irreversible in the incident · touches a statutory deadlineAuthorizing OfficialOne dataset, to one recovery point, with the transactions between that point and now enumerated before the decision.Permanent.24 h16 h to decide + 8 h to land
29 Execute the trusted rebuild of the identity planeT1 Identity · irreversible in the incident · touches a statutory deadlineAuthorizing OfficialThe whole identity plane. There is no partial version of this decision.Permanent.40 h16 h to decide + 24 h to land

01 Revoke an authenticated session

T1 Identity · reversible · no service effect

Authority in garrison
Pre-authorized
Scope bound
A single named account. Never a group, an application registration, or a tenant-wide session policy.
Duration bound
Instantaneous — the session ends; the account is not disabled.
Expected latency
1 minimmediate to decide + 1 min to land

02 Force step-up authentication

T1 Identity · reversible · internal users feel it

Authority in garrison
Pre-authorized
Scope bound
Up to 250 internal accounts, or one application. Beyond that it is a change to the identity posture rather than a response, and it goes to the SOC lead.
Duration bound
24 hours.
Expected latency
5 minimmediate to decide + 5 min to land

03 Disable a standard internal account

T1 Identity · reversible · internal users feel it

Authority in garrison
Pre-authorized
Scope bound
One account at a time, up to five in an hour. The sixth is a pattern rather than an incident and goes to the SOC lead.
Duration bound
8 hours.
Expected latency
2 minimmediate to decide + 2 min to land

04 Disable a privileged account

T1 Identity · costly to reverse · internal users feel it

Authority in garrison
SOC lead
Scope bound
One named privileged account, bound to a named holder in the privileged human register. Never a service principal, and never a break-glass credential.
Duration bound
4 hours.
Expected latency
22 min20 min to decide + 2 min to land

05 Disable an executive or appointee account

T1 Identity · costly to reverse · internal users feel it

Authority in garrison
CISO
Scope bound
One named account on the executive list, which is maintained in the privileged human register alongside the technical accounts.
Duration bound
4 hours.
Expected latency
4 h 2 min4 h to decide + 2 min to land

06 Force credential reset for external portal users

T1 Identity · costly to reverse · public service degraded

Authority in garrison
Pre-authorized
Scope bound
Up to 500 external accounts identified by a specific compromise indicator. A population defined by anything broader than an indicator — a whole state, a whole filing type — is not this line.
Duration bound
Until reset. The account is not disabled and the service is not degraded.
Expected latency
10 minimmediate to decide + 10 min to land

07 Suspend a federated trust

T1 Identity · costly to reverse · internal users feel it

Authority in garrison
CISO
Scope bound
One federation. Never the whole federation set, which is an identity-plane outage wearing a containment label.
Duration bound
12 hours.
Expected latency
4 h 15 min4 h to decide + 15 min to land

08 Disable a legacy authentication path

T1 Identity · reversible · internal users feel it

Authority in garrison
SOC lead
Scope bound
One protocol path, agency-wide, or one application’s legacy endpoint.
Duration bound
Standing until reversed — this one is intended to become permanent.
Expected latency
50 min20 min to decide + 30 min to land

09 Rotate a service credential

T1 Identity · reversible · no service effect

Authority in garrison
Pre-authorized
Scope bound
Credentials with an automated rotation path registered in the secret store. A credential with no registered rotation path is a manual change and is not this line.
Duration bound
Permanent — the new value stands.
Expected latency
20 minimmediate to decide + 20 min to land

10 Activate the break-glass credential

T1 Identity · costly to reverse · no service effect

Authority in garrison
CISO
Scope bound
One credential, for one stated purpose, for the duration of one action.
Duration bound
2 hours, after which the credential is rotated and re-sealed whether or not it was used.
Expected latency
4 h 10 min4 h to decide + 10 min to land

11 Quarantine a mission-staff workstation

T2 Devices · reversible · internal users feel it

Authority in garrison
Pre-authorized
Scope bound
Up to ten endpoints per incident. The eleventh indicates a campaign rather than a compromise and goes to the SOC lead.
Duration bound
12 hours.
Expected latency
3 minimmediate to decide + 3 min to land

12 Isolate a production workload

T4 Applications and Workloads · costly to reverse · internal users feel it

Authority in garrison
SOC lead
Scope bound
One workload, where the terrain overlay shows at least one healthy peer carrying the same service.
Duration bound
6 hours.
Expected latency
30 min20 min to decide + 10 min to land

13 Terminate a process and quarantine its artifact

T2 Devices · reversible · no service effect

Authority in garrison
Pre-authorized
Scope bound
Any endpoint or server, excluding operational technology and anything on the recovery path.
Duration bound
Instantaneous.
Expected latency
2 minimmediate to decide + 2 min to land

14 Block named external infrastructure

T3 Networks · reversible · no service effect

Authority in garrison
Pre-authorized
Scope bound
Individual addresses, fully-qualified domains, and prefixes no larger than a /24. Autonomous-system-wide or provider-wide blocks are a different line.
Duration bound
30 days, then reviewed.
Expected latency
5 minimmediate to decide + 5 min to land

15 Block a source range carrying public traffic

T3 Networks · reversible · public service degraded

Authority in garrison
CISO
Scope bound
One service, one range, with the legitimate population inside the range estimated before firing rather than after.
Duration bound
4 hours.
Expected latency
4 h 10 min4 h to decide + 10 min to land

16 Isolate a network segment

T3 Networks · costly to reverse · internal users feel it

Authority in garrison
CISO
Scope bound
One declared trust zone, from the zone definitions on the terrain overlay. Never an undeclared boundary invented during the incident.
Duration bound
4 hours.
Expected latency
4 h 25 min4 h to decide + 25 min to land

17 Throttle the public data API

T3 Networks · reversible · public service degraded

Authority in garrison
SOC lead
Scope bound
The public API surface, down to a documented floor rate that keeps published service commitments satisfiable.
Duration bound
8 hours.
Expected latency
30 min20 min to decide + 10 min to land

18 Sinkhole a domain internally

T3 Networks · reversible · no service effect

Authority in garrison
Pre-authorized
Scope bound
Any external domain not on the partner or supplier integration list.
Duration bound
30 days.
Expected latency
5 minimmediate to decide + 5 min to land

19 Disable a function of a public service application

T4 Applications and Workloads · reversible · public service degraded

Authority in garrison
SOC lead
Scope bound
One named function, on one service, where a documented alternative path exists for the public.
Duration bound
8 hours.
Expected latency
50 min20 min to decide + 30 min to land

20 Degrade or withdraw a public mission service

T4 Applications and Workloads · costly to reverse · touches a statutory deadline

Authority in garrison
Authorizing Official
Scope bound
One named service, for a stated period, with the statutory register consulted and the affected deadline named in the decision.
Duration bound
As stated in the authorization, and no longer.
Expected latency
16 h 45 min16 h to decide + 45 min to land

21 Kill an in-flight bulk export

T5 Data · reversible · internal users feel it

Authority in garrison
Pre-authorized
Scope bound
Any export against a store marked as holding sensitive mission records, controlled unclassified information, or personal data.
Duration bound
Instantaneous.
Expected latency
5 minimmediate to decide + 5 min to land

22 Emplace decoys in the data terrain

T5 Data · reversible · no service effect

Authority in garrison
SOC lead
Scope bound
Decoys drawn from the approved decoy set. Bespoke decoy content is authored outside the incident and reviewed before it enters the set.
Duration bound
Standing.
Expected latency
80 min20 min to decide + 60 min to land

23 Halt the build and release pipeline

T9 Supply Chain · costly to reverse · internal users feel it

Authority in garrison
SOC lead
Scope bound
The pipeline serving the affected product line. A halt across every product line is a CISO decision.
Duration bound
12 hours.
Expected latency
25 min20 min to decide + 5 min to land

24 Revoke a supplier’s access mid-engagement

T9 Supply Chain · costly to reverse · internal users feel it

Authority in garrison
SOC lead
Scope bound
The supplier’s access, through the agency’s own identity plane. Not the supplier’s connectivity, their data, or their contract — those are the severance line.
Duration bound
24 hours.
Expected latency
30 min20 min to decide + 10 min to land

25 Sever a supplier entirely

T9 Supply Chain · irreversible in the incident · internal users feel it

Authority in garrison
Authorizing Official
Scope bound
One supplier, across every path recorded in the supplier terrain register.
Duration bound
Until reversed by decision — there is no expiry on this line.
Expected latency
18 h16 h to decide + 2 h to land

26 Suspend all access for an individual under insider referral

T7 Workforce · costly to reverse · internal users feel it

Authority in garrison
SOC lead
Scope bound
One individual, through the single revocation path that WF-5 requires to exist.
Duration bound
Standing until the referral is resolved.
Expected latency
25 min20 min to decide + 5 min to land

27 Revoke physical access to a facility zone

T8 Facilities · reversible · no service effect

Authority in garrison
SOC lead
Scope bound
One zone, from the declared physical zone boundaries. Individuals or a named maintenance group, not a whole workforce category.
Duration bound
24 hours.
Expected latency
40 min20 min to decide + 20 min to land

28 Restore a mission dataset over live data

T5 Data · irreversible in the incident · touches a statutory deadline

Authority in garrison
Authorizing Official
Scope bound
One dataset, to one recovery point, with the transactions between that point and now enumerated before the decision.
Duration bound
Permanent.
Expected latency
24 h16 h to decide + 8 h to land

29 Execute the trusted rebuild of the identity plane

T1 Identity · irreversible in the incident · touches a statutory deadline

Authority in garrison
Authorizing Official
Scope bound
The whole identity plane. There is no partial version of this decision.
Duration bound
Permanent.
Expected latency
40 h16 h to decide + 24 h to land
Latency is decision plus execution, computed per line from the authority it sits at and the time the effect takes to land. Sub-labels give the terrain layer, how hard the action is to undo, and who notices — the three properties that decide where a line sits.
Phasing

Phase III Is Not Phase 0.

A phase declaration that does not move the schedule has not changed anything operational. Only the phase at which a line moves is written down; every other cell is carried forward or produced by rule.

The schedule is not one document with a single set of widths. It is a garrison position plus a small number of authored widenings, and two narrowing rules that no phase may override. That structure is deliberate: 29 lines across 6 phases is 174 cells, and 174 hand-maintained cells is 174 chances for the schedule to contradict itself in the one situation where nobody has time to notice.

Every phase

A fire that can degrade a service carrying a statutory deadline never sits below the Authorizing Official.

FO-5 sets the floor from outside the agency. No campaign phase, and no argument about tempo, moves a deadline that a statute or an authorizing instrument fixed.

Every phase

A widening carries forward until it is changed. Only the phase at which a line moves is written down.

A schedule that restates every line in every phase is a schedule with 174 cells to keep consistent, and it will not stay consistent. Carrying forward also matches how a campaign actually runs: authority granted in Phase II is not silently withdrawn on entering Phase III.

Phase IV

For the duration of a recovery, every fire that is not both reversible and free of public effect returns to the Authorizing Official.

Phase IV narrows deliberately. A service that has just been restored is carrying the agency’s credibility as well as its traffic, and the Authorizing Official re-enters the decision path for anything that could take it back down — which is everything costly to reverse and everything the public can see. The suspension of the wider authority is itself recorded, with an owner and a restoration point.

Phase V

The schedule returns to its garrison widths.

Phase V hands back to garrison. Every authority exception logged during the campaign is then evidence about whether the garrison widths were right — which is the only moment at which that evidence is both fresh and unpressured.

Exhibit 3

The Shape of the Schedule in Each Campaign Phase

PhasePre-authorizedSOC leadCISOAuthorizing OfficialMedian latency
Phase 0 — ShapeGarrison decision times1034% of the schedule105430 minmean 4 h 23 min
Phase I — DeterGarrison decision times1241% of the schedule85430 minmean 4 h 22 min
Phase II — Seize InitiativeStanding bridge open1655% of the schedule54410 minmean 1 h 46 min
Phase III — DominateStanding bridge open2172% of the schedule41310 minmean 1 h 37 min
Phase IV — StabilizeStanding bridge open1241% of the schedule00172 h 5 minmean 2 h 33 min
Phase V — Enable / RestoreGarrison decision times1034% of the schedule105430 minmean 4 h 23 min

Phase 0 — Shape

Garrison decision times

Pre-authorized
1034% of the schedule
SOC lead
10
CISO
5
Authorizing Official
4
Median latency
30 minmean 4 h 23 min

Phase I — Deter

Garrison decision times

Pre-authorized
1241% of the schedule
SOC lead
8
CISO
5
Authorizing Official
4
Median latency
30 minmean 4 h 22 min

Phase II — Seize Initiative

Standing bridge open

Pre-authorized
1655% of the schedule
SOC lead
5
CISO
4
Authorizing Official
4
Median latency
10 minmean 1 h 46 min

Phase III — Dominate

Standing bridge open

Pre-authorized
2172% of the schedule
SOC lead
4
CISO
1
Authorizing Official
3
Median latency
10 minmean 1 h 37 min

Phase IV — Stabilize

Standing bridge open

Pre-authorized
1241% of the schedule
SOC lead
0
CISO
0
Authorizing Official
17
Median latency
2 h 5 minmean 2 h 33 min

Phase V — Enable / Restore

Garrison decision times

Pre-authorized
1034% of the schedule
SOC lead
10
CISO
5
Authorizing Official
4
Median latency
30 minmean 4 h 23 min
Counts and latencies are computed from the schedule for that phase, not authored per phase. Median and mean are over all 29 lines. Phases from Seize Initiative through Stabilize use the standing bridge, which is why an escalated line is survivable in contact and not in garrison.

Phase IV is the interesting row. It is the only phase in which the middle of the schedule empties: what is undoable and invisible stays standing, everything else returns to the Authorizing Official, and there is nothing in between. That is the correct shape for a recovery — a service that has just come back is carrying the agency’s credibility as well as its traffic — but it should be a declared, temporary suspension with a restoration point, not a state the program drifts into and stays in.

What Moves, and When

Phase I — Deter2 of 29 move

12 of the 29 lines never widen at all, in any phase. That set is the honest test of whether a schedule has a spine: a document in which everything eventually becomes pre-authorized under enough pressure has not decided anything, it has only sequenced its surrender.

The Floor

What May Not Be Degraded, at Any Authority.

Every other constraint on this page is an agency decision and can be revisited. This one is not, and treating it as though it were is the failure mode the control exists to prevent.

The statutory availability floor is the framework’s statement that some availability requirements are not business preferences. A benefit that must be paid, a filing window that must stay open, a report that must be delivered by a date — where an instrument fixes the deadline, the agency’s recovery objectives are constrained by it rather than negotiated against it, and naming the instrument is required precisely because an availability requirement without a citation gets revised downward the moment it becomes inconvenient.

On this page the floor does three specific things, and it is worth being precise about which, because “FO-5 constrains the ROE” is the kind of sentence that sounds like a control and functions like a slogan.

It holds 3 lines at the Authorizing Official, permanently

Where a statutory deadline is riding on a service, anything capable of degrading it stays at the top of the schedule in every phase, Phase III included. There is no mechanism in this document to move them, which is the point: the widening rules operate on agency risk appetite, and this is not agency risk appetite.

It voids the standing authority on every other line

The first standing exclusion is the register check. Whatever a line’s width, it escalates the moment its target appears on the availability register inside a deadline window. What the operator does at 02:00 is a lookup, not a judgment — which is the only version of this rule that survives contact.

It is not a thing the schedule can authorize breaching

This is the part most often got wrong. The Authorizing Official can authorize degradation within the floor, and can accept a breach that has already happened. What no level of this schedule can do is authorize missing a statutory deadline as a defensive choice — that decision belongs to the instrument’s owner, with counsel and the agency head, and a rules-of-engagement document that implies otherwise is writing cheques on somebody else’s authority.

It depends entirely on the register being real

Every claim above collapses if the statutory availability register is incomplete or stale. An operator checking a register that does not list the filing system will fire, correctly by the schedule and wrongly by the mission. The floor is a terrain-currency problem wearing a governance hat, and the honest place to fix it is upstream.

The reference agency’s own intent — degrade gracefully, never fail open — is the tie-breaker when the floor and the defense pull in opposite directions, and it is why the top line of this schedule is a deliberate, authorized, recorded degradation rather than an unplanned outage discovered afterwards.

Where the Line Sits

The Easy Cases Decide Themselves. These Do Not.

Revoking a session is obviously pre-authorizable and degrading a statutory service obviously is not. The schedule is only worth writing because of what sits between them.

Case 1

A supplier’s account is implicated in an intrusion, and their engagement is live. May the SOC cut their access at 02:00?

The case for standing authority

Supplier access is the most reliable route into a federal estate that exists, and the window in which cutting it matters is measured in minutes. The access is technically identical to any other account: brokered through the agency identity plane, revocable in one action, restorable in another. Every property that makes session revocation an easy call is present here.

The case against

The cost of being wrong does not land on the SOC. It lands on a contracting officer’s representative explaining to a supplier why their engineers were locked out mid-delivery, on a delivery schedule, and sometimes on a contract. That cost is real, it is invisible from the SOC console, and it is precisely the kind of cost that produces a schedule operators are told informally to ignore.

Where this schedule puts it

SOC lead in garrison, pre-authorized from Phase II. The reasoning is that the decision hinges on a control question rather than an incident question: LC-3 requires supplier access to be brokered through the agency’s own identity plane with no standing access to a decisive point. Where that control holds, revocation is a bounded, reversible action against an agency-controlled credential and belongs low on the schedule. Where it does not hold — where the supplier’s access runs through their own infrastructure, or where they hold standing access to a decisive point — revocation is not a fire the agency can execute at all. It is a phone call, and the honest schedule entry for it is an LC-3 finding.

What would move the line
  • The access is not brokered through the agency identity plane. The line becomes unavailable rather than escalated — the agency cannot fire it, and the finding is the answer.
  • The supplier operates a service on the statutory availability register. FO-5 holds, and the fire escalates whatever the phase.
  • The supplier holds the only operational knowledge of a system in an active availability incident, in which case cutting them off extends the incident the agency is trying to end.
  • Full severance rather than access revocation: a different line, marked irreversible, and never pre-authorized in any phase.
Roles
Case 2

Lateral movement is confirmed inside a segment. The segment carries a case-filing system, and the filing window closes in nine hours. Isolate it?

The case for standing authority

Segment isolation is the most effective containment action in the catalog. Nine hours is long enough for an adversary to reach the data terrain from where they are, and every minute spent finding somebody with authority is a minute of movement. Isolation is also reversible — the segment comes back when the boundary is restored.

The case against

A missed filing window is not an outage the agency apologizes for. It is a statutory position with consequences for the public that no amount of good incident handling repairs afterwards, and FO-5 exists precisely because availability requirements of this kind get revised downward the moment they become inconvenient.

Where this schedule puts it

CISO in garrison, pre-authorized from Phase III — but the statutory-window exclusion binds the line at every level, so on these facts it escalates regardless of phase. The schedule does not resolve this by choosing containment or availability; it resolves it by requiring the register to be consulted before the fire, which converts an argument into a lookup. What the operator does at 02:00 is check whether the element is inside its window, and if it is, escalate with the deadline named. The Authorizing Official then makes the decision they are there to make, on facts rather than on adrenaline.

What would move the line
  • The filing window has closed, or the deadline is far enough out that isolation and restoration both fit inside it — the exclusion lifts and the line runs at its phase authority.
  • A middle rung exists: disabling the filing function while leaving the rest of the segment reachable is a lower line with a documented alternative path, and it is very often the right answer.
  • The overlay does not show which services in the segment carry deadlines. Then the answer is not a rules-of-engagement problem, it is a terrain currency problem, and the fire is escalating because TM-6 failed.
  • The recovery objective for the segment is shorter than the time remaining in the window, which makes isolation recoverable inside the deadline and changes the risk the Authorizing Official is being asked to accept.
Roles
Case 3

A moderate-confidence signal suggests a deputy administrator’s account is being used by someone else. The same signal against a case worker would be pre-authorized. Disable it?

The case for standing authority

The action is technically identical to disabling any other account, and the account is more valuable to an adversary than any case worker’s: it reaches pre-decisional records, it carries authority in every workflow it touches, and it is trusted by recipients in a way that makes it useful for onward access. If anything the argument for speed is stronger, not weaker.

The case against

Moderate confidence means the signal is wrong a meaningful fraction of the time, and the cost of being wrong is not symmetric. Locking out a case worker for twenty minutes is an inconvenience; locking out a deputy administrator during a hearing is an incident of a different kind, with a conversation nobody in the SOC is positioned to have. Operators know this, and a schedule that ignores it produces hesitation rather than compliance — which is worse than an honest escalation, because the delay is unrecorded.

Where this schedule puts it

CISO in garrison, SOC lead from Phase II, pre-authorized from Phase III — with the confidence floor doing the real work. The line sits at moderate confidence, which is deliberately the same floor as for a standard account: the schedule does not demand better evidence for a senior person, because that is how a privileged position becomes a protected one. What it demands instead is a decision-maker who can absorb the political cost, until a declared contact phase makes that cost obviously smaller than the alternative. The framework’s position is that the escalation here is honest — the cost is real and it is not technical — and that the correct fix is not to widen the line but to shorten the CISO’s decision latency, which the standing bridge does.

What would move the line
  • Confidence rises to observed fact — credential use from an impossible location, or the holder confirming they are not signed in. The signal, not the seniority, is what moved.
  • A contact phase is declared. The fire widens twice on the way to Phase III, and the political cost of being wrong falls each time.
  • The holder is the Authorizing Official, or is in the continuity-of-operations succession line: the line becomes unavailable rather than escalated, because firing it removes the agency’s ability to authorize its own response.
  • A weaker action satisfies the need — forcing step-up authentication is pre-authorized, reversible in seconds, and answers the same question in most cases without disabling anything.
Roles
Case 4

Credential-stuffing against the public portal comes overwhelmingly from one provider’s address space, which also carries legitimate users. Block the range?

The case for standing authority

The action is a firewall rule. It is reversible in seconds, it costs nothing to undo, and by every test this schedule applies to reversibility it belongs at the widest authority available.

The case against

Reversibility is not the only test, and this is the case that shows why. The users denied are members of the public trying to reach a government service, they have no alternative supplier, and many of them will not try again. The harm is not undone when the rule is removed — it has already happened to whoever was denied, and it lands hardest on the population least able to absorb it.

Where this schedule puts it

CISO in garrison, SOC lead from Phase III, and the pre-authorized level is never reached. The reasoning is that reversibility of the *action* is not reversibility of the *harm*, and where those two diverge the schedule follows the harm. The bound that makes the line workable at all is the requirement to estimate the legitimate population inside the range before firing rather than after: without that number the decision is not fast, it is merely uninformed, and the exclusion refuses the fire outright.

What would move the line
  • A narrower discriminator exists — a device signature, a request pattern, a set of accounts. Then it is a different, cheaper line, and the range block was never the right instrument.
  • The service is on the statutory availability register inside its window: the fire escalates whatever the phase.
  • Throttling achieves the same protection. Delay is a lower rung than denial, and the schedule reaches for it first by design.
  • The range carries no measurable legitimate traffic to this service, verified from the service’s own logs rather than assumed from the provider’s reputation.
Maneuver
Roles
Case 5

An artifact in the build pipeline fails its provenance check during a release window. Halting the pipeline stops a release the agency has committed to. Halt it?

The case for standing authority

The pipeline is a declared decisive point at the reference agency: everything downstream of it inherits whatever it produces, which makes it the highest-leverage piece of ground an adversary can hold. Halting it is reversible — nothing is destroyed, builds queue — and the alternative is signing and deploying an artifact whose provenance is in question.

The case against

Release commitments in a federal estate are frequently commitments to somebody else: a mission deadline, an interagency dependency, a public communication that has already gone out. A SOC that can stop the agency shipping has an authority that looks operational and is really programmatic, and it will be used the first time an indicator looks bad on a Friday.

Where this schedule puts it

SOC lead in garrison, pre-authorized from Phase II. This is the line where the decisive-point argument wins, and it wins because of what a decisive point means: KT-2 requires every decisive point to have an assigned, operational defensive move, and a move that can only be executed after a twenty-minute approval is not operational at the tempo the ground demands. The bound that keeps it honest is scope — the pipeline for the affected product line, not every pipeline — and an exclusion for the case where the release itself is the remedy for an availability incident.

What would move the line
  • The release is the fix for an active availability incident. The exclusion applies and the halt escalates.
  • The halt would span every product line, which is a programmatic decision and sits with the CISO.
  • The pipeline is not on the decisive-point list. Then the whole argument for the widened authority evaporates, and the line should sit where any other workload-isolation line sits.
  • A staging gate can hold the artifact without stopping the pipeline. Update integrity and staging exists so that a provenance failure has a smaller answer than a halt.
Roles
Index

Every Line, by the Ground It Acts On.

The Schedule in Full

Effect, Authority, Bounds, Exclusions, Record and Latency.

Each line carries its authority in all 6 phases, derived from its garrison position and the rules above rather than authored six times.

T1 IdentityThe high ground

Line 01

Revoke an authenticated session

Pre-authorized

Kill the active session and refresh tokens for a standard internal account, forcing full re-authentication at the policy decision point.

Reversibilityreversible
Exposureno service effect
Confidence floormoderate confidence
Latency in garrison1 minimmediate to decide, 1 min to land
Scope bound

A single named account. Never a group, an application registration, or a tenant-wide session policy.

Duration and renewal

Instantaneous — the session ends; the account is not disabled. None required. The user re-authenticates and continues; a repeat inside four hours escalates to the SOC lead under the standing second-fire rule.

Where this authority does not apply
  • The account is privileged, executive, or bound to a service rather than a person — those are separate lines with their own authority.
  • The session belongs to an emergency responder actively working the incident.

Plus the 8 standing exclusions, which bind every line.

Record owed, within 60 min
  • The detection that prompted it, and whether re-authentication succeeded from the same source

Plus the 6 standing fields.

Why the line sits here

The easiest line on the schedule, and worth stating precisely because it sets the standard the harder lines are measured against: bounded to one account, undone by the user typing a password, no service effect, and a record that takes thirty seconds. Anything with those four properties should be pre-authorized, and a program that cannot get this one approved has a governance problem rather than a risk problem.

Authority by phase
0 ShapePre-authorized1 min
I DeterPre-authorized1 min
II Seize InitiativePre-authorized1 min
III DominatePre-authorized1 min
IV StabilizePre-authorized1 min
V Enable / RestorePre-authorized1 min
Controls
Roles
Cycle step
Line 02

Force step-up authentication

Pre-authorized

Raise the authentication requirement for a named account or a defined group — phishing-resistant factor, device compliance, or re-registration — at the policy decision point.

Reversibilityreversible
Exposureinternal users feel it
Confidence floormoderate confidence
Latency in garrison5 minimmediate to decide, 5 min to land
Scope bound

Up to 250 internal accounts, or one application. Beyond that it is a change to the identity posture rather than a response, and it goes to the SOC lead.

Duration and renewal

24 hours. Expires to the standing policy unless the SOC lead renews it. A step-up that has been standing for a week is policy and belongs in the change process.

Where this authority does not apply
  • The population includes external portal users — a step-up they cannot satisfy is a denial of service to the public, which is a different line.
  • The factor being demanded is not already registered for the population, which turns a step-up into a lock-out.

Plus the 8 standing exclusions, which bind every line.

Record owed, within 4 h
  • Population size, and the number of accounts that failed to satisfy the raised requirement

Plus the 6 standing fields.

Authority by phase
0 ShapePre-authorized5 min
I DeterPre-authorized5 min
II Seize InitiativePre-authorized5 min
III DominatePre-authorized5 min
IV StabilizePre-authorized5 min
V Enable / RestorePre-authorized5 min
Controls
Roles
Glossary
Line 03

Disable a standard internal account

Pre-authorized

Disable a non-privileged staff account and revoke its sessions and tokens.

Reversibilityreversible
Exposureinternal users feel it
Confidence floorhigh confidence
Latency in garrison2 minimmediate to decide, 2 min to land
Scope bound

One account at a time, up to five in an hour. The sixth is a pattern rather than an incident and goes to the SOC lead.

Duration and renewal

8 hours. Auto-restores unless renewed by the SOC lead with a stated reason. Default-restore is the point: an account disabled at 03:00 on a signal that dissolved by 09:00 should not require anyone to remember it.

Where this authority does not apply
  • The holder is on-call for a mission service and disabling them removes the only person who can restore it.
  • The account is the last administrative account for a system — the last-instance rule applies to people as well as servers.

Plus the 8 standing exclusions, which bind every line.

Record owed, within 60 min
  • Whether the holder was notified, and by whom
  • The restoration decision at expiry

Plus the 6 standing fields.

Authority by phase
0 ShapePre-authorized2 min
I DeterPre-authorized2 min
II Seize InitiativePre-authorized2 min
III DominatePre-authorized2 min
IV StabilizePre-authorized2 min
V Enable / RestorePre-authorized2 min

Worked through in Disabling an executive account on a moderate-confidence signal.

Controls
Roles
Line 04

Disable a privileged account

SOC lead

Disable an account holding administrative rights over an identity, platform or mission system, and revoke its sessions.

Reversibilitycostly to reverse
Exposureinternal users feel it
Confidence floorhigh confidence
Latency in garrison22 min20 min to decide, 2 min to land
Scope bound

One named privileged account, bound to a named holder in the privileged human register. Never a service principal, and never a break-glass credential.

Duration and renewal

4 hours. Auto-restores unless renewed. Renewal in Phase II or later is a SOC lead decision; in garrison it is the CISO.

Where this authority does not apply
  • The account is running a scheduled mission job inside its window — the job fails silently and the failure is found days later.
  • It is the only privileged account for a system with no break-glass path registered.

Plus the 8 standing exclusions, which bind every line.

Record owed, within 60 min
  • The privileged register entry for the holder, and whether their vetting was current
  • Any mission job or automation that depended on the account

Plus the 6 standing fields.

Why the line sits here

The interesting half of this line is why it is not pre-authorized in garrison. Privileged accounts in a federal estate run things — batch jobs, integrations, nightly reconciliations — and the blast radius of disabling one is knowable only from the privileged register, which is exactly the artifact a night-shift operator is least likely to consult under pressure. The second pair of eyes is not distrust of the operator; it is a twenty-minute check against a register. Once contact is declared, the calculus inverts: a privileged account on the observed avenue is the adversary’s objective, and twenty minutes is the whole engagement.

Authority by phase
0 ShapeSOC lead22 min
I DeterSOC lead22 min
II Seize InitiativePre-authorized2 min
III DominatePre-authorized2 min
IV StabilizeAuthorizing Official2 h 2 min
V Enable / RestoreSOC lead22 min
Controls
Roles
Line 05

Disable an executive or appointee account

CISO

Disable an account held by an agency executive, political appointee, or their immediate staff, and revoke its sessions.

Reversibilitycostly to reverse
Exposureinternal users feel it
Confidence floormoderate confidence
Latency in garrison4 h 2 min4 h to decide, 2 min to land
Scope bound

One named account on the executive list, which is maintained in the privileged human register alongside the technical accounts.

Duration and renewal

4 hours. Auto-restores unless renewed by the CISO. The renewal, not the fire, is where the conversation with the executive happens.

Where this authority does not apply
  • The holder is the Authorizing Official and the fire would remove the agency’s ability to authorize its own response.
  • A continuity-of-operations event is active and the holder is in the succession line for it.

Plus the 8 standing exclusions, which bind every line.

Record owed, within 60 min
  • Notification to the holder and to their chief of staff, with times
  • The confidence level at the moment of firing, and what changed it afterwards

Plus the 6 standing fields.

Why the line sits here

Discussed at length below. In short: the fire is technically identical to disabling any other account, and the reason it sits higher is entirely political — the cost of being wrong is a conversation nobody in the SOC can have. That is a real cost, and pretending it is a technical one is how schedules get written that operators quietly ignore.

Authority by phase
0 ShapeCISO4 h 2 min
I DeterCISO4 h 2 min
II Seize InitiativeSOC lead7 min
III DominatePre-authorized2 min
IV StabilizeAuthorizing Official2 h 2 min
V Enable / RestoreCISO4 h 2 min

Worked through in Disabling an executive account on a moderate-confidence signal.

Roles
Line 06

Force credential reset for external portal users

Pre-authorized

Invalidate credentials for a defined population of external users — citizens, businesses, or their filing agents — and require reset on next sign-in.

Reversibilitycostly to reverse
Exposurepublic service degraded
Confidence floorhigh confidence
Latency in garrison10 minimmediate to decide, 10 min to land
Scope bound

Up to 500 external accounts identified by a specific compromise indicator. A population defined by anything broader than an indicator — a whole state, a whole filing type — is not this line.

Duration and renewal

Until reset. The account is not disabled and the service is not degraded. Not applicable; the user completes the reset. Accounts unreset after 30 days go to the mission owner, not to the SOC.

Where this authority does not apply
  • The population is inside a statutory filing window and lacks a supported reset path — a reset the user cannot complete before a deadline is a denial of the deadline.
  • The reset path itself depends on the system suspected of compromise.

Plus the 8 standing exclusions, which bind every line.

Record owed, within 4 h
  • Population size, the indicator that defined it, and the completed-reset rate at 24 and 72 hours
  • Volume delivered to the public contact center, which is where the real cost of this fire lands

Plus the 6 standing fields.

Why the line sits here

Pre-authorized despite a public effect, because the effect is on the user’s credential rather than on the service, and because a compromised external credential on a public portal is the single most common way a federal estate acquires an adversary. The bound that makes it safe is not the authority level, it is the requirement that the population be defined by an indicator rather than by a category.

Authority by phase
0 ShapePre-authorized10 min
I DeterPre-authorized10 min
II Seize InitiativePre-authorized10 min
III DominatePre-authorized10 min
IV StabilizeAuthorizing Official2 h 10 min
V Enable / RestorePre-authorized10 min
Controls
Roles
Line 07

Suspend a federated trust

CISO

Suspend the federation with a partner agency, supplier, or external identity provider, cutting inbound assertions from that source.

Reversibilitycostly to reverse
Exposureinternal users feel it
Confidence floorhigh confidence
Latency in garrison4 h 15 min4 h to decide, 15 min to land
Scope bound

One federation. Never the whole federation set, which is an identity-plane outage wearing a containment label.

Duration and renewal

12 hours. CISO renews, with the partner notified. A suspension standing beyond 48 hours becomes a supplier or interagency matter rather than a security one.

Where this authority does not apply
  • The federation carries authentication for a service on the statutory availability register inside its window.
  • The partner is the agency’s own shared-service provider and the suspension would lock out the response team.

Plus the 8 standing exclusions, which bind every line.

Record owed, within 2 h
  • The partner, the notification made to them, and the time of it
  • What the suspended trust was carrying, from the connection register

Plus the 6 standing fields.

Why the line sits here

This sits at CISO in garrison because the fire lands on somebody else’s users, and the agency will be explaining it to a peer organization within the hour. It widens in Phase III because by then the explanation is easier than the alternative.

Authority by phase
0 ShapeCISO4 h 15 min
I DeterCISO4 h 15 min
II Seize InitiativeCISO60 min
III DominateSOC lead20 min
IV StabilizeAuthorizing Official2 h 15 min
V Enable / RestoreCISO4 h 15 min
Controls
Roles
Line 08

Disable a legacy authentication path

SOC lead

Turn off a protocol path that cannot carry phishing-resistant authentication — legacy mail protocols, basic auth endpoints, an unmodernised API surface.

Reversibilityreversible
Exposureinternal users feel it
Confidence floormoderate confidence
Latency in garrison50 min20 min to decide, 30 min to land
Scope bound

One protocol path, agency-wide, or one application’s legacy endpoint.

Duration and renewal

Standing until reversed — this one is intended to become permanent. Reviewed at the next cycle assessment. A legacy path turned off in an incident and quietly turned back on afterwards is the clearest evidence a program is not converting contact into advantage.

Where this authority does not apply
  • A mission integration is known to depend on it and no migration has been agreed — that is a change, not a fire.
  • The path is the fallback authentication for the operational technology estate.

Plus the 8 standing exclusions, which bind every line.

Record owed, within 4 h
  • What broke, and the exploitation finding raised to close the path permanently

Plus the 6 standing fields.

Authority by phase
0 ShapeSOC lead50 min
I DeterPre-authorized30 min
II Seize InitiativePre-authorized30 min
III DominatePre-authorized30 min
IV StabilizePre-authorized30 min
V Enable / RestoreSOC lead50 min
Controls
Roles
Cycle step
Line 09

Rotate a service credential

Pre-authorized

Force rotation of an API key, service-principal secret, or machine credential, and invalidate the old value.

Reversibilityreversible
Exposureno service effect
Confidence floormoderate confidence
Latency in garrison20 minimmediate to decide, 20 min to land
Scope bound

Credentials with an automated rotation path registered in the secret store. A credential with no registered rotation path is a manual change and is not this line.

Duration and renewal

Permanent — the new value stands. Not applicable.

Where this authority does not apply
  • The credential is a signing key, a certificate authority key, or anything whose rotation invalidates artifacts already issued.
  • The consuming system is mid-run on a batch that would fail on rotation.

Plus the 8 standing exclusions, which bind every line.

Record owed, within 4 h
  • Consumers of the credential, from the secret store, and whether each picked up the new value

Plus the 6 standing fields.

Why the line sits here

The exclusion for signing keys is the whole line. Rotating a service secret is invisible; rotating a signing key invalidates every artifact already issued under it, which in a federal estate can mean documents that have legal effect. Same verb, different fire, different authority.

Authority by phase
0 ShapePre-authorized20 min
I DeterPre-authorized20 min
II Seize InitiativePre-authorized20 min
III DominatePre-authorized20 min
IV StabilizePre-authorized20 min
V Enable / RestorePre-authorized20 min
Controls
Roles
Line 10

Activate the break-glass credential

CISO

Take the sealed administrative credential out of escrow and use it, on the assumption that the normal privileged path is unavailable or untrusted.

Reversibilitycostly to reverse
Exposureno service effect
Confidence floormoderate confidence
Latency in garrison4 h 10 min4 h to decide, 10 min to land
Scope bound

One credential, for one stated purpose, for the duration of one action.

Duration and renewal

2 hours, after which the credential is rotated and re-sealed whether or not it was used. A second activation is a separate CISO decision, and the fact that one was needed is a finding.

Where this authority does not apply
  • The normal privileged path is available and merely slow — impatience is not an activation condition.
  • The credential has not been exercised in the last reconstitution exercise, in which case its state is unknown and using it during an incident is a gamble.

Plus the 8 standing exclusions, which bind every line.

Record owed, within 60 min
  • Every action taken under the credential, from an independent log the credential itself cannot alter
  • The rotation and re-seal, with the time

Plus the 6 standing fields.

Why the line sits here

Break-glass is the one place where an authority level protects the credential rather than the estate. The activation is not risky; the loss of the credential’s meaning is. A break-glass path activated casually is a standing privileged account with a dramatic name.

Authority by phase
0 ShapeCISO4 h 10 min
I DeterCISO4 h 10 min
II Seize InitiativeCISO55 min
III DominateSOC lead15 min
IV StabilizeAuthorizing Official2 h 10 min
V Enable / RestoreCISO4 h 10 min
Controls
Roles
Line 29

Execute the trusted rebuild of the identity plane

Authorizing Official

Stand up a clean identity plane from the trusted rebuild path and cut over, on the assumption that the production one can no longer be trusted.

Reversibilityirreversible in the incident
Exposuretouches a statutory deadline
Confidence floorhigh confidence
Latency in garrison40 h16 h to decide, 24 h to land
Scope bound

The whole identity plane. There is no partial version of this decision.

Duration and renewal

Permanent. Not applicable.

Where this authority does not apply
  • None that widen it.
  • The rebuild path has not been exercised inside the stated reconstitution cadence, in which case the decision is being taken on an untested capability and the record must say so.

Plus the 8 standing exclusions, which bind every line.

Record owed, within 4 h
  • The authorization, and the assessment of production identity-plane trust that justified it
  • Every service re-federated, with the time each came back
  • Elapsed time against the recovery objective, and against the statutory floor for every service that depends on it

Plus the 6 standing fields.

Why the line sits here

The most consequential decision in the framework and the one least likely to appear in a rules-of-engagement document, because it is filed under recovery. It belongs here: it is an action taken under contact, with an authority question, a latency, and a record — which is the definition the rest of this schedule uses.

Authority by phase
0 ShapeAuthorizing Official40 h
I DeterAuthorizing Official40 h
II Seize InitiativeAuthorizing Official26 h
III DominateAuthorizing Official26 h
IV StabilizeAuthorizing Official26 h
V Enable / RestoreAuthorizing Official40 h
Roles

T2 DevicesThe entry fords

Line 11

Quarantine a mission-staff workstation

Pre-authorized

Place an endpoint into network isolation at the agent, leaving management and response channels reachable and everything else cut.

Reversibilityreversible
Exposureinternal users feel it
Confidence floormoderate confidence
Latency in garrison3 minimmediate to decide, 3 min to land
Scope bound

Up to ten endpoints per incident. The eleventh indicates a campaign rather than a compromise and goes to the SOC lead.

Duration and renewal

12 hours. Auto-releases unless renewed by the SOC lead. Release is deliberate: an endpoint released by timer without a triage decision is a fire that achieved nothing.

Where this authority does not apply
  • The endpoint is an engineering workstation with a live connection into the operational technology estate — isolation there can leave a physical process without its operator.
  • The endpoint is a clinical, laboratory, or control-room device where the workstation is the mission rather than the means of access to it.

Plus the 8 standing exclusions, which bind every line.

Record owed, within 2 h
  • The holder and their mission function
  • Whether the isolation held — an endpoint that kept talking is a finding about the agent, not about the incident

Plus the 6 standing fields.

Authority by phase
0 ShapePre-authorized3 min
I DeterPre-authorized3 min
II Seize InitiativePre-authorized3 min
III DominatePre-authorized3 min
IV StabilizePre-authorized3 min
V Enable / RestorePre-authorized3 min
Controls
Roles
Glossary
Line 13

Terminate a process and quarantine its artifact

Pre-authorized

Kill a running process on an endpoint or server and move its binary or script into quarantine.

Reversibilityreversible
Exposureno service effect
Confidence floormoderate confidence
Latency in garrison2 minimmediate to decide, 2 min to land
Scope bound

Any endpoint or server, excluding operational technology and anything on the recovery path.

Duration and renewal

Instantaneous. Not applicable. Recurrence means the persistence mechanism was not addressed, which is a hunt task rather than a repeat fire.

Where this authority does not apply
  • The process is a mission batch job inside its processing window and terminating it loses the batch.
  • The artifact is the only copy of evidence and no acquisition has been taken — the evidence exclusion applies.

Plus the 8 standing exclusions, which bind every line.

Record owed, within 60 min
  • The artifact hash and where it was quarantined to
  • Whether the process returned, which is the only interesting part

Plus the 6 standing fields.

Authority by phase
0 ShapePre-authorized2 min
I DeterPre-authorized2 min
II Seize InitiativePre-authorized2 min
III DominatePre-authorized2 min
IV StabilizePre-authorized2 min
V Enable / RestorePre-authorized2 min
Controls
Terrain
Roles
Cycle step

T3 NetworksThe corridors

Line 14

Block named external infrastructure

Pre-authorized

Block an external address, domain, or narrow prefix at the perimeter and in egress policy.

Reversibilityreversible
Exposureno service effect
Confidence floormoderate confidence
Latency in garrison5 minimmediate to decide, 5 min to land
Scope bound

Individual addresses, fully-qualified domains, and prefixes no larger than a /24. Autonomous-system-wide or provider-wide blocks are a different line.

Duration and renewal

30 days, then reviewed. Blocks are converted to standing policy at the cycle assessment or dropped. A block list nobody prunes becomes an outage generator with a six-month fuse.

Where this authority does not apply
  • The address belongs to a cloud or content-delivery provider whose address space is shared with mission services.
  • The domain is a partner or supplier endpoint carrying a live integration.

Plus the 8 standing exclusions, which bind every line.

Record owed, within 4 h
  • The indicator source and its confidence
  • Hits against the block in the following 24 hours, which is the evidence the fire was worth taking

Plus the 6 standing fields.

Authority by phase
0 ShapePre-authorized5 min
I DeterPre-authorized5 min
II Seize InitiativePre-authorized5 min
III DominatePre-authorized5 min
IV StabilizePre-authorized5 min
V Enable / RestorePre-authorized5 min
Controls
Roles
Line 15

Block a source range carrying public traffic

CISO

Block an external source range — a provider, a geography, an autonomous system — from reaching a public-facing mission service.

Reversibilityreversible
Exposurepublic service degraded
Confidence floorhigh confidence
Latency in garrison4 h 10 min4 h to decide, 10 min to land
Scope bound

One service, one range, with the legitimate population inside the range estimated before firing rather than after.

Duration and renewal

4 hours. CISO renews with the mission owner consulted. Every renewal restates the estimate of legitimate users denied.

Where this authority does not apply
  • The service is on the statutory availability register inside its window.
  • No estimate of the legitimate population inside the range is available — firing blind on a public service is not a fast decision, it is an unmeasured one.

Plus the 8 standing exclusions, which bind every line.

Record owed, within 2 h
  • Legitimate sessions denied, estimated before and measured after
  • Contact-center volume attributable to the block
  • The mission owner consulted, and their position

Plus the 6 standing fields.

Why the line sits here

Worked through below — this is the case where the reversibility test and the exposure test disagree.

Authority by phase
0 ShapeCISO4 h 10 min
I DeterCISO4 h 10 min
II Seize InitiativeCISO55 min
III DominateSOC lead15 min
IV StabilizeAuthorizing Official2 h 10 min
V Enable / RestoreCISO4 h 10 min

Worked through in Blocking a range that carries legitimate public traffic.

Controls
Roles
Line 16

Isolate a network segment

CISO

Sever a network segment or trust zone from the rest of the estate, leaving only the response path reachable.

Reversibilitycostly to reverse
Exposureinternal users feel it
Confidence floorhigh confidence
Latency in garrison4 h 25 min4 h to decide, 25 min to land
Scope bound

One declared trust zone, from the zone definitions on the terrain overlay. Never an undeclared boundary invented during the incident.

Duration and renewal

4 hours. CISO in garrison; SOC lead once the isolation is standing and the segment’s owners are on the bridge.

Where this authority does not apply
  • The segment carries a service on the statutory availability register inside its window.
  • The segment contains the recovery zone or any part of the rebuild path.
  • The isolation would strand the operational technology estate from its supervisory systems.

Plus the 8 standing exclusions, which bind every line.

Record owed, within 2 h
  • The zone as declared on the overlay, and any element found inside it that the overlay did not show
  • Services interrupted, and the deadline register consulted before firing

Plus the 6 standing fields.

Why the line sits here

Worked through below. The short version: segment isolation is the most effective containment action in the catalog and the one most likely to hit a deadline the SOC has never heard of.

Authority by phase
0 ShapeCISO4 h 25 min
I DeterCISO4 h 25 min
II Seize InitiativeCISO70 min
III DominatePre-authorized25 min
IV StabilizeAuthorizing Official2 h 25 min
V Enable / RestoreCISO4 h 25 min

Worked through in Isolating a segment that carries a filing deadline.

Roles
Line 17

Throttle the public data API

SOC lead

Apply or tighten rate limits on the public bulk-data or open API surface.

Reversibilityreversible
Exposurepublic service degraded
Confidence floormoderate confidence
Latency in garrison30 min20 min to decide, 10 min to land
Scope bound

The public API surface, down to a documented floor rate that keeps published service commitments satisfiable.

Duration and renewal

8 hours. SOC lead renews; a throttle standing past 48 hours goes to the mission owner as a capacity conversation.

Where this authority does not apply
  • The proposed rate is below the published floor — that is a degradation of a public service and a different line.
  • A statutory bulk-delivery obligation falls inside the throttle window.

Plus the 8 standing exclusions, which bind every line.

Record owed, within 4 h
  • Rate before and after, and the published floor
  • Consumers affected, by API key

Plus the 6 standing fields.

Why the line sits here

Throttling is delay rather than denial, which is what keeps it low on the schedule despite a public effect. The documented floor is what makes that true; without one, "throttle" is a euphemism for an outage the SOC can perform unilaterally.

Authority by phase
0 ShapeSOC lead30 min
I DeterSOC lead30 min
II Seize InitiativeSOC lead15 min
III DominatePre-authorized10 min
IV StabilizeAuthorizing Official2 h 10 min
V Enable / RestoreSOC lead30 min

Worked through in Blocking a range that carries legitimate public traffic.

Controls
Roles
Glossary
Line 18

Sinkhole a domain internally

Pre-authorized

Redirect internal resolution of a domain to a controlled sinkhole and record every client that asks for it.

Reversibilityreversible
Exposureno service effect
Confidence floormoderate confidence
Latency in garrison5 minimmediate to decide, 5 min to land
Scope bound

Any external domain not on the partner or supplier integration list.

Duration and renewal

30 days. Reviewed with the block list at the cycle assessment.

Where this authority does not apply
  • The domain is a supplier or partner integration endpoint.
  • The domain resolves an authentication or certificate-validation service.

Plus the 8 standing exclusions, which bind every line.

Record owed, within 4 h
  • Clients observed at the sinkhole, which is usually more valuable than the block itself

Plus the 6 standing fields.

Why the line sits here

The cheapest intelligence-producing fire on the schedule: it contains and it collects at once, and the collection is often what identifies the rest of the footprint. Fires that produce intelligence should be biased toward pre-authorization for that reason alone.

Authority by phase
0 ShapePre-authorized5 min
I DeterPre-authorized5 min
II Seize InitiativePre-authorized5 min
III DominatePre-authorized5 min
IV StabilizePre-authorized5 min
V Enable / RestorePre-authorized5 min
Controls
Roles
Cycle step
Glossary

T4 Applications and WorkloadsThe urban terrain

Line 12

Isolate a production workload

SOC lead

Remove a production server, container workload, or virtual machine from service and cut its network reachability.

Reversibilitycostly to reverse
Exposureinternal users feel it
Confidence floorhigh confidence
Latency in garrison30 min20 min to decide, 10 min to land
Scope bound

One workload, where the terrain overlay shows at least one healthy peer carrying the same service.

Duration and renewal

6 hours. Renewed by the SOC lead in a contact phase, by the CISO in garrison.

Where this authority does not apply
  • The overlay shows no healthy peer — the last-instance rule.
  • The workload holds state that is not replicated and would be lost rather than paused.
  • The workload is part of the recovery zone or the rebuild path.

Plus the 8 standing exclusions, which bind every line.

Record owed, within 2 h
  • The peer that absorbed the load, and whether it did so within its own capacity
  • Mission impact observed, from the service owner rather than from the SOC

Plus the 6 standing fields.

Why the line sits here

Pre-authorized from Phase II because in contact the alternative to isolating a workload is leaving an adversary a foothold with a mission workload’s network position, which is worse than the outage risk the SOC lead check exists to prevent. In garrison, where there is time, the check is worth twenty minutes.

Authority by phase
0 ShapeSOC lead30 min
I DeterSOC lead30 min
II Seize InitiativePre-authorized10 min
III DominatePre-authorized10 min
IV StabilizeAuthorizing Official2 h 10 min
V Enable / RestoreSOC lead30 min
Roles
Line 19

Disable a function of a public service application

SOC lead

Turn off a specific capability inside a public-facing application — bulk export, document upload, a payment path, an account-recovery flow — leaving the rest of the service up.

Reversibilityreversible
Exposurepublic service degraded
Confidence floorhigh confidence
Latency in garrison50 min20 min to decide, 30 min to land
Scope bound

One named function, on one service, where a documented alternative path exists for the public.

Duration and renewal

8 hours. SOC lead in a contact phase; CISO in garrison. The mission owner is notified at the point of firing, not at renewal.

Where this authority does not apply
  • The function is the only way to satisfy a statutory obligation inside its window.
  • No alternative path exists and the function is the service in practice — disabling filing on a filing system is a degradation, not a function toggle.

Plus the 8 standing exclusions, which bind every line.

Record owed, within 2 h
  • The alternative path offered to the public, and where it was published
  • Transactions blocked during the window, from the application rather than from the SOC

Plus the 6 standing fields.

Why the line sits here

This line exists to keep the previous one — full degradation of a public service — rare. Most incidents that appear to require taking a service down actually require taking one function of it down, and a schedule with no middle rung forces the operator to choose between doing nothing and calling the Authorizing Official.

Authority by phase
0 ShapeSOC lead50 min
I DeterSOC lead50 min
II Seize InitiativeSOC lead35 min
III DominatePre-authorized30 min
IV StabilizeAuthorizing Official2 h 30 min
V Enable / RestoreSOC lead50 min

Worked through in Isolating a segment that carries a filing deadline.

Controls
Roles
Line 20

Degrade or withdraw a public mission service

Authorizing Official

Take a public-facing mission service into read-only mode, into a static holding page, or offline entirely.

Reversibilitycostly to reverse
Exposuretouches a statutory deadline
Confidence floorhigh confidence
Latency in garrison16 h 45 min16 h to decide, 45 min to land
Scope bound

One named service, for a stated period, with the statutory register consulted and the affected deadline named in the decision.

Duration and renewal

As stated in the authorization, and no longer. Every extension is a fresh Authorizing Official decision with a fresh statement of the deadline position.

Where this authority does not apply
  • None that widen it. This line is at the Authorizing Official in every phase, including Phase III, and the schedule contains no mechanism to move it.

Plus the 8 standing exclusions, which bind every line.

Record owed, within 60 min
  • The authorization itself, with the risk accepted stated in the Authorizing Official’s own words
  • The statutory instrument, the deadline, and the position against it at the moment of the decision
  • Public notification: what was said, where, and when
  • Restoration, with the elapsed degradation measured against the recovery objective

Plus the 6 standing fields.

Why the line sits here

The line that defines the top of the schedule. Degrading a public mission service is the one action where the framework’s own intent — degrade gracefully, never fail open — and the statutory floor pull in opposite directions, and resolving that is exactly what an Authorizing Official is for. Nothing about a declared campaign phase changes who should make it.

Authority by phase
0 ShapeAuthorizing Official16 h 45 min
I DeterAuthorizing Official16 h 45 min
II Seize InitiativeAuthorizing Official2 h 45 min
III DominateAuthorizing Official2 h 45 min
IV StabilizeAuthorizing Official2 h 45 min
V Enable / RestoreAuthorizing Official16 h 45 min
Roles

T5 DataThe objective

Line 21

Kill an in-flight bulk export

Pre-authorized

Terminate a running bulk export, replication job, or large query against a sensitive data store, and revoke its token.

Reversibilityreversible
Exposureinternal users feel it
Confidence floormoderate confidence
Latency in garrison5 minimmediate to decide, 5 min to land
Scope bound

Any export against a store marked as holding sensitive mission records, controlled unclassified information, or personal data.

Duration and renewal

Instantaneous. Not applicable. A legitimate export is restarted by its owner; that is cheaper than the alternative by several orders of magnitude.

Where this authority does not apply
  • The export is a scheduled statutory delivery inside its window — the register is checked before the fire, not after.
  • The job is the recovery capability taking its own backup.

Plus the 8 standing exclusions, which bind every line.

Record owed, within 60 min
  • Rows or volume already transferred before termination
  • The job owner and whether the export was legitimate

Plus the 6 standing fields.

Why the line sits here

The asymmetry here is as steep as it gets: killing a legitimate export costs someone a restart, and failing to kill an illegitimate one costs the agency the records themselves. When the asymmetry is that steep the fire belongs at the widest authority, and the argument for a second pair of eyes is an argument for losing the data politely.

Authority by phase
0 ShapePre-authorized5 min
I DeterPre-authorized5 min
II Seize InitiativePre-authorized5 min
III DominatePre-authorized5 min
IV StabilizePre-authorized5 min
V Enable / RestorePre-authorized5 min
Controls
Roles
Line 22

Emplace decoys in the data terrain

SOC lead

Deploy decoy credentials, documents, hosts, or records into a data store or identity plane, instrumented to alert on any interaction.

Reversibilityreversible
Exposureno service effect
Confidence floormoderate confidence
Latency in garrison80 min20 min to decide, 60 min to land
Scope bound

Decoys drawn from the approved decoy set. Bespoke decoy content is authored outside the incident and reviewed before it enters the set.

Duration and renewal

Standing. Reviewed at the cycle assessment for coverage against the data terrain.

Where this authority does not apply
  • The decoy content is not from the approved set — improvised decoys have a way of containing real data.
  • The store is subject to a records-management obligation where an injected record becomes an official one.

Plus the 8 standing exclusions, which bind every line.

Record owed, within 24 h
  • Where the decoys were placed, so they can be removed and so they do not become an unexplained finding later

Plus the 6 standing fields.

Why the line sits here

A fire with essentially no false-positive budget and no service effect, which is why it widens as early as Phase I. The exclusion about records management is not hypothetical: a decoy document in a system of record is a decoy the agency now has to disclose.

Authority by phase
0 ShapeSOC lead80 min
I DeterPre-authorized60 min
II Seize InitiativePre-authorized60 min
III DominatePre-authorized60 min
IV StabilizePre-authorized60 min
V Enable / RestoreSOC lead80 min
Controls
Terrain
Roles
Glossary
Line 28

Restore a mission dataset over live data

Authorizing Official

Restore a dataset from the isolated recovery copy, overwriting the production copy at a stated recovery point.

Reversibilityirreversible in the incident
Exposuretouches a statutory deadline
Confidence floorhigh confidence
Latency in garrison24 h16 h to decide, 8 h to land
Scope bound

One dataset, to one recovery point, with the transactions between that point and now enumerated before the decision.

Duration and renewal

Permanent. Not applicable.

Where this authority does not apply
  • None that widen it. Restoration over live data destroys work the agency accepted from the public, and no phase makes that a SOC decision.

Plus the 8 standing exclusions, which bind every line.

Record owed, within 4 h
  • The recovery point chosen and the transaction window discarded, counted rather than estimated
  • The integrity verification against the independent record, before the restored data was returned to service
  • The statutory position for every deadline the dataset serves

Plus the 6 standing fields.

Why the line sits here

Irreversible and statutory at once — the two properties that put a fire at the top of the schedule and hold it there. Worth stating on a rules-of-engagement page because restoration is often assumed to be a recovery activity outside the ROE entirely, which is how it ends up being performed at 04:00 by whoever had the credentials.

Authority by phase
0 ShapeAuthorizing Official24 h
I DeterAuthorizing Official24 h
II Seize InitiativeAuthorizing Official10 h
III DominateAuthorizing Official10 h
IV StabilizeAuthorizing Official10 h
V Enable / RestoreAuthorizing Official24 h
Terrain
Roles

T7 WorkforceTerrain that is also the force

Line 26

Suspend all access for an individual under insider referral

SOC lead

Execute the single-action revocation for one individual — every system, every credential, physical access included — while they remain employed.

Reversibilitycostly to reverse
Exposureinternal users feel it
Confidence floorhigh confidence
Latency in garrison25 min20 min to decide, 5 min to land
Scope bound

One individual, through the single revocation path that WF-5 requires to exist.

Duration and renewal

Standing until the referral is resolved. Reviewed by the insider risk function on its own cadence, not by the SOC.

Where this authority does not apply
  • Counsel and the human-resources function have not been notified — this exclusion never lifts, in any phase, because the fire has employment consequences the schedule has no authority over.
  • The individual is the Authorizing Official or is in the continuity-of-operations succession line.

Plus the 8 standing exclusions, which bind every line.

Record owed, within 60 min
  • The referral reference and the notifications made to counsel and human resources
  • Elapsed time from decision to last access removed, measured against the stated revocation tempo

Plus the 6 standing fields.

Why the line sits here

The one line whose exclusion is a permanent gate rather than a phase-sensitive one. The technical action is trivial and fast; the consequence is an employment action, and no campaign phase gives a security program authority it does not otherwise have over a person’s job. Speed here comes from having the single revocation path built, not from widening the authority.

Authority by phase
0 ShapeSOC lead25 min
I DeterSOC lead25 min
II Seize InitiativeSOC lead10 min
III DominateSOC lead10 min
IV StabilizeAuthorizing Official2 h 5 min
V Enable / RestoreSOC lead25 min
Controls
Roles
Glossary

T8 FacilitiesThe physical boundary

Line 27

Revoke physical access to a facility zone

SOC lead

Withdraw badge access to a controlled zone — a data hall, a control room, a records store — for an individual or a group.

Reversibilityreversible
Exposureno service effect
Confidence floormoderate confidence
Latency in garrison40 min20 min to decide, 20 min to land
Scope bound

One zone, from the declared physical zone boundaries. Individuals or a named maintenance group, not a whole workforce category.

Duration and renewal

24 hours. Renewed with facilities, who own the zone.

Where this authority does not apply
  • The revocation would leave a facility with an environmental or life-safety dependency without anyone able to reach it.
  • The individual is emergency response or facilities staff on call for that zone.

Plus the 8 standing exclusions, which bind every line.

Record owed, within 4 h
  • The zone, the individuals affected, and the facilities contact notified

Plus the 6 standing fields.

Why the line sits here

Included because a schedule that stops at the network edge leaves the maintenance-access path — the one physical route into an estate that supplier engineers routinely hold — with no fire against it at all.

Authority by phase
0 ShapeSOC lead40 min
I DeterSOC lead40 min
II Seize InitiativeSOC lead25 min
III DominatePre-authorized20 min
IV StabilizePre-authorized20 min
V Enable / RestoreSOC lead40 min
Controls
Roles

T9 Supply ChainThe lines of communication

Line 23

Halt the build and release pipeline

SOC lead

Stop the CI/CD pipeline: no builds promoted, no artifacts signed, no deployments to production.

Reversibilitycostly to reverse
Exposureinternal users feel it
Confidence floormoderate confidence
Latency in garrison25 min20 min to decide, 5 min to land
Scope bound

The pipeline serving the affected product line. A halt across every product line is a CISO decision.

Duration and renewal

12 hours. SOC lead once, then CISO. A halt standing beyond 24 hours has release-schedule consequences that are not a SOC decision.

Where this authority does not apply
  • A release inside the halt window is the remedy for an active availability incident.
  • The pipeline is the deployment path for the response tooling itself.

Plus the 8 standing exclusions, which bind every line.

Record owed, within 2 h
  • Builds and deployments blocked, and the release commitments affected
  • The provenance check that resumed it: what was verified before the first build was allowed through

Plus the 6 standing fields.

Why the line sits here

Worked through below. The pipeline is a declared decisive point at the reference agency, and a decisive point that can only be defended with a twenty-minute approval is a decisive point defended at the adversary’s convenience.

Authority by phase
0 ShapeSOC lead25 min
I DeterSOC lead25 min
II Seize InitiativePre-authorized5 min
III DominatePre-authorized5 min
IV StabilizeAuthorizing Official2 h 5 min
V Enable / RestoreSOC lead25 min

Worked through in Halting the release pipeline mid-release.

Roles
Line 24

Revoke a supplier’s access mid-engagement

SOC lead

Withdraw a supplier’s brokered access to agency systems — accounts disabled, sessions killed, the brokered path closed — while their engagement is live.

Reversibilitycostly to reverse
Exposureinternal users feel it
Confidence floormoderate confidence
Latency in garrison30 min20 min to decide, 10 min to land
Scope bound

The supplier’s access, through the agency’s own identity plane. Not the supplier’s connectivity, their data, or their contract — those are the severance line.

Duration and renewal

24 hours. CISO, with the contracting officer’s representative informed. Beyond 72 hours it is a contractual matter.

Where this authority does not apply
  • The supplier holds the only operational knowledge of a system in an active availability incident.
  • The access is not brokered through the agency identity plane, in which case this is a request to the supplier rather than an action the agency can take.

Plus the 8 standing exclusions, which bind every line.

Record owed, within 2 h
  • The engagement, the contracting officer’s representative, and the notification made
  • Whether the access was in fact revocable in one action — if it was not, that is an LC-3 finding regardless of the incident’s outcome

Plus the 6 standing fields.

Why the line sits here

Worked through below. The framework’s answer turns on whether the access was brokered, which is a control question rather than an incident question.

Authority by phase
0 ShapeSOC lead30 min
I DeterSOC lead30 min
II Seize InitiativePre-authorized10 min
III DominatePre-authorized10 min
IV StabilizeAuthorizing Official2 h 10 min
V Enable / RestoreSOC lead30 min

Worked through in Blocking a supplier mid-engagement.

Controls
Roles
Line 25

Sever a supplier entirely

Authorizing Official

Cut every connection to a supplier: accounts, network paths, data feeds, managed-service access, and any automation they operate inside the estate.

Reversibilityirreversible in the incident
Exposureinternal users feel it
Confidence floorhigh confidence
Latency in garrison18 h16 h to decide, 2 h to land
Scope bound

One supplier, across every path recorded in the supplier terrain register.

Duration and renewal

Until reversed by decision — there is no expiry on this line. Not applicable. Restoration is a fresh decision with its own conditions.

Where this authority does not apply
  • The supplier operates a service on the statutory availability register and no continuity path has been demonstrated.
  • Severance has never been exercised for this supplier, in which case its blast radius is unknown and the exercise finding is the honest answer.

Plus the 8 standing exclusions, which bind every line.

Record owed, within 4 h
  • Every path severed, against the supplier terrain register, and any path found that the register did not show
  • Mission impact observed, measured against the impact predicted by the last severance exercise
  • Legal and contracting notified, with times

Plus the 6 standing fields.

Why the line sits here

Marked irreversible deliberately, and therefore never pre-authorized in any phase. Severance is technically undoable — the accounts can be re-enabled — but the relationship, the engagement, and frequently the contract are not, and a fire whose real cost lands somewhere the SOC cannot see is exactly the kind that should never carry standing authority.

Authority by phase
0 ShapeAuthorizing Official18 h
I DeterAuthorizing Official18 h
II Seize InitiativeAuthorizing Official4 h
III DominateCISO2 h 45 min
IV StabilizeAuthorizing Official4 h
V Enable / RestoreAuthorizing Official18 h

Worked through in Blocking a supplier mid-engagement, Halting the release pipeline mid-release.

Roles
Reach

What the Schedule Connects to, Computed from the Lines.

Nothing here is maintained by hand. Every figure is the number of distinct things the lines and cases cite, resolved against the shipped data — a line cannot cite something that does not exist, because the reference fails the build.

357 resolved cross-references reaching 90 distinct things across 7 kinds — every one checked against the shipped data at build time.

Elsewhere in the Apparatus

Where This Schedule Comes from and Where It Goes.