Six Roles, and Every Control Each One Touches.
A control with no accountable role is a wish. This section takes the RACI carried by all 78 controls and reads it the other way round — by role rather than by control — so that each of the six can see its whole footprint at once: what it answers for, what it does, what it produces, and what it depends on somebody else producing.
Few Enough That Every Control Has an Owner Nobody Has to Look Up.
These are functions, not job titles. A small agency may have one person holding three of them; a large one may have forty people inside a single role. What may not happen is a control whose accountable role is two of them.
Enforced across the whole catalog — 0 controls carry anything other than a single A. Two accountable roles means each can reasonably believe the other is handling it, which is indistinguishable from nobody handling it, right up until the assessment.
A role with no entry against a control has no role in it. Padding the chart with a defensive “I” against everything produces a RACI in which everyone is informed of everything, which informs nobody and hides the three or four places where being informed actually matters.
Platform and product owners carry 36 of the 78 controls as Responsible — more than any other role, and more than the SOC and the intelligence cell combined. That is a real fact about federal estates, not a drafting accident: obstacles are emplaced on somebody’s ground, and the people who hold the ground rarely report to the CISO.
The average role appears on 78 of the 78 controls in some capacity. Most of that is Consulted — the framework’s working assumption is that the person who knows whether a control is achievable is usually not the person accountable for it.
Each One, in Full.
Every role page carries its complete derived footprint — every control by assignment, every product it owns, every product it consumes — followed by what the role is, what it has to be good at, how it fails, and how it stands against the other five.
Authorizing Official / CISO
Intent, risk acceptance, and the scheme itself.
- 78 accountable
- 0 responsible
- 0 consulted
- 0 informed
Cyber Threat Intelligence cell
Frame, Map and Fuse. The intelligence requirements, the threat courses of action, and the confidence levels.
- 0 accountable
- 9 responsible
- 27 consulted
- 42 informed
SOC / Defensive Operations
Maneuver. Executes fires and emplaces obstacles inside the standing rules of engagement.
- 0 accountable
- 8 responsible
- 50 consulted
- 20 informed
Hunt team
Counterattack. Works the hypotheses that Fuse raises.
- 0 accountable
- 3 responsible
- 18 consulted
- 57 informed
Platform and product owners
Their own terrain. Obstacles get emplaced on their ground, so they site them.
- 0 accountable
- 36 responsible
- 20 consulted
- 22 informed
Governance / RMF / ISSO
Translating cycle outputs into FISMA and RMF artifacts, and owning the rules of engagement.
- 0 accountable
- 18 responsible
- 34 consulted
- 26 informed
Three Things the Matrix Says That the Prose Never Does.
A RACI is normally read down a column — “what am I on the hook for?”. Read across the rows instead and it starts describing the shape of the organization the framework assumes.
The Authorizing Official / CISO does no work in this framework and answers for almost all of it. That is the correct shape — the commander owns intent and risk, the staff owns production — and it is only safe where the accountable role reads what it signs. Where it does not, the RACI still passes inspection and nothing anywhere is actually being decided.
Cyber Threat Intelligence cell and SOC / Defensive Operations and Hunt team and Platform and product owners and Governance / RMF / ISSO hold no A at all. For the SOC that is deliberate: every fire it delivers is either pre-authorized in the rules of engagement or escalated, and a SOC holding its own accountability is a SOC that can authorize its own fires. The first time a containment action takes a statutory service offline, the question of who agreed to that needs an answer.
Five controls Responsible, and three of them exist to disprove something the program has claimed — that the routes are enumerated, that the decisive points are out of reach, and that the maneuvers do what the scheme says. A hunt team folded into the SOC keeps the headcount and loses the function.
All 78 controls, all 6 roles.
On a wide screen this is the grid an assessor expects. On a phone it becomes one block per control listing only the roles that have a part — the blanks carry no information, so nothing is lost by omitting them. Both renderings come from the same records.
| Control | AO | CTI | SOC | HUNT | PLAT | ISSO |
|---|---|---|---|---|---|---|
| TM-1Terrain Inventory and Overlay | Authorizing Official / CISO: Accountable | Cyber Threat Intelligence cell: Consulted | SOC / Defensive Operations: Consulted | Hunt team: Informed | Platform and product owners: Responsible | Governance / RMF / ISSO: Informed |
| TM-2Defensive Layer Classification | Authorizing Official / CISO: Accountable | Cyber Threat Intelligence cell: Consulted | SOC / Defensive Operations: Informed | Hunt team: Informed | Platform and product owners: Responsible | Governance / RMF / ISSO: Informed |
| TM-3Asset Weighting | Authorizing Official / CISO: Accountable | Cyber Threat Intelligence cell: Consulted | SOC / Defensive Operations: Informed | Hunt team: Informed | Platform and product owners: Responsible | Governance / RMF / ISSO: Consulted |
| TM-4Trust Zone Definition | Authorizing Official / CISO: Accountable | Cyber Threat Intelligence cell: Informed | SOC / Defensive Operations: Consulted | Hunt team: Informed | Platform and product owners: Responsible | Governance / RMF / ISSO: Informed |
| TM-5Connection and Denied-Path Register | Authorizing Official / CISO: Accountable | Cyber Threat Intelligence cell: Consulted | SOC / Defensive Operations: Consulted | Hunt team: Informed | Platform and product owners: Responsible | Governance / RMF / ISSO: Informed |
| TM-6Terrain Currency | Authorizing Official / CISO: Accountable | Cyber Threat Intelligence cell: Informed | SOC / Defensive Operations: Informed | Hunt team: Informed | Platform and product owners: Responsible | Governance / RMF / ISSO: Consulted |
| TM-7Terrain Ownership | Authorizing Official / CISO: Accountable | Cyber Threat Intelligence cell: Informed | SOC / Defensive Operations: Informed | Hunt team: Informed | Platform and product owners: Consulted | Governance / RMF / ISSO: Responsible |
| KT-1Decisive Point Identification | Authorizing Official / CISO: Accountable | Cyber Threat Intelligence cell: Responsible | SOC / Defensive Operations: Consulted | Hunt team: Informed | Platform and product owners: Consulted | Governance / RMF / ISSO: Informed |
| KT-2Decisive Point Protection Floor | Authorizing Official / CISO: Accountable | Cyber Threat Intelligence cell: Informed | SOC / Defensive Operations: Consulted | Hunt team: Informed | Platform and product owners: Responsible | Governance / RMF / ISSO: Consulted |
| KT-3Avenue of Approach Analysis | Authorizing Official / CISO: Accountable | Cyber Threat Intelligence cell: Responsible | SOC / Defensive Operations: Informed | Hunt team: Consulted | Platform and product owners: Consulted | Governance / RMF / ISSO: Informed |
| KT-4Adversary Reachability Assessment | Authorizing Official / CISO: Accountable | Cyber Threat Intelligence cell: Responsible | SOC / Defensive Operations: Consulted | Hunt team: Informed | Platform and product owners: Consulted | Governance / RMF / ISSO: Informed |
| KT-5Barrier Sufficiency | Authorizing Official / CISO: Accountable | Cyber Threat Intelligence cell: Consulted | SOC / Defensive Operations: Consulted | Hunt team: Informed | Platform and product owners: Responsible | Governance / RMF / ISSO: Informed |
| SM-1Maneuver Catalog Adoption | Authorizing Official / CISO: Accountable | Cyber Threat Intelligence cell: Consulted | SOC / Defensive Operations: Consulted | Hunt team: Informed | Platform and product owners: Informed | Governance / RMF / ISSO: Responsible |
| SM-2Maneuver Assignment | Authorizing Official / CISO: Accountable | Cyber Threat Intelligence cell: Informed | SOC / Defensive Operations: Consulted | Hunt team: Informed | Platform and product owners: Responsible | Governance / RMF / ISSO: Consulted |
| SM-3Implementation State Tracking | Authorizing Official / CISO: Accountable | Cyber Threat Intelligence cell: Informed | SOC / Defensive Operations: Consulted | Hunt team: Informed | Platform and product owners: Responsible | Governance / RMF / ISSO: Consulted |
| SM-4Main Effort Designation | Authorizing Official / CISO: Accountable | Cyber Threat Intelligence cell: Consulted | SOC / Defensive Operations: Consulted | Hunt team: Informed | Platform and product owners: Informed | Governance / RMF / ISSO: Consulted |
| SM-5Branches and Sequels | Authorizing Official / CISO: Accountable | Cyber Threat Intelligence cell: Responsible | SOC / Defensive Operations: Consulted | Hunt team: Consulted | Platform and product owners: Informed | Governance / RMF / ISSO: Informed |
| SM-6Maneuver Effectiveness Validation | Authorizing Official / CISO: Accountable | Cyber Threat Intelligence cell: Consulted | SOC / Defensive Operations: Consulted | Hunt team: Responsible | Platform and product owners: Informed | Governance / RMF / ISSO: Consulted |
| SM-7Deception Emplacement | Authorizing Official / CISO: Accountable | Cyber Threat Intelligence cell: Consulted | SOC / Defensive Operations: Responsible | Hunt team: Consulted | Platform and product owners: Informed | Governance / RMF / ISSO: Informed |
| TA-1Decision Loop Measurement | Authorizing Official / CISO: Accountable | Cyber Threat Intelligence cell: Consulted | SOC / Defensive Operations: Responsible | Hunt team: Consulted | Platform and product owners: Informed | Governance / RMF / ISSO: Informed |
| TA-2Adversary Dwell Estimation | Authorizing Official / CISO: Accountable | Cyber Threat Intelligence cell: Responsible | SOC / Defensive Operations: Informed | Hunt team: Consulted | Platform and product owners: Informed | Governance / RMF / ISSO: Informed |
| TA-3Temporal Advantage Threshold | Authorizing Official / CISO: Accountable | Cyber Threat Intelligence cell: Consulted | SOC / Defensive Operations: Consulted | Hunt team: Informed | Platform and product owners: Informed | Governance / RMF / ISSO: Responsible |
| TA-4Pre-authorized Response | Authorizing Official / CISO: Accountable | Cyber Threat Intelligence cell: Informed | SOC / Defensive Operations: Consulted | Hunt team: Informed | Platform and product owners: Informed | Governance / RMF / ISSO: Consulted |
| TA-5Tempo Degradation Trigger | Authorizing Official / CISO: Accountable | Cyber Threat Intelligence cell: Informed | SOC / Defensive Operations: Responsible | Hunt team: Informed | Platform and product owners: Consulted | Governance / RMF / ISSO: Consulted |
| CE-1Cycle Cadence | Authorizing Official / CISO: Accountable | Cyber Threat Intelligence cell: Responsible | SOC / Defensive Operations: Consulted | Hunt team: Informed | Platform and product owners: Informed | Governance / RMF / ISSO: Consulted |
| CE-2Priority Intelligence Requirements | Authorizing Official / CISO: Accountable | Cyber Threat Intelligence cell: Responsible | SOC / Defensive Operations: Consulted | Hunt team: Consulted | Platform and product owners: Informed | Governance / RMF / ISSO: Informed |
| CE-3Fusion and Confidence | Authorizing Official / CISO: Accountable | Cyber Threat Intelligence cell: Responsible | SOC / Defensive Operations: Informed | Hunt team: Consulted | Platform and product owners: Informed | Governance / RMF / ISSO: Informed |
| CE-4Coverage and Residual Risk Computation | Authorizing Official / CISO: Accountable | Cyber Threat Intelligence cell: Consulted | SOC / Defensive Operations: Informed | Hunt team: Informed | Platform and product owners: Consulted | Governance / RMF / ISSO: Responsible |
| CE-5Remediation Backlog Prioritization | Authorizing Official / CISO: Accountable | Cyber Threat Intelligence cell: Informed | SOC / Defensive Operations: Consulted | Hunt team: Informed | Platform and product owners: Consulted | Governance / RMF / ISSO: Responsible |
| CE-6Cycle Record and Trend | Authorizing Official / CISO: Accountable | Cyber Threat Intelligence cell: Consulted | SOC / Defensive Operations: Informed | Hunt team: Informed | Platform and product owners: Informed | Governance / RMF / ISSO: Responsible |
| CE-7Brief Generation and Distribution | Authorizing Official / CISO: Accountable | Cyber Threat Intelligence cell: Responsible | SOC / Defensive Operations: Consulted | Hunt team: Informed | Platform and product owners: Informed | Governance / RMF / ISSO: Consulted |
| CG-1Defensive Intent | Authorizing Official / CISO: Accountable | Cyber Threat Intelligence cell: Consulted | SOC / Defensive Operations: Informed | Hunt team: Informed | Platform and product owners: Informed | Governance / RMF / ISSO: Consulted |
| CG-2Phase Declaration | Authorizing Official / CISO: Accountable | Cyber Threat Intelligence cell: Consulted | SOC / Defensive Operations: Consulted | Hunt team: Informed | Platform and product owners: Informed | Governance / RMF / ISSO: Consulted |
| CG-3Rules of Engagement | Authorizing Official / CISO: Accountable | Cyber Threat Intelligence cell: Informed | SOC / Defensive Operations: Consulted | Hunt team: Informed | Platform and product owners: Consulted | Governance / RMF / ISSO: Responsible |
| CG-4Findings Disposition | Authorizing Official / CISO: Accountable | Cyber Threat Intelligence cell: Informed | SOC / Defensive Operations: Informed | Hunt team: Informed | Platform and product owners: Consulted | Governance / RMF / ISSO: Responsible |
| CG-5Control Inheritance Mapping | Authorizing Official / CISO: Accountable | Cyber Threat Intelligence cell: Consulted | SOC / Defensive Operations: Informed | Hunt team: Informed | Platform and product owners: Consulted | Governance / RMF / ISSO: Responsible |
| RC-1Recovery Objectives | Authorizing Official / CISO: Accountable | Cyber Threat Intelligence cell: Informed | SOC / Defensive Operations: Consulted | Hunt team: Informed | Platform and product owners: Responsible | Governance / RMF / ISSO: Consulted |
| RC-2Isolated Recovery Capability | Authorizing Official / CISO: Accountable | Cyber Threat Intelligence cell: Informed | SOC / Defensive Operations: Consulted | Hunt team: Consulted | Platform and product owners: Responsible | Governance / RMF / ISSO: Informed |
| RC-3Trusted Rebuild Path | Authorizing Official / CISO: Accountable | Cyber Threat Intelligence cell: Informed | SOC / Defensive Operations: Consulted | Hunt team: Informed | Platform and product owners: Responsible | Governance / RMF / ISSO: Consulted |
| RC-4Recovery Integrity Verification | Authorizing Official / CISO: Accountable | Cyber Threat Intelligence cell: Consulted | SOC / Defensive Operations: Informed | Hunt team: Consulted | Platform and product owners: Responsible | Governance / RMF / ISSO: Informed |
| RC-5Reconstitution Exercise | Authorizing Official / CISO: Accountable | Cyber Threat Intelligence cell: Informed | SOC / Defensive Operations: Responsible | Hunt team: Consulted | Platform and product owners: Consulted | Governance / RMF / ISSO: Consulted |
| FO-1Privacy Terrain Identification | Authorizing Official / CISO: Accountable | Cyber Threat Intelligence cell: Consulted | SOC / Defensive Operations: Informed | Hunt team: Informed | Platform and product owners: Consulted | Governance / RMF / ISSO: Responsible |
| FO-2Controlled Unclassified Information Handling | Authorizing Official / CISO: Accountable | Cyber Threat Intelligence cell: Informed | SOC / Defensive Operations: Consulted | Hunt team: Informed | Platform and product owners: Consulted | Governance / RMF / ISSO: Responsible |
| FO-3Tenancy and Inheritance Boundary | Authorizing Official / CISO: Accountable | Cyber Threat Intelligence cell: Informed | SOC / Defensive Operations: Consulted | Hunt team: Informed | Platform and product owners: Consulted | Governance / RMF / ISSO: Responsible |
| FO-4Operational Technology Terrain | Authorizing Official / CISO: Accountable | Cyber Threat Intelligence cell: Informed | SOC / Defensive Operations: Consulted | Hunt team: Informed | Platform and product owners: Responsible | Governance / RMF / ISSO: Consulted |
| FO-5Statutory Availability Floor | Authorizing Official / CISO: Accountable | Cyber Threat Intelligence cell: Informed | SOC / Defensive Operations: Consulted | Hunt team: Informed | Platform and product owners: Consulted | Governance / RMF / ISSO: Responsible |
| FO-6Supply Chain Obligation | Authorizing Official / CISO: Accountable | Cyber Threat Intelligence cell: Informed | SOC / Defensive Operations: Informed | Hunt team: Informed | Platform and product owners: Consulted | Governance / RMF / ISSO: Responsible |
| FO-7Obligation Profile Declaration | Authorizing Official / CISO: Accountable | Cyber Threat Intelligence cell: Informed | SOC / Defensive Operations: Informed | Hunt team: Informed | Platform and product owners: Consulted | Governance / RMF / ISSO: Responsible |
| WF-1Workforce Terrain Identification | Authorizing Official / CISO: Accountable | Cyber Threat Intelligence cell: Consulted | SOC / Defensive Operations: Informed | Hunt team: Informed | Platform and product owners: Responsible | Governance / RMF / ISSO: Consulted |
| WF-2Privileged Human Register | Authorizing Official / CISO: Accountable | Cyber Threat Intelligence cell: Informed | SOC / Defensive Operations: Consulted | Hunt team: Informed | Platform and product owners: Responsible | Governance / RMF / ISSO: Consulted |
| WF-3Role-Based Readiness | Authorizing Official / CISO: Accountable | Cyber Threat Intelligence cell: Consulted | SOC / Defensive Operations: Informed | Hunt team: Informed | Platform and product owners: Consulted | Governance / RMF / ISSO: Responsible |
| WF-4Insider Risk Position | Authorizing Official / CISO: Accountable | Cyber Threat Intelligence cell: Consulted | SOC / Defensive Operations: Informed | Hunt team: Consulted | Platform and product owners: Informed | Governance / RMF / ISSO: Responsible |
| WF-5Separation and Revocation Tempo | Authorizing Official / CISO: Accountable | Cyber Threat Intelligence cell: Informed | SOC / Defensive Operations: Consulted | Hunt team: Informed | Platform and product owners: Responsible | Governance / RMF / ISSO: Consulted |
| FC-1Facility Terrain Identification | Authorizing Official / CISO: Accountable | Cyber Threat Intelligence cell: Informed | SOC / Defensive Operations: Consulted | Hunt team: Informed | Platform and product owners: Responsible | Governance / RMF / ISSO: Consulted |
| FC-2Physical Zone Boundary | Authorizing Official / CISO: Accountable | Cyber Threat Intelligence cell: Informed | SOC / Defensive Operations: Consulted | Hunt team: Informed | Platform and product owners: Responsible | Governance / RMF / ISSO: Consulted |
| FC-3Maintenance Access Control | Authorizing Official / CISO: Accountable | Cyber Threat Intelligence cell: Informed | SOC / Defensive Operations: Consulted | Hunt team: Informed | Platform and product owners: Responsible | Governance / RMF / ISSO: Consulted |
| FC-4Environmental Continuity | Authorizing Official / CISO: Accountable | Cyber Threat Intelligence cell: Informed | SOC / Defensive Operations: Consulted | Hunt team: Informed | Platform and product owners: Responsible | Governance / RMF / ISSO: Consulted |
| LC-1Supplier Terrain Register | Authorizing Official / CISO: Accountable | Cyber Threat Intelligence cell: Informed | SOC / Defensive Operations: Consulted | Hunt team: Informed | Platform and product owners: Responsible | Governance / RMF / ISSO: Consulted |
| LC-2Component Provenance | Authorizing Official / CISO: Accountable | Cyber Threat Intelligence cell: Consulted | SOC / Defensive Operations: Informed | Hunt team: Informed | Platform and product owners: Responsible | Governance / RMF / ISSO: Consulted |
| LC-3Supplier Access Constraint | Authorizing Official / CISO: Accountable | Cyber Threat Intelligence cell: Informed | SOC / Defensive Operations: Consulted | Hunt team: Informed | Platform and product owners: Responsible | Governance / RMF / ISSO: Consulted |
| LC-4Update Integrity and Staging | Authorizing Official / CISO: Accountable | Cyber Threat Intelligence cell: Consulted | SOC / Defensive Operations: Consulted | Hunt team: Informed | Platform and product owners: Responsible | Governance / RMF / ISSO: Informed |
| LC-5Supplier Severance Capability | Authorizing Official / CISO: Accountable | Cyber Threat Intelligence cell: Informed | SOC / Defensive Operations: Consulted | Hunt team: Informed | Platform and product owners: Responsible | Governance / RMF / ISSO: Consulted |
| ID-1Identity Plane Definition | Authorizing Official / CISO: Accountable | Cyber Threat Intelligence cell: Consulted | SOC / Defensive Operations: Consulted | Hunt team: Informed | Platform and product owners: Responsible | Governance / RMF / ISSO: Informed |
| ID-2Credential Strength and Binding | Authorizing Official / CISO: Accountable | Cyber Threat Intelligence cell: Informed | SOC / Defensive Operations: Consulted | Hunt team: Informed | Platform and product owners: Responsible | Governance / RMF / ISSO: Consulted |
| ID-3Authentication Assurance | Authorizing Official / CISO: Accountable | Cyber Threat Intelligence cell: Informed | SOC / Defensive Operations: Consulted | Hunt team: Consulted | Platform and product owners: Responsible | Governance / RMF / ISSO: Informed |
| ID-4Identity Assertion Protection | Authorizing Official / CISO: Accountable | Cyber Threat Intelligence cell: Informed | SOC / Defensive Operations: Consulted | Hunt team: Consulted | Platform and product owners: Responsible | Governance / RMF / ISSO: Informed |
| ID-5Authorization Decision Integrity | Authorizing Official / CISO: Accountable | Cyber Threat Intelligence cell: Informed | SOC / Defensive Operations: Consulted | Hunt team: Informed | Platform and product owners: Responsible | Governance / RMF / ISSO: Consulted |
| EN-1Event Declaration and Triage | Authorizing Official / CISO: Accountable | Cyber Threat Intelligence cell: Consulted | SOC / Defensive Operations: Responsible | Hunt team: Consulted | Platform and product owners: Informed | Governance / RMF / ISSO: Informed |
| EN-2Engagement Reconstruction | Authorizing Official / CISO: Accountable | Cyber Threat Intelligence cell: Consulted | SOC / Defensive Operations: Consulted | Hunt team: Responsible | Platform and product owners: Informed | Governance / RMF / ISSO: Informed |
| EN-3Evidence Preservation | Authorizing Official / CISO: Accountable | Cyber Threat Intelligence cell: Informed | SOC / Defensive Operations: Responsible | Hunt team: Consulted | Platform and product owners: Informed | Governance / RMF / ISSO: Consulted |
| EN-4Escalation and Engagement Authority | Authorizing Official / CISO: Accountable | Cyber Threat Intelligence cell: Informed | SOC / Defensive Operations: Responsible | Hunt team: Informed | Platform and product owners: Informed | Governance / RMF / ISSO: Consulted |
| EN-5Eradication and Transition to Recovery | Authorizing Official / CISO: Accountable | Cyber Threat Intelligence cell: Informed | SOC / Defensive Operations: Consulted | Hunt team: Responsible | Platform and product owners: Consulted | Governance / RMF / ISSO: Informed |
| EN-6Engagement Communication | Authorizing Official / CISO: Accountable | Cyber Threat Intelligence cell: Consulted | SOC / Defensive Operations: Consulted | Hunt team: Informed | Platform and product owners: Informed | Governance / RMF / ISSO: Responsible |
| DV-1Device Terrain Identification | Authorizing Official / CISO: Accountable | Cyber Threat Intelligence cell: Informed | SOC / Defensive Operations: Consulted | Hunt team: Informed | Platform and product owners: Responsible | Governance / RMF / ISSO: Consulted |
| DV-2Device Posture as an Access Precondition | Authorizing Official / CISO: Accountable | Cyber Threat Intelligence cell: Informed | SOC / Defensive Operations: Consulted | Hunt team: Consulted | Platform and product owners: Responsible | Governance / RMF / ISSO: Informed |
| DV-3Endpoint Sensor Coverage and Liveness | Authorizing Official / CISO: Accountable | Cyber Threat Intelligence cell: Informed | SOC / Defensive Operations: Responsible | Hunt team: Consulted | Platform and product owners: Consulted | Governance / RMF / ISSO: Informed |
| DV-4Execution Control | Authorizing Official / CISO: Accountable | Cyber Threat Intelligence cell: Informed | SOC / Defensive Operations: Consulted | Hunt team: Consulted | Platform and product owners: Responsible | Governance / RMF / ISSO: Informed |
| DV-5Device Lifecycle and Sanitization | Authorizing Official / CISO: Accountable | Cyber Threat Intelligence cell: Informed | SOC / Defensive Operations: Consulted | Hunt team: Informed | Platform and product owners: Responsible | Governance / RMF / ISSO: Consulted |
AO Authorizing Official / CISOCTI Cyber Threat Intelligence cellSOC SOC / Defensive OperationsHUNT Hunt teamPLAT Platform and product ownersISSO Governance / RMF / ISSO
TM-1 Terrain Inventory and Overlay
- AccountableAuthorizing Official / CISO
- ConsultedCyber Threat Intelligence cell
- ConsultedSOC / Defensive Operations
- InformedHunt team
- ResponsiblePlatform and product owners
- InformedGovernance / RMF / ISSO
TM-2 Defensive Layer Classification
- AccountableAuthorizing Official / CISO
- ConsultedCyber Threat Intelligence cell
- InformedSOC / Defensive Operations
- InformedHunt team
- ResponsiblePlatform and product owners
- InformedGovernance / RMF / ISSO
TM-3 Asset Weighting
- AccountableAuthorizing Official / CISO
- ConsultedCyber Threat Intelligence cell
- InformedSOC / Defensive Operations
- InformedHunt team
- ResponsiblePlatform and product owners
- ConsultedGovernance / RMF / ISSO
TM-4 Trust Zone Definition
- AccountableAuthorizing Official / CISO
- InformedCyber Threat Intelligence cell
- ConsultedSOC / Defensive Operations
- InformedHunt team
- ResponsiblePlatform and product owners
- InformedGovernance / RMF / ISSO
TM-5 Connection and Denied-Path Register
- AccountableAuthorizing Official / CISO
- ConsultedCyber Threat Intelligence cell
- ConsultedSOC / Defensive Operations
- InformedHunt team
- ResponsiblePlatform and product owners
- InformedGovernance / RMF / ISSO
TM-6 Terrain Currency
- AccountableAuthorizing Official / CISO
- InformedCyber Threat Intelligence cell
- InformedSOC / Defensive Operations
- InformedHunt team
- ResponsiblePlatform and product owners
- ConsultedGovernance / RMF / ISSO
TM-7 Terrain Ownership
- AccountableAuthorizing Official / CISO
- InformedCyber Threat Intelligence cell
- InformedSOC / Defensive Operations
- InformedHunt team
- ConsultedPlatform and product owners
- ResponsibleGovernance / RMF / ISSO
KT-1 Decisive Point Identification
- AccountableAuthorizing Official / CISO
- ResponsibleCyber Threat Intelligence cell
- ConsultedSOC / Defensive Operations
- InformedHunt team
- ConsultedPlatform and product owners
- InformedGovernance / RMF / ISSO
KT-2 Decisive Point Protection Floor
- AccountableAuthorizing Official / CISO
- InformedCyber Threat Intelligence cell
- ConsultedSOC / Defensive Operations
- InformedHunt team
- ResponsiblePlatform and product owners
- ConsultedGovernance / RMF / ISSO
KT-3 Avenue of Approach Analysis
- AccountableAuthorizing Official / CISO
- ResponsibleCyber Threat Intelligence cell
- InformedSOC / Defensive Operations
- ConsultedHunt team
- ConsultedPlatform and product owners
- InformedGovernance / RMF / ISSO
KT-4 Adversary Reachability Assessment
- AccountableAuthorizing Official / CISO
- ResponsibleCyber Threat Intelligence cell
- ConsultedSOC / Defensive Operations
- InformedHunt team
- ConsultedPlatform and product owners
- InformedGovernance / RMF / ISSO
KT-5 Barrier Sufficiency
- AccountableAuthorizing Official / CISO
- ConsultedCyber Threat Intelligence cell
- ConsultedSOC / Defensive Operations
- InformedHunt team
- ResponsiblePlatform and product owners
- InformedGovernance / RMF / ISSO
SM-1 Maneuver Catalog Adoption
- AccountableAuthorizing Official / CISO
- ConsultedCyber Threat Intelligence cell
- ConsultedSOC / Defensive Operations
- InformedHunt team
- InformedPlatform and product owners
- ResponsibleGovernance / RMF / ISSO
SM-2 Maneuver Assignment
- AccountableAuthorizing Official / CISO
- InformedCyber Threat Intelligence cell
- ConsultedSOC / Defensive Operations
- InformedHunt team
- ResponsiblePlatform and product owners
- ConsultedGovernance / RMF / ISSO
SM-3 Implementation State Tracking
- AccountableAuthorizing Official / CISO
- InformedCyber Threat Intelligence cell
- ConsultedSOC / Defensive Operations
- InformedHunt team
- ResponsiblePlatform and product owners
- ConsultedGovernance / RMF / ISSO
SM-4 Main Effort Designation
- AccountableAuthorizing Official / CISO
- ConsultedCyber Threat Intelligence cell
- ConsultedSOC / Defensive Operations
- InformedHunt team
- InformedPlatform and product owners
- ConsultedGovernance / RMF / ISSO
SM-5 Branches and Sequels
- AccountableAuthorizing Official / CISO
- ResponsibleCyber Threat Intelligence cell
- ConsultedSOC / Defensive Operations
- ConsultedHunt team
- InformedPlatform and product owners
- InformedGovernance / RMF / ISSO
SM-6 Maneuver Effectiveness Validation
- AccountableAuthorizing Official / CISO
- ConsultedCyber Threat Intelligence cell
- ConsultedSOC / Defensive Operations
- ResponsibleHunt team
- InformedPlatform and product owners
- ConsultedGovernance / RMF / ISSO
SM-7 Deception Emplacement
- AccountableAuthorizing Official / CISO
- ConsultedCyber Threat Intelligence cell
- ResponsibleSOC / Defensive Operations
- ConsultedHunt team
- InformedPlatform and product owners
- InformedGovernance / RMF / ISSO
TA-1 Decision Loop Measurement
- AccountableAuthorizing Official / CISO
- ConsultedCyber Threat Intelligence cell
- ResponsibleSOC / Defensive Operations
- ConsultedHunt team
- InformedPlatform and product owners
- InformedGovernance / RMF / ISSO
TA-2 Adversary Dwell Estimation
- AccountableAuthorizing Official / CISO
- ResponsibleCyber Threat Intelligence cell
- InformedSOC / Defensive Operations
- ConsultedHunt team
- InformedPlatform and product owners
- InformedGovernance / RMF / ISSO
TA-3 Temporal Advantage Threshold
- AccountableAuthorizing Official / CISO
- ConsultedCyber Threat Intelligence cell
- ConsultedSOC / Defensive Operations
- InformedHunt team
- InformedPlatform and product owners
- ResponsibleGovernance / RMF / ISSO
TA-4 Pre-authorized Response
- AccountableAuthorizing Official / CISO
- InformedCyber Threat Intelligence cell
- ConsultedSOC / Defensive Operations
- InformedHunt team
- InformedPlatform and product owners
- ConsultedGovernance / RMF / ISSO
TA-5 Tempo Degradation Trigger
- AccountableAuthorizing Official / CISO
- InformedCyber Threat Intelligence cell
- ResponsibleSOC / Defensive Operations
- InformedHunt team
- ConsultedPlatform and product owners
- ConsultedGovernance / RMF / ISSO
CE-1 Cycle Cadence
- AccountableAuthorizing Official / CISO
- ResponsibleCyber Threat Intelligence cell
- ConsultedSOC / Defensive Operations
- InformedHunt team
- InformedPlatform and product owners
- ConsultedGovernance / RMF / ISSO
CE-2 Priority Intelligence Requirements
- AccountableAuthorizing Official / CISO
- ResponsibleCyber Threat Intelligence cell
- ConsultedSOC / Defensive Operations
- ConsultedHunt team
- InformedPlatform and product owners
- InformedGovernance / RMF / ISSO
CE-3 Fusion and Confidence
- AccountableAuthorizing Official / CISO
- ResponsibleCyber Threat Intelligence cell
- InformedSOC / Defensive Operations
- ConsultedHunt team
- InformedPlatform and product owners
- InformedGovernance / RMF / ISSO
CE-4 Coverage and Residual Risk Computation
- AccountableAuthorizing Official / CISO
- ConsultedCyber Threat Intelligence cell
- InformedSOC / Defensive Operations
- InformedHunt team
- ConsultedPlatform and product owners
- ResponsibleGovernance / RMF / ISSO
CE-5 Remediation Backlog Prioritization
- AccountableAuthorizing Official / CISO
- InformedCyber Threat Intelligence cell
- ConsultedSOC / Defensive Operations
- InformedHunt team
- ConsultedPlatform and product owners
- ResponsibleGovernance / RMF / ISSO
CE-6 Cycle Record and Trend
- AccountableAuthorizing Official / CISO
- ConsultedCyber Threat Intelligence cell
- InformedSOC / Defensive Operations
- InformedHunt team
- InformedPlatform and product owners
- ResponsibleGovernance / RMF / ISSO
CE-7 Brief Generation and Distribution
- AccountableAuthorizing Official / CISO
- ResponsibleCyber Threat Intelligence cell
- ConsultedSOC / Defensive Operations
- InformedHunt team
- InformedPlatform and product owners
- ConsultedGovernance / RMF / ISSO
CG-1 Defensive Intent
- AccountableAuthorizing Official / CISO
- ConsultedCyber Threat Intelligence cell
- InformedSOC / Defensive Operations
- InformedHunt team
- InformedPlatform and product owners
- ConsultedGovernance / RMF / ISSO
CG-2 Phase Declaration
- AccountableAuthorizing Official / CISO
- ConsultedCyber Threat Intelligence cell
- ConsultedSOC / Defensive Operations
- InformedHunt team
- InformedPlatform and product owners
- ConsultedGovernance / RMF / ISSO
CG-3 Rules of Engagement
- AccountableAuthorizing Official / CISO
- InformedCyber Threat Intelligence cell
- ConsultedSOC / Defensive Operations
- InformedHunt team
- ConsultedPlatform and product owners
- ResponsibleGovernance / RMF / ISSO
CG-4 Findings Disposition
- AccountableAuthorizing Official / CISO
- InformedCyber Threat Intelligence cell
- InformedSOC / Defensive Operations
- InformedHunt team
- ConsultedPlatform and product owners
- ResponsibleGovernance / RMF / ISSO
CG-5 Control Inheritance Mapping
- AccountableAuthorizing Official / CISO
- ConsultedCyber Threat Intelligence cell
- InformedSOC / Defensive Operations
- InformedHunt team
- ConsultedPlatform and product owners
- ResponsibleGovernance / RMF / ISSO
RC-1 Recovery Objectives
- AccountableAuthorizing Official / CISO
- InformedCyber Threat Intelligence cell
- ConsultedSOC / Defensive Operations
- InformedHunt team
- ResponsiblePlatform and product owners
- ConsultedGovernance / RMF / ISSO
RC-2 Isolated Recovery Capability
- AccountableAuthorizing Official / CISO
- InformedCyber Threat Intelligence cell
- ConsultedSOC / Defensive Operations
- ConsultedHunt team
- ResponsiblePlatform and product owners
- InformedGovernance / RMF / ISSO
RC-3 Trusted Rebuild Path
- AccountableAuthorizing Official / CISO
- InformedCyber Threat Intelligence cell
- ConsultedSOC / Defensive Operations
- InformedHunt team
- ResponsiblePlatform and product owners
- ConsultedGovernance / RMF / ISSO
RC-4 Recovery Integrity Verification
- AccountableAuthorizing Official / CISO
- ConsultedCyber Threat Intelligence cell
- InformedSOC / Defensive Operations
- ConsultedHunt team
- ResponsiblePlatform and product owners
- InformedGovernance / RMF / ISSO
RC-5 Reconstitution Exercise
- AccountableAuthorizing Official / CISO
- InformedCyber Threat Intelligence cell
- ResponsibleSOC / Defensive Operations
- ConsultedHunt team
- ConsultedPlatform and product owners
- ConsultedGovernance / RMF / ISSO
FO-1 Privacy Terrain Identification
- AccountableAuthorizing Official / CISO
- ConsultedCyber Threat Intelligence cell
- InformedSOC / Defensive Operations
- InformedHunt team
- ConsultedPlatform and product owners
- ResponsibleGovernance / RMF / ISSO
FO-2 Controlled Unclassified Information Handling
- AccountableAuthorizing Official / CISO
- InformedCyber Threat Intelligence cell
- ConsultedSOC / Defensive Operations
- InformedHunt team
- ConsultedPlatform and product owners
- ResponsibleGovernance / RMF / ISSO
FO-3 Tenancy and Inheritance Boundary
- AccountableAuthorizing Official / CISO
- InformedCyber Threat Intelligence cell
- ConsultedSOC / Defensive Operations
- InformedHunt team
- ConsultedPlatform and product owners
- ResponsibleGovernance / RMF / ISSO
FO-4 Operational Technology Terrain
- AccountableAuthorizing Official / CISO
- InformedCyber Threat Intelligence cell
- ConsultedSOC / Defensive Operations
- InformedHunt team
- ResponsiblePlatform and product owners
- ConsultedGovernance / RMF / ISSO
FO-5 Statutory Availability Floor
- AccountableAuthorizing Official / CISO
- InformedCyber Threat Intelligence cell
- ConsultedSOC / Defensive Operations
- InformedHunt team
- ConsultedPlatform and product owners
- ResponsibleGovernance / RMF / ISSO
FO-6 Supply Chain Obligation
- AccountableAuthorizing Official / CISO
- InformedCyber Threat Intelligence cell
- InformedSOC / Defensive Operations
- InformedHunt team
- ConsultedPlatform and product owners
- ResponsibleGovernance / RMF / ISSO
FO-7 Obligation Profile Declaration
- AccountableAuthorizing Official / CISO
- InformedCyber Threat Intelligence cell
- InformedSOC / Defensive Operations
- InformedHunt team
- ConsultedPlatform and product owners
- ResponsibleGovernance / RMF / ISSO
WF-1 Workforce Terrain Identification
- AccountableAuthorizing Official / CISO
- ConsultedCyber Threat Intelligence cell
- InformedSOC / Defensive Operations
- InformedHunt team
- ResponsiblePlatform and product owners
- ConsultedGovernance / RMF / ISSO
WF-2 Privileged Human Register
- AccountableAuthorizing Official / CISO
- InformedCyber Threat Intelligence cell
- ConsultedSOC / Defensive Operations
- InformedHunt team
- ResponsiblePlatform and product owners
- ConsultedGovernance / RMF / ISSO
WF-3 Role-Based Readiness
- AccountableAuthorizing Official / CISO
- ConsultedCyber Threat Intelligence cell
- InformedSOC / Defensive Operations
- InformedHunt team
- ConsultedPlatform and product owners
- ResponsibleGovernance / RMF / ISSO
WF-4 Insider Risk Position
- AccountableAuthorizing Official / CISO
- ConsultedCyber Threat Intelligence cell
- InformedSOC / Defensive Operations
- ConsultedHunt team
- InformedPlatform and product owners
- ResponsibleGovernance / RMF / ISSO
WF-5 Separation and Revocation Tempo
- AccountableAuthorizing Official / CISO
- InformedCyber Threat Intelligence cell
- ConsultedSOC / Defensive Operations
- InformedHunt team
- ResponsiblePlatform and product owners
- ConsultedGovernance / RMF / ISSO
FC-1 Facility Terrain Identification
- AccountableAuthorizing Official / CISO
- InformedCyber Threat Intelligence cell
- ConsultedSOC / Defensive Operations
- InformedHunt team
- ResponsiblePlatform and product owners
- ConsultedGovernance / RMF / ISSO
FC-2 Physical Zone Boundary
- AccountableAuthorizing Official / CISO
- InformedCyber Threat Intelligence cell
- ConsultedSOC / Defensive Operations
- InformedHunt team
- ResponsiblePlatform and product owners
- ConsultedGovernance / RMF / ISSO
FC-3 Maintenance Access Control
- AccountableAuthorizing Official / CISO
- InformedCyber Threat Intelligence cell
- ConsultedSOC / Defensive Operations
- InformedHunt team
- ResponsiblePlatform and product owners
- ConsultedGovernance / RMF / ISSO
FC-4 Environmental Continuity
- AccountableAuthorizing Official / CISO
- InformedCyber Threat Intelligence cell
- ConsultedSOC / Defensive Operations
- InformedHunt team
- ResponsiblePlatform and product owners
- ConsultedGovernance / RMF / ISSO
LC-1 Supplier Terrain Register
- AccountableAuthorizing Official / CISO
- InformedCyber Threat Intelligence cell
- ConsultedSOC / Defensive Operations
- InformedHunt team
- ResponsiblePlatform and product owners
- ConsultedGovernance / RMF / ISSO
LC-2 Component Provenance
- AccountableAuthorizing Official / CISO
- ConsultedCyber Threat Intelligence cell
- InformedSOC / Defensive Operations
- InformedHunt team
- ResponsiblePlatform and product owners
- ConsultedGovernance / RMF / ISSO
LC-3 Supplier Access Constraint
- AccountableAuthorizing Official / CISO
- InformedCyber Threat Intelligence cell
- ConsultedSOC / Defensive Operations
- InformedHunt team
- ResponsiblePlatform and product owners
- ConsultedGovernance / RMF / ISSO
LC-4 Update Integrity and Staging
- AccountableAuthorizing Official / CISO
- ConsultedCyber Threat Intelligence cell
- ConsultedSOC / Defensive Operations
- InformedHunt team
- ResponsiblePlatform and product owners
- InformedGovernance / RMF / ISSO
LC-5 Supplier Severance Capability
- AccountableAuthorizing Official / CISO
- InformedCyber Threat Intelligence cell
- ConsultedSOC / Defensive Operations
- InformedHunt team
- ResponsiblePlatform and product owners
- ConsultedGovernance / RMF / ISSO
ID-1 Identity Plane Definition
- AccountableAuthorizing Official / CISO
- ConsultedCyber Threat Intelligence cell
- ConsultedSOC / Defensive Operations
- InformedHunt team
- ResponsiblePlatform and product owners
- InformedGovernance / RMF / ISSO
ID-2 Credential Strength and Binding
- AccountableAuthorizing Official / CISO
- InformedCyber Threat Intelligence cell
- ConsultedSOC / Defensive Operations
- InformedHunt team
- ResponsiblePlatform and product owners
- ConsultedGovernance / RMF / ISSO
ID-3 Authentication Assurance
- AccountableAuthorizing Official / CISO
- InformedCyber Threat Intelligence cell
- ConsultedSOC / Defensive Operations
- ConsultedHunt team
- ResponsiblePlatform and product owners
- InformedGovernance / RMF / ISSO
ID-4 Identity Assertion Protection
- AccountableAuthorizing Official / CISO
- InformedCyber Threat Intelligence cell
- ConsultedSOC / Defensive Operations
- ConsultedHunt team
- ResponsiblePlatform and product owners
- InformedGovernance / RMF / ISSO
ID-5 Authorization Decision Integrity
- AccountableAuthorizing Official / CISO
- InformedCyber Threat Intelligence cell
- ConsultedSOC / Defensive Operations
- InformedHunt team
- ResponsiblePlatform and product owners
- ConsultedGovernance / RMF / ISSO
EN-1 Event Declaration and Triage
- AccountableAuthorizing Official / CISO
- ConsultedCyber Threat Intelligence cell
- ResponsibleSOC / Defensive Operations
- ConsultedHunt team
- InformedPlatform and product owners
- InformedGovernance / RMF / ISSO
EN-2 Engagement Reconstruction
- AccountableAuthorizing Official / CISO
- ConsultedCyber Threat Intelligence cell
- ConsultedSOC / Defensive Operations
- ResponsibleHunt team
- InformedPlatform and product owners
- InformedGovernance / RMF / ISSO
EN-3 Evidence Preservation
- AccountableAuthorizing Official / CISO
- InformedCyber Threat Intelligence cell
- ResponsibleSOC / Defensive Operations
- ConsultedHunt team
- InformedPlatform and product owners
- ConsultedGovernance / RMF / ISSO
EN-4 Escalation and Engagement Authority
- AccountableAuthorizing Official / CISO
- InformedCyber Threat Intelligence cell
- ResponsibleSOC / Defensive Operations
- InformedHunt team
- InformedPlatform and product owners
- ConsultedGovernance / RMF / ISSO
EN-5 Eradication and Transition to Recovery
- AccountableAuthorizing Official / CISO
- InformedCyber Threat Intelligence cell
- ConsultedSOC / Defensive Operations
- ResponsibleHunt team
- ConsultedPlatform and product owners
- InformedGovernance / RMF / ISSO
EN-6 Engagement Communication
- AccountableAuthorizing Official / CISO
- ConsultedCyber Threat Intelligence cell
- ConsultedSOC / Defensive Operations
- InformedHunt team
- InformedPlatform and product owners
- ResponsibleGovernance / RMF / ISSO
DV-1 Device Terrain Identification
- AccountableAuthorizing Official / CISO
- InformedCyber Threat Intelligence cell
- ConsultedSOC / Defensive Operations
- InformedHunt team
- ResponsiblePlatform and product owners
- ConsultedGovernance / RMF / ISSO
DV-2 Device Posture as an Access Precondition
- AccountableAuthorizing Official / CISO
- InformedCyber Threat Intelligence cell
- ConsultedSOC / Defensive Operations
- ConsultedHunt team
- ResponsiblePlatform and product owners
- InformedGovernance / RMF / ISSO
DV-3 Endpoint Sensor Coverage and Liveness
- AccountableAuthorizing Official / CISO
- InformedCyber Threat Intelligence cell
- ResponsibleSOC / Defensive Operations
- ConsultedHunt team
- ConsultedPlatform and product owners
- InformedGovernance / RMF / ISSO
DV-4 Execution Control
- AccountableAuthorizing Official / CISO
- InformedCyber Threat Intelligence cell
- ConsultedSOC / Defensive Operations
- ConsultedHunt team
- ResponsiblePlatform and product owners
- InformedGovernance / RMF / ISSO
DV-5 Device Lifecycle and Sanitization
- AccountableAuthorizing Official / CISO
- InformedCyber Threat Intelligence cell
- ConsultedSOC / Defensive Operations
- InformedHunt team
- ResponsiblePlatform and product owners
- ConsultedGovernance / RMF / ISSO