ASOM-Fedv6.1Open the explorer
Reference manual · roles

Six Roles, and Every Control Each One Touches.

A control with no accountable role is a wish. This section takes the RACI carried by all 78 controls and reads it the other way round — by role rather than by control — so that each of the six can see its whole footprint at once: what it answers for, what it does, what it produces, and what it depends on somebody else producing.

6RolesFunctions, not job titles
78ControlsEvery one carries a full assignment
0Controls with two accountable rolesShared accountability is the same as none
78Answered for by one roleAO is accountable for this many of 78
Why Six

Few Enough That Every Control Has an Owner Nobody Has to Look Up.

These are functions, not job titles. A small agency may have one person holding three of them; a large one may have forty people inside a single role. What may not happen is a control whose accountable role is two of them.

Exactly one accountable role per control

Enforced across the whole catalog — 0 controls carry anything other than a single A. Two accountable roles means each can reasonably believe the other is handling it, which is indistinguishable from nobody handling it, right up until the assessment.

Blank means no part, not courtesy

A role with no entry against a control has no role in it. Padding the chart with a defensive “I” against everything produces a RACI in which everyone is informed of everything, which informs nobody and hides the three or four places where being informed actually matters.

Responsibility is deliberately unbalanced

Platform and product owners carry 36 of the 78 controls as Responsible — more than any other role, and more than the SOC and the intelligence cell combined. That is a real fact about federal estates, not a drafting accident: obstacles are emplaced on somebody’s ground, and the people who hold the ground rarely report to the CISO.

Roles touch far more than they own

The average role appears on 78 of the 78 controls in some capacity. Most of that is Consulted — the framework’s working assumption is that the person who knows whether a control is achievable is usually not the person accountable for it.

The Six

Each One, in Full.

Every role page carries its complete derived footprint — every control by assignment, every product it owns, every product it consumes — followed by what the role is, what it has to be good at, how it fails, and how it stands against the other five.

Reading It Across

Three Things the Matrix Says That the Prose Never Does.

A RACI is normally read down a column — “what am I on the hook for?”. Read across the rows instead and it starts describing the shape of the organization the framework assumes.

Command is accountable for 78 controls and responsible for none

The Authorizing Official / CISO does no work in this framework and answers for almost all of it. That is the correct shape — the commander owns intent and risk, the staff owns production — and it is only safe where the accountable role reads what it signs. Where it does not, the RACI still passes inspection and nothing anywhere is actually being decided.

5 roles are accountable for nothing

Cyber Threat Intelligence cell and SOC / Defensive Operations and Hunt team and Platform and product owners and Governance / RMF / ISSO hold no A at all. For the SOC that is deliberate: every fire it delivers is either pre-authorized in the rules of engagement or escalated, and a SOC holding its own accountability is a SOC that can authorize its own fires. The first time a containment action takes a statutory service offline, the question of who agreed to that needs an answer.

The hunt team has the smallest footprint and the sharpest one

Five controls Responsible, and three of them exist to disprove something the program has claimed — that the routes are enumerated, that the decisive points are out of reach, and that the maneuvers do what the scheme says. A hunt team folded into the SOC keeps the headcount and loses the function.

The Full Matrix

All 78 controls, all 6 roles.

On a wide screen this is the grid an assessor expects. On a phone it becomes one block per control listing only the roles that have a part — the blanks carry no information, so nothing is lost by omitting them. Both renderings come from the same records.

Responsibility assignment for all 78 ASOM-Fed controls across 6 roles.
ControlAOCTISOCHUNTPLATISSO
TM-1Terrain Inventory and OverlayAuthorizing Official / CISO: AccountableCyber Threat Intelligence cell: ConsultedSOC / Defensive Operations: ConsultedHunt team: InformedPlatform and product owners: ResponsibleGovernance / RMF / ISSO: Informed
TM-2Defensive Layer ClassificationAuthorizing Official / CISO: AccountableCyber Threat Intelligence cell: ConsultedSOC / Defensive Operations: InformedHunt team: InformedPlatform and product owners: ResponsibleGovernance / RMF / ISSO: Informed
TM-3Asset WeightingAuthorizing Official / CISO: AccountableCyber Threat Intelligence cell: ConsultedSOC / Defensive Operations: InformedHunt team: InformedPlatform and product owners: ResponsibleGovernance / RMF / ISSO: Consulted
TM-4Trust Zone DefinitionAuthorizing Official / CISO: AccountableCyber Threat Intelligence cell: InformedSOC / Defensive Operations: ConsultedHunt team: InformedPlatform and product owners: ResponsibleGovernance / RMF / ISSO: Informed
TM-5Connection and Denied-Path RegisterAuthorizing Official / CISO: AccountableCyber Threat Intelligence cell: ConsultedSOC / Defensive Operations: ConsultedHunt team: InformedPlatform and product owners: ResponsibleGovernance / RMF / ISSO: Informed
TM-6Terrain CurrencyAuthorizing Official / CISO: AccountableCyber Threat Intelligence cell: InformedSOC / Defensive Operations: InformedHunt team: InformedPlatform and product owners: ResponsibleGovernance / RMF / ISSO: Consulted
TM-7Terrain OwnershipAuthorizing Official / CISO: AccountableCyber Threat Intelligence cell: InformedSOC / Defensive Operations: InformedHunt team: InformedPlatform and product owners: ConsultedGovernance / RMF / ISSO: Responsible
KT-1Decisive Point IdentificationAuthorizing Official / CISO: AccountableCyber Threat Intelligence cell: ResponsibleSOC / Defensive Operations: ConsultedHunt team: InformedPlatform and product owners: ConsultedGovernance / RMF / ISSO: Informed
KT-2Decisive Point Protection FloorAuthorizing Official / CISO: AccountableCyber Threat Intelligence cell: InformedSOC / Defensive Operations: ConsultedHunt team: InformedPlatform and product owners: ResponsibleGovernance / RMF / ISSO: Consulted
KT-3Avenue of Approach AnalysisAuthorizing Official / CISO: AccountableCyber Threat Intelligence cell: ResponsibleSOC / Defensive Operations: InformedHunt team: ConsultedPlatform and product owners: ConsultedGovernance / RMF / ISSO: Informed
KT-4Adversary Reachability AssessmentAuthorizing Official / CISO: AccountableCyber Threat Intelligence cell: ResponsibleSOC / Defensive Operations: ConsultedHunt team: InformedPlatform and product owners: ConsultedGovernance / RMF / ISSO: Informed
KT-5Barrier SufficiencyAuthorizing Official / CISO: AccountableCyber Threat Intelligence cell: ConsultedSOC / Defensive Operations: ConsultedHunt team: InformedPlatform and product owners: ResponsibleGovernance / RMF / ISSO: Informed
SM-1Maneuver Catalog AdoptionAuthorizing Official / CISO: AccountableCyber Threat Intelligence cell: ConsultedSOC / Defensive Operations: ConsultedHunt team: InformedPlatform and product owners: InformedGovernance / RMF / ISSO: Responsible
SM-2Maneuver AssignmentAuthorizing Official / CISO: AccountableCyber Threat Intelligence cell: InformedSOC / Defensive Operations: ConsultedHunt team: InformedPlatform and product owners: ResponsibleGovernance / RMF / ISSO: Consulted
SM-3Implementation State TrackingAuthorizing Official / CISO: AccountableCyber Threat Intelligence cell: InformedSOC / Defensive Operations: ConsultedHunt team: InformedPlatform and product owners: ResponsibleGovernance / RMF / ISSO: Consulted
SM-4Main Effort DesignationAuthorizing Official / CISO: AccountableCyber Threat Intelligence cell: ConsultedSOC / Defensive Operations: ConsultedHunt team: InformedPlatform and product owners: InformedGovernance / RMF / ISSO: Consulted
SM-5Branches and SequelsAuthorizing Official / CISO: AccountableCyber Threat Intelligence cell: ResponsibleSOC / Defensive Operations: ConsultedHunt team: ConsultedPlatform and product owners: InformedGovernance / RMF / ISSO: Informed
SM-6Maneuver Effectiveness ValidationAuthorizing Official / CISO: AccountableCyber Threat Intelligence cell: ConsultedSOC / Defensive Operations: ConsultedHunt team: ResponsiblePlatform and product owners: InformedGovernance / RMF / ISSO: Consulted
SM-7Deception EmplacementAuthorizing Official / CISO: AccountableCyber Threat Intelligence cell: ConsultedSOC / Defensive Operations: ResponsibleHunt team: ConsultedPlatform and product owners: InformedGovernance / RMF / ISSO: Informed
TA-1Decision Loop MeasurementAuthorizing Official / CISO: AccountableCyber Threat Intelligence cell: ConsultedSOC / Defensive Operations: ResponsibleHunt team: ConsultedPlatform and product owners: InformedGovernance / RMF / ISSO: Informed
TA-2Adversary Dwell EstimationAuthorizing Official / CISO: AccountableCyber Threat Intelligence cell: ResponsibleSOC / Defensive Operations: InformedHunt team: ConsultedPlatform and product owners: InformedGovernance / RMF / ISSO: Informed
TA-3Temporal Advantage ThresholdAuthorizing Official / CISO: AccountableCyber Threat Intelligence cell: ConsultedSOC / Defensive Operations: ConsultedHunt team: InformedPlatform and product owners: InformedGovernance / RMF / ISSO: Responsible
TA-4Pre-authorized ResponseAuthorizing Official / CISO: AccountableCyber Threat Intelligence cell: InformedSOC / Defensive Operations: ConsultedHunt team: InformedPlatform and product owners: InformedGovernance / RMF / ISSO: Consulted
TA-5Tempo Degradation TriggerAuthorizing Official / CISO: AccountableCyber Threat Intelligence cell: InformedSOC / Defensive Operations: ResponsibleHunt team: InformedPlatform and product owners: ConsultedGovernance / RMF / ISSO: Consulted
CE-1Cycle CadenceAuthorizing Official / CISO: AccountableCyber Threat Intelligence cell: ResponsibleSOC / Defensive Operations: ConsultedHunt team: InformedPlatform and product owners: InformedGovernance / RMF / ISSO: Consulted
CE-2Priority Intelligence RequirementsAuthorizing Official / CISO: AccountableCyber Threat Intelligence cell: ResponsibleSOC / Defensive Operations: ConsultedHunt team: ConsultedPlatform and product owners: InformedGovernance / RMF / ISSO: Informed
CE-3Fusion and ConfidenceAuthorizing Official / CISO: AccountableCyber Threat Intelligence cell: ResponsibleSOC / Defensive Operations: InformedHunt team: ConsultedPlatform and product owners: InformedGovernance / RMF / ISSO: Informed
CE-4Coverage and Residual Risk ComputationAuthorizing Official / CISO: AccountableCyber Threat Intelligence cell: ConsultedSOC / Defensive Operations: InformedHunt team: InformedPlatform and product owners: ConsultedGovernance / RMF / ISSO: Responsible
CE-5Remediation Backlog PrioritizationAuthorizing Official / CISO: AccountableCyber Threat Intelligence cell: InformedSOC / Defensive Operations: ConsultedHunt team: InformedPlatform and product owners: ConsultedGovernance / RMF / ISSO: Responsible
CE-6Cycle Record and TrendAuthorizing Official / CISO: AccountableCyber Threat Intelligence cell: ConsultedSOC / Defensive Operations: InformedHunt team: InformedPlatform and product owners: InformedGovernance / RMF / ISSO: Responsible
CE-7Brief Generation and DistributionAuthorizing Official / CISO: AccountableCyber Threat Intelligence cell: ResponsibleSOC / Defensive Operations: ConsultedHunt team: InformedPlatform and product owners: InformedGovernance / RMF / ISSO: Consulted
CG-1Defensive IntentAuthorizing Official / CISO: AccountableCyber Threat Intelligence cell: ConsultedSOC / Defensive Operations: InformedHunt team: InformedPlatform and product owners: InformedGovernance / RMF / ISSO: Consulted
CG-2Phase DeclarationAuthorizing Official / CISO: AccountableCyber Threat Intelligence cell: ConsultedSOC / Defensive Operations: ConsultedHunt team: InformedPlatform and product owners: InformedGovernance / RMF / ISSO: Consulted
CG-3Rules of EngagementAuthorizing Official / CISO: AccountableCyber Threat Intelligence cell: InformedSOC / Defensive Operations: ConsultedHunt team: InformedPlatform and product owners: ConsultedGovernance / RMF / ISSO: Responsible
CG-4Findings DispositionAuthorizing Official / CISO: AccountableCyber Threat Intelligence cell: InformedSOC / Defensive Operations: InformedHunt team: InformedPlatform and product owners: ConsultedGovernance / RMF / ISSO: Responsible
CG-5Control Inheritance MappingAuthorizing Official / CISO: AccountableCyber Threat Intelligence cell: ConsultedSOC / Defensive Operations: InformedHunt team: InformedPlatform and product owners: ConsultedGovernance / RMF / ISSO: Responsible
RC-1Recovery ObjectivesAuthorizing Official / CISO: AccountableCyber Threat Intelligence cell: InformedSOC / Defensive Operations: ConsultedHunt team: InformedPlatform and product owners: ResponsibleGovernance / RMF / ISSO: Consulted
RC-2Isolated Recovery CapabilityAuthorizing Official / CISO: AccountableCyber Threat Intelligence cell: InformedSOC / Defensive Operations: ConsultedHunt team: ConsultedPlatform and product owners: ResponsibleGovernance / RMF / ISSO: Informed
RC-3Trusted Rebuild PathAuthorizing Official / CISO: AccountableCyber Threat Intelligence cell: InformedSOC / Defensive Operations: ConsultedHunt team: InformedPlatform and product owners: ResponsibleGovernance / RMF / ISSO: Consulted
RC-4Recovery Integrity VerificationAuthorizing Official / CISO: AccountableCyber Threat Intelligence cell: ConsultedSOC / Defensive Operations: InformedHunt team: ConsultedPlatform and product owners: ResponsibleGovernance / RMF / ISSO: Informed
RC-5Reconstitution ExerciseAuthorizing Official / CISO: AccountableCyber Threat Intelligence cell: InformedSOC / Defensive Operations: ResponsibleHunt team: ConsultedPlatform and product owners: ConsultedGovernance / RMF / ISSO: Consulted
FO-1Privacy Terrain IdentificationAuthorizing Official / CISO: AccountableCyber Threat Intelligence cell: ConsultedSOC / Defensive Operations: InformedHunt team: InformedPlatform and product owners: ConsultedGovernance / RMF / ISSO: Responsible
FO-2Controlled Unclassified Information HandlingAuthorizing Official / CISO: AccountableCyber Threat Intelligence cell: InformedSOC / Defensive Operations: ConsultedHunt team: InformedPlatform and product owners: ConsultedGovernance / RMF / ISSO: Responsible
FO-3Tenancy and Inheritance BoundaryAuthorizing Official / CISO: AccountableCyber Threat Intelligence cell: InformedSOC / Defensive Operations: ConsultedHunt team: InformedPlatform and product owners: ConsultedGovernance / RMF / ISSO: Responsible
FO-4Operational Technology TerrainAuthorizing Official / CISO: AccountableCyber Threat Intelligence cell: InformedSOC / Defensive Operations: ConsultedHunt team: InformedPlatform and product owners: ResponsibleGovernance / RMF / ISSO: Consulted
FO-5Statutory Availability FloorAuthorizing Official / CISO: AccountableCyber Threat Intelligence cell: InformedSOC / Defensive Operations: ConsultedHunt team: InformedPlatform and product owners: ConsultedGovernance / RMF / ISSO: Responsible
FO-6Supply Chain ObligationAuthorizing Official / CISO: AccountableCyber Threat Intelligence cell: InformedSOC / Defensive Operations: InformedHunt team: InformedPlatform and product owners: ConsultedGovernance / RMF / ISSO: Responsible
FO-7Obligation Profile DeclarationAuthorizing Official / CISO: AccountableCyber Threat Intelligence cell: InformedSOC / Defensive Operations: InformedHunt team: InformedPlatform and product owners: ConsultedGovernance / RMF / ISSO: Responsible
WF-1Workforce Terrain IdentificationAuthorizing Official / CISO: AccountableCyber Threat Intelligence cell: ConsultedSOC / Defensive Operations: InformedHunt team: InformedPlatform and product owners: ResponsibleGovernance / RMF / ISSO: Consulted
WF-2Privileged Human RegisterAuthorizing Official / CISO: AccountableCyber Threat Intelligence cell: InformedSOC / Defensive Operations: ConsultedHunt team: InformedPlatform and product owners: ResponsibleGovernance / RMF / ISSO: Consulted
WF-3Role-Based ReadinessAuthorizing Official / CISO: AccountableCyber Threat Intelligence cell: ConsultedSOC / Defensive Operations: InformedHunt team: InformedPlatform and product owners: ConsultedGovernance / RMF / ISSO: Responsible
WF-4Insider Risk PositionAuthorizing Official / CISO: AccountableCyber Threat Intelligence cell: ConsultedSOC / Defensive Operations: InformedHunt team: ConsultedPlatform and product owners: InformedGovernance / RMF / ISSO: Responsible
WF-5Separation and Revocation TempoAuthorizing Official / CISO: AccountableCyber Threat Intelligence cell: InformedSOC / Defensive Operations: ConsultedHunt team: InformedPlatform and product owners: ResponsibleGovernance / RMF / ISSO: Consulted
FC-1Facility Terrain IdentificationAuthorizing Official / CISO: AccountableCyber Threat Intelligence cell: InformedSOC / Defensive Operations: ConsultedHunt team: InformedPlatform and product owners: ResponsibleGovernance / RMF / ISSO: Consulted
FC-2Physical Zone BoundaryAuthorizing Official / CISO: AccountableCyber Threat Intelligence cell: InformedSOC / Defensive Operations: ConsultedHunt team: InformedPlatform and product owners: ResponsibleGovernance / RMF / ISSO: Consulted
FC-3Maintenance Access ControlAuthorizing Official / CISO: AccountableCyber Threat Intelligence cell: InformedSOC / Defensive Operations: ConsultedHunt team: InformedPlatform and product owners: ResponsibleGovernance / RMF / ISSO: Consulted
FC-4Environmental ContinuityAuthorizing Official / CISO: AccountableCyber Threat Intelligence cell: InformedSOC / Defensive Operations: ConsultedHunt team: InformedPlatform and product owners: ResponsibleGovernance / RMF / ISSO: Consulted
LC-1Supplier Terrain RegisterAuthorizing Official / CISO: AccountableCyber Threat Intelligence cell: InformedSOC / Defensive Operations: ConsultedHunt team: InformedPlatform and product owners: ResponsibleGovernance / RMF / ISSO: Consulted
LC-2Component ProvenanceAuthorizing Official / CISO: AccountableCyber Threat Intelligence cell: ConsultedSOC / Defensive Operations: InformedHunt team: InformedPlatform and product owners: ResponsibleGovernance / RMF / ISSO: Consulted
LC-3Supplier Access ConstraintAuthorizing Official / CISO: AccountableCyber Threat Intelligence cell: InformedSOC / Defensive Operations: ConsultedHunt team: InformedPlatform and product owners: ResponsibleGovernance / RMF / ISSO: Consulted
LC-4Update Integrity and StagingAuthorizing Official / CISO: AccountableCyber Threat Intelligence cell: ConsultedSOC / Defensive Operations: ConsultedHunt team: InformedPlatform and product owners: ResponsibleGovernance / RMF / ISSO: Informed
LC-5Supplier Severance CapabilityAuthorizing Official / CISO: AccountableCyber Threat Intelligence cell: InformedSOC / Defensive Operations: ConsultedHunt team: InformedPlatform and product owners: ResponsibleGovernance / RMF / ISSO: Consulted
ID-1Identity Plane DefinitionAuthorizing Official / CISO: AccountableCyber Threat Intelligence cell: ConsultedSOC / Defensive Operations: ConsultedHunt team: InformedPlatform and product owners: ResponsibleGovernance / RMF / ISSO: Informed
ID-2Credential Strength and BindingAuthorizing Official / CISO: AccountableCyber Threat Intelligence cell: InformedSOC / Defensive Operations: ConsultedHunt team: InformedPlatform and product owners: ResponsibleGovernance / RMF / ISSO: Consulted
ID-3Authentication AssuranceAuthorizing Official / CISO: AccountableCyber Threat Intelligence cell: InformedSOC / Defensive Operations: ConsultedHunt team: ConsultedPlatform and product owners: ResponsibleGovernance / RMF / ISSO: Informed
ID-4Identity Assertion ProtectionAuthorizing Official / CISO: AccountableCyber Threat Intelligence cell: InformedSOC / Defensive Operations: ConsultedHunt team: ConsultedPlatform and product owners: ResponsibleGovernance / RMF / ISSO: Informed
ID-5Authorization Decision IntegrityAuthorizing Official / CISO: AccountableCyber Threat Intelligence cell: InformedSOC / Defensive Operations: ConsultedHunt team: InformedPlatform and product owners: ResponsibleGovernance / RMF / ISSO: Consulted
EN-1Event Declaration and TriageAuthorizing Official / CISO: AccountableCyber Threat Intelligence cell: ConsultedSOC / Defensive Operations: ResponsibleHunt team: ConsultedPlatform and product owners: InformedGovernance / RMF / ISSO: Informed
EN-2Engagement ReconstructionAuthorizing Official / CISO: AccountableCyber Threat Intelligence cell: ConsultedSOC / Defensive Operations: ConsultedHunt team: ResponsiblePlatform and product owners: InformedGovernance / RMF / ISSO: Informed
EN-3Evidence PreservationAuthorizing Official / CISO: AccountableCyber Threat Intelligence cell: InformedSOC / Defensive Operations: ResponsibleHunt team: ConsultedPlatform and product owners: InformedGovernance / RMF / ISSO: Consulted
EN-4Escalation and Engagement AuthorityAuthorizing Official / CISO: AccountableCyber Threat Intelligence cell: InformedSOC / Defensive Operations: ResponsibleHunt team: InformedPlatform and product owners: InformedGovernance / RMF / ISSO: Consulted
EN-5Eradication and Transition to RecoveryAuthorizing Official / CISO: AccountableCyber Threat Intelligence cell: InformedSOC / Defensive Operations: ConsultedHunt team: ResponsiblePlatform and product owners: ConsultedGovernance / RMF / ISSO: Informed
EN-6Engagement CommunicationAuthorizing Official / CISO: AccountableCyber Threat Intelligence cell: ConsultedSOC / Defensive Operations: ConsultedHunt team: InformedPlatform and product owners: InformedGovernance / RMF / ISSO: Responsible
DV-1Device Terrain IdentificationAuthorizing Official / CISO: AccountableCyber Threat Intelligence cell: InformedSOC / Defensive Operations: ConsultedHunt team: InformedPlatform and product owners: ResponsibleGovernance / RMF / ISSO: Consulted
DV-2Device Posture as an Access PreconditionAuthorizing Official / CISO: AccountableCyber Threat Intelligence cell: InformedSOC / Defensive Operations: ConsultedHunt team: ConsultedPlatform and product owners: ResponsibleGovernance / RMF / ISSO: Informed
DV-3Endpoint Sensor Coverage and LivenessAuthorizing Official / CISO: AccountableCyber Threat Intelligence cell: InformedSOC / Defensive Operations: ResponsibleHunt team: ConsultedPlatform and product owners: ConsultedGovernance / RMF / ISSO: Informed
DV-4Execution ControlAuthorizing Official / CISO: AccountableCyber Threat Intelligence cell: InformedSOC / Defensive Operations: ConsultedHunt team: ConsultedPlatform and product owners: ResponsibleGovernance / RMF / ISSO: Informed
DV-5Device Lifecycle and SanitizationAuthorizing Official / CISO: AccountableCyber Threat Intelligence cell: InformedSOC / Defensive Operations: ConsultedHunt team: InformedPlatform and product owners: ResponsibleGovernance / RMF / ISSO: Consulted

AO Authorizing Official / CISOCTI Cyber Threat Intelligence cellSOC SOC / Defensive OperationsHUNT Hunt teamPLAT Platform and product ownersISSO Governance / RMF / ISSO

TM-1 Terrain Inventory and Overlay

  • AccountableAuthorizing Official / CISO
  • ConsultedCyber Threat Intelligence cell
  • ConsultedSOC / Defensive Operations
  • InformedHunt team
  • ResponsiblePlatform and product owners
  • InformedGovernance / RMF / ISSO

TM-2 Defensive Layer Classification

  • AccountableAuthorizing Official / CISO
  • ConsultedCyber Threat Intelligence cell
  • InformedSOC / Defensive Operations
  • InformedHunt team
  • ResponsiblePlatform and product owners
  • InformedGovernance / RMF / ISSO

TM-3 Asset Weighting

  • AccountableAuthorizing Official / CISO
  • ConsultedCyber Threat Intelligence cell
  • InformedSOC / Defensive Operations
  • InformedHunt team
  • ResponsiblePlatform and product owners
  • ConsultedGovernance / RMF / ISSO

TM-4 Trust Zone Definition

  • AccountableAuthorizing Official / CISO
  • InformedCyber Threat Intelligence cell
  • ConsultedSOC / Defensive Operations
  • InformedHunt team
  • ResponsiblePlatform and product owners
  • InformedGovernance / RMF / ISSO

TM-5 Connection and Denied-Path Register

  • AccountableAuthorizing Official / CISO
  • ConsultedCyber Threat Intelligence cell
  • ConsultedSOC / Defensive Operations
  • InformedHunt team
  • ResponsiblePlatform and product owners
  • InformedGovernance / RMF / ISSO

TM-6 Terrain Currency

  • AccountableAuthorizing Official / CISO
  • InformedCyber Threat Intelligence cell
  • InformedSOC / Defensive Operations
  • InformedHunt team
  • ResponsiblePlatform and product owners
  • ConsultedGovernance / RMF / ISSO

TM-7 Terrain Ownership

  • AccountableAuthorizing Official / CISO
  • InformedCyber Threat Intelligence cell
  • InformedSOC / Defensive Operations
  • InformedHunt team
  • ConsultedPlatform and product owners
  • ResponsibleGovernance / RMF / ISSO

KT-1 Decisive Point Identification

  • AccountableAuthorizing Official / CISO
  • ResponsibleCyber Threat Intelligence cell
  • ConsultedSOC / Defensive Operations
  • InformedHunt team
  • ConsultedPlatform and product owners
  • InformedGovernance / RMF / ISSO

KT-2 Decisive Point Protection Floor

  • AccountableAuthorizing Official / CISO
  • InformedCyber Threat Intelligence cell
  • ConsultedSOC / Defensive Operations
  • InformedHunt team
  • ResponsiblePlatform and product owners
  • ConsultedGovernance / RMF / ISSO

KT-3 Avenue of Approach Analysis

  • AccountableAuthorizing Official / CISO
  • ResponsibleCyber Threat Intelligence cell
  • InformedSOC / Defensive Operations
  • ConsultedHunt team
  • ConsultedPlatform and product owners
  • InformedGovernance / RMF / ISSO

KT-4 Adversary Reachability Assessment

  • AccountableAuthorizing Official / CISO
  • ResponsibleCyber Threat Intelligence cell
  • ConsultedSOC / Defensive Operations
  • InformedHunt team
  • ConsultedPlatform and product owners
  • InformedGovernance / RMF / ISSO

KT-5 Barrier Sufficiency

  • AccountableAuthorizing Official / CISO
  • ConsultedCyber Threat Intelligence cell
  • ConsultedSOC / Defensive Operations
  • InformedHunt team
  • ResponsiblePlatform and product owners
  • InformedGovernance / RMF / ISSO

SM-1 Maneuver Catalog Adoption

  • AccountableAuthorizing Official / CISO
  • ConsultedCyber Threat Intelligence cell
  • ConsultedSOC / Defensive Operations
  • InformedHunt team
  • InformedPlatform and product owners
  • ResponsibleGovernance / RMF / ISSO

SM-2 Maneuver Assignment

  • AccountableAuthorizing Official / CISO
  • InformedCyber Threat Intelligence cell
  • ConsultedSOC / Defensive Operations
  • InformedHunt team
  • ResponsiblePlatform and product owners
  • ConsultedGovernance / RMF / ISSO

SM-3 Implementation State Tracking

  • AccountableAuthorizing Official / CISO
  • InformedCyber Threat Intelligence cell
  • ConsultedSOC / Defensive Operations
  • InformedHunt team
  • ResponsiblePlatform and product owners
  • ConsultedGovernance / RMF / ISSO

SM-4 Main Effort Designation

  • AccountableAuthorizing Official / CISO
  • ConsultedCyber Threat Intelligence cell
  • ConsultedSOC / Defensive Operations
  • InformedHunt team
  • InformedPlatform and product owners
  • ConsultedGovernance / RMF / ISSO

SM-5 Branches and Sequels

  • AccountableAuthorizing Official / CISO
  • ResponsibleCyber Threat Intelligence cell
  • ConsultedSOC / Defensive Operations
  • ConsultedHunt team
  • InformedPlatform and product owners
  • InformedGovernance / RMF / ISSO

SM-6 Maneuver Effectiveness Validation

  • AccountableAuthorizing Official / CISO
  • ConsultedCyber Threat Intelligence cell
  • ConsultedSOC / Defensive Operations
  • ResponsibleHunt team
  • InformedPlatform and product owners
  • ConsultedGovernance / RMF / ISSO

SM-7 Deception Emplacement

  • AccountableAuthorizing Official / CISO
  • ConsultedCyber Threat Intelligence cell
  • ResponsibleSOC / Defensive Operations
  • ConsultedHunt team
  • InformedPlatform and product owners
  • InformedGovernance / RMF / ISSO

TA-1 Decision Loop Measurement

  • AccountableAuthorizing Official / CISO
  • ConsultedCyber Threat Intelligence cell
  • ResponsibleSOC / Defensive Operations
  • ConsultedHunt team
  • InformedPlatform and product owners
  • InformedGovernance / RMF / ISSO

TA-2 Adversary Dwell Estimation

  • AccountableAuthorizing Official / CISO
  • ResponsibleCyber Threat Intelligence cell
  • InformedSOC / Defensive Operations
  • ConsultedHunt team
  • InformedPlatform and product owners
  • InformedGovernance / RMF / ISSO

TA-3 Temporal Advantage Threshold

  • AccountableAuthorizing Official / CISO
  • ConsultedCyber Threat Intelligence cell
  • ConsultedSOC / Defensive Operations
  • InformedHunt team
  • InformedPlatform and product owners
  • ResponsibleGovernance / RMF / ISSO

TA-4 Pre-authorized Response

  • AccountableAuthorizing Official / CISO
  • InformedCyber Threat Intelligence cell
  • ConsultedSOC / Defensive Operations
  • InformedHunt team
  • InformedPlatform and product owners
  • ConsultedGovernance / RMF / ISSO

TA-5 Tempo Degradation Trigger

  • AccountableAuthorizing Official / CISO
  • InformedCyber Threat Intelligence cell
  • ResponsibleSOC / Defensive Operations
  • InformedHunt team
  • ConsultedPlatform and product owners
  • ConsultedGovernance / RMF / ISSO

CE-1 Cycle Cadence

  • AccountableAuthorizing Official / CISO
  • ResponsibleCyber Threat Intelligence cell
  • ConsultedSOC / Defensive Operations
  • InformedHunt team
  • InformedPlatform and product owners
  • ConsultedGovernance / RMF / ISSO

CE-2 Priority Intelligence Requirements

  • AccountableAuthorizing Official / CISO
  • ResponsibleCyber Threat Intelligence cell
  • ConsultedSOC / Defensive Operations
  • ConsultedHunt team
  • InformedPlatform and product owners
  • InformedGovernance / RMF / ISSO

CE-3 Fusion and Confidence

  • AccountableAuthorizing Official / CISO
  • ResponsibleCyber Threat Intelligence cell
  • InformedSOC / Defensive Operations
  • ConsultedHunt team
  • InformedPlatform and product owners
  • InformedGovernance / RMF / ISSO

CE-4 Coverage and Residual Risk Computation

  • AccountableAuthorizing Official / CISO
  • ConsultedCyber Threat Intelligence cell
  • InformedSOC / Defensive Operations
  • InformedHunt team
  • ConsultedPlatform and product owners
  • ResponsibleGovernance / RMF / ISSO

CE-5 Remediation Backlog Prioritization

  • AccountableAuthorizing Official / CISO
  • InformedCyber Threat Intelligence cell
  • ConsultedSOC / Defensive Operations
  • InformedHunt team
  • ConsultedPlatform and product owners
  • ResponsibleGovernance / RMF / ISSO

CE-6 Cycle Record and Trend

  • AccountableAuthorizing Official / CISO
  • ConsultedCyber Threat Intelligence cell
  • InformedSOC / Defensive Operations
  • InformedHunt team
  • InformedPlatform and product owners
  • ResponsibleGovernance / RMF / ISSO

CE-7 Brief Generation and Distribution

  • AccountableAuthorizing Official / CISO
  • ResponsibleCyber Threat Intelligence cell
  • ConsultedSOC / Defensive Operations
  • InformedHunt team
  • InformedPlatform and product owners
  • ConsultedGovernance / RMF / ISSO

CG-1 Defensive Intent

  • AccountableAuthorizing Official / CISO
  • ConsultedCyber Threat Intelligence cell
  • InformedSOC / Defensive Operations
  • InformedHunt team
  • InformedPlatform and product owners
  • ConsultedGovernance / RMF / ISSO

CG-2 Phase Declaration

  • AccountableAuthorizing Official / CISO
  • ConsultedCyber Threat Intelligence cell
  • ConsultedSOC / Defensive Operations
  • InformedHunt team
  • InformedPlatform and product owners
  • ConsultedGovernance / RMF / ISSO

CG-3 Rules of Engagement

  • AccountableAuthorizing Official / CISO
  • InformedCyber Threat Intelligence cell
  • ConsultedSOC / Defensive Operations
  • InformedHunt team
  • ConsultedPlatform and product owners
  • ResponsibleGovernance / RMF / ISSO

CG-4 Findings Disposition

  • AccountableAuthorizing Official / CISO
  • InformedCyber Threat Intelligence cell
  • InformedSOC / Defensive Operations
  • InformedHunt team
  • ConsultedPlatform and product owners
  • ResponsibleGovernance / RMF / ISSO

CG-5 Control Inheritance Mapping

  • AccountableAuthorizing Official / CISO
  • ConsultedCyber Threat Intelligence cell
  • InformedSOC / Defensive Operations
  • InformedHunt team
  • ConsultedPlatform and product owners
  • ResponsibleGovernance / RMF / ISSO

RC-1 Recovery Objectives

  • AccountableAuthorizing Official / CISO
  • InformedCyber Threat Intelligence cell
  • ConsultedSOC / Defensive Operations
  • InformedHunt team
  • ResponsiblePlatform and product owners
  • ConsultedGovernance / RMF / ISSO

RC-2 Isolated Recovery Capability

  • AccountableAuthorizing Official / CISO
  • InformedCyber Threat Intelligence cell
  • ConsultedSOC / Defensive Operations
  • ConsultedHunt team
  • ResponsiblePlatform and product owners
  • InformedGovernance / RMF / ISSO

RC-3 Trusted Rebuild Path

  • AccountableAuthorizing Official / CISO
  • InformedCyber Threat Intelligence cell
  • ConsultedSOC / Defensive Operations
  • InformedHunt team
  • ResponsiblePlatform and product owners
  • ConsultedGovernance / RMF / ISSO

RC-4 Recovery Integrity Verification

  • AccountableAuthorizing Official / CISO
  • ConsultedCyber Threat Intelligence cell
  • InformedSOC / Defensive Operations
  • ConsultedHunt team
  • ResponsiblePlatform and product owners
  • InformedGovernance / RMF / ISSO

RC-5 Reconstitution Exercise

  • AccountableAuthorizing Official / CISO
  • InformedCyber Threat Intelligence cell
  • ResponsibleSOC / Defensive Operations
  • ConsultedHunt team
  • ConsultedPlatform and product owners
  • ConsultedGovernance / RMF / ISSO

FO-1 Privacy Terrain Identification

  • AccountableAuthorizing Official / CISO
  • ConsultedCyber Threat Intelligence cell
  • InformedSOC / Defensive Operations
  • InformedHunt team
  • ConsultedPlatform and product owners
  • ResponsibleGovernance / RMF / ISSO

FO-2 Controlled Unclassified Information Handling

  • AccountableAuthorizing Official / CISO
  • InformedCyber Threat Intelligence cell
  • ConsultedSOC / Defensive Operations
  • InformedHunt team
  • ConsultedPlatform and product owners
  • ResponsibleGovernance / RMF / ISSO

FO-3 Tenancy and Inheritance Boundary

  • AccountableAuthorizing Official / CISO
  • InformedCyber Threat Intelligence cell
  • ConsultedSOC / Defensive Operations
  • InformedHunt team
  • ConsultedPlatform and product owners
  • ResponsibleGovernance / RMF / ISSO

FO-4 Operational Technology Terrain

  • AccountableAuthorizing Official / CISO
  • InformedCyber Threat Intelligence cell
  • ConsultedSOC / Defensive Operations
  • InformedHunt team
  • ResponsiblePlatform and product owners
  • ConsultedGovernance / RMF / ISSO

FO-5 Statutory Availability Floor

  • AccountableAuthorizing Official / CISO
  • InformedCyber Threat Intelligence cell
  • ConsultedSOC / Defensive Operations
  • InformedHunt team
  • ConsultedPlatform and product owners
  • ResponsibleGovernance / RMF / ISSO

FO-6 Supply Chain Obligation

  • AccountableAuthorizing Official / CISO
  • InformedCyber Threat Intelligence cell
  • InformedSOC / Defensive Operations
  • InformedHunt team
  • ConsultedPlatform and product owners
  • ResponsibleGovernance / RMF / ISSO

FO-7 Obligation Profile Declaration

  • AccountableAuthorizing Official / CISO
  • InformedCyber Threat Intelligence cell
  • InformedSOC / Defensive Operations
  • InformedHunt team
  • ConsultedPlatform and product owners
  • ResponsibleGovernance / RMF / ISSO

WF-1 Workforce Terrain Identification

  • AccountableAuthorizing Official / CISO
  • ConsultedCyber Threat Intelligence cell
  • InformedSOC / Defensive Operations
  • InformedHunt team
  • ResponsiblePlatform and product owners
  • ConsultedGovernance / RMF / ISSO

WF-2 Privileged Human Register

  • AccountableAuthorizing Official / CISO
  • InformedCyber Threat Intelligence cell
  • ConsultedSOC / Defensive Operations
  • InformedHunt team
  • ResponsiblePlatform and product owners
  • ConsultedGovernance / RMF / ISSO

WF-3 Role-Based Readiness

  • AccountableAuthorizing Official / CISO
  • ConsultedCyber Threat Intelligence cell
  • InformedSOC / Defensive Operations
  • InformedHunt team
  • ConsultedPlatform and product owners
  • ResponsibleGovernance / RMF / ISSO

WF-4 Insider Risk Position

  • AccountableAuthorizing Official / CISO
  • ConsultedCyber Threat Intelligence cell
  • InformedSOC / Defensive Operations
  • ConsultedHunt team
  • InformedPlatform and product owners
  • ResponsibleGovernance / RMF / ISSO

WF-5 Separation and Revocation Tempo

  • AccountableAuthorizing Official / CISO
  • InformedCyber Threat Intelligence cell
  • ConsultedSOC / Defensive Operations
  • InformedHunt team
  • ResponsiblePlatform and product owners
  • ConsultedGovernance / RMF / ISSO

FC-1 Facility Terrain Identification

  • AccountableAuthorizing Official / CISO
  • InformedCyber Threat Intelligence cell
  • ConsultedSOC / Defensive Operations
  • InformedHunt team
  • ResponsiblePlatform and product owners
  • ConsultedGovernance / RMF / ISSO

FC-2 Physical Zone Boundary

  • AccountableAuthorizing Official / CISO
  • InformedCyber Threat Intelligence cell
  • ConsultedSOC / Defensive Operations
  • InformedHunt team
  • ResponsiblePlatform and product owners
  • ConsultedGovernance / RMF / ISSO

FC-3 Maintenance Access Control

  • AccountableAuthorizing Official / CISO
  • InformedCyber Threat Intelligence cell
  • ConsultedSOC / Defensive Operations
  • InformedHunt team
  • ResponsiblePlatform and product owners
  • ConsultedGovernance / RMF / ISSO

FC-4 Environmental Continuity

  • AccountableAuthorizing Official / CISO
  • InformedCyber Threat Intelligence cell
  • ConsultedSOC / Defensive Operations
  • InformedHunt team
  • ResponsiblePlatform and product owners
  • ConsultedGovernance / RMF / ISSO

LC-1 Supplier Terrain Register

  • AccountableAuthorizing Official / CISO
  • InformedCyber Threat Intelligence cell
  • ConsultedSOC / Defensive Operations
  • InformedHunt team
  • ResponsiblePlatform and product owners
  • ConsultedGovernance / RMF / ISSO

LC-2 Component Provenance

  • AccountableAuthorizing Official / CISO
  • ConsultedCyber Threat Intelligence cell
  • InformedSOC / Defensive Operations
  • InformedHunt team
  • ResponsiblePlatform and product owners
  • ConsultedGovernance / RMF / ISSO

LC-3 Supplier Access Constraint

  • AccountableAuthorizing Official / CISO
  • InformedCyber Threat Intelligence cell
  • ConsultedSOC / Defensive Operations
  • InformedHunt team
  • ResponsiblePlatform and product owners
  • ConsultedGovernance / RMF / ISSO

LC-4 Update Integrity and Staging

  • AccountableAuthorizing Official / CISO
  • ConsultedCyber Threat Intelligence cell
  • ConsultedSOC / Defensive Operations
  • InformedHunt team
  • ResponsiblePlatform and product owners
  • InformedGovernance / RMF / ISSO

LC-5 Supplier Severance Capability

  • AccountableAuthorizing Official / CISO
  • InformedCyber Threat Intelligence cell
  • ConsultedSOC / Defensive Operations
  • InformedHunt team
  • ResponsiblePlatform and product owners
  • ConsultedGovernance / RMF / ISSO

ID-1 Identity Plane Definition

  • AccountableAuthorizing Official / CISO
  • ConsultedCyber Threat Intelligence cell
  • ConsultedSOC / Defensive Operations
  • InformedHunt team
  • ResponsiblePlatform and product owners
  • InformedGovernance / RMF / ISSO

ID-2 Credential Strength and Binding

  • AccountableAuthorizing Official / CISO
  • InformedCyber Threat Intelligence cell
  • ConsultedSOC / Defensive Operations
  • InformedHunt team
  • ResponsiblePlatform and product owners
  • ConsultedGovernance / RMF / ISSO

ID-3 Authentication Assurance

  • AccountableAuthorizing Official / CISO
  • InformedCyber Threat Intelligence cell
  • ConsultedSOC / Defensive Operations
  • ConsultedHunt team
  • ResponsiblePlatform and product owners
  • InformedGovernance / RMF / ISSO

ID-4 Identity Assertion Protection

  • AccountableAuthorizing Official / CISO
  • InformedCyber Threat Intelligence cell
  • ConsultedSOC / Defensive Operations
  • ConsultedHunt team
  • ResponsiblePlatform and product owners
  • InformedGovernance / RMF / ISSO

ID-5 Authorization Decision Integrity

  • AccountableAuthorizing Official / CISO
  • InformedCyber Threat Intelligence cell
  • ConsultedSOC / Defensive Operations
  • InformedHunt team
  • ResponsiblePlatform and product owners
  • ConsultedGovernance / RMF / ISSO

EN-1 Event Declaration and Triage

  • AccountableAuthorizing Official / CISO
  • ConsultedCyber Threat Intelligence cell
  • ResponsibleSOC / Defensive Operations
  • ConsultedHunt team
  • InformedPlatform and product owners
  • InformedGovernance / RMF / ISSO

EN-2 Engagement Reconstruction

  • AccountableAuthorizing Official / CISO
  • ConsultedCyber Threat Intelligence cell
  • ConsultedSOC / Defensive Operations
  • ResponsibleHunt team
  • InformedPlatform and product owners
  • InformedGovernance / RMF / ISSO

EN-3 Evidence Preservation

  • AccountableAuthorizing Official / CISO
  • InformedCyber Threat Intelligence cell
  • ResponsibleSOC / Defensive Operations
  • ConsultedHunt team
  • InformedPlatform and product owners
  • ConsultedGovernance / RMF / ISSO

EN-4 Escalation and Engagement Authority

  • AccountableAuthorizing Official / CISO
  • InformedCyber Threat Intelligence cell
  • ResponsibleSOC / Defensive Operations
  • InformedHunt team
  • InformedPlatform and product owners
  • ConsultedGovernance / RMF / ISSO

EN-5 Eradication and Transition to Recovery

  • AccountableAuthorizing Official / CISO
  • InformedCyber Threat Intelligence cell
  • ConsultedSOC / Defensive Operations
  • ResponsibleHunt team
  • ConsultedPlatform and product owners
  • InformedGovernance / RMF / ISSO

EN-6 Engagement Communication

  • AccountableAuthorizing Official / CISO
  • ConsultedCyber Threat Intelligence cell
  • ConsultedSOC / Defensive Operations
  • InformedHunt team
  • InformedPlatform and product owners
  • ResponsibleGovernance / RMF / ISSO

DV-1 Device Terrain Identification

  • AccountableAuthorizing Official / CISO
  • InformedCyber Threat Intelligence cell
  • ConsultedSOC / Defensive Operations
  • InformedHunt team
  • ResponsiblePlatform and product owners
  • ConsultedGovernance / RMF / ISSO

DV-2 Device Posture as an Access Precondition

  • AccountableAuthorizing Official / CISO
  • InformedCyber Threat Intelligence cell
  • ConsultedSOC / Defensive Operations
  • ConsultedHunt team
  • ResponsiblePlatform and product owners
  • InformedGovernance / RMF / ISSO

DV-3 Endpoint Sensor Coverage and Liveness

  • AccountableAuthorizing Official / CISO
  • InformedCyber Threat Intelligence cell
  • ResponsibleSOC / Defensive Operations
  • ConsultedHunt team
  • ConsultedPlatform and product owners
  • InformedGovernance / RMF / ISSO

DV-4 Execution Control

  • AccountableAuthorizing Official / CISO
  • InformedCyber Threat Intelligence cell
  • ConsultedSOC / Defensive Operations
  • ConsultedHunt team
  • ResponsiblePlatform and product owners
  • InformedGovernance / RMF / ISSO

DV-5 Device Lifecycle and Sanitization

  • AccountableAuthorizing Official / CISO
  • InformedCyber Threat Intelligence cell
  • ConsultedSOC / Defensive Operations
  • InformedHunt team
  • ResponsiblePlatform and product owners
  • ConsultedGovernance / RMF / ISSO
Elsewhere in the Apparatus

The Rest of the Reference Layer.