ASOM-Fedv6.1Open the explorer
AO · touches 78 of 78 controls

Authorizing Official / CISO

Accountable for all 78 controls and responsible for none of them. That is the correct shape for command, and it is only safe if the Authorizing Official reads.

78AccountableAnswers for the outcome
0ResponsibleDoes the work
0ConsultedAsked before it is settled
0InformedTold after it is settled
The Role

What It Is.

Owns. Intent, risk acceptance, and the scheme itself.
Doctrinal origin. The commander. In the doctrine this framework is drawn from, the commander owns the intent and the risk; the staff owns the work. The split is not ceremonial — it is what lets a subordinate act without asking.

The Authorizing Official — in most civilian agencies the CISO, sometimes a separate official who holds the authorization decision — is the single accountable authority for the defensive campaign. The role exists here for the same reason the commander exists in the doctrine: a scheme of maneuver nobody can approve is a suggestion, and a risk nobody can accept is a risk that gets accepted silently, by default, at whatever level it happened to be discovered.

The Authorizing Official is Responsible for nothing. Three controls are nonetheless the role’s real work, because they are the ones every other control resolves against: the defensive intent paragraph (CG-1), the declared campaign phase (CG-2), and the rules of engagement (CG-3). The intelligence cell drafts all three. The Authorizing Official decides them, and the decision is not delegable — an intent written by staff and approved without argument has no author.

The three controls the Authorizing Official is only Informed on are the interesting ones: fusion and confidence (CE-3), the cycle record (CE-6), and brief generation (CE-7). Those are the controls that produce the picture the Authorizing Official then decides from. Holding the role at arm’s length from them is deliberate — an analytic judgment the commander helped shape is no longer an independent judgment — and it is also the single place this RACI is easiest to abuse. Confidence levels have to survive contact with the Authorizing Official’s preferences. Where they do not, the fusion step has quietly become an echo, and the scoreboard will start reporting what is wanted rather than what is true.

Derived

Every Control It Touches.

Computed from the RACI each control carries, not written down a second time. If an assignment changes in the manual, this list changes with it.

Responsible0 controls

Does the work, or shares it. More than one role may be Responsible for the same control.

None. This role holds no responsible assignment anywhere in the framework.

Consulted0 controls

Asked before the control is settled, because it holds knowledge the accountable role does not.

None. This role holds no consulted assignment anywhere in the framework.

Informed0 controls

Told the outcome. Not padding — each of these is a place the role has to be able to reconstruct a decision it did not make.

None. This role holds no informed assignment anywhere in the framework.

Derived

What It Puts into the Chain.

The outputs declared by every control this role is Accountable or Responsible for, and where each one goes. 215 products across 78 controls.

This role is accountable for most of the framework, so its product list is very close to the framework’s entire output. That is the honest consequence of the accountability, and it is why the Responsible column above is the more useful one for planning work.

TMTerrain Management

KTKey Terrain and Decisive Points

SMScheme of Maneuver

TATempo and Temporal Advantage

CECycle Execution and Assurance

CGCommand and Governance

RCReconstitution and Recovery

FOFederal Obligations

WFWorkforce Terrain

FCFacilities Terrain

LCLines of Communication

IDIdentity Terrain

ENEngagement and Pursuit

DVDevices Terrain

Derived

What It Depends On.

The inputs those same controls declare. Anything sourced from another control is a dependency on another role; anything marked as outside the framework has to be obtained from the wider organization.

TMTerrain Management

KTKey Terrain and Decisive Points

SMScheme of Maneuver

TATempo and Temporal Advantage

CECycle Execution and Assurance

CGCommand and Governance

RCReconstitution and Recovery

FOFederal Obligations

WFWorkforce Terrain

FCFacilities Terrain

LCLines of Communication

IDIdentity Terrain

ENEngagement and Pursuit

DVDevices Terrain

Capability

What the Role Has to Be Good At.

Writing intent in one paragraph

The defensive intent has to say what is being protected, what degradation is acceptable, and what must never happen, in words a platform owner can act on without a translator. It is a writing task, and it is the highest-leverage hour the role spends in a cycle.

Accepting risk explicitly

Signing an acceptance, with a rationale and a date, is harder than asking for remediation. A program in which nothing is ever formally accepted is a program in which everything is informally accepted.

Detecting a gamed number

Coverage rises when the denominator shrinks. The Authorizing Official does not need to compute coverage, but does need to ask what is in the denominator, and whether anything left it this cycle.

Tolerating a losing scoreboard

Temporal advantage (TA-1, TA-3) can come out negative. An Authorizing Official who reacts badly to that number will not be shown it again, and will lose the only honest measure in the framework.

Statutory judgment

Which availability floors are legal obligations rather than service targets (FO-5), and what that means at the moment containment and availability are in direct conflict. That call belongs to this role and arrives with no time to prepare.

Failure

How It Goes Wrong.

Each of these is a way the role can appear to be operating — the artifacts arrive, the chart still shows one accountable party — while producing nothing the defense can use.

Accountability by signature

Artifacts approved without being read. The RACI still shows exactly one accountable role, the audit still passes, and no decision has actually been made anywhere in the program.

Intent so broad it constrains nothing

“Protect the mission” designates no main effort, so every effort is the main effort and none of them is. SM-4 then has nothing to consume.

Findings that age instead of dispositioning

CG-4 offers three outcomes — remediated, accepted, transferred. Leaving a finding open past its period is not a fourth outcome; it is the absence of one, and it is the clearest single indicator of a governance failure.

Reading the brief instead of using it

The moment CE-7 is produced *for* the Authorizing Official rather than used *by* the Authorizing Official, the loop is decorative and the cycle is a reporting obligation.

Delegating the risk decision to governance

The ISSO can document an acceptance. Only the Authorizing Official can make one. Where those two get confused, the register fills with acceptances nobody with authority ever agreed to.

Relationships

Against the Other Five.

The shared count beside each is derived — how many controls the two roles both appear on. The note is authored: what the relationship is actually for, and where it breaks.

Cyber Threat Intelligence cell78 shared controls

Drafts the intent this role signs and produces the assessment it decides from. Press the cell on its confidence and its sourcing; never on its conclusions.

SOC / Defensive Operations78 shared controls

Operates entirely inside the rules of engagement this role approves. Every escalation the SOC has to make is a place the Authorizing Official chose not to pre-authorize — that list is a tempo decision, not an administrative one.

Hunt team78 shared controls

The independent check. Hunt is the only role structurally positioned to disprove the program’s own claims, and protecting its ability to report a reachable decisive point is a command responsibility.

Platform and product owners78 shared controls

Owns the ground. Intent becomes real only when platform owners site obstacles on their own systems, and an intent platform owners have not read has not actually been issued.

Governance / RMF / ISSO78 shared controls

Turns decisions into the record. The ISSO is accountable for the cycle record (CE-6) — the artifact that eventually goes to the agency OIG with this role’s name on the decisions inside it.