Authorizing Official / CISO
Accountable for all 78 controls and responsible for none of them. That is the correct shape for command, and it is only safe if the Authorizing Official reads.
What It Is.
Owns. Intent, risk acceptance, and the scheme itself.
Doctrinal origin. The commander. In the doctrine this framework is drawn from, the commander owns the intent and the risk; the staff owns the work. The split is not ceremonial — it is what lets a subordinate act without asking.
The Authorizing Official — in most civilian agencies the CISO, sometimes a separate official who holds the authorization decision — is the single accountable authority for the defensive campaign. The role exists here for the same reason the commander exists in the doctrine: a scheme of maneuver nobody can approve is a suggestion, and a risk nobody can accept is a risk that gets accepted silently, by default, at whatever level it happened to be discovered.
The Authorizing Official is Responsible for nothing. Three controls are nonetheless the role’s real work, because they are the ones every other control resolves against: the defensive intent paragraph (CG-1), the declared campaign phase (CG-2), and the rules of engagement (CG-3). The intelligence cell drafts all three. The Authorizing Official decides them, and the decision is not delegable — an intent written by staff and approved without argument has no author.
The three controls the Authorizing Official is only Informed on are the interesting ones: fusion and confidence (CE-3), the cycle record (CE-6), and brief generation (CE-7). Those are the controls that produce the picture the Authorizing Official then decides from. Holding the role at arm’s length from them is deliberate — an analytic judgment the commander helped shape is no longer an independent judgment — and it is also the single place this RACI is easiest to abuse. Confidence levels have to survive contact with the Authorizing Official’s preferences. Where they do not, the fusion step has quietly become an echo, and the scoreboard will start reporting what is wanted rather than what is true.
Every Control It Touches.
Computed from the RACI each control carries, not written down a second time. If an assignment changes in the manual, this list changes with it.
Accountable78 controls
Answers for the outcome. Exactly one role per control, and it is not delegable.
- TM-1
- TM-2
- TM-3
- TM-4
- TM-5
- TM-6
- TM-7
- KT-1
- KT-2
- KT-3
- KT-4
- KT-5
- SM-1
- SM-2
- SM-3
- SM-4
- SM-5
- SM-6
- SM-7
- TA-1
- TA-2
- TA-3
- TA-4
- TA-5
- CE-1
- CE-2
- CE-3
- CE-4
- CE-5
- CE-6
- CE-7
- CG-1
- CG-2
- CG-3
- CG-4
- CG-5
- RC-1
- RC-2
- RC-3
- RC-4
- RC-5
- FO-1
- FO-2
- FO-3
- FO-4
- FO-5
- FO-6
- FO-7
- WF-1
- WF-2
- WF-3
- WF-4
- WF-5
- FC-1
- FC-2
- FC-3
- FC-4
- LC-1
- LC-2
- LC-3
- LC-4
- LC-5
- ID-1
- ID-2
- ID-3
- ID-4
- ID-5
- EN-1
- EN-2
- EN-3
- EN-4
- EN-5
- EN-6
- DV-1
- DV-2
- DV-3
- DV-4
- DV-5
Responsible0 controls
Does the work, or shares it. More than one role may be Responsible for the same control.
None. This role holds no responsible assignment anywhere in the framework.
Consulted0 controls
Asked before the control is settled, because it holds knowledge the accountable role does not.
None. This role holds no consulted assignment anywhere in the framework.
Informed0 controls
Told the outcome. Not padding — each of these is a place the role has to be able to reconstruct a decision it did not make.
None. This role holds no informed assignment anywhere in the framework.
What It Puts into the Chain.
The outputs declared by every control this role is Accountable or Responsible for, and where each one goes. 215 products across 78 controls.
This role is accountable for most of the framework, so its product list is very close to the framework’s entire output. That is the honest consequence of the accountability, and it is why the Responsible column above is the more useful one for planning work.
TM — Terrain Management
- Element list awaiting defensive-layer classification
- Candidate elements for decisive-point designation
- Positional map used to enumerate avenues of approach
- The population over which coverage and residual risk are computed
- Layer assignment used to aggregate coverage per defensive layer
- Layer context constraining which maneuvers can apply to an element
- Defensive weight used to compute weighted coverage and residual risk
- Weight component of the ranked remediation backlog
- Weighting evidence supporting decisive-point designation
- Zone boundaries against which permitted and denied paths are recorded
- Boundary set an avenue of approach must cross
- Logical zones to be reconciled against physical zone boundaries
- Permitted paths from which avenues of approach are derived
- The permitted-path graph the reachability tracer walks
- Denied paths that become barriers requiring enforcement and monitoring
- Refresh trigger requiring the overlay to be rebuilt or amended
- Ownership routing for findings disposition
- Named owner for each barrier requiring enforcement
KT — Key Terrain and Decisive Points
- Designated points requiring a protection floor
- Targets whose approach routes must be enumerated
- Targets for the reachability assessment
- Candidates for main-effort designation
- Floor breaches entering the remediation backlog at highest priority
- Findings where a decisive point sits below its floor
- Route set for formal reachability assessment
- Routes requiring a maneuver to be sited on them
- Intelligence gaps arising from unassessed routes
- The specific barriers holding the line where reachability is prevented
- Reachability result feeding the residual risk picture
- Headline finding for the cycle brief
- Reachable decisive points requiring disposition
- Barriers requiring an obstacle maneuver to be assigned and maintained
- Barrier inventory tracked across cycles for silent erosion
- Barrier failure as a tempo degradation trigger
SM — Scheme of Maneuver
- The catalog from which assignments are drawn
- Assumed effectiveness per form, to be validated
- Assignments requiring an implementation state
- Assigned moves counted toward the decisive-point protection floor
- Mitigation input to the coverage computation
- State weighting — only operational moves count in full toward risk reduction
- Planned and partial assignments forming remediation candidates
- Prioritization weighting applied to the remediation backlog
- Main effort stated in the cycle brief
- Candidate actions for pre-authorization
- Branch actions requiring an authority level in the rules of engagement
- Corrected effectiveness values feeding the coverage computation
- Moves that failed validation, entering the backlog
- Catalog revision where a form’s assumed indicator proves wrong
- Interaction alerts carrying no false-positive budget
- Detection events contributing to the detect segment
- Emplacement coverage feeding the posture computation
TA — Tempo and Temporal Advantage
- Defender loop time, the denominator of the temporal advantage ratio
- Loop time recorded for trend across cycles
- Baseline against which degradation is detected
- Dwell estimate, the numerator of the temporal advantage ratio
- Stated basis reported alongside the posture result
- Temporal advantage result — the framework’s headline metric
- Deficit requiring formal disposition
- Tempo-driven items entering the remediation backlog
- Reduced decision segment in the measured loop
- The approved pre-authorization set, recorded in the rules of engagement
- Degradation scenarios requiring a pre-planned branch
- Degradation status reported with the posture result
CE — Cycle Execution and Assurance
- Baseline refresh interval for the terrain overlay
- Trigger to set the cycle’s intelligence requirements
- Cycle boundary for the record and trend
- Questions whose answers require fusion and a confidence level
- Requirements identifying the courses of action to pre-plan against
- Requirements answered and outstanding, reported in the brief
- Confidence discipline applied to the dwell estimate
- Conclusions recorded in the cycle record
- Confidence-tagged assessments for the brief
- Residual risk per element, ranked into the backlog
- Posture result recorded for the cycle
- Coverage and residual risk reported in the brief
- Items requiring formal disposition
- Backlog movement recorded across cycles
- Top-ranked items reported in the brief
- Trend content for the brief
- Continuous-monitoring evidence for the control baseline
- Barrier inventory tracked for erosion across cycles
- Evidence informing revision of the defensive intent
- Findings requiring disposition
- Continuous-monitoring evidence for oversight and audit
CG — Command and Governance
- Basis for decisive-point designation
- Basis for main-effort designation
- Direction for intelligence requirements
- Acceptable risk informing the temporal advantage threshold
- Phase context for main-effort designation
- Phase-driven adjustment to cycle cadence
- Phase-dependent authority levels
- Authority framework within which pre-authorization sits
- Authority exceptions reported in the brief
- Disposition outcomes recorded in the cycle record
- Accepted risks reflected in the control baseline
- Assessment and authorization evidence for the existing baseline
- Inheritance status reported to the accountable authority
RC — Reconstitution and Recovery
- The time budget a trusted rebuild path must meet
- The objectives that reconstitution exercises must demonstrate
- Service dependency informing environmental continuity requirements
- Trusted media source for the rebuild path
- Independent store supporting integrity verification
- The isolation boundary as a load-bearing barrier requiring monitoring
- The paths that reconstitution exercises must walk
- Untested or over-budget paths entering the backlog
- Verification step exercised during reconstitution
- Verification outcome reported after any real recovery
- Objectives missed in exercise, entering the backlog
- Exercise results recorded across cycles
- Undemonstrated objectives requiring disposition
FO — Federal Obligations
- Privacy sensitivity informing criticality scoring
- Candidate decisive points among privacy holdings
- Privacy control inheritance mapping
- Denied paths required to enforce declared boundaries
- Controlled-information control inheritance
- Constraints on supplier access to controlled information
- Inheritance feeding the control baseline mapping
- Inherited mitigation counted correctly in coverage
- Distinct defensive layer for aggregation
- Facility association for physical terrain
- Enterprise-to-operational crossings as avenues of approach
- Floor constraining recovery objectives
- Availability constraints bounding what may be degraded under contact
- Limits on pre-authorized actions that degrade a statutory service
- Population for the detailed supplier terrain register
- Supplier paths as avenues of approach
- Supplier connections recorded in the connection register
- The scoped FO denominator posture is computed against
- Obligation scope the inheritance mapping is verified within
- Which statutory reporting windows bind an engagement
WF — Workforce Terrain
- Roles requiring a privileged human register entry
- Roles requiring role-specific readiness
- Personnel populations informing facility identification
- Register against which separation and revocation is executed
- Ownership verification for terrain elements
- Unresolved accounts entering the backlog
- Readiness gaps as tempo degradation conditions
- Readiness shortfalls entering the backlog
- Authority levels for actions affecting an individual
- Suspension pathway into revocation
- Case dispositions recorded
- Ownership reassignment required before revocation orphans an element
- Register update following removal
- Systems outside single-action revocation entering the backlog
FC — Facilities Terrain
- Facilities requiring zone division
- Facilities carrying mission services
- Physical exposure informing asset weighting
- Zones within which maintenance access must be controlled
- Physical approach routes to decisive points
- Physical barriers holding the line
- Maintenance paths recorded in the connection register
- Maintenance access as an avenue of approach
- Standing maintenance paths entering the backlog
- Endurance constraint on achievable recovery objectives
- Facilities whose endurance is shorter than the objectives they must support
LC — Lines of Communication
- Access requiring constraint
- Population for severance capability
- Supplier paths as avenues of approach
- Suppliers holding maintenance access
- Provenance basis for update integrity verification
- Components with unverifiable origin entering the backlog
- Component exposure informing intelligence requirements
- Supplier paths recorded as permitted or denied
- Brokered access as the severance point
- Constraints applied to maintenance windows
- Update deployment as a material change triggering terrain refresh
- Unverifiable or unstaged update paths entering the backlog
- The staging gate as a barrier requiring monitoring
- Severance scenarios included in reconstitution exercise
- Suppliers that cannot be severed within the period entering the backlog
- Demonstration results recorded across cycles
ID — Identity Terrain
- Identity planes as candidates for decisive-point designation
- Trust edges as avenues of approach
- Enforcement point register the decision path is measured against
- Authentication records used to discover devices reaching the estate
- Credential binding the achieved assurance level is computed from
- Non-human secret inventory that scopes revocation on separation
- Achieved assurance, as an input to the authorization decision
- Assurance requirement that device posture is evaluated alongside
- Revocation time as the containment segment of the decision loop
- Identity-plane revocation, without which eradication cannot be claimed
- Authorization paths over which reachability is computed
- Barrier set whose continued enforcement is monitored
- The decision point at which device posture is enforced
EN — Engagement and Pursuit
- Declared incidents requiring reconstruction
- Prioritized incidents requiring an authority decision
- Measured decide segment of the decision loop
- Reconstruction that determines a safe restore point
- Observed dwell, correcting the estimate
- New intelligence requirements arising from the engagement
- Scope and magnitude eradication is verified against
- The material reconstruction is performed from
- Integrity record restore points are verified against
- Retention requirement sensor coverage must satisfy
- Authority response time within the decide segment
- Evidence for revising the pre-authorized set
- The decision authorizing transition to recovery
- Verified-clean state the rebuild path proceeds from
- Recurrence findings requiring disposition
- Eradication status that communication reports against
- Missed-window findings requiring disposition
- Communication record forming part of the cycle history
DV — Devices Terrain
- Device population that posture is evaluated for
- Inventory that sensor coverage is reconciled against
- Device terrain over which execution control is scoped
- Device crossings as avenues of approach
- Device posture as a component of achieved assurance
- Gated-access figures feeding coverage computation
- Detection telemetry that declaration and triage run on
- The record reconstruction is performed from
- Coverage as the detect segment of the decision loop
- Unauthorized execution events as declaration triggers
- Enforcement scope feeding coverage computation
- Retirement events that keep the terrain overlay current
- Orphaned-trust findings requiring disposition
What It Depends On.
The inputs those same controls declare. Anything sourced from another control is a dependency on another role; anything marked as outside the framework has to be obtained from the wider organization.
TM — Terrain Management
- Authoritative asset inventory and system boundary documentation
- Network and cloud architecture diagrams
- Refresh trigger from the currency cadence or a material architectural change
- Element list from the terrain overlay
- Element list and position
- Mission impact analysis and statutory obligations
- Overlay elements requiring containment
- Segmentation, trust-zone and network boundary configuration
- Zone boundaries the connections cross
- Firewall, security-group and policy configuration; observed flow telemetry
- Cycle cadence establishing the baseline refresh interval
- Change management records identifying material architectural change
- Element list requiring ownership
- Separation events invalidating a recorded owner
KT — Key Terrain and Decisive Points
- Candidate elements and their position
- Defensive weight supporting the designation
- Defensive intent identifying what the campaign exists to protect
- Designated decisive points
- Maneuvers assigned to elements and their implementation state
- Decisive points to be approached
- Permitted connections forming candidate routes
- Zone boundaries a route must cross
- Threat intelligence on adversary tradecraft and observed campaign behavior
- Enumerated avenues of approach
- Permitted-path graph — denied paths are excluded by definition
- The denied paths identified as preventing reachability
- Accountable owner for each enforcing element
SM — Scheme of Maneuver
- Published forms of defensive maneuver and their technique mappings
- Defensive intent constraining which forms are relevant
- The adopted catalog of defensive forms
- Defensive layer constraining applicable forms
- Avenues of approach requiring a move to be sited on them
- Barriers requiring an obstacle move to maintain them
- Maneuver assignments requiring a state
- Declared campaign phase
- Decisive points as main-effort candidates
- Defensive intent identifying what must be protected
- Avenues of approach informing likely courses of action
- Priority intelligence requirements identifying what is being watched for
- Threat intelligence on most-likely and most-dangerous adversary behavior
- Moves recorded as operational and therefore claiming full credit
- Exercise results, control testing, and observed incident performance
- Avenues of approach that determine where deception is worth placing
- Decisive points whose approaches are seeded first
- Terrain classification, so decoys are plausible for their layer
- Decide-segment measurement the response target is set against
TA — Tempo and Temporal Advantage
- Incident and alert timestamps from case management and response tooling
- Cycle cadence establishing the reporting period
- Sector threat reporting, incident history, partner and government intelligence
- Confidence discipline applied to the estimate
- Measured defender decision loop
- Estimated adversary dwell
- Acceptable risk from the defensive intent
- Branch actions that need to execute at speed
- Rules of engagement defining authority levels
- Statutory availability floor constraining what may be degraded
- Baseline loop measurement to detect degradation against
- Barrier failure as a degradation trigger
- Role readiness gaps that would slow the loop
CE — Cycle Execution and Assurance
- Defensive intent establishing why the cycle exists
- Declared phase, which may justify a faster cadence
- Cycle start
- Defensive intent identifying what must be protected
- Gaps in avenue-of-approach analysis raising collection needs
- Intelligence requirements to be answered
- Collected telemetry, threat reporting and hunt results
- Defensive weight per element
- Defensive layer assignment for aggregation
- Implementation state discounting planned and partial work
- Validated effectiveness values
- Reachability result
- Residual risk per element
- Decisive-point floor breaches, ranked ahead of lower-weighted work
- Planned and partial assignments
- Main effort weighting
- Computed posture for the cycle
- Measured decision loop
- Analytic conclusions and their confidence
- Backlog state at cycle close
- Terrain overlay
- Reachability result
- Main effort
- Temporal advantage result
- Coverage and residual risk
- Trend across cycles
CG — Command and Governance
- Mission, statutory obligations and organizational risk appetite
- Prior cycle evidence informing revision
- Defensive intent
- Fused assessment of the current situation
- Reachability result as a phase-change indicator
- The approved pre-authorization set
- Branch actions requiring an authority level
- Statutory availability constraints bounding what may be degraded
- Ranked remediation backlog
- Decisive-point floor breaches
- Temporal advantage deficits
- Ownership routing
- The organization’s existing control baseline and assessment results
- Cycle records serving as continuous-monitoring evidence
- Accepted risks to be reflected in the baseline
RC — Reconstitution and Recovery
- Mission services represented on the terrain overlay
- Statutory deadlines constraining how weak an objective may be
- Business impact analysis and service-owner agreement
- Trust zone boundaries defining what production credentials can reach
- Recovery point objectives determining retention
- Designated decisive points requiring a rebuild path
- Recovery time objective setting the budget
- Isolated trusted media
- Independently held integrity record
- Rebuilt systems awaiting verification
- Objectives to be demonstrated
- Rebuild paths to be walked
- Verification step to be exercised
FO — Federal Obligations
- Terrain overlay
- Privacy assessments and the authorities under which information is held
- Terrain overlay
- Connection register showing where information can move
- Trust zone boundaries
- Hosted elements on the overlay
- Provider authorization packages and responsibility matrices
- Terrain overlay
- Engineering and facilities system inventories
- Statute, regulation and authorizing instruments setting mission deadlines
- Mission services on the overlay
- Contract, procurement and vendor access records
- Terrain overlay
- Governing instruments, authorizing legislation and legal determinations
- Statutory availability floors that must appear in the profile
WF — Workforce Terrain
- Terrain overlay
- Decisive points whose operators constitute high-consequence roles
- Human resources role and organizational data
- Identified high-consequence roles
- Identity system account data, HR records and vetting status
- Identified roles requiring preparation
- Threat intelligence on tradecraft targeting each role
- Privileged human register
- Legal, human-resources, privacy and union or works-council requirements
- Privileged human register identifying what each individual holds
- Suspension decisions requiring immediate revocation
- Human resources separation and suspension triggers
FC — Facilities Terrain
- Terrain overlay elements requiring a physical location
- Personnel populations requiring facility association
- Operational technology with a physical location
- Facilities and their contents
- Decisive points requiring physical location
- Logical trust zones to reconcile against
- Zones requiring maintenance access control
- Suppliers holding maintenance access
- Access constraint requirements
- Facilities carrying mission services
- Recovery objectives of the services housed
LC — Lines of Communication
- Suppliers represented as external actors on the overlay
- Contract and procurement records
- Component inventories, build manifests and supplier attestations
- Suppliers providing the components
- Registered supplier access
- Decisive points to which standing access is prohibited
- Controlled information constraints
- Component provenance supporting verification
- Suppliers providing updates
- Supplier register
- Brokered access forming the severance point
- Statutory availability floor that must survive severance
ID — Identity Terrain
- Terrain overlay the identity planes are drawn onto
- Identity provider and directory configuration, federation agreements
- Application authorization configuration
- Identity planes the credentials are bound within
- Privileged human register, to match proofing to privilege
- Decisive points, which set the strength the credential must meet
- Entitlement data and identity proofing records
- Identity planes and their enforcement points
- Credential binding, which bounds achievable assurance
- Terrain classification that sets the required level
- Decisive points requiring the highest assurance
- Identity planes and the enforcement points that honor revocation
- Assurance records the assertion carries
- Campaign phase, which can shorten required lifetimes
- Enforcement point register defining the paths that must be covered
- Assurance level consumed by the decision
- Terrain classification the policy is written against
EN — Engagement and Pursuit
- Endpoint detection telemetry
- Deception interaction alerts, which carry no false-positive budget
- Asset weighting used to rank what was declared
- Decide-segment target the triage period is set against
- Declared incidents
- Preserved evidence, without which reconstruction cannot run
- Terrain overlay the movement is traced across
- Connection and denied-path register bounding plausible movement
- Declared incidents that trigger preservation
- Dwell estimate that sets the retention floor
- Terrain classification determining what must be preserved
- Legal and privacy determinations bounding what may be held
- Declared and prioritized incidents
- Pre-authorized response set, which bounds what needs escalating
- Rules of engagement defining the limits of authority
- Declared phase, which can widen standing authority
- Reconstruction defining the scope that must be cleared
- Identity-plane revocation, without which eviction is incomplete
- Recovery objectives constraining how long eradication may take
- The authority under which transition is declared
- Declared incidents and their category
- Reconstruction and magnitude, which set what must be reported
- Eradication status
- Obligation profile determining which statutory windows bind
DV — Devices Terrain
- Terrain overlay the device layer is placed on
- Identity planes, from which devices reaching the estate are discovered
- Authentication records naming the devices that actually connect
- Endpoint management platform, procurement and asset records
- Device terrain the posture requirement is applied across
- Authorization decision point that enforces the precondition
- Decisive points setting the strictest posture requirement
- Posture telemetry from the endpoint platform
- Device inventory coverage is reconciled against
- Dwell estimate that sets how long telemetry must survive
- Evidence retention requirement the sensors must satisfy
- Device terrain over which enforcement is scoped
- Decisive points where enforcement is mandatory
- Component provenance establishing what may legitimately run
- Device terrain and its recorded holders
- Baseline provenance the provisioning image is built from
- Separation triggers that start the trust-removal clock
What the Role Has to Be Good At.
The defensive intent has to say what is being protected, what degradation is acceptable, and what must never happen, in words a platform owner can act on without a translator. It is a writing task, and it is the highest-leverage hour the role spends in a cycle.
Signing an acceptance, with a rationale and a date, is harder than asking for remediation. A program in which nothing is ever formally accepted is a program in which everything is informally accepted.
Coverage rises when the denominator shrinks. The Authorizing Official does not need to compute coverage, but does need to ask what is in the denominator, and whether anything left it this cycle.
Temporal advantage (TA-1, TA-3) can come out negative. An Authorizing Official who reacts badly to that number will not be shown it again, and will lose the only honest measure in the framework.
Which availability floors are legal obligations rather than service targets (FO-5), and what that means at the moment containment and availability are in direct conflict. That call belongs to this role and arrives with no time to prepare.
How It Goes Wrong.
Each of these is a way the role can appear to be operating — the artifacts arrive, the chart still shows one accountable party — while producing nothing the defense can use.
Artifacts approved without being read. The RACI still shows exactly one accountable role, the audit still passes, and no decision has actually been made anywhere in the program.
“Protect the mission” designates no main effort, so every effort is the main effort and none of them is. SM-4 then has nothing to consume.
CG-4 offers three outcomes — remediated, accepted, transferred. Leaving a finding open past its period is not a fourth outcome; it is the absence of one, and it is the clearest single indicator of a governance failure.
The moment CE-7 is produced *for* the Authorizing Official rather than used *by* the Authorizing Official, the loop is decorative and the cycle is a reporting obligation.
The ISSO can document an acceptance. Only the Authorizing Official can make one. Where those two get confused, the register fills with acceptances nobody with authority ever agreed to.
Against the Other Five.
The shared count beside each is derived — how many controls the two roles both appear on. The note is authored: what the relationship is actually for, and where it breaks.
Drafts the intent this role signs and produces the assessment it decides from. Press the cell on its confidence and its sourcing; never on its conclusions.
Operates entirely inside the rules of engagement this role approves. Every escalation the SOC has to make is a place the Authorizing Official chose not to pre-authorize — that list is a tempo decision, not an administrative one.
The independent check. Hunt is the only role structurally positioned to disprove the program’s own claims, and protecting its ability to report a reachable decisive point is a command responsibility.
Owns the ground. Intent becomes real only when platform owners site obstacles on their own systems, and an intent platform owners have not read has not actually been issued.
Turns decisions into the record. The ISSO is accountable for the cycle record (CE-6) — the artifact that eventually goes to the agency OIG with this role’s name on the decisions inside it.