Governance / RMF / ISSO
Accountable for one control and Responsible for twenty. The one is the cycle record — the artifact that turns a series of cycles into a trend, and a trend into evidence.
What It Is.
Owns. Translating cycle outputs into FISMA and RMF artifacts, and owning the rules of engagement.
Doctrinal origin. The staff function that holds the record and the engagement authority — the one that can say what was decided, by whom, and under what rules, after everyone who was in the room has moved on.
The ISSO is Accountable for CE-6, the cycle record and trend. That is the only accountability in the framework held outside the Authorizing Official, and it is placed deliberately: the value of running a loop is entirely in the series, and the series has to be kept by someone whose job survives a reorganization of the SOC.
Beyond that the role is Responsible for the rules of engagement (CG-3), findings disposition (CG-4), control inheritance mapping (CG-5), terrain ownership with platform owners (TM-7), pre-authorized response documentation (TA-4), brief generation (CE-7), and the majority of Federal Obligations and Workforce — privacy terrain, controlled unclassified information, tenancy boundaries, statutory availability, supply-chain register and access constraint.
The role also carries the widest Informed footprint in the framework — 18 controls where it is neither doing the work nor being consulted, only kept in the loop. That is not courtesy padding. The ISSO has to be able to reconstruct what a cycle decided without having participated in it, because that reconstruction is what an OIG audit actually consumes. An ISSO who is Informed of nothing writes an accurate description of a program they cannot evidence.
CG-5 deserves separate mention because it is the control that prevents this framework from becoming a second compliance burden. Where an existing 800-53 assessment already satisfies a requirement, the requirement is inherited and cited — assessed once, not twice. The ISSO owns that judgment, and getting it wrong in the cautious direction is what makes adopters conclude the framework is expensive.
Every Control It Touches.
Computed from the RACI each control carries, not written down a second time. If an assignment changes in the manual, this list changes with it.
Accountable0 controls
Answers for the outcome. Exactly one role per control, and it is not delegable.
None. This role holds no accountable assignment anywhere in the framework.
Responsible18 controls
Does the work, or shares it. More than one role may be Responsible for the same control.
Consulted34 controls
Asked before the control is settled, because it holds knowledge the accountable role does not.
What It Puts into the Chain.
The outputs declared by every control this role is Accountable or Responsible for, and where each one goes. 46 products across 18 controls.
TM — Terrain Management
- Ownership routing for findings disposition
- Named owner for each barrier requiring enforcement
SM — Scheme of Maneuver
- The catalog from which assignments are drawn
- Assumed effectiveness per form, to be validated
TA — Tempo and Temporal Advantage
- Temporal advantage result — the framework’s headline metric
- Deficit requiring formal disposition
- Tempo-driven items entering the remediation backlog
CE — Cycle Execution and Assurance
- Residual risk per element, ranked into the backlog
- Posture result recorded for the cycle
- Coverage and residual risk reported in the brief
- Items requiring formal disposition
- Backlog movement recorded across cycles
- Top-ranked items reported in the brief
- Trend content for the brief
- Continuous-monitoring evidence for the control baseline
- Barrier inventory tracked for erosion across cycles
CG — Command and Governance
- Authority framework within which pre-authorization sits
- Authority exceptions reported in the brief
- Disposition outcomes recorded in the cycle record
- Accepted risks reflected in the control baseline
- Assessment and authorization evidence for the existing baseline
- Inheritance status reported to the accountable authority
FO — Federal Obligations
- Privacy sensitivity informing criticality scoring
- Candidate decisive points among privacy holdings
- Privacy control inheritance mapping
- Denied paths required to enforce declared boundaries
- Controlled-information control inheritance
- Constraints on supplier access to controlled information
- Inheritance feeding the control baseline mapping
- Inherited mitigation counted correctly in coverage
- Floor constraining recovery objectives
- Availability constraints bounding what may be degraded under contact
- Limits on pre-authorized actions that degrade a statutory service
- Population for the detailed supplier terrain register
- Supplier paths as avenues of approach
- Supplier connections recorded in the connection register
- The scoped FO denominator posture is computed against
- Obligation scope the inheritance mapping is verified within
- Which statutory reporting windows bind an engagement
WF — Workforce Terrain
- Readiness gaps as tempo degradation conditions
- Readiness shortfalls entering the backlog
- Authority levels for actions affecting an individual
- Suspension pathway into revocation
- Case dispositions recorded
EN — Engagement and Pursuit
- Missed-window findings requiring disposition
- Communication record forming part of the cycle history
What It Depends On.
The inputs those same controls declare. Anything sourced from another control is a dependency on another role; anything marked as outside the framework has to be obtained from the wider organization.
TM — Terrain Management
- Element list requiring ownership
- Separation events invalidating a recorded owner
SM — Scheme of Maneuver
- Published forms of defensive maneuver and their technique mappings
- Defensive intent constraining which forms are relevant
TA — Tempo and Temporal Advantage
- Measured defender decision loop
- Estimated adversary dwell
- Acceptable risk from the defensive intent
CE — Cycle Execution and Assurance
- Defensive weight per element
- Defensive layer assignment for aggregation
- Implementation state discounting planned and partial work
- Validated effectiveness values
- Reachability result
- Residual risk per element
- Decisive-point floor breaches, ranked ahead of lower-weighted work
- Planned and partial assignments
- Main effort weighting
- Computed posture for the cycle
- Measured decision loop
- Analytic conclusions and their confidence
- Backlog state at cycle close
CG — Command and Governance
- The approved pre-authorization set
- Branch actions requiring an authority level
- Statutory availability constraints bounding what may be degraded
- Ranked remediation backlog
- Decisive-point floor breaches
- Temporal advantage deficits
- Ownership routing
- The organization’s existing control baseline and assessment results
- Cycle records serving as continuous-monitoring evidence
- Accepted risks to be reflected in the baseline
FO — Federal Obligations
- Terrain overlay
- Privacy assessments and the authorities under which information is held
- Terrain overlay
- Connection register showing where information can move
- Trust zone boundaries
- Hosted elements on the overlay
- Provider authorization packages and responsibility matrices
- Statute, regulation and authorizing instruments setting mission deadlines
- Mission services on the overlay
- Contract, procurement and vendor access records
- Terrain overlay
- Governing instruments, authorizing legislation and legal determinations
- Statutory availability floors that must appear in the profile
WF — Workforce Terrain
- Identified roles requiring preparation
- Threat intelligence on tradecraft targeting each role
- Privileged human register
- Legal, human-resources, privacy and union or works-council requirements
EN — Engagement and Pursuit
- Declared incidents and their category
- Reconstruction and magnitude, which set what must be reported
- Eradication status
- Obligation profile determining which statutory windows bind
What the Role Has to Be Good At.
Deciding when an existing control assessment genuinely covers an ASOM-Fed requirement, and being able to defend the citation when an assessor tests two of them (CG-5).
An artifact that is dated, attributable and reproducible. A screenshot of a dashboard is evidence that a dashboard existed on a Tuesday.
CG-4 gives three dispositions. The skill is getting an acceptance signed by someone with the authority to accept, rather than letting the finding age into de facto acceptance by nobody.
The cycle record has to be usable as continuous-monitoring evidence and as an operational trend line. Optimising it only for the first produces a document nobody inside the program reads.
FO-5 requires the availability floor to be traced to the authorizing instrument, not to a service-level target someone once wrote in a contract.
How It Goes Wrong.
Each of these is a way the role can appear to be operating — the artifacts arrive, the chart still shows one accountable party — while producing nothing the defense can use.
Artifacts produced on schedule, decisions made nowhere. The tell is a cycle record whose entries never differ from one another.
Reassessing inherited controls because it is safer than defending an inheritance. Cost goes up, nothing is learned, and the program acquires a reputation for burden.
Findings recorded diligently and dispositioned rarely. CG-4 measures the age against the defined period precisely so this becomes visible early.
Recording a risk as accepted on the strength of an unanswered email. The register then contains a decision with no decider, which is worse than an open finding.
CE-6 written once a year in the four weeks before an assessment. There is no trend in it, and the one thing the control exists to produce is the trend.
Against the Other Five.
The shared count beside each is derived — how many controls the two roles both appear on. The note is authored: what the relationship is actually for, and where it breaks.
The ISSO prepares the decision and holds its record; the Authorizing Official makes it. Keeping that line sharp is what stops the register filling with unowned acceptances.
Consumes the cell’s products and turns them into FISMA and RMF artifacts. The ISSO should be the one arguing about which 800-53 control an activity satisfies, so the cell does not have to.
Co-responsible for the rules of engagement (CG-3) and for pre-authorized response documentation (TA-4). The SOC says what it needs; the ISSO makes it defensible.
The largest shared workload of the six pairings — Federal Obligations, Facilities and Supply Chain are nearly all co-responsible. The ISSO knows the obligation, the platform owner knows the system.
Almost no direct contact by design. Hunt’s findings arrive through fusion (CE-3) and disposition (CG-4) rather than through a governance channel, which keeps hunt’s reporting fast.