Platform and product owners
Responsible for 31 controls — more than any other role in the framework. The largest single share of the work sits with people who usually do not report to the accountable authority.
What It Is.
Owns. Their own terrain. Obstacles get emplaced on their ground, so they site them.
Doctrinal origin. The terrain owner. Obstacles are emplaced on somebody’s ground, and the unit that holds the ground sites them — because it is the one that has to live with the effect on movement.
Platform and product owners hold the ground: the portal, the case systems, the identity plane, the pipeline, the data stores, the facilities and the supplier relationships. They are Responsible for the overlay alongside the intelligence cell (TM-1), for trust zones and the connection register (TM-4, TM-5), for ownership itself (TM-7), for the decisive-point protection floor and barriers (KT-2, KT-5), for maneuver assignment and implementation state (SM-2, SM-3), for the whole of Reconstitution and Recovery (RC-1 to RC-5), for most of Federal Obligations, Facilities, and Supply Chain, and for the remediation backlog with the SOC (CE-5).
The structural fact worth naming: the role carrying the most responsibility in this framework typically has no reporting line to the role carrying the accountability. A platform owner answers to a program executive on delivery, not to the CISO on defense. Nothing in a RACI fixes that. What the framework does about it is narrower and more useful — TM-7 requires a named individual rather than a team mailbox, CG-4 routes each finding to that named owner with a date, and the cycle record (CE-6) makes an unactioned route visible across cycles rather than only inside one.
Recovery objectives are the clearest case of why the ground belongs to its owner. RC-1 puts the recovery time and recovery point objective with the service owner, not with the security function, because those numbers encode a mission judgment about how much interruption and how much data loss the mission can survive. Security can tell you what is achievable. Only the service owner can say what is acceptable.
Every Control It Touches.
Computed from the RACI each control carries, not written down a second time. If an assignment changes in the manual, this list changes with it.
Accountable0 controls
Answers for the outcome. Exactly one role per control, and it is not delegable.
None. This role holds no accountable assignment anywhere in the framework.
Responsible36 controls
Does the work, or shares it. More than one role may be Responsible for the same control.
Consulted20 controls
Asked before the control is settled, because it holds knowledge the accountable role does not.
What It Puts into the Chain.
The outputs declared by every control this role is Accountable or Responsible for, and where each one goes. 98 products across 36 controls.
TM — Terrain Management
- Element list awaiting defensive-layer classification
- Candidate elements for decisive-point designation
- Positional map used to enumerate avenues of approach
- The population over which coverage and residual risk are computed
- Layer assignment used to aggregate coverage per defensive layer
- Layer context constraining which maneuvers can apply to an element
- Defensive weight used to compute weighted coverage and residual risk
- Weight component of the ranked remediation backlog
- Weighting evidence supporting decisive-point designation
- Zone boundaries against which permitted and denied paths are recorded
- Boundary set an avenue of approach must cross
- Logical zones to be reconciled against physical zone boundaries
- Permitted paths from which avenues of approach are derived
- The permitted-path graph the reachability tracer walks
- Denied paths that become barriers requiring enforcement and monitoring
- Refresh trigger requiring the overlay to be rebuilt or amended
KT — Key Terrain and Decisive Points
- Floor breaches entering the remediation backlog at highest priority
- Findings where a decisive point sits below its floor
- Barriers requiring an obstacle maneuver to be assigned and maintained
- Barrier inventory tracked across cycles for silent erosion
- Barrier failure as a tempo degradation trigger
SM — Scheme of Maneuver
- Assignments requiring an implementation state
- Assigned moves counted toward the decisive-point protection floor
- Mitigation input to the coverage computation
- State weighting — only operational moves count in full toward risk reduction
- Planned and partial assignments forming remediation candidates
RC — Reconstitution and Recovery
- The time budget a trusted rebuild path must meet
- The objectives that reconstitution exercises must demonstrate
- Service dependency informing environmental continuity requirements
- Trusted media source for the rebuild path
- Independent store supporting integrity verification
- The isolation boundary as a load-bearing barrier requiring monitoring
- The paths that reconstitution exercises must walk
- Untested or over-budget paths entering the backlog
- Verification step exercised during reconstitution
- Verification outcome reported after any real recovery
FO — Federal Obligations
- Distinct defensive layer for aggregation
- Facility association for physical terrain
- Enterprise-to-operational crossings as avenues of approach
WF — Workforce Terrain
- Roles requiring a privileged human register entry
- Roles requiring role-specific readiness
- Personnel populations informing facility identification
- Register against which separation and revocation is executed
- Ownership verification for terrain elements
- Unresolved accounts entering the backlog
- Ownership reassignment required before revocation orphans an element
- Register update following removal
- Systems outside single-action revocation entering the backlog
FC — Facilities Terrain
- Facilities requiring zone division
- Facilities carrying mission services
- Physical exposure informing asset weighting
- Zones within which maintenance access must be controlled
- Physical approach routes to decisive points
- Physical barriers holding the line
- Maintenance paths recorded in the connection register
- Maintenance access as an avenue of approach
- Standing maintenance paths entering the backlog
- Endurance constraint on achievable recovery objectives
- Facilities whose endurance is shorter than the objectives they must support
LC — Lines of Communication
- Access requiring constraint
- Population for severance capability
- Supplier paths as avenues of approach
- Suppliers holding maintenance access
- Provenance basis for update integrity verification
- Components with unverifiable origin entering the backlog
- Component exposure informing intelligence requirements
- Supplier paths recorded as permitted or denied
- Brokered access as the severance point
- Constraints applied to maintenance windows
- Update deployment as a material change triggering terrain refresh
- Unverifiable or unstaged update paths entering the backlog
- The staging gate as a barrier requiring monitoring
- Severance scenarios included in reconstitution exercise
- Suppliers that cannot be severed within the period entering the backlog
- Demonstration results recorded across cycles
ID — Identity Terrain
- Identity planes as candidates for decisive-point designation
- Trust edges as avenues of approach
- Enforcement point register the decision path is measured against
- Authentication records used to discover devices reaching the estate
- Credential binding the achieved assurance level is computed from
- Non-human secret inventory that scopes revocation on separation
- Achieved assurance, as an input to the authorization decision
- Assurance requirement that device posture is evaluated alongside
- Revocation time as the containment segment of the decision loop
- Identity-plane revocation, without which eradication cannot be claimed
- Authorization paths over which reachability is computed
- Barrier set whose continued enforcement is monitored
- The decision point at which device posture is enforced
DV — Devices Terrain
- Device population that posture is evaluated for
- Inventory that sensor coverage is reconciled against
- Device terrain over which execution control is scoped
- Device crossings as avenues of approach
- Device posture as a component of achieved assurance
- Gated-access figures feeding coverage computation
- Unauthorized execution events as declaration triggers
- Enforcement scope feeding coverage computation
- Retirement events that keep the terrain overlay current
- Orphaned-trust findings requiring disposition
What It Depends On.
The inputs those same controls declare. Anything sourced from another control is a dependency on another role; anything marked as outside the framework has to be obtained from the wider organization.
TM — Terrain Management
- Authoritative asset inventory and system boundary documentation
- Network and cloud architecture diagrams
- Refresh trigger from the currency cadence or a material architectural change
- Element list from the terrain overlay
- Element list and position
- Mission impact analysis and statutory obligations
- Overlay elements requiring containment
- Segmentation, trust-zone and network boundary configuration
- Zone boundaries the connections cross
- Firewall, security-group and policy configuration; observed flow telemetry
- Cycle cadence establishing the baseline refresh interval
- Change management records identifying material architectural change
KT — Key Terrain and Decisive Points
- Designated decisive points
- Maneuvers assigned to elements and their implementation state
- The denied paths identified as preventing reachability
- Accountable owner for each enforcing element
SM — Scheme of Maneuver
- The adopted catalog of defensive forms
- Defensive layer constraining applicable forms
- Avenues of approach requiring a move to be sited on them
- Barriers requiring an obstacle move to maintain them
- Maneuver assignments requiring a state
RC — Reconstitution and Recovery
- Mission services represented on the terrain overlay
- Statutory deadlines constraining how weak an objective may be
- Business impact analysis and service-owner agreement
- Trust zone boundaries defining what production credentials can reach
- Recovery point objectives determining retention
- Designated decisive points requiring a rebuild path
- Recovery time objective setting the budget
- Isolated trusted media
- Independently held integrity record
- Rebuilt systems awaiting verification
FO — Federal Obligations
- Terrain overlay
- Engineering and facilities system inventories
WF — Workforce Terrain
- Terrain overlay
- Decisive points whose operators constitute high-consequence roles
- Human resources role and organizational data
- Identified high-consequence roles
- Identity system account data, HR records and vetting status
- Privileged human register identifying what each individual holds
- Suspension decisions requiring immediate revocation
- Human resources separation and suspension triggers
FC — Facilities Terrain
- Terrain overlay elements requiring a physical location
- Personnel populations requiring facility association
- Operational technology with a physical location
- Facilities and their contents
- Decisive points requiring physical location
- Logical trust zones to reconcile against
- Zones requiring maintenance access control
- Suppliers holding maintenance access
- Access constraint requirements
- Facilities carrying mission services
- Recovery objectives of the services housed
LC — Lines of Communication
- Suppliers represented as external actors on the overlay
- Contract and procurement records
- Component inventories, build manifests and supplier attestations
- Suppliers providing the components
- Registered supplier access
- Decisive points to which standing access is prohibited
- Controlled information constraints
- Component provenance supporting verification
- Suppliers providing updates
- Supplier register
- Brokered access forming the severance point
- Statutory availability floor that must survive severance
ID — Identity Terrain
- Terrain overlay the identity planes are drawn onto
- Identity provider and directory configuration, federation agreements
- Application authorization configuration
- Identity planes the credentials are bound within
- Privileged human register, to match proofing to privilege
- Decisive points, which set the strength the credential must meet
- Entitlement data and identity proofing records
- Identity planes and their enforcement points
- Credential binding, which bounds achievable assurance
- Terrain classification that sets the required level
- Decisive points requiring the highest assurance
- Identity planes and the enforcement points that honor revocation
- Assurance records the assertion carries
- Campaign phase, which can shorten required lifetimes
- Enforcement point register defining the paths that must be covered
- Assurance level consumed by the decision
- Terrain classification the policy is written against
DV — Devices Terrain
- Terrain overlay the device layer is placed on
- Identity planes, from which devices reaching the estate are discovered
- Authentication records naming the devices that actually connect
- Endpoint management platform, procurement and asset records
- Device terrain the posture requirement is applied across
- Authorization decision point that enforces the precondition
- Decisive points setting the strictest posture requirement
- Posture telemetry from the endpoint platform
- Device terrain over which enforcement is scoped
- Decisive points where enforcement is mandatory
- Component provenance establishing what may legitimately run
- Device terrain and its recorded holders
- Baseline provenance the provisioning image is built from
- Separation triggers that start the trust-removal clock
What the Role Has to Be Good At.
TM-4 defines a trust zone by the control that enforces it. Distinguishing an enforced boundary from a diagrammed one is a platform-owner skill, and it is the one most often assumed rather than checked.
RC-1 numbers set under pressure by whoever is loudest are worse than none. Setting them in advance, with statutory floors (FO-5) accounted for, is the whole control.
TM-5 asks for deliberately blocked paths to be recorded with a named enforcing control — so that the defensive decision survives the staff member who made it.
A new element defaults to no zone, no owner and no classification. Which means every architectural change is a terrain change, and the overlay refresh (TM-6) is not a security team’s problem to notice.
Coverage, floor breaches and recovery-exercise results all land on named systems with named owners. That is uncomfortable by design and the alternative is aggregate numbers nobody can act on.
How It Goes Wrong.
Each of these is a way the role can appear to be operating — the artifacts arrive, the chart still shows one accountable party — while producing nothing the defense can use.
A trust zone that exists on the diagram and is not technically enforced. TM-4 says to record these as findings rather than as zones, which is the only reason they ever get fixed.
Platform owners who regard TM-1 as somebody else’s document stop reconciling it, and the estate drifts away from its own map one deployment at a time.
An RTO chosen because it sounds achievable rather than because the mission or a statute requires it. RC-5 finds these the first time the exercise is run honestly.
TM-7 requires a named individual. A distribution list is unowned terrain with an address.
A segmentation rule agreed at design time and exempted at go-live. This is why KT-5 asks how a change to a load-bearing barrier would be detected.
Against the Other Five.
The shared count beside each is derived — how many controls the two roles both appear on. The note is authored: what the relationship is actually for, and where it breaks.
The Authorizing Official’s intent lands here or nowhere. Platform owners are Informed on CG-1 and on main-effort designation (SM-4) — the minimum that makes the scheme legible on the ground.
Co-responsible for the overlay and connection register. The cell brings positional meaning; platform owners bring what is actually deployed this week.
Shares responsibility for the protection floor, barriers, maneuver assignment and implementation state. Most of the framework’s real negotiation happens on this edge.
Hunt works in production on this role’s systems. Consulted on KT-3 and KT-4 so that the routes traced are the ones the platform actually permits.
Co-responsible across Federal Obligations, Facilities and Supply Chain. The ISSO knows the obligation; the platform owner knows the system it lands on.