ASOM-Fedv6.1Open the explorer
PLAT · touches 78 of 78 controls

Platform and product owners

Responsible for 31 controls — more than any other role in the framework. The largest single share of the work sits with people who usually do not report to the accountable authority.

0AccountableAnswers for the outcome
36ResponsibleDoes the work
20ConsultedAsked before it is settled
22InformedTold after it is settled
The Role

What It Is.

Owns. Their own terrain. Obstacles get emplaced on their ground, so they site them.
Doctrinal origin. The terrain owner. Obstacles are emplaced on somebody’s ground, and the unit that holds the ground sites them — because it is the one that has to live with the effect on movement.

Platform and product owners hold the ground: the portal, the case systems, the identity plane, the pipeline, the data stores, the facilities and the supplier relationships. They are Responsible for the overlay alongside the intelligence cell (TM-1), for trust zones and the connection register (TM-4, TM-5), for ownership itself (TM-7), for the decisive-point protection floor and barriers (KT-2, KT-5), for maneuver assignment and implementation state (SM-2, SM-3), for the whole of Reconstitution and Recovery (RC-1 to RC-5), for most of Federal Obligations, Facilities, and Supply Chain, and for the remediation backlog with the SOC (CE-5).

The structural fact worth naming: the role carrying the most responsibility in this framework typically has no reporting line to the role carrying the accountability. A platform owner answers to a program executive on delivery, not to the CISO on defense. Nothing in a RACI fixes that. What the framework does about it is narrower and more useful — TM-7 requires a named individual rather than a team mailbox, CG-4 routes each finding to that named owner with a date, and the cycle record (CE-6) makes an unactioned route visible across cycles rather than only inside one.

Recovery objectives are the clearest case of why the ground belongs to its owner. RC-1 puts the recovery time and recovery point objective with the service owner, not with the security function, because those numbers encode a mission judgment about how much interruption and how much data loss the mission can survive. Security can tell you what is achievable. Only the service owner can say what is acceptable.

Derived

Every Control It Touches.

Computed from the RACI each control carries, not written down a second time. If an assignment changes in the manual, this list changes with it.

Accountable0 controls

Answers for the outcome. Exactly one role per control, and it is not delegable.

None. This role holds no accountable assignment anywhere in the framework.

Responsible36 controls

Does the work, or shares it. More than one role may be Responsible for the same control.

Consulted20 controls

Asked before the control is settled, because it holds knowledge the accountable role does not.

Informed22 controls

Told the outcome. Not padding — each of these is a place the role has to be able to reconstruct a decision it did not make.

Derived

What It Puts into the Chain.

The outputs declared by every control this role is Accountable or Responsible for, and where each one goes. 98 products across 36 controls.

TMTerrain Management

KTKey Terrain and Decisive Points

SMScheme of Maneuver

RCReconstitution and Recovery

FOFederal Obligations

WFWorkforce Terrain

FCFacilities Terrain

LCLines of Communication

IDIdentity Terrain

DVDevices Terrain

Derived

What It Depends On.

The inputs those same controls declare. Anything sourced from another control is a dependency on another role; anything marked as outside the framework has to be obtained from the wider organization.

TMTerrain Management

KTKey Terrain and Decisive Points

SMScheme of Maneuver

RCReconstitution and Recovery

FOFederal Obligations

WFWorkforce Terrain

FCFacilities Terrain

LCLines of Communication

IDIdentity Terrain

DVDevices Terrain

Capability

What the Role Has to Be Good At.

Knowing where the boundary actually is

TM-4 defines a trust zone by the control that enforces it. Distinguishing an enforced boundary from a diagrammed one is a platform-owner skill, and it is the one most often assumed rather than checked.

Declaring recovery objectives as a mission judgment

RC-1 numbers set under pressure by whoever is loudest are worse than none. Setting them in advance, with statutory floors (FO-5) accounted for, is the whole control.

Recording a denied path as a decision

TM-5 asks for deliberately blocked paths to be recorded with a named enforcing control — so that the defensive decision survives the staff member who made it.

Change discipline

A new element defaults to no zone, no owner and no classification. Which means every architectural change is a terrain change, and the overlay refresh (TM-6) is not a security team’s problem to notice.

Accepting measurement

Coverage, floor breaches and recovery-exercise results all land on named systems with named owners. That is uncomfortable by design and the alternative is aggregate numbers nobody can act on.

Failure

How It Goes Wrong.

Each of these is a way the role can appear to be operating — the artifacts arrive, the chart still shows one accountable party — while producing nothing the defense can use.

Paper zones

A trust zone that exists on the diagram and is not technically enforced. TM-4 says to record these as findings rather than as zones, which is the only reason they ever get fixed.

The overlay treated as a security artifact

Platform owners who regard TM-1 as somebody else’s document stop reconciling it, and the estate drifts away from its own map one deployment at a time.

Recovery objectives set by comfort

An RTO chosen because it sounds achievable rather than because the mission or a statute requires it. RC-5 finds these the first time the exercise is run honestly.

Ownership recorded as a mailbox

TM-7 requires a named individual. A distribution list is unowned terrain with an address.

Obstacles accepted, then quietly relaxed

A segmentation rule agreed at design time and exempted at go-live. This is why KT-5 asks how a change to a load-bearing barrier would be detected.

Relationships

Against the Other Five.

The shared count beside each is derived — how many controls the two roles both appear on. The note is authored: what the relationship is actually for, and where it breaks.

Authorizing Official / CISO78 shared controls

The Authorizing Official’s intent lands here or nowhere. Platform owners are Informed on CG-1 and on main-effort designation (SM-4) — the minimum that makes the scheme legible on the ground.

Cyber Threat Intelligence cell78 shared controls

Co-responsible for the overlay and connection register. The cell brings positional meaning; platform owners bring what is actually deployed this week.

SOC / Defensive Operations78 shared controls

Shares responsibility for the protection floor, barriers, maneuver assignment and implementation state. Most of the framework’s real negotiation happens on this edge.

Hunt team78 shared controls

Hunt works in production on this role’s systems. Consulted on KT-3 and KT-4 so that the routes traced are the ones the platform actually permits.

Governance / RMF / ISSO78 shared controls

Co-responsible across Federal Obligations, Facilities and Supply Chain. The ISSO knows the obligation; the platform owner knows the system it lands on.