ASOM-Fedv6.1Open the explorer
SOC · touches 78 of 78 controls

SOC / Defensive Operations

Responsible for 15 controls, consulted on 30, accountable for none. The SOC acts entirely inside authority granted elsewhere — which is the design, and also the risk.

0AccountableAnswers for the outcome
8ResponsibleDoes the work
50ConsultedAsked before it is settled
20InformedTold after it is settled
The Role

What It Is.

Owns. Maneuver. Executes fires and emplaces obstacles inside the standing rules of engagement.
Doctrinal origin. The G3. Executes the scheme — emplaces obstacles, repositions sensors, delivers fires — inside standing engagement authority.

The SOC executes. It is Responsible for maneuver assignment and implementation state (SM-2, SM-3), for the decisive-point protection floor and barrier sufficiency alongside platform owners (KT-2, KT-5), for decision-loop measurement (TA-1), for pre-authorized response (TA-4), for the tempo degradation trigger (TA-5), for the remediation backlog (CE-5), for drafting the rules of engagement it will then operate under (CG-3), and for recovery integrity verification and the reconstitution exercise (RC-4, RC-5).

That the SOC is Accountable for nothing is not an oversight. Every action it takes is either pre-authorized by the rules of engagement or escalated to the Authorizing Official; a SOC that holds its own accountability is a SOC that can authorize its own fires, and the first time a containment action takes a statutory service offline, the question of who agreed to that has no answer. Engagement authority is exactly what this structure is protecting.

One honest tension sits inside TA-1: the SOC measures its own decision loop. Detect, decide, contain — three timestamps, all recorded by the party being measured. The control’s own assessment procedure exists because of this and says to test the derivation against a sample of raw incident records rather than accept the computed figure. An assessor who skips that step is measuring the SOC’s reporting, not its tempo.

Derived

Every Control It Touches.

Computed from the RACI each control carries, not written down a second time. If an assignment changes in the manual, this list changes with it.

Accountable0 controls

Answers for the outcome. Exactly one role per control, and it is not delegable.

None. This role holds no accountable assignment anywhere in the framework.

Responsible8 controls

Does the work, or shares it. More than one role may be Responsible for the same control.

Informed20 controls

Told the outcome. Not padding — each of these is a place the role has to be able to reconstruct a decision it did not make.

Derived

What It Puts into the Chain.

The outputs declared by every control this role is Accountable or Responsible for, and where each one goes. 23 products across 8 controls.

SMScheme of Maneuver

TATempo and Temporal Advantage

RCReconstitution and Recovery

ENEngagement and Pursuit

DVDevices Terrain

Derived

What It Depends On.

The inputs those same controls declare. Anything sourced from another control is a dependency on another role; anything marked as outside the framework has to be obtained from the wider organization.

SMScheme of Maneuver

TATempo and Temporal Advantage

RCReconstitution and Recovery

ENEngagement and Pursuit

DVDevices Terrain

Capability

What the Role Has to Be Good At.

Playbook engineering with a reverse gear

A pre-authorized fire (TA-4) has to be reversible and bounded, because it will execute without a human at machine speed. The design question is not whether it works but what it does when the detection was wrong.

Timestamp honesty

The decision loop is only as real as the moment recorded as “decide”. Recording it when the ticket was updated rather than when the judgment was made produces a scoreboard that is precise and false.

Restraint inside the rules of engagement

Acting outside the ROE once, successfully, is how a program loses its engagement authority — because the next review will narrow it.

Detection engineering against terrain

SM-2 sites moves on specific ground. A detection that is not attached to an element on the overlay cannot be counted toward coverage and will not survive the next tooling change.

Escalation judgment

Knowing which decisions genuinely need the Authorizing Official is what keeps the escalation path fast when it is actually used.

Failure

How It Goes Wrong.

Each of these is a way the role can appear to be operating — the artifacts arrive, the chart still shows one accountable party — while producing nothing the defense can use.

Volume reported as effect

Alerts triaged, tickets closed, hours worked. All measures of performance, none of effectiveness — the exact failure MOP and MOE exist to separate.

The pre-authorized list frozen at its first draft

The ROE is written once and never revisited, so the pre-authorized proportion silently falls as the estate grows. Tempo degrades without any single decision to degrade it.

Implementation state recorded as purchased

SM-3 tracks whether a maneuver is operational, not whether a product is licensed. A control marked implemented on the strength of a procurement is the most common way coverage numbers become fiction.

Normalized out-of-ROE action

The exception becomes the practice, undocumented, and the rules of engagement stop describing what the SOC actually does.

Barrier erosion unnoticed

KT-5 exists because an unmonitored barrier fails silently. When it does, the reachability answer changes and nothing raises its hand.

Relationships

Against the Other Five.

The shared count beside each is derived — how many controls the two roles both appear on. The note is authored: what the relationship is actually for, and where it breaks.

Authorizing Official / CISO78 shared controls

The source of the SOC’s authority. The width of the pre-authorized list is the Authorizing Official’s single largest lever on defensive tempo.

Cyber Threat Intelligence cell78 shared controls

Supplies the routes and the priorities the SOC sites moves against. The SOC is Consulted on almost all of the cell’s controls — that consultation is where “this route is not actually reachable in production” gets said.

Hunt team78 shared controls

Adjacent but deliberately separate. Hunt validates maneuver effectiveness (SM-6) on ground the SOC operates, and that check is worthless if the two are the same people under a different name.

Platform and product owners78 shared controls

The SOC proposes obstacles; platform owners site them and live with them. Co-responsibility on KT-2, KT-5, SM-2 and SM-3 makes that a negotiation rather than an instruction.

Governance / RMF / ISSO78 shared controls

Co-responsible for the rules of engagement (CG-3) — the SOC drafts what it needs to execute, the ISSO makes it defensible, the Authorizing Official approves it.