Control Statement
The organization shall adopt a defined catalog of defensive moves expressed as intent and mechanism rather than as product names.
Purpose. To fix a shared vocabulary of defensive moves stated as intent, so the plan survives replacement of the tools that implement it.
Discussion
Products are replaced every few years; intent is durable. Expressing the catalog as intent means the framework survives procurement cycles and lets leaders direct without technical fluency. The adoption test is not whether the catalog exists but whether leadership can actually issue direction in its terms — a catalog nobody commands with is a glossary.
Goals and Metrics
A metric that cannot come out badly is not a metric. Each of these is capable of reporting that the control is not working.
- Number of catalog entries naming a specific product
- Percentage of entries carrying a stated intent, mechanism and observable indicator
Accountability
Exactly one role is accountable, and every other role carries at least Informed — no control in the published catalog leaves a role with zero relationship to it. That is a stated property of how these were authored, not a coincidence, and not a claim that every role's work is worth equal attention here.
| AO | CTI | SOC | HUNT | PLAT | ISSO |
|---|---|---|---|---|---|
| Authorizing Official / CISO: Accountable | Cyber Threat Intelligence cell: Consulted | SOC / Defensive Operations: Consulted | Hunt team: Informed | Platform and product owners: Informed | Governance / RMF / ISSO: Responsible |
AO Authorizing Official / CISOCTI Cyber Threat Intelligence cellSOC SOC / Defensive OperationsHUNT Hunt teamPLAT Platform and product ownersISSO Governance / RMF / ISSO
- AccountableAuthorizing Official / CISO
- ConsultedCyber Threat Intelligence cell
- ConsultedSOC / Defensive Operations
- InformedHunt team
- InformedPlatform and product owners
- ResponsibleGovernance / RMF / ISSO
Inputs and Outputs
Consumes
- Outside the frameworkPublished forms of defensive maneuver and their technique mappings
- CG-1 Defensive IntentDefensive intent constraining which forms are relevant
- SM-6 Maneuver Effectiveness ValidationCatalog revision where a form’s assumed indicator proves wrong
Produces
- SM-2 Maneuver AssignmentThe catalog from which assignments are drawn
- SM-6 Maneuver Effectiveness ValidationAssumed effectiveness per form, to be validated
Activities
- L2Adopt the eleven-move catalog as issued, or extend it with locally defined moves in the same form.
- L2Record each move's intent, mechanism and effectiveness weighting.
- L2Publish the catalog where those who must use it can reach it.
- L3State every move as intent and mechanism, and reject any candidate that names a product category rather than a defensive effect.
- L3Require any locally defined move to meet the same admission criteria as an issued one: durable, expressible as intent, distinct in effect, supported by at least five techniques, and capable of being absent.
- L3Confirm by interview that leadership can direct using the catalog's terms without translation by an engineer.
- L3Review the catalog when the framework issues a version, and record which local extensions were superseded.
- L4Measure how often direction is actually issued in catalog terms versus in product terms, since the second indicates adoption has not occurred.
- L5Contribute locally defined moves that met the admission criteria back to the framework steward, so the catalog improves from field use.
Measurement
Percentage of defensive direction issued in catalog terms.
Percentage of local extensions meeting the admission criteria.
Evidence and Assessment
Adopted catalog with intent, mechanism and effectiveness weighting per move; local extension record.
Examine the adopted catalog; interview leadership on their ability to direct using it.
Related Guidance
- PL-2
- PM-7
- GV.PO-01
Position in the Chain
Derived from the other controls’ own declarations, so the two directions cannot disagree.
Where This Control Is Used
Derived, in every case, from the declaration at the other end: the forms whose techniques name this control, the artifacts whose producing and consuming controls include it, the layers whose control lists name it, and the roles its own accountability chart puts to work. Nothing here is authored on this page, so the sheet cannot claim an edge the other end does not.
Forms of Maneuver It Assesses
- M10Exploitation & PursuitConvert contact into durable advantage rather than closing the ticket.1 of 7 techniques — M10.06
Terrain It Is Named On
- TXCross-CuttingManeuver catalog adoption is a governance act before it is an operational one.
Artifacts It Stands On
- producesAdopted maneuver catalogThe forms of defensive maneuver the organization has adopted, each with the effectiveness it is assumed to deliver — recorded so the assumption can later be validated rather than believed indefinitely.
- consumesDefensive intent paragraphOne signed paragraph stating what the defense exists to protect, what may be degraded to protect it, and the acceptable risk. The commander’s-intent analog, and the citation every downstream designation rests on.
Roles It Puts to Work
- AccountableAuthorizing Official / CISOIntent, risk acceptance, and the scheme itself.
- ResponsibleGovernance / RMF / ISSOTranslating cycle outputs into FISMA and RMF artifacts, and owning the rules of engagement.
- ConsultedCyber Threat Intelligence cellFrame, Map and Fuse. The intelligence requirements, the threat courses of action, and the confidence levels.
- ConsultedSOC / Defensive OperationsManeuver. Executes fires and emplaces obstacles inside the standing rules of engagement.
- InformedHunt teamCounterattack. Works the hypotheses that Fuse raises.
- InformedPlatform and product ownersTheir own terrain. Obstacles get emplaced on their ground, so they site them.