Control Statement
Pre-planned contingency maneuvers shall be defined for the most likely and most dangerous adversary courses of action.
Purpose. To decide contingency responses before contact, so that the decision loop under pressure is a selection rather than a design exercise.
Discussion
The distinction between most likely and most dangerous is the whole value of the control. Planning only against the likely course produces a program that is efficient until the day it is not; planning only against the dangerous one produces a program that cannot afford its own contingencies. Holding both, and knowing which cells both demand, is where a single investment answers two threats.
Goals and Metrics
A metric that cannot come out badly is not a metric. Each of these is capable of reporting that the control is not working.
- Number of adversary courses of action with a pre-planned branch
- Number of incidents in the period that invoked a pre-planned branch rather than an improvised response
Accountability
Exactly one role is accountable, and every other role carries at least Informed — no control in the published catalog leaves a role with zero relationship to it. That is a stated property of how these were authored, not a coincidence, and not a claim that every role's work is worth equal attention here.
| AO | CTI | SOC | HUNT | PLAT | ISSO |
|---|---|---|---|---|---|
| Authorizing Official / CISO: Accountable | Cyber Threat Intelligence cell: Responsible | SOC / Defensive Operations: Consulted | Hunt team: Consulted | Platform and product owners: Informed | Governance / RMF / ISSO: Informed |
AO Authorizing Official / CISOCTI Cyber Threat Intelligence cellSOC SOC / Defensive OperationsHUNT Hunt teamPLAT Platform and product ownersISSO Governance / RMF / ISSO
- AccountableAuthorizing Official / CISO
- ResponsibleCyber Threat Intelligence cell
- ConsultedSOC / Defensive Operations
- ConsultedHunt team
- InformedPlatform and product owners
- InformedGovernance / RMF / ISSO
Inputs and Outputs
Consumes
- KT-3 Avenue of Approach AnalysisAvenues of approach informing likely courses of action
- CE-2 Priority Intelligence RequirementsPriority intelligence requirements identifying what is being watched for
- Outside the frameworkThreat intelligence on most-likely and most-dangerous adversary behavior
- TA-5 Tempo Degradation TriggerDegradation scenarios requiring a pre-planned branch
Produces
- TA-4 Pre-authorized ResponseCandidate actions for pre-authorization
- CG-3 Rules of EngagementBranch actions requiring an authority level in the rules of engagement
Activities
- L2Define contingency moves against the most likely adversary course of action.
- L2Define contingency moves against the most dangerous course of action.
- L2Link each to the response procedure that executes it.
- L3Derive both courses of action from current intelligence rather than from a standing scenario library.
- L3Identify the moves demanded by both courses, since those are where one investment answers two threats.
- L3State the trigger condition for each branch, specifically enough that an operator can recognize it without escalating to ask.
- L3Exercise at least one branch per cycle through tabletop or live test.
- L4Measure the elapsed time from trigger condition to branch execution in exercise, and compare it against the tempo the branch assumes.
- L4Trend branch currency against the threat picture; a branch built for a course of action no longer assessed is a maintenance liability.
- L5Re-derive branches from engagements, replacing assumed adversary behavior with observed behavior.
Measurement
Percentage of assessed courses of action carrying a current branch.
Elapsed time from trigger to execution in exercise.
Evidence and Assessment
Branch and sequel register with triggers; linked response procedures; exercise records.
Examine defined branches; test one through a tabletop exercise; examine currency against the current threat assessment.
Related Guidance
- IR-4
- CP-2
- RS.MA-01
- ID.IM-02
- ID.IM-04
Position in the Chain
Derived from the other controls’ own declarations, so the two directions cannot disagree.
Where This Control Is Used
Derived, in every case, from the declaration at the other end: the forms whose techniques name this control, the artifacts whose producing and consuming controls include it, the layers whose control lists name it, and the roles its own accountability chart puts to work. Nothing here is authored on this page, so the sheet cannot claim an edge the other end does not.
Forms of Maneuver It Assesses
- M8Isolation / RetrogradeGive ground deliberately to preserve the force. Degrade gracefully; never fail open.7 of 17 techniques — M8.01, M8.02, M8.03, M8.11, M8.13, M8.15, M8.16
- M7CounterattackSeize the initiative and evict before the adversary reaches the objective.3 of 17 techniques — M7.03, M7.05, M7.11
- M2Defense in DepthEnsure no single failure is decisive.1 of 18 techniques — M2.13
Terrain It Is Named On
No layer names this control for a reason of its own, and it is not part of the common spine. It acts on the framework rather than on any particular ground.
Artifacts It Stands On
- producesThreat course-of-action sketchTwo courses of action, most likely and most dangerous, drawn against the decisive points already designated. Each is a route across ground the estate really has, not a category of threat.
- producesBranch and sequel planThe branches answer the most-dangerous course of action; the sequels answer success. Every one names the authority it needs, and any expected to run inside the decision window is pre-authorized when it is written.
- consumesPriority Cyber Intelligence RequirementsThree to seven questions the cycle will try to answer, each naming the decision it informs, the collection source expected to answer it, and an individual owner.
- consumesAvenue-of-approach analysisThe enumerated routes an adversary could take toward each decisive point, including physical, supplier and maintenance routes, with unassessed routes recorded as intelligence gaps rather than as absence of risk.
- consumesIndicators and signpostsFor each surviving hypothesis, the observable events that would confirm or kill it, handed to collection. The mechanism that makes this cycle’s analysis into next cycle’s requirements.
Roles It Puts to Work
- AccountableAuthorizing Official / CISOIntent, risk acceptance, and the scheme itself.
- ResponsibleCyber Threat Intelligence cellFrame, Map and Fuse. The intelligence requirements, the threat courses of action, and the confidence levels.
- ConsultedSOC / Defensive OperationsManeuver. Executes fires and emplaces obstacles inside the standing rules of engagement.
- ConsultedHunt teamCounterattack. Works the hypotheses that Fuse raises.
- InformedPlatform and product ownersTheir own terrain. Obstacles get emplaced on their ground, so they site them.
- InformedGovernance / RMF / ISSOTranslating cycle outputs into FISMA and RMF artifacts, and owning the rules of engagement.