Control Statement
The assumed effectiveness of each move shall be validated through exercise, testing, or observed incident performance, and adjusted where evidence contradicts assumption.
Purpose. To replace assumed effectiveness with demonstrated effectiveness, so the coverage figure reflects what controls do rather than what was assumed of them.
Discussion
The framework's own design documentation concedes that the riskReduction weightings are an allocation model for prioritization rather than an empirical finding, and states that they should be re-based against an agency's own incident history. SM-6 is the control that discharges that obligation. An agency running the framework for several cycles without adjusting a single weighting has not validated anything — it has confirmed its priors, and its coverage figure remains a statement about doctrine rather than about its estate.
Goals and Metrics
A metric that cannot come out badly is not a metric. Each of these is capable of reporting that the control is not working.
- Percentage of operational moves validated by exercise, test or observed incident performance in the period
- Number of assumed effectiveness values revised downward after validation
Accountability
Exactly one role is accountable, and every other role carries at least Informed — no control in the published catalog leaves a role with zero relationship to it. That is a stated property of how these were authored, not a coincidence, and not a claim that every role's work is worth equal attention here.
| AO | CTI | SOC | HUNT | PLAT | ISSO |
|---|---|---|---|---|---|
| Authorizing Official / CISO: Accountable | Cyber Threat Intelligence cell: Consulted | SOC / Defensive Operations: Consulted | Hunt team: Responsible | Platform and product owners: Informed | Governance / RMF / ISSO: Consulted |
AO Authorizing Official / CISOCTI Cyber Threat Intelligence cellSOC SOC / Defensive OperationsHUNT Hunt teamPLAT Platform and product ownersISSO Governance / RMF / ISSO
- AccountableAuthorizing Official / CISO
- ConsultedCyber Threat Intelligence cell
- ConsultedSOC / Defensive Operations
- ResponsibleHunt team
- InformedPlatform and product owners
- ConsultedGovernance / RMF / ISSO
Inputs and Outputs
Consumes
- SM-3 Implementation State TrackingMoves recorded as operational and therefore claiming full credit
- Outside the frameworkExercise results, control testing, and observed incident performance
- SM-1 Maneuver Catalog AdoptionAssumed effectiveness per form, to be validated
Produces
- CE-4 Coverage and Residual Risk ComputationCorrected effectiveness values feeding the coverage computation
- CE-5 Remediation Backlog PrioritizationMoves that failed validation, entering the backlog
- SM-1 Maneuver Catalog AdoptionCatalog revision where a form’s assumed indicator proves wrong
Activities
- L2Test or exercise assigned moves and record the result.
- L2Record the basis on which each effectiveness weighting currently rests.
- L2Adjust weightings where evidence contradicts assumption.
- L3Define what constitutes validating evidence for each move, distinguishing exercise, red-team test and observed incident performance.
- L3Use each technique's success indicator as the pass/fail condition, so validation tests the framework's own stated observable.
- L3Record every adjustment with its justification and the evidence that drove it.
- L3Propagate adjusted weightings into the posture computation rather than holding them as a separate finding.
- L4Measure the proportion of weightings resting on evidence rather than on issued default, and trend it upward.
- L4Measure the divergence between assumed and demonstrated effectiveness, since a consistently positive divergence indicates the defaults are optimistic.
- L5Re-base the full weighting distribution against accumulated agency incident history, and contribute the finding to the framework steward.
Measurement
Percentage of effectiveness weightings resting on agency evidence rather than issued default.
Divergence between assumed and demonstrated effectiveness.
Evidence and Assessment
Validation results; adjusted weightings with justification and supporting evidence.
Examine validation evidence; test that adjustments were reflected in the posture computation; examine whether any weighting has ever been reduced.
Related Guidance
- CA-2
- CA-8
- IR-3
- ID.IM-02
- ID.IM-03
Position in the Chain
Derived from the other controls’ own declarations, so the two directions cannot disagree.
Where This Control Is Used
Derived, in every case, from the declaration at the other end: the forms whose techniques name this control, the artifacts whose producing and consuming controls include it, the layers whose control lists name it, and the roles its own accountability chart puts to work. Nothing here is authored on this page, so the sheet cannot claim an edge the other end does not.
Forms of Maneuver It Assesses
- M7CounterattackSeize the initiative and evict before the adversary reaches the objective.4 of 17 techniques — M7.06, M7.07, M7.09, M7.10
- M10Exploitation & PursuitConvert contact into durable advantage rather than closing the ticket.2 of 7 techniques — M10.01, M10.02
- M2Defense in DepthEnsure no single failure is decisive.1 of 18 techniques — M2.14
- M4Obstacle / CanalizationForce the adversary onto ground you own and watch.1 of 17 techniques — M4.12
- M5AmbushTrade space for information and time, and impose cost.1 of 13 techniques — M5.10
- M8Isolation / RetrogradeGive ground deliberately to preserve the force. Degrade gracefully; never fail open.1 of 17 techniques — M8.12
Terrain It Is Named On
- T4Applications and WorkloadsManeuver effectiveness validation is where a rate limit or a WAF rule is shown to have changed adversary behavior rather than merely existing.
Artifacts It Stands On
- producesManeuver effectiveness validation recordWhether the moves claiming operational status produced the effect the catalog assumed — from exercise results, control testing, and observed incident performance.
- consumesScheme of maneuverOne graphic and one narrative: which forms of maneuver are sited where, in what sequence. The assignment record behind it carries the element, the avenue and the implementation state for every move.
- consumesChange recordEvery defensive action carried out, stamped twice — at the decision and at the effect. A thin, unglamorous table, and the one the headline metric is computed from.
- consumesImplementation state recordPlanned, partial or operational, per maneuver assignment. The mechanism that stops intended work being counted as deployed protection.
Roles It Puts to Work
- AccountableAuthorizing Official / CISOIntent, risk acceptance, and the scheme itself.
- ResponsibleHunt teamCounterattack. Works the hypotheses that Fuse raises.
- ConsultedCyber Threat Intelligence cellFrame, Map and Fuse. The intelligence requirements, the threat courses of action, and the confidence levels.
- ConsultedSOC / Defensive OperationsManeuver. Executes fires and emplaces obstacles inside the standing rules of engagement.
- ConsultedGovernance / RMF / ISSOTranslating cycle outputs into FISMA and RMF artifacts, and owning the rules of engagement.
- InformedPlatform and product ownersTheir own terrain. Obstacles get emplaced on their ground, so they site them.