ASOM-Fedv6.1Open the explorer
Reference manual · sources and provenance

Where This Came from, and Where It Did Not.

This framework says on every page that it is built from public doctrine and public sources. That sentence is free to write, so here is the working. Every source is named with what was taken from it and — the part that decides whether the rest of the site can be trusted — what was deliberately left behind. Then the claims that are original are listed as original, because a reader has to be able to tell which parts of this carry someone else’s authority and which carry only ours.

12Sources citedEach with what is taken and what is refused
130SP 800-53 controls namedAcross 20 of 20 families, counted from the catalog
93CSF 2.0 subcategoriesUnevenly distributed, and the page shows how unevenly
9Claims that are oursCarrying no authority but this framework’s
How to Read This Page

Three Bases, Two Refusals, and a Count.

A bibliography lists influences. A provenance statement draws a boundary: it says where the borrowing stopped and why. The second is the only one worth publishing, because it is the only one that can be wrong.

What it is

The document, described for a reader who has not read it. No source is cited here that was not used.

What is taken

Specific borrowings, not themes. “The analytic process as the spine of the cycle” is checkable; “inspired by intelligence doctrine” is not.

What is not taken

The refusals, with reasons. Every source has at least one — a source with nothing declined has been cited rather than read.

What is counted

Where inheritance is computable it is computed, from the published catalog and the terrain model rather than from a sentence about them. Those tables move when the framework moves.

The doctrinal base

The method. How a force analyzes ground, decides what is worth holding, arrays itself against an opponent who is also thinking, and phases a campaign over time.

3 sources

The federal base

The ground and the obligations. What a federal estate is made of, what statute and policy already require of it, and the identifiers an agency already reports against.

8 sources

The analogical base

One structural shape, borrowed from a discipline outside security because it had already solved the same traceability problem. It supplies no authority, only a form.

1 source
The doctrinal base

Where the method comes from.

The method. How a force analyzes ground, decides what is worth holding, arrays itself against an opponent who is also thinking, and phases a campaign over time.

ATP 2-33.4

ATP 2-33.4, Intelligence Analysis

Headquarters, Department of the Army — Army Techniques Publication

The Army’s publication on how intelligence analysis is actually performed: the analytic process, the structured techniques that discipline it, the preparation of the battlefield that precedes it, and the requirement that a product state how much weight it can bear.

What this framework takes
  • The analytic process — screen, analyze, integrate, produce — as the spine of the operating cycle. The framework’s six steps are a decomposition of this sequence, not a replacement for it.
  • Structured analytic techniques, kept under their own names and grouped as the publication groups them: basic, diagnostic, contrarian, imaginative. Analysis of competing hypotheses and a key-assumptions check are cited as what they are rather than paraphrased into house vocabulary.
  • Intelligence Preparation of the Battlefield, recast as Cyber Preparation of the Environment — define the environment, describe its effects, evaluate the threat, determine threat courses of action — which is the entire content of the Map step.
  • Priority Intelligence Requirements, which become Priority Cyber Intelligence Requirements: a small set of questions, each tied to a decision, set before collection rather than after it.
  • The requirement that a product carry an explicit confidence level, published with the assessment rather than left for the reader to infer.
  • Analytic Design’s discipline of specifying the product — audience, questions, sources, method, schedule — before collection begins.
What it does not take
  • Collection management.The publication assumes organic collection assets that can be tasked. A federal agency collects from its own telemetry and from what partners choose to share; it does not task collectors, and a framework that pretended otherwise would produce collection plans nobody can execute.
  • The intelligence disciplines.Source taxonomies exist to manage classified collection across services. Nothing here is classified, and importing the taxonomy would import a handling regime the framework has no business asserting.
  • The staff structure.The analytic function is mapped onto whatever the agency already has — a threat-intelligence cell, a hunt team, sometimes one analyst. The framework names the function, never the box on an org chart.
Joint phasing

The joint phasing model — shape, deter, seize initiative, dominate, stabilize, enable

Joint doctrine on operations and planning (JP 3-0 / JP 5-0)

The six-phase model by which a joint operation is planned and described over time, together with the branches-and-sequels planning discipline that goes with it.

What this framework takes
  • The six-phase spine and its names, unrenamed, so that a reader who knows the model recognizes it and a reader who does not can look it up.
  • The principle that a phase declaration is an act with consequences — it changes cadence, it changes what is pre-authorized, and it changes which forms of maneuver dominate.
  • Branches and sequels: contingency maneuvers planned before they are needed, so that a decision under pressure is a selection rather than an invention.
What it does not take
  • A single estate-wide phase.Phase here is declared against a named scope. An agency can be in Dominate on one mission service and Shape on everything else, and forcing one phase across the estate would make the declaration meaningless.
  • Phase as maturity.Phase III is not an achievement. It means an adversary is on or adjacent to key terrain. Read as a ladder, phasing becomes a scoreboard nobody wants to climb down from — so regression must be declarable without embarrassment.
  • The offensive content of the model.Seize Initiative and Dominate here mean contesting an intrusion on ground the agency owns. No part of this framework contemplates action on infrastructure the agency does not own, and no authority in it would support one.
  • Phase V as written.The joint phase concerns transition to civil authority. The federal-network analog is handing a contested estate back to normal operations, so the phase is renamed rather than stretched.
Visible in
Allen (2020)

Cyber Maneuver and Schemes of Maneuver

Allen · The Cyber Defense Review (2020), cited as the framework’s own source material cites it

The paper that makes cyber maneuver a usable idea rather than a metaphor: it defines maneuver in cyberspace as action taken to achieve positional and temporal advantage over an adversary, and argues that a scheme of maneuver specifies which categories apply and in what sequence.

What this framework takes
  • The definition itself. Positional and temporal advantage is the framework’s stated objective, and both halves of it are measured rather than asserted.
  • The durability argument: categories of maneuver outlive the techniques that implement them, which is why a commander can direct a scheme without being an engineer. This is the single load-bearing idea behind separating eleven forms from 154 techniques.
  • The structure of a scheme — which categories, on what ground, in what sequence — as the shape of the framework’s central product.
What it does not take
  • The paper’s own categories.The eleven forms in this framework are not the paper’s list. They are authored here, from land-warfare maneuver vocabulary, and the paper is credited for the idea that such a list should exist rather than for its contents.
  • Offensive maneuver.The concept spans both directions. This framework takes only the defensive half, on terrain the agency owns and is authorized to act on.
  • The assumption of a maneuver force.The paper can assume a unit with authority to move. A civilian agency has a change-approval process instead, which is why pre-authorized fires are a control here rather than an assumption.
The federal base

Where the ground and the obligations come from.

The ground and the obligations. What a federal estate is made of, what statute and policy already require of it, and the identifiers an agency already reports against.

SP 800-53 Rev. 5

NIST SP 800-53 Rev. 5, Security and Privacy Controls for Information Systems and Organizations

National Institute of Standards and Technology

The federal control catalog. Every control this framework publishes names the 800-53 controls it derives from, and the distribution of those references is computed below rather than described.

What this framework takes
  • Descent, recorded per control. Each entry publishes the 800-53 identifiers it grew out of, which is what allows the twelve genuinely new controls to be counted rather than asserted.
  • The grammar of a control: a normative statement of what the organization shall do, separated from the discussion of why it exists.
  • The family structure as the index against which lineage is expressed.
What it does not take
  • Baselines and tailoring.Nothing resembling a low, moderate or high baseline is taken from 800-53, and none is invented to replace it. Which controls apply is a categorization decision, and that decision belongs to the agency making it.
  • Control enhancements and the overlay mechanism.Lineage is expressed at the control level. Claiming enhancement-level derivation would imply a rigour of mapping that has not been performed.
  • Any claim of coverage.What is cited amounts to a small fraction of Rev. 5, and the direction of the debt runs one way: this framework borrows from 800-53 and returns nothing to it. Implementing one does not discharge the other.
SP 800-37 (RMF)

NIST SP 800-37, Risk Management Framework for Information Systems and Organizations

National Institute of Standards and Technology

The lifecycle that carries a federal system from categorization through authorization and then holds it under continuous monitoring — seven steps, of which only the last turns more than once.

What this framework takes
  • The authorization boundary as the scope statement. Terrain is mapped inside a boundary that already exists, so the overlay can be reconciled against the system inventory rather than invented beside it.
  • The Authorizing Official as the commander analog: the accountable person who owns the risk and therefore owns the intent.
  • The outer ring of the RMF, which the operating cycle turns inside. What is taken is the obligation to keep watching; what is added is a cadence, a clock and a record for doing it.
What it does not take
  • The authorization decision.What the RMF requires as evidence — the system security plan, the assessment report, the plan of action and milestones, each in its prescribed form — is not among the artifacts this framework emits, and no route from one to the other is implied.
  • The assessment cadence.The lifecycle is inherited; its cadence is not. A defense that re-examines itself on an anniversary is the exact tempo problem the operating cycle was built to answer.
  • Categorization.Defensive weight is borrowed from nowhere in FIPS 199 and is not offered back to it. The two numbers answer different questions, and substituting one for the other would put an editorial figure where a statutory determination is required.
CSF 2.0

The NIST Cybersecurity Framework 2.0

National Institute of Standards and Technology

The six-function outcome framework — govern, identify, protect, detect, respond, recover — whose subcategory identifiers have become the common index for describing security outcomes across agencies and vendors.

What this framework takes
  • Subcategory identifiers as an index. An agency already reporting in CSF terms can find the ASOM-Fed controls that bear on a subcategory without a translation exercise.
  • The Govern function’s existence as first-class. Command and intent are governance outcomes here, not a preamble to the technical ones.
What it does not take
  • Tiers and Profiles.The five pillars are taken; the four-stage scale is left where it is. An estate graded on two scales at once yields two verdicts and no principled way to pick one, so capability is scored here on the framework’s own scale and reported under the pillar names an agency already files against.
  • Even coverage of the six functions.The citation distribution below is lopsided and is published lopsided. Respond is cited through a single subcategory, because what this framework has to say about responding sits in the maneuver catalog and the phase model, neither of which is a control. An agency that needs CSF Respond coverage should not take it from here.
CISA ZTMM

CISA Zero Trust Maturity Model

Cybersecurity and Infrastructure Security Agency

CISA’s maturity model for federal zero trust, and the vocabulary an agency is already reporting against: five pillars carrying three cross-cutting capabilities, graded traditional through optimal.

What this framework takes
  • The five pillars, verbatim and deliberately unrenamed, as terrain layers T1 through T5. An agency already reporting ZTMM maturity should not have to translate its own reporting to read this framework.
  • The four stages, reused as the rungs a sub-tower is scored on and as the arithmetic behind the coverage percentage that rolls up into residual risk.
  • The cross-cutting capabilities, which become the cross-cutting terrain — visibility, automation and governance are enablers of movement rather than ground to be held.
What it does not take
  • The pillar set as complete.Operational technology, workforce, facilities and supply chain are added, each covering ground a federal estate really holds and the five pillars leave unaddressed. The table below derives which layers are inherited and which are ours, rather than asserting it.
  • Maturity read as progress.A layer’s stage says what the estate can currently do on that ground, not how well the program is performing. The framework scores coverage per sub-tower for that reason — an estate with excellent authentication and no privileged-access control averages to a respectable number and will still be lost.
  • The assumption that Optimal is universally reachable.Several sub-towers on operational-technology ground cannot reach the top rung without a vendor change the agency does not control. That ceiling is recorded against the terrain rather than reported as a permanent failure.
Visible in
SP 800-207

NIST SP 800-207, Zero Trust Architecture

National Institute of Standards and Technology

The architectural definition of zero trust, and the policy decision point / policy enforcement point vocabulary that makes it concrete.

What this framework takes
  • The policy decision point and policy enforcement point as named elements on the terrain overlay, which is what allows a decisive point to be a specific thing rather than an important-sounding system.
  • The principle that trust is evaluated per request, which is what makes identity the high ground rather than one control family among many.
What it does not take
  • The deployment variants.The document sets out several architectural approaches. Choosing between them is an agency engineering decision; the framework needs only that the decision points be locatable on the map.
Visible in
TIC 3.0

Trusted Internet Connections 3.0

Cybersecurity and Infrastructure Security Agency

The federal program that replaced a single physical internet gateway with trust zones and distributed policy enforcement, and the capability catalog that goes with it.

What this framework takes
  • Trust zones and policy enforcement points as the boundary vocabulary the terrain overlay is drawn in, so that zone crossings on the map are the same crossings an agency already documents.
  • The perimeter sub-tower’s content, expressed in the program’s own capability language.
What it does not take
  • The use cases as an architecture prescription.Which use case an agency adopts is left open. The requirement is narrower: whichever boundaries exist belong on the map, and traffic crossing them has to be observed.
Visible in
FISMA

The Federal Information Security Modernization Act

United States statute

The statute the whole federal obligation set descends from, and the reason a federal estate is different ground to defend than a commercial one.

What this framework takes
  • The obligation treated as terrain rather than as paperwork. Privacy, controlled unclassified information, shared tenancy, statutory availability and the supply chain are ground the framework defends, which is why they form a control family of their own.
  • The requirement that a program be assessed rather than described, which is why every control here carries an assessment procedure and an evidence artifact.
What it does not take
  • Reporting instrumentation.The framework produces no FISMA metrics submission and no inspector-general evaluation score, and is not a substitute for either.
  • Compliance as the objective.A compliant estate can still be lost. Statutory obligation sets a floor that the framework treats as ground to be defended, not as the definition of a successful defense.
OMB M-22-09

OMB M-22-09, Moving the U.S. Government Toward Zero Trust Cybersecurity Principles

Office of Management and Budget (2022)

The federal zero-trust strategy memorandum: a set of specific end-state goals across identity, devices, networks, applications and data, with dates attached.

What this framework takes
  • The concrete end states — phishing-resistant multifactor authentication, endpoint detection and response, encryption in transit, meaningful segmentation, application-layer testing — as outcomes the maneuver catalog must actually be able to produce. A form of maneuver that cannot be traced to one of them is decoration.
  • The principle that a strategy carries dates. Tempo thresholds here are stated as numbers with owners for the same reason.
What it does not take
  • The action-item list as an adoption plan.The memorandum sequences by deadline. This framework sequences by what the next phase of a defensive campaign requires, and the two orders are not the same. Where they conflict, the deadline is the agency’s obligation and the framework yields to it.
  • Applicability.The memorandum binds specific agencies under its own terms. Nothing here extends, interprets or restates that scope.
The analogical base

Where the shape comes from — and only the shape.

One structural shape, borrowed from a discipline outside security because it had already solved the same traceability problem. It supplies no authority, only a form.

TBM cost towers

The Technology Business Management taxonomy — the cost-tower model

Technology Business Management Council, taxonomy v5 (the edition the tower model was drawn against)

An IT financial-management taxonomy in which cost flows upward through four layers — cost pools, resource towers, solutions, consumers — so that any dollar can be traced from where it was spent to the business unit that consumed it, and back.

What this framework takes
  • The four-layer upward-allocation shape, mirrored one for one: asset pools, defense towers and sub-towers, maneuver solutions, mission consumers.
  • The allocation-driver idea. Cost flows on a cost driver; coverage flows on a defensive weight, computed from criticality and exposure.
  • The per-consumer bill. A Bill of IT states what a business unit consumes; a Bill of Defense states what defends a mission service, at what coverage, with what residual risk.
  • Bidirectional traceability as the actual point of the model: pick a mission and see everything defending it, or pick an asset and see everything it protects.
What it does not take
  • The money.Nothing in this framework is denominated in dollars. It does not cost a control, does not price a maneuver, and produces no budget artifact. The analogy is to the shape of the allocation, not to its content.
  • The taxonomy itself.The tower names, sub-tower contents and cost-pool categories are not imported. The towers here are zero-trust pillars and the framework’s own additions.
  • Benchmarking.Comparing unit cost across organizations is a legitimate use of the original model. Comparing coverage percentages across agencies is not — the weights are locally assigned, and a cross-agency league table built on them would be arithmetic dressed as insight.
  • The fungibility assumption.A dollar moved between towers is the same dollar. Coverage moved between sub-towers is not the same coverage: a point of privileged-access maturity does not substitute for a point of segmentation. The allocation shape survives the translation; the interchangeability does not.
The Inheritance, Counted

What the Lineage Actually Looks like When You Add It Up.

Everything in this section is computed from the data it describes. “Inherits SP 800-53” is a claim; the distribution below is a measurement, and it is not a flattering one everywhere.

Exhibit 1

Which SP 800-53 Rev. 5 Families the Control Catalog Draws From

800-53 familyControls citedReferencesASOM-Fed families drawing on it
PMProgram Management1434CE · CG · DV · EN · FC · FO · ID · KT · LC · RC · SM · TA · TM · WF
CPContingency Planning1016CG · EN · FC · FO · KT · LC · RC · SM · TA
ACAccess Control914CG · DV · FO · ID · KT · LC · TA · TM · WF
SCSystem and Communications Protection914FC · FO · ID · KT · RC · SM · TM
IRIncident Response823CG · EN · LC · RC · SM · TA
RARisk Assessment816CE · CG · FO · KT · SM · TA · TM
CMConfiguration Management813DV · KT · LC · RC · TM
IAIdentification and Authentication810DV · ID · WF
SRSupply Chain Risk Management88FO · LC
SISystem and Information Integrity712CE · DV · EN · FO · KT · LC · RC · SM · TA
CAAssessment, Authorization, and Monitoring616CE · CG · KT · SM · TM
AUAudit and Accountability610CE · DV · EN · ID · RC · TA · WF
PSPersonnel Security67TA · WF
PEPhysical and Environmental Protection66FC
SASystem and Services Acquisition46CG · FO · LC
MAMaintenance44DV · FC
ATAwareness and Training33WF
PLPlanning25CE · CG · FO · SM
MPMedia Protection22DV · FO
PTPersonally Identifiable Information Processing and Transparency22FO

PM

Program Management

Controls cited
14
References
34
ASOM-Fed families drawing on it
CE · CG · DV · EN · FC · FO · ID · KT · LC · RC · SM · TA · TM · WF

CP

Contingency Planning

Controls cited
10
References
16
ASOM-Fed families drawing on it
CG · EN · FC · FO · KT · LC · RC · SM · TA

AC

Access Control

Controls cited
9
References
14
ASOM-Fed families drawing on it
CG · DV · FO · ID · KT · LC · TA · TM · WF

SC

System and Communications Protection

Controls cited
9
References
14
ASOM-Fed families drawing on it
FC · FO · ID · KT · RC · SM · TM

IR

Incident Response

Controls cited
8
References
23
ASOM-Fed families drawing on it
CG · EN · LC · RC · SM · TA

RA

Risk Assessment

Controls cited
8
References
16
ASOM-Fed families drawing on it
CE · CG · FO · KT · SM · TA · TM

CM

Configuration Management

Controls cited
8
References
13
ASOM-Fed families drawing on it
DV · KT · LC · RC · TM

IA

Identification and Authentication

Controls cited
8
References
10
ASOM-Fed families drawing on it
DV · ID · WF

SR

Supply Chain Risk Management

Controls cited
8
References
8
ASOM-Fed families drawing on it
FO · LC

SI

System and Information Integrity

Controls cited
7
References
12
ASOM-Fed families drawing on it
CE · DV · EN · FO · KT · LC · RC · SM · TA

CA

Assessment, Authorization, and Monitoring

Controls cited
6
References
16
ASOM-Fed families drawing on it
CE · CG · KT · SM · TM

AU

Audit and Accountability

Controls cited
6
References
10
ASOM-Fed families drawing on it
CE · DV · EN · ID · RC · TA · WF

PS

Personnel Security

Controls cited
6
References
7
ASOM-Fed families drawing on it
TA · WF

PE

Physical and Environmental Protection

Controls cited
6
References
6
ASOM-Fed families drawing on it
FC

SA

System and Services Acquisition

Controls cited
4
References
6
ASOM-Fed families drawing on it
CG · FO · LC

MA

Maintenance

Controls cited
4
References
4
ASOM-Fed families drawing on it
DV · FC

AT

Awareness and Training

Controls cited
3
References
3
ASOM-Fed families drawing on it
WF

PL

Planning

Controls cited
2
References
5
ASOM-Fed families drawing on it
CE · CG · FO · SM

MP

Media Protection

Controls cited
2
References
2
ASOM-Fed families drawing on it
DV · FO

PT

Personally Identifiable Information Processing and Transparency

Controls cited
2
References
2
ASOM-Fed families drawing on it
FO
Computed from the inherits array of each of the 78 published controls: 221 references to 130 distinct controls, 2.8 per control on average. Every one of the 20 Rev. 5 families is cited at least once. Reading the shape rather than the total: the heaviest draw is Program Management (PM), cited by controls in all 14 ASOM-Fed families — which is a fair description of what this framework is. It is a program framework wearing a control catalog, and the technical families it is often assumed to be about sit further down the table. The right-hand column uses the two-letter ASOM-Fed family codes from the control manual.

The bottom of that table is the more useful part, and it is where this framework found its own largest gap. Through version 4.0, Identification and Authentication was cited exactly once across the whole catalog — incidentally, through a workforce control about privileged account holders — in a framework that calls identity the high ground and treats it as the usual main effort. Nobody reviewing the catalog noticed; the crosswalk did, because a completeness test is not an opinion. That finding is what produced the ID family, and IA is now cited across it. The 3 families still cited exactly once — Planning (PL), Media Protection (MP), Personally Identifiable Information Processing and Transparency (PT) — are the ones to read the same way now: not as a defect, but as the next place to point the test. Lineage records where a control came from. It does not record what the framework is about, and it is never a coverage claim.

Exhibit 2

CSF 2.0 Citations by Function, Published as They Fall

CSF 2.0 functionSubcategoriesCitationsWhere that content lives here
GVGovern2238Command, intent, phase declaration and rules of engagement are governance outcomes here, so the Command and Governance family cites heavily into this function.
IDIdentify1949The terrain overlay is an identification artifact before it is anything else, which is why the heaviest citation in the catalog sits here.
PRProtect2038Protection is expressed as maneuver rather than as control text, so the controls cite the outcome and the technique catalog carries the substance.
DEDetect1115Detection content lives in the screen, ambush and hunt forms. The controls here assess whether detection is sited on key terrain, not whether a sensor exists.
RSRespond1318Response is the framework’s campaign phases and its pre-authorized fires, neither of which is a control. One subcategory is cited, and no claim of Respond coverage is made on the strength of it.
RCRecover811Reconstitution is a control family of its own here, and its citations are concentrated rather than spread — recovery is assessed by whether it has been proven, not by how many outcomes it touches.

GV

Govern

Subcategories
22
Citations
38
Where that content lives here
Command, intent, phase declaration and rules of engagement are governance outcomes here, so the Command and Governance family cites heavily into this function.

ID

Identify

Subcategories
19
Citations
49
Where that content lives here
The terrain overlay is an identification artifact before it is anything else, which is why the heaviest citation in the catalog sits here.

PR

Protect

Subcategories
20
Citations
38
Where that content lives here
Protection is expressed as maneuver rather than as control text, so the controls cite the outcome and the technique catalog carries the substance.

DE

Detect

Subcategories
11
Citations
15
Where that content lives here
Detection content lives in the screen, ambush and hunt forms. The controls here assess whether detection is sited on key terrain, not whether a sensor exists.

RS

Respond

Subcategories
13
Citations
18
Where that content lives here
Response is the framework’s campaign phases and its pre-authorized fires, neither of which is a control. One subcategory is cited, and no claim of Respond coverage is made on the strength of it.

RC

Recover

Subcategories
8
Citations
11
Where that content lives here
Reconstitution is a control family of its own here, and its citations are concentrated rather than spread — recovery is assessed by whether it has been proven, not by how many outcomes it touches.
169 citations to 93 distinct subcategories across all 6 functions. The distribution is deliberately not smoothed: the widest function cites 22 distinct subcategories, and Recover cites 8. An agency that needs CSF Recover coverage should take it from somewhere else — the third column says where that content actually lives here, which is not in the control catalog.
Exhibit 3

Which Terrain Layers Are Inherited and Which Are Additions

OriginLayersWhat that means
CISA ZTMM pillar5 layersT1 Identity · T2 Devices · T3 Networks · T4 Applications and Workloads · T5 DataInherited verbatim from the maturity model, unrenamed so an agency’s existing reporting still reads.
Cross-cutting1 layerTX Cross-CuttingMirrors the model’s cross-cutting capabilities: enablers of movement rather than ground to be held.
ASOM-Fed v2.01 layerT6 Operational TechnologyAuthored here, because a measurable part of a federal estate had nowhere else to stand.
ASOM-Fed v3.03 layersT7 Workforce · T8 Facilities · T9 Supply ChainAuthored here, because a measurable part of a federal estate had nowhere else to stand.

CISA ZTMM pillar

5 layers

Layers
T1 Identity · T2 Devices · T3 Networks · T4 Applications and Workloads · T5 Data
What that means
Inherited verbatim from the maturity model, unrenamed so an agency’s existing reporting still reads.

Cross-cutting

1 layer

Layers
TX Cross-Cutting
What that means
Mirrors the model’s cross-cutting capabilities: enablers of movement rather than ground to be held.

ASOM-Fed v2.0

1 layer

Layers
T6 Operational Technology
What that means
Authored here, because a measurable part of a federal estate had nowhere else to stand.

ASOM-Fed v3.0

3 layers

Layers
T7 Workforce · T8 Facilities · T9 Supply Chain
What that means
Authored here, because a measurable part of a federal estate had nowhere else to stand.
Read from each layer’s own recorded origin. 5 of the 10 layers are the maturity model’s pillars, unrenamed; 1 mirrors its cross-cutting capabilities; the remaining 4 are this framework’s additions. Half the ground it maneuvers on is therefore inherited and half is asserted — which is the honest ratio to know before accepting the terrain model.
Exhibit 4

The Operating Cycle’s Named Techniques, by Citation

SourceTechniquesInherited or oursSteps they appear in
ATP 2-33.413Inheritedframe · map · array · fuse · assess
Army planning1Inheritedarray
Joint assessment doctrine1Inheritedassess
Rules of engagement1Inheritedmaneuver
Authored7Authored hereframe · map · maneuver · assess

ATP 2-33.4

Techniques
13
Inherited or ours
Inherited
Steps they appear in
frame · map · array · fuse · assess

Army planning

Techniques
1
Inherited or ours
Inherited
Steps they appear in
array

Joint assessment doctrine

Techniques
1
Inherited or ours
Inherited
Steps they appear in
assess

Rules of engagement

Techniques
1
Inherited or ours
Inherited
Steps they appear in
maneuver

Authored

Techniques
7
Inherited or ours
Authored here
Steps they appear in
frame · map · maneuver · assess
Every technique named in the cycle reference carries a source. Of 23 techniques, 16 carry a doctrinal citation and 7 are authored here. The authored ones cluster where they should: the Maneuver step is execution rather than analysis, and it deliberately borrows almost nothing from an analysis publication.
Original Synthesis

The Claims That Carry No Authority but This Framework’s.

The sources above make this look well-founded, and a reader who stops there will over-credit it. These are the parts nobody else stands behind: 11 forms of maneuver, 154 techniques, 78 controls, 4 added terrain layers, and every number in the arithmetic.

The union itself. Fusing an intelligence-analysis method with maneuver planning, and calling the result an analytic scheme of maneuver, is not something either source does.

Nearest inherited thing

Both halves are mature and public. Neither publication proposes combining them, and neither is written for a civilian network defender.

What it stands on

An argument, tested by whether it produces better decisions than the alternative. It is not a doctrinal position and should not be cited as one.

The eleven forms of defensive cyber maneuver and every technique beneath them — their names, their scope, the terrain each is emplaced on, the phases each is employed in, and the indicator that shows each is working.

Nearest inherited thing

The argument that categories of maneuver should exist and should outlive techniques. The categories themselves are authored here.

What it stands on

Land-warfare maneuver vocabulary applied by analogy, and the internal test that every technique names an observable capable of showing it has failed.

The control catalog. Every statement, discussion, application note, evidence artifact and assessment procedure is written for this framework.

Nearest inherited thing

The controls each one derives from. Lineage is recorded per control and counted below; the text is not inherited text.

What it stands on

The framework’s own drafting, assessed by whether each control can actually be failed. A control whose evidence cannot be produced is a defect here, not a difference of opinion.

The terrain layers beyond the zero-trust pillars — operational technology, workforce, facilities and supply chain — and in particular the claim that workforce is simultaneously terrain and the defending force.

Nearest inherited thing

The five pillars, which are inherited verbatim. The additions are not in the model they extend.

What it stands on

The argument that each names measurable ground a federal estate actually holds and could not otherwise score. The workforce layer carries the strongest objection against it, and the terrain reference states that objection rather than answering it quietly.

The Defense Tower Model: mapping defensive coverage and residual risk onto an upward allocation waterfall, and issuing a per-mission Bill of Defense.

Nearest inherited thing

The cost-tower shape, which is borrowed. What flows through it here is not what flows through it there.

What it stands on

The analogy holding well enough to be useful, which it does for traceability and does not for fungibility. The boundary is stated with the source above.

The arithmetic. Defensive weight as criticality multiplied by exposure, coverage as a weighted average of the towers protecting a mission, residual risk as its inverse, and the per-form weighting used to score a design.

Nearest inherited thing

Nothing. No cited source supplies these numbers, and none of them is a measurement of the world.

What it stands on

Nothing but internal consistency, and it should be read that way. These are ranking devices for comparing options within one estate. They are not risk quantification, they do not carry across agencies, and the per-form weighting in particular is a framework contract number that has already been misread once as a technique count.

The six-step operating cycle as a named loop — frame, map, array, maneuver, fuse, assess — with entry and exit criteria for each step.

Nearest inherited thing

The four-part analytic process, which is inherited and which each step is mapped back onto explicitly.

What it stands on

The claim that a step you cannot tell you have finished is not a step. The exit criteria are the test, and they are written to be capable of failing.

The Federal Reference Agency: a composite public-facing agency with a filing portal, a case-processing estate, bulk public data and a fee operation, used throughout as the worked example.

Nearest inherited thing

Nothing. It is a construct, invented so the framework can be shown working on something concrete.

What it stands on

Its usefulness as an illustration. It is not a model of any particular agency, and no finding stated against it is a finding about a real estate.

Every threshold: the tempo numbers, the capability scale, the protection floors, and the measures of performance and effectiveness that report against them.

Nearest inherited thing

The doctrinal insistence that tempo decides the outcome, which supplies the question but not a single number.

What it stands on

Being starting values an agency is expected to replace with its own, once it has measured itself. A threshold adopted unchanged from this framework has not yet been calibrated to anything.

Limits of This Provenance

What Citing a Document Does Not Buy.

Provenance is a claim about origin, and origin is easy to overread. These are the limits of what the page above establishes — stated here rather than in a footer, because they are load-bearing.

  1. This is not a government publication.

    It is an unclassified reference framework published by a private steward. Nothing in it has been adopted, reviewed, or endorsed by any agency, department, or standards body, and citing a document here creates no relationship with the body that issued it.

  2. Citation is not endorsement, in either direction.

    Naming a publication states where an idea came from. It does not imply that the publication’s issuer agrees with what was done to the idea afterwards — and several of the boundaries above exist precisely because it would not.

  3. Everything here is built from public material.

    No non-public information about any agency’s posture, architecture or incidents was used. The worked example is a composite, and every number attached to it is illustrative.

  4. Doctrine and federal policy are revised; this framework is a snapshot.

    Where a cited publication has since moved on, it is this framework that is out of date, not the source. A reader with a current edition in front of them should trust the edition.

  5. Lineage is not compliance.

    A control that names its 800-53 ancestors has stated where it comes from, not that implementing it satisfies them. An assessor tests controls against the agency’s own authorized baseline, and this framework does not stand in for that baseline.

  6. Analogy is the framework’s method and its largest risk.

    Land-warfare doctrine earns its place by producing better questions, not because a network is a battlefield. Where the metaphor stops carrying weight, the framework should give way — the glossary’s “not to be confused with” entries are where that boundary is drawn, and they are the honest part of the vocabulary.

ASOM-Fed is published unclassified by a private steward as a reference framework. It is not a government publication, carries no endorsement from any agency, department or standards body, and is not a substitute for any authority it cites.

Elsewhere in the Apparatus

Where the Inheritance Is Visible in Use.