ASOM-Fedv6.1Open the explorer
TA-4 · Tempo and Temporal Advantage

Pre-authorized Response

Control Statement

Defensive actions that may be executed without escalation shall be defined in advance and approved by the accountable authority.

Purpose. To remove authority latency from the decision loop, so that the segment most programs cannot shorten with tooling is shortened by governance.

Discussion

This is the highest-leverage control in the family and the cheapest to implement, because it costs no technology. TA-1's segment breakdown usually shows the decide segment dominating the loop, and decide latency is almost entirely the time spent locating someone with authority. Pre-authorization converts that from an incident-time search into a design-time decision. The constraint is that it must be genuinely bounded: an authority so broad that it permits degrading a public service without reference will not survive its first use, and one so narrow that every real action falls outside it changes nothing.

Goals and Metrics

A metric that cannot come out badly is not a metric. Each of these is capable of reporting that the control is not working.

A defined set of actions is pre-authorized and known to the operators.
  • Percentage of routine containment actions that are pre-authorized
  • Number of incidents in which containment waited on an authorization that could have been pre-granted

Accountability

Exactly one role is accountable, and every other role carries at least Informed — no control in the published catalog leaves a role with zero relationship to it. That is a stated property of how these were authored, not a coincidence, and not a claim that every role's work is worth equal attention here.

AOCTISOCHUNTPLATISSO
Authorizing Official / CISO: AccountableCyber Threat Intelligence cell: InformedSOC / Defensive Operations: ConsultedHunt team: InformedPlatform and product owners: InformedGovernance / RMF / ISSO: Consulted

AO Authorizing Official / CISOCTI Cyber Threat Intelligence cellSOC SOC / Defensive OperationsHUNT Hunt teamPLAT Platform and product ownersISSO Governance / RMF / ISSO

  • AccountableAuthorizing Official / CISO
  • InformedCyber Threat Intelligence cell
  • ConsultedSOC / Defensive Operations
  • InformedHunt team
  • InformedPlatform and product owners
  • ConsultedGovernance / RMF / ISSO

Inputs and Outputs

Consumes

Produces

Activities

  1. L2Define which defensive actions may be executed without escalation.
  2. L2Obtain the accountable authority's approval of that set.
  3. L2Link each pre-authorized action to the maneuvers it enables.
  4. L3Bound each authorization by condition, scope and duration, rather than by action type alone — "revoke sessions for a confirmed compromised account" is bounded; "revoke sessions" is not.
  5. L3Define the escalation matrix for actions outside the pre-authorized set, naming the authority and the reachable path to it at any hour.
  6. L3Key the pre-authorized set to campaign phase, so a declared Phase III widens what may be executed without reference.
  7. L3Rehearse the authority in exercise, confirming operators can state what they may do unaided.
  8. L4Measure the proportion of executed actions that fell inside the pre-authorized set, since a low proportion means the set is drawn in the wrong place.
  9. L4Measure decide-segment latency for pre-authorized versus escalated actions, so the control's contribution is quantified rather than assumed.
  10. L5Widen or narrow the set from observed use — actions repeatedly escalated and always approved are candidates for pre-authorization; actions pre-authorized and never used are candidates for removal.

Measurement

Outcome

Proportion of executed defensive actions falling inside the pre-authorized set.

Performance

Decide-segment latency for pre-authorized versus escalated actions.

Evidence and Assessment

Evidence expected

Approved rules of engagement with bounds; escalation matrix; rehearsal records; action logs referencing authorization.

Assessment procedure

Examine the approval; test that operators executed within authority during a recorded incident; interview operators on whether they believe the authority will be honored.

Related Guidance

Inherits
  • IR-4(2)
  • AC-2(13)
  • IR-9
Satisfies
  • RS.MA-01
  • RS.MI-01
  • GV.RR-01

Position in the Chain

Derived from the other controls’ own declarations, so the two directions cannot disagree.

Where This Control Is Used

Derived, in every case, from the declaration at the other end: the forms whose techniques name this control, the artifacts whose producing and consuming controls include it, the layers whose control lists name it, and the roles its own accountability chart puts to work. Nothing here is authored on this page, so the sheet cannot claim an edge the other end does not.

Forms of Maneuver It Assesses

  • M8Isolation / RetrogradeGive ground deliberately to preserve the force. Degrade gracefully; never fail open.5 of 17 techniques — M8.01, M8.02, M8.05, M8.06, M8.07
  • M7CounterattackSeize the initiative and evict before the adversary reaches the objective.4 of 17 techniques — M7.03, M7.04, M7.05, M7.17
  • M6DelayBuy decision time and prevent the adversary culminating on the objective.3 of 10 techniques — M6.02, M6.04, M6.05
  • M3EnvelopmentMake identity, not network location, the decisive plane — surround the adversary with policy.2 of 20 techniques — M3.03, M3.11
  • M9Spoiling AttackDisrupt adversary staging before the attack is launched.2 of 9 techniques — M9.01, M9.05
  • M1Screen / GuardGain early warning and buy reaction time before the adversary touches key terrain.1 of 15 techniques — M1.06
  • M5AmbushTrade space for information and time, and impose cost.1 of 13 techniques — M5.09

Terrain It Is Named On

  • T1IdentitySession and credential revocation is the archetypal pre-authorized response — its value is entirely in whether it can be executed without an escalation.
  • T3NetworksSevering a segment is a pre-authorized action or it is a forty-minute conference call. Which one it is decides whether M8 exists in this estate.
  • TXCross-CuttingPre-authorized response is where the ceiling on every contested maneuver is actually set.

Artifacts It Stands On

  • producesPre-authorized response setThe specific containment and response actions the SOC may execute at machine speed, bounded by the statutory availability floor. Directly measurable: it shortens the decision segment of the defender loop.
  • consumesThreat course-of-action sketchTwo courses of action, most likely and most dangerous, drawn against the decisive points already designated. Each is a route across ground the estate really has, not a category of threat.
  • consumesBranch and sequel planThe branches answer the most-dangerous course of action; the sequels answer success. Every one names the authority it needs, and any expected to run inside the decision window is pre-authorized when it is written.
  • consumesRules of engagementWhich defensive actions may be taken by whom without escalation, which need the Authorizing Official, and what is prohibited outright. The cyber analog of engagement authority, and the single largest determinant of tempo.
  • consumesChange recordEvery defensive action carried out, stamped twice — at the decision and at the effect. A thin, unglamorous table, and the one the headline metric is computed from.
  • consumesAuthority exception logActions taken outside the standing rules of engagement, with who approved them and why. Exceptions are not failures; unrecorded exceptions are.
  • consumesStatutory availability floorThe mission services whose availability is set by statute or regulation, and the floor below which degradation stops being a defensive choice. Bounds what may be pre-authorized and what may be degraded under contact.

Roles It Puts to Work