ASOM-Fedv6.1Open the explorer
Reference manual · analytic overlays

The Clock Is the Measure. Here Is How It Is Read.

Temporal advantage is this framework’s decisive measure of effectiveness, and the only one it publishes that can be honestly lost: the defender’s decision loop, measured, against the adversary’s dwell, estimated, as a ratio with a declared threshold. Everything below is how each half of that ratio is produced, what a deficit obliges, and which of the 154 cataloged techniques move it at all — 56 of them, on the framework’s own reckoning.

Illustrative · not an assessment

The model is real. The reading is an archetype’s, and no agency was measured to produce it.

The measurement definitions, the ratio and the controls are the framework as published. The numbers in the worked reading — 14 days of loop against a 21-day dwell estimate — belong to the Federal Reference Agency, the same illustrative estate at the same maturity as the coverage baseline and the case studies.

They are consistent with that baseline by construction rather than by coincidence: an agency that scores almost nothing on deception and delay has no mechanism to shorten detection or to lengthen dwell, and this reading is what that looks like when it is timed. Do not use it as a benchmark — a loop time borrowed from an archetype is exactly the kind of unsourced number the dwell rules below warn against.

1.5×Temporal advantageAgainst a declared threshold of 3× — a deficit
14 daysDefender decision loopDetect 11d · decide 2.4d · contain 0.6d
56Cells that move the clockOf 154 cataloged — 3 validated on this baseline
5Controls that govern tempoTA-1 through TA-5
The Metric

Adversary Dwell, Divided by Defender Loop.

Two quantities of different kinds: one measured from the agency’s own records, one estimated from intelligence with a stated basis. Keeping them apart is what makes the ratio arguable — a reader can reject the numerator without rejecting the measurement.

Temporal advantage is adversary dwell divided by defender loop. Above 1, the loop closes inside the adversary’s budget; below 1, the adversary finishes first in the median case. The threshold is where the agency decides how much margin it needs above 1, and a reading below the threshold is a deficit whether or not anything has yet gone wrong.

21dAdversary dwell · estimated

Sector reporting for credential-driven intrusion against civilian federal records estates, moderate confidence, revised this cycle.

14dDefender loop · measured

Detect, decide and contain, summed. Measured from the cycle’s closed incidents rather than from a target.

3×Declared threshold

Set by the Authorizing Official against the defensive intent: containment must complete well inside the adversary’s expected budget, because a ratio near 1 means the median case is a coin toss and the worst case is a loss.

The Denominator

Three Segments, Each with a Start Point That Has to Be Defensible.

Almost every dishonest tempo number comes from moving a start point rather than from arithmetic. Each segment below carries the specific way it gets flattered, because naming the counterfeit is the only reliable defense against it.

Detect

Starts. The first observable the adversary generated that the agency’s own telemetry recorded — whether or not anybody looked at it at the time.

Stops. An analyst holds a finding that names the activity as hostile, at a stated confidence.

Made of. Time the evidence sat in a log nobody queried. On an estate that detects by signature, this segment is measured in weeks, and almost none of it is analysis.

Shortened by. Deception, because a decoy interaction has no benign explanation and needs no baseline to be believed; and behavioral baselining on the identity plane, because it converts a legitimate-looking action into a deviation.

Counterfeit. Starting the clock at alert triage rather than at first observable. That measures how fast the SOC works on what it was handed, and says nothing about the fortnight before it was handed anything.

Decide

Starts. The finding exists and is attributable to a named owner.

Stops. A containment action is authorized — not taken, authorized.

Made of. Waiting on authority. Where the action is outside the pre-authorized set this segment is an escalation queue, and its length is a property of the rules of engagement rather than of the analysis.

Shortened by. Pre-authorization. Settling in advance which actions may be taken without asking removes the queue from the critical path, and it is the cheapest hour on the whole loop to buy.

Counterfeit. Recording the decision timestamp as the moment the approver replied, when the request had been waiting since the previous evening. The gap between decision and effect is where authority latency hides.

Contain

Starts. The action is authorized.

Stops. The adversary’s access to the affected terrain is actually severed — verified, not requested. A revocation that a live session survives has not stopped this clock.

Made of. Whether the action is one system or forty. Isolating a host is minutes; revoking a token estate-wide, or severing a segment, is only fast if it was built to be.

Shortened by. Isolation and retrograde capability — the ability to fail a service secure, sever a segment or quarantine an account as a single deliberate action rather than as a project.

Counterfeit. Stopping the clock when the containment ticket closes. The measurement is the adversary’s loss of access, and the two are the same thing only when somebody checked.

The Numerator

An Estimate That Has to Carry Its Basis with It.

The elapsed time an adversary of the relevant class expects to hold access before being evicted — the budget they plan against. It is the numerator of the ratio, it is an estimate rather than a measurement, and it has to carry its basis with it.

Exhibit 1

Three Bases for a Dwell Estimate, and What Each One Gets Wrong

BasisWhat it is good forWhere it misleads
The agency’s own closed incidentsDirectly relevant, and the only basis derived from this estate’s actual ground. Reconstructing dwell after the fact is itself a cataloged technique.Survivorship. It measures the adversaries who were caught, which biases the estimate toward the fast and clumsy ones and says nothing about the patient one still resident.
Sector and government reportingCovers adversaries this agency has not yet met, and is the basis a reviewer can check independently.Aggregated across estates that do not resemble this one. A civilian records agency and an operational-technology-heavy one do not share a dwell profile.
Intelligence assessment of a named campaignSpecific to the adversary the intelligence requirements actually name, which is the only kind of specificity the threshold can be defended with.Perishable and confidence-bearing. Used without its confidence level it becomes a precise number resting on a judgment nobody restated.

The agency’s own closed incidents

What it is good for
Directly relevant, and the only basis derived from this estate’s actual ground. Reconstructing dwell after the fact is itself a cataloged technique.
Where it misleads
Survivorship. It measures the adversaries who were caught, which biases the estimate toward the fast and clumsy ones and says nothing about the patient one still resident.

Sector and government reporting

What it is good for
Covers adversaries this agency has not yet met, and is the basis a reviewer can check independently.
Where it misleads
Aggregated across estates that do not resemble this one. A civilian records agency and an operational-technology-heavy one do not share a dwell profile.

Intelligence assessment of a named campaign

What it is good for
Specific to the adversary the intelligence requirements actually name, which is the only kind of specificity the threshold can be defended with.
Where it misleads
Perishable and confidence-bearing. Used without its confidence level it becomes a precise number resting on a judgment nobody restated.
Authored guidance, not published data. The control that governs it is TA-2 Adversary Dwell Estimation, which requires the basis to be recorded alongside the number.
Worked

One Cycle, Read End to End.

Held as three segment measurements. Every other figure in this section — the shares, the ratio, the shortfall, the counterfactual — is arithmetic on those three, so none of them can drift from the measurement they describe.

Exhibit 2

The Defender Decision Loop, by Segment

  • Detect11 days · 78.6%

    Median across the cycle’s closed incidents, clocked from first recorded observable. The estate detects by signature and by third-party notification; nothing on it is designed to make an adversary announce themselves.

  • Decide2.4 days · 17.3%

    Dominated by two escalations that crossed a weekend. The pre-authorized set covers host isolation and little else, so anything touching identity or a shared service waits for the Authorizing Official.

  • Contain0.6 days · 4.2%

    Fast where the action is host isolation, slow where it is estate-wide session revocation — which on this estate is a sequence of manual steps rather than one action.

Illustrative Federal Reference Agency archetype. The bar is decoration — every hour and every share it draws is printed beneath it.
1.5×
The computation
504 hours of estimated dwell ÷ 336 hours of measured loop = 1.5×, against a declared threshold of 3×. That is a deficit of 1.5.
What closing it would take
Holding the dwell estimate fixed, the loop would have to fall to 7 days — from 14. That is not a tuning exercise; it is a different detection posture.
The counterfactual worth doing
Pre-authorization is the cheapest hour on this loop to buy. Remove the decide segment entirely — every containment action authorized in advance — and the ratio moves to 1.8×. Still a deficit. Detection is 78.6% of this loop, and that is where the deficit lives.

Which is exactly what the coverage baseline predicts. The forms that shorten detection are deception and screening; the forms that lengthen dwell are delay and isolation. On this estate M5, M6, M7 carry the most clock-moving cells — M5 at 11.1%, M6 at 11.1%, M7 at 27.8% supplied. A program cannot buy tempo out of the segment that is already fast.

Deficit

What Being Behind Obliges.

A deficit is a reportable condition, not a bad quarter. The distinction is the whole reason tempo is a control family rather than a dashboard tile: a metric with no escalation consequence is a statistic.

It is a reportable condition, in the cycle it occurs.

A deficit that is noticed and absorbed inside the SOC is indistinguishable from one that was never measured. The control makes it travel to the authority that can fund or accept it.

The threshold does not move.

Adjusting the threshold to clear the deficit converts the metric into a description of current performance, which is precisely what it was built not to be. The defense changes or the risk is accepted explicitly.

It ranks the backlog.

A deficit is an argument for the specific cells that shorten the loop or lengthen dwell, ahead of work that improves neither. It is the framework’s answer to "everything is a priority".

It bounds what may be planned.

A branch that assumes containment inside four hours is not executable by a program whose measured loop is two weeks. The deficit is what makes that visible before the branch is needed rather than during it.

It is a trend, not a verdict.

One cycle is noise. The direction across cycles is the signal, and a program in deficit that is closing is in a different position from one in deficit that is widening.

Where a Deficit Actually Goes

Not asserted here — read off TA-3’s own declared outputs, so this page and the control sheet cannot disagree about where the finding travels.

Governance

The Five Controls That Make Tempo a Control Rather Than a Chart.

Every metric in this family is capable of reporting that the defender is behind. A tempo family whose numbers only ever improve is measuring activity, and the counts beside each control below say how much of the clock-moving catalog it actually reaches.

TA-1
Decision Loop Measurement7 clock-moving techniques name it

To make the defender's tempo a measured quantity rather than an impression, so that the numerator of temporal advantage exists at all.

Requires The organization shall measure the elapsed time from detection through decision to containment, and shall record it each cycle.

TA-2
Adversary Dwell Estimation1 clock-moving technique name it

To establish the denominator of temporal advantage with an explicit, challengeable basis, so the comparison the framework rests on can be argued with.

Requires The organization shall maintain a documented estimate of adversary dwell time relevant to its threat profile, with a stated basis.

TA-3
Temporal Advantage Threshold1 clock-moving technique name it

To convert the temporal advantage figure into a governed condition with an escalation consequence, so that being behind is a decision the organization has to make rather than a number it can note.

Requires The organization shall define the minimum acceptable ratio of adversary dwell to defender decision loop, and shall treat a deficit as a reportable condition.

TA-4
Pre-authorized Response17 clock-moving techniques name it

To remove authority latency from the decision loop, so that the segment most programs cannot shorten with tooling is shortened by governance.

Requires Defensive actions that may be executed without escalation shall be defined in advance and approved by the accountable authority.

TA-5
Tempo Degradation Trigger7 clock-moving techniques name it

To plan for the periods in which tempo predictably falls, so that the measured advantage is not a statement about the organization's best hours only.

Requires Conditions under which the defender decision loop is expected to degrade shall be identified, with compensating measures defined.

The lopsidedness is the finding. TA-4 Pre-authorized Response is named by 17 of the clock-moving techniques — more than any other control in the family — because pre-authorization is what converts a capability into one that can be used inside the loop rather than after it.

What Moves the Clock

Only Two Things Change the Ratio.

Get faster, or make the adversary slower. The published tempo overlay marks the cells that do either, and it is a selection rather than a judgment of the rest — the 98 techniques it does not name are necessary, they are simply not what wins the clock.

Temporal advantage is the defender detect→decide→contain tempo measured against adversary dwell. Only two things move it: getting faster, or making the adversary slower. These are the cells that do either. Everything else in the matrix is necessary, but it is not what wins the clock.

ASOM-Fed Defensive Maneuver Framework v6.1 · overlay “Temporal advantage
21Shortens the defender loop — detect and decide

1 validated, 7 partial, 13 absent — 21.4% supplied.

19Lengthens the adversary loop — delay and friction

1 validated, 8 partial, 10 absent — 26.3% supplied.

16Both — the highest-leverage cells

1 validated, 5 partial, 10 absent — 21.9% supplied.

Exhibit 3

Clock-Moving Cells by Form of Maneuver, and What This Baseline Supplies

FormWhich way it moves the clockWhat the baseline supplies
M1 Screen / Guard6 of the form’s 15 techniques move the clock6 shorten the loop
41.7%1 validated, 3 partial, 2 absent
M2 Defense in Depth1 of the form’s 18 techniques move the clock1 shorten the loop
0%0 validated, 0 partial, 1 absent
M3 Envelopment4 of the form’s 20 techniques move the clock2 shorten the loop · 2 both
37.5%0 validated, 3 partial, 1 absent
M4 Obstacle / Canalization5 of the form’s 17 techniques move the clock5 slow the adversary
50%1 validated, 3 partial, 1 absent
M5 Ambush9 of the form’s 13 techniques move the clock7 shorten the loop · 2 both
11.1%0 validated, 2 partial, 7 absent
M6 Delay9 of the form’s 10 techniques move the clock6 slow the adversary · 3 both
11.1%0 validated, 2 partial, 7 absent
M7 Counterattack9 of the form’s 17 techniques move the clock5 shorten the loop · 4 both
27.8%1 validated, 3 partial, 5 absent
M8 Isolation / Retrograde7 of the form’s 17 techniques move the clock2 slow the adversary · 5 both
14.3%0 validated, 2 partial, 5 absent
M9 Spoiling Attack4 of the form’s 9 techniques move the clock4 slow the adversary
25%0 validated, 2 partial, 2 absent
M11 Reconstitution2 of the form’s 11 techniques move the clock2 slow the adversary
0%0 validated, 0 partial, 2 absent

M1 Screen / Guard

6 of the form’s 15 techniques move the clock

Which way it moves the clock
6 shorten the loop
What the baseline supplies
41.7%1 validated, 3 partial, 2 absent

M2 Defense in Depth

1 of the form’s 18 techniques move the clock

Which way it moves the clock
1 shorten the loop
What the baseline supplies
0%0 validated, 0 partial, 1 absent

M3 Envelopment

4 of the form’s 20 techniques move the clock

Which way it moves the clock
2 shorten the loop · 2 both
What the baseline supplies
37.5%0 validated, 3 partial, 1 absent

M4 Obstacle / Canalization

5 of the form’s 17 techniques move the clock

Which way it moves the clock
5 slow the adversary
What the baseline supplies
50%1 validated, 3 partial, 1 absent

M5 Ambush

9 of the form’s 13 techniques move the clock

Which way it moves the clock
7 shorten the loop · 2 both
What the baseline supplies
11.1%0 validated, 2 partial, 7 absent

M6 Delay

9 of the form’s 10 techniques move the clock

Which way it moves the clock
6 slow the adversary · 3 both
What the baseline supplies
11.1%0 validated, 2 partial, 7 absent

M7 Counterattack

9 of the form’s 17 techniques move the clock

Which way it moves the clock
5 shorten the loop · 4 both
What the baseline supplies
27.8%1 validated, 3 partial, 5 absent

M8 Isolation / Retrograde

7 of the form’s 17 techniques move the clock

Which way it moves the clock
2 slow the adversary · 5 both
What the baseline supplies
14.3%0 validated, 2 partial, 5 absent

M9 Spoiling Attack

4 of the form’s 9 techniques move the clock

Which way it moves the clock
4 slow the adversary
What the baseline supplies
25%0 validated, 2 partial, 2 absent

M11 Reconstitution

2 of the form’s 11 techniques move the clock

Which way it moves the clock
2 slow the adversary
What the baseline supplies
0%0 validated, 0 partial, 2 absent
Illustrative supply Cell counts and direction from the published tempo overlay; supply from the coverage grading on the baseline. Forms the overlay names no tempo cell for are omitted — currently M10.

Across all 56 clock-moving cells the reference agency holds 3 validated and 20 partial, for 23.2% supplied. That figure, not the tooling budget, is why the loop in the worked reading is 14 days long.

Counterfeits

Things That Look like Tempo Improvement and Are Not.

Each of these moves a number that gets reported. None of them moves the ratio, and two of them make it worse while appearing to help.

Both Directions at Once

The 16 highest-leverage cells.

These shorten the defender’s loop and lengthen the adversary’s in the same move, which is what makes them worth more than the sum of two cells that each do one. On this baseline 10 of them are absent.

New to this vocabulary? Form of maneuver, technique, control and posture are different classes of thing, and swapping two of them produces work that looks correct and decides nothing. The object model states each one with the question it answers and the class it is most often mistaken for.

Where This Goes

A Clock Is Only Meaningful Against Somebody.