Ten Layers, and the Model That Adds Them Up.
The terrain model says where things sit. The Defense Tower Model says what that is worth: every asset carries a defensive weight, every sub-tower carries a maturity, and the two roll up into a coverage figure and a residual risk for each mission the agency runs. This is the reference treatment of both — each layer in full, and the arithmetic that joins them, stated so it can be checked rather than believed.
Seven Questions, Answered in the Same Order Every Time.
The control sheets in this manual answer six questions per control. A layer entry answers seven, and the fourth is the one that carries the weight: a maturity rung is meaningless as a global adjective and useful only when someone has said what it looks like on this specific sub-tower.
The ground, and why that ground
The doctrinal metaphor stated as a claim about the terrain’s properties — not as decoration, because a reader will reason from it.
Key terrain
What confers decisive advantage on this layer if you hold it, each item with the reason it qualifies.
The decisive point
The narrower question: where seizing control unhinges the adversary’s plan, and why that point rather than a neighboring one.
Sub-towers, rung by rung
What Traditional, Initial, Advanced and Optimal actually look like on that specific sub-tower, with the observable that tells you which one you are on.
Weight and residual risk
How criticality and exposure behave on this ground, and the arithmetic that turns maturity into coverage and coverage into a ranked backlog.
Maneuvers and controls
Which forms of maneuver consume the layer — derived from the catalog — and which controls act on it, linked into the control reference.
Why the layer exists
For the four layers ASOM-Fed added: the objection stated at its strongest, the answer, and what the layer does not fix.
Every Layer, with What It Is Currently Worth.
The coverage and weight beside each layer are computed from the illustrative maturity of its sub-towers on the Federal Reference Agency profile — a plausible mid-adoption civilian agency. They are there to show the arithmetic working end to end, not to describe any real estate. An adopter replaces them with their own assessment and the numbers recompute.
In zero trust, whoever controls identity controls movement. Every other layer is downstream of this one, which is why it is almost always the main effort.
Decisive pointThe conditional-access policy engineIllustrative58.1% coverage · weight 77 · residual 32.3 points- CISA ZTMM pillar
- Authentication (phishing-resistant MFA)
- Authorization / PDP
- Privileged Access (JIT/PAM)
- Identity Governance (ICAM)
Where an adversary crosses from outside to inside. Managed and unmanaged endpoints are not the same ground, and a framework that scores them together hides the crossing.
Decisive pointThe device-posture signal the policy engine trustsIllustrative57.9% coverage · weight 63 · residual 26.5 points- CISA ZTMM pillar
- Endpoint Protection (EDR)
- Device Compliance / Posture
- Mobile & BYOD
- Server / Workload Hardening
Movement corridors and the obstacles that canalize them. This is the layer where you decide which ground the adversary is allowed to walk on.
Decisive pointThe east-west boundary between the public tier and the mission tierIllustrative63.2% coverage · weight 76 · residual 28 points- CISA ZTMM pillar
- Perimeter / TIC 3.0
- Microsegmentation
- Egress & DNS Control
- WAF & DDoS
Dense, complex, and hard to clear — the layer where defenders lose track of what they own. It also holds the single most leveraged decisive point in a modern estate.
Decisive pointThe CI/CD pipeline — poisoning it envelops everything downstreamIllustrative50% coverage · weight 68 · residual 34 points- CISA ZTMM pillar
- AppSec (SAST / DAST)
- API Security
- Pipeline Security (CI/CD)
- Runtime & Container
The reason the campaign exists. Every other layer is defended in order to hold this one, and a scheme that cannot say which records it is protecting is not a scheme.
Decisive pointThe data-access governance boundary around the crown-jewel record setIllustrative49.6% coverage · weight 66 · residual 33.3 points- CISA ZTMM pillar
- Classification
- Encryption & Key Management
- DLP
- Data Access Governance
Scored separately because the moves available here are narrower and the consequence of loss is physical. Treating an OT estate as ordinary network terrain overstates the defender’s options.
Decisive pointThe OT/IT boundary and the accounts permitted to cross itIllustrative33.5% coverage · weight 59 · residual 39.3 points- Added v2.0
- OT Asset Inventory
- OT / IT Boundary
- Engineering Access
- Passive OT Monitoring
The only layer that is simultaneously the ground being defended and the force doing the defending. Insider risk and analyst saturation are the same measurement problem seen from two directions.
Decisive pointThe register of who holds privilege, and how fast it is revoked when they leaveIllustrative44.9% coverage · weight 59 · residual 32.5 points- Added v3.0
- Privileged Human Register
- Role-Based Readiness
- Insider Risk Position
- Separation Tempo
A federal estate with data centers, laboratories and public counters has physical ground that a purely logical model scores as though it were not there.
Decisive pointVendor and maintenance access to space holding production systemsIllustrative40.5% coverage · weight 42 · residual 25 points- Added v3.0
- Facility Inventory
- Physical Zone Boundary
- Maintenance Access
- Environmental Continuity
Doctrinally, an army’s lines of communication are terrain an enemy attacks precisely because they are not defended like the front. Software supply chain is the same idea with a different noun.
Decisive pointThe staging gate an untrusted update must pass before it reaches productionIllustrative44.4% coverage · weight 72 · residual 40 points- Added v3.0
- Supplier Register
- Component Provenance
- Access Constraint
- Update Staging
Not ground, but what makes maneuver on the other nine possible: reconnaissance, mobility, and command authority. Scored as enablers rather than as terrain with a coverage gap.
Decisive pointWhich defensive fires are pre-authorized without escalationIllustrative56.8% coverage · weight 37 · residual 16 points- CISA ZTMM pillar
- Visibility & Analytics (ISR)
- Automation & Orchestration (mobility)
- Governance (command authority)
Coverage Flows Upward, and so Does What Is Missing.
The model borrows a shape from IT financial management, where cost is allocated from pools through towers to the business units that consume it, so a unit’s bill can be traced back to the spend that produced it. Here the thing that flows is defensive coverage, and the useful half is the inverse: residual risk, traced from an exposed mission back to the asset exposing it.
The Four-Layer Allocation
Asset pools
Assets grouped by nature — the sources of both coverage and exposure. Every asset carries a defensive weight of criticality times exposure, 1 to 25.
Weight allocates upward: criticality × exposure, 1–25 per asset
Defense towers
The terrain layers as towers, each divided into sub-towers. Maturity on a sub-tower converts to a coverage percentage, which is what the weight below is allocated against.
Each maneuver consumes named towers, so a tower gap reaches a mission
Maneuver solutions
Maneuvers are the solutions layer: they consume tower capability to produce a defensive outcome. A scheme of maneuver is a bundle of them serving one mission.
Coverage rolls up as a weighted mean; the inverse is residual risk
Mission consumers
The agency mission services that consume defense. Each one receives a Bill of Defense: what protects it, its rolled-up coverage, and the residual risk left over.
The Allocation Driver
Every asset carries a defensive weight of criticality × exposure, each scored 1 to 5, giving a range of 1 to 25. Weight is what the model allocates with: a sub-tower’s coverage is credited against the weight it protects, a layer’s coverage is the weighted mean of its sub-towers, and a mission’s coverage is the weighted mean of the layers it draws on. Nothing is a flat average anywhere, because a flat average is how a critical gap disappears behind three well-covered peripheral ones.
The two axes have to be scored against stated anchors or they drift into a general sense of importance. The anchors used throughout this reference:
| Score | Axis | What that score asserts |
|---|---|---|
| 1 | Criticality | Loss is an inconvenience to a single team. No mission service degrades. |
| 3 | Criticality | A mission service degrades or a statutory timeline is put at risk. |
| 5 | Criticality | A mission service stops, or the crown-jewel record set is exposed. |
| 1 | Exposure | Reachable only from an administrative path by a named, small population. |
| 3 | Exposure | Reachable by any authenticated staff identity, or by a supplier under contract. |
| 5 | Exposure | Reachable from the public internet, or by an unmanaged device, or by an unbounded population. |
1
- Axis
- Criticality
- What that score asserts
- Loss is an inconvenience to a single team. No mission service degrades.
3
- Axis
- Criticality
- What that score asserts
- A mission service degrades or a statutory timeline is put at risk.
5
- Axis
- Criticality
- What that score asserts
- A mission service stops, or the crown-jewel record set is exposed.
1
- Axis
- Exposure
- What that score asserts
- Reachable only from an administrative path by a named, small population.
3
- Axis
- Exposure
- What that score asserts
- Reachable by any authenticated staff identity, or by a supplier under contract.
5
- Axis
- Exposure
- What that score asserts
- Reachable from the public internet, or by an unmanaged device, or by an unbounded population.
Scores of 2 and 4 interpolate. The anchors deliberately describe consequences rather than asset classes, because an asset class is not a risk — the same database is a 5 in one agency and a 2 in another, and a weighting scheme that cannot express that is measuring the technology rather than the mission.
Four Rungs, Carried Verbatim from CISA, Converted to a Percentage.
The rungs are the Zero Trust Maturity Model’s own, unrenamed, so an agency reporting maturity under OMB M-22-09 reports the same rung here. The conversion to a percentage is the tower model’s convention and it is a convention, not a measurement — it exists so that a qualitative judgment can be weighted and summed.
| Rung | Coverage credited | What the rung asserts | How it is usually overstated |
|---|---|---|---|
| Traditional | 25% | Manual, static, and evaluated once rather than continuously. | Reported as Initial because a tool has been purchased. A tool that is deployed but not enforcing is Traditional. |
| Initial | 50% | Automated in places, with the estate’s hard cases handled by exception. | Reported as Advanced by counting the estate the automation covers and excluding the estate it does not. |
| Advanced | 75% | Centrally enforced across the whole layer, with the exceptions named and owned. | Claimed with a standing exception list that has no owners and no expiry, which is the same as no enforcement. |
| Optimal | 100% | Continuous, dynamic, and measured against adversary tempo rather than against a policy. | Claimed on the strength of a capability that exists but has never been exercised. Optimal rungs in this reference generally require the rehearsal, not the mechanism. |
Traditional
- Coverage credited
- 25%
- What the rung asserts
- Manual, static, and evaluated once rather than continuously.
- How it is usually overstated
- Reported as Initial because a tool has been purchased. A tool that is deployed but not enforcing is Traditional.
Initial
- Coverage credited
- 50%
- What the rung asserts
- Automated in places, with the estate’s hard cases handled by exception.
- How it is usually overstated
- Reported as Advanced by counting the estate the automation covers and excluding the estate it does not.
Advanced
- Coverage credited
- 75%
- What the rung asserts
- Centrally enforced across the whole layer, with the exceptions named and owned.
- How it is usually overstated
- Claimed with a standing exception list that has no owners and no expiry, which is the same as no enforcement.
Optimal
- Coverage credited
- 100%
- What the rung asserts
- Continuous, dynamic, and measured against adversary tempo rather than against a policy.
- How it is usually overstated
- Claimed on the strength of a capability that exists but has never been exercised. Optimal rungs in this reference generally require the rehearsal, not the mechanism.
Credited coverage of 100% is not an assertion that a layer is safe. It says the sub-tower is at the top of the maturity scale the framework can measure, which is a statement about the defense’s construction and not a prediction about its outcome. Residual risk is reported in weight points alongside the percentage for exactly this reason.
Pick a Mission and See What Defends It. Pick an Asset and See What It Defends.
Traceability in one direction is a report. In both directions it is an argument a reviewer can attack, which is the point: an agency Inspector General asking why a mission is exposed should be able to walk the chain to a named asset, and a platform owner asking why their remediation matters should be able to walk it the other way.
From a Mission to the Ground
A mission consumer draws on named layers at stated weights. Each layer’s coverage comes from its sub-towers, each sub-tower’s maturity comes from an assessment with an observable behind it, and each observable is produced by an asset somebody owns. Four steps, and every one of them has a name attached.
From an Asset to the Mission
An asset’s weight allocates into its sub-tower, its sub-tower into a layer, and the layer into every mission that draws on it. This is the direction that answers “why is this worth funding”, and it is the direction a remediation backlog is built from: weight multiplied by coverage gap, ranked.
The trace is only as honest as the overlay under it, which is why terrain currency (TM-6) is a control rather than a practice. A rollup computed from a six-month-old overlay is arithmetic performed on a memory.
What Each Mission Is Actually Being Defended By.
The per-mission statement: which layers defend it, at what weight, what that rolls up to, and what is left over. Residual risk is given in weight points as well as a percentage, because the percentage alone flatters the missions with the most weight — 47% residual on a weight of 127 is not the same finding as 47% on a weight of 66.
| Mission consumer | Total weight | Rolled-up coverage | Residual risk | Heaviest dependency |
|---|---|---|---|---|
| Public service deliveryThe public service portal and external-user accounts | 118 | 53.7% | 46.3% · 54.7 points | T1 Identity (weight 25) |
| Case processing and adjudicationThe case processing system and mission-staff workflow | 127 | 52.4% | 47.6% · 60.5 points | T5 Data (weight 25) |
| Administrative adjudicationThe administrative adjudication and e-filing systems | 98 | 53.2% | 46.8% · 45.9 points | T1 Identity (weight 20) |
| Secondary public serviceAdditional public service lines and secondary portals | 75 | 54.4% | 45.6% · 34.2 points | T4 Applications and Workloads (weight 16) |
| Public data servicesBulk data and open API surfaces | 66 | 53.7% | 46.3% · 30.6 points | T4 Applications and Workloads (weight 20) |
| Fee and financial operationsFee, payment and financial data systems | 127 | 52.2% | 47.8% · 60.8 points | T1 Identity (weight 25) |
Public service delivery
The public service portal and external-user accounts
- Total weight
- 118
- Rolled-up coverage
- 53.7%
- Residual risk
- 46.3% · 54.7 points
- Heaviest dependency
- T1 Identity (weight 25)
Case processing and adjudication
The case processing system and mission-staff workflow
- Total weight
- 127
- Rolled-up coverage
- 52.4%
- Residual risk
- 47.6% · 60.5 points
- Heaviest dependency
- T5 Data (weight 25)
Administrative adjudication
The administrative adjudication and e-filing systems
- Total weight
- 98
- Rolled-up coverage
- 53.2%
- Residual risk
- 46.8% · 45.9 points
- Heaviest dependency
- T1 Identity (weight 20)
Secondary public service
Additional public service lines and secondary portals
- Total weight
- 75
- Rolled-up coverage
- 54.4%
- Residual risk
- 45.6% · 34.2 points
- Heaviest dependency
- T4 Applications and Workloads (weight 16)
Public data services
Bulk data and open API surfaces
- Total weight
- 66
- Rolled-up coverage
- 53.7%
- Residual risk
- 46.3% · 30.6 points
- Heaviest dependency
- T4 Applications and Workloads (weight 20)
Fee and financial operations
Fee, payment and financial data systems
- Total weight
- 127
- Rolled-up coverage
- 52.2%
- Residual risk
- 47.8% · 60.8 points
- Heaviest dependency
- T1 Identity (weight 25)
Two honest notes on this table. First, the figures are illustrative, computed from the reference profile’s maturity — the shape of the answer is the deliverable, not the numbers. Second, the maneuver trace is currently coarse: because four layers host no form of maneuver as their primary terrain, all eleven forms reach all six missions, and the trace differentiates missions by weight rather than by which maneuvers apply. That is a limitation of the catalog’s single-primary-terrain declaration, not a property of the missions.
Four Things It Will Not Tell You, Stated so Nobody Has to Discover Them.
A rollup that produces one number per mission invites more confidence than the inputs support. The limits below are structural rather than fixable, and an adopter who states them alongside the figures keeps the model’s credibility when the first figure turns out to be wrong.
It Does Not Predict Compromise
Coverage is a statement about how the defense is built, not about whether it will hold. A mission at 80% can be lost through the 20%, and the model’s own arithmetic says so — which is why residual risk is reported in points rather than being described as small.
It Inherits the Overlay’s Errors
Every figure is computed against the terrain overlay. An asset that is not on the overlay contributes no weight, so an incomplete overlay does not produce a lower score — it produces a higher one. This is the failure mode most likely to go unnoticed.
Maturity Is a Judgment
The conversion of a rung to a percentage is exact; the assignment of the rung is not. The observable stated on each sub-tower exists to constrain that judgment, and an assessment that cannot produce the observable should record the rung as unassessed rather than as the one it hopes for.
Enablers Are Not Added In
The cross-cutting layer bounds what the towers can do rather than contributing coverage to them. A mission with strong towers and Traditional automation cannot execute the maneuvers its coverage assumes, and no single number expresses that. Read TX before reading the towers.
On the illustrative profile, the heaviest residual risk in the model sits on T9 Supply Chain at 40 points — a layer that is not a CISA pillar at all, which is the clearest single argument for having added the four.
New to this vocabulary? Terrain layer, tower and tier are different classes of thing, and swapping two of them produces work that looks correct and decides nothing. The object model states each one with the question it answers and the class it is most often mistaken for.
The Layers Are the Ground. the Controls Are How You Prove You Hold It.
Every layer entry links into the control reference, where each control carries its statement, accountable role, inputs and outputs, activities, and assessment procedure.