ASOM-Fedv6.1Open the explorer
T5 · CISA ZTMM pillar · The objective

Data

The reason the campaign exists. Every other layer is defended in order to hold this one, and a scheme that cannot say which records it is protecting is not a scheme.

The Ground

The objective.

The objective is the thing the operation exists to take or hold. Everything else in a scheme of maneuver is justified by reference to it, and a plan that cannot name its objective is not a plan — it is activity. Data is the objective in a federal estate: the records are what the adversary came for, and every other layer is defended in order to hold this one.

Naming data as the objective has an immediate practical consequence, which is the real reason the metaphor is here. It forces the question "which records?" to be answered before any prioritization is possible. An agency that cannot say which record set is the crown jewel cannot rank its backlog, because every weight in the model ultimately derives from proximity to this layer.

It also sets the terms of failure. Compromise of any other layer is recoverable in the sense that the ground can be retaken. Exfiltration of the objective is not: the records are copied, the copy is outside the estate, and no subsequent defensive action changes that. This asymmetry is why detection tempo on this layer is worth more than prevention depth on most others.

Origin

A CISA Zero Trust Maturity Model pillar, carried with its name and boundary unchanged so an agency reporting maturity under OMB M-22-09 reports the same rung here.

Asset pools feeding it
  • Data assets — sensitive mission records, PII stores, fee and financial data, mission-staff work product, audit logs, and every copy of these in analytic and non-production environments

Key Terrain

Key terrain is what confers decisive advantage if you hold it. Everything else on this layer is defended in order to hold these.

  • Sensitive mission recordsOften pre-decisional and non-public. This is what a nation-state collector comes for, and the one holding that cannot be un-lost.
  • PII storesThe statutory exposure. Loss triggers obligations that run on a clock the agency does not control.
  • Fee and financial dataThe fraud target. Attacked continuously at low intensity by a different adversary class than the records are.
  • Copies, extracts and analytic environmentsThe crown-jewel record set as it exists in three other places with a fraction of the controls. Usually the actual location of the loss.
  • Audit logsData that is also evidence. Its integrity determines whether anything else on this list can be reconstructed after an incident.

The Decisive Point

The data-access governance boundary around the crown-jewel record set

The decisive point is the data-access governance boundary around the crown-jewel record set — the mechanism that decides which identities may read the records in volume, and leaves a record of who did.

It is decisive because it is the last point at which the defense still has agency. Encryption protects records from someone without a key; classification tells you which records matter; neither of them constrains an authorized identity reading at scale, and an authorized identity reading at scale is what almost every serious loss looks like from the inside.

Holding it also changes what detection on this layer can do. Where bulk access is brokered and logged, a decoy record (M5) and a volume threshold both become usable triggers with a tolerable false-positive cost. Where it is not, the same detections drown in legitimate query traffic, and the agency ends up monitoring mail because mail is the path it can see.

Sub-Towers, Rung by Rung

Maturity is scored here, not on the layer. Each rung below is stated for this sub-tower specifically — “Advanced” means something testable on each one, and something different on each one. The rung marked current is the illustrative position on the Federal Reference Agency profile.

Classification

Knowing which data is which, at a granularity that a control can act on.

  • Criticality 5
  • Exposure 3
  • Weight 15
  • Illustrative rung Initial · 50%
Traditional25% coverage

Sensitivity is known informally by the teams that own the data. There are no labels, and controlled unclassified information is identified on documents only, by the author.

Initial50% coverage · current

A classification scheme exists and is applied to document stores. Structured data is classified at the system level rather than at the field level, so "the database is sensitive" is the finest available statement.

Advanced75% coverage

Every data store in the overlay carries a sensitivity and a named owner. Privacy and controlled-unclassified categories are identified at field or column level in the crown-jewel stores.

Optimal100% coverage

Classification is asserted at creation and travels with the data through copies, extracts and analytic environments. An unclassified store appearing in the estate is detected as a terrain-currency failure rather than discovered during an incident.

ObservableShare of stores in the overlay carrying both a classification and an owner, and the number of unclassified stores discovered per cycle.

Encryption & Key Management

Cryptographic protection of data at rest and in transit, and control of the keys that undo it.

  • Criticality 5
  • Exposure 3
  • Weight 15
  • Illustrative rung Advanced · 75%
Traditional25% coverage

TLS externally, plaintext internally. Disk encryption where the platform supplies it by default, and keys stored beside the data they protect.

Initial50% coverage

Encryption at rest and in transit for the main mission stores, with keys managed by the platform’s default service and administered by the same team that administers the data.

Advanced75% coverage · current

Keys are held in a managed service under agency control, with separation between key custodian and data administrator. Key use is logged, rotation is enforced, and backups are encrypted under keys the production identity plane cannot reach.

Optimal100% coverage

Access to a key is an authorization decision made by the same policy engine as access to the data, so revoking an identity revokes decryption. Anomalous key use is a detection, and cryptographic recovery of a store has been exercised rather than assumed.

ObservableShare of crown-jewel stores whose keys are separable from their administrators, and the date a key-loss recovery was last exercised.

DLP

Detecting and preventing records leaving by the paths they can actually leave by.

  • Criticality 4
  • Exposure 4
  • Weight 16
  • Illustrative rung Traditional · 25%
Traditional25% coverage · current

Data egress is unmonitored. Loss is discovered when it is reported from outside the agency.

Initial50% coverage

Loss-prevention tooling covers mail and endpoint with policies matching obvious patterns. Alerts are triaged when capacity allows, which is a statement about capacity rather than about risk.

Advanced75% coverage

Monitoring covers the paths that actually carry records in volume — database export, API, cloud storage, the analytic environment — not only mail. Policies are written against the classified stores rather than against pattern matching alone.

Optimal100% coverage

Movement of records above a stated volume from a crown-jewel store is a pre-authorized containment trigger rather than a report. Decoy records seeded in those stores produce detections with no false-positive budget, which is what makes the threshold usable at all.

ObservableShare of the enumerated egress paths from crown-jewel stores that are monitored, and the number of detections raised by decoy interaction.

Data Access Governance

Who may read the records, in what volume, through which path, and with what record left behind.

  • Criticality 5
  • Exposure 4
  • Weight 20
  • Illustrative rung Initial · 50%
Traditional25% coverage

Access is granted on request and rarely removed. Broad read groups exist on the main record stores, and extracts are made and kept without control.

Initial50% coverage · current

Access is reviewed annually and direct database access is restricted to named administrators. Application-mediated bulk read is unconstrained because it is considered normal use.

Advanced75% coverage

Access to the crown-jewel record set is brokered through a governed path with per-object authorization, logged to the record. Bulk extract requires justification and produces an audit event. Copies into non-production are prohibited or masked.

Optimal100% coverage

Entitlement to the record set is time-bound and continuously re-evaluated. Every copy of the record set is itself terrain in the overlay, so a shadow extract has nowhere to sit unobserved, and the record of who read what is admissible as cycle evidence.

ObservableNumber of identities entitled to bulk read of the crown-jewel record set and the trend in that number; count of known copies reconciled against the overlay.

Weight, Coverage and Residual Risk

Weight is criticality × exposure, 1–25 per sub-tower. Coverage is the weighted mean of the sub-towers’ maturity coverage — never a flat average. Residual risk is reported both as the inverse percentage and in weight points, because the points are what rank a backlog.

  • 66Layer weightSum of criticality × exposure across 4 sub-towers
  • 49.6%Rolled-up coverageWeighted mean of the sub-tower maturity coverage
  • 50.4%Residual riskThe inverse of coverage, before weight is considered
  • 33.3Residual pointsWeight left uncovered — the figure that ranks against other layers
Sub-towerCriticalityExposureWeightIllustrative rungCoverageResidual points
Classification5315Initial50%7.5
Encryption & Key Management5315Advanced75%3.8
DLP4416Traditional25%12
Data Access Governance5420Initial50%10

Classification

Criticality
5
Exposure
3
Weight
15
Illustrative rung
Initial
Coverage
50%
Residual points
7.5

Encryption & Key Management

Criticality
5
Exposure
3
Weight
15
Illustrative rung
Advanced
Coverage
75%
Residual points
3.8

DLP

Criticality
4
Exposure
4
Weight
16
Illustrative rung
Traditional
Coverage
25%
Residual points
12

Data Access Governance

Criticality
5
Exposure
4
Weight
20
Illustrative rung
Initial
Coverage
50%
Residual points
10

This is the only layer where criticality should be scored directly rather than inherited. Every other layer’s criticality is a statement about which data it gives access to; scoring T5 from something else makes the whole model circular.

Exposure on T5 is the count and quality of the paths to the records, not whether the store is internet-facing. A database with no public route, reachable by four hundred staff identities through an application that permits unbounded export, is high exposure. The reference profile’s most common scoring error is marking the crown-jewel store as low exposure because it sits in a private subnet.

Residual risk here should be read in absolute terms, not as a percentage. Ninety per cent coverage of the crown-jewel record set still leaves the objective partially undefended, and the model’s convention of expressing residual risk as weight points rather than as a percentage exists so that this is visible: the same 10 per cent gap is worth 2.5 points on a low-weight asset and 25 on this one.

Maneuvers That Consume This Layer

The primary list is derived from each form’s own primary-terrain declaration in the maneuver catalog, so the two cannot disagree. The supporting list is authored: “consumes without being principally about” is a judgment, and deriving it would be a false claim of rigour.

Primary — Derived

  • M5 AmbushTrade space for information and time, and impose cost.

Supporting — Authored

  • M3 EnvelopmentEnvelopment is what makes data access governance enforceable — per-object authorization is an identity decision applied to a data object.
  • M8 Isolation / RetrogradeRetrograde on this layer means cutting access to records while keeping the mission service running, which is the hardest version of graceful degradation.
  • M11 ReconstitutionReconstitution is judged on this layer: restoring service without restoring verified data has restored the wrong thing.

Controls That Apply

Two lists. The first is specific to this ground; the second is the spine every layer runs through, stated once here rather than repeated ten times across the reference.

Specific to T5

The Common Spine