The Ground
The objective.
The objective is the thing the operation exists to take or hold. Everything else in a scheme of maneuver is justified by reference to it, and a plan that cannot name its objective is not a plan — it is activity. Data is the objective in a federal estate: the records are what the adversary came for, and every other layer is defended in order to hold this one.
Naming data as the objective has an immediate practical consequence, which is the real reason the metaphor is here. It forces the question "which records?" to be answered before any prioritization is possible. An agency that cannot say which record set is the crown jewel cannot rank its backlog, because every weight in the model ultimately derives from proximity to this layer.
It also sets the terms of failure. Compromise of any other layer is recoverable in the sense that the ground can be retaken. Exfiltration of the objective is not: the records are copied, the copy is outside the estate, and no subsequent defensive action changes that. This asymmetry is why detection tempo on this layer is worth more than prevention depth on most others.
A CISA Zero Trust Maturity Model pillar, carried with its name and boundary unchanged so an agency reporting maturity under OMB M-22-09 reports the same rung here.
- Data assets — sensitive mission records, PII stores, fee and financial data, mission-staff work product, audit logs, and every copy of these in analytic and non-production environments
Key Terrain
Key terrain is what confers decisive advantage if you hold it. Everything else on this layer is defended in order to hold these.
- Sensitive mission recordsOften pre-decisional and non-public. This is what a nation-state collector comes for, and the one holding that cannot be un-lost.
- PII storesThe statutory exposure. Loss triggers obligations that run on a clock the agency does not control.
- Fee and financial dataThe fraud target. Attacked continuously at low intensity by a different adversary class than the records are.
- Copies, extracts and analytic environmentsThe crown-jewel record set as it exists in three other places with a fraction of the controls. Usually the actual location of the loss.
- Audit logsData that is also evidence. Its integrity determines whether anything else on this list can be reconstructed after an incident.
The Decisive Point
The data-access governance boundary around the crown-jewel record set
The decisive point is the data-access governance boundary around the crown-jewel record set — the mechanism that decides which identities may read the records in volume, and leaves a record of who did.
It is decisive because it is the last point at which the defense still has agency. Encryption protects records from someone without a key; classification tells you which records matter; neither of them constrains an authorized identity reading at scale, and an authorized identity reading at scale is what almost every serious loss looks like from the inside.
Holding it also changes what detection on this layer can do. Where bulk access is brokered and logged, a decoy record (M5) and a volume threshold both become usable triggers with a tolerable false-positive cost. Where it is not, the same detections drown in legitimate query traffic, and the agency ends up monitoring mail because mail is the path it can see.
Sub-Towers, Rung by Rung
Maturity is scored here, not on the layer. Each rung below is stated for this sub-tower specifically — “Advanced” means something testable on each one, and something different on each one. The rung marked current is the illustrative position on the Federal Reference Agency profile.
Classification
Knowing which data is which, at a granularity that a control can act on.
- Criticality 5
- Exposure 3
- Weight 15
- Illustrative rung Initial · 50%
Sensitivity is known informally by the teams that own the data. There are no labels, and controlled unclassified information is identified on documents only, by the author.
A classification scheme exists and is applied to document stores. Structured data is classified at the system level rather than at the field level, so "the database is sensitive" is the finest available statement.
Every data store in the overlay carries a sensitivity and a named owner. Privacy and controlled-unclassified categories are identified at field or column level in the crown-jewel stores.
Classification is asserted at creation and travels with the data through copies, extracts and analytic environments. An unclassified store appearing in the estate is detected as a terrain-currency failure rather than discovered during an incident.
ObservableShare of stores in the overlay carrying both a classification and an owner, and the number of unclassified stores discovered per cycle.
Encryption & Key Management
Cryptographic protection of data at rest and in transit, and control of the keys that undo it.
- Criticality 5
- Exposure 3
- Weight 15
- Illustrative rung Advanced · 75%
TLS externally, plaintext internally. Disk encryption where the platform supplies it by default, and keys stored beside the data they protect.
Encryption at rest and in transit for the main mission stores, with keys managed by the platform’s default service and administered by the same team that administers the data.
Keys are held in a managed service under agency control, with separation between key custodian and data administrator. Key use is logged, rotation is enforced, and backups are encrypted under keys the production identity plane cannot reach.
Access to a key is an authorization decision made by the same policy engine as access to the data, so revoking an identity revokes decryption. Anomalous key use is a detection, and cryptographic recovery of a store has been exercised rather than assumed.
ObservableShare of crown-jewel stores whose keys are separable from their administrators, and the date a key-loss recovery was last exercised.
DLP
Detecting and preventing records leaving by the paths they can actually leave by.
- Criticality 4
- Exposure 4
- Weight 16
- Illustrative rung Traditional · 25%
Data egress is unmonitored. Loss is discovered when it is reported from outside the agency.
Loss-prevention tooling covers mail and endpoint with policies matching obvious patterns. Alerts are triaged when capacity allows, which is a statement about capacity rather than about risk.
Monitoring covers the paths that actually carry records in volume — database export, API, cloud storage, the analytic environment — not only mail. Policies are written against the classified stores rather than against pattern matching alone.
Movement of records above a stated volume from a crown-jewel store is a pre-authorized containment trigger rather than a report. Decoy records seeded in those stores produce detections with no false-positive budget, which is what makes the threshold usable at all.
ObservableShare of the enumerated egress paths from crown-jewel stores that are monitored, and the number of detections raised by decoy interaction.
Data Access Governance
Who may read the records, in what volume, through which path, and with what record left behind.
- Criticality 5
- Exposure 4
- Weight 20
- Illustrative rung Initial · 50%
Access is granted on request and rarely removed. Broad read groups exist on the main record stores, and extracts are made and kept without control.
Access is reviewed annually and direct database access is restricted to named administrators. Application-mediated bulk read is unconstrained because it is considered normal use.
Access to the crown-jewel record set is brokered through a governed path with per-object authorization, logged to the record. Bulk extract requires justification and produces an audit event. Copies into non-production are prohibited or masked.
Entitlement to the record set is time-bound and continuously re-evaluated. Every copy of the record set is itself terrain in the overlay, so a shadow extract has nowhere to sit unobserved, and the record of who read what is admissible as cycle evidence.
ObservableNumber of identities entitled to bulk read of the crown-jewel record set and the trend in that number; count of known copies reconciled against the overlay.
Weight, Coverage and Residual Risk
Weight is criticality × exposure, 1–25 per sub-tower. Coverage is the weighted mean of the sub-towers’ maturity coverage — never a flat average. Residual risk is reported both as the inverse percentage and in weight points, because the points are what rank a backlog.
- 66Layer weightSum of criticality × exposure across 4 sub-towers
- 49.6%Rolled-up coverageWeighted mean of the sub-tower maturity coverage
- 50.4%Residual riskThe inverse of coverage, before weight is considered
- 33.3Residual pointsWeight left uncovered — the figure that ranks against other layers
| Sub-tower | Criticality | Exposure | Weight | Illustrative rung | Coverage | Residual points |
|---|---|---|---|---|---|---|
| Classification | 5 | 3 | 15 | Initial | 50% | 7.5 |
| Encryption & Key Management | 5 | 3 | 15 | Advanced | 75% | 3.8 |
| DLP | 4 | 4 | 16 | Traditional | 25% | 12 |
| Data Access Governance | 5 | 4 | 20 | Initial | 50% | 10 |
Classification
- Criticality
- 5
- Exposure
- 3
- Weight
- 15
- Illustrative rung
- Initial
- Coverage
- 50%
- Residual points
- 7.5
Encryption & Key Management
- Criticality
- 5
- Exposure
- 3
- Weight
- 15
- Illustrative rung
- Advanced
- Coverage
- 75%
- Residual points
- 3.8
DLP
- Criticality
- 4
- Exposure
- 4
- Weight
- 16
- Illustrative rung
- Traditional
- Coverage
- 25%
- Residual points
- 12
Data Access Governance
- Criticality
- 5
- Exposure
- 4
- Weight
- 20
- Illustrative rung
- Initial
- Coverage
- 50%
- Residual points
- 10
This is the only layer where criticality should be scored directly rather than inherited. Every other layer’s criticality is a statement about which data it gives access to; scoring T5 from something else makes the whole model circular.
Exposure on T5 is the count and quality of the paths to the records, not whether the store is internet-facing. A database with no public route, reachable by four hundred staff identities through an application that permits unbounded export, is high exposure. The reference profile’s most common scoring error is marking the crown-jewel store as low exposure because it sits in a private subnet.
Residual risk here should be read in absolute terms, not as a percentage. Ninety per cent coverage of the crown-jewel record set still leaves the objective partially undefended, and the model’s convention of expressing residual risk as weight points rather than as a percentage exists so that this is visible: the same 10 per cent gap is worth 2.5 points on a low-weight asset and 25 on this one.
Maneuvers That Consume This Layer
The primary list is derived from each form’s own primary-terrain declaration in the maneuver catalog, so the two cannot disagree. The supporting list is authored: “consumes without being principally about” is a judgment, and deriving it would be a false claim of rigour.
Primary — Derived
- M5 AmbushTrade space for information and time, and impose cost.
Supporting — Authored
- M3 EnvelopmentEnvelopment is what makes data access governance enforceable — per-object authorization is an identity decision applied to a data object.
- M8 Isolation / RetrogradeRetrograde on this layer means cutting access to records while keeping the mission service running, which is the hardest version of graceful degradation.
- M11 ReconstitutionReconstitution is judged on this layer: restoring service without restoring verified data has restored the wrong thing.
Controls That Apply
Two lists. The first is specific to this ground; the second is the spine every layer runs through, stated once here rather than repeated ten times across the reference.
Specific to T5
- KT-4 Adversary Reachability AssessmentReachability of the crown-jewel store, from where and by whom, is the reachability question the others are asked in service of.
- FO-3 Tenancy and Inheritance BoundaryMost of this layer now sits in shared tenancy, so which protections are inherited from the provider and which are the agency’s own has to be stated before coverage means anything.
- FO-1 Privacy Terrain IdentificationPrivacy terrain identification names the PII holdings as terrain rather than as a compliance register.
- FO-2 Controlled Unclassified Information HandlingControlled unclassified information handling sets what may be done with a large part of this layer’s contents, independent of its sensitivity to the agency.
- RC-4 Recovery Integrity VerificationRecovery integrity verification is what distinguishes restored data from data an adversary was content to let you restore.
- CE-6 Cycle Record and TrendThe cycle record depends on audit data that lives on this layer, so its integrity is a precondition for the framework’s own evidence.
The Common Spine
- TM-1 Terrain Inventory and OverlayPuts the layer’s elements on the overlay in the first place. Nothing below can be computed for terrain that is not inventoried.
- TM-2 Defensive Layer ClassificationAssigns each element to a layer. This is the control that decides whether a thing is scored here or somewhere else.
- TM-3 Asset WeightingSets criticality and exposure per asset, which is the allocation driver every coverage and residual-risk number on the layer is weighted by.
- TM-6 Terrain CurrencyAges the overlay. A layer’s coverage figure inherits the staleness of the inventory it was computed from.
- TM-7 Terrain OwnershipNames an owner for the ground, so a coverage gap has somebody to be assigned to.
- KT-1 Decisive Point IdentificationIdentifies the decisive point on this layer rather than accepting the one this page names by default.
- KT-2 Decisive Point Protection FloorSets the minimum protection the layer’s decisive point must hold regardless of its rolled-up coverage.
- FO-7 Obligation Profile DeclarationDeclares which federal obligations bind the estate, which is what makes any FO coverage figure on this layer comparable to another agency’s.
- EN-1 Event Declaration and TriageAn engagement on this layer starts by being declared. Until it is, nothing below this line is running.
- EN-2 Engagement ReconstructionReconstruction is what establishes how far the adversary actually got across this layer, and it is what corrects the dwell estimate the layer’s tempo figures use.
- EN-3 Evidence PreservationSets how long this layer’s telemetry must survive — measured against estimated dwell, not against a retention default.
- EN-4 Escalation and Engagement AuthorityNames who may authorize action on this layer out of hours, which is where the decide segment is usually spent.
- EN-5 Eradication and Transition to RecoveryVerifies the adversary is off this layer before the mission is restored onto it.
- EN-6 Engagement CommunicationReports what happened on this layer to those who must know, inside and outside the agency.
- SM-7 Deception EmplacementDeception is emplaced per layer, on the approaches to that layer’s decisive point — the one detection here with no false-positive budget.
- CE-4 Coverage and Residual Risk ComputationPerforms the coverage and residual-risk computation described below, on the cycle cadence.
- CE-5 Remediation Backlog PrioritizationTurns weight multiplied by coverage gap into a ranked backlog, which is what the layer’s numbers are for.