ASOM-Fedv6.1Open the explorer
T6 · ASOM-Fed v2.0 · Ground you cannot maneuver freely on

Operational Technology

Scored separately because the moves available here are narrower and the consequence of loss is physical. Treating an OT estate as ordinary network terrain overstates the defender’s options.

The Ground

Ground you cannot maneuver freely on.

Some ground permits movement but not maneuver: a force can be there, but it cannot reposition freely, cannot be resupplied quickly, and cannot fall back without giving up something that does not come back. Operational technology is that ground. The moves available on it are narrower than on any IT layer, and the consequence of loss is physical rather than informational.

The narrowness is the doctrinal point, and it is what a general-purpose maturity model gets wrong. Standard advice on an IT layer — patch promptly, deploy an agent, isolate on detection — ranges from unavailable to actively dangerous here. A building control system cannot be patched on the vendor’s absence, an agent cannot be installed on a controller with no operating system to host one, and isolating a segment mid-process can cause the physical outcome the defense exists to prevent.

The correct posture follows from the constraint rather than from ambition: know exactly what is there, control the boundary and the accounts that cross it, watch passively, and write down in advance which responses are forbidden. That is a smaller set of moves than any other layer offers, and pretending otherwise produces a score that overstates the defender’s options.

Origin

Added by ASOM-Fed in v2.0. Not a CISA pillar — the justification is stated in full below.

Asset pools feeding it
  • Operational technology assets — building control and access systems, laboratory and facility instrumentation, engineering workstations, vendor maintenance paths

Key Terrain

Key terrain is what confers decisive advantage if you hold it. Everything else on this layer is defended in order to hold these.

  • Building control systemsPower, cooling and access control. Their failure takes the data center with them, which makes them an IT dependency wearing an OT interface.
  • Laboratory and facility instrumentationMission-supporting equipment sitting on ordinary networks, bought through program offices, and routinely missing from the security register.
  • Engineering workstationsThe devices that can change a process. The one place on this layer where a conventional endpoint compromise converts directly into physical consequence.
  • Vendor remote-access pathsMaintained by contract rather than by architecture, and the most common way the OT/IT boundary is crossed in practice.

The Decisive Point

The OT/IT boundary and the accounts permitted to cross it

The decisive point is the OT/IT boundary and the accounts permitted to cross it — the two together, because a boundary with permitted crossings is only as strong as the identities holding them.

It is decisive because it is the only place on this layer where a defender has both freedom of action and leverage. Inside the OT segment, options are constrained by the process; at the boundary, ordinary network and identity controls apply and can be exercised without physical consequence.

It is also the correct place to state what happens under compromise. A boundary designed so that loss of the IT side does not require the OT side to stop is what makes graceful degradation real on this layer. Where the two are coupled, an IT incident forces a choice between defending the estate and continuing a physical process — and that choice will be made badly, under time pressure, by whoever is on the call.

Sub-Towers, Rung by Rung

Maturity is scored here, not on the layer. Each rung below is stated for this sub-tower specifically — “Advanced” means something testable on each one, and something different on each one. The rung marked current is the illustrative position on the Federal Reference Agency profile.

OT Asset Inventory

Knowing what OT exists, who owns it, and what it is connected to.

  • Criticality 4
  • Exposure 3
  • Weight 12
  • Illustrative rung Traditional · 25%
Traditional25% coverage · current

Building and laboratory systems are held on vendor spreadsheets. The security program does not know what exists, and the facilities organization does not know what is networked.

Initial50% coverage

A one-time survey has produced a list. It began ageing on the day it was signed and has no owner, so it is treated as historical rather than authoritative.

Advanced75% coverage

OT assets sit in the same terrain overlay as IT assets, with owner, criticality, exposure and connectivity recorded. Collection is passive and does not put the process at risk.

Optimal100% coverage

The inventory is maintained from passive observation rather than survey, so a controller added by a facilities contractor appears without anyone reporting it. Each asset is tied to the mission or facility function it serves.

ObservableShare of OT assets found by passive discovery that were already in the overlay — the gap is the finding.

OT / IT Boundary

The separation between the process network and everything else, and every permitted crossing.

  • Criticality 5
  • Exposure 4
  • Weight 20
  • Illustrative rung Initial · 50%
Traditional25% coverage

OT segments are reachable from the corporate network, and vendor remote access arrives through the general-purpose VPN with a standard account.

Initial50% coverage · current

A firewall separates OT from IT, with a rule set accumulated over years. The boundary is documented; it is not reconciled against what actually crosses it.

Advanced75% coverage

A default-deny boundary with an enumerated, owner-approved set of crossings, and every crossing identity registered. Vendor remote access is brokered, time-boxed and recorded.

Optimal100% coverage

Crossings are unidirectional wherever the process permits, boundary assumptions are tested by exercise, and loss of the IT side does not require the OT side to stop — which is what makes M8 available here at all.

ObservableCount of approved crossings against the count of observed crossings. Any difference is either an undocumented path or a stale approval.

Engineering Access

Who may change a process, from what device, with what accountability.

  • Criticality 5
  • Exposure 3
  • Weight 15
  • Illustrative rung Traditional · 25%
Traditional25% coverage · current

Engineering workstations are ordinary laptops with local administrator rights and vendor software, used for mail and browsing as well as for the process.

Initial50% coverage

Dedicated workstations exist for some systems. Shared vendor accounts persist because the vendor’s support model requires them, and nobody has the leverage to change it.

Advanced75% coverage

Engineering access runs from dedicated, hardened, non-general-purpose workstations. Every action is individually attributable even where the device authenticates with a shared vendor credential, and a process change requires a second party.

Optimal100% coverage

Access is time-boxed and recorded like privileged access on T1, and the same register covers both — so a separation removes a person’s OT access on the same clock as their IT access.

ObservableCount of engineering accounts without individual attribution, and the measured time from separation to OT access revocation.

Passive OT Monitoring

Visibility of the process network, obtained without interacting with the process.

  • Criticality 4
  • Exposure 3
  • Weight 12
  • Illustrative rung Traditional · 25%
Traditional25% coverage · current

No monitoring. The first indicator of a problem is a physical symptom noticed by someone standing next to the equipment.

Initial50% coverage

Network taps exist on some segments and alerts go to the facilities team rather than to the SOC, where nobody correlates them with anything else.

Advanced75% coverage

Protocol-aware passive monitoring on every OT segment, feeding the same pipeline as IT telemetry, with detections owned by the SOC and a documented escalation to the facility owner.

Optimal100% coverage

Detection is baselined against normal process behavior rather than against IT signatures, and the response is bounded by rules of engagement that state explicitly which actions are forbidden because they could affect the process — written down in advance rather than improvised during an incident.

ObservableShare of OT segments monitored, and the number of OT detections triaged by the SOC rather than by facilities per cycle.

Weight, Coverage and Residual Risk

Weight is criticality × exposure, 1–25 per sub-tower. Coverage is the weighted mean of the sub-towers’ maturity coverage — never a flat average. Residual risk is reported both as the inverse percentage and in weight points, because the points are what rank a backlog.

  • 59Layer weightSum of criticality × exposure across 4 sub-towers
  • 33.5%Rolled-up coverageWeighted mean of the sub-tower maturity coverage
  • 66.5%Residual riskThe inverse of coverage, before weight is considered
  • 39.3Residual pointsWeight left uncovered — the figure that ranks against other layers
Sub-towerCriticalityExposureWeightIllustrative rungCoverageResidual points
OT Asset Inventory4312Traditional25%9
OT / IT Boundary5420Initial50%10
Engineering Access5315Traditional25%11.3
Passive OT Monitoring4312Traditional25%9

OT Asset Inventory

Criticality
4
Exposure
3
Weight
12
Illustrative rung
Traditional
Coverage
25%
Residual points
9

OT / IT Boundary

Criticality
5
Exposure
4
Weight
20
Illustrative rung
Initial
Coverage
50%
Residual points
10

Engineering Access

Criticality
5
Exposure
3
Weight
15
Illustrative rung
Traditional
Coverage
25%
Residual points
11.3

Passive OT Monitoring

Criticality
4
Exposure
3
Weight
12
Illustrative rung
Traditional
Coverage
25%
Residual points
9

Criticality on T6 is measured in physical and mission consequence rather than in records exposed. A building control system carries no records at all and can still take a data center off the air: scored from data exposure it rates a 1, and it is weighted at 4.

Exposure is usually lower than on any IT layer and should be scored honestly rather than defensively. Most OT in a civilian agency is not internet-reachable; its exposure comes almost entirely from the boundary and from vendor access, which is precisely why those two are separate sub-towers and carry the layer’s weight.

The layer’s coverage number should be read alongside a note that its ceiling is lower. Several sub-towers cannot reach Optimal without a vendor change the agency does not control, and a program that scores T6 as though it could is either going to report a permanent failure or quietly stop reporting it. The honest treatment is to record the constraint against the asset and let the residual risk stand as accepted rather than as outstanding.

Maneuvers That Consume This Layer

The primary list is derived from each form’s own primary-terrain declaration in the maneuver catalog, so the two cannot disagree. The supporting list is authored: “consumes without being principally about” is a judgment, and deriving it would be a false claim of rigour.

Primary — Derived

No form of maneuver names this layer as its primary terrain. That is a real gap in the catalog rather than a property of the layer: the eleven forms were derived before T6 existed, and a form whose primary ground is this layer has not yet been added. Until it is, this layer is consumed only in support.

Supporting — Authored

  • M2 Defense in DepthDepth on this layer is mostly boundary depth, because the assets themselves cannot carry independent controls.
  • M4 Obstacle / CanalizationCanalization is the dominant available move here: the process network is small enough that every legitimate path can be enumerated and everything else denied.
  • M8 Isolation / RetrogradeIsolation is available only if the boundary was designed for it. Where it was not, the retrograde option does not exist and the scheme should say so rather than assume it.

Controls That Apply

Two lists. The first is specific to this ground; the second is the spine every layer runs through, stated once here rather than repeated ten times across the reference.

Specific to T6

  • FO-4 Operational Technology TerrainThe control that requires operational technology to be identified and treated as terrain in the first place. T6 is its scoring surface.
  • TM-5 Connection and Denied-Path RegisterThe connection and denied-path register is where OT crossings are stated; the OT boundary is the register’s hardest case and its most valuable one.
  • KT-5 Barrier SufficiencyBarrier sufficiency on the OT boundary is testable in a way most of this layer is not, which makes it the highest-yield assessment available here.
  • CG-3 Rules of EngagementRules of engagement must state which responses are forbidden on OT. This is the only layer where the ROE’s prohibitions matter more than its authorizations.
  • FC-4 Environmental ContinuityEnvironmental continuity and building control are the same systems seen from the facilities side; scoring them twice is a modeling error, ignoring the overlap is worse.
  • FO-5 Statutory Availability FloorWhere OT carries a mission process, the statutory availability floor constrains what may be done to defend it.

The Common Spine

Why ASOM-Fed Adds This Layer

T6 is not a CISA pillar. Extending someone else’s taxonomy requires a reason per addition, and the reason cannot be completeness. The objection is stated first, at its strongest.

The challenge

CISA’s Zero Trust Maturity Model already covers devices and networks. Operational technology is devices on networks. Adding a sixth pillar duplicates two existing ones and breaks comparability with the maturity assessment the agency already reports under OMB M-22-09.

  1. Comparability is preserved by construction: T1–T5 keep the ZTMM names, boundaries and maturity rungs exactly, and an agency’s reported ZTMM figures drop into this model unchanged. T6–T9 are scored alongside them, not blended into them. Removing the four added layers reproduces the ZTMM result exactly, which is the test the separation is designed to pass.
  2. The substantive objection is the interesting one, and it fails on the moves available rather than on the assets present. A maturity model is a statement about what good looks like. Scored as T2 devices, an OT estate is assessed against endpoint protection, posture-based access and rebuild-from-image — three practices that are respectively unavailable, unavailable and dangerous on a process controller. The estate scores Traditional forever, and the score carries no information because it was never achievable.
  3. Scoring OT separately changes what the number means. The four sub-towers here are the moves that are actually available on this ground — inventory, boundary, engineering access, passive monitoring — so a Traditional score is a finding somebody can act on and an Advanced score is a claim that can be tested.
  4. There is a second-order reason that matters in a federal estate specifically. OT is procured by program and facilities offices under different authorities, so it is systematically absent from an IT-derived asset register. A layer with its own inventory sub-tower forces the discovery; a sub-heading under Devices inherits the register that already does not contain it.

What it does not fixThis layer does not make an agency competent at OT security, and its four sub-towers are a floor rather than a program — an agency running genuine industrial control should be working to a sector-specific standard, with this layer serving only to place OT on the same map as everything else. It also overlaps deliberately with T8 Facilities on building systems; the overlap is resolved by ownership, not by cloning the asset into both layers.