The Ground
Terrain that is also the force.
Every other layer in the model is ground the force stands on. This one is ground that is also the force. The people who hold privilege over the estate are simultaneously the terrain an adversary attacks, the sensors that report contact, and the element that executes every maneuver in the catalog.
That dual character is not a rhetorical flourish; it is the reason two problems normally treated separately belong in one layer. Insider risk asks whether a privileged human is acting against the mission. Analyst saturation asks whether the defending humans can still decide faster than the adversary. Both are questions about the state of the same population, both are measured by the same registers, and separating them produces a program that surveils its workforce while exhausting it.
The doctrinal term for the second half is the culminating point — the moment a force can no longer sustain its operation regardless of the strength of its position. A defense with excellent controls and a saturated team has culminated, and no control on any other layer detects that condition. Scoring the workforce as terrain is what puts it on the map.
Added by ASOM-Fed in v3.0. Not a CISA pillar — the justification is stated in full below.
- Workforce assets — privileged administrator populations, approval and exception-granting roles, mission-staff populations by data reach, contractor and vendor staff, the defending team itself
Key Terrain
Key terrain is what confers decisive advantage if you hold it. Everything else on this layer is defended in order to hold these.
- Privileged humansThe population whose credentials are worth stealing and whose actions cannot be undone by a control on another layer.
- Approval rolesThe people who can authorize a change, a payment or an exception. Compromising an approver defeats a separation of duties that no technical control replaces.
- The separation pipelineThe path by which someone stops being staff. Its speed is a defensive property, and it is usually owned by an organization that does not know that.
- The defending team itselfThe SOC and hunt capacity that every maneuver is executed by. Terrain in the sense that its loss ends the campaign.
The Decisive Point
The register of who holds privilege, and how fast it is revoked when they leave
The decisive point is the register of who holds privilege, together with how fast it is revoked when they leave.
The pairing is the point. A register alone is an inventory; revocation tempo alone is a metric with no denominator. Together they answer the only question this layer needs to answer under contact: when a named human becomes untrusted — separated, compromised or suspected — how long is it until they can no longer reach key terrain, and how confident are we that the answer covers every system rather than the four we thought of?
It is decisive because it is the one place on this layer where a defender can act quickly and completely. Behavioral indicators are slow, contested and probabilistic; revocation is fast, unambiguous and total. An agency that can revoke comprehensively in an hour has a usable response to insider risk. One that takes a week has, in practice, no response at all, whatever its insider-risk program is called.
Sub-Towers, Rung by Rung
Maturity is scored here, not on the layer. Each rung below is stated for this sub-tower specifically — “Advanced” means something testable on each one, and something different on each one. The rung marked current is the illustrative position on the Federal Reference Agency profile.
Privileged Human Register
The authoritative statement of which humans can reach key terrain, and through what.
- Criticality 5
- Exposure 3
- Weight 15
- Illustrative rung Initial · 50%
There is no register. Privilege is established by querying each system individually, which means it is established during incidents and not before them.
A list of administrators exists per platform, assembled periodically. There is no common definition of privilege, so the lists cannot be added together meaningfully.
One register of humans holding privilege over key terrain, with privilege defined by what they can reach rather than by which group they belong to, an owner per entry, and a review interval.
The register is derived from entitlement data rather than maintained by hand, reconciles continuously against T1 identity governance, and covers contractors and vendor staff on the same footing as employees.
ObservableNumber of humans able to reach key terrain, by system, reconciled against the register — and the size of the discrepancy, which is the real metric.
Role-Based Readiness
Whether the people in each role can actually do the defensive thing their role requires.
- Criticality 3
- Exposure 4
- Weight 12
- Illustrative rung Initial · 50%
Annual awareness training, identical for everyone, with completion tracked as the outcome. A 100 per cent completion rate is reported as a security metric.
Additional training exists for administrators and developers. Effectiveness is still measured by completion, so the number cannot come out badly and therefore says nothing.
Readiness is defined per role against what that role can do to key terrain, and measured by exercise — a phishing-resistant workforce is demonstrated by a simulation the workforce can fail, not by a course they completed.
Readiness decay is measured between exercises and drives re-qualification. A role that cannot demonstrate readiness loses the privilege the readiness was qualifying it for, which is the only version of this sub-tower with consequences attached.
ObservableExercise pass rate by role for the roles that touch key terrain, and the interval since each of those roles last exercised.
Insider Risk Position
The agency’s stated position on insider risk: what is watched, what is deliberately not, and under whose authority.
- Criticality 4
- Exposure 3
- Weight 12
- Illustrative rung Traditional · 25%
Insider risk is handled as a personnel matter after the fact. There is no defined position and no telemetry, so the first case sets the precedent.
A policy exists. Monitoring is whatever the loss-prevention tool produces by default, and legal and privacy review happens per incident rather than per design.
The position is stated as terrain: which behaviors on which ground are indicators, what is deliberately not monitored, and under whose authority — reviewed with counsel and privacy, and executed by a named function rather than by whoever notices.
Indicators are correlated across the identity, data and workforce layers with a stated confidence, dispositioned under the same findings process as anything else, and the cost of false positives to the workforce is measured — because a program that treats its own staff as adversaries loses the force it is defending with.
ObservableTime from indicator to disposition, the ratio of dispositioned to raised indicators, and a documented scope of what is not monitored.
Separation Tempo
The measured interval between someone ceasing to be trusted and ceasing to have access.
- Criticality 5
- Exposure 4
- Weight 20
- Illustrative rung Initial · 50%
Access removal follows a manual checklist after the separation date. Contractor departures are often not notified at all, so the account simply remains.
Employee separations trigger deprovisioning from the HR feed within days. Contractors are handled by the sponsoring manager, with no measurement and no backstop.
Every identity type has a named separation trigger, and revocation of access to key terrain occurs inside a stated interval measured in hours. The interval is measured rather than asserted.
Separation revokes sessions and tokens as well as accounts — including credentials held in vaults, pipelines and vendor portals — and the measured interval for privileged humans is inside the observed adversary dwell budget for stolen-credential use.
ObservableMedian and 95th-percentile time from separation trigger to loss of access to key terrain, reported separately for employees, contractors and vendor staff.
Weight, Coverage and Residual Risk
Weight is criticality × exposure, 1–25 per sub-tower. Coverage is the weighted mean of the sub-towers’ maturity coverage — never a flat average. Residual risk is reported both as the inverse percentage and in weight points, because the points are what rank a backlog.
- 59Layer weightSum of criticality × exposure across 4 sub-towers
- 44.9%Rolled-up coverageWeighted mean of the sub-tower maturity coverage
- 55.1%Residual riskThe inverse of coverage, before weight is considered
- 32.5Residual pointsWeight left uncovered — the figure that ranks against other layers
| Sub-tower | Criticality | Exposure | Weight | Illustrative rung | Coverage | Residual points |
|---|---|---|---|---|---|---|
| Privileged Human Register | 5 | 3 | 15 | Initial | 50% | 7.5 |
| Role-Based Readiness | 3 | 4 | 12 | Initial | 50% | 6 |
| Insider Risk Position | 4 | 3 | 12 | Traditional | 25% | 9 |
| Separation Tempo | 5 | 4 | 20 | Initial | 50% | 10 |
Privileged Human Register
- Criticality
- 5
- Exposure
- 3
- Weight
- 15
- Illustrative rung
- Initial
- Coverage
- 50%
- Residual points
- 7.5
Role-Based Readiness
- Criticality
- 3
- Exposure
- 4
- Weight
- 12
- Illustrative rung
- Initial
- Coverage
- 50%
- Residual points
- 6
Insider Risk Position
- Criticality
- 4
- Exposure
- 3
- Weight
- 12
- Illustrative rung
- Traditional
- Coverage
- 25%
- Residual points
- 9
Separation Tempo
- Criticality
- 5
- Exposure
- 4
- Weight
- 20
- Illustrative rung
- Initial
- Coverage
- 50%
- Residual points
- 10
Weight on T7 attaches to populations, not to people. The unit is "privileged platform administrators", not each administrator by name; scoring individuals produces a register that is both operationally useless and uncomfortable to hold.
Criticality is inherited from what the population can reach, which is what makes this layer computable at all: a population that can reach the crown-jewel record set inherits its criticality. Exposure is a property of the population’s attack surface — how much external contact the role has, how much of its work is on unmanaged devices, how attractive its credential is.
This layer needs one measurement discipline the others do not: the residual risk it reports must not be interpreted as a statement about individuals. The model computes an exposure of a population and a tempo of a process. A program that reads a T7 residual-risk figure as a list of suspects has produced exactly the failure mode the insider-risk sub-tower’s Optimal rung warns about.
Maneuvers That Consume This Layer
The primary list is derived from each form’s own primary-terrain declaration in the maneuver catalog, so the two cannot disagree. The supporting list is authored: “consumes without being principally about” is a judgment, and deriving it would be a false claim of rigour.
Primary — Derived
No form of maneuver names this layer as its primary terrain. That is a real gap in the catalog rather than a property of the layer: the eleven forms were derived before T7 existed, and a form whose primary ground is this layer has not yet been added. Until it is, this layer is consumed only in support.
Supporting — Authored
- M3 EnvelopmentEnvelopment is executed against identities, and the privileged human register is what tells you which identities the envelopment has to hold.
- M5 AmbushDecoy credentials and documents are one of the few insider indicators with no false-positive budget, which is why ambush is the ethical option on this layer.
- M7 CounterattackCounterattack is performed by humans; the hunt team’s capacity is the constraint that decides whether the maneuver is available this week.
Controls That Apply
Two lists. The first is specific to this ground; the second is the spine every layer runs through, stated once here rather than repeated ten times across the reference.
Specific to T7
- WF-1 Workforce Terrain IdentificationWorkforce terrain identification is the control that puts this population on the overlay at all.
- WF-2 Privileged Human RegisterThe privileged human register, which is the decisive point on this layer stated as a control.
- WF-3 Role-Based ReadinessRole-based readiness, and the requirement that it be demonstrated rather than completed.
- WF-4 Insider Risk PositionInsider risk position — including the requirement to state what is deliberately not monitored.
- WF-5 Separation and Revocation TempoSeparation and revocation tempo, the other half of the decisive point.
- CG-3 Rules of EngagementMonitoring one’s own workforce requires an explicit authority and explicit limits; the rules of engagement are where both are written.
- TA-5 Tempo Degradation TriggerThe tempo degradation trigger is the control that detects the culminating point — the defending force’s own saturation.
The Common Spine
- TM-1 Terrain Inventory and OverlayPuts the layer’s elements on the overlay in the first place. Nothing below can be computed for terrain that is not inventoried.
- TM-2 Defensive Layer ClassificationAssigns each element to a layer. This is the control that decides whether a thing is scored here or somewhere else.
- TM-3 Asset WeightingSets criticality and exposure per asset, which is the allocation driver every coverage and residual-risk number on the layer is weighted by.
- TM-6 Terrain CurrencyAges the overlay. A layer’s coverage figure inherits the staleness of the inventory it was computed from.
- TM-7 Terrain OwnershipNames an owner for the ground, so a coverage gap has somebody to be assigned to.
- KT-1 Decisive Point IdentificationIdentifies the decisive point on this layer rather than accepting the one this page names by default.
- KT-2 Decisive Point Protection FloorSets the minimum protection the layer’s decisive point must hold regardless of its rolled-up coverage.
- FO-7 Obligation Profile DeclarationDeclares which federal obligations bind the estate, which is what makes any FO coverage figure on this layer comparable to another agency’s.
- EN-1 Event Declaration and TriageAn engagement on this layer starts by being declared. Until it is, nothing below this line is running.
- EN-2 Engagement ReconstructionReconstruction is what establishes how far the adversary actually got across this layer, and it is what corrects the dwell estimate the layer’s tempo figures use.
- EN-3 Evidence PreservationSets how long this layer’s telemetry must survive — measured against estimated dwell, not against a retention default.
- EN-4 Escalation and Engagement AuthorityNames who may authorize action on this layer out of hours, which is where the decide segment is usually spent.
- EN-5 Eradication and Transition to RecoveryVerifies the adversary is off this layer before the mission is restored onto it.
- EN-6 Engagement CommunicationReports what happened on this layer to those who must know, inside and outside the agency.
- SM-7 Deception EmplacementDeception is emplaced per layer, on the approaches to that layer’s decisive point — the one detection here with no false-positive budget.
- CE-4 Coverage and Residual Risk ComputationPerforms the coverage and residual-risk computation described below, on the cycle cadence.
- CE-5 Remediation Backlog PrioritizationTurns weight multiplied by coverage gap into a ranked backlog, which is what the layer’s numbers are for.
Why ASOM-Fed Adds This Layer
T7 is not a CISA pillar. Extending someone else’s taxonomy requires a reason per addition, and the reason cannot be completeness. The objection is stated first, at its strongest.
People are not terrain. Personnel security, training and insider threat are established disciplines with their own programs and their own statutory basis; recasting them as a maturity layer in a cyber framework is a category error, and one that invites a security organization to surveil its own staff under the cover of a maturity score.
- The category objection is answered by what the layer actually scores. It does not score people; it scores four registers and processes — who holds privilege, whether roles can demonstrate readiness, what the agency’s stated monitoring position is, and how fast access is revoked. Every one of those is an organizational property with an owner and a measurable state, and none of them is a judgment about an individual.
- The reason they belong on the terrain map rather than beside it is that they are already load-bearing for the rest of the model and are invisible to it. T1 identity governance can revoke an entitlement in seconds and cannot tell you that the human behind it left the agency three weeks ago, because the trigger lives in a personnel process. Scoring identity without workforce produces an identity layer that reports Advanced while carrying accounts for people who no longer work there.
- The saturation half has no home anywhere else at all. The framework’s central claim is temporal — that the defender must decide and act faster than the adversary — and the binding constraint on that claim in every real SOC is human capacity. A model that measures tooling maturity and not the state of the force will report a strengthening defense right up to the point where the defense culminates.
- On the surveillance risk, which is the strongest form of the objection: the layer is deliberately constructed to make an over-reaching program score badly. The insider-risk sub-tower cannot reach Advanced without a documented statement of what is deliberately not monitored, reviewed with counsel and privacy, and cannot reach Optimal without measuring the cost of false positives to the workforce. Those requirements exist because the risk is real, and a layer that ignored it would deserve the objection.
What it does not fixThis layer does not replace personnel security, background investigation or an insider-threat program constituted under its own authority, and it does not attempt to model human behavior. It measures whether the registers exist, whether readiness is demonstrated, whether the monitoring position is stated and bounded, and whether revocation is fast. Where an agency has a formal insider-threat function, this layer’s role is to keep it connected to the terrain rather than to duplicate it.