ASOM-Fedv6.1Open the explorer
TX · Cross-cutting · The enablers of movement

Cross-Cutting

Not ground, but what makes maneuver on the other nine possible: reconnaissance, mobility, and command authority. Scored as enablers rather than as terrain with a coverage gap.

The Ground

The enablers of movement.

The cross-cutting domains are not ground. They are reconnaissance, mobility and command — the things that make maneuver on ground possible. A force with no reconnaissance holds terrain blindly, a force with no mobility holds only what it is standing on, and a force with no command authority cannot commit to anything. None of the three is a position that can be taken, which is why they are modeled as enablers spanning the stack rather than as a tenth layer beneath it.

The modeling consequence is specific: these three are deliberately not gap-scored the same way. A coverage percentage on Identity means a proportion of identity terrain is defended. A coverage percentage on Visibility would mean nothing of the kind — visibility is not defended, it is possessed or not possessed, per layer. So the enablers are assessed on maturity and their effect is expressed as a constraint on the other nine rather than as a number added to them.

That constraint is real and it is the reason this section exists at all. Automation maturity sets the upper bound on how fast any maneuver can be executed; visibility maturity sets the upper bound on which maneuvers can be selected, because a form of maneuver you cannot observe the effect of cannot be validated; governance maturity sets what may be done without escalation. An estate with excellent tower coverage and Traditional enablers has ground it cannot maneuver on.

Origin

A cross-cutting enabler rather than ground. Assessed on maturity, and expressed as a constraint on the other nine layers rather than as coverage added to them.

Asset pools feeding it
  • Cross-cutting assets — telemetry and analytics platform, orchestration and response tooling, the intelligence function, the rules of engagement and the cycle record

Key Terrain

Key terrain is what confers decisive advantage if you hold it. Everything else on this layer is defended in order to hold these.

  • The telemetry pipelineThe reconnaissance asset. Its coverage decides which parts of the estate the defense can see contact on at all.
  • The orchestration layerThe mobility asset. It converts a decision into an action at machine speed, or fails to, which is the difference between a scheme and a document.
  • The rules of engagementCommand authority in written form. Nothing in the catalog can be executed under contact faster than the ROE permits.
  • The cycle recordThe evidentiary product. It is what makes the framework auditable rather than merely operated.

The Decisive Point

Which defensive fires are pre-authorized without escalation

The decisive point is which defensive fires are pre-authorized without escalation.

This is a governance artifact, not a technical one, and it is decisive because it sets the ceiling on the entire framework’s central claim. Every form of maneuver in the catalog has an execution time, and for the contested ones — isolation, credential revocation, segment severing — that time is dominated by the authorization step rather than by the action. An agency whose containment requires a bridge call has an adversary tempo advantage that no additional tooling removes.

It is also the cheapest decisive point in the model to seize. Writing down which actions may be taken, under which conditions, by which role, without escalation, costs an afternoon of the Authorizing Official’s time and converts several maneuvers from theoretical to available. Very little else in this framework has that ratio.

Sub-Towers, Rung by Rung

Maturity is scored here, not on the layer. Each rung below is stated for this sub-tower specifically — “Advanced” means something testable on each one, and something different on each one. The rung marked current is the illustrative position on the Federal Reference Agency profile.

Visibility & Analytics (ISR)

What the defense can see, across which terrain, for how long.

  • Criticality 5
  • Exposure 3
  • Weight 15
  • Illustrative rung Initial · 50%
Traditional25% coverage

Logs are collected where a tool happens to need them. Retention is set by license cost, and there is no statement of what is and is not visible.

Initial50% coverage · current

A central platform holds the main sources. Coverage is described by source count — "forty-two feeds" — which cannot be reconciled against terrain and therefore cannot show a gap.

Advanced75% coverage

Telemetry coverage is stated per terrain layer against the overlay, so a gap reads as "no visibility of east-west flows into the data tier" rather than as a missing feed. Retention is set by the declared hunt window.

Optimal100% coverage

Collection is driven by priority cyber intelligence requirements and re-tasked each cycle. Detection coverage is measured against adversary behaviors relevant to this estate, and an unanswerable requirement is a finding with an owner.

ObservableShare of terrain layers with a stated telemetry coverage position, and the number of intelligence requirements that current collection cannot answer.

Automation & Orchestration (mobility)

How fast a decision becomes an action, and whether that has been demonstrated.

  • Criticality 4
  • Exposure 3
  • Weight 12
  • Illustrative rung Initial · 50%
Traditional25% coverage

Response is manual, so the speed of the defense is the speed of a ticket queue and varies with the day of the week.

Initial50% coverage · current

Playbooks are documented and enrichment is partly automated. Containment remains a human sequence with a human in each step.

Advanced75% coverage

Defined containment actions execute automatically under stated conditions, with the authority recorded in the rules of engagement and a rollback path. Time from detection to action is measured.

Optimal100% coverage

Mobility is measured against adversary tempo rather than against an internal service target, and automation is exercised so that its failure modes are known. An automated containment that has never been rehearsed is an untested weapon.

ObservableMedian time from detection to containment across the pre-authorized set, and the share of containments executed without escalation.

Governance (command authority)

Intent, phase, rules of engagement, and the disposition of findings.

  • Criticality 5
  • Exposure 2
  • Weight 10
  • Illustrative rung Advanced · 75%
Traditional25% coverage

Security is governed as compliance activity. Intent is implicit, and nobody in the organization could state what defensive phase the agency is currently in.

Initial50% coverage

Policies exist and are current. Risk decisions are made and recorded, but not phrased as intent, so they cannot direct a scheme of maneuver.

Advanced75% coverage · current

The Authorizing Official states defensive intent and declares a phase. Rules of engagement name the pre-authorized actions and the ones requiring escalation. Findings are dispositioned rather than aged.

Optimal100% coverage

Intent, phase and rules of engagement are reviewed on the cycle cadence and change in response to the running estimate. The record of those decisions is the same evidence used for continuous monitoring, so governance produces its own compliance artifact rather than a second one.

ObservableInterval since intent and the rules of engagement were last reviewed, and the share of findings carrying a disposition rather than an age.

Weight, Coverage and Residual Risk

Weight is criticality × exposure, 1–25 per sub-tower. Coverage is the weighted mean of the sub-towers’ maturity coverage — never a flat average. Residual risk is reported both as the inverse percentage and in weight points, because the points are what rank a backlog.

  • 37Layer weightSum of criticality × exposure across 3 sub-towers
  • 56.8%Rolled-up coverageWeighted mean of the sub-tower maturity coverage
  • 43.2%Residual riskThe inverse of coverage, before weight is considered
  • 16Residual pointsWeight left uncovered — the figure that ranks against other layers
Sub-towerCriticalityExposureWeightIllustrative rungCoverageResidual points
Visibility & Analytics (ISR)5315Initial50%7.5
Automation & Orchestration (mobility)4312Initial50%6
Governance (command authority)5210Advanced75%2.5

Visibility & Analytics (ISR)

Criticality
5
Exposure
3
Weight
15
Illustrative rung
Initial
Coverage
50%
Residual points
7.5

Automation & Orchestration (mobility)

Criticality
4
Exposure
3
Weight
12
Illustrative rung
Initial
Coverage
50%
Residual points
6

Governance (command authority)

Criticality
5
Exposure
2
Weight
10
Illustrative rung
Advanced
Coverage
75%
Residual points
2.5

The enablers are not weighted with the towers, and the model would be wrong if they were. Adding a Visibility coverage percentage to nine terrain coverage percentages produces a tenth number that does not mean the same thing as the other nine and quietly dilutes them.

The enablers instead act as a stated constraint on the rollup. A mission consumer’s Bill of Defense carries its towers’ weighted coverage and, separately, the enabler maturity that bounds it — because a mission with 80 per cent tower coverage and Traditional automation cannot execute the maneuvers that coverage assumes.

The practical rule for an adopter: read the enablers first, then the towers. If automation is Traditional, most of the ranked backlog the towers produce is not executable this cycle, and the correct first move is on this layer rather than on the layer the backlog names.

Maneuvers That Consume This Layer

The primary list is derived from each form’s own primary-terrain declaration in the maneuver catalog, so the two cannot disagree. The supporting list is authored: “consumes without being principally about” is a judgment, and deriving it would be a false claim of rigour.

Primary — Derived

Supporting — Authored

None authored. This layer is an enabler of every form rather than the ground any particular one is executed on, so listing supporting forms here would list all eleven and say nothing.

Controls That Apply

Two lists. The first is specific to this ground; the second is the spine every layer runs through, stated once here rather than repeated ten times across the reference.

Specific to TX

The Common Spine