ASOM-Fedv6.1Open the explorer
TM-1 · Terrain Management

Terrain Inventory and Overlay

Control Statement

The organization shall maintain a current graphical overlay of all systems, data stores, and external actors within the authorization boundary, including the trust zones in which they reside.

Purpose. To establish one authoritative positional picture of the estate, so that every later judgment about priority, reachability and risk is made against the same ground.

Discussion

A register in a spreadsheet is not terrain. Terrain is positional: it records where an element sits relative to boundaries and to other elements, because position determines how an adversary moves. The overlay is the single artifact from which every other ASOM product is derived, which means an error introduced here propagates to reachability, coverage, backlog ranking and the Brief without being independently detectable in any of them.

Goals and Metrics

A metric that cannot come out badly is not a metric. Each of these is capable of reporting that the control is not working.

The overlay accounts for everything inside the authorization boundary.
  • Percentage of inventoried systems present on the overlay
  • Number of elements discovered during a cycle that were absent from the overlay
The overlay records position, not just existence.
  • Percentage of elements placed inside a declared trust zone
  • Number of elements with no recorded connections

Accountability

Exactly one role is accountable, and every other role carries at least Informed — no control in the published catalog leaves a role with zero relationship to it. That is a stated property of how these were authored, not a coincidence, and not a claim that every role's work is worth equal attention here.

AOCTISOCHUNTPLATISSO
Authorizing Official / CISO: AccountableCyber Threat Intelligence cell: ConsultedSOC / Defensive Operations: ConsultedHunt team: InformedPlatform and product owners: ResponsibleGovernance / RMF / ISSO: Informed

AO Authorizing Official / CISOCTI Cyber Threat Intelligence cellSOC SOC / Defensive OperationsHUNT Hunt teamPLAT Platform and product ownersISSO Governance / RMF / ISSO

  • AccountableAuthorizing Official / CISO
  • ConsultedCyber Threat Intelligence cell
  • ConsultedSOC / Defensive Operations
  • InformedHunt team
  • ResponsiblePlatform and product owners
  • InformedGovernance / RMF / ISSO

Inputs and Outputs

Consumes

  • Outside the frameworkNetwork and cloud architecture diagrams
  • TM-6 Terrain CurrencyRefresh trigger from the currency cadence or a material architectural change

Produces

Activities

  1. L2Establish the authorization boundary as the overlay's outer edge, and record what was deliberately excluded and on whose authority.
  2. L2Populate the overlay from the authoritative asset inventory.
  3. L2Represent external actors — public users, partner agencies, suppliers, unauthenticated internet — as first-class elements rather than as an arrow at the boundary.
  4. L3Reconcile count and identity against the inventory rather than transcribing a subset, so completeness is a property of the method.
  5. L3Group every element into the trust zone that actually contains it, taken from enforced configuration rather than architectural intent.
  6. L3Record the derivation of each element: system of record, date, and who confirmed it.
  7. L3Publish the overlay in a form readable without the tool that produced it, so the artifact survives a change of platform.
  8. L4Measure reconciliation variance between overlay and inventory each cycle and set a threshold above which the overlay is not fit to plan from.
  9. L4Trend the age of the overlay at the moment it is used for a decision, not at the moment it was refreshed.
  10. L5Feed elements discovered during engagements — which the inventory did not contain — back into the inventory process, not only onto the overlay.

Measurement

Outcome

Percentage of inventory elements present on the overlay.

Performance

Median age of the overlay at time of use.

Evidence and Assessment

Evidence expected

Cyber Terrain Overlay (Figure 1 of the Brief); exported diagram source; derivation and reconciliation record.

Assessment procedure

Examine the overlay; interview the architecture owner; compare against the authoritative asset inventory for completeness.

Related Guidance

Inherits
  • CM-8
  • PM-5
  • RA-9
Satisfies
  • ID.AM-01
  • ID.AM-03

Position in the Chain

Derived from the other controls’ own declarations, so the two directions cannot disagree.

Where This Control Is Used

Derived, in every case, from the declaration at the other end: the forms whose techniques name this control, the artifacts whose producing and consuming controls include it, the layers whose control lists name it, and the roles its own accountability chart puts to work. Nothing here is authored on this page, so the sheet cannot claim an edge the other end does not.

Forms of Maneuver It Assesses

  • M1Screen / GuardGain early warning and buy reaction time before the adversary touches key terrain.5 of 15 techniques — M1.01, M1.02, M1.03, M1.11, M1.15
  • M10Exploitation & PursuitConvert contact into durable advantage rather than closing the ticket.2 of 7 techniques — M10.03, M10.07

Terrain It Is Named On

Applies to all ten layersPuts the layer’s elements on the overlay in the first place. Nothing below can be computed for terrain that is not inventoried.

Artifacts It Stands On

  • producesCyber Terrain OverlayThe positional map of the estate: every element with a defensive layer, a defensive weight, a named accountable owner and its adjacencies. Not an asset inventory — an inventory enumerates, an overlay positions.
  • consumesChange recordEvery defensive action carried out, stamped twice — at the decision and at the effect. A thin, unglamorous table, and the one the headline metric is computed from.

Roles It Puts to Work