Control Statement
Personnel in identified workforce terrain shall receive preparation specific to how their role is actually attacked, and their readiness shall be measured rather than attested.
Purpose. To prepare people for the attacks their role attracts, and to know whether the preparation worked.
Discussion
Completion is attestation; performance is measurement, and the gap between them is where most awareness programs live. A hundred percent completion rate across generic annual training tells you about administration, not about readiness. Role specificity is the other half: the attacks aimed at a finance approver, a systems administrator and a public-facing caseworker are different, and generic content prepares none of them well. The design constraint worth stating is that measurement here is of a *role's* readiness, and results should be used to direct preparation rather than to identify individuals for sanction — a program that punishes failure gets under-reporting, which is the opposite of what it needs.
Goals and Metrics
A metric that cannot come out badly is not a metric. Each of these is capable of reporting that the control is not working.
- Measured readiness by role, from exercise performance rather than completion records
- Gap between attested completion and measured performance
Accountability
Exactly one role is accountable, and every other role carries at least Informed — no control in the published catalog leaves a role with zero relationship to it. That is a stated property of how these were authored, not a coincidence, and not a claim that every role's work is worth equal attention here.
| AO | CTI | SOC | HUNT | PLAT | ISSO |
|---|---|---|---|---|---|
| Authorizing Official / CISO: Accountable | Cyber Threat Intelligence cell: Consulted | SOC / Defensive Operations: Informed | Hunt team: Informed | Platform and product owners: Consulted | Governance / RMF / ISSO: Responsible |
AO Authorizing Official / CISOCTI Cyber Threat Intelligence cellSOC SOC / Defensive OperationsHUNT Hunt teamPLAT Platform and product ownersISSO Governance / RMF / ISSO
- AccountableAuthorizing Official / CISO
- ConsultedCyber Threat Intelligence cell
- InformedSOC / Defensive Operations
- InformedHunt team
- ConsultedPlatform and product owners
- ResponsibleGovernance / RMF / ISSO
Inputs and Outputs
Consumes
- WF-1 Workforce Terrain IdentificationIdentified roles requiring preparation
- Outside the frameworkThreat intelligence on tradecraft targeting each role
Produces
- TA-5 Tempo Degradation TriggerReadiness gaps as tempo degradation conditions
- CE-5 Remediation Backlog PrioritizationReadiness shortfalls entering the backlog
Activities
- L2Provide preparation to personnel in identified workforce terrain.
- L2Measure readiness by test or exercise rather than by completion.
- L2Record results against the role.
- L3Derive content per role from current reporting on how that role is actually attacked, rather than from a generic curriculum.
- L3Define the readiness threshold per role and its provenance per GA4.
- L3Use results to direct further preparation at the role, and define explicitly how individual results may and may not be used.
- L3Refresh content when the attack pattern against a role changes, not on an annual calendar alone.
- L4Trend measured readiness per role against its threshold and escalate roles that remain below it across cycles.
- L4Correlate readiness against real incidents involving those roles, since a readiness measure that does not predict incident involvement is measuring the wrong thing.
- L5Redesign the role or its controls where readiness cannot be brought to threshold, on the basis that a role people cannot reliably hold is a design problem rather than a training problem.
Measurement
Measured readiness per marked role against its threshold.
Currency of role content against current attack reporting.
Evidence and Assessment
Exercise results by role; content mapped to the campaigns it prepares for; threshold definitions with provenance.
Examine content against current threat reporting for those roles; test measured results against the stated readiness threshold; examine whether individual results are used within the stated limits.
Related Guidance
- AT-3
- AT-2(1)
- PS-7
- PR.AT-01
- PR.AT-02
Position in the Chain
Derived from the other controls’ own declarations, so the two directions cannot disagree.
Where This Control Is Used
Derived, in every case, from the declaration at the other end: the forms whose techniques name this control, the artifacts whose producing and consuming controls include it, the layers whose control lists name it, and the roles its own accountability chart puts to work. Nothing here is authored on this page, so the sheet cannot claim an edge the other end does not.
Forms of Maneuver It Assesses
- M2Defense in DepthEnsure no single failure is decisive.1 of 18 techniques — M2.16
- M5AmbushTrade space for information and time, and impose cost.1 of 13 techniques — M5.12
- M9Spoiling AttackDisrupt adversary staging before the attack is launched.1 of 9 techniques — M9.08
Terrain It Is Named On
- T7WorkforceRole-based readiness, and the requirement that it be demonstrated rather than completed.
Artifacts It Stands On
- producesRole-based readiness recordPreparation targeted at the tradecraft that actually targets each role, and the gaps that would slow the decision loop if the role were needed under contact.
- consumesWorkforce terrain registerThe roles whose compromise is equivalent to compromising a decisive point — the operators of decisive points, and the roles with standing access to them.
Roles It Puts to Work
- AccountableAuthorizing Official / CISOIntent, risk acceptance, and the scheme itself.
- ResponsibleGovernance / RMF / ISSOTranslating cycle outputs into FISMA and RMF artifacts, and owning the rules of engagement.
- ConsultedCyber Threat Intelligence cellFrame, Map and Fuse. The intelligence requirements, the threat courses of action, and the confidence levels.
- ConsultedPlatform and product ownersTheir own terrain. Obstacles get emplaced on their ground, so they site them.
- InformedSOC / Defensive OperationsManeuver. Executes fires and emplaces obstacles inside the standing rules of engagement.
- InformedHunt teamCounterattack. Works the hypotheses that Fuse raises.