ASOM-Fedv6.1Open the explorer
WF-3 · Workforce Terrain

Role-Based Readiness

Control Statement

Personnel in identified workforce terrain shall receive preparation specific to how their role is actually attacked, and their readiness shall be measured rather than attested.

Purpose. To prepare people for the attacks their role attracts, and to know whether the preparation worked.

Discussion

Completion is attestation; performance is measurement, and the gap between them is where most awareness programs live. A hundred percent completion rate across generic annual training tells you about administration, not about readiness. Role specificity is the other half: the attacks aimed at a finance approver, a systems administrator and a public-facing caseworker are different, and generic content prepares none of them well. The design constraint worth stating is that measurement here is of a *role's* readiness, and results should be used to direct preparation rather than to identify individuals for sanction — a program that punishes failure gets under-reporting, which is the opposite of what it needs.

Goals and Metrics

A metric that cannot come out badly is not a metric. Each of these is capable of reporting that the control is not working.

Preparation is role-specific and measured.
  • Measured readiness by role, from exercise performance rather than completion records
  • Gap between attested completion and measured performance

Accountability

Exactly one role is accountable, and every other role carries at least Informed — no control in the published catalog leaves a role with zero relationship to it. That is a stated property of how these were authored, not a coincidence, and not a claim that every role's work is worth equal attention here.

AOCTISOCHUNTPLATISSO
Authorizing Official / CISO: AccountableCyber Threat Intelligence cell: ConsultedSOC / Defensive Operations: InformedHunt team: InformedPlatform and product owners: ConsultedGovernance / RMF / ISSO: Responsible

AO Authorizing Official / CISOCTI Cyber Threat Intelligence cellSOC SOC / Defensive OperationsHUNT Hunt teamPLAT Platform and product ownersISSO Governance / RMF / ISSO

  • AccountableAuthorizing Official / CISO
  • ConsultedCyber Threat Intelligence cell
  • InformedSOC / Defensive Operations
  • InformedHunt team
  • ConsultedPlatform and product owners
  • ResponsibleGovernance / RMF / ISSO

Inputs and Outputs

Consumes

Produces

Activities

  1. L2Provide preparation to personnel in identified workforce terrain.
  2. L2Measure readiness by test or exercise rather than by completion.
  3. L2Record results against the role.
  4. L3Derive content per role from current reporting on how that role is actually attacked, rather than from a generic curriculum.
  5. L3Define the readiness threshold per role and its provenance per GA4.
  6. L3Use results to direct further preparation at the role, and define explicitly how individual results may and may not be used.
  7. L3Refresh content when the attack pattern against a role changes, not on an annual calendar alone.
  8. L4Trend measured readiness per role against its threshold and escalate roles that remain below it across cycles.
  9. L4Correlate readiness against real incidents involving those roles, since a readiness measure that does not predict incident involvement is measuring the wrong thing.
  10. L5Redesign the role or its controls where readiness cannot be brought to threshold, on the basis that a role people cannot reliably hold is a design problem rather than a training problem.

Measurement

Outcome

Measured readiness per marked role against its threshold.

Performance

Currency of role content against current attack reporting.

Evidence and Assessment

Evidence expected

Exercise results by role; content mapped to the campaigns it prepares for; threshold definitions with provenance.

Assessment procedure

Examine content against current threat reporting for those roles; test measured results against the stated readiness threshold; examine whether individual results are used within the stated limits.

Related Guidance

Inherits
  • AT-3
  • AT-2(1)
  • PS-7
Satisfies
  • PR.AT-01
  • PR.AT-02

Position in the Chain

Derived from the other controls’ own declarations, so the two directions cannot disagree.

Where This Control Is Used

Derived, in every case, from the declaration at the other end: the forms whose techniques name this control, the artifacts whose producing and consuming controls include it, the layers whose control lists name it, and the roles its own accountability chart puts to work. Nothing here is authored on this page, so the sheet cannot claim an edge the other end does not.

Forms of Maneuver It Assesses

  • M2Defense in DepthEnsure no single failure is decisive.1 of 18 techniques — M2.16
  • M5AmbushTrade space for information and time, and impose cost.1 of 13 techniques — M5.12
  • M9Spoiling AttackDisrupt adversary staging before the attack is launched.1 of 9 techniques — M9.08

Terrain It Is Named On

  • T7WorkforceRole-based readiness, and the requirement that it be demonstrated rather than completed.

Artifacts It Stands On

  • producesRole-based readiness recordPreparation targeted at the tradecraft that actually targets each role, and the gaps that would slow the decision loop if the role were needed under contact.
  • consumesWorkforce terrain registerThe roles whose compromise is equivalent to compromising a decisive point — the operators of decisive points, and the roles with standing access to them.

Roles It Puts to Work