ASOM-Fedv6.1Open the explorer
Worked example

One Estate, Put on the Map Asset by Asset.

The Federal Reference Agency is not a real agency — it is the archetype every ASOM-Fed artifact is instantiated against, so that an adopter maps their real systems onto its slots rather than starting from an empty canvas. This page runs it through the framework once, end to end, and stops at the step where the finding appears.

ASOM-Fed v6.1 · scored against the published catalog

Step One

Draw the Estate as Ground, Not as an Inventory.

Zones run top to bottom by trust. Color is the terrain layer, not the network segment — which is the distinction the whole exercise turns on. Drawing it this way is already TM-1 and TM-4.

Exhibit 1

The Federal Reference Agency, Colored by Terrain Layer.

INTERNETTIC / EDGEIDENTITY PUBLIC TIERMISSION TIERDATA / CLOUD Public filersPartner agenciesAdversary TIC access ptDDoS / CDNWAFDNS resolverVPN gateway ICAM / IdPPKI / PIVPAM brokerExternal usersService accts Service PortalBulk-data APIAdjudicationCI/CD pipeline Staff laptopsContractor devServer fleetCase Processing Case recordsPII storeFee / financeAudit logCloud (S3/IAM) PEPPEPPEPPEPPEP

Dashed lines are policy enforcement points. An asset list sorted by owner or by cost cannot produce this picture, and no scheme of maneuver can be written without it.

Step Two

Exactly One Layer per Asset — The Layer Whose Loss Defeats It.

The step agencies skip, and the one everything downstream depends on: an unclassified asset cannot be scored, defended deliberately, or reported on. TM-2 exists to make it non-optional.

LayerAssetsCrit × Exp
T1 IdentityICAM/IdP, PKI & PIV issuance, PAM broker, external-user directory, service and machine accounts5 × 4
T2 DevicesMission-staff laptops, contractor devices, mobile and BYOD, the server fleet, container hosts3 × 4
T3 NetworksTIC access point, DDoS/CDN edge, WAF, DNS resolver, VPN gateway, cloud VPC peering4 × 5
T4 Applications and WorkloadsPublic Service Portal, Case Processing System, adjudication workflow, public bulk-data API, CI/CD pipeline, secrets store5 × 5
T5 DataCase records, PII store, fee and financial database, staff work product, audit-log archive5 × 2
TX Cross-CuttingSIEM, SOAR, RMF and GRC tooling4 × 2

The argument you will have. Someone will insist the Case Processing System is “really” a data asset. Assign it to the layer whose loss defeats it: the application is defeated by application compromise, so it is T4, and the records it serves are separately T5. Splitting them is the point — they fail differently and are defended differently.

An asset is not the layer it sits on, and a layer is not a tier. If those words are doing unfamiliar work, the object model states all ten classes and what each one is mistaken for.

Step Three

Four or Five Pieces of Key Terrain. One or Two Decisive Points.

Key terrain confers decisive advantage to whoever holds it. A decisive point is narrower: where seizing control unhinges the whole plan. If your list runs to twenty, you have listed important systems.

KEY
ICAM / IdP

Whoever holds identity moves anywhere. Every other layer authorizes against it.

KEY
Case records store

The objective. The reason the campaign exists at all.

KEY
Public Service Portal

Statutory availability, and the widest avenue of approach.

DECISIVE
Conditional-access policy engine

One policy change re-authorizes the estate. Inside the IdP, and distinct from it.

DECISIVE
CI/CD pipeline

Poisoning it envelops everything downstream without touching any of it directly.

Every layer’s own key terrain and decisive point are declared in the terrain model; these are this estate’s.

Step Four

Score the Matrix, Then Read It by Column.

Score each of the 154 techniques against the estate — SM-3 defines the states, and only operational counts toward coverage. Then ignore the percentage. The output that matters is which columns are empty.

M2
Defense in DepthStrong

Zones, PEPs, EDR and encryption are all funded — this is what compliance programs buy.

M3
EnvelopmentStrong

Phishing-resistant MFA is in place under the M-22-09 mandate, and conditional access was built alongside it.

M4
Obstacle / CanalizationPartial

Segmentation exists; nothing deliberately herds movement onto instrumented ground.

M1
Screen / GuardPartial

Advisories arrive; there is no timed path from advisory to disposition.

M7
CounterattackPartial

A hunt team exists and is competent; it is triggered by curiosity rather than by a standing intelligence requirement.

M5
AmbushAbsent

No deception anywhere. Every detection depends on recognizing something as bad.

M6
DelayAbsent

Nothing slows an adversary who is already authenticated and behaving plausibly.

M8
Isolation / RetrogradeAbsent

No rehearsed way to sever a zone or degrade the portal without an outage.

M9
Spoiling AttackAbsent

Nothing is done to raise the adversary’s cost before contact — no pre-emptive credential rotation, no forced re-tooling.

M10
Exploitation & PursuitAbsent

An engagement ends when the alert closes. What was learned does not become the next cycle’s collection.

M11
ReconstitutionAbsent

Backups are reachable with production credentials, so they are part of the objective rather than the means of recovery.

This is the finding. The agency is well defended in the two columns that money and mandates already point at, and cannot perform four forms of maneuver at all. M5, M6, M8 and M11 are not missing products — they are missing capabilities, and no amount of further hardening inside M2 and M3 substitutes. An adversary who defeats identity once faces an estate that cannot deceive them, cannot slow them, and cannot give ground without falling over.

That sentence is what a budget conversation needs, and no control catalog produces it.

Step Five

Where the Walkthrough Hands Off.

Everything above is preparation — Frame and Map, in the cycle’s terms. What follows is the framework running, and each of these is covered in full rather than summarized here.

Proactive

The Hunt That Found Nothing

A cycle in which nobody was attacked, traced beat by beat, with every beat recording what it did not establish. It produces a bounded statement of cleared ground and a precise account of the ground it could not reach.

Walk the proactive case →

Reactive

The Engagement

Contact on the estate above, from first indicator to transition back to steady state, with the authority latency on every beat that waited for a decision — which is most of the difference between a fast program and a slow one.

Walk the reactive case →

At scale

Clearing the Whole Estate

One hunt on one corridor is a demonstration. Running the same loop across a thousand devices, segment by segment, with a throughput that says what share you can honestly call clear, is the capability.

The clearing drill →

From here

Your Estate, Not This One

Ten agency archetypes ship pre-scored, each a starting position rather than an empty canvas. Map your real systems onto the slots and every artifact downstream becomes yours.

The adoption path →

Against What You Already Report

Both Hunts Produce Evidence for Obligations the Agency Already Carries.

The forms map onto the NIST CSF 2.0 functions and onto MITRE D3FEND’s seven defensive tactics — D3FEND being this framework’s closest neighbor, and a natural source of technique-level rigor beneath these forms.

ASOM-Fed formNIST CSF 2.0D3FEND tactic
M1 Screen / GuardDetect · IdentifyModel, Detect, Deceive
M2 Defense in DepthProtectModel, Harden, Detect, Isolate, Evict, Restore
M3 EnvelopmentProtectHarden, Detect, Isolate, Evict
M4 Obstacle / CanalizationProtectModel, Harden, Detect, Isolate
M5 AmbushDetectIsolate, Deceive
M6 DelayRespondModel, Harden, Detect, Isolate, Evict
M7 CounterattackDetect · RespondModel, Harden, Detect, Isolate, Evict, Restore
M8 Isolation / RetrogradeRespond · RecoverDetect, Isolate, Evict, Restore
M9 Spoiling AttackIdentify · ProtectModel, Harden, Detect, Isolate, Evict
M10 Exploitation & PursuitRecover · GovernModel, Detect
M11 ReconstitutionRecover · ProtectModel, Harden, Detect, Isolate, Restore

A gap this crosswalk exposed in ASOM-Fed itself. In version 1.0, M8 and M10 were mapped to the CSF 2.0 Recover function on doctrinal grounds — while not one of the sixty controls then published carried an RC. subcategory. The control set covered Govern, Identify, Protect, Detect and Respond, and stopped. An agency using the framework as its sole evidence source would have had no Recover evidence at all.

Version 2.0 closed it: M11 Reconstitution and five RC controls put real evidence behind the mapping. The gap is recorded here rather than deleted, because how a framework handles being wrong is part of what an adopter is assessing.

Read it in the right direction. D3FEND names what a countermeasure is; ASOM-Fed names when you employ it, on what ground, and what you give up. The tactics above are summarized from the full technique-level join — every mapping, the countermeasures it does not reach, and the reason recorded for each, are at the D3FEND crosswalk. That mapping used to be withheld from this site on the grounds that mirroring MITRE’s identifiers would let them drift; it is published now because a generator derives it from the register and a test fails on drift, which answers the objection better than omission did. Every control additionally carries its own NIST SP 800-53 Rev. 5 inheritance and CSF 2.0 subcategories; see the control catalog. D3FEND™ and ATT&CK® are trademarks of The MITRE Corporation. This mapping is published by threatDefendr and is neither produced nor endorsed by MITRE.

The Rest of the Suite

What to Open Next, Depending on Who Is Asking.

Next

The Gap This Example Exposed Is the One the Catalog Is Organized Around.

Four forms of maneuver absent is a statement about capability, not about spending. The control set says what each of those forms requires, at a level of detail an assessor can examine, interview and test against.