One Estate, Put on the Map Asset by Asset.
The Federal Reference Agency is not a real agency — it is the archetype every ASOM-Fed artifact is instantiated against, so that an adopter maps their real systems onto its slots rather than starting from an empty canvas. This page runs it through the framework once, end to end, and stops at the step where the finding appears.
ASOM-Fed v6.1 · scored against the published catalog
Draw the Estate as Ground, Not as an Inventory.
Zones run top to bottom by trust. Color is the terrain layer, not the network segment — which is the distinction the whole exercise turns on. Drawing it this way is already TM-1 and TM-4.
The Federal Reference Agency, Colored by Terrain Layer.
Dashed lines are policy enforcement points. An asset list sorted by owner or by cost cannot produce this picture, and no scheme of maneuver can be written without it.
Exactly One Layer per Asset — The Layer Whose Loss Defeats It.
The step agencies skip, and the one everything downstream depends on: an unclassified asset cannot be scored, defended deliberately, or reported on. TM-2 exists to make it non-optional.
| Layer | Assets | Crit × Exp |
|---|---|---|
| T1 Identity | ICAM/IdP, PKI & PIV issuance, PAM broker, external-user directory, service and machine accounts | 5 × 4 |
| T2 Devices | Mission-staff laptops, contractor devices, mobile and BYOD, the server fleet, container hosts | 3 × 4 |
| T3 Networks | TIC access point, DDoS/CDN edge, WAF, DNS resolver, VPN gateway, cloud VPC peering | 4 × 5 |
| T4 Applications and Workloads | Public Service Portal, Case Processing System, adjudication workflow, public bulk-data API, CI/CD pipeline, secrets store | 5 × 5 |
| T5 Data | Case records, PII store, fee and financial database, staff work product, audit-log archive | 5 × 2 |
| TX Cross-Cutting | SIEM, SOAR, RMF and GRC tooling | 4 × 2 |
The argument you will have. Someone will insist the Case Processing System is “really” a data asset. Assign it to the layer whose loss defeats it: the application is defeated by application compromise, so it is T4, and the records it serves are separately T5. Splitting them is the point — they fail differently and are defended differently.
An asset is not the layer it sits on, and a layer is not a tier. If those words are doing unfamiliar work, the object model states all ten classes and what each one is mistaken for.
Four or Five Pieces of Key Terrain. One or Two Decisive Points.
Key terrain confers decisive advantage to whoever holds it. A decisive point is narrower: where seizing control unhinges the whole plan. If your list runs to twenty, you have listed important systems.
Whoever holds identity moves anywhere. Every other layer authorizes against it.
The objective. The reason the campaign exists at all.
Statutory availability, and the widest avenue of approach.
One policy change re-authorizes the estate. Inside the IdP, and distinct from it.
Poisoning it envelops everything downstream without touching any of it directly.
Every layer’s own key terrain and decisive point are declared in the terrain model; these are this estate’s.
Score the Matrix, Then Read It by Column.
Score each of the 154 techniques against the estate — SM-3 defines the states, and only operational counts toward coverage. Then ignore the percentage. The output that matters is which columns are empty.
Zones, PEPs, EDR and encryption are all funded — this is what compliance programs buy.
Phishing-resistant MFA is in place under the M-22-09 mandate, and conditional access was built alongside it.
Segmentation exists; nothing deliberately herds movement onto instrumented ground.
Advisories arrive; there is no timed path from advisory to disposition.
A hunt team exists and is competent; it is triggered by curiosity rather than by a standing intelligence requirement.
No deception anywhere. Every detection depends on recognizing something as bad.
Nothing slows an adversary who is already authenticated and behaving plausibly.
No rehearsed way to sever a zone or degrade the portal without an outage.
Nothing is done to raise the adversary’s cost before contact — no pre-emptive credential rotation, no forced re-tooling.
An engagement ends when the alert closes. What was learned does not become the next cycle’s collection.
Backups are reachable with production credentials, so they are part of the objective rather than the means of recovery.
This is the finding. The agency is well defended in the two columns that money and mandates already point at, and cannot perform four forms of maneuver at all. M5, M6, M8 and M11 are not missing products — they are missing capabilities, and no amount of further hardening inside M2 and M3 substitutes. An adversary who defeats identity once faces an estate that cannot deceive them, cannot slow them, and cannot give ground without falling over.
That sentence is what a budget conversation needs, and no control catalog produces it.
Where the Walkthrough Hands Off.
Everything above is preparation — Frame and Map, in the cycle’s terms. What follows is the framework running, and each of these is covered in full rather than summarized here.
The Hunt That Found Nothing
A cycle in which nobody was attacked, traced beat by beat, with every beat recording what it did not establish. It produces a bounded statement of cleared ground and a precise account of the ground it could not reach.
The Engagement
Contact on the estate above, from first indicator to transition back to steady state, with the authority latency on every beat that waited for a decision — which is most of the difference between a fast program and a slow one.
Clearing the Whole Estate
One hunt on one corridor is a demonstration. Running the same loop across a thousand devices, segment by segment, with a throughput that says what share you can honestly call clear, is the capability.
Your Estate, Not This One
Ten agency archetypes ship pre-scored, each a starting position rather than an empty canvas. Map your real systems onto the slots and every artifact downstream becomes yours.
Both Hunts Produce Evidence for Obligations the Agency Already Carries.
The forms map onto the NIST CSF 2.0 functions and onto MITRE D3FEND’s seven defensive tactics — D3FEND being this framework’s closest neighbor, and a natural source of technique-level rigor beneath these forms.
| ASOM-Fed form | NIST CSF 2.0 | D3FEND tactic |
|---|---|---|
| M1 Screen / Guard | Detect · Identify | Model, Detect, Deceive |
| M2 Defense in Depth | Protect | Model, Harden, Detect, Isolate, Evict, Restore |
| M3 Envelopment | Protect | Harden, Detect, Isolate, Evict |
| M4 Obstacle / Canalization | Protect | Model, Harden, Detect, Isolate |
| M5 Ambush | Detect | Isolate, Deceive |
| M6 Delay | Respond | Model, Harden, Detect, Isolate, Evict |
| M7 Counterattack | Detect · Respond | Model, Harden, Detect, Isolate, Evict, Restore |
| M8 Isolation / Retrograde | Respond · Recover | Detect, Isolate, Evict, Restore |
| M9 Spoiling Attack | Identify · Protect | Model, Harden, Detect, Isolate, Evict |
| M10 Exploitation & Pursuit | Recover · Govern | Model, Detect |
| M11 Reconstitution | Recover · Protect | Model, Harden, Detect, Isolate, Restore |
A gap this crosswalk exposed in ASOM-Fed itself. In version 1.0, M8 and M10 were mapped to the CSF 2.0 Recover function on doctrinal grounds — while not one of the sixty controls then published carried an RC. subcategory. The control set covered Govern, Identify, Protect, Detect and Respond, and stopped. An agency using the framework as its sole evidence source would have had no Recover evidence at all.
Version 2.0 closed it: M11 Reconstitution and five RC controls put real evidence behind the mapping. The gap is recorded here rather than deleted, because how a framework handles being wrong is part of what an adopter is assessing.
Read it in the right direction. D3FEND names what a countermeasure is; ASOM-Fed names when you employ it, on what ground, and what you give up. The tactics above are summarized from the full technique-level join — every mapping, the countermeasures it does not reach, and the reason recorded for each, are at the D3FEND crosswalk. That mapping used to be withheld from this site on the grounds that mirroring MITRE’s identifiers would let them drift; it is published now because a generator derives it from the register and a test fails on drift, which answers the objection better than omission did. Every control additionally carries its own NIST SP 800-53 Rev. 5 inheritance and CSF 2.0 subcategories; see the control catalog. D3FEND™ and ATT&CK® are trademarks of The MITRE Corporation. This mapping is published by threatDefendr and is neither produced nor endorsed by MITRE.
What to Open Next, Depending on Who Is Asking.
- The Control Guide — every control with its statement, discussion, evidence expectation and assessment procedure. For the assessor.
- The Playbook — the framework as an operating document, scored against a live design. For the program lead.
- The Tower Model — the estate rolled up through the framework’s layers, which is where coverage becomes a number. For the architect.
- The Executive Brief — the version you present to an Authorizing Official who has twenty minutes.
The Gap This Example Exposed Is the One the Catalog Is Organized Around.
Four forms of maneuver absent is a statement about capability, not about spending. The control set says what each of those forms requires, at a level of detail an assessor can examine, interview and test against.