ASOM-Fed translates the Army's Analytic Scheme of Maneuver into cyber terrain, forms of defensive maneuver, and a campaign operating cycle for federal agency networks — with temporal advantage as the signature metric.
Agency-agnostic by design. The framework is built against a generic Federal Reference Agency archetype; adopters substitute their own systems, boundaries, and mission threads. It maps to ZTMM, NIST RMF, CSF 2.0, and FISMA.
Federal cyber defense is well served at two levels and unserved between them. Above, maturity and outcome models — ZTMM, CSF 2.0 — say what should be true. Below, control catalogs — SP 800-53, with roughly 1,196 of them — say what must be present. Neither expresses the thing that decides an engagement: how a defence is arrayed, what it does first, what it gives up, and whether it can act faster than the adversary can adapt.
That gap is not theoretical. Doctrine on cyber manoeuvre argues persuasively that defenders should think in terms of terrain, position and tempo, and then stops short of stating anything an assessor could examine, interview against, or test. ASOM-Fed is the missing specification: the manoeuvre layer, written so it can be assessed and so performing it produces the evidence as a by-product.
We scored ten representative federal agency architectures — benefits administration, a regulator, a research laboratory, law enforcement, health services, a financial regulator, land management, a defense-adjacent civilian agency, a small independent agency, and a shared service provider — against the whole framework. Coverage is measured as ground held: the framework is 75 terrain×form cells, and an estate scores by how many it can actually operate on, not by how many technique rows a single tag happens to light up.
These are illustrative reference architectures, not audits of named agencies. The point is not the scores; it is that the questions are answerable at all, and that the answers are uncomfortable in the same places across very different agency shapes. An eleventh reference estate — the target state — holds all 75 cells and every one of the 150 techniques. It is an exemplar rather than an agency: no real federal estate looks like that, and it exists so a remediation plan has a destination instead of a slogan.
It is not a replacement for SP 800-53 — it inherits from it and says so in every control. It is not a threat-intelligence source, it names no vendors, and nothing in it contemplates action outside an agency's own boundary. It is unclassified, agency-agnostic, free to use, free to extend, and built to be argued with.
Eleven durable forms of defensive cyber maneuver across the top, 150 techniques beneath them — the whole framework laid out the way an adversary-behavior matrix lays out attacker tradecraft, but for the defender's half of the problem. It is the studio's framework connector: load a canvas design and the matrix reports which techniques that design actually evidences, and which forms of maneuver it cannot perform at all.
Open the matrix →Drag assets onto the canvas, connect them, and group them into zones. The studio scores the design live — assets, connections, key terrain, and defensive weight by tower — then exports to SVG or PNG. Load the Federal Reference Agency template to start from the archetype.
Open the studio →A complete agency estate put on the ASOM-Fed map asset by asset — terrain, key terrain, coverage scoring — then run as both a proactive and a reactive hunt, crosswalked to CSF 2.0 and MITRE D3FEND.
Walk the example →Why the framework is shaped the way it is — the object model, the level of abstraction it occupies, and the criteria every form of maneuver and technique must meet to be admitted.
Read the design document →The operating cycle end to end: cyber terrain overlays, the maneuver catalog, campaign phasing, and pre-authorized fires/ROE.
Read the playbook →The asset → tower → maneuver → mission allocation model, showing how defensive effort maps from infrastructure up to mission outcomes.
Explore the model →The full written doctrine document — definitions, maneuver forms, metrics, and the control-framework crosswalk.
Download (.docx) ↓The leadership-level walkthrough: why maneuver, what changes operationally, and how temporal advantage is measured.
Download (.pptx) ↓Implementation guidance for the control set — what each control requires, the evidence it produces, and how it is assessed.
Download (.docx) ↓