ASOM-Fed · Asset & Network Tower Model

Applying the Analytic Scheme of Maneuver — assets on cyber terrain, maneuvers, and mission coverage
v3.0 · Recommended reference framework for U.S. federal agencies · adopt & adapt · Unclassified / Illustrative

ASOM applied end-to-end

A recommended reference framework any U.S. federal agency can adopt to apply the Analytic Scheme of Maneuver (ASOM) in full to its network. Assets occupy cyber terrain (the towers); maneuvers are arrayed on that terrain to protect mission services; coverage and residual risk roll up into the CISO's running estimate and the temporal-advantage scoreboard. The allocation spine is native to ASOM — terrain → maneuver → mission. The allocation driver is Defensive Weight = Criticality × Exposure. Systems below are a generic Federal Reference Agency archetype — swap in your own.

Network topology — the terrain, keyed to towers

A generic Federal Reference Agency network as zero-trust zones — adopt and rename per agency. Every request is brokered at the Identity plane; policy-enforcement points (PEP) guard each boundary. Asset color = the Defense Tower that owns it — the same colors used across every other tab.

Federal Reference Agency — Zero-Trust Network Topology, keyed to Defense Towers Every request is brokered at the Identity plane; policy-enforcement points (PEP) sit at each zone boundary. Asset color = owning Defense Tower. INTERNET · EXTERNAL ACTORS Public / Mission Users — citizens · businessesPublic / Mission Userscitizens · businesses External Partners — contractors · other agenciesExternal Partnerscontractors · other agencies API / Open-Data Consumers — public data pipelinesAPI / Open-Data Consumerspublic data pipelines ⚠ Threat Actors — nation-state · fraud · ransomware⚠ Threat Actorsnation-state · fraud · ransomware VISIBILITY & AUTOMATION SIEM / SOC — Visibility & AnalyticsSIEM / SOCVisibility & Analytics SOAR — Automation & OrchestrationSOARAutomation & Orchestration Threat Intel / CISA-JCDC — feeds M1, M9Threat Intel / CISA-JCDCfeeds M1, M9 Hunt Team — counterattack (M7)Hunt Teamcounterattack (M7) observes every zone ↓ ◈ PEP · TIC 3.0 Access TIC 3.0 EDGE · PERIMETER DDoS Mitigation / CDN — edge — T3DDoS Mitigation / CDNedge — T3 Web Application Firewall (WAF) — T3 / T4Web Application Firewall (WAF)T3 / T4 TIC 3.0 Trust-Zone Gateway — egress + inspection — T3TIC 3.0 Trust-Zone Gatewayegress + inspection — T3 ◈ PEP · Identity — every request IDENTITY PLANE — the decisive terrain ICAM / Policy Decision Point — T1 — brokers all accessICAM / Policy Decision PointT1 — brokers all access Phishing-resistant MFA — T1Phishing-resistant MFAT1 PKI / PIV — T1PKI / PIVT1 Privileged Access (PAM/JIT) — T1Privileged Access (PAM/JIT)T1 AWS CLOUD — VPCs (segmented) PUBLIC-FACING MISSION TIER Load Balancer — T3Load BalancerT3 Public Service Portal — mission app — T4Public Service Portalmission app — T4 Secondary Portal — T4Secondary PortalT4 Case Filing — T4Case FilingT4 Public Data / Open API — T4Public Data / Open APIT4 ◈ PEP · east-west denied INTERNAL · MISSION-PROCESSING TIER Case Processing System — mission workload — T4Case Processing Systemmission workload — T4 Mission-Staff Workstations — EDR — T2Mission-Staff WorkstationsEDR — T2 Microsegmentation — T3MicrosegmentationT3 CI/CD Pipeline — decisive point — T4CI/CD Pipelinedecisive point — T4 ◈ PEP · data — most restricted DATA TIER — the objective Sensitive Mission Records — crown jewel — T5Sensitive Mission Recordscrown jewel — T5 PII Store — T5PII StoreT5 Financial Data — T5Financial DataT5 S3 Buckets — T5S3 BucketsT5 Audit Logs — telemetry — T5Audit Logstelemetry — T5 Defense Tower key: IdentityDevicesNetworksApplications and WorkloadsDataCross-cutting ◈ PEP = Policy-Enforcement Point (zero-trust boundary check). Dashed = observation by Visibility/Automation. ⚠ = adversary avenue of approach.

Tower Allocation Map — bidirectional traceability

Click any node to trace it. Pick a mission to see every maneuver, tower, and asset defending it — or an asset to see everything it protects. Click empty space to reset.

Asset Register — the Cyber Terrain Overlay

The CPE output: every asset on the terrain, its owning tower, whether it is key terrain / a decisive point, its Defensive Weight (Crit×Exp), the coverage it inherits from its tower, the maneuvers protecting it, and its residual risk. Sortable — click a header.

Tower Coverage — terrain readiness

Each Defense Tower's rolled-up coverage (ZTMM maturity → %), its sub-towers, and the assets and weight it carries. Weakest sub-towers are the ranked control backlog that the ASOM Cycle's ASSESS step feeds back into the next FRAME.

Mission Bill of Defense — the running estimate per mission

For each mission service: the assets and towers defending it, its weighted coverage, and residual risk — the CISO's running estimate at mission altitude, and the input to the temporal-advantage scoreboard.

Part of the ASOM-Fed suite
This allocation model is one of seven interlocking artefacts. The Framework states the doctrine; the Application & Control Guide turns it into 60 assessable controls inheriting from NIST SP 800-53 Rev. 5; the Playbook is the browsable reference; this Tower Model allocates assets to layers, maneuvers and missions; the Diagram Studio is where the work is done and where the control set evaluates live; the Brief it generates is the cycle record; and the topology diagrams give the reference architecture.
The chain: Framework (why) → Control Guide (what must be true) → Studio (do it) → Brief (prove it) → Cycle history (prove it over time).