Maturity Model

Maturity Model

How a security program actually progresses - ten phases across three stages, four recognized maturity tiers, and what each number on your results page means for where you actually stand.

Model at a glance

All ten phases side by side: what goes in, what comes out, and what "done" actually looks like before the program moves on. Use this as the quick reference; the sections below go phase by phase in depth.

LevelPhaseStageInputs reviewedWhat it producesDefinition of done
01 Asset & Data Discovery Discovery Hardware, software, and cloud resource lists; data stores; shadow IT reports. A living asset inventory covering every system and data store. Every asset can be named to an owner - nothing is on the network by surprise.
02 Attack Surface Mapping Discovery External-facing infrastructure: websites, APIs, VPNs, remote access, third-party integrations. A complete external attack-surface map showing every entry point. You can name every way in from outside, not just the obvious ones.
03 Governance & Ownership Baseline Discovery Org chart, existing decision-making authority, current (if any) security responsibilities. Named ownership assigned for every security decision and control. You can point to the specific person accountable for any given control.
04 Gap Analysis & Prioritization Discovery Current-state controls measured against a recognized framework (NIST CSF, CIS Controls). A ranked backlog of gaps ordered by risk - this is what the Assessment tab generates. Every gap has a severity ranking and a place in the backlog, not just a list of problems.
05 Control Implementation Transformation The prioritized gap backlog from Phase 4. Deployed technical controls - MFA, EDR, segmentation, email auth, backup isolation. The gap that triggered a control's deployment no longer shows up on the next Assessment.
06 Policy & Documentation Transformation Controls implemented in Phase 5, plus any regulatory or compliance obligations. Written policy, incident response plan, backup/DR plan, and risk register (see Runbooks). The program is documented well enough that someone new could follow it without tribal knowledge.
07 Response Readiness & Testing Transformation The written plans and runbooks produced in Phase 6. Completed tabletop exercises, backup-restore drills, and rehearsed runbook walkthroughs. Every plan has actually been rehearsed, not just filed.
08 Continuous Monitoring & Tuning Optimization Live telemetry - logs, alerts, and detection signals. Tuned detection with a signal-to-noise ratio the team actually trusts. False-positive rate is trending down, not just alert volume trending up.
09 Auditing & Validation Optimization Deployed controls and monitoring output from Phases 5 and 8. Vulnerability scan results, penetration test findings, and compliance audits (ISO 27001, SOC 2). Findings are tracked to remediation, not just discovered.
10 Adaptive Iteration Optimization Lessons from real incidents, audit findings, and a changing threat landscape. Updated priorities fed back into Phase 4's gap analysis. Next quarter's priorities visibly reflect what was actually learned.

Discovery

Phases 1–4

You don't have a security program yet so much as a starting point - the goal is visibility: what exists, where it's exposed, and who owns fixing it.

01

Asset & Data Discovery

Inventory hardware, software, cloud resources, and data stores - including shadow IT. You can't protect what you don't know exists, and this is where most real gaps first surface.

02

Attack Surface Mapping

Identify every external-facing entry point - websites, APIs, VPNs, remote access, third-party integrations - and understand how an attacker would actually get in.

03

Governance & Ownership Baseline

Assign real accountability for security decisions before writing a single control. Without an owner, findings from every later phase just accumulate unactioned.

04

Gap Analysis & Prioritization

Compare current state against a recognized framework (NIST CSF, CIS Controls) and rank gaps by risk - this is the exact function this site's Assessment tab performs.

Transformation

Phases 5–7

Findings become controls, and controls become documented, rehearsed processes - this is where most of the actual engineering and writing happens.

05

Control Implementation

Roll out the prioritized technical controls - MFA, EDR, network segmentation, email authentication, backup isolation - turning the roadmap into deployed defenses.

06

Policy & Documentation

Formalize the program in writing: security policy, incident response plan, backup/DR plan, risk register. See the Runbooks tab for what each of these should actually contain.

07

Response Readiness & Testing

Rehearse the plans, don't just file them - tabletop exercises, restore drills from backup, and walkthroughs of the ransomware/phishing/DDoS runbooks before a real incident forces it.

Optimization

Phases 8–10

The program runs continuously - monitored, tested, and adjusted as the environment and threat landscape change, rather than declared "done."

08

Continuous Monitoring & Tuning

Operationalize logging and detection, and tune it against real telemetry - an alert nobody trusts because of noise is functionally the same as no alert.

09

Auditing & Validation

Vulnerability scans, penetration tests, and control audits confirm defenses work as intended rather than just existing on paper - this is also where compliance audits (ISO 27001, SOC 2) fit in.

10

Adaptive Iteration

Feed lessons from incidents, audits, and a changing threat landscape back into the program - and back into Phase 4's gap analysis, since this loop never really ends.

Phase 10 feeds back into Phase 4 - the Assessment tab is designed to be re-run on a cadence, precisely to drive this loop rather than end it.

Maturity is a known concept - we're borrowing it deliberately

NIST CSF itself defines four Implementation Tiers describing how an organization's risk management practice matures - this site's repeat-assessment design mirrors that same progression, just measured through this specific instrument instead of a qualitative review.

01

Partial

Risk management is reactive and ad hoc. Practices exist inconsistently across the organization, often driven by individual initiative rather than policy.

02

Risk Informed

Risk management practices are approved by management but not established as organization-wide policy - awareness exists, consistency doesn't yet.

03

Repeatable

Practices are formally approved and expressed as policy, applied consistently, and regularly updated based on changes in risk and the environment.

04

Adaptive

The organization adapts its practices continuously based on lessons learned and predictive indicators - security is a living, improving process, not a static state.

The full phase table

Every phase, with how it's actually monitored and what it unlocks next. For how your score itself is calculated, see the Metrics page.

LevelStageTitleHow it's monitoredHow it advances the program
01 Discovery Asset & Data Discovery Tracked via a living asset inventory, reviewed whenever new systems, cloud resources, or vendors are added - not just annually. Once assets are known, Phase 2 can map real exposure instead of guessing at it.
02 Discovery Attack Surface Mapping Re-checked whenever external-facing infrastructure changes - new domains, new APIs, new remote-access points. A mapped surface is what makes Phase 4's gap analysis meaningful rather than generic.
03 Discovery Governance & Ownership Baseline Verified through named accountability - can you point to the specific person who owns a given control? Without an owner, nothing found in later phases gets actioned - this single phase unlocks every one after it.
04 Discovery Gap Analysis & Prioritization This is literally what the Assessment tab re-measures every time you run it - your score IS this phase's monitoring signal. Turns raw findings into an ordered backlog, which is what Phase 5 actually executes against.
05 Transformation Control Implementation Tracked as percentage of the Phase 4 backlog actually deployed, not just planned or ticketed. Each control closed here is a specific finding that disappears from your next Assessment run.
06 Transformation Policy & Documentation Reviewed on the cadence the policy itself states - typically annually, or after any material infrastructure change. Turns implemented controls into an auditable, teachable program instead of tribal knowledge that leaves when one person does.
07 Transformation Response Readiness & Testing Measured by whether tabletop exercises and restore drills actually happened, not whether a plan merely exists on paper. The last step before a program is operational rather than aspirational - directly supported by the Runbooks tab.
08 Optimization Continuous Monitoring & Tuning Tracked via alert precision over time - false-positive rate trending down, not just alert volume trending up. Reliable detection is the precondition for Phase 9's audits meaning anything at all.
09 Optimization Auditing & Validation Tracked via time-to-remediate findings from scans, pen tests, and compliance audits - not merely whether audits happened. Confirms which Phase 5 controls are actually working versus just installed and forgotten.
10 Optimization Adaptive Iteration Tracked by whether lessons from real incidents and audits visibly change next quarter's priorities. Feeds directly back into Phase 4 - the phase that makes the other nine a cycle instead of a one-time checklist.