How a security program actually progresses - ten phases across three stages, four recognized maturity tiers, and what each number on your results page means for where you actually stand.
All ten phases side by side: what goes in, what comes out, and what "done" actually looks like before the program moves on. Use this as the quick reference; the sections below go phase by phase in depth.
| Level | Phase | Stage | Inputs reviewed | What it produces | Definition of done |
|---|---|---|---|---|---|
| 01 | Asset & Data Discovery | Discovery | Hardware, software, and cloud resource lists; data stores; shadow IT reports. | A living asset inventory covering every system and data store. | Every asset can be named to an owner - nothing is on the network by surprise. |
| 02 | Attack Surface Mapping | Discovery | External-facing infrastructure: websites, APIs, VPNs, remote access, third-party integrations. | A complete external attack-surface map showing every entry point. | You can name every way in from outside, not just the obvious ones. |
| 03 | Governance & Ownership Baseline | Discovery | Org chart, existing decision-making authority, current (if any) security responsibilities. | Named ownership assigned for every security decision and control. | You can point to the specific person accountable for any given control. |
| 04 | Gap Analysis & Prioritization | Discovery | Current-state controls measured against a recognized framework (NIST CSF, CIS Controls). | A ranked backlog of gaps ordered by risk - this is what the Assessment tab generates. | Every gap has a severity ranking and a place in the backlog, not just a list of problems. |
| 05 | Control Implementation | Transformation | The prioritized gap backlog from Phase 4. | Deployed technical controls - MFA, EDR, segmentation, email auth, backup isolation. | The gap that triggered a control's deployment no longer shows up on the next Assessment. |
| 06 | Policy & Documentation | Transformation | Controls implemented in Phase 5, plus any regulatory or compliance obligations. | Written policy, incident response plan, backup/DR plan, and risk register (see Runbooks). | The program is documented well enough that someone new could follow it without tribal knowledge. |
| 07 | Response Readiness & Testing | Transformation | The written plans and runbooks produced in Phase 6. | Completed tabletop exercises, backup-restore drills, and rehearsed runbook walkthroughs. | Every plan has actually been rehearsed, not just filed. |
| 08 | Continuous Monitoring & Tuning | Optimization | Live telemetry - logs, alerts, and detection signals. | Tuned detection with a signal-to-noise ratio the team actually trusts. | False-positive rate is trending down, not just alert volume trending up. |
| 09 | Auditing & Validation | Optimization | Deployed controls and monitoring output from Phases 5 and 8. | Vulnerability scan results, penetration test findings, and compliance audits (ISO 27001, SOC 2). | Findings are tracked to remediation, not just discovered. |
| 10 | Adaptive Iteration | Optimization | Lessons from real incidents, audit findings, and a changing threat landscape. | Updated priorities fed back into Phase 4's gap analysis. | Next quarter's priorities visibly reflect what was actually learned. |
You don't have a security program yet so much as a starting point - the goal is visibility: what exists, where it's exposed, and who owns fixing it.
Inventory hardware, software, cloud resources, and data stores - including shadow IT. You can't protect what you don't know exists, and this is where most real gaps first surface.
Identify every external-facing entry point - websites, APIs, VPNs, remote access, third-party integrations - and understand how an attacker would actually get in.
Assign real accountability for security decisions before writing a single control. Without an owner, findings from every later phase just accumulate unactioned.
Compare current state against a recognized framework (NIST CSF, CIS Controls) and rank gaps by risk - this is the exact function this site's Assessment tab performs.
Findings become controls, and controls become documented, rehearsed processes - this is where most of the actual engineering and writing happens.
Roll out the prioritized technical controls - MFA, EDR, network segmentation, email authentication, backup isolation - turning the roadmap into deployed defenses.
Formalize the program in writing: security policy, incident response plan, backup/DR plan, risk register. See the Runbooks tab for what each of these should actually contain.
Rehearse the plans, don't just file them - tabletop exercises, restore drills from backup, and walkthroughs of the ransomware/phishing/DDoS runbooks before a real incident forces it.
The program runs continuously - monitored, tested, and adjusted as the environment and threat landscape change, rather than declared "done."
Operationalize logging and detection, and tune it against real telemetry - an alert nobody trusts because of noise is functionally the same as no alert.
Vulnerability scans, penetration tests, and control audits confirm defenses work as intended rather than just existing on paper - this is also where compliance audits (ISO 27001, SOC 2) fit in.
Feed lessons from incidents, audits, and a changing threat landscape back into the program - and back into Phase 4's gap analysis, since this loop never really ends.
NIST CSF itself defines four Implementation Tiers describing how an organization's risk management practice matures - this site's repeat-assessment design mirrors that same progression, just measured through this specific instrument instead of a qualitative review.
Risk management is reactive and ad hoc. Practices exist inconsistently across the organization, often driven by individual initiative rather than policy.
Risk management practices are approved by management but not established as organization-wide policy - awareness exists, consistency doesn't yet.
Practices are formally approved and expressed as policy, applied consistently, and regularly updated based on changes in risk and the environment.
The organization adapts its practices continuously based on lessons learned and predictive indicators - security is a living, improving process, not a static state.
Every phase, with how it's actually monitored and what it unlocks next. For how your score itself is calculated, see the Metrics page.
| Level | Stage | Title | How it's monitored | How it advances the program |
|---|---|---|---|---|
| 01 | Discovery | Asset & Data Discovery | Tracked via a living asset inventory, reviewed whenever new systems, cloud resources, or vendors are added - not just annually. | Once assets are known, Phase 2 can map real exposure instead of guessing at it. |
| 02 | Discovery | Attack Surface Mapping | Re-checked whenever external-facing infrastructure changes - new domains, new APIs, new remote-access points. | A mapped surface is what makes Phase 4's gap analysis meaningful rather than generic. |
| 03 | Discovery | Governance & Ownership Baseline | Verified through named accountability - can you point to the specific person who owns a given control? | Without an owner, nothing found in later phases gets actioned - this single phase unlocks every one after it. |
| 04 | Discovery | Gap Analysis & Prioritization | This is literally what the Assessment tab re-measures every time you run it - your score IS this phase's monitoring signal. | Turns raw findings into an ordered backlog, which is what Phase 5 actually executes against. |
| 05 | Transformation | Control Implementation | Tracked as percentage of the Phase 4 backlog actually deployed, not just planned or ticketed. | Each control closed here is a specific finding that disappears from your next Assessment run. |
| 06 | Transformation | Policy & Documentation | Reviewed on the cadence the policy itself states - typically annually, or after any material infrastructure change. | Turns implemented controls into an auditable, teachable program instead of tribal knowledge that leaves when one person does. |
| 07 | Transformation | Response Readiness & Testing | Measured by whether tabletop exercises and restore drills actually happened, not whether a plan merely exists on paper. | The last step before a program is operational rather than aspirational - directly supported by the Runbooks tab. |
| 08 | Optimization | Continuous Monitoring & Tuning | Tracked via alert precision over time - false-positive rate trending down, not just alert volume trending up. | Reliable detection is the precondition for Phase 9's audits meaning anything at all. |
| 09 | Optimization | Auditing & Validation | Tracked via time-to-remediate findings from scans, pen tests, and compliance audits - not merely whether audits happened. | Confirms which Phase 5 controls are actually working versus just installed and forgotten. |
| 10 | Optimization | Adaptive Iteration | Tracked by whether lessons from real incidents and audits visibly change next quarter's priorities. | Feeds directly back into Phase 4 - the phase that makes the other nine a cycle instead of a one-time checklist. |