Maturity Model
What is Maturity Model?
A framework that describes levels of organisational capability or process maturity, typically from initial/ad hoc to optimised. Used to benchmark progress and set improvement targets.
Terms that appear alongside maturity model
Each of these is named in at least one of the same controls as maturity model. The number is how many controls name both.
- cybersecurity 10 shared controls
- nist 9 shared controls
- compliance 6 shared controls
- information security 6 shared controls
- governance 5 shared controls
- policy 5 shared controls
- cybersecurity maturity 5 shared controls
- cisa 5 shared controls
Frameworks that govern maturity model
What the standards actually require on maturity model
Requirements naming maturity model across 6 standards, quoted from the control text.
STAR Certification includes a maturity capability assessment that scores the management of CCM control areas beyond a pass/fail basis, giving customers insight into control maturity.
STAR-L2-05 · Maturity model scoring →FISMA + FedRAMP coordination for cloud services. FEDRAMP (Federal Risk and Authorization Management Program) operationalizes FISMA for CLOUD SERVICES used by federal agencies (established by OMB Memorandum M-11-30 + modernized by M-24-15 of July 2024).
FISMA-FedRAMP-Cloud-Coordination · FedRAMP for Cloud Services + 800-37 ATO Integration →The IRM Risk Architecture + Strategy + Protocols (RASP) framework defines the governance + structural + behavioural enabling elements of effective enterprise risk management.
IRM-Architecture-Strategy-Protocols-Appetite-Culture-Board-Audit-Committee-CRO-Three-Lines · IRM RASP - Risk Architecture + Strategy + Protocols + Risk Appetite Statement + Risk Culture + Board + Audit Committee + Chief Risk Officer + Three Lines of Defence + Tone at the Top →Implement the Australian Signals Directorate's Essential Eight strategies to mitigate targeted cyber incidents, and self-assess maturity using the Essential Eight Maturity Model.
ASIC-CR-PR-1 · Implement the ASD Essential Eight →FIRST CSIRT Services Framework v2.1 (2019) Foundational. MANDATE + SCOPE: the CSIRT must have a CLEARLY DOCUMENTED MANDATE from its parent organisation (national authority + sector authority + corporate executive) defining: (a) AUTHORITY level (advisory + coor...
FIRST-CSIRTF-Mandate-Quality · CSIRT Services Framework v2.1 - Mandate, Scope and Quality Management →STATERAMP + GovRAMP are FedRAMP-aligned authorization programs for state + local + tribal governments. STATERAMP (https://stateramp.org/) - non-profit organization + administers state-government cloud authorization mirroring FedRAMP processes + uses FedRAMP-co...
FedRAMP-StateRAMP-GovRAMP · Coordination with StateRAMP, GovRAMP and state + local + tribal government cloud authorization →Questions people ask about maturity model
What is Maturity Model?
Why is Maturity Model important for compliance?
Which compliance frameworks address Maturity Model?
Where can I learn more about Maturity Model?
See how Maturity Model applies across compliance frameworks
Our platform maps 686 frameworks with 311K cross-framework control mappings. Explore how this concept is addressed across standards.