TID-CMM Threat-Informed Detection Capability Maturity Model
HomeAssessmentEnvironment

Step 1 — your environment

What you run, what you collect and how you work. Everything downstream is derived from this.

What this step establishes

Everything downstream derives from this step. The platforms you declare determine which ATT&CK techniques can apply to you at all; the telemetry you declare determines what could ever be detected; the operating model and size determine how much of the model you are assessed against.

What it asks

How to answer well

Declare what is true today, not what is planned or partially rolled out. The telemetry step later asks how much of the estate each source covers, so there is a place for “we have it on the servers only” — it is not here.

The profile is derived, not chosen. A small organisation with no SOC lands on the essential profile and is assessed against 22 sub-capabilities. You may choose a heavier or lighter profile, and the model records a challenge if the choice is implausible for what you declared. The tool shows the reasoning behind the derivation rather than only its result, because a derivation nobody can see is indistinguishable from an arbitrary one.

Declaring that you are regulated never leaves you on the essential profile. That profile exists for teams under no obligation to show their working to anyone outside. A regulator, an auditor or an incoming CISO is exactly such a reader, so the floor for a regulated organisation is the standard profile.

Start the assessment