TID-CMM Threat-Informed Detection Capability Maturity Model
Home › Assessment › Results

Step 10 — results

The adjusted score, which constraints bound it, and which adversaries would walk through the gaps.

What this step shows

The results page reports the self-assessed score, the adjusted score, every constraint that bound it, and — the part most people have not seen before — which adversaries would walk through the gaps.

Detection exposure

For each threat group, the share of their in-scope playbook you would not reliably see: “you would not see 82 of 217 techniques they use”. Your prioritised groups first, then a second list of groups you did not prioritise and would not see either — which is usually the point of the exercise.

The exposure index

Probability × impact × visibility gap, aggregated and banded. A technique you can already see contributes nothing regardless of how dangerous it is, because this measures undetected risk rather than risk.

There is no currency figure, deliberately. A monetary number produced by a free tool from a guessed input is the number that gets challenged in the meeting where it matters. Crown jewels carry qualitative impact bands instead, and the CSV export carries every input out so real financial values can be applied in a register that owns them.

Derived readiness views

Below the domain table, three views read the answers you already gave through existing sub-capabilities. They add no domain, no weight and no score. Unknown-Threat Readiness groups TI.2 and TM.6 (threat-model learning), DC.2, DC.5, DC.6, DE.6 and DE.10 (visibility and resilience) and AA.2, AA.4, AA.5, AA.6 and AA.7 (investigation and adaptation), shows each level as the results table counts it, whether evidence text was supplied, the weakest and missing capabilities, and next actions taken from the model’s own level descriptors — never a percentage, because unknown threats cannot be counted. “Supplied” means that evidence text was entered; it does not by itself prove that the entry identifies a valid artefact, and C3 still requires a named artefact for levels 4 and 5. Each view opens as a summary with its full tables and every action in a disclosure beneath it. Correlation and Adversary Timeline Readiness shows AA.2 with AA.1, AA.6, TM.4, DC.2 and DC.3, and states that the tool evaluates whether the capability exists and does not correlate events, reconstruct incidents or predict activity. Prevention and Protection Readiness shows the AV.8 level and whether evidence text was supplied, the five AV.8 dimensions with what the browser tool actually collects for each, the TID-CMM–TIR-CMM boundary and the Export for TIR-CMM action; if AV.8 was not assessed it says so rather than estimating. AV.8 is not exported as a separate field or evidence narrative: when it is in scope its assessment can contribute to the aggregate AV domain and overall results, and the export does not carry AV.8 or per-technique prevention outcomes separately. The methodology behind each is on Known-Threat Assurance and Unknown-Threat Readiness, Cross-domain correlation and adversary timeline reconstruction and Prevention, protection and the TID-CMM–TIR-CMM boundary.

External framework views

Formerly the standards and assurance lens. A non-scoring card reads the result through the external frameworks declared on step 1. For each standard with a documented mapping it lists the in-profile sub-capabilities that carry a reference, groups them by reference with the lowest counted level, reminds you of the evidence the model asks for where a mapped sub-capability is below target or held down by a constraint, tags the matching roadmap rows, and repeats the sub-capability questions the standard would ask. It then states exactly what it did — how many sub-capabilities were cross-referenced, rows tagged and reminders added — and that no score changed. A regime without a reviewed mapping in the model is named as unmapped; nothing is inferred in its place. The lens never claims certification or complete compliance, and completing TID-CMM satisfies no legal obligation.

Assurance at a glance

Immediately before the roadmap, five evidence-based readings of what has already been recorded. Counts and denominators throughout; no new score, no gauge, no pie chart. Every visual has a table view beneath it.

ViewWhat it showsDenominator
A. Technique assuranceHow many in-scope techniques are blind or unobservable, visible only, detection evidenced, locally validated, or not assessed, from the detection register. A missing answer is not assessed, never visibility, detection or failure, even where the telemetry reach is 0%; the telemetry finding is stated separately beneath the bar.In-scope techniques
B. Tier A technique assurance by stageThe Tier A techniques placed on TIR-CMM stages S1–S7 from their ATT&CK tactics (a technique may appear at more than one stage): per stage, how many are visible, detected, validated, blind and not assessed; the blind arriving stages (a stage at which no Tier A technique is visible); the earliest stage with an evidenced detection. A distribution, not an ordered attack path: it does not evidence a transition. Only the scenario register (view C) can claim ordered paths, joined transitions or reconstructibility.Tier A technique-stage placements
C. Multi-step scenario statusScenarios covered under the existing SCS rule (two distinct stages detected with evidence, one validated by a qualifying method), partially evidenced, not covered and not assessed; claimed detections without evidence are counted separately and never towards coverage. The SCS percentage appears only when the register has at least one scenario and every scenario has an assessed step.Registered scenarios
D. Unknown and emerging-threat readinessOf the twelve relevant sub-capabilities in profile: assessed and not assessed, the lowest counted levels, evidence text supplied or not, and the top improvement actions from the model’s own descriptors. No percentage, by design.Relevant sub-capabilities in profile
E. Key bottlenecksA ranked list of what is holding assurance back — missing telemetry, insufficient estate reach, detection not assessed, detection absent, missing evidence, validation expired or missing, missing cross-domain correlation, incomplete scenario register — each with the number of items it holds back and what removes it.Items affected, per factor

UTIOM operating-model view

After “Assurance at a glance” and before the roadmap, a card always present because TID-CMM is the detection module of UTIOM, the Unified Threat-Informed Operations Model. It is an ecosystem view, not an external standard: The UTIOM ecosystem view is always included because TID-CMM is UTIOM’s detection module. It organises existing findings across threat context, visibility, detection, validation, investigation, response handoff and continuous improvement. It does not change the maturity score.

It is derived only from what the assessment already holds, through the same functions the views above use, and it is organised in six parts: threat and business context (declared crown jewels and critical services, threat-profile provenance, prioritised adversaries and ATT&CK scope, modelled paths and scenarios); visibility foundation (assured, partial, weak, blind and not-assessed technique counts, the ranked telemetry bottlenecks, and the statement that visibility bounds every later detection claim); detection and validation (register statuses 0–3 and not assessed, expired validation, evidence supplied against not supplied; no new percentage or score); multi-step investigation (scenario status under the existing SCS rule; the Tier A stage distribution’s earliest represented stage with an evidenced detection, which is tactic placement and not evidence of a path; each registered scenario’s own earliest evidenced detection; blind arriving stages, broken or unevidenced joins, and whether each scenario can be reconstructed in order); UTIOM and TIR-CMM handoff (what stays inside TID-CMM against the response-readiness work that belongs to TIR-CMM, with the existing export action and its unchanged payload — exporting proves nothing about response readiness); and feedback and improvement (how unknown and emerging findings feed hunting, detection engineering, validation, threat-model updates and the roadmap, read from the existing Unknown-Threat Readiness view, with no unknown-threat coverage percentage).

The card discloses on its face: “This is an operating-model interpretation of existing TID-CMM results. It is non-scoring and is not a formal crosswalk or compliance assessment.” It invents no UTIOM maturity level, mapping, score or percentage; UTIOM’s published lifecycle phases and enablers are named as vocabulary only, because no authoritative mapping between individual sub-capabilities and UTIOM components is published. The view is browser-only: the workbooks carry no UTIOM tab, so that no incomplete mapping is shipped in a form that could be mistaken for one.

Hand this to TIR-CMM

The results page exports a file for TIR-CMM, the response module of UTIOM. TIR-CMM 1.0 imports the core handoff context it recognises — your crown jewels with their asset classes, your adversaries, the stage and asset-class scope of your attack paths, and your detection score as the ceiling on response. The extended 1.6 detail travels in the file, but the current TIR-CMM importer does not yet consume every extended field, and scenario step order does not survive the handoff. What travels is the constrained score before any TIR-CMM result is substituted back into IR, so the two models cannot inflate each other. Per-technique status carries 2 or 3 only where the detection register holds the evidence the model requires — a deployed, enabled detection with healthy required telemetry and a named artefact, and a validation with a recorded method and a fired outcome inside the stated recency window; every other technique stays at telemetry reach, 0 or 1, and a technique without a detection answer is never promoted. Registered scenarios travel as attack paths (SC-n) in the contract’s own shape. The shape and every derivation are on the data model page.

Declared versus claimed

Where what you declared in step 1 disagrees with what you scored in step 9, the model reports it rather than averaging it away — intelligence scored highly with no source declared, deception maturity claimed with nothing deployed, and so on.

Start the assessment