TID-CMM Threat-Informed Detection Capability Maturity Model
HomeAssessmentRoadmap

Steps 9 and 10 — roadmap and plan

What to fix, ranked by what it unlocks, and a 30/60/90 plan naming owners and the artefact that proves each step is done.

What these steps produce

The roadmap ranks what to fix. The action plan turns it into something with dates, owners and an artefact that proves each step is done.

Ranked by what it unlocks

Prioritisation is mechanical — domain weight × sub-capability weight × gap — with one important addition: a domain that is capping others is promoted above its own weighted gap. If validation is holding six domains at 2, raising validation buys back their suppressed score as well as its own, and the roadmap says so in those terms.

Example. With validation at 1, the roadmap leads with adversarial emulation and states plainly: AV is capping other domains; raising it releases 1.72 of weighted score already earned elsewhere.

The 30/60/90 plan

Three horizons, each item naming what to do, who owns it, and the artefact that would prove it done — which is the same artefact the evidence rule will ask for at the next assessment. Telemetry fixes appear here too when a material share of your scope is blind.

Taking it away

Export the plan as CSV, the whole assessment as JSON, the coverage set as CSV, and the exposure detail as CSV for a risk register. Or print the results to PDF.

Start the assessment