{
  "organisation": "Northgate Financial Services (illustrative example)",
  "assessed_on": "2026-08-10",
  "model_version": "1.1.0",
  "strict": true,
  "overall_raw": 2.43,
  "overall_score": 2.37,
  "overall_band": "Level 2 \u2014 Repeatable",
  "constraint_log": [
    "C1: DC 2.84 exceeds AV 1.63 + 1; capped to 2.63.",
    "C1: DE 2.70 exceeds AV 1.63 + 1; capped to 2.63.",
    "C1: IR 2.86 exceeds AV 1.63 + 1; capped to 2.63."
  ],
  "coverage": null,
  "priorities": [
    {
      "subcapability_id": "AV.3",
      "domain": "AV",
      "name": "Threat-actor emulation plans",
      "current": 1,
      "target": 4,
      "gap": 3,
      "impact": 63.0,
      "next_level_action": "Public emulation plans are executed occasionally with limited tailoring to the environment.",
      "evidence_required": [
        "Emulation plan library referencing ATT&CK Group/Campaign IDs",
        "Per-step detection outcome records showing earliest detection point",
        "Evasion-variant test results"
      ],
      "owner": "Purple Team Lead"
    },
    {
      "subcapability_id": "TM.3",
      "domain": "TM",
      "name": "Attack tree construction",
      "current": 1,
      "target": 4,
      "gap": 3,
      "impact": 57.6,
      "next_level_action": "Attack trees are drawn for selected scenarios but stay as diagrams; leaves are not mapped to techniques or to controls.",
      "evidence_required": [
        "Attack tree library in structured form (YAML/JSON/graph DB)",
        "Node-to-ATT&CK mapping and per-leaf control decisions",
        "Choke-point analysis showing nodes shared across trees"
      ],
      "owner": "Security Architecture"
    },
    {
      "subcapability_id": "DC.5",
      "domain": "DC",
      "name": "Coverage breadth across attack surfaces",
      "current": 2,
      "target": 4,
      "gap": 2,
      "impact": 56.0,
      "next_level_action": "Coverage is deliberately scoped per surface against the threat profile, with documented decisions on surfaces deliberately not covered and the risk accepted.",
      "evidence_required": [
        "Per-surface coverage report",
        "Accepted-risk records for uncovered surfaces",
        "Technology-adoption gate requiring a telemetry plan"
      ],
      "owner": "Detection Platform Lead"
    },
    {
      "subcapability_id": "AV.4",
      "domain": "AV",
      "name": "Purple team programme",
      "current": 1,
      "target": 4,
      "gap": 3,
      "impact": 54.6,
      "next_level_action": "Purple team exercises happen once or twice a year, ad hoc in scope, with a report at the end.",
      "evidence_required": [
        "Programme charter, cadence and rules of engagement",
        "Per-technique outcome matrix and re-test confirmations",
        "Time-to-detect improvement trend across cycles"
      ],
      "owner": "Purple Team Lead"
    },
    {
      "subcapability_id": "TM.4",
      "domain": "TM",
      "name": "Attack path and exposure analysis",
      "current": 1,
      "target": 4,
      "gap": 3,
      "impact": 54.0,
      "next_level_action": "Point-in-time path analysis is run occasionally with a tool (identity graph, cloud permission analysis, AD path tooling) for specific reviews.",
      "evidence_required": [
        "Attack path analysis output with paths to crown jewels",
        "Trend of viable path count and shortest path length",
        "Choke-point instrumentation records"
      ],
      "owner": "Security Architecture"
    },
    {
      "subcapability_id": "AV.6",
      "domain": "AV",
      "name": "Red teaming and independent assurance",
      "current": 1,
      "target": 4,
      "gap": 3,
      "impact": 50.4,
      "next_level_action": "Periodic red team engagements with limited objectives and heavy scope restrictions; the blue team is usually informed.",
      "evidence_required": [
        "Intelligence-led engagement scope and rules of engagement",
        "Objective-by-objective detection and response performance record",
        "Cross-cycle comparison showing improvement"
      ],
      "owner": "Purple Team Lead"
    },
    {
      "subcapability_id": "TM.5",
      "domain": "TM",
      "name": "Abuse cases to detection requirements traceability",
      "current": 1,
      "target": 4,
      "gap": 3,
      "impact": 50.4,
      "next_level_action": "Some detection tickets reference a threat model informally in free text.",
      "evidence_required": [
        "Traceability matrix or graph query output",
        "Orphaned-node and orphaned-detection reports",
        "Assurance report tracing an incident back to a model node"
      ],
      "owner": "Security Architecture"
    },
    {
      "subcapability_id": "TI.2",
      "domain": "TI",
      "name": "Threat profile and adversary prioritisation",
      "current": 2,
      "target": 4,
      "gap": 2,
      "impact": 48.0,
      "next_level_action": "Threat profile is built from sector, geography, technology stack, crown-jewel exposure and observed activity; actors are ranked by a documented relevance methodology and mapped to ATT&CK Groups and Campaigns.",
      "evidence_required": [
        "Threat profile document with ranking methodology and ATT&CK Group/Campaign IDs",
        "Quarterly re-score records",
        "Tasking records showing profile change to backlog change"
      ],
      "owner": "Head of CTI"
    },
    {
      "subcapability_id": "TI.5",
      "domain": "TI",
      "name": "Intelligence-to-detection tasking",
      "current": 2,
      "target": 4,
      "gap": 2,
      "impact": 43.2,
      "next_level_action": "Every prioritised behaviour produces a tracked work item routed to detection engineering, hunting or emulation, with a documented disposition even when the answer is \"no action\".",
      "evidence_required": [
        "Intel-to-detection ticket trail with dispositions",
        "Publication-to-validated-detection cycle-time trend",
        "Escalation records for uncovered top-tier behaviours"
      ],
      "owner": "Head of CTI"
    },
    {
      "subcapability_id": "AV.8",
      "domain": "AV",
      "name": "Control efficacy scoring",
      "current": 1,
      "target": 4,
      "gap": 3,
      "impact": 42.0,
      "next_level_action": "Pass/fail per test, aggregated informally.",
      "evidence_required": [
        "Efficacy scoring scale definition with recency rules",
        "Per-technique efficacy matrix",
        "Investment case referencing efficacy-derived risk reduction"
      ],
      "owner": "Purple Team Lead"
    },
    {
      "subcapability_id": "DE.4",
      "domain": "DE",
      "name": "Testing and pre-deployment validation",
      "current": 2,
      "target": 4,
      "gap": 2,
      "impact": 41.6,
      "next_level_action": "Every detection has a positive test (a reproducible execution or synthetic event that must trigger it) and a negative test set of benign activity that must not; results are recorded against the rule version.",
      "evidence_required": [
        "Test definitions stored with the detection content",
        "CI test run history and coverage-of-portfolio metric",
        "Unverified-detection report"
      ],
      "owner": "Detection Engineering Lead"
    },
    {
      "subcapability_id": "DC.6",
      "domain": "DC",
      "name": "Visibility gap management",
      "current": 2,
      "target": 4,
      "gap": 2,
      "impact": 39.2,
      "next_level_action": "Gaps are registered with the technique(s) they blind, the crown jewels affected, an owner, a priority derived from the threat profile, and a target date.",
      "evidence_required": [
        "Visibility gap register with owners and dates",
        "Gap ageing and closure-rate trend",
        "Risk acceptance records for tolerated gaps"
      ],
      "owner": "Detection Platform Lead"
    }
  ],
  "domains": [
    {
      "id": "TI",
      "name": "Threat Intelligence & Adversary Prioritisation",
      "weight": 12.0,
      "raw_score": 2.62,
      "score": 2.62,
      "band": "Level 2 \u2014 Repeatable",
      "scored": 6,
      "not_applicable": 0,
      "target_score": 4.0,
      "gap_to_target": 1.38,
      "adjustments": [],
      "subcapabilities": [
        {
          "id": "TI.1",
          "name": "Intelligence requirements and PIRs",
          "weight": 18.0,
          "score": 3,
          "effective_score": 3,
          "target": 4,
          "evidence": "",
          "notes": "",
          "owner": "Head of CTI",
          "status": "scored"
        },
        {
          "id": "TI.2",
          "name": "Threat profile and adversary prioritisation",
          "weight": 20.0,
          "score": 2,
          "effective_score": 2,
          "target": 4,
          "evidence": "",
          "notes": "",
          "owner": "Head of CTI",
          "status": "scored"
        },
        {
          "id": "TI.3",
          "name": "Technical CTI ingestion and indicator lifecycle",
          "weight": 14.0,
          "score": 3,
          "effective_score": 3,
          "target": 4,
          "evidence": "",
          "notes": "",
          "owner": "Head of CTI",
          "status": "scored"
        },
        {
          "id": "TI.4",
          "name": "TTP extraction and ATT&CK mapping discipline",
          "weight": 18.0,
          "score": 3,
          "effective_score": 3,
          "target": 4,
          "evidence": "",
          "notes": "",
          "owner": "Head of CTI",
          "status": "scored"
        },
        {
          "id": "TI.5",
          "name": "Intelligence-to-detection tasking",
          "weight": 18.0,
          "score": 2,
          "effective_score": 2,
          "target": 4,
          "evidence": "",
          "notes": "",
          "owner": "Head of CTI",
          "status": "scored"
        },
        {
          "id": "TI.6",
          "name": "Dissemination, sharing and community contribution",
          "weight": 12.0,
          "score": 3,
          "effective_score": 3,
          "target": 4,
          "evidence": "",
          "notes": "",
          "owner": "Head of CTI",
          "status": "scored"
        }
      ]
    },
    {
      "id": "TM",
      "name": "Threat Modeling & Attack Path Analysis",
      "weight": 12.0,
      "raw_score": 1.69,
      "score": 1.69,
      "band": "Level 1 \u2014 Ad hoc",
      "scored": 7,
      "not_applicable": 0,
      "target_score": 4.0,
      "gap_to_target": 2.31,
      "adjustments": [],
      "subcapabilities": [
        {
          "id": "TM.1",
          "name": "Asset, identity and crown-jewel identification",
          "weight": 13.0,
          "score": 2,
          "effective_score": 2,
          "target": 4,
          "evidence": "",
          "notes": "",
          "owner": "Security Architecture",
          "status": "scored"
        },
        {
          "id": "TM.2",
          "name": "System and data-flow threat modeling",
          "weight": 16.0,
          "score": 2,
          "effective_score": 2,
          "target": 4,
          "evidence": "",
          "notes": "",
          "owner": "Security Architecture",
          "status": "scored"
        },
        {
          "id": "TM.7",
          "name": "Attack surface enumeration",
          "weight": 14.0,
          "score": 3,
          "effective_score": 3,
          "target": 4,
          "evidence": "",
          "notes": "added in v1.1",
          "owner": "",
          "status": "scored"
        },
        {
          "id": "TM.3",
          "name": "Attack tree construction",
          "weight": 16.0,
          "score": 1,
          "effective_score": 1,
          "target": 4,
          "evidence": "",
          "notes": "",
          "owner": "Security Architecture",
          "status": "scored"
        },
        {
          "id": "TM.4",
          "name": "Attack path and exposure analysis",
          "weight": 15.0,
          "score": 1,
          "effective_score": 1,
          "target": 4,
          "evidence": "",
          "notes": "",
          "owner": "Security Architecture",
          "status": "scored"
        },
        {
          "id": "TM.5",
          "name": "Abuse cases to detection requirements traceability",
          "weight": 14.0,
          "score": 1,
          "effective_score": 1,
          "target": 4,
          "evidence": "",
          "notes": "",
          "owner": "Security Architecture",
          "status": "scored"
        },
        {
          "id": "TM.6",
          "name": "Model maintenance and change triggers",
          "weight": 12.0,
          "score": 2,
          "effective_score": 2,
          "target": 4,
          "evidence": "",
          "notes": "",
          "owner": "Security Architecture",
          "status": "scored"
        }
      ]
    },
    {
      "id": "DC",
      "name": "Telemetry & Detection Coverage",
      "weight": 14.0,
      "raw_score": 2.84,
      "score": 2.63,
      "band": "Level 2 \u2014 Repeatable",
      "scored": 6,
      "not_applicable": 0,
      "target_score": 4.0,
      "gap_to_target": 1.37,
      "adjustments": [
        "C1: DC 2.84 exceeds AV 1.63 + 1; capped to 2.63."
      ],
      "subcapabilities": [
        {
          "id": "DC.1",
          "name": "Log source inventory and ownership",
          "weight": 14.0,
          "score": 3,
          "effective_score": 3,
          "target": 4,
          "evidence": "Log source inventory (LSI-2026-Q2) with owner attestation, reviewed 2026-05-14",
          "notes": "",
          "owner": "Detection Platform Lead",
          "status": "scored"
        },
        {
          "id": "DC.2",
          "name": "Telemetry quality, completeness and timeliness",
          "weight": 18.0,
          "score": 4,
          "effective_score": 4,
          "target": 4,
          "evidence": "Data quality dashboard with SLOs per source; canary events on 22 of 41 sources",
          "notes": "",
          "owner": "Detection Platform Lead",
          "status": "scored"
        },
        {
          "id": "DC.3",
          "name": "Normalisation and data model discipline",
          "weight": 14.0,
          "score": 3,
          "effective_score": 3,
          "target": 4,
          "evidence": "",
          "notes": "",
          "owner": "Detection Platform Lead",
          "status": "scored"
        },
        {
          "id": "DC.4",
          "name": "ATT&CK technique coverage measurement",
          "weight": 20.0,
          "score": 3,
          "effective_score": 3,
          "target": 4,
          "evidence": "",
          "notes": "",
          "owner": "Detection Platform Lead",
          "status": "scored"
        },
        {
          "id": "DC.5",
          "name": "Coverage breadth across attack surfaces",
          "weight": 20.0,
          "score": 2,
          "effective_score": 2,
          "target": 4,
          "evidence": "",
          "notes": "",
          "owner": "Detection Platform Lead",
          "status": "scored"
        },
        {
          "id": "DC.6",
          "name": "Visibility gap management",
          "weight": 14.0,
          "score": 2,
          "effective_score": 2,
          "target": 4,
          "evidence": "",
          "notes": "",
          "owner": "Detection Platform Lead",
          "status": "scored"
        }
      ]
    },
    {
      "id": "DE",
      "name": "Detection Engineering",
      "weight": 16.0,
      "raw_score": 2.7,
      "score": 2.63,
      "band": "Level 2 \u2014 Repeatable",
      "scored": 10,
      "not_applicable": 0,
      "target_score": 4.0,
      "gap_to_target": 1.37,
      "adjustments": [
        "C1: DE 2.70 exceeds AV 1.63 + 1; capped to 2.63."
      ],
      "subcapabilities": [
        {
          "id": "DE.1",
          "name": "Detection lifecycle and intake",
          "weight": 10.0,
          "score": 3,
          "effective_score": 3,
          "target": 4,
          "evidence": "",
          "notes": "",
          "owner": "Detection Engineering Lead",
          "status": "scored"
        },
        {
          "id": "DE.2",
          "name": "Detection-as-code",
          "weight": 12.0,
          "score": 4,
          "effective_score": 4,
          "target": 4,
          "evidence": "GitHub repo sec-detections, branch protection + CODEOWNERS, CI run #4821",
          "notes": "",
          "owner": "Detection Engineering Lead",
          "status": "scored"
        },
        {
          "id": "DE.3",
          "name": "Detection standards, metadata and documentation",
          "weight": 10.0,
          "score": 3,
          "effective_score": 3,
          "target": 4,
          "evidence": "",
          "notes": "",
          "owner": "Detection Engineering Lead",
          "status": "scored"
        },
        {
          "id": "DE.4",
          "name": "Testing and pre-deployment validation",
          "weight": 13.0,
          "score": 2,
          "effective_score": 2,
          "target": 4,
          "evidence": "",
          "notes": "",
          "owner": "Detection Engineering Lead",
          "status": "scored"
        },
        {
          "id": "DE.5",
          "name": "Tuning, precision and false-positive management",
          "weight": 10.0,
          "score": 3,
          "effective_score": 3,
          "target": 4,
          "evidence": "",
          "notes": "",
          "owner": "Detection Engineering Lead",
          "status": "scored"
        },
        {
          "id": "DE.6",
          "name": "Detection health and silent-failure monitoring",
          "weight": 10.0,
          "score": 2,
          "effective_score": 2,
          "target": 4,
          "evidence": "",
          "notes": "",
          "owner": "Detection Engineering Lead",
          "status": "scored"
        },
        {
          "id": "DE.7",
          "name": "Versioning, deprecation and retirement",
          "weight": 8.0,
          "score": 3,
          "effective_score": 3,
          "target": 4,
          "evidence": "",
          "notes": "",
          "owner": "Detection Engineering Lead",
          "status": "scored"
        },
        {
          "id": "DE.8",
          "name": "Portfolio composition and detection strategy",
          "weight": 12.0,
          "score": 2,
          "effective_score": 2,
          "target": 4,
          "evidence": "",
          "notes": "",
          "owner": "Detection Engineering Lead",
          "status": "scored"
        },
        {
          "id": "DE.9",
          "name": "Detection content sourcing and provenance",
          "weight": 8.0,
          "score": 3,
          "effective_score": 3,
          "target": 4,
          "evidence": "",
          "notes": "added in v1.1",
          "owner": "",
          "status": "scored"
        },
        {
          "id": "DE.10",
          "name": "Detection modality breadth",
          "weight": 7.0,
          "score": 2,
          "effective_score": 2,
          "target": 4,
          "evidence": "",
          "notes": "added in v1.1",
          "owner": "",
          "status": "scored"
        }
      ]
    },
    {
      "id": "AV",
      "name": "Adversarial Validation & Emulation",
      "weight": 14.0,
      "raw_score": 1.63,
      "score": 1.63,
      "band": "Level 1 \u2014 Ad hoc",
      "scored": 8,
      "not_applicable": 0,
      "target_score": 4.0,
      "gap_to_target": 2.37,
      "adjustments": [],
      "subcapabilities": [
        {
          "id": "AV.1",
          "name": "Atomic testing and control verification",
          "weight": 13.0,
          "score": 3,
          "effective_score": 3,
          "target": 4,
          "evidence": "Atomic Red Team runner results, quarterly run 2026-Q2, 214 tests",
          "notes": "",
          "owner": "Purple Team Lead",
          "status": "scored"
        },
        {
          "id": "AV.2",
          "name": "Breach and attack simulation automation",
          "weight": 12.0,
          "score": 2,
          "effective_score": 2,
          "target": 4,
          "evidence": "",
          "notes": "",
          "owner": "Purple Team Lead",
          "status": "scored"
        },
        {
          "id": "AV.3",
          "name": "Threat-actor emulation plans",
          "weight": 15.0,
          "score": 1,
          "effective_score": 1,
          "target": 4,
          "evidence": "",
          "notes": "",
          "owner": "Purple Team Lead",
          "status": "scored"
        },
        {
          "id": "AV.4",
          "name": "Purple team programme",
          "weight": 13.0,
          "score": 1,
          "effective_score": 1,
          "target": 4,
          "evidence": "",
          "notes": "",
          "owner": "Purple Team Lead",
          "status": "scored"
        },
        {
          "id": "AV.5",
          "name": "Penetration testing integration",
          "weight": 12.0,
          "score": 2,
          "effective_score": 2,
          "target": 4,
          "evidence": "",
          "notes": "",
          "owner": "Purple Team Lead",
          "status": "scored"
        },
        {
          "id": "AV.6",
          "name": "Red teaming and independent assurance",
          "weight": 12.0,
          "score": 1,
          "effective_score": 1,
          "target": 4,
          "evidence": "",
          "notes": "",
          "owner": "Purple Team Lead",
          "status": "scored"
        },
        {
          "id": "AV.7",
          "name": "Findings-to-closure loop",
          "weight": 13.0,
          "score": 2,
          "effective_score": 2,
          "target": 4,
          "evidence": "",
          "notes": "",
          "owner": "Purple Team Lead",
          "status": "scored"
        },
        {
          "id": "AV.8",
          "name": "Control efficacy scoring",
          "weight": 10.0,
          "score": 1,
          "effective_score": 1,
          "target": 4,
          "evidence": "",
          "notes": "",
          "owner": "Purple Team Lead",
          "status": "scored"
        }
      ]
    },
    {
      "id": "AA",
      "name": "Analytics, Automation & Hunting",
      "weight": 12.0,
      "raw_score": 2.63,
      "score": 2.63,
      "band": "Level 2 \u2014 Repeatable",
      "scored": 8,
      "not_applicable": 0,
      "target_score": 4.0,
      "gap_to_target": 1.37,
      "adjustments": [],
      "subcapabilities": [
        {
          "id": "AA.1",
          "name": "Triage enrichment and context automation",
          "weight": 13.0,
          "score": 4,
          "effective_score": 4,
          "target": 4,
          "evidence": "SOAR enrichment spec v3.1; triage-time study 2026-03 (18min -> 6min)",
          "notes": "",
          "owner": "SOC Manager",
          "status": "scored"
        },
        {
          "id": "AA.2",
          "name": "Correlation and attack-chain assembly",
          "weight": 14.0,
          "score": 3,
          "effective_score": 3,
          "target": 4,
          "evidence": "",
          "notes": "",
          "owner": "SOC Manager",
          "status": "scored"
        },
        {
          "id": "AA.3",
          "name": "Response automation and orchestration",
          "weight": 12.0,
          "score": 3,
          "effective_score": 3,
          "target": 4,
          "evidence": "",
          "notes": "",
          "owner": "SOC Manager",
          "status": "scored"
        },
        {
          "id": "AA.4",
          "name": "Advanced analytics governance",
          "weight": 11.0,
          "score": 2,
          "effective_score": 2,
          "target": 4,
          "evidence": "",
          "notes": "",
          "owner": "SOC Manager",
          "status": "scored"
        },
        {
          "id": "AA.5",
          "name": "Threat hunting programme",
          "weight": 15.0,
          "score": 2,
          "effective_score": 2,
          "target": 4,
          "evidence": "",
          "notes": "",
          "owner": "SOC Manager",
          "status": "scored"
        },
        {
          "id": "AA.7",
          "name": "Deception and adversary engagement",
          "weight": 13.0,
          "score": 2,
          "effective_score": 2,
          "target": 4,
          "evidence": "",
          "notes": "added in v1.1",
          "owner": "",
          "status": "scored"
        },
        {
          "id": "AA.6",
          "name": "Case management and knowledge capture",
          "weight": 11.0,
          "score": 3,
          "effective_score": 3,
          "target": 4,
          "evidence": "",
          "notes": "",
          "owner": "SOC Manager",
          "status": "scored"
        },
        {
          "id": "AA.8",
          "name": "Agentic and AI-assisted operations",
          "weight": 11.0,
          "score": 2,
          "effective_score": 2,
          "target": 4,
          "evidence": "",
          "notes": "added in v1.1",
          "owner": "",
          "status": "scored"
        }
      ]
    },
    {
      "id": "IR",
      "name": "Incident Response & Recovery",
      "weight": 10.0,
      "raw_score": 2.86,
      "score": 2.63,
      "band": "Level 2 \u2014 Repeatable",
      "scored": 6,
      "not_applicable": 0,
      "target_score": 4.0,
      "gap_to_target": 1.37,
      "adjustments": [
        "C1: IR 2.86 exceeds AV 1.63 + 1; capped to 2.63."
      ],
      "subcapabilities": [
        {
          "id": "IR.1",
          "name": "Response plan, playbooks and readiness",
          "weight": 18.0,
          "score": 4,
          "effective_score": 4,
          "target": 4,
          "evidence": "IR-PLAN-v4.2 and 9 scenario playbooks; ransomware playbook exercised 2026-04-22",
          "notes": "",
          "owner": "Incident Response Manager",
          "status": "scored"
        },
        {
          "id": "IR.2",
          "name": "Detection-to-response handoff and SLAs",
          "weight": 17.0,
          "score": 3,
          "effective_score": 3,
          "target": 4,
          "evidence": "",
          "notes": "",
          "owner": "Incident Response Manager",
          "status": "scored"
        },
        {
          "id": "IR.3",
          "name": "Forensic readiness and evidence handling",
          "weight": 15.0,
          "score": 2,
          "effective_score": 2,
          "target": 4,
          "evidence": "",
          "notes": "",
          "owner": "Incident Response Manager",
          "status": "scored"
        },
        {
          "id": "IR.4",
          "name": "Containment, eradication and recovery",
          "weight": 17.0,
          "score": 3,
          "effective_score": 3,
          "target": 4,
          "evidence": "",
          "notes": "",
          "owner": "Incident Response Manager",
          "status": "scored"
        },
        {
          "id": "IR.5",
          "name": "Exercising and crisis management",
          "weight": 16.0,
          "score": 3,
          "effective_score": 3,
          "target": 4,
          "evidence": "",
          "notes": "",
          "owner": "Incident Response Manager",
          "status": "scored"
        },
        {
          "id": "IR.6",
          "name": "Post-incident review to detection backlog",
          "weight": 17.0,
          "score": 2,
          "effective_score": 2,
          "target": 4,
          "evidence": "",
          "notes": "",
          "owner": "Incident Response Manager",
          "status": "scored"
        }
      ]
    },
    {
      "id": "GV",
      "name": "Governance, Metrics & Continuous Improvement",
      "weight": 10.0,
      "raw_score": 2.57,
      "score": 2.57,
      "band": "Level 2 \u2014 Repeatable",
      "scored": 7,
      "not_applicable": 0,
      "target_score": 4.0,
      "gap_to_target": 1.43,
      "adjustments": [],
      "subcapabilities": [
        {
          "id": "GV.1",
          "name": "Strategy, mandate and funding",
          "weight": 15.0,
          "score": 3,
          "effective_score": 3,
          "target": 4,
          "evidence": "",
          "notes": "",
          "owner": "Deputy CISO",
          "status": "scored"
        },
        {
          "id": "GV.2",
          "name": "Roles, skills and capability development",
          "weight": 15.0,
          "score": 3,
          "effective_score": 3,
          "target": 4,
          "evidence": "",
          "notes": "",
          "owner": "Deputy CISO",
          "status": "scored"
        },
        {
          "id": "GV.3",
          "name": "Metrics and performance measurement",
          "weight": 18.0,
          "score": 2,
          "effective_score": 2,
          "target": 4,
          "evidence": "",
          "notes": "",
          "owner": "Deputy CISO",
          "status": "scored"
        },
        {
          "id": "GV.4",
          "name": "Risk and compliance alignment",
          "weight": 14.0,
          "score": 3,
          "effective_score": 3,
          "target": 4,
          "evidence": "",
          "notes": "",
          "owner": "Deputy CISO",
          "status": "scored"
        },
        {
          "id": "GV.5",
          "name": "Executive and board reporting",
          "weight": 13.0,
          "score": 2,
          "effective_score": 2,
          "target": 4,
          "evidence": "",
          "notes": "",
          "owner": "Deputy CISO",
          "status": "scored"
        },
        {
          "id": "GV.6",
          "name": "Continuous improvement cadence",
          "weight": 13.0,
          "score": 3,
          "effective_score": 3,
          "target": 4,
          "evidence": "",
          "notes": "",
          "owner": "Deputy CISO",
          "status": "scored"
        },
        {
          "id": "GV.7",
          "name": "Third-party and supply-chain detection",
          "weight": 12.0,
          "score": 2,
          "effective_score": 2,
          "target": 4,
          "evidence": "",
          "notes": "",
          "owner": "Deputy CISO",
          "status": "scored"
        }
      ]
    }
  ]
}