Methodology
How an assessment is run, how it is scored, and the rules that stop it flattering itself.
In this section
Assessment guide
Who to involve, how long it takes, how to scope it, and the mistakes that make a maturity assessment worthless.
Scoring
The weighted rollup, the order constraints are applied in, the Validated Coverage Score and the prioritisation arithmetic.
Integrity constraints
Validation ceiling, visibility ceiling, evidence rule, intent ceiling and inherited intent — applied mechanically, because exhortation does not survive a budget cycle.
Evidence requirements
A score of 4 or 5 requires a named artefact. What qualifies, what does not, and why the rule exists.
Telemetry assurance
Whether you have the visibility to detect a given behaviour at all, computed from the log sources ATT&CK's own analytics require.
Validated coverage
Replacing percentage of ATT&CK covered with a number that distinguishes a rule that exists from a detection proven to fire.
Why the method is the hard part
The method matters more than the model. A well-written maturity model scored badly produces a number that is worse than no number, because it carries the authority of a framework without the substance of one.
These pages cover how to run an assessment, who to involve, how it is scored, and the four rules that stop the result flattering the organisation that produced it. If you read only one, read the constraints — they are what separates this from a questionnaire.
Verifiable, not asserted
Every calculation is specified in full and published, and the repository carries conformance vectors: complete assessments with the scores a conforming implementation must produce. You do not have to trust the arithmetic. You can check it.