TID-CMM Threat-Informed Detection Capability Maturity Model
Home › Methodology

Methodology

How an assessment is run, how it is scored, and the rules that stop it flattering itself.

How the pieces fit

The method assesses one chain. Visibility sits in the middle of it because no detection, validation or timeline can exceed the telemetry it runs on; the branch beside it is how behaviour outside the threat model becomes new evidence for it.

  1. Crown jewels and environmentwhat must be protected, and what an adversary finds on arrival
  2. Adversaries, ATT&CK techniques and attack pathswho may target it, which behaviours matter, which paths reach it
  3. Visibility and telemetrywhether the required telemetry exists and how much of the estate it reaches. The foundation: every stage below is bounded by itfoundation
  4. Detection logicdeployed, enabled, healthy, evidenced
  5. Local validationexecuted against and observed to fire, within the recency window
  6. Multi-step correlation and timelineseparate detections joined in order along the path
  7. TIR-CMM response and containmentthe handover: could you stop them?

Secondary branch: outside today’s threat model

  1. Anomalies, hunting and deceptionsignals that no prioritised technique predicted
  2. Investigation and correlationturned into a verdict, not left as an alert
  3. Threat-model and detection feedbacka new adversary, path or technique enters the chain

feeds back into adversaries, techniques and attack paths and into detection logic

The chain TID-CMM assesses. Visibility sits in the middle because everything after it is bounded by it: no detection, validation or timeline can exceed the telemetry it runs on. The branch on the right is how behaviour outside the threat model becomes new evidence for it. The assessment tests whether each capability exists and has been demonstrated; it does not itself detect, correlate or reconstruct.

Because TID-CMM is the detection module of UTIOM, the results page always carries a non-scoring UTIOM operating-model view that organises the same findings across threat context, visibility, detection, validation, investigation, response handoff and continuous improvement. It is an ecosystem view, kept apart from the external framework views (NIST CSF 2.0, SOC-CMM, ISO/IEC 27001): UTIOM is the parent operating model, not a standard, a certification or a crosswalk, and the view changes no score.

In this section

Assessment guide

Who to involve, how long it takes, how to scope it, and the mistakes that make a maturity assessment worthless.

Scoring

The weighted rollup, the order constraints are applied in, the Validated Coverage Score and the prioritisation arithmetic.

Integrity constraints

Validation ceiling, visibility ceiling, evidence rule, intent ceiling and inherited intent — applied mechanically, because exhortation does not survive a budget cycle.

Evidence requirements

A score of 4 or 5 requires a named artefact. What qualifies, what does not, and why the rule exists.

Telemetry assurance

Whether you have the visibility to detect a given behaviour at all, computed from the log sources ATT&CK's own analytics require.

ATT&CK Evaluations

Where an independent evaluation result is admissible in the model, where it is not, and why it is consumed as evidence rather than converted into a score.

Validated coverage

Replacing percentage of ATT&CK covered with a number that distinguishes a rule that exists from a detection proven to fire.

Unknown & emerging threats

Assurance against the adversaries you have prioritised is a coverage question. Readiness for behaviour outside the threat model is not, and cannot be a percentage. What the model scores instead, through twelve existing sub-capabilities.

Correlation & timeline

What the model expects when it asks whether related alerts become a narrative of adversary progress: the maturity ladder from isolated events to graph reconstruction, the inputs, the outputs that count as evidence, and five things called a path that are not the same thing.

Prevention & the TIR-CMM boundary

Prevention is one of five efficacy dimensions a validation result must score, and it is never detection. Where TID-CMM stops, what crosses the line to TIR-CMM, and why external protection results are advisory.

Why the method is the hard part

The method matters more than the model. A well-written maturity model scored badly produces a number that is worse than no number, because it carries the authority of a framework without the substance of one.

These pages cover how to run an assessment, who to involve, how it is scored, and the five constraints that stop the result flattering the organisation that produced it. If you read only one, read the constraints — they are what separates this from a questionnaire.

Verifiable, not asserted

Every calculation is specified in full and published, so an independent implementation can be written from the specification alone. You do not have to trust the arithmetic. You can check it. Conformance vectors — complete assessments with the scores a conforming implementation must produce — are not yet published and may accompany a future release.