Prevention, protection and the TID-CMM–TIR-CMM boundary
A control that stops a behaviour is a good thing, and it is not a detection. This page explains how prevention appears inside TID-CMM — as one of five efficacy dimensions a validation result must score — and where the model stops and hands the question of stopping the adversary to TIR-CMM.
TID-CMM measures whether an organisation would see the adversaries that matter to it. Its companion, TIR-CMM, measures whether it could stop them: inside the breakout window, with the authority to do so. Prevention sits awkwardly across that line. A prevented behaviour is the best possible outcome and, if nothing recorded it, a blind spot with a good ending. The model handles this by recording prevention as evidence and refusing to score it as visibility.
The five efficacy dimensions of AV.8
AV.8, control efficacy scoring, asks whether validation results
are expressed as a defensible efficacy score per technique across the prevent / detect /
alert / respond chain. At level 3 a defined scale scores each in-scope technique separately
on five dimensions, from recorded validation evidence inside a stated recency window. They
are separate on purpose: a technique can be prevented and invisible, visible and
undetected, detected and never alerted, alerted and never acted on.
| Dimension | The question the emulation answers | What it evidences in TID-CMM | Whose capability it is |
|---|---|---|---|
| 1 Prevention | Was the behaviour stopped before it completed — blocked, denied, killed? | Control efficacy evidence, which the model expects per technique at AV.8 level 3. It does not raise a telemetry, detection or validation status; a blocked behaviour with no record is still status 0 on the coverage scale. | TIR-CMM — Prevent & Harden is its first stage. AV.8 defines how local prevention evidence should be assessed; the current browser assessment records the AV.8 maturity response and its evidence narrative, and does not yet collect or export per-technique prevention results. |
| 2 Telemetry | Did the behaviour generate a record you collect, on the estate it ran on? | Coverage status 1. The telemetry assurance computation and DC. | TID-CMM. |
| 3 Detection | Did deployed detection logic fire on the behaviour, correctly? | Coverage status 2 when the logic exists and is healthy; status 3 when this emulation proved it inside the window. DE, and AV as the proof. | TID-CMM. |
| 4 Alerting | Did the detection reach a person or a decision, enriched, at operational tempo? | Whether detection output became a decision. AA, with AA.1 and AA.2 as the mechanics. | TID-CMM. |
| 5 Response | Was the alert acted on, by whom, how fast, and did the action work? | Recorded as a validation result — the playbook fired, or did not, during the emulation. TID-CMM’s IR domain scores readiness at the detection programme’s level. | TIR-CMM assesses response as a capability: authority, tempo, blast radius, eradication, recovery, forensics. |
The Validated Coverage Score reads only dimensions 2 and 3 — telemetry and detection, with a local emulation as the proof. That is the point of it: it measures visibility. A programme that prevents brilliantly and sees nothing will score low on coverage and should, because the day the prevention fails it will not know.
The boundary
Two models, one loop. TID-CMM runs from intelligence through modeling, telemetry, detection and validation to the point where an adversary has been seen; TIR-CMM runs from that point to the adversary being stopped, evicted and the estate recovered. Neither absorbs the other.
| TID-CMM | TIR-CMM |
|---|---|
| Identifies relevant adversary behaviours. | Owns Prevent & Harden. |
| Determines whether the necessary telemetry exists. | Assesses containment and response authority. |
| Assesses detection engineering and validation. | Assesses response tempo. |
| Records locally demonstrated control efficacy. | Assesses blast-radius control. |
| Identifies gaps and passes relevant context downstream. | Assesses eradication, recovery and forensic readiness. |
| Determines whether the organisation can stop the adversary in time. |
What crosses the line is the
TIR-CMM export: the
constrained detection score before any substitution, the crown jewels, the prioritised
adversaries, the derived attack paths and every in-scope technique with its telemetry reach
and ATT&CK mitigations. AV.8 is not exported as a separate field or evidence
narrative. When AV.8 is in scope, its assessment can contribute to the aggregate
AV domain and overall TID-CMM results; the current export does not carry AV.8
or per-technique prevention outcomes separately. TIR-CMM reads the score as the ceiling on response — its
constraint R4 will not score response, containment or forensics more than one level above
what can be detected — so the two models cannot inflate each other. The reverse
direction, a TIR-CMM overall substituting into TID-CMM’s IR domain, is
documented on tir-cmm.com and is not something the assessment tool performs today.
External protection results are advisory
ATT&CK Evaluations score protection alongside detection: whether a product blocked a behaviour in MITRE’s range. The same evidence boundary applies: external results are advisory; locally recorded and time-bounded validation is authoritative. A product preventing a behaviour in an external evaluation is capability evidence about the product. It does not show that the control is deployed on your estate, configured as it was in the range, observable when it acts, or effective against the procedure your adversary actually uses. Four separate things, each of which has to be demonstrated locally.
In AV.8 terms an external protection result may inform which controls to
validate first. It never populates the prevention dimension. That dimension is filled by an
emulation that ran here, against the deployed control, with the result recorded and dated.
It is not evidence of detection, either: a blocked behaviour in the range says nothing
about whether the same behaviour would have produced a record in your telemetry, and the
coverage score asks about
records.
Two things the model refuses to do
It does not present prevention as detection. A prevented behaviour that
left no record is status 0 on the coverage scale, and it stays status 0 however good the
control is. The reasoning is in the model’s central claim: an untested capability is
an assumed capability, and a prevention control nobody can see acting is one that will fail
silently the day it is misconfigured, bypassed or switched off during a change. Prevention
without telemetry is a blind spot with a good outcome. Record the efficacy, keep the
coverage status honest, and put the missing record on the visibility gap register
(DC.6).
It does not absorb TIR-CMM. The temptation is obvious: add a few
sub-capabilities for containment, a constraint for tempo, and call the model complete.
The reason not to is the same reason the domains are weighted as they are: detection is
manufactured in one place and response is exercised in another, by people with different
authority, on a different clock. A model that scored both in one number would let a strong
detection programme mask an organisation that cannot revoke a credential without a change
board, or the reverse. TID-CMM’s IR domain scores whether detection
output can be acted on at the programme level; it is ten percent of the weight for exactly
that reason, and it hands the rest to a model built for it.
What this means in an assessment
- A prevention result never raises a visibility or detection status. The detection register and the scenario timeline read observability from telemetry reach and detection from deployed, evidenced logic; a behaviour that is blocked but not logged is still unobservable to detection operations, and is recorded that way. The register collects no per-technique prevention outcome.
- Record prevention results from your own emulations per technique, dated, in the
efficacy matrix
AV.8asks for, and name that matrix in theAV.8evidence field. The browser assessment records the level and the narrative, not the matrix itself. Do not let a prevention result change a coverage status. - Where a control prevents a behaviour and nothing records the attempt, register the
missing telemetry as a gap (
DC.6) even though the outcome was good. - Treat external protection results as a list of controls worth validating locally, not as validation.
- When the assessment is complete, export it for TIR-CMM. The response questions — authority, tempo, blast radius, recovery — are answered there, against the detection ceiling this assessment established.
Using ATT&CK Evaluations as external evidence · Correlation and timeline reconstruction · Known-Threat Assurance and Unknown-Threat Readiness · The TIR-CMM export
MITRE ATT&CK® is a registered trademark of The MITRE Corporation. TID-CMM is an independent project and is not affiliated with or endorsed by MITRE.