TID-CMM Threat-Informed Detection Capability Maturity Model
Home › Methodology › Prevention & protection

Prevention, protection and the TID-CMM–TIR-CMM boundary

A control that stops a behaviour is a good thing, and it is not a detection. This page explains how prevention appears inside TID-CMM — as one of five efficacy dimensions a validation result must score — and where the model stops and hands the question of stopping the adversary to TIR-CMM.

TID-CMM measures whether an organisation would see the adversaries that matter to it. Its companion, TIR-CMM, measures whether it could stop them: inside the breakout window, with the authority to do so. Prevention sits awkwardly across that line. A prevented behaviour is the best possible outcome and, if nothing recorded it, a blind spot with a good ending. The model handles this by recording prevention as evidence and refusing to score it as visibility.

The five efficacy dimensions of AV.8

AV.8, control efficacy scoring, asks whether validation results are expressed as a defensible efficacy score per technique across the prevent / detect / alert / respond chain. At level 3 a defined scale scores each in-scope technique separately on five dimensions, from recorded validation evidence inside a stated recency window. They are separate on purpose: a technique can be prevented and invisible, visible and undetected, detected and never alerted, alerted and never acted on.

DimensionThe question the emulation answersWhat it evidences in TID-CMMWhose capability it is
1 PreventionWas the behaviour stopped before it completed — blocked, denied, killed?Control efficacy evidence, which the model expects per technique at AV.8 level 3. It does not raise a telemetry, detection or validation status; a blocked behaviour with no record is still status 0 on the coverage scale.TIR-CMM — Prevent & Harden is its first stage. AV.8 defines how local prevention evidence should be assessed; the current browser assessment records the AV.8 maturity response and its evidence narrative, and does not yet collect or export per-technique prevention results.
2 TelemetryDid the behaviour generate a record you collect, on the estate it ran on?Coverage status 1. The telemetry assurance computation and DC.TID-CMM.
3 DetectionDid deployed detection logic fire on the behaviour, correctly?Coverage status 2 when the logic exists and is healthy; status 3 when this emulation proved it inside the window. DE, and AV as the proof.TID-CMM.
4 AlertingDid the detection reach a person or a decision, enriched, at operational tempo?Whether detection output became a decision. AA, with AA.1 and AA.2 as the mechanics.TID-CMM.
5 ResponseWas the alert acted on, by whom, how fast, and did the action work?Recorded as a validation result — the playbook fired, or did not, during the emulation. TID-CMM’s IR domain scores readiness at the detection programme’s level.TIR-CMM assesses response as a capability: authority, tempo, blast radius, eradication, recovery, forensics.

The Validated Coverage Score reads only dimensions 2 and 3 — telemetry and detection, with a local emulation as the proof. That is the point of it: it measures visibility. A programme that prevents brilliantly and sees nothing will score low on coverage and should, because the day the prevention fails it will not know.

The boundary

Two models, one loop. TID-CMM runs from intelligence through modeling, telemetry, detection and validation to the point where an adversary has been seen; TIR-CMM runs from that point to the adversary being stopped, evicted and the estate recovered. Neither absorbs the other.

The TID-CMM to TIR-CMM boundary Two stacked boxes. The upper box, TID-CMM, asks whether you would see the adversary and lists five responsibilities: identify relevant adversary behaviours, determine whether the necessary telemetry exists, assess detection engineering and validation, record locally demonstrated control efficacy, and identify gaps and pass context downstream. A solid arrow labelled the export carries the constrained detection score, crown jewels, adversaries, derived attack paths and in-scope techniques down to the lower box. The lower box, TIR-CMM, asks whether you could stop them and lists six responsibilities: own Prevent and Harden, assess containment and response authority, assess response tempo, assess blast-radius control, assess eradication, recovery and forensic readiness, and determine whether the organisation can stop the adversary in time. A dashed arrow back up, labelled documented and not yet performed by the tool, shows the TIR-CMM overall substituting into the TID-CMM IR domain. Figure 1 — Where TID-CMM stops and TIR-CMM starts Seeing is one model. Stopping is the other. One file crosses the line. TID-CMM would you see the adversary? 1. Identifies the adversary behaviours that are relevant to you 2. Determines whether the telemetry to see them exists 3. Assesses detection engineering and its validation 4. Records locally demonstrated control efficacy (AV.8) 5. Identifies gaps and passes the context downstream TI · TM · DC · DE · AV · AA · IR · GV — constrained by C1–C5 the export — one file, written in the browser constrained detection score, pre-substitution crown jewels · adversaries · derived attack paths in-scope techniques with reach and mitigations R4: response, containment and forensics cannot exceed D + 1 TIR-CMM overall → TID-CMM IR domain (dashed) documented on tir-cmm.com · not performed by the tool yet TIR-CMM could you stop them? 1. Owns Prevent & Harden 2. Assesses containment and response authority 3. Assesses response tempo against the breakout window 4. Assesses blast-radius control 5. Assesses eradication, recovery and forensic readiness 6. Determines whether the adversary can be stopped in time Containment Lattice: 8 asset classes × 8 attack-path stages, S0 Prevent & Harden to S7 Impact TID-CMM · © 2022–2026 Reza Adineh · Not affiliated with or endorsed by MITRE.
Figure 1 — Where TID-CMM stops and TIR-CMM starts. The solid arrow is the export the assessment tool writes; the dashed arrow is the documented substitution of a TIR-CMM overall into the IR domain, which the tool does not yet perform.
TID-CMMTIR-CMM
Identifies relevant adversary behaviours.Owns Prevent & Harden.
Determines whether the necessary telemetry exists.Assesses containment and response authority.
Assesses detection engineering and validation.Assesses response tempo.
Records locally demonstrated control efficacy.Assesses blast-radius control.
Identifies gaps and passes relevant context downstream.Assesses eradication, recovery and forensic readiness.
 Determines whether the organisation can stop the adversary in time.

What crosses the line is the TIR-CMM export: the constrained detection score before any substitution, the crown jewels, the prioritised adversaries, the derived attack paths and every in-scope technique with its telemetry reach and ATT&CK mitigations. AV.8 is not exported as a separate field or evidence narrative. When AV.8 is in scope, its assessment can contribute to the aggregate AV domain and overall TID-CMM results; the current export does not carry AV.8 or per-technique prevention outcomes separately. TIR-CMM reads the score as the ceiling on response — its constraint R4 will not score response, containment or forensics more than one level above what can be detected — so the two models cannot inflate each other. The reverse direction, a TIR-CMM overall substituting into TID-CMM’s IR domain, is documented on tir-cmm.com and is not something the assessment tool performs today.

External protection results are advisory

ATT&CK Evaluations score protection alongside detection: whether a product blocked a behaviour in MITRE’s range. The same evidence boundary applies: external results are advisory; locally recorded and time-bounded validation is authoritative. A product preventing a behaviour in an external evaluation is capability evidence about the product. It does not show that the control is deployed on your estate, configured as it was in the range, observable when it acts, or effective against the procedure your adversary actually uses. Four separate things, each of which has to be demonstrated locally.

In AV.8 terms an external protection result may inform which controls to validate first. It never populates the prevention dimension. That dimension is filled by an emulation that ran here, against the deployed control, with the result recorded and dated. It is not evidence of detection, either: a blocked behaviour in the range says nothing about whether the same behaviour would have produced a record in your telemetry, and the coverage score asks about records.

Two things the model refuses to do

It does not present prevention as detection. A prevented behaviour that left no record is status 0 on the coverage scale, and it stays status 0 however good the control is. The reasoning is in the model’s central claim: an untested capability is an assumed capability, and a prevention control nobody can see acting is one that will fail silently the day it is misconfigured, bypassed or switched off during a change. Prevention without telemetry is a blind spot with a good outcome. Record the efficacy, keep the coverage status honest, and put the missing record on the visibility gap register (DC.6).

It does not absorb TIR-CMM. The temptation is obvious: add a few sub-capabilities for containment, a constraint for tempo, and call the model complete. The reason not to is the same reason the domains are weighted as they are: detection is manufactured in one place and response is exercised in another, by people with different authority, on a different clock. A model that scored both in one number would let a strong detection programme mask an organisation that cannot revoke a credential without a change board, or the reverse. TID-CMM’s IR domain scores whether detection output can be acted on at the programme level; it is ten percent of the weight for exactly that reason, and it hands the rest to a model built for it.

What this means in an assessment

Using ATT&CK Evaluations as external evidence · Correlation and timeline reconstruction · Known-Threat Assurance and Unknown-Threat Readiness · The TIR-CMM export

MITRE ATT&CK® is a registered trademark of The MITRE Corporation. TID-CMM is an independent project and is not affiliated with or endorsed by MITRE.