TID-CMM Threat-Informed Detection Capability Maturity Model
HomeModel

The model

Eight domains, 58 sub-capabilities and 348 level descriptors describing what a threat-informed detection capability looks like at each level of maturity — and five constraints that stop an assessment flattering itself.

Overview

Why rule counts and alert volumes do not measure detection capability, and what the model measures instead.

Eight domains

Threat intelligence, threat modeling, telemetry, detection engineering, adversarial validation, analytics, incident response and governance — with the weight each carries and the question each answers.

58 sub-capabilities

Every sub-capability in the model, its domain, its weight, its applicability profile and the question it asks.

Maturity levels

What each level means in practice, and why level 5 is not a target for most organisations.

Seven principles

The arguments the model enacts rather than merely states: scope is an intersection, capability requires evidence, detection is bounded by visibility, and validation expires.

Relationship to ATT&CK

ATT&CK is consumed, not reproduced. How the in-scope technique set is derived, and why covering all 697 techniques is not the goal.