TID-CMM Threat-Informed Detection Capability Maturity Model
HomeModelSeven principles

The seven principles

Every one of these is enforced by the scoring, not asserted in the documentation. A principle nobody can violate is decoration; each of these changes a number when it is breached.

1. Scope is an intersection, not a selection

The set of techniques worth detecting is derived from three things at once: the platforms you actually run, the adversaries who plausibly target you, and the paths through your estate that reach something worth taking. A technique that fails any of those three is out of scope, and saying so is a decision, not an omission.

Why it is a rule and not advice. It prevents the two commonest scoping errors — assessing against all of ATT&CK, which is not ambition but the absence of scoping, and assessing against whatever the current tooling happens to cover, which is scoping by procurement.

2. Detection is bounded by visibility

You cannot detect a behaviour that generates no record you collect. Detection engineering maturity is therefore capped by telemetry coverage, and no amount of rule writing raises the ceiling.

Why it is a rule and not advice. It stops the most expensive failure in detection programmes: buying content for data you do not have, then reporting the content as coverage.

3. Capability requires evidence

A claim of high maturity that cannot name an artefact is an intention. Scores of 4 or 5 require a named artefact recorded against them, and are counted as 3 without one.

Why it is a rule and not advice. In any process where an unevidenced claim scores the same as an evidenced one, assertion drives out evidence, and it does so quietly.

4. Validation is what turns a claim into a fact

Adversarial validation — atomic testing, emulation, purple teaming, red teaming — is a first-class domain, and it caps every other domain at its own score plus one. An untested capability is an assumed capability.

Why it is a rule and not advice. It is the difference between a programme that believes it would detect credential dumping and one that has watched itself do so.

5. Validation expires

A detection proven eighteen months ago, across two platform migrations and a schema change, is not proven now. Validated status has a recency window, and results outside it decay rather than persist.

Why it is a rule and not advice. Coverage metrics that never decay reward the year an organisation ran a purple team exercise, indefinitely.

6. Sensors without intent produce noise

Telemetry and detection content cannot be more mature than the threat intelligence and threat modeling directing them. Collecting more and writing more is not a substitute for knowing who you are defending against and how they would move.

Why it is a rule and not advice. It is the failure mode of well-funded programmes: enormous data volumes, a large rule estate, and no articulable answer to which adversary any of it is for.

7. The assessment must be able to disappoint you

Every constraint above is applied mechanically at scoring time. None of them can be argued with during a review, and none of them can raise a score — a ceiling only lowers.

Why it is a rule and not advice. Exhortations to be honest do not survive a budget cycle. Arithmetic does.

The through-line. Each principle prevents a specific, common, expensive failure — and each is implemented as arithmetic rather than as guidance, because guidance does not survive the meeting where the number is reported.