Awareness maturity
Also known as: security awareness maturity
A measure of how far an organisation has come in making security part of how its people think and act.
Draft - this entry has not been reviewed yet.
Formal
An assessment that places an organisation's awareness work on a scale of stages - from nothing in place, through a yearly course held only to meet requirements, to lasting change in behaviour and security culture - to show where it stands and what to improve next.
In plain English
Like the swimming badges children earn in stages - a badge does not make them swim better, but it shows honestly where they are and what the next step is.
In practice
The awareness lead at a pension fund places it at the stage “one course a year, nothing measured”, and sets the goal of tracking phishing reports every quarter to reach the next stage.
Why it matters
Without a measure, awareness work is judged by how much training was held rather than whether behaviour changed, and leaders cannot see progress or decide where to spend.
Technical deep dive
Awareness maturity models are staged capability models in the tradition of CMM/CMMI, applied to the human side of security. The most widely cited is the SANS Security Awareness Maturity Model, which defines five stages: Non-Existent; Compliance Focused, where the goal is to satisfy an audit or regulatory training requirement, typically with an annual module; Promoting Awareness and Behavior Change, where the programme targets a small set of high-impact human risks and addresses them continuously; Long-Term Culture Change; and a fifth stage, originally labelled Metrics Framework and in the current edition Optimization and Resilience, where outcomes are tied to measurable risk reduction. SANS itself puts measurable results from stage three at roughly six to twelve months, and stage four at three to ten years depending on size and complexity.
NIST SP 800-50 Rev. 1 (September 2024) takes a different route: its Appendix A offers example maturity levels adapted from the FY21 Inspector General FISMA metrics - Ad Hoc, Defined, Consistently Implemented, Managed and Measurable, and Optimized - scored per question, for example whether roles are defined and resourced, whether workforce skills are assessed, and whether the programme's effectiveness is measured through practical exercises. At the top level the organisation must be able to show that incidents caused by personnel actions or inactions are decreasing over time, which moves the evidence from activity to outcome.
The key methodological point is that maturity describes the programme's capability, not the workforce's current risk level. A mature programme can still report a high click rate in a hard simulation, and an immature one can look good on a trivial template. Assessments should therefore combine document evidence (strategy, plan, roles, budget), process evidence (needs analysis, audience segmentation, repetition cadence) and outcome evidence (reporting rate, time-to-report, repeat-clicker trends, incidents with a human root cause). Completion percentages of mandatory e-learning are the classic stage-two metric and say almost nothing about behaviour.
Common failure modes are self-assessment inflation, scoring the average of many dimensions and hiding one weak dimension, and treating a level as an end state rather than a snapshot. In practice the score feeds a gap analysis against a target level chosen from the organisation's risk appetite, and the reassessment is repeated yearly as the Check step of a PDCA cycle. Awareness maturity is a sub-dimension of overall security maturity; it borrows the same scale logic as, for example, the implementation tiers in the NIST Cybersecurity Framework, but measures learning and behaviour rather than technical controls.
What to learn first
Everything this builds on, foundations first.
- Security policy
- →Threat
- →Security awareness
- →Security culture
- →Awareness maturity
Relationships
- A kind of
- Security maturity
Sources & further reading
Standards & official texts
Course material
- Cyber Security Fast Track - Ordliste
Reference works
- SANS Security Awareness Maturity Model · SANS Institute
Where this data comes from
This entry was drafted by an AI from the sources above and has not yet been checked by a person. Treat it as a starting point, and check anything important against the sources.
See the review queueSuggest a correction on GitHubThis term as JSON
Check yourself
Loading…