Skip to content
atlas

Security maturity

Also known as: maturity level, maturity model, cybersecurity maturity

How far an organisation's security has grown - from random and tied to single people to planned, measured and steadily improving.

Draft - this entry has not been reviewed yet.

Formal

A rating of how established and repeatable an organisation's security practices are, usually on a scale of levels (for example from "initial" to "always improving"), used to compare against a target and to plan the next steps.

In plain English

Like belt colours in karate - they show not whether you can win one fight, but how steady and practised your skills have become.

In practice

A regional bus company rates itself at level 2 of 5, because backups are taken but only one person knows how to restore them; it sets level 3 as next year's goal.

Why it matters

It lets an organisation show customers and authorities where it stands and grow step by step instead of chasing everything at once.

Technical deep dive

Most security maturity scales descend from the Capability Maturity Model developed at Carnegie Mellon's Software Engineering Institute for software processes, whose successor CMMI uses five levels: Initial, Managed, Defined, Quantitatively Managed and Optimizing. The logic carries over: level 1 means outcomes depend on individuals, level 2 that practices are planned and tracked at project or team level, level 3 that they are documented and standardised across the organisation, level 4 that they are managed with quantitative data, and level 5 that they are systematically improved. Process assessment standards in the ISO/IEC 33000 series, which replaced ISO/IEC 15504, and COBIT 2019 use comparable capability levels from 0 to 5.

Security-specific models vary in what they rate. The US Department of Energy's C2M2 uses maturity indicator levels MIL0 to MIL3 per domain; OWASP SAMM scores software assurance practices from 0 to 3; BSIMM is descriptive, reporting which activities other firms actually perform rather than prescribing levels. The NIST CSF Tiers (Partial, Risk Informed, Repeatable, Adaptive) are frequently used as a maturity scale, although NIST describes them as characterising the rigour of risk governance and management rather than as maturity levels. ISO/IEC 27001 has no maturity levels at all: a requirement is either conformed with or not, and maturity scoring is layered on top by assessors or by the organisation itself.

A useful distinction is between capability (can the process be performed reliably?) and effectiveness (does it reduce risk?). A well-documented, level-3 patch process that takes 60 days to close critical vulnerabilities is mature on paper and weak in practice, which is why maturity ratings should be paired with security metrics that measure outcomes.

Common pitfalls: averaging scores across domains hides a single critical weakness; self-ratings are inflated unless every level requires evidence; organisations set level 5 as a universal target when a risk-based target profile might call for level 2 in some domains and level 4 in others; and changes to the scale between assessments make year-on-year comparisons meaningless. Done well, a maturity assessment produces a gap between current and target levels per domain, a roadmap prioritised by risk, and a repeatable method so that the next assessment measures progress rather than a different assessor's opinion.

What to learn first

Everything this builds on, foundations first.

  1. Governance
  2. →Security maturity

Relationships

Requires
Governance

Sources & further reading

Standards & official texts

  • NIST Cybersecurity Framework 2.0 (Tiers)

Course material

  • Cyber Security Fast Track - Kursuskompendium, Modul 8

Where this data comes from

This entry was drafted by an AI from the sources above and has not yet been checked by a person. Treat it as a starting point, and check anything important against the sources.

See the review queueSuggest a correction on GitHubThis term as JSON

Check yourself

Loading…

Atlas is in beta.