Methods and protocols
Maturity model
Maturity is measured neither by the number of models in use nor by the degree of autonomy.
| Level | State | Expected evidence |
|---|---|---|
| M0 — Informal | Uninventoried individual use | No reliable control |
| M1 — Visible | Usage rules, register, and owners | Inventory, basic training, prohibited-data rules |
| M2 — Measured | Prioritized cases and reproducible evaluations | Baselines, thresholds, pilot reports |
| M3 — Governed | Portfolio, common architecture, and risk management | Gates, responsibilities, suppliers, incidents |
| M4 — Adaptive | Monitoring, reassessment, and controlled retirement | Trends, exercises, audits, and lifecycle decisions |
Progression rule
An organization progresses only when evidence from the previous level exists for the scope concerned. It may be M3 in one department and M0 in another; an overall score must not hide those gaps.
Next action by level
- M0 → M1: inventory real use and publish simple data rules.
- M1 → M2: select a measurable case and build evaluations before the prototype.
- M2 → M3: establish gates, a supplier register, and a shared security foundation.
- M3 → M4: automate controls, exercise incident response, and institutionalize retirement.
To print or save as PDF: Ctrl+P (⌘P on Mac).
Source and history · GitHub