From the course: Building an Effective Cybersecurity Program for Your Startup

Unlock the full course today

Join today to access over 23,200 courses taught by industry experts.

The capability maturity model

The capability maturity model

- [Instructor] When you summarize your risk assessment, your security controls assessment, your compliance assessment, and your penetration test for your leadership team, you're enabling them to make a well-informed decision about what your startup cybersecurity program could look like. But all the assessments we've discussed so far focus on where your cybersecurity program is today. None of them really focus on where you want that program to be in the near future. That's why you should round out your list of assessments with a cybersecurity program maturity assessment. The Capability Maturity Model, or CMM, breaks out of that binary compliance mode. You're either doing it or you're not. And it enables you to assign expected levels of quality or excellence to each control in your cybersecurity program. That model has five maturity levels: initial, repeatable, defined, capable, and efficient. When a security control is at…

Contents