One hundred and five indicators covering the full UTIOM lifecycle, grouped by the framework's three pillars. Score each honestly and you get a position per pillar and per domain, plus the specific gaps worth closing first.
Your results are below. The dashboard reads them back as the seven lifecycle phases and shows which organisational dimension is most associated with each gap; the roadmap then sequences what to do about it.
Two results, and they answer different questions. The Diagnostic Capability Index is continuous: it weights the lowest domain rather than the mean, because each lifecycle phase depends on the one before it, and it drives the radar, trends and prioritisation. The Governed UTIOM Maturity level is the official ordinal result, derived from the three assessment tiers and floored by the binding constraint.
This assessment scores all three pillars at the same resolution. Two of them have a dedicated maturity model that goes further, built on the same premise that everything a security operations function does is incident response. They add measurement depth; they do not replace what you have just done.
Three tiers in sequence: a foundation, the capability built on it, and the assurance that proves it works. The diagnostic index is continuous and shows direction. The governed level is ordinal and is floored by the tier below, so a strong area cannot report above a hollow foundation. Where a tier is constrained, the reason is shown rather than the score silently lowered.
STRATA explains why a capability is strong or weak. It does not create a competing maturity score. Each dimension is derived from the domains you have just scored, using influence weights read from the indicators themselves. Those weights are heuristic: they express relative influence and enabling relationships, not measured contribution. Read the direction and the spread, not a decimal place.
Each axis is a domain. The further from centre, the stronger the capability.
Where the same unit of effort buys the most operational risk reduction, accounting for lifecycle dependencies.
How each phase limits the one that depends on it. A phase built far ahead of its foundation returns less than its score suggests.
A directional model, not an actuarial estimate. Exposure weights each domain by its leverage in the lifecycle and discounts downstream gains when upstream phases are weak, so improving detection while visibility is thin returns less than the raw score suggests.