← Toolkit
1 · Maturity→2 · Capability→3 · Metrics→4 · Roadmap
UTIOM · Capability Assessmentv1.4

Where does your security operation actually stand?

One hundred and five indicators covering the full UTIOM lifecycle, grouped by the framework's three pillars. Score each honestly and you get a position per pillar and per domain, plus the specific gaps worth closing first.

Score what is true today, not what is planned. An indicator counts as measured only if someone could produce the number this week without starting a project. Indicators marked KPI map to a metric in the framework. Those marked AUTO describe the automated end-state the framework treats as the mature form of that activity.
measure
Capability assessment
105 indicators scored
understand
Capability dashboard
what the scores mean
act
Improvement roadmap
what to do first
—
Not started
0/105
Fills the form with a realistic profile so you can see the output before doing the real thing.
Step 2 of 4 · 0/105 answered

Next: measure whether the fixes worked

Your results are below. The dashboard reads them back as the seven lifecycle phases and shows which organisational dimension is most associated with each gap; the roadmap then sequences what to do about it.

Your UTIOM position

Two results, and they answer different questions. The Diagnostic Capability Index is continuous: it weights the lowest domain rather than the mean, because each lifecycle phase depends on the one before it, and it drives the radar, trends and prioritisation. The Governed UTIOM Maturity level is the official ordinal result, derived from the three assessment tiers and floored by the binding constraint.

—
Governed UTIOM Maturity
Diagnostic Capability Index 0 / 5 ·

Measuring a pillar in more depth

This assessment scores all three pillars at the same resolution. Two of them have a dedicated maturity model that goes further, built on the same premise that everything a security operations function does is incident response. They add measurement depth; they do not replace what you have just done.

Assessment tiers

Three tiers in sequence: a foundation, the capability built on it, and the assurance that proves it works. The diagnostic index is continuous and shows direction. The governed level is ordinal and is floored by the tier below, so a strong area cannot report above a hollow foundation. Where a tier is constrained, the reason is shown rather than the score silently lowered.

STRATA lens

STRATA explains why a capability is strong or weak. It does not create a competing maturity score. Each dimension is derived from the domains you have just scored, using influence weights read from the indicators themselves. Those weights are heuristic: they express relative influence and enabling relationships, not measured contribution. Read the direction and the spread, not a decimal place.

Capability profile

Each axis is a domain. The further from centre, the stronger the capability.

Risk reduction leverage

Where the same unit of effort buys the most operational risk reduction, accounting for lifecycle dependencies.

Influence and constraint

How each phase limits the one that depends on it. A phase built far ahead of its foundation returns less than its score suggests.

—
Operational risk exposure today
—
If the top three reach level 4
—
Reduction available

A directional model, not an actuarial estimate. Exposure weights each domain by its leverage in the lifecycle and discounts downstream gains when upstream phases are weak, so improving detection while visibility is thin returns less than the raw score suggests.

Close these first

    Build your roadmap Open metrics calculator