UTIOM is a living framework. Every release records what changed and why. Point releases cover additions to the assessment instruments and supporting content; major versions cover changes to the framework model itself.
The same questions, read through three tiers, so a strong area can no longer conceal a hollow foundation.
The Framework Book remains at edition v1.2 until its methodology sections are updated. Full methodology detail is in what UTIOM is and the capability assessment.
A new view that reads the assessments you have already completed and explains what the scores mean.
Content and instrument updates. No change to the framework model itself.
The release that made the framework executable rather than descriptive.
The complete written framework, published free under Creative Commons.
The framework was made public for the first time: the lifecycle, the three pillars, the seven laws of the doctrine, and the central argument that incident response is not a phase but the operating mode of security operations.
Serious development began roughly four years before public release, refined against real security operations work across banking, FinTech and hybrid enterprise environments. The lifecycle, the crown-jewel-first prioritisation and the validation pairing all came out of that period, not from a whiteboard.
The concept first surfaced while the author was writing his first book: the observation that security operations were being assembled from parts rather than designed as a system, and that the gap between strategy and execution was where organisations were actually losing. It took the following decade of building and operating SOCs to work out what to do about it.
UTIOM does not evolve alone. Two capability maturity models measure its pillars in depth, and each has its own release track.
Join the UTIOM community. Discuss, contribute evidence and share implementation experience. About the community →