← UTIOM
UTIOMv1.4

Changelog

UTIOM is a living framework. Every release records what changed and why. Point releases cover additions to the assessment instruments and supporting content; major versions cover changes to the framework model itself.

Release history

Version 1.4September 2026

Assessment architecture refinement

The same questions, read through three tiers, so a strong area can no longer conceal a hollow foundation.

  • Introduced three assessment tiers — Strategic & Governance Foundation, Engineering & Operational Capability, and Assurance & Evolution.
  • Separated the continuous Diagnostic Tier Index from ordinal Governed Maturity.
  • Added binding-constraint logic: a tier cannot be governed above the tier it rests on, and the reason is always shown.
  • Clarified STRATA as an explanatory enabling lens rather than a maturity score, with heuristic influence weights and evidence counts.
  • Aligned optional TID-CMM and TIR-CMM integration with governed maturity: depth modules constrain downward and never inflate a score.
  • Synchronised the web assessment and the downloadable workbook on one tier definition.
  • Assessment content unchanged at 50 criteria, 105 indicators and 70 metrics. Results produced under v1.3 remain v1.3 results.
  • Added UTIOM Security Assurance v0.1 (Practitioner Preview) as a new ecosystem module for reviewing whether Governed UTIOM Maturity claims are supported by sufficient, current and trustworthy evidence.

The Framework Book remains at edition v1.2 until its methodology sections are updated. Full methodology detail is in what UTIOM is and the capability assessment.

Version 1.3August 2026

The capability dashboard

A new view that reads the assessments you have already completed and explains what the scores mean.

  • Added the capability dashboard, which shows the seven lifecycle phases together with the capability domains that support them.
  • Added a STRATA diagnostic view indicating which organisational dimension is most associated with each gap.
  • Connected assessment → dashboard → roadmap as one journey, so results lead into a plan.
  • Every roadmap action now names the lifecycle phase it affects.
  • Response times are compared against adversary breakout rather than shown as a score.
  • Assessment content is unchanged: 50 maturity criteria, 105 capability indicators, 70 metrics.
Version 1.2August 2026

Diagrams, and two capability gaps closed

Content and instrument updates. No change to the framework model itself.

  • Added the diagrams page: how UTIOM maps onto NIST SP 800-61 and SANS PICERL, the traceability chain, the validation rail and the framework family.
  • Added a page on the economics of security operations.
  • Extended the instruments to 105 capability indicators, 50 maturity criteria and 70 metrics, closing gaps around containment blast radius and decision latency.
  • Expanded standards alignment from nine references to seventeen.
Version 1.1August 2026

The assessment instruments

The release that made the framework executable rather than descriptive.

  • Added four browser-based assessment tools: maturity, capability, metrics and improvement roadmap.
  • Maturity assessment: 45 staged criteria, gated so advanced practice on an incomplete foundation does not count.
  • Capability assessment: 93 indicators across the lifecycle domains.
  • Metrics calculator: 67 metrics with explicit formulas.
  • Added an offline workbook and a self-hosted package for use inside closed networks.
Version 1.0February 2026

First edition of the framework book

The complete written framework, published free under Creative Commons.

  • Full seven-phase lifecycle across three pillars
  • Capability layer model and threat-informed maturity model
  • Five-phase implementation blueprint
  • Metrics and performance indicators
  • Worked industry examples: cloud-native FinTech under DORA, hybrid banking with SWIFT and branch environments, and OT-heavy manufacturing
  • Alignment sections for NIST CSF 2.0, SOC-CMM and DORA
Public releaseAugust 2025

UTIOM published

The framework was made public for the first time: the lifecycle, the three pillars, the seven laws of the doctrine, and the central argument that incident response is not a phase but the operating mode of security operations.

DevelopmentFrom 2022

Four years of building and testing

Serious development began roughly four years before public release, refined against real security operations work across banking, FinTech and hybrid enterprise environments. The lifecycle, the crown-jewel-first prioritisation and the validation pairing all came out of that period, not from a whiteboard.

OriginCirca 2018

The core idea

The concept first surfaced while the author was writing his first book: the observation that security operations were being assembled from parts rather than designed as a system, and that the gap between strategy and execution was where organisations were actually losing. It took the following decade of building and operating SOCs to work out what to do about it.

The framework family

UTIOM does not evolve alone. Two capability maturity models measure its pillars in depth, and each has its own release track.

TID-CMM
The Threat-Informed Detection Capability Maturity Model. Derives an in-scope ATT&CK set from your environment and threat profile rather than assuming all 697 Enterprise techniques and sub-techniques apply, then computes which prioritised behaviours are structurally undetectable with the telemetry you collect. Measures the engineering pillar. Published at tid-cmm.com.
TIR-CMM
The Threat-Informed Response Capability Maturity Model. Introduces the Containment Lattice and the Containment Margin metric, and measures decision latency separately rather than burying it inside MTTR. Three assessment tiers from a twenty-minute Pulse to an evidence-led Assurance review. Published at tir-cmm.com.
STRATA
Extends People, Process and Technology into six dimensions, adding Resilience, Automation, Telemetry and Adaptability to Strategy and Talent. Supplies the organisational layer UTIOM assesses in its People and operating model domain.
RSMM
The Realistic SIEM Maturity Model. Five levels from Blame Collector to Outcome-Driven SIEM, measuring the platform that detection runs on.

Join the UTIOM community. Discuss, contribute evidence and share implementation experience. About the community →