NIST CSF 2.0
CSF 2.0 introduced GOVERN as a first-class function, emphasising strategy, risk ownership and accountability. UTIOM operationalises that shift directly: Vision and Strategy embed governance into operational behaviour rather than leaving it as a policy layer, Crown Jewels shifts identification from asset inventories to business-critical focus, and the engineering phases treat detection as a discipline rather than alert accumulation.
ISO/IEC 27001:2022 + Amd 1:2024
The mandatory clauses map to UTIOM's leadership pillar: Clauses 4.1–4.2 and 5.1–5.3 to Vision, Clauses 6.1–6.2 and 8.2–8.3 to Strategy, Clause 10 to Continuous Improvement. Annex A controls map to the engineering and operations pillars, with A.5.7 threat intelligence, A.8.15 logging, A.8.16 monitoring and the A.5.24 to A.5.28 incident management set carrying most of the weight.
SOC-CMM
SOC-CMM measures how mature a SOC is across business, people, process, technology and services. UTIOM provides the mechanism to become mature. Lower maturity SOCs benefit from the lifecycle and prioritisation logic; higher maturity SOCs use it to integrate threat intelligence into detection engineering and institutionalise improvement loops.
DORA
DORA mandates operational resilience for financial entities. UTIOM operationalises it: Crown Jewels and threat-informed Strategy focus ICT risk management on systems critical to financial stability, Threat Visibility and Detection improve early identification of significant incidents, tiered Response supports consistent classification and regulatory reporting, and Continuous Improvement translates lessons into demonstrable resilience.
MITRE ATT&CK and DeTT&CT
ATT&CK describes adversary behaviour; DeTT&CT measures detection coverage against it using data source quality. UTIOM anchors both to crown jewels, so coverage is prioritised by business consequence rather than by technique count.
TID-CMM
The Threat-Informed Detection Capability Maturity Model measures the engineering pillar specifically: telemetry coverage per modelled threat, detection traceability and validation depth. SOC-CMM assesses breadth across the whole function; TID-CMM assesses depth in one part of it, and refuses to score highly where telemetry is weak or nothing has been tested. Eight domains and 58 sub-capabilities, aligned to MITRE ATT&CK Enterprise and crosswalked to NIST CSF 2.0 and SOC-CMM. Published separately at
tid-cmm.com.
TIR-CMM
The Threat-Informed Response Capability Maturity Model measures the operations pillar: containment authority, playbooks executed under a clock, containment options with known blast radius, and whether you move faster than the adversary. It contains no detection domain, consuming detection maturity as an input constraint instead. 58 sub-capabilities across three assessment tiers. Published at
tir-cmm.com.
STRATA
Six dimensions replacing the People, Process, Technology triad: Strategy, Talent, Resilience, Automation, Telemetry and Adaptability. Informs how UTIOM treats analyst autonomy, learning time and burnout as design signals rather than staffing issues.
TOGAF Standard, 10th Edition and COBIT
TOGAF Standard, 10th Edition's Architecture Vision phase and COBIT's governance objectives feed UTIOM's Vision and Strategy phases, keeping the operating model traceable to existing enterprise architecture and governance work.
NIST SP 800-61 and SANS PICERL
The two incident response lifecycles most practitioners already know. SP 800-61 uses four phases and SANS uses six-step PICERL, and both concentrate on what happens once an incident is known. UTIOM spans a wider arc: Vision, Strategy and Crown Jewels sit before Preparation, and Threat Visibility and Threat Detection make preparation an engineering discipline rather than a checklist. Revision 3 of SP 800-61 reorganises the same activities under CSF 2.0 functions. The crosswalk is drawn as Figure 2 on the
diagrams page.
ISO/IEC 27035-1:2023
Information security incident management, in four parts: 27035-1:2023 principles and process, 27035-2:2023 planning and readiness, 27035-3:2020 ICT incident response operations, and 27035-4:2024 coordination. Where ISO 27001 requires that incidents be managed, 27035 says how. UTIOM's Response phase produces the pre-engineered playbooks, containment authority and evidence handling that 27035 describes as readiness.
NIS2 and GDPR
NIS2 Article 21 requires policies to assess the effectiveness of cybersecurity risk management measures, which a control inventory cannot evidence. Article 23 sets 24-hour early warning, 72-hour incident notification and a final report not later than one month after the incident notification. GDPR Article 33 sets its own 72-hour clock for personal data breaches. Whether either is achievable is a telemetry and scoping question decided months earlier. See the
NIS2 and DORA page for the requirement-to-output mapping.
TIBER-EU 2025
The European framework for threat intelligence-based ethical red teaming, updated by the Eurosystem in 2025 to align with DORA’s TLPT regulatory technical standards, providing operational guidance for TLPT where used consistently with DORA and the applicable RTS. UTIOM's Validation domain produces the adversary emulation evidence that a TLPT exercise formalises, though TIBER-EU 2025 itself requires accredited providers and is outside what any self-assessment can deliver.
CIS Critical Security Controls v8.1
A prioritised set of defensive actions with implementation groups by organisation size. Where CIS says which controls to implement first, UTIOM says which assets they must protect and how to prove they work. The two sit well together: CIS answers what to deploy, UTIOM answers what it must defend and how it is validated.
Sigma, MITRE Engage and D3FEND
Sigma is a platform-agnostic detection rule format, supporting the portability principle in detection engineering. Engage structures adversary engagement and deception, used in UTIOM to place deception along modelled crown jewel attack paths. D3FEND maps countermeasures to the techniques in ATT&CK, giving the defensive counterpart to the offensive matrix.
RSMM
The Realistic SIEM Maturity Model. Five levels from Blame Collector to Outcome-Driven SIEM, measuring the platform detection actually runs on. Deliberately anti-aspirational: there is no level five, because the highest level most organisations should aim for is a platform that reliably serves the operation rather than one that impresses in a demonstration.
CTI-CMM and MITRE INFORM
Peer maturity models worth positioning against rather than competing with. CTI-CMM measures threat intelligence support to stakeholders across ten domains. INFORM, formerly M3TID, measures threat-informed defence at programme level. Both operate alongside UTIOM: they measure how well a function serves its consumers, where UTIOM defines the operating model that connects those functions into one lifecycle.