CDC Maturity Self-Assessment Checklist¶
Scoring rules: see ../docs/08-maturity-model.md. A level is achieved only when all its boxes and all lower-level boxes are checked, with evidence recorded. Copy this file, date it, and keep assessments in version control to track the trend.
Assessment date: | Assessor(s): | Evidence repository:
GOVERN¶
Level 2 - [ ] Signed CDC charter defining mission, scope and authority — evidence: … - [ ] Security policies approved and reviewed within last 12 months — evidence: … - [ ] RACI for security roles exists — evidence: …
Level 3 - [ ] Cyber risk items appear in the enterprise risk register with owners — evidence: … - [ ] Quarterly (or better) reporting to executive management — evidence: … - [ ] Supplier contracts include security requirements; supplier register maintained — evidence: … - [ ] Multi-year budget/staffing plan approved — evidence: …
Level 4 - [ ] Management completed cybersecurity training and participated in an exercise in last 12 months — evidence: … - [ ] Resource decisions demonstrably driven by risk/maturity data — evidence: …
Function score: ☐ L1 ☐ L2 ☐ L3 ☐ L4
IDENTIFY¶
Level 2 - [ ] Automated asset discovery on core networks — evidence: … - [ ] Vulnerability scanning at least quarterly on core estate — evidence: … - [ ] Subscribed to national CSIRT / ENISA advisories — evidence: … - [ ] Crown-jewel services listed with owners — evidence: …
Level 3 - [ ] Inventory accuracy measured, > 90% — evidence: … - [ ] Documented threat profile mapped to MITRE ATT&CK, reviewed annually — evidence: … - [ ] Risk-based remediation SLAs defined and tracked — evidence: … - [ ] Annual risk assessment feeds budget/backlog — evidence: …
Level 4 - [ ] Continuous attack-surface monitoring incl. cloud/SaaS — evidence: … - [ ] Threat intel demonstrably drives hunts and new detections (traceable) — evidence: …
Function score: ☐ L1 ☐ L2 ☐ L3 ☐ L4
PROTECT¶
Level 2 - [ ] MFA enforced for all remote and administrative access — evidence: … - [ ] Hardening baselines defined for main platforms — evidence: … - [ ] Patching SLA for critical vulnerabilities defined and measured — evidence: … - [ ] Backup restore tested within last 12 months — evidence: …
Level 3 - [ ] Phishing-resistant MFA for privileged accounts; PAM operational — evidence: … - [ ] Network segmentation isolates crown-jewel zones — evidence: … - [ ] Offline/immutable backup copy for critical data — evidence: … - [ ] Control coverage measured (e.g., % endpoints with EDR ≥ 95%) — evidence: …
Level 4 - [ ] Continuous/periodic technical control validation (attack simulation) — evidence: … - [ ] Security requirements embedded in procurement and SDLC with verification — evidence: …
Function score: ☐ L1 ☐ L2 ☐ L3 ☐ L4
DETECT¶
Level 2 - [ ] Central log platform; identity, endpoint and email sources onboarded — evidence: … - [ ] ≥ 20 documented use cases mapped to ATT&CK — evidence: … - [ ] Triage runbook with severity matrix — evidence: … - [ ] Defined coverage hours with on-call arrangement — evidence: …
Level 3 - [ ] Detection lifecycle with version control and testing — evidence: … - [ ] Coverage measured against ATT&CK and crown jewels; gaps drive backlog — evidence: … - [ ] 24/7 monitoring (in-house or hybrid) — evidence: … - [ ] MTTD measured per confirmed incident — evidence: … - [ ] Threat hunting performed on a schedule — evidence: …
Level 4 - [ ] All production detections validated (fired in test) within 12 months — evidence: … - [ ] Detection-as-code with CI/CD pipeline — evidence: … - [ ] FP rates and coverage trended, demonstrably driving engineering — evidence: …
Function score: ☐ L1 ☐ L2 ☐ L3 ☐ L4
RESPOND¶
Level 2 - [ ] Approved IR plan with severity classification and roles — evidence: … - [ ] Playbooks for top scenarios incl. ransomware and data breach — evidence: … - [ ] Statutory reporting contacts and templates prepared (NIS2/GDPR/DORA as applicable) — evidence: … - [ ] Tabletop exercise within last 12 months — evidence: …
Level 3 - [ ] Containment authority pre-agreed in charter; isolation technically tested — evidence: … - [ ] Forensic capability in-house or via retainer, with chain-of-custody procedure — evidence: … - [ ] Reporting drill executed against statutory deadlines — evidence: … - [ ] Post-incident reviews with tracked actions for all P1/P2 — evidence: …
Level 4 - [ ] MTTC trended; containment steps automated with approval gates — evidence: … - [ ] Cross-functional crisis exercise incl. management and comms within 12 months — evidence: …
Function score: ☐ L1 ☐ L2 ☐ L3 ☐ L4
RECOVER¶
Level 2 - [ ] Recovery plans with RTO/RPO for crown-jewel services — evidence: … - [ ] Restore tests annually — evidence: … - [ ] Post-incident review process defined — evidence: …
Level 3 - [ ] Rebuild-from-known-good procedure; integrity verification before reconnection — evidence: … - [ ] Credential rotation standard in recovery runbooks — evidence: … - [ ] Joint BCM/CDC exercise within 12 months — evidence: … - [ ] Lessons-learned actions tracked to closure — evidence: …
Level 4 - [ ] Ransomware-scale recovery exercised; measured recovery vs. RTO — evidence: … - [ ] Demonstrable control/detection changes originating from incidents — evidence: …
Function score: ☐ L1 ☐ L2 ☐ L3 ☐ L4
Result¶
| Function | Score | Target | Gap actions |
|---|---|---|---|
| GOVERN | |||
| IDENTIFY | |||
| PROTECT | |||
| DETECT | |||
| RESPOND | |||
| RECOVER |
Next assessment due: …