Specification §10
Standards alignment
TIR-CMM operationalises rather than replaces. Four ontologies anchor the model, each doing a distinct job, and the eight domains crosswalk cleanly to the frameworks an organisation is already reporting against.
Nothing here asks you to abandon a framework you already run. D3FEND supplies the countermeasure vocabulary, RE&CT supplies the response-action spine, ATT&CK Mitigations carry the traceability from detection scope to response scope, and NIST SP 800-61r3 provides the governance crosswalk. TIR-CMM's contribution is the measurement layer none of them provide: whether the capability is proven, authorised, and faster than the adversary.
The four anchoring ontologies
| Anchor | Role in TIR-CMM |
|---|---|
| MITRE D3FEND 1.5.0 7 tactics; Isolate / Evict / Restore are response-side |
Structural mirror of ATT&CK. Provides the countermeasure vocabulary for the containment primitives held per asset class in the lattice, and the conceptual symmetry with TID-CMM. |
| RE&CT RA1000–RA6000, 6 stages, 300+ response actions |
The operational spine. Provides the response-action library that RE-5 and RE-8 score against, and the phase structure practitioners already recognise. |
| ATT&CK Mitigations M-codes |
Traceability bridge. Techniques scoped by TID-CMM carry M-codes; these map to lattice cells, so the response scope derives from the detection scope automatically. |
| NIST SP 800-61r3 April 2025, CSF 2.0 Community Profile |
Governance crosswalk. r3 deliberately abandons the linear four-phase lifecycle in favour of CSF 2.0 functions. |
D3FEND 1.5.0
Seven tactics, of which Isolate, Evict and Restore are the response-side ones. The CE domain — containment, eradication and recovery — maps directly onto those three.
RE&CT
Response actions coded RA1000–RA6000 across six stages, with over 300 response actions. RE-8 scores whether an organisation's actions are mapped to these codes bidirectionally.
NIST SP 800-61r3
Published April 2025 as a CSF 2.0 Community Profile. TIR-CMM follows r3, not r2 — and that is a deliberate choice, not a detail.
Following r3 rather than r2 is a differentiator. Revision 3 deliberately abandons the linear four-phase incident lifecycle — prepare, detect, contain, recover — in favour of CSF 2.0 functions. TIR-CMM follows r3, which sets it apart from models still built on the 2012 phase model.
Domain-level crosswalk
The eight TIR-CMM domains, mapped across the frameworks most organisations already report against. Domain codes read: RP Response Preparation & Readiness · RA Response Authority & Decision Rights · RE Response Engineering & Playbooks · CE Containment, Eradication & Recovery · AO Automation & Orchestration · FI Forensics, Evidence & Investigation · RV Response Validation & Exercising · RG Response Governance, Metrics & Improvement.
| TIR-CMM | NIST CSF 2.0 | NIST SP 800-61r3 | ISO/IEC 27035 | RE&CT | D3FEND | SOC-CMM | DORA / NIS2 |
|---|---|---|---|---|---|---|---|
| RP | GV, PR.IP, RS.MA | Preparation (GV/ID/PR) | Plan & prepare | RA1000 | Model, Harden | Process, People | ICT continuity, incident mgmt |
| RA | GV.RR, RS.MA | Governance & roles | Plan & prepare | RA1000 | — | Governance | Management body accountability |
| RE | RS.AN, RS.MI | Response execution | Detection & reporting; Response | RA2000–RA5000 | Isolate, Evict | Process, Technology | Response & recovery plans |
| CE | RS.MI, RC.RP | Containment/eradication/recovery | Response; Recovery | RA3000–RA5000 | Isolate, Evict, Restore | Technology | ICT continuity, backup |
| AO | RS.MI, DE.AE | Response execution | Response | RA3000 | Isolate | Technology | Operational resilience |
| FI | RS.AN, ID.RA | Analysis | Assessment & decision | RA2000 | — | Technology, Process | Evidence, root cause |
| RV | ID.IM, PR.PT | Continuous improvement | Lessons learned | RA6000 | — | Process | Testing (TLPT/DORA), NIS2 testing |
| RG | GV, ID.IM, RS.CO | Continuous improvement | Lessons learned | RA6000 | — | Governance, Services | Reporting clocks (24h/72h/1m) |
Positioning against adjacent models
| Model | Relationship |
|---|---|
| SOC-CMM | Assesses the SOC as a function. TIR-CMM assesses whether the organisation can act — including the parts of response that sit outside the SOC: authority, business acceptance, recovery. Complementary. |
| NIST CSF 2.0 | Reporting layer above TIR-CMM. TIR-CMM supplies the evidence CSF Respond and Recover ask for. |
| TID-CMM | Sibling module. Bonded through constraint R4 and the bridge domain. |
| Gartner CTEM | Asks whether exposure is exploitable and observable. TIR-CMM asks whether exploitation can be stopped. |
| DORA / NIS2 | TIR-CMM produces the testing, reporting-clock and continuity evidence these regimes require, without being a compliance model. |
| VERIS | Incident taxonomy; useful as an input to scenario derivation, not a maturity model. |
External references
- MITRE D3FEND — the countermeasure knowledge graph behind the containment primitives.
- RE&CT — the response action framework, RA1000–RA6000.
- MITRE ATT&CK — techniques and Mitigations (M-codes) used as the traceability bridge.
- NIST SP 800-61r3 — Incident Response Recommendations and Considerations for Cybersecurity Risk Management, April 2025.