Specification §10

Standards alignment

TIR-CMM operationalises rather than replaces. Four ontologies anchor the model, each doing a distinct job, and the eight domains crosswalk cleanly to the frameworks an organisation is already reporting against.

Nothing here asks you to abandon a framework you already run. D3FEND supplies the countermeasure vocabulary, RE&CT supplies the response-action spine, ATT&CK Mitigations carry the traceability from detection scope to response scope, and NIST SP 800-61r3 provides the governance crosswalk. TIR-CMM's contribution is the measurement layer none of them provide: whether the capability is proven, authorised, and faster than the adversary.

The four anchoring ontologies

Each anchor does a distinct job. None of them is a maturity model, which is why TIR-CMM exists alongside them.
Anchor Role in TIR-CMM
MITRE D3FEND 1.5.0
7 tactics; Isolate / Evict / Restore are response-side
Structural mirror of ATT&CK. Provides the countermeasure vocabulary for the containment primitives held per asset class in the lattice, and the conceptual symmetry with TID-CMM.
RE&CT
RA1000–RA6000, 6 stages, 300+ response actions
The operational spine. Provides the response-action library that RE-5 and RE-8 score against, and the phase structure practitioners already recognise.
ATT&CK Mitigations
M-codes
Traceability bridge. Techniques scoped by TID-CMM carry M-codes; these map to lattice cells, so the response scope derives from the detection scope automatically.
NIST SP 800-61r3
April 2025, CSF 2.0 Community Profile
Governance crosswalk. r3 deliberately abandons the linear four-phase lifecycle in favour of CSF 2.0 functions.

D3FEND 1.5.0

Seven tactics, of which Isolate, Evict and Restore are the response-side ones. The CE domain — containment, eradication and recovery — maps directly onto those three.

RE&CT

Response actions coded RA1000–RA6000 across six stages, with over 300 response actions. RE-8 scores whether an organisation's actions are mapped to these codes bidirectionally.

NIST SP 800-61r3

Published April 2025 as a CSF 2.0 Community Profile. TIR-CMM follows r3, not r2 — and that is a deliberate choice, not a detail.

Following r3 rather than r2 is a differentiator. Revision 3 deliberately abandons the linear four-phase incident lifecycle — prepare, detect, contain, recover — in favour of CSF 2.0 functions. TIR-CMM follows r3, which sets it apart from models still built on the 2012 phase model.

Domain-level crosswalk

The eight TIR-CMM domains, mapped across the frameworks most organisations already report against. Domain codes read: RP Response Preparation & Readiness · RA Response Authority & Decision Rights · RE Response Engineering & Playbooks · CE Containment, Eradication & Recovery · AO Automation & Orchestration · FI Forensics, Evidence & Investigation · RV Response Validation & Exercising · RG Response Governance, Metrics & Improvement.

An em dash indicates the framework has no meaningful counterpart for that domain — which is itself informative: no crosswalk partner covers response authority, and only DORA/NIS2 and SOC-CMM reach validation.
TIR-CMM NIST CSF 2.0 NIST SP 800-61r3 ISO/IEC 27035 RE&CT D3FEND SOC-CMM DORA / NIS2
RP GV, PR.IP, RS.MA Preparation (GV/ID/PR) Plan & prepare RA1000 Model, Harden Process, People ICT continuity, incident mgmt
RA GV.RR, RS.MA Governance & roles Plan & prepare RA1000 Governance Management body accountability
RE RS.AN, RS.MI Response execution Detection & reporting; Response RA2000–RA5000 Isolate, Evict Process, Technology Response & recovery plans
CE RS.MI, RC.RP Containment/eradication/recovery Response; Recovery RA3000–RA5000 Isolate, Evict, Restore Technology ICT continuity, backup
AO RS.MI, DE.AE Response execution Response RA3000 Isolate Technology Operational resilience
FI RS.AN, ID.RA Analysis Assessment & decision RA2000 Technology, Process Evidence, root cause
RV ID.IM, PR.PT Continuous improvement Lessons learned RA6000 Process Testing (TLPT/DORA), NIS2 testing
RG GV, ID.IM, RS.CO Continuous improvement Lessons learned RA6000 Governance, Services Reporting clocks (24h/72h/1m)

Positioning against adjacent models

Where TIR-CMM sits relative to the models it is most often compared with.
Model Relationship
SOC-CMM Assesses the SOC as a function. TIR-CMM assesses whether the organisation can act — including the parts of response that sit outside the SOC: authority, business acceptance, recovery. Complementary.
NIST CSF 2.0 Reporting layer above TIR-CMM. TIR-CMM supplies the evidence CSF Respond and Recover ask for.
TID-CMM Sibling module. Bonded through constraint R4 and the bridge domain.
Gartner CTEM Asks whether exposure is exploitable and observable. TIR-CMM asks whether exploitation can be stopped.
DORA / NIS2 TIR-CMM produces the testing, reporting-clock and continuity evidence these regimes require, without being a compliance model.
VERIS Incident taxonomy; useful as an input to scenario derivation, not a maturity model.

External references

  • MITRE D3FEND — the countermeasure knowledge graph behind the containment primitives.
  • RE&CT — the response action framework, RA1000–RA6000.
  • MITRE ATT&CK — techniques and Mitigations (M-codes) used as the traceability bridge.
  • NIST SP 800-61r3 — Incident Response Recommendations and Considerations for Cybersecurity Risk Management, April 2025.