Glossary · v0.2
Glossary
Every term TIR-CMM uses, defined so that each definition stands on its own. TIR-CMM is the Threat-Informed Response Capability Maturity Model, and the vocabulary below is the one its assessments, reports and machine-readable exports use.
Definitions follow the machine-readable model that the assessment tool reads, so a term on this page means exactly what it means in an assessment, a report or an export. Terms are listed alphabetically.
| Term | Definition |
|---|---|
| Asset class | An asset class is one of the eight kinds of system that form the columns of the TIR-CMM Containment Lattice: identity and access infrastructure, endpoint and user compute, server and datacentre workload, cloud control plane and SaaS, network and edge, application, source and CI/CD, data stores and backup, and OT, ICS, IoT and specialist systems. Asset classes group systems by the containment primitives available on them — an identity platform is contained by revoking sessions and breaking trust, an endpoint by network isolation and reimaging. An asset class not present in the environment is excluded from the lattice entirely. |
| Assurance tier | The Assurance tier is the deepest of the three TIR-CMM assessment tiers, taking two to four weeks and carrying no band ceiling. Assurance covers everything in the Baseline tier plus telemetry attributes per asset class, exercised scenarios with observed timings, the evidence register and the governance layer of decision rights, independent calibration and second review. The Assurance tier is a facilitated engagement with evidence-led interviews rather than self-scoring, and it is the only tier that can support a band L5 result. |
| Attack-path stage | An attack-path stage is one of the eight phases of an intrusion that form the rows of the TIR-CMM Containment Lattice: Prevent & Harden, Initial Access & Foothold, Execution & Persistence, Privilege Escalation & Credential Access, Discovery & Lateral Movement, Collection & Staging, Command & Control and Exfiltration, and Impact & Objective. The eight stages collapse MITRE ATT&CK tactics into the boundaries at which a different response decision becomes available. Each stage carries a stage leverage weight, because containing early is worth more than containing late. |
| Authority ceiling | The authority ceiling is TIR-CMM integrity constraint R2, which caps the automation and orchestration domain and the containment domain at the response authority score plus one. The authority ceiling exists because automation you are not permitted to fire is a demonstration, not a capability. An organisation with excellent containment tooling and no pre-authorisation to use it will see both domains capped regardless of the tooling. |
| Baseline tier | The Baseline tier is the middle of the three TIR-CMM assessment tiers, taking one to two hours and capping the band at L4. Baseline covers all 58 sub-capabilities with evidence levels, the Containment Lattice scoped to the organisation's crown jewels, the authority map and response tempo. The Baseline tier is self-service and defensible enough to take to a leadership team, and it is the tier most internal assessments should run. |
| Blind cell | A blind cell is a Containment Lattice cell scored at status 0 — no response option exists at all — that sits at criticality tier T1 or T2, meaning it is a crown jewel or lies on a modelled attack path to one. A blind cell identifies a point in an intrusion where the organisation would improvise or watch rather than act. Blind cells are reported as a count beside the Validated Response Score, and a blind cell at tier T1 caps the whole assessment at band L2. |
| Blind-cell gate | The blind-cell gate is TIR-CMM integrity constraint R6, which caps the maturity band at L2 where any tier-1 Containment Lattice cell is scored at status 0. The blind-cell gate exists because an organisation with no response option at all at some stage on a crown jewel is not threat-informed, whatever the rest of the assessment says. The gate is applied mechanically and cannot be argued away by strength elsewhere. |
| Breakout time | Breakout time is the interval between an adversary establishing an initial foothold and moving laterally to a second system, and it is the clock every response capability is racing against. TIR-CMM takes breakout time per priority actor from threat intelligence, or from published industry figures with an explicit estimated flag where actor-specific intelligence is unavailable. Breakout time is the baseline of the Containment Margin and the denominator of the Tempo Ratio, and a band L4 claim is never permitted on estimated breakout time. |
| Containment Lattice | The Containment Lattice is the atomic scoring unit of TIR-CMM: a grid of eight attack-path stages crossed with eight asset classes, in which each in-scope cell is scored 0 to 3 for response readiness. The full lattice is 64 cells and is deliberately never the working set, because a cell is in scope only where the asset class exists in the environment and a modelled attack path traverses that stage on it — a typical scoped lattice is 24 to 38 cells. The Containment Lattice exists because response varies by where on the attack path you are and what kind of asset you are acting on, not by which ATT&CK technique the adversary used. |
| Containment Margin | Containment Margin is the headline tempo metric of TIR-CMM: breakout time minus the sum of mean time to detect, mean time to decide and mean time to contain, expressed in signed minutes per priority actor. A positive Containment Margin means containment lands before the adversary spreads. A negative Containment Margin means the organisation is containing a spread intrusion rather than a foothold, however good its detection coverage looks. Containment Margin is the metric unique to response, because detection maturity is a coverage problem and response maturity is a race. |
| Criticality tier | A criticality tier is the weight a Containment Lattice cell inherits from the crown-jewel mapping, on a three-point scale. Tier T1 carries a weight of 3 and means the cell is a crown jewel or directly hosts one. Tier T2 carries a weight of 2 and means the cell lies on a modelled attack path to a crown jewel. Tier T3 carries a weight of 1 and means the cell is in scope but peripheral to crown-jewel paths. Criticality tiers are what make the reported Validated Response Score reflect readiness where it matters rather than readiness on average. |
| Crown jewel | A crown jewel is a system, dataset or service whose loss, corruption or exposure the organisation cannot absorb, agreed and owned by the business rather than declared by the security team. Crown jewels drive the scoping of the Containment Lattice, set the criticality tier of each cell, and determine which findings rank highest in the TIR-CMM roadmap. An organisation with no agreed crown-jewel list cannot scope a threat-informed response assessment, which is why TIR-CMM asks about crown jewels before it asks about capability. |
| Detection dependency | Detection dependency is TIR-CMM integrity constraint R4, which caps the response engineering, containment and forensics domains at the detection maturity score plus one. Detection dependency exists because you cannot respond to what you never saw. The detection input comes from a TID-CMM export where one exists, or from five short standalone questions where it does not, and supplying no detection input at all caps the overall band at L3. |
| Domain | A domain is one of the eight capability areas TIR-CMM scores: response preparation and readiness, response authority and decision rights, response engineering and playbooks, containment, eradication and recovery, automation and orchestration, forensics, evidence and investigation, response validation and exercising, and response governance, metrics and improvement. Each domain carries a weight in the overall score, and response engineering is the largest at 16 per cent. Validation is the ceiling-setting domain, because every other domain is capped at the validation score plus one. |
| Engineered rate | The engineered rate is the proportion of in-scope Containment Lattice cells scored at status 2 or above, meaning a documented, tooled, owned and pre-authorised response action exists. The engineered rate answers the claim we believe we can act here. TIR-CMM reports the engineered rate beside the proven rate and refuses to average them, because the gap between the two is usually the most important finding an assessment produces. |
| Evidence cap | The evidence cap is TIR-CMM integrity constraint R3, which caps every sub-capability score at the strength of the evidence supporting it: an assertion caps at 1, a design or policy document at 2, an implemented and tested control at 4, and only repeatable validation permits 5. The evidence cap is a ceiling rather than a conversion — strong evidence permits a high score, it does not create one. Raising an evidence level in order to lift a cap is explicitly listed among the anti-gaming rules, because the cap is itself the finding. |
| Evidence level | An evidence level is the grade of proof attached to a TIR-CMM sub-capability score, on a four-point scale from VC0 to VC3. VC0 is assertion only and caps the score at 1. VC1 is design or policy — a document, screenshot or partial implementation — and caps at 2. VC2 is implemented and tested, requiring implementation evidence plus a test result, ticket or system record, and caps at 4. VC3 is repeatably validated, requiring recent, repeatable, independently reviewable proof from the live environment, and permits 5. A blank evidence level is treated as VC0. |
| Integrity constraint | An integrity constraint is one of the seven rules TIR-CMM applies mechanically at scoring time to cap a result where a claim is not safe to make. The seven constraints are the rehearsal ceiling (R1), the authority ceiling (R2), the evidence cap (R3), detection dependency (R4), the tempo ceiling (R5), the blind-cell gate (R6) and the assessment depth and governance ceiling (R7). Integrity constraints can only ever lower a score, never raise one, and they are not negotiable within an assessment. |
| Lattice cell | A lattice cell is a single intersection of one attack-path stage and one asset class in the TIR-CMM Containment Lattice — for example, privilege escalation on identity infrastructure. Each in-scope lattice cell carries a Response Readiness Status from 0 to 3 and a criticality tier from T1 to T3. A cell outside scope is marked not applicable and excluded from both the numerator and the denominator, with no penalty and no benefit. |
| Maturity band | A maturity band is the headline TIR-CMM result, on a six-point scale from L0 to L5. L0 Improvised means response is individual heroics. L1 Documented means plans exist on paper but have never met a clock. L2 Repeatable means playbooks and tooling are consistently executed but unproven under time pressure, and it is the most common band. L3 Threat-informed means response traces to modelled attack paths and containment is pre-authorised, and it is the realistic target for most organisations. L4 Validated means containment is demonstrably inside the breakout window. L5 Adaptive means response regenerates as the threat model changes. |
| MTTC | MTTC is mean time to contain: the average elapsed time from an authorised containment decision to the containment action taking effect. MTTC is one of the three intervals TIR-CMM sums to calculate Containment Margin and Tempo Ratio. In most organisations MTTC is the smallest of the three intervals, which is why measuring it alone gives a flattering and misleading picture of response speed. |
| MTTD | MTTD is mean time to detect: the average elapsed time from an adversary action occurring to an alert being validated as a real incident. MTTD is imported from detection tooling or from a TID-CMM assessment rather than measured by TIR-CMM itself, and it is the first of the three intervals in the Containment Margin calculation. TIR-CMM consumes MTTD as an input because it contains no detection domain of its own. |
| MTTDecide | MTTDecide is mean time to decide: the average elapsed time from a validated alert to an authorised containment decision. MTTDecide is the metric TIR-CMM contributes, because every maturity model in circulation folds decision latency into MTTR, where it becomes invisible. Measuring MTTDecide separately exposes the most common and most fixable failure in incident response — the organisation is not slow at containing, it is slow at being allowed to contain — and organisations that measure it routinely find it exceeds MTTC by an order of magnitude. |
| MTTR | MTTR is mean time to respond or resolve, the aggregate interval most organisations report as their headline response metric. TIR-CMM treats MTTR as insufficient on its own, because it conceals the split between detection, decision and execution, and therefore conceals which of the three is the binding constraint. TIR-CMM requires MTTD, MTTDecide and MTTC to be reported separately, and measures decision latency against breakout time rather than against a service level target. |
| Prevent stage | The Prevent stage, formally Prevent & Harden, is stage S0 of the TIR-CMM Containment Lattice and carries the highest stage leverage in the model at 1.6. The Prevent stage asks whether architecture can stop an attack, or materially slow it, before response is needed at all. Prevent was added to the lattice in version 0.2 ahead of initial access, because prevention buys the one thing response cannot manufacture, which is time. |
| Proven rate | The proven rate is the proportion of in-scope Containment Lattice cells scored at status 3, meaning the response action has been executed against a real incident or a live-fire exercise within the recency window, met its stage time objective, and produced the blast radius it was designed to produce. The proven rate answers the claim we have shown we can act here. The proven rate is normally far lower than the engineered rate, and TIR-CMM is built to make that gap unavoidable rather than to flatter it. |
| Pulse tier | The Pulse tier is the shortest of the three TIR-CMM assessment tiers, taking twenty minutes and capping the band at L3. Pulse asks twenty questions with no Containment Lattice, no ATT&CK scoping and no evidence review, and produces a band, the three things holding the organisation back, and a quick-fix list. The Pulse tier is indicative rather than defensible, and the report it generates says so. |
| Readiness lens | A readiness lens is a re-cut of the same 58 TIR-CMM sub-capabilities against a question leadership actually asks, of which there are three. Readiness to respond asks whether the organisation could act in time if the attack started now. Readiness to recover asks whether it could get the business back, clean, and prove it. Operational resilience asks whether it could keep running through the incident and be harder to hit next time. Each lens reports what the organisation claims and what it can prove, side by side. |
| Recency window | The recency window is the period within which proof of a response action remains valid, set at twelve months in TIR-CMM. A Containment Lattice cell reverts from proven to engineered once the recency window expires, and also on any change of the tooling that executes the action, any change to the on-call or escalation model, any reorganisation or departure of the named owner, any material architecture change affecting that asset class, and any change of managed provider or retainer. The recency window is shorter than TID-CMM's eighteen months because response capability rests on people and authority, which change faster than detection logic. |
| Rehearsal ceiling | The rehearsal ceiling is TIR-CMM integrity constraint R1, which caps every domain other than validation at the validation score plus one. The rehearsal ceiling exists because an unrehearsed playbook is an assumed capability, not a demonstrated one. The rehearsal ceiling makes validation the ceiling-setting domain of the whole model: an organisation that never exercises cannot score well anywhere, regardless of how much it has built. |
| Response Readiness Status | Response Readiness Status, or RRS, is the 0 to 3 score assigned to each in-scope Containment Lattice cell. Status 0, no option, means no means exists to act at that stage on that asset class. Status 1, manual only, means the action is technically possible but ad-hoc, undocumented, person-dependent, or gated behind an approval path with no defined service level. Status 2, engineered, means a documented, parameterised playbook exists with tooling, a named owner and pre-defined authority, but is unproven. Status 3, proven, means it has been executed for real or in live fire within the recency window, met its time objective, and produced the intended blast radius. |
| Stage leverage | Stage leverage is the weight TIR-CMM assigns to each attack-path stage in prioritisation, reflecting that containing early is worth more than containing late. Prevent & Harden carries 1.6, initial access 1.5, execution and persistence 1.4, privilege escalation 1.3, lateral movement 1.2, collection and command-and-control 1.0 each, and impact 0.8. Impact is weighted lowest not because impact response is unimportant, but because by that stage the model is measuring damage limitation rather than defence — an organisation whose entire capability sits at the impact stage is running disaster recovery and calling it incident response. |
| Sub-capability | A sub-capability is one of the 58 individually scored elements of the TIR-CMM model, grouped into eight domains and each carrying a weight within its domain. Every sub-capability has a level 3 anchor describing what good looks like, an expected evidence type, and a concrete action with an effort tier and the role that must perform it. Sub-capabilities are scored 0 to 5 and are subject to the evidence cap, which is why a well-documented but unproven capability cannot score above 2. |
| Telemetry attribute | A telemetry attribute is one of the eight qualities TIR-CMM assesses per asset class in the Assurance tier: collection, completeness, timeliness, integrity and normalisation, retention, queryability, health monitoring and access protection. Telemetry attributes ask not whether evidence exists but whether a responder could actually use it under pressure — whether it arrives fast enough to act on inside the breakout window, survives longer than median dwell time, and would be missed if it stopped. Telemetry attributes are the bridge between detection coverage and investigative capability. |
| Tempo ceiling | The tempo ceiling is TIR-CMM integrity constraint R5, which caps the maturity band by Tempo Ratio: a ratio of 2.0 or above caps at L1, a ratio of 1.0 or above caps at L2, and supplying no tempo evidence at all caps at L3. The tempo ceiling exists because a response capability structurally slower than the adversary is not a level 3 capability, whatever the documentation says. The tempo ceiling is the constraint that makes TIR-CMM a measurement of speed rather than of paperwork. |
| Tempo Ratio | Tempo Ratio is the sum of mean time to detect, mean time to decide and mean time to contain, divided by the breakout time of a priority actor. A Tempo Ratio below 0.5 means containment lands well inside the breakout window and represents a genuine tempo advantage. Between 0.5 and 1.0 the organisation contains before spread with little margin. Between 1.0 and 2.0 it is structurally behind and containing a spread intrusion rather than a foothold. At 2.0 and above it is performing post-incident recovery and calling it response. |
| TID-CMM | TID-CMM is the Threat-Informed Detection Capability Maturity Model, the companion model to TIR-CMM, published at tid-cmm.com. TID-CMM measures threat visibility and detection engineering and answers the question would we see it?, producing a Validated Coverage Score that exposes the gap between detection claimed and detection proven. TID-CMM measures the engineering pillar of UTIOM, while TIR-CMM measures the operations pillar. TID-CMM is not required in order to run a TIR-CMM assessment. |
| TIR-CMM | TIR-CMM is the Threat-Informed Response Capability Maturity Model, a free maturity model that measures whether an organisation can act on the attacks it detects. TIR-CMM scores eight domains and 58 sub-capabilities, scores a Containment Lattice of eight attack-path stages crossed with eight asset classes, and applies seven integrity constraints that can only lower a result. TIR-CMM produces a maturity band from L0 to L5, a Validated Response Score, a Containment Margin against adversary breakout time, and a ranked roadmap. TIR-CMM is the response module of UTIOM and the companion to TID-CMM, and it is free to use, including commercially. |
| UTIOM | UTIOM is the Unified Threat-Informed Operations Model, the parent operating model of TIR-CMM, published at utiom.de. UTIOM organises security operations into three pillars — leadership and governance, engineering and enablement, and operations and analysis — and supplies the vision, strategy, crown jewels and unified improvement roadmap that its capability maturity modules feed. TID-CMM measures the engineering pillar of UTIOM and TIR-CMM measures the operations pillar. |
| Validated Response Score | The Validated Response Score, or VRS, is the proportion of achievable response readiness actually demonstrated across the in-scope Containment Lattice, weighted by the criticality tier of each cell. VRS is the direct response analogue of TID-CMM's Validated Coverage Score, and it is reported alongside the engineered rate, the proven rate and the count of blind cells. The Validated Response Score answers how much of the containment surface that matters is genuinely covered, rather than how much of it has been written down. |
TIR-CMM is published under CC BY-ND 4.0 and the machine-readable model under CC BY 4.0, so these definitions may be quoted and built against with attribution. The full terms are on the licence page.
The eight domains and 58 sub-capabilities → · The Containment Lattice → · Scoring and constraints →