TIR-CMM assessment
Import or declare context
TIR-CMM measures whether you can act on what you detect. It therefore starts from your detection assessment rather than repeating it.
Everything here runs in your browser. No data is sent anywhere, stored remotely, or analysed. Progress is kept in this browser's local storage only; use Export progress to keep a copy.
One model, three depths. Each is a strict superset of the one below, so you can start with Pulse and deepen later without rescoring anything.
TIR-CMM constrains response maturity by detection maturity, because you cannot respond to what you never saw. Either route satisfies that — you do not need TID-CMM to use this model.
Paste a tid-cmm/export/1.3 JSON document.
Set automatically by the import; override here if you already know it.
What you run
Select the asset classes present in your environment. Classes you do not run are excluded from the lattice entirely — no penalty, no benefit.
What you must keep running
Your crown jewels, and the asset classes they live on. This sets the criticality tier of every lattice cell, which drives both the weighted coverage score and the roadmap ranking.
A cell hosting a crown jewel is T1 (weight 3). A cell on a modelled path to one is T2 (weight 2). Everything else in scope is T3 (weight 1).
Who targets you, and how fast
Breakout time — foothold to first lateral movement — is the clock your response is racing. Without it, response maturity is a paperwork exercise.
If you have no actor-specific breakout intelligence, use a published industry figure and mark it estimated. An estimated breakout time is usable for L0–L3; it cannot support an L4 claim.
Lattice scoping
Seven attack-path stages by your asset classes. Click a cell to cycle it: not in scope → T3 → T2 → T1. A cell is in scope only if at least one modelled attack path traverses that stage on that asset class.
Set what is in scope, and how critical
Typical working lattice is 24–38 cells. A 56-cell lattice usually means the scoping step was skipped.
Containment options
For each asset class in scope, which graded containment tiers can you actually execute today? This is the reality check behind domain CE.
Authority map
Who is permitted to authorise containment on each asset class, and how long that takes out of hours. This step comes before you score the lattice, deliberately.
Assessors who map authority first score the lattice more honestly, because they have just discovered how many actions require an approval they cannot obtain at 03:00. An action gated behind an approval path with no defined SLA is status 1, not status 2, however good the tooling is.
Lattice status
For each in-scope cell, set the Response Readiness Status. Click to cycle 0 → 1 → 2 → 3.
| Status | Name | Means |
|---|---|---|
| 0 | No option | No means exists to act at this stage on this asset class. You would improvise or watch. |
| 1 | Manual only | Technically possible but ad-hoc, undocumented, person-dependent, or gated behind an approval path with no defined SLA. |
| 2 | Engineered | Documented parameterised playbook, tooling can execute it, owner named, authority defined in advance. Unproven. |
| 3 | Proven | Executed against a real incident or live-fire exercise within the recency window, met its stage time objective, blast radius as designed. |
Containment Lattice
Cells outside scope are inert. Tier-1 and Tier-2 cells at status 0 are flagged as blind cells.
Capability scoring
Fifty-eight sub-capabilities across eight domains, scored 0–5. Tick the evidence box only where you can name a dated artifact — constraint R3 demotes an unevidenced 4 or 5 to 3 automatically.
Tempo & results
Response tempo
Measured against your highest-priority actor. MTTDecide — validated alert to authorised containment decision — is measured separately from MTTR here, because folding it into MTTR is what makes the most common failure in incident response invisible.
Tempo clock
Elapsed time to containment against the adversary's breakout window.
Result
Readiness
The eight domains describe how the capability is built. These three lenses re-cut the same answers against the outcomes leadership actually asks about. They are lenses, not partitions — a sub-capability can serve more than one.
Current state
What is holding you back
Derived from the binding constraints, the band caps, your weakest domains and the gap between engineered and proven coverage.
Improvement blueprint
The same mechanical ranking as the roadmap below, bucketed by what it actually takes to do. Quick fixes need one person and no budget — they are usually the highest-leverage items in the whole model, which is the point.
Domain profile
Self-assessed against constraint-adjusted.
Constraint effect by domain
Where the ceilings bind.
Integrity constraints
Independent effect is what each constraint would cap on its own, evaluated against pre-constraint scores. Marginal effect is what it actually changed given the constraints applied before it. R1 is applied last and usually subsumes the others — without the independent column, R2 and R4 would read as "no effect" in exactly the organisations they were written for.
Containment Lattice
Ranked roadmap
Mechanical. Capability gaps and lattice gaps are each normalised to their own maximum before merging, then sorted. No advocacy, no facilitator bias. The output names capabilities and authorities required, not products.
Twenty questions
The shortest honest read on your response capability. Every domain is represented, weighted towards the things that most often decide the outcome: authority, rehearsal, and whether containment options exist at all.
Pulse is indicative, not defensible. Domain scores are extrapolated from the questions below, and the band is capped at L3 — twenty questions cannot evidence a claim beyond that. The report says so on its face.
Telemetry attributes
Eight attributes per asset class. Collection is only the first of them — evidence that arrives too late, cannot be searched under pressure, or can be deleted by the adversary is not usable evidence.
Scored per asset class rather than per data component. Telemetry health is a property of a platform, not of an individual log type, and scoring 106 data components is the single largest cost in a traditional assessment for very little added signal.
Scenario validation
Questionnaires reveal claims. Scenarios reveal integration. Each traces one business-relevant path from first evidence to trusted recovery, testing people, data, tooling, authority, suppliers and communications together.
An exercise with no recorded times cannot lift a readiness claim. A scenario passes only when every stage is above 1, it was actually exercised, the exercise was timed, and observed recovery met its target.
Pass conditions and the minimum scenario record
Governance
A populated assessment without controlled scope, evidence, decision rights and retesting is a draft, not an assurance result. This is the difference between the two.
Calibration questions
Asked of the assessor, not the assessed. Each is designed to find a score that is true on paper and false in practice.