TIR-CMM assessment

Import or declare context

TIR-CMM measures whether you can act on what you detect. It therefore starts from your detection assessment rather than repeating it.

Everything here runs in your browser. No data is sent anywhere, stored remotely, or analysed. Progress is kept in this browser's local storage only; use Export progress to keep a copy.

How deep are you going?

One model, three depths. Each is a strict superset of the one below, so you can start with Pulse and deepen later without rescoring anything.

How are you running this?

TIR-CMM constrains response maturity by detection maturity, because you cannot respond to what you never saw. Either route satisfies that — you do not need TID-CMM to use this model.


What you run

Select the asset classes present in your environment. Classes you do not run are excluded from the lattice entirely — no penalty, no benefit.

What you must keep running

Your crown jewels, and the asset classes they live on. This sets the criticality tier of every lattice cell, which drives both the weighted coverage score and the roadmap ranking.

A cell hosting a crown jewel is T1 (weight 3). A cell on a modelled path to one is T2 (weight 2). Everything else in scope is T3 (weight 1).

Who targets you, and how fast

Breakout time — foothold to first lateral movement — is the clock your response is racing. Without it, response maturity is a paperwork exercise.

If you have no actor-specific breakout intelligence, use a published industry figure and mark it estimated. An estimated breakout time is usable for L0–L3; it cannot support an L4 claim.

Lattice scoping

Seven attack-path stages by your asset classes. Click a cell to cycle it: not in scope → T3 → T2 → T1. A cell is in scope only if at least one modelled attack path traverses that stage on that asset class.

Set what is in scope, and how critical

Typical working lattice is 24–38 cells. A 56-cell lattice usually means the scoping step was skipped.

Containment options

For each asset class in scope, which graded containment tiers can you actually execute today? This is the reality check behind domain CE.

Authority map

Who is permitted to authorise containment on each asset class, and how long that takes out of hours. This step comes before you score the lattice, deliberately.

Assessors who map authority first score the lattice more honestly, because they have just discovered how many actions require an approval they cannot obtain at 03:00. An action gated behind an approval path with no defined SLA is status 1, not status 2, however good the tooling is.

Lattice status

For each in-scope cell, set the Response Readiness Status. Click to cycle 0 → 1 → 2 → 3.

Status 3 expires after twelve months, and on tooling change, on-call model change, response reorganisation, owner departure, material architecture change, or a change of managed provider.
StatusNameMeans
0No optionNo means exists to act at this stage on this asset class. You would improvise or watch.
1Manual onlyTechnically possible but ad-hoc, undocumented, person-dependent, or gated behind an approval path with no defined SLA.
2EngineeredDocumented parameterised playbook, tooling can execute it, owner named, authority defined in advance. Unproven.
3ProvenExecuted against a real incident or live-fire exercise within the recency window, met its stage time objective, blast radius as designed.

Containment Lattice

Cells outside scope are inert. Tier-1 and Tier-2 cells at status 0 are flagged as blind cells.

Capability scoring

Fifty-eight sub-capabilities across eight domains, scored 0–5. Tick the evidence box only where you can name a dated artifact — constraint R3 demotes an unevidenced 4 or 5 to 3 automatically.

Tempo & results

Response tempo

Measured against your highest-priority actor. MTTDecide — validated alert to authorised containment decision — is measured separately from MTTR here, because folding it into MTTR is what makes the most common failure in incident response invisible.

Tempo clock

Elapsed time to containment against the adversary's breakout window.


Result

Readiness

The eight domains describe how the capability is built. These three lenses re-cut the same answers against the outcomes leadership actually asks about. They are lenses, not partitions — a sub-capability can serve more than one.

Current state

What is holding you back

Derived from the binding constraints, the band caps, your weakest domains and the gap between engineered and proven coverage.

Improvement blueprint

The same mechanical ranking as the roadmap below, bucketed by what it actually takes to do. Quick fixes need one person and no budget — they are usually the highest-leverage items in the whole model, which is the point.

Domain profile

Self-assessed against constraint-adjusted.

Constraint effect by domain

Where the ceilings bind.

Integrity constraints

Independent effect is what each constraint would cap on its own, evaluated against pre-constraint scores. Marginal effect is what it actually changed given the constraints applied before it. R1 is applied last and usually subsumes the others — without the independent column, R2 and R4 would read as "no effect" in exactly the organisations they were written for.

Containment Lattice

Ranked roadmap

Mechanical. Capability gaps and lattice gaps are each normalised to their own maximum before merging, then sorted. No advocacy, no facilitator bias. The output names capabilities and authorities required, not products.

Twenty questions

The shortest honest read on your response capability. Every domain is represented, weighted towards the things that most often decide the outcome: authority, rehearsal, and whether containment options exist at all.

Pulse is indicative, not defensible. Domain scores are extrapolated from the questions below, and the band is capped at L3 — twenty questions cannot evidence a claim beyond that. The report says so on its face.

Telemetry attributes

Eight attributes per asset class. Collection is only the first of them — evidence that arrives too late, cannot be searched under pressure, or can be deleted by the adversary is not usable evidence.

Scored per asset class rather than per data component. Telemetry health is a property of a platform, not of an individual log type, and scoring 106 data components is the single largest cost in a traditional assessment for very little added signal.

Scenario validation

Questionnaires reveal claims. Scenarios reveal integration. Each traces one business-relevant path from first evidence to trusted recovery, testing people, data, tooling, authority, suppliers and communications together.

An exercise with no recorded times cannot lift a readiness claim. A scenario passes only when every stage is above 1, it was actually exercised, the exercise was timed, and observed recovery met its target.

Pass conditions and the minimum scenario record

Governance

A populated assessment without controlled scope, evidence, decision rights and retesting is a draft, not an assurance result. This is the difference between the two.

Calibration questions

Asked of the assessor, not the assessed. Each is designed to find a score that is true on paper and false in practice.

Decision rights, RACI, anti-gaming rules and publication cautions