Skip to content

Capability Maturity Model

The ORSM Capability Maturity Model

Within ORSM, maturity reflects the quality of architectural decision-making, not the number of controls implemented.

!!! important ORSM maturity is not the same thing as security maturity. An organisation may operate sophisticated security controls while still creating excessive complexity, dependency concentration or poor recoverability.

Level 1 --- Reactive Control Implementation

Security is implemented in response to incidents, audit findings or regulatory obligations. Architectural decisions are tactical and recovery capability is poorly understood.

Level 2 --- Governed Security

Policies, governance and standards are established and architectural decisions become more consistent, though complexity and sustainability are not yet evaluated systematically.

Level 3 --- Risk-Aligned Architecture

Architectural decisions become evidence-based. Protection intent is documented, dependencies are mapped, complexity is measured and recovery is regularly tested.

Level 4 --- Operationally Resilient Architecture

Operational resilience becomes an explicit design objective. Complexity budgets are established, architectural quality is actively measured and simplification is continual.

Level 5 --- Adaptive Security Ecosystem

Security operates as a continuously improving capability. Measurements inform decisions, complexity is actively reduced and security is recognised as a business enabler.

Applying the model

Different parts of an enterprise may legitimately operate at different maturity levels.

The objective is not uniform maturity. The objective is to understand where architectural improvement will deliver the greatest operational benefit.