Capability Maturity Model¶
Within ORSM, maturity reflects the quality of architectural decision-making, not the number of controls implemented.
!!! important ORSM maturity is not the same thing as security maturity. An organisation may operate sophisticated security controls while still creating excessive complexity, dependency concentration or poor recoverability.
Level 1 --- Reactive Control Implementation¶
Security is implemented in response to incidents, audit findings or regulatory obligations. Architectural decisions are tactical and recovery capability is poorly understood.
Level 2 --- Governed Security¶
Policies, governance and standards are established and architectural decisions become more consistent, though complexity and sustainability are not yet evaluated systematically.
Level 3 --- Risk-Aligned Architecture¶
Architectural decisions become evidence-based. Protection intent is documented, dependencies are mapped, complexity is measured and recovery is regularly tested.
Level 4 --- Operationally Resilient Architecture¶
Operational resilience becomes an explicit design objective. Complexity budgets are established, architectural quality is actively measured and simplification is continual.
Level 5 --- Adaptive Security Ecosystem¶
Security operates as a continuously improving capability. Measurements inform decisions, complexity is actively reduced and security is recognised as a business enabler.
Applying the model¶
Different parts of an enterprise may legitimately operate at different maturity levels.
The objective is not uniform maturity. The objective is to understand where architectural improvement will deliver the greatest operational benefit.