Information and cybersecurity maturity models
| Maturity model | Organization/authors | Purpose/target |
|---|---|---|
| Cybersecurity Capability Maturity Model (ES-C2M2) (US Department of Energy, 2014) | The US Department of Energy (DOE) | Assessment of critical infrastructures |
| Open Information Security Management Maturity Model (O-ISM3) (The Open Group, 2017) | The Open Group | Any type of organization |
| National Initiative for Cybersecurity Education – Capability Maturity Model (NICE) (US Department of Homeland Security, 2014) | The US Department of Homeland Security | Workforce planning for cybersecurity |
| Information Security Focus Area Maturity model (ISFAM) (Spruit and Roeling, 2014) | (Spruit and Roeling, 2014) | Any type of organization |
| Maturity model | Organization/authors | Purpose/target |
|---|---|---|
| Cybersecurity Capability Maturity Model (ES-C2M2) ( | The US Department of Energy (DOE) | Assessment of critical infrastructures |
| Open Information Security Management Maturity Model (O-ISM3) ( | The Open Group | Any type of organization |
| National Initiative for Cybersecurity Education – Capability Maturity Model (NICE) ( | The US Department of Homeland Security | Workforce planning for cybersecurity |
| Information Security Focus Area Maturity model (ISFAM) ( | ( | Any type of organization |
Sharing content requires targeting cookies to be enabled. Please update your cookie preferences to use this feature.