TableĀ 6

Comparison of the maturity models

Comparing factorsInformation security awareness maturity models
ISACMUAMMSANSMMISA
Referred StandardISO 27002 (2005)NoneISO 27002, PCI DSS, SOX, GLBA, HIPAA, NERC, NIST 800, ENISANone
FocusIT Stakeholder Groups (IT Staff, Senior Management, End Users)IT UsersAwareness ProgrammeInterested Parties
Dimensions of MaturityImportance, Capability, Risk (Three)Threat and Countermeasure, Prescription and Discretion (Two)(One)Attitude (Approach), Knowledge (Skills and Abilities) (Two)
Number of Maturity Grades7555
Defined Controls, by GradeYesNoneNoneYes
Defined Audit Evidence, by GradeNoneNoneNoneYes
Supports Audit WorkPartlyNonePartlyYes

Source(s): Authors' own work

or Create an Account

Close Modal
Close Modal