Applying a CMM
The main idea behind a CMM is to provide a standard mechanism for any organization to perform a self-assessment of their cybersecurity level.
They are being used and implemented by many organizations all around the globe, from top multinational organizations to small businesses, and each can leverage all the advantages associated with the implementation of a CMM.
The goals of a CMM
A CMM is a great tool that allows cybersecurity professionals to achieve the following three goals:
- Determine (by using a standardized mechanism) the level of cybersecurity of a given company.
- Determine, based on company objectives (or regulations), the expected level of cybersecurity (based on a standardized mechanism).
- A clear path to go from point #1 to point #2.
Characteristics of a good CMM
A good CMM needs to have the following characteristics:
- Easy to implement: We don't want the complexity of an International Standards for Organization...