// Instruments · Self-Assessment

Maturity Lens

Calibrate each threat domain across the six CSF functions — how mature, and how sure — and watch the quadrant charts light up: detection vs response, readiness vs reaction, and a magic quadrant of the whole framework. Load a second baseline and see exactly what improved, and what slid.

🧭
How it works. Open the calibration console and rate each threat domain across the six CSF functions on the CMMI scale, plus a confidence index for each read — 60 signals, and the console tucks itself away once they're all locked in. Charts plot confidence-weighted maturity (level × confidence), so an unverified L4 sits lower than a proven one. Your calibration compresses into a portable MSK3 code: paste any saved code into slot A to reproduce it exactly, add a second in slot B and every chart plots before → after with delta arrows. Hover or focus any marker for exact values; the full table sits under the chart.
A Baseline
B Compare (optional)

Portable baselines

Your 60 calibration signals — level × confidence — compress into one MSK3 code: a snapshot you can save anywhere. Capture one before a security push and one after, load both, and the lens tracks every improvement and regression. Codes carry only levels and confidence: no names, no dates, nothing else.

Explore the Threat Domain Model →

Methodology

  • Calibration. You rate each threat domain (TD00–TD09) directly against the six CSF functions on the CMMI scale — a deliberate expert judgement per domain, independent of the outcome-level CSF matrix. Each rating carries a confidence index (50–100%); charts plot level × confidence, so positions move continuously and uncertainty widens a marker's halo. A domain's axis value is the mean of its weighted levels in that axis's function group; unrated functions count as L0, so unassessed ground honestly drags the score.
  • Magic quadrant. Each CSF function is plotted by coverage (how many domains you've rated it across) against its confidence-weighted maturity where rated — deep-but-narrow and broad-but-shallow programs land in different quadrants.
  • MSK3 codes. One base-36 character per signal encodes level and confidence together — 65 characters that fully reproduce a calibration (older levels-only MSK2 codes still import, read as 100% confidence). Codes carry only levels and confidence, and everything runs in your browser.

The NIST Cybersecurity Framework 2.0 is a U.S. Government work in the public domain. CMMI maturity level names are used descriptively. The threat-domain model, calibration, lenses, and scoring are Messink Academy study aids — not part of, nor endorsed by, NIST or ISACA.

ESC
↑↓ navigate jack in