// Instruments · Self-Assessment
Maturity Lens
Calibrate each threat domain across the six CSF functions — how mature, and how sure — and watch the quadrant charts light up: detection vs response, readiness vs reaction, and a magic quadrant of the whole framework. Load a second baseline and see exactly what improved, and what slid.
MSK3
code: paste any saved code into slot A to reproduce it
exactly, add a second in slot B and every chart plots
before → after with delta
arrows. Hover or focus any marker for exact values; the full
table sits under the chart.
⚙ Domain Calibration
Rate each threat domain across the six CSF functions — and how confident you are in each read. 60 signals on the CMMI scale; the lens charts draw from this calibration, and it locks away once complete.
Portable baselines
Your 60 calibration signals — level × confidence — compress into one MSK3 code: a snapshot you can save anywhere. Capture one before a security push and one after, load both, and the lens tracks every improvement and regression. Codes carry only levels and confidence: no names, no dates, nothing else.
solid = weighted · dashed = claimed
Methodology
- Calibration. You rate each threat domain (TD00–TD09) directly against the six CSF functions on the CMMI scale — a deliberate expert judgement per domain, independent of the outcome-level CSF matrix. Each rating carries a confidence index (50–100%); charts plot level × confidence, so positions move continuously and uncertainty widens a marker's halo. A domain's axis value is the mean of its weighted levels in that axis's function group; unrated functions count as L0, so unassessed ground honestly drags the score.
- Magic quadrant. Each CSF function is plotted by coverage (how many domains you've rated it across) against its confidence-weighted maturity where rated — deep-but-narrow and broad-but-shallow programs land in different quadrants.
- MSK3 codes. One base-36 character per signal encodes level and confidence together — 65 characters that fully reproduce a calibration (older levels-only MSK2 codes still import, read as 100% confidence). Codes carry only levels and confidence, and everything runs in your browser.
The NIST Cybersecurity Framework 2.0 is a U.S. Government work in the public domain. CMMI maturity level names are used descriptively. The threat-domain model, calibration, lenses, and scoring are Messink Academy study aids — not part of, nor endorsed by, NIST or ISACA.