Four axes, applied without exception.
All four are weighted, and not equally. Strategy and execution carry the most, because a service has to be well-defined and consistently delivered before anything else about it matters.
01
Strategy and objectives
Whether the business requirement was read correctly and turned into a service with a stated mandate and objectives. Then roles and responsibilities, and the operating model that decides what the team does itself and what it makes sense to send outside.
Processes carry the most weight here, then tool selection, because a service is designed before it is bought. Design covers the delivery and operating models, and knowing which parts of the standard guidance, NIST Special Publications among them, are worth adopting and how to adapt them to this environment. Weighted near the top with execution: a service nobody has defined cannot be delivered consistently, and everything measured afterwards inherits that ambiguity.
02
Execution and coverage
What actually gets done, past the processes and the documentation. Tools decide part of it: whether their features match the objectives, and how much of their potential is genuinely used rather than licensed. SOAR belongs here, an enabler across hunting, response and log management, and the mature teams are the ones getting the most from it. Skills decide the rest: a tool is an enabler only in the right hands.
The heaviest of the four. The subject is what the team produced: playbooks, standards, incident documentation, the quality of the lessons learned. Coverage is the other half: effort aimed at what matters, not at what is easy. Retention that cannot support a hunt or an investigation. Offensive testing aimed at Active Directory while the crown jewels go untouched. Hunts that duplicate monitoring instead of the threats nobody is detecting.
03
Integration and improvement
How much the wider defense actually gains from this service. The test is balance. It fails when nobody consumes what it produces: hunting that never reaches incident response, investigations that yield no lessons. It fails just as surely when it over-delivers: logs nobody queries, intelligence nobody reads, tools nobody opens.
Cross-team alignment, responsiveness and automation are what make that balance possible. It shows up in the handovers: detection to response, response to recovery, the SOC to the business. Much of what looks like a detection failure turns out to be a handover nobody owned. Weighted lower, deliberately, and not because it matters less in a mature program: it is a lagging indicator, meaningful only once strategy and execution exist.
04
Metrics and feedback
If you cannot measure a service you cannot improve it. So the question is what gets measured, who reads it, and whether any of it changes a decision. A count of closed alerts says nothing about whether the right ones were closed. A metric nobody acts on is reporting rather than feedback.
Metrics have to be relevant and insightful enough to show patterns and trends, and they belong at every step of the value delivery chain, covering tools, processes and people. Weighted lowest of the four because good metrics tend to follow from good design, so their contribution to the overall picture is more limited than the other three dimensions.
Every service is scored on all four axes, forty judgments in total, and those roll up into the two lines below. Maturity is where the service is today. Capability is what it could reach with the people, process and tooling already in place, without buying anything.