Navigate / EASA
GM1 IS.D.OR.260(a) Continuous improvement

ED Decision 2023/009/R

(a) As general guidance, the elements of the ISMS that should be monitored, measured and evaluated should be, as a minimum:

(1) the risk assessment and treatment process (including risks at the interfaces with other organisations);

(2) the management of non-conformities and corrective actions;

(3) the incident and vulnerability management;

(4) the personnel competence management.

(b) Existing maturity models for ISMS maturity evaluation

As general guidance, for the definition or the adoption of a maturity model (MM), the following existing models may be considered:

— Cybersecurity Capability Maturity Model (C2M2), version 1.1: this model was published by the US Department of Energy in 2014. It introduces the notion of Maturity Indicator Levels (MIL) ranging from 0 to 3 and addresses not only performance levels but also performance practices (under Approach Objectives and approach progression) as well as assurance practices (under Management Objectives and institutionalization progression).

— Systems Security Engineering – Capability Maturity Model (SSE-CMM): published by ISO as ISO 21827 in 2008. It focuses on engineering practices, much less on operational practices that are split in 11 ‘Security Base Practices’, and 11 ‘Project and Organizational Base Practices’. It introduces the notion of five Capability Levels, from ‘Performed Informally’ to ‘Continuously Improving’.

— NIST Cybersecurity Framework (NIST CSF), version 1.1: published by NIST in April 2018. Although it is not proposed as a MM, the framework defines four ‘Implementation Tiers’, from ‘Partial’ to ‘Adaptive’, which are a qualitative measure of organisational cybersecurity risk management practices. It focuses on the functionality and repeatability of cybersecurity risk management.

— ATM Cybersecurity Maturity Model, edition 1: published in February 2019 by the EUROCONTROL NM for organisations in the ATM domain. Whilst not being designed for wider application, it can be adapted as necessary. It defines five maturity levels, ranging from ‘Non-existent’ to ‘Adaptive’ inspired by the ‘Tier’ terminology from the NIST CSF. In fact, the model is founded on NIST CSF, together with some elements of ISO/IEC 27001.

The following Table 1 maps the MM mentioned above to a hypothetical five-level MM.



Table 1: Mapping matrix of an existing MM to a hypothetical five-level MM

Mapping to a five-level MM

C2M2

Eurocontrol NM

ISO 21827

NIST CSF 1.1

Initial

MIL 0

Non-Existent

Performed Informally


Defined

MIL 1 (Initial)

Partial

Planned & Tracked

Partial

Implemented

MIL 2 (Identified)

Defined

Well defined

Risk-Informed

Managed

MIL 3 (Managed)

Assured

Quantitatively Controlled

Repeatable

Improved


Adaptive

Continuously Improving

Adaptive



No specific maturity level is required. However, if and when compliance is achieved, organisations will determine which requirements of which models have already been met (mandatory) and can opt to reach a level that is beneficial to the organisation (voluntary). In the longer term, achieving higher maturity levels may increase the confidence of oversight authorities, which can have an impact upon the level of oversight activities regarding such organisation.