
Critical Infrastructure Maturity Model (CIMM)
Status:
PUBLISHED
As of:
April 2020
Region(s):
USA
Body:
DEPARTMENT OF ENERGY (DOE)
Applicable to:
Critical Infrastructure, General, Government Facilities
Summary:
The Critical Infrastructure Maturity Model (CIMM) is a framework used to assess and improve the resilience and security of critical infrastructure systems to include the following levels of maturity. Initial: Processes are ad-hoc and reactive. There is little to no documentation or standardized practices. Developing: Some processes are defined, but they are not consistently applied. Awareness of risks is growing. Defined: Processes are documented and standardized. Risk management practices are implemented. Managed: Performance is monitored and measured. Continuous improvement is emphasized. Optimizing: Best practices are regularly updated, and the organization proactively adapts to emerging threats. Core Areas of Focus include Risk Assessment, Incident Response, Resilience Planning and Collaboration. The implementation steps of CIMM include Assessment, Goal Setting, Action Plan, Training and Awareness and Review and Adaptation.