Root · Service

Security Maturity Assessment

A structured assessment of an organization's security maturity, identifying capability gaps, supporting evidence and prioritized improvement opportunities.

Overview

The Security Maturity Assessment provides a structured, evidence-based view of an organization's security maturity. Where the assessment is delivered, the outputs identify capability gaps, the evidence supporting them, and prioritized improvement opportunities.

What is assessed

The assessment covers the security practices and capabilities that are relevant to the organization's context and risk profile. The scope of each engagement is defined up front, aligned with the domains the organization actually operates — it does not claim to assess an enterprise posture that goes beyond the agreed scope.

Reference models are used where appropriate, such as OWASP SAMM, to ground the assessment in an established framework. The Security Maturity Assessment is a Root service; established models are used as methodological references within it, and Root is not affiliated with, endorsed by, or certified by the reference model organizations.

Assessment approach

The methodology is deliberately pragmatic and evidence-driven:

  • Assessment — structured review of relevant security practices and capabilities.
  • Evidence — conclusions supported by available documentation, process evidence, technical evidence, or stakeholder input, where appropriate.
  • Maturity — identification of the current maturity level of assessed capabilities.
  • Gap analysis — identification of differences between the current state and the desired or target state.
  • Risk prioritisation — not every maturity gap carries the same business significance.
  • Improvement opportunities — findings translated into practical improvement actions.

Evidence

Assessment conclusions are supported wherever possible by documentation, process evidence, technical evidence, or stakeholder input. Where evidence is absent or limited, the assessment records that gap rather than assuming a capability exists.

Maturity

Each assessed capability is positioned by its current maturity level — the operating reality of the practice today, not the intent of a process on paper. The target state is defined with organization's context in mind, and the difference between the two forms the basis of the gap analysis.

Risk prioritisation

Priorities are set by considering, per finding:

  • organisational context
  • exposure
  • impact
  • existing controls
  • capability gaps
  • business priorities

The result is a ranked view of what to address first — based on business significance, not on framework completeness.

Deliverables

Typical assessment outputs include:

  • Executive assessment summary
  • Security maturity profile
  • Capability and control gaps
  • Evidence and findings register
  • Prioritized improvement opportunities
  • Improvement roadmap

Contact

Root is the independent consulting practice of André Ataíde. For an assessment engagement, contact me directly: andre_ataide@proton.me.