Root · Service
Security Maturity Assessment
A structured assessment of an organization's security maturity, identifying capability gaps, supporting evidence and prioritized improvement opportunities.
Overview
The Security Maturity Assessment provides a structured, evidence-based view of an organization's security maturity. Where the assessment is delivered, the outputs identify capability gaps, the evidence supporting them, and prioritized improvement opportunities.
What is assessed
The assessment covers the security practices and capabilities that are relevant to the organization's context and risk profile. The scope of each engagement is defined up front, aligned with the domains the organization actually operates — it does not claim to assess an enterprise posture that goes beyond the agreed scope.
Reference models are used where appropriate, such as OWASP SAMM, to ground the assessment in an established framework. The Security Maturity Assessment is a Root service; established models are used as methodological references within it, and Root is not affiliated with, endorsed by, or certified by the reference model organizations.
Assessment approach
The methodology is deliberately pragmatic and evidence-driven:
- Assessment — structured review of relevant security practices and capabilities.
- Evidence — conclusions supported by available documentation, process evidence, technical evidence, or stakeholder input, where appropriate.
- Maturity — identification of the current maturity level of assessed capabilities.
- Gap analysis — identification of differences between the current state and the desired or target state.
- Risk prioritisation — not every maturity gap carries the same business significance.
- Improvement opportunities — findings translated into practical improvement actions.
Evidence
Assessment conclusions are supported wherever possible by documentation, process evidence, technical evidence, or stakeholder input. Where evidence is absent or limited, the assessment records that gap rather than assuming a capability exists.
Maturity
Each assessed capability is positioned by its current maturity level — the operating reality of the practice today, not the intent of a process on paper. The target state is defined with organization's context in mind, and the difference between the two forms the basis of the gap analysis.
Risk prioritisation
Priorities are set by considering, per finding:
- organisational context
- exposure
- impact
- existing controls
- capability gaps
- business priorities
The result is a ranked view of what to address first — based on business significance, not on framework completeness.
Deliverables
Typical assessment outputs include:
- Executive assessment summary
- Security maturity profile
- Capability and control gaps
- Evidence and findings register
- Prioritized improvement opportunities
- Improvement roadmap
Contact
Root is the independent consulting practice of André Ataíde. For an assessment engagement, contact me directly: andre_ataide@proton.me.