Skip to content

A comprehensive framework and assessment toolkit for measuring and improving Cloud Native security maturity across 8 critical business functions. Includes automated scoring, contextual recommendations, and evidence-based evaluation.

License

Notifications You must be signed in to change notification settings

devsecflow/Cloud-Native-Assurance-Maturity-Model

Folders and files

NameName
Last commit message
Last commit date

Latest commit

 

History

46 Commits
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 

Repository files navigation

Cloud Native Assurance Maturity Model (CNAMM)

License: CC BY-SA 4.0 Website

For the best experience with CNAMM, please visit our interactive website where you can explore the framework, take a quick assessment, and access all resources in a user-friendly interface.

Our Mission

Our mission is to provide organizations with an effective and measurable way to evaluate and enhance their Cloud Native security posture. We aim to enable organizations to confidently design, deploy, and operate secure Cloud Native systems through a self-assessment model that drives continuous improvement.

Overview

The Cloud Native Assurance Maturity Model (CNAMM) is a framework designed to help organizations measure and improve their Cloud Native security and assurance capabilities. This toolkit provides a structured approach to assess your organization's current maturity level and identify areas for improvement.

CNAMM Framework

Interactive Resources

  • Interactive Website: Explore the framework, take the quick assessment, and access all resources
  • Quick Assessment: Get an immediate overview of your Cloud Native security maturity in minutes
  • Sample Assessment: View a completed assessment with scorecard visualization
  • Full Toolkit: Download the comprehensive assessment toolkit

Framework Structure

CNAMM evaluates eight critical business functions, each containing three Practice Areas with two assessment Streams:

Business Functions

  1. Strategy and Risk Governance
  2. Supply Chain and Vendor Security
  3. Infrastructure and Platform Security
  4. Application and Data Protection
  5. Identity and Access Governance
  6. Runtime Security Operations
  7. Threat Detection and Response
  8. Resilience and Service Assurance

Assessment Streams

  • Stream A (Core): Essential capabilities and security controls
  • Stream B (Advanced): Advanced capabilities and innovative practices

Practice Area Heatmap

Scoring System

Raw Scores

  • 1.0: Foundation - Basic security controls and initial processes
  • 1.1-2.0: Standardized - Consistent security practices and documentation
  • 2.1-3.0: Optimized - Efficient processes and automation
  • 3.1-3.5: Leading - Advanced capabilities and proactive security
  • 3.6-4.0: Transformative - Innovative practices and industry leadership

Weighted Scores

Your organization's context affects your target security maturity level through a profile multiplier (0.9-1.2x) based on:

  • Industry Requirements
  • Regulatory Obligations
  • Organizational Scale
  • Cloud Native Maturity

Radar Chart and Bar Graph

Assessment Toolkit Features

Scorecard Overview

  • Overall Maturity Score and Level
  • Assessment Completion Status
  • Business Function Scoring Summary
  • Comprehensive Visualizations

Maturity Distribution

Repository Contents

This repository contains essential tools and documentation for implementing CNAMM:

Getting Started

  1. Visit our interactive website for the most user-friendly experience

  2. Download the Assessment Toolkit

  3. Complete Organization Profile

    • Define your context
    • Understand your target maturity
  4. Conduct Assessment

    • Evaluate each business function
    • Document evidence
    • Review scores and insights
  5. Plan Improvements

    • Identify gaps
    • Prioritize enhancements
    • Track progress

Contributing

We welcome community contributions to improve CNAMM:

Support

For questions or support:

Created By

  • Abdel Sy Fane - CTO of DevSecFlow and Co-Founder and Executive Director of CyberSecurity NonProfit (CSNP)
  • Francis Ofungwu - CEO of DevSecFlow

License

This work is licensed under the Creative Commons Attribution-Share Alike 4.0 License. To view a copy of this license, visit http://creativecommons.org/licenses/by-sa/4.0/legalcode


© 2025 DevSecFlow Community. All Rights Reserved.

About

A comprehensive framework and assessment toolkit for measuring and improving Cloud Native security maturity across 8 critical business functions. Includes automated scoring, contextual recommendations, and evidence-based evaluation.

Resources

License

Stars

Watchers

Forks

Releases

No releases published

Packages

No packages published

Languages