⛏️ Get Splunky!
Lv.1Intern
0 XP
0
Home Map Stats Drill Board Log In
Back to Floor
Metrics Hall • Room 3

Security Program Maturity Models

The architect uses maturity models to benchmark and plan security program growth. The SOC Capability Maturity Model (CMM) ranges from Level 1 (ad-hoc, reactive) to Level 5 (optimized, predictive). Most enterprise SOCs target Level 3 (defined, consistent processes) as a stable foundation.

Splunk's Security Operations Maturity Model (SOMM) is a Splunk-specific framework assessing maturity across data, analytics, automation, and content dimensions. The architect uses assessment results to build a multi-year roadmap: Year 1 — data normalization and baseline detections; Year 2 — automation and SOAR integration; Year 3 — predictive analytics and ML-driven anomaly detection.

Knowledge Check

Prove your understanding to clear the room (Rewards XP)
❤️❤️❤️
Question 1 of 1
At CMM Level 1, how are security incidents typically handled?
AVia fully automated playbooks with no human intervention
BAd-hoc and reactively — there are no defined processes, and response depends on individual heroics
CThrough a structured, documented IR process followed consistently
DVia predictive ML models that prevent incidents before they occur