Testing is no longer reactive. Assessments run on a schedule, findings are tracked to closure, and someone owns the process. Coverage is expanding past compliance-defined boundaries, and trend data is beginning to accumulate into institutional knowledge.
Outcomes
- ·Testing runs on a documented schedule, independent of compliance deadlines
- ·The asset inventory has grown past compliance scope, closing known blind spots
- ·Vulnerabilities are tracked from identification to validated closure, not self-attestation
- ·Basic threat modeling begins to inform scope and scenario selection
- ·Year-over-year trend data shows whether the program is improving or regressing
Actions
- 01Set and document a testing cadence, annual at minimum and semi-annual or quarterly preferred, with budget formally assigned
- 02Expand the asset inventory past compliance scope to broader business applications and infrastructure
- 03Record each expansion at review so growth in coverage is visible and traceable
- 04Run remediation through ticketing or project tooling, with owners and target closure dates
- 05Confirm remediation by retesting rather than self-attestation
- 06Hold at least one threat modeling session a year to inform scope
Sustainment Criteria
All criteria must be met to hold this level. If any criterion is unmet at reassessment, consider yourself at the previous level.
Testing runs on its documented schedule, not on external prompting
Inventory coverage extends past compliance scope, with each expansion documented at quarterly review
Every finding has an owner, a priority, and a documented path to closure
Retesting confirms a fix before closure is recorded
At least one threat modeling session a year informs scope decisions
Practitioner note
The most common T2 failure is tracking without closing: the workflow gets built and populated, then the backlog grows. The second is holding T1-level inventory scope while claiming T2. Coverage expansion has to be shown, not just intended.
Moving to T3
Write an offensive security strategy, formally extend scope to cloud and third-party environments, define remediation SLAs, and build security testing into change management.
Corresponding Governance & Accountability level
G2 Responsive
Organizations often develop these axes at different rates. Compare your position on both.
