Assessments / Threat-Informed Defense Maturity Assessment
Threat-Informed Defense Maturity Assessment
12 questions across Cyber Threat Intelligence, Defensive Measures, and Test & Evaluation — weighted 35 / 40 / 25, the same shape MITRE's own INFORM framework uses. Answer one at a time — step back whenever you want to change an earlier answer. Nothing is uploaded.
You maintain a current, named list of ATT&CK techniques prioritized for your actual threat model — not a generic industry top-techniques list.
// About this tool
Threat-Informed Defense Maturity Assessment
Threat-Informed Defense (TID) is the practice of building detections and mitigations from real adversary tradecraft — MITRE ATT&CK techniques — instead of generic best practice or compliance checklists. MITRE's own Center for Threat-Informed Defense (CTID) formalizes this into three dimensions: Cyber Threat Intelligence, Defensive Measures, and Test & Evaluation, published as a full maturity model called INFORM (the successor to their earlier M3TID model).
This tool borrows INFORM's three-dimension structure and its weighting shape — Defensive Measures weighted highest (40%), then Cyber Threat Intelligence (35%), then Test & Evaluation (25%) — because that's the order CTID's own research says matters. Twelve questions, four per dimension, answered Yes / Partial / No, roll up into a weighted 0-100 score and a maturity tier.
This is an informal practitioner self-check inspired by publicly described CTID material — it is not MITRE's INFORM assessment, not affiliated with MITRE or CTID, and not a substitute for running the real assessment at ctid.mitre.org/inform. Everything runs in your browser; nothing is uploaded or stored.
// When to use it
Sanity-check a TID initiative before you pitch it
Run the assessment before writing a threat-informed defense roadmap, so the pitch targets your program's actual weakest dimension instead of a guess.
Find out if you're chasing coverage instead of resilience
A high Defensive Measures score built on brittle, easily-evaded detections still fails Test & Evaluation. The per-dimension breakdown shows exactly where that gap is.
Justify investment in purple-teaming or CTI headcount
A low Test & Evaluation or Cyber Threat Intelligence score, next to a strong Defensive Measures score, is a concrete case for where the next hire or budget line should go.
// Questions
Is this MITRE's official INFORM assessment?
No. It's an informal self-check inspired by publicly described CTID material, built for a quick gut-check — not a substitute for MITRE's own INFORM assessment at ctid.mitre.org/inform, and not affiliated with MITRE or the Center for Threat-Informed Defense.
Why are the three dimensions weighted 35/40/25 instead of evenly?
That weighting mirrors the shape MITRE's own INFORM framework uses: Defensive Measures counts for the most because taking defensive action is the point, Cyber Threat Intelligence next because it drives what gets defended, and Test & Evaluation last — not because it matters least, but because it validates the other two rather than standing alone.
Why only 12 questions when INFORM has 22 components?
This is a condensed practitioner gut-check, not a replacement for INFORM's full assessment. Four questions per dimension is enough to tell you which of the three is weakest — if the result says you're weak in, say, Test & Evaluation, that's your cue to go run the real INFORM assessment for the detailed breakdown, not to treat this score as the final word.
What if I don't have a dedicated purple team?
Score Test & Evaluation honestly rather than generously. Occasional manual testing against a known technique — even without a formal purple-team function — is a fair 'Partial.' The point of a low score there isn't to shame you, it's to show that Test & Evaluation is where your program's investment should go next.
// Related tools