Why this module exists. Every Indian enterprise we audit has a “maturity assessment” somewhere on file. Few have one that has been refreshed in the last 18 months; fewer still use it to drive funding decisions. The pattern is the same: a one-time scoring exercise that produced a slide, the slide got presented to the board, and then nothing operational changed. This module covers how to make the model actually drive the programme.
The four models that matter for an Indian enterprise
| Model | Scope | When to use |
|---|---|---|
| NIST CSF 2.0 | Whole-of-organisation cyber programme | Annual board-level baseline. Default choice for enterprise CISO. |
| ISO 27001:2022 + Annex A controls | Information security management system | When you need a certifiable management system. |
| SAMM (OWASP) | Software security in product engineering | Product-led companies; AppSec function maturity. |
| CIS Critical Security Controls (v8.1) | Technical control implementation | Mid-market organisations needing a prioritised technical baseline. |
Pick one as your headline framework — the one the board sees, the one the budget is built around. Use the others as reference for specific functions. Running multiple in parallel and reporting separately on each is how the maturity work becomes overhead.
Get a DPDP gap assessment
Free 30-minute call. We map your data flows against DPDP §8 obligations and tell you exactly which gaps to fix first. Auditor-defensible output.