Each tier currently lists controls with descriptions, but lacks practical implementation guidance.
What's needed
For each tier, add:
- Prerequisites -- what an organisation should have in place before starting this tier
- Implementation order -- suggested sequence for adopting controls within the tier
- Success criteria -- how to know when a control is adequately implemented
- Common pitfalls -- mistakes practitioners frequently make at this maturity level
Acceptance criteria
Each tier currently lists controls with descriptions, but lacks practical implementation guidance.
What's needed
For each tier, add:
Acceptance criteria