{"id":66470,"url":"https://github.com/keithmccammon/cybersecurity-models","name":"cybersecurity-models","description":"A collection of models for organizing, prioritizing, and understanding cybersecurity and information risk management concepts.","projects_count":34,"last_synced_at":"2026-09-03T14:00:43.630Z","repository":{"id":253456128,"uuid":"838962117","full_name":"keithmccammon/cybersecurity-models","owner":"keithmccammon","description":"A collection of models for organizing, prioritizing, and understanding cybersecurity and information risk management concepts.","archived":false,"fork":false,"pushed_at":"2026-07-09T00:23:57.000Z","size":27,"stargazers_count":27,"open_issues_count":0,"forks_count":3,"subscribers_count":3,"default_branch":"main","last_synced_at":"2026-07-26T11:04:26.468Z","etag":null,"topics":["awesome-list","cybersecurity","maturity-models","risk-management"],"latest_commit_sha":null,"homepage":"https://kwm.me/posts/cybersecurity-models/","language":null,"has_issues":true,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":null,"license":null,"status":null,"scm":"git","pull_requests_enabled":true,"icon_url":"https://github.com/keithmccammon.png","metadata":{"files":{"readme":"README.md","changelog":null,"contributing":null,"funding":null,"license":null,"code_of_conduct":null,"threat_model":null,"audit":null,"citation":null,"codeowners":null,"security":null,"support":null,"governance":null,"roadmap":null,"authors":null,"dei":null,"publiccode":null,"codemeta":null}},"created_at":"2024-08-06T17:26:05.000Z","updated_at":"2026-07-09T15:33:54.000Z","dependencies_parsed_at":"2024-08-29T06:29:30.728Z","dependency_job_id":"80e14504-8f4b-4296-b138-9539b2dd3079","html_url":"https://github.com/keithmccammon/cybersecurity-models","commit_stats":null,"previous_names":["keithmccammon/cybersecurity-models"],"tags_count":0,"template":false,"template_full_name":null,"purl":"pkg:github/keithmccammon/cybersecurity-models","repository_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/keithmccammon%2Fcybersecurity-models","tags_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/keithmccammon%2Fcybersecurity-models/tags","releases_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/keithmccammon%2Fcybersecurity-models/releases","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/keithmccammon%2Fcybersecurity-models/manifests","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/keithmccammon","download_url":"https://codeload.github.com/keithmccammon/cybersecurity-models/tar.gz/refs/heads/main","sbom_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/keithmccammon%2Fcybersecurity-models/sbom","scorecard":null,"host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":286080680,"owners_count":36665210,"icon_url":"https://github.com/github.png","version":null,"created_at":"2022-05-30T11:31:42.601Z","updated_at":"2026-08-06T04:43:03.162Z","status":"online","status_checked_at":"2026-08-14T02:00:06.934Z","response_time":54,"last_error":null,"robots_txt_status":"success","robots_txt_updated_at":"2025-07-24T06:49:26.215Z","robots_txt_url":"https://github.com/robots.txt","online":true,"can_crawl_api":true,"host_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names","owners_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners"}},"created_at":"2024-09-26T01:54:16.179Z","updated_at":"2026-09-03T14:00:43.630Z","primary_language":null,"list_of_lists":false,"displayable":true,"categories":["Intrusion and/or adversary analysis models","Functional models","Threat, risk, resilience and other management models","Maturity models","Shared responsibility models"],"sub_categories":[],"readme":"# Cybersecurity models\n\nA collection of models for organizing, prioritizing, and understanding cybersecurity and information risk management concepts.\n\n## Functional models\n\n[Cybersecurity Framework (CSF)](https://www.nist.gov/cyberframework) by the National Institute of Standards and Technology (NIST), U.S. Department of Commerce\n\n[Cyber Defense Matrix](https://cyberdefensematrix.com/) by Sounil Yu\n\n## Intrusion and/or adversary analysis models\n\n[ATLAS](https://atlas.mitre.org/) by the MITRE Corporation\n\n[ATT\u0026CK](https://attack.mitre.org/) by the MITRE Corporation\n\n[Cyber Kill Chain](https://www.lockheedmartin.com/en-us/capabilities/cyber/cyber-kill-chain.html) by Lockheed Martin\n\n[D3FEND](https://d3fend.mitre.org/) by the MITRE Corporation \n\n[Diamond Model](https://apps.dtic.mil/sti/pdfs/ADA586960.pdf) by the United States Department of Defense (DoD)\n\n[GenAI Attacks Matrix](https://ttps.ai/)\n\n[SaaS Attacks](https://github.com/pushsecurity/saas-attacks) by Push Security\n \n## Maturity models\n\n[Consumer Authentication Strength Maturity Model (CASMM)](https://danielmiessler.com/p/casmm-consumer-authentication-security-maturity-model) by Daniel Meissler \n\n[CSIRT Maturity Framework](https://www.enisa.europa.eu/topics/incident-response/csirt-capabilities/csirt-maturity) by the European Union Agency for Cybersecurity (ENISA)\n\n[Cyber Threat Intelligence Capability Maturity Model (CTI-CMM)](https://cti-cmm.org/) by the CTI-CMM team / working group\n\n[Cybersecurity Capability Maturity Model (C2M2)](https://www.energy.gov/ceser/cybersecurity-capability-maturity-model-c2m2) by the United States Department of Energy (DoE)\n\n[Cybersecurity Maturity Matrix](https://cybermaturitymatrix.com/) by Keith McCammon\n\n[Cybersecurity Maturity Model Certification](https://dodcio.defense.gov/CMMC/), by the United States Department of Defense (DoD)\n\n[Detection Engineering Maturity Model](https://detectionengineering.io/) by Kyle Bailey\n\n[Essential Eight Maturity Model](https://www.cyber.gov.au/resources-business-and-government/essential-cyber-security/essential-eight/essential-eight-maturity-model) by the Australian Signals Directorate (ASD)\n\n[Red Team Maturity Model (RTCMM)](https://www.redteammaturity.com/) by Brent Harrell and Garet Stroup\n\n[Security Incident Management Maturity Model](https://opencsirt.org/csirt-maturity/sim3-and-references/), by the Open CSIRT Foundation\n\n[Zero Trust Maturity Model](https://www.cisa.gov/zero-trust-maturity-model) by the Cybersecurity \u0026 Infrastructure Security Agency (CISA)\n\n## Shared responsibility models\n\n[Artificial intelligence (AI) shared responsibility model](https://learn.microsoft.com/en-us/azure/security/fundamentals/shared-responsibility-ai) by Microsoft\n\n[AI Security Shared Responsibility Model](https://www.returnonsecurity.com/p/ai-security-shared-responsibility-model-navigating-risks-ai-deployment) by Mike Privette\n\n[AI Shared Responsibility Framework, V1.0](https://www.coalitionforsecureai.org/wp-content/uploads/2026/05/CoSAI-Shared-Responsibility-Framework.pdf) by the Coalition for Secure AI\n\n[Shared responsibilities and shared fate on Google Cloud](https://cloud.google.com/architecture/framework/security/shared-responsibility-shared-fate) by Google\n\n[Shared responsibility in the cloud](https://learn.microsoft.com/en-us/azure/security/fundamentals/shared-responsibility) by Microsoft\n\n[Shared Responsibility Model](https://aws.amazon.com/compliance/shared-responsibility-model/) by Amazon Web Services\n\n## Threat, risk, resilience and other management models\n\n[AI Risk Management Framework](https://www.nist.gov/itl/ai-risk-management-framework) by the National Institute of Standards and Technology (NIST), U.S. Department of Commerce\n\n[AI Risk Repository](https://airisk.mit.edu/) by MIT\n\n[CERT Resilience Management Model](https://insights.sei.cmu.edu/library/cert-resilience-management-model-cert-rmm-version-12/) by Carnegie Mellon University\n\n[DIE Triad](https://youtu.be/VaE3jLPB4zU) by Sounil Yu\n\n[FAIR Risk Management](https://www.fairinstitute.org/fair-risk-management) by the FAIR Institute\n\n[OCTAVE](https://insights.sei.cmu.edu/library/operationally-critical-threat-asset-and-vulnerability-evaluation-octave-framework-version-10/) by Carnegie Mellon University\n\n[Risk Management Framework](https://csrc.nist.gov/projects/risk-management/about-rmf) by the National Institute of Standards and Technology (NIST), U.S. Department of Commerce\n\n[Threat Assessment and Remediation Analysis (TARA)](https://www.mitre.org/news-insights/publication/threat-assessment-and-remediation-analysis-tara) by the MITRE Corporation\n","projects_url":"https://awesome.ecosyste.ms/api/v1/lists/keithmccammon%2Fcybersecurity-models/projects"}