Why Your Security Program Needs a Map, Not More Maps

The problem the CDM solves and what this series covers.

Five Functions, Five Assets, One Matrix

The core 5x5 structure, the 25 cells, and the People/Tech/Process continuum.

You Don't Just Defend Your Assets

The four-ring extended asset model: enterprise, employee, vendor, customer.

Using the CDM to Cut Through Vendor Noise

The single-aisle test, primary vs. supporting capabilities, portfolio gap analysis.

Why You Keep Buying Tools That End Up on the Shelf

The shelfware problem, the Tech:People ratio by function, why Detect can't be automated away.

Who Owns What: Mapping Security Responsibilities Across Your Organization

Cell-level RACI, where handoffs break, and why the Japan FSI organizational model matters.

From Checklist Fatigue to a Real Security Scorecard

Mapping compliance controls to CDM cells for a posture heat map instead of a compliance average.

Maximum Possible vs. Minimum Required: Designing for Real Users

Security design patterns by user persona and what to do when the gap between possible and required can't be closed.

VA, Pentest, BAS, Red Team: What Each One Actually Tests

Four assessment types mapped to four CDM columns. Sequencing logic for real programs.

Zero Trust Is Not a Product: What the Matrix Reveals

Row-by-row CDM mapping of Zero Trust, where implementations fall short, and why ZT has nothing to say about Detect and Respond.

How CDM Connects to the Frameworks You're Already Using

Kill Chain, ATT&CK, CIS Controls, and NIST CSF mapped to CDM. Use all of them together.

Reading the Matrix in the APJ Context

JFSA, FISC, MAS, APRA, ISMS-P mapped to CDM cells. Regional operational characteristics.

The Quantum Clock Is Already Running: PQC Through a CDM Lens

PQC through a CDM lens: where cryptographic risk lives in the matrix and what a structured migration program looks like.

mcphail.pro · McPhail Security