Reading the Matrix
Why Your Security Program Needs a Map, Not More Maps
The problem the CDM solves and what this series covers.
Five Functions, Five Assets, One Matrix
The core 5x5 structure, the 25 cells, and the People/Tech/Process continuum.
You Don't Just Defend Your Assets
The four-ring extended asset model: enterprise, employee, vendor, customer.
Using the CDM to Cut Through Vendor Noise
The single-aisle test, primary vs. supporting capabilities, portfolio gap analysis.
Why You Keep Buying Tools That End Up on the Shelf
The shelfware problem, the Tech:People ratio by function, why Detect can't be automated away.
Who Owns What: Mapping Security Responsibilities Across Your Organization
Cell-level RACI, where handoffs break, and why the Japan FSI organizational model matters.
From Checklist Fatigue to a Real Security Scorecard
Mapping compliance controls to CDM cells for a posture heat map instead of a compliance average.
Maximum Possible vs. Minimum Required: Designing for Real Users
Security design patterns by user persona and what to do when the gap between possible and required can't be closed.
VA, Pentest, BAS, Red Team: What Each One Actually Tests
Four assessment types mapped to four CDM columns. Sequencing logic for real programs.
Zero Trust Is Not a Product: What the Matrix Reveals
Row-by-row CDM mapping of Zero Trust, where implementations fall short, and why ZT has nothing to say about Detect and Respond.
How CDM Connects to the Frameworks You're Already Using
Kill Chain, ATT&CK, CIS Controls, and NIST CSF mapped to CDM. Use all of them together.
Reading the Matrix in the APJ Context
JFSA, FISC, MAS, APRA, ISMS-P mapped to CDM cells. Regional operational characteristics.
The Quantum Clock Is Already Running: PQC Through a CDM Lens
PQC through a CDM lens: where cryptographic risk lives in the matrix and what a structured migration program looks like.