DOE Cybersecurity Capability Maturity Model v2.1
Voluntary cybersecurity maturity model developed by the Department of Energy for the energy sector. 10 domains covering asset management, threat and vulnerability management, risk management, identity and access management, situational awareness, event and incident response, third-party risk management, workforce management, cybersecurity architecture, and program management. Each domain assessed across Maturity Indicator Levels (MIL 0-3) measuring organizational capability progression. Used by electric utilities, oil and gas companies, and other energy subsectors for self-assessment.
| Clause | Title | SP 800-53 Controls |
|---|---|---|
| ACCESS | Identity and Access Management | |
| ARCHITECTURE | Cybersecurity Architecture | |
| ASSET | Asset, Change, and Configuration Management | |
| PROGRAM | Cybersecurity Program Management | |
| RESPONSE | Event and Incident Response, Continuity of Operations | |
| RISK | Risk Management | |
| SITUATION | Situational Awareness | |
| THIRD | Third-Party Risk Management | |
| THREAT | Threat and Vulnerability Management | |
| WORKFORCE | Workforce Management |