MIL
What is MIL?
Maturity Indicator Level
The maturity scale used by C2M2 and by the AESCSF, running from MIL-0 to MIL-3. It applies to each domain separately, and a domain reaches a level only when every practice at that level and below is performed. An organisation overall sits at the level of its weakest domain, not at an average. A MIL measures where you are, which is a different question from the Security Profile that says where you are supposed to be.
How the scale behaves
MILs run from MIL-0 to MIL-3 and apply to each domain separately. A domain reaches a level only when every practice at that level and below is performed, so the levels cannot be achieved out of order.
An organisation overall sits at the level of its weakest domain rather than at an average. Ten strong domains and one neglected one produce a low overall position, which is usually a surprise the first time an assessment is run properly.
What a MIL does not tell you
A MIL measures current maturity. It does not say what maturity you are required to reach. In the AESCSF that target is set by the Security Profile assigned to your criticality.
Read more
- AESCSF Security Profile 2: What the Enhanced CIRMP Rules Now Require
The AESCSF has two scales and people mix them up. Maturity Indicator Levels measure where you are; Security Profiles say where you must be. The Enhanced CIRMP Rules move named energy asset classes to SP-2 by June 2028, and cumulative profiles make that further than it looks.
- The Essential Eight Is Being Retired: What It Means for Your CIRMP Nomination
ASD will retire the Essential Eight within about two years, replacing it with a domain-split Essentials series that includes an operational technology chapter. The Enhanced CIRMP Rules give you until June 2028 to comply with a nominated framework. Those two clocks overlap, and it changes what you should nominate.
See also
- SP Security Profile The target state scale used by the AESCSF, running SP-1, SP-2 and SP-3 for low, moderate and high criticality entities.
- C2M2 Cybersecurity Capability Maturity Model A maturity model published by the US Department of Energy.
- AESCSF Australian Energy Sector Cyber Security Framework A cyber security framework maintained by AEMO for the Australian energy sector, adapted from the US DOE C2M2.
O/IT Cyber advises Australian critical infrastructure operators on risk management programs, framework nomination and OT security. Talk to us.