Cyber Defense Capabilities Assessment and Maturity Model for the Military Forces
Keywords:
cyber defense, cybersecurity, model, maturityAbstract
The purpose of this document is to propose a solution to the challenge of assessing the maturity of essential capabilities in the practice of cyber defense through a model that provides a comparative analysis of the various manuals, guidelines, and systems within the cyber defense framework. The model is based on a methodology and framework that incorporates variables with defined measurement levels and is adaptable to both individual and collective capabilities. It contributes to decision-making and the development of this discipline by seeking to strengthen policies, governance, legal frameworks, management, and investment in the short, medium, and long term, in order to address any type of cyber threat or attack.
References
Almuhammadi, S., & Alsaleh, M. (2017). Information security maturity model for NIST Cybersecurity Framework. Computer Science & Information Technology (CS & IT). https://www.researchgate.net/profile/SultanfiAlmuhammadi/publication/314291503fiInformationfiSecurityfiMaturityfiModelfiforfiNistfiCyberfiSecurityfiFramework/links/5c5e630fa6fdccb608b288de/Information-Security-Maturity-Model-for-Nist-Cyber-Security-Framework.pdf
Arbelaez, R. (2017, febrero 21). ACIS VIII Jornada Nacional de Seguridad Informática. https://52.1.175.72/portal/sites/all/themes/argo/assets/img/Pagina/05-ModelosMadurezSeguridadInformatica.pdf
Cabuya Padilla, D., & Sierra Abril, F. (2019). Método de evaluación del Sistema Integral de Ciberdefensa-SICID [Documento reservado]. Comando Conjunto Cibernético.
Comando Conjunto Cibernético. (2018). Concepto funcional conjunto de ciberseguridad y ciberdefensa [Documento reservado]. Comando General de las Fuerzas Militares.
Departamento Nacional de Planeación. (2016, abril 11). Documento CONPES 3854: Política nacional de seguridad digital. https://bibliotecadigital.ccb.org.co/bitstream/handle/11520/14856/DNP-Conpes-Pol%2B%c2%a1tica%20Nacional%20de%20Seguridad%20Digital.pdf?sequence=1&isAllowed=y
Departamento Nacional de Planeación. (2021, julio 14). Documento CONPES 3701. https://www.mintic.gov.co/portal/604/articles-3510fidocumento.pdf
U.S. Department of Energy. (2014). Cybersecurity Capability Maturity Model (C2M2), version 1.1. Carnegie Mellon University. https://www.energy.gov/sites/prod/files/2014/03/f13/C2M2-v1-1ficor.pdf
Goksen, Y., Cevik, E., & Avunduk, E. (2015). A case analysis on the focus on the maturity models and information technologies. Procedia Economics and Finance, 19, 208–216. https://www.sciencedirect.com/science/article/pii/S2212567115000222
Junta Interamericana de Defensa. (2020). Guía de ciberdefensa. JID.
Junta Interamericana de Defensa & Fundación Interamericana de Defensa. (2020). Informe II Conferencia de Ciberdefensa.
Le, N., & Hoang, D. (2016). Can maturity models support cyber? In 2016 IEEE 35th International Performance Computing and Communications Conference (IPCCC). IEEE. https://ieeexplore.ieee.org/document/7820663
NATO Cooperative Cyber Defence Centre of Excellence. (2012). National cyber security framework manual. Alexander Klimburg.
Rea-Guamán, A., Sánchez, I., Feliu, T., & Calvo, J. (2017). Maturity models in cybersecurity: A systematic review. In Proceedings of the 12th Iberian Conference on Information Systems and Technologies (pp. 284–289). IEEE. https://ieeexplore.ieee.org/document/7975865
Villa, M., Ruiz, M., & Ramos, I. (2004). Modelos de evaluación y mejora de procesos: Análisis comparativo. https://www.researchgate.net/publication/228925424fiModelosfidefievaluacionfiyfimejorafidefiprocesosfiAnalisisficomparativo
Villa, M., Ruiz, M., & Ramos, I. (2006). Un estudio crítico comparativo de ISO 9001, CMMI e ISO 15504. CISTI, II, 551.
White, G. (2007). The community cyber security maturity model. In Proceedings of the 40th Annual Hawaii International Conference on System Sciences. IEEE.
Downloads
Published
How to Cite
Issue
Section
License
Copyright (c) 2026 Andrés Fernando Ortiz Alfonso

This work is licensed under a Creative Commons Attribution 4.0 International License.
The authors retain copyright and grant the journal the right to publish the work under a Creative Commons Attribution License, which allows third parties to use the published content as long as they credit the author(s) and the publication in DERROTERO.
This work is licensed under a Creative Commons Attribution-NonCommercial-ShareAlike 4.0 International License.


