Skip to main content
Governance & stewardship

CR-CMM Advisory Board.

CR-CMM is the community-driven cyber resilience capability maturity model, guided by an Advisory Board for technical integrity and strategic input. CR-CMM is sponsored and owned by High Value Target, a boutique cyber resilience firm.

Practice
Leads

10

Meeting notes posted

3

Change request routes

25

Anyone from the community can submit change requests to the CR-CMM team via email, to Advisory Board members, or via LinkedIn. Meeting notes are posted on this website for transparency.
The role of the CR-CMM Advisory Board

Technical integrity, interpretation, and responsible evolution.

The Advisory Board helps guide the technical integrity, interpretation, and responsible evolution of CR-CMM. Advisory Board membership does not by itself transfer ownership or authorize official public representation, partnerships, or commercialization under the CR-CMM brand without approval. Any change request is then periodically reviewed and triaged by the Advisory Board and meeting notes are posted on this website for transparency.

Community governance

CR-CMM is the community-driven cyber resilience capability maturity model, guided by an Advisory Board for technical integrity and strategic input. Anyone from the community, especially from prominent cyber resilience subject-matter expert groups, can submit change requests to the CR-CMM team via email, to its Advisory Board members or via its LinkedIn page. Any change request is then periodically reviewed and triaged by the Advisory Board. CR-CMM is sponsored and owned by High Value Target, a boutique cyber resilience firm.

CR-CMM is made available for community benefit under its published licensing terms. High Value Target retains ownership, sponsorship, and control of official branding, external positioning, and approved commercial use.
Current board

Practice-aligned advisors.

The Advisory Board brings together domain expertise across the ten CR-CMM practices to help review interpretation, change requests, and the ongoing evolution of the model.

PracticeAdvisorOrganization
Criticality AnalysisHeath RenfrowFenix24
Situational AwarenessRob van OsSOC-CMM
Threat-Informed DefenseMehdi AzaouiouiLimber Security
Defensible ArchitecturePerry YoungAiSP CISO SIG
Crisis ManagementMark Orsi, Alex SharpeGRF
Scenario SimulationPatrick LechnerResion
Contingency TestingItay MesholamISSA Cyber Resilience SIG
System TestingDr. Mark WinsteadMITRE
Security TestingPiotr BorkowskiCyberArms
Cyber RecoveryCarlos RecaldeSheltered Harbor
Submit a change request

Route feedback through the official channels.

Community members, especially cyber resilience subject-matter expert groups, can submit change requests to the CR-CMM team via email, directly to Advisory Board members, or through LinkedIn.

Meeting notes

Posted for transparency.

Official summaries, decisions, and action items from CR-CMM Advisory Board meetings guiding the model's evolution.

December 2025

Advisory Board Meeting Summary - December 2025

PDF99 KB

Download

November 2025

Advisory Board Meeting Summary - November 2025

PDF115 KB

Download

October 2025

Advisory Board Meeting Summary - October 2025

PDF101 KB

Download