A security environment can be large and complex, and organizations often find it hard to define, track, and report on what areas of their environment they deem to be in need of investments. To help CISOs, this spreadsheet provides:A taxonomy for how to define the elements of your program, a tool and scale for scoring the relative maturity of different elements of your program, and a way of weighting the importance of those elements.