<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>measurement Archives - IDPro</title>
	<atom:link href="https://idpro.org/tag/measurement/feed/" rel="self" type="application/rss+xml" />
	<link>https://idpro.org/tag/measurement/</link>
	<description>The Professional Organization for Digital Identity Management</description>
	<lastBuildDate>Wed, 29 Jul 2026 18:31:39 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	

<image>
	<url>https://idpro.org/wp-content/uploads/2023/07/cropped-idpro_stickerA-circle-100-32x32.jpg</url>
	<title>measurement Archives - IDPro</title>
	<link>https://idpro.org/tag/measurement/</link>
	<width>32</width>
	<height>32</height>
</image> 
	<item>
		<title>What Good IAM Measurement Looks Like</title>
		<link>https://idpro.org/what-good-iam-measurement-looks-like/</link>
		
		<dc:creator><![CDATA[Elizabeth Garber]]></dc:creator>
		<pubDate>Wed, 29 Jul 2026 18:31:38 +0000</pubDate>
				<category><![CDATA[Blog]]></category>
		<category><![CDATA[Newsletter]]></category>
		<category><![CDATA[iam]]></category>
		<category><![CDATA[iam maturity]]></category>
		<category><![CDATA[identity and access management]]></category>
		<category><![CDATA[measurement]]></category>
		<guid isPermaLink="false">https://idpro.org/?p=3066</guid>

					<description><![CDATA[<p>This post explores seven design principles based on research, precedent from other domains, and the practical needs of practitioners.</p>
<p>The post <a href="https://idpro.org/what-good-iam-measurement-looks-like/">What Good IAM Measurement Looks Like</a> appeared first on <a href="https://idpro.org">IDPro</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p class="wp-block-paragraph"><strong>NEWSLETTER SERIES: WE STILL DON&#8217;T HAVE A STANDARD WAY TO MEASURE IAM MATURITY</strong></p>



<p class="wp-block-paragraph">Part 3 of 3</p>



<p class="wp-block-paragraph">By Vidyaa Ganesh</p>



<p class="wp-block-paragraph"><em><em>This is Part 3 of a three-part series on IAM maturity measurement. <a href="https://idpro.org/the-measurement-problem/">Part 1 </a>reviewed the published research showing that 60-70% of organizations remain at early-to-mid stages of IAM maturity. <a href="https://idpro.org/incompatible-approaches-to-iam-maturity/">Part 2</a> examined the frameworks currently available and the structural reasons no standard has emerged.</em></em> <em>This final installment proposes what a credible standard would need to include.</em><br></p>



<p class="wp-block-paragraph">If the IAM community is going to move toward standardized measurement, what would a credible framework need to look like? Based on the published research reviewed in this series, established precedent from other domains, and the practical needs of practitioners, seven design principles emerge.</p>



<h2 class="wp-block-heading"><strong>Principle 1: Domain Decomposition, Not Monolithic Scoring</strong></h2>



<p class="wp-block-paragraph">IAM is not one thing. A useful maturity framework must decompose the discipline into distinct domains and assess each independently before producing any aggregate score. Treating IAM as a monolith obscures critical gaps. An organization with excellent identity governance but absent privileged access controls has a fundamentally different risk profile than one with moderate capabilities across the board, even if their aggregate scores are identical.</p>



<p class="wp-block-paragraph">Gartner&#8217;s six-dimension structure is a reasonable reference point for domain decomposition. At minimum, a framework should separately assess identity lifecycle management, access management and authentication, privileged access management, and governance. Depending on the organization&#8217;s context, customer identity, cloud identity, and identity threat detection may also warrant distinct assessment.</p>



<h2 class="wp-block-heading"><strong>Principle 2: Foundational Prerequisites Must Gate Advanced Claims</strong></h2>



<p class="wp-block-paragraph">This may be the single most important design principle. A framework must account for the reality that some IAM capabilities are prerequisites for others. An organization that has deployed sophisticated analytics and AI-driven threat detection but has not implemented basic multi-factor authentication on privileged accounts has a fundamentally flawed security posture. A credible maturity score should reflect that.</p>



<p class="wp-block-paragraph">This principle is well-established in adjacent fields. CMMI&#8217;s staged representation explicitly requires lower-level process areas to be satisfied before higher-level ratings can be claimed. SailPoint&#8217;s Horizons framework states that to be placed in a given horizon, capabilities must cover most environments and identity types. CISA&#8217;s Zero Trust Maturity Model states that identity pillar capabilities must be established before device trust can be meaningful.</p>



<p class="wp-block-paragraph">A standardized IAM framework should identify a limited set of foundational controls and ensure that gaps in those controls are reflected in the overall maturity score. Without this, organizations can game the assessment by investing in visible, advanced capabilities while neglecting the basics that actually prevent breaches.</p>



<h2 class="wp-block-heading"><strong>Principle 3: Risk-Weighted Scoring</strong></h2>



<p class="wp-block-paragraph">Not all IAM controls carry equal risk. The presence or absence of MFA on privileged accounts has a materially different security impact than the presence or absence of a formal identity data classification scheme. A credible framework must reflect this through some form of risk-weighted scoring.</p>



<p class="wp-block-paragraph">Published research supports this approach. IBM&#8217;s 2025 data shows that organizations with extensive security automation experienced average breach costs of $3.62 million compared to $5.52 million without, a 34% cost reduction attributable to mature controls. Microsoft&#8217;s Digital Defense Report found that MFA blocks over 99% of account compromise attacks. The data makes clear that certain controls deliver disproportionate risk reduction and should be weighted accordingly.</p>



<h2 class="wp-block-heading"><strong>Principle 4: Industry-Contextualized Benchmarks Derived from Empirical Data</strong></h2>



<p class="wp-block-paragraph">A maturity score in isolation is nearly useless. What makes it actionable is context: how does this score compare to others in the same industry, of similar size, facing similar regulatory requirements? A credible framework must include an empirical benchmark layer.</p>



<p class="wp-block-paragraph">The data for this already partially exists. SailPoint publishes industry breakdowns. Ponemon publishes breach cost data by industry. Simeio publishes maturity scores by vertical. What does not exist is a single, consistent benchmark set that covers all IAM domains across major industries. Building this requires either a large-scale survey effort or, more practically, the aggregation of assessment data across organizations over time, with appropriate anonymization and consent.</p>



<h2 class="wp-block-heading"><strong>Principle 5: Transparency of Methodology</strong></h2>



<p class="wp-block-paragraph">Every number in a maturity assessment should have a documented derivation. If a domain receives a higher weight than another, the rationale should be published. If a benchmark is based on a specific data source, that source should be cited. If a benchmark is estimated rather than measured, that should be disclosed.</p>



<p class="wp-block-paragraph">This level of transparency is uncommon in commercial assessment tools, where scoring logic is often proprietary. But for a community standard, it is essential. Consultants need to be able to explain and defend the numbers they present to clients. CISOs need to trust that the methodology is sound before presenting results to their boards. Transparency is not just a nice-to-have. It is a prerequisite for adoption.</p>



<h2 class="wp-block-heading"><strong>Principle 6: Technology Agnosticism</strong></h2>



<p class="wp-block-paragraph">A standardized framework must assess capability, not tooling. The question is not whether an organization has deployed a specific vendor&#8217;s IGA platform, but whether it has a functioning identity lifecycle management process that covers joiners, movers, and leavers with appropriate automation and oversight. This distinction matters because organizations achieve similar maturity outcomes with very different technology stacks, and a useful standard must accommodate that diversity.</p>



<h2 class="wp-block-heading"><strong>Principle 7: Actionable Outputs</strong></h2>



<p class="wp-block-paragraph">A maturity assessment that produces only a number is insufficient. The assessment process should produce outputs that enable direct action: identification of specific capability gaps, prioritized remediation guidance, regulatory compliance mapping, and clear criteria for what moving from one level to the next requires.</p>



<p class="wp-block-paragraph">Gartner&#8217;s recommendation of outcome-driven metrics for IAM aligns with this principle. The goal of measurement is not the score itself but the improvement roadmap it enables. A framework that scores but does not guide action is an academic exercise.</p>



<h2 class="wp-block-heading"><strong>Gaps and Open Questions</strong></h2>



<p class="wp-block-paragraph">Even with sound design principles, significant gaps remain that the community will need to address.</p>



<p class="wp-block-paragraph"><strong>Non-human identity. </strong>Machine identities (service accounts, API keys, certificates, workload identities) now outnumber human identities by ratios that CyberArk&#8217;s 2025 research places at approximately 80 to 1. Yet most maturity models treat identity as synonymous with human identity. A credible standard will need to account for non-human identity management as a distinct assessment domain.</p>



<p class="wp-block-paragraph"><strong>AI agent governance. </strong>As AI agents increasingly operate autonomously within enterprise environments, the question of how to govern their identities, permissions, and access patterns is emerging as a new challenge. SailPoint&#8217;s 2025 Horizons research added AI agent governance to its capability thresholds. No existing maturity model addresses this domain in depth. Any framework designed for longevity should be extensible enough to incorporate it.</p>



<p class="wp-block-paragraph"><strong>The data collection problem. </strong>The most practical path to building reliable industry benchmarks is through the aggregation of anonymized assessment data across many organizations over time. This creates a chicken-and-egg problem: organizations are reluctant to contribute data to a benchmark pool unless the benchmark already exists, and the benchmark cannot exist without contributed data. Solving this will likely require a combination of opt-in data sharing, strong privacy guarantees, and a trusted neutral party to manage the aggregation.</p>



<p class="wp-block-paragraph"><strong>Weighting validation. </strong>Any risk-weighted scoring system involves judgment calls about how much weight to assign to different controls and domains. These weights can be informed by published research on breach costs, attack frequency, and control effectiveness, but they cannot be fully derived from first principles. Ongoing validation through correlation analysis between assessment scores and actual security outcomes is needed to refine the weights over time.</p>



<h2 class="wp-block-heading"><strong>Conclusion</strong></h2>



<p class="wp-block-paragraph">The IAM community has a measurement problem. Five independent research sources, covering over 2,000 respondents, consistently show that 60% to 70% of organizations are at early-to-mid stages of IAM maturity. At the same time, the industry relies on a fragmented set of incompatible frameworks that prevent meaningful comparison, benchmarking, or progress tracking.</p>



<p class="wp-block-paragraph">This is not a technology problem. The tools exist. This is a standards problem. The community lacks a shared, vendor-neutral, empirically-grounded framework for measuring IAM maturity, and the absence of such a standard has real consequences: CISOs cannot articulate their posture to boards in comparable terms, consulting firms deliver assessments that start from scratch with each engagement, and the industry has no aggregate data pool that could identify systemic weaknesses and drive collective improvement.</p>



<p class="wp-block-paragraph">The design principles outlined in this series are not radical. Domain decomposition, foundational prerequisite gating, risk-weighted scoring, empirical benchmarks, methodology transparency, technology agnosticism, and actionable outputs are all well-supported by existing research and established practice in adjacent disciplines. What is missing is the will to build and adopt a standard that incorporates them.</p>



<p class="wp-block-paragraph">Identity practitioners are the people best positioned to solve this. They live the problem daily. They understand the domains. They see the consequences of unmeasured and unmeasurable IAM programs. The question is whether the community will continue to tolerate a landscape where every assessment is a one-off, or whether it will converge on a shared approach that raises the bar for everyone.</p>



<p class="wp-block-paragraph"><strong>About the Author</strong></p>



<p class="wp-block-paragraph">Vidyaa Ganesh is a Senior IAM Engineer and Team Lead at Raah Technologies, with over six years of experience spanning enterprise IAM implementations, strategic advisory, and maturity assessments. She has held consulting roles at KPMG Canada and Indigo Consulting, delivering identity governance and privileged access programs for financial services, energy, telecommunications, and public sector clients. She holds Okta and Saviynt certifications and a Master of Engineering from Concordia University. She is a member of IDPro.</p>



<p class="wp-block-paragraph"><strong>Endnotes</strong></p>



<p class="wp-block-paragraph">17. Gartner, IAM Program Maturity Model (September 2025).</p>



<p class="wp-block-paragraph">18. ISACA, CMMI Version 3.0: &#8220;A maturity level rating is achieved when all process areas at that level have been appraised as meeting their specific and generic goals.&#8221;</p>



<p class="wp-block-paragraph">19. SailPoint, Horizons 2025-2026: &#8220;To be in one horizon, customer capabilities need to cover most environments and identities.&#8221;</p>



<p class="wp-block-paragraph">20. CISA, Zero Trust Maturity Model (2023).</p>



<p class="wp-block-paragraph">21. IBM Security, Cost of a Data Breach Report 2025.</p>



<p class="wp-block-paragraph">22. Microsoft, Digital Defense Report (Microsoft Security, 2024).</p>



<p class="wp-block-paragraph">23. NIST, SP 800-30 Rev 1: Guide for Conducting Risk Assessments (2012). See also FAIR Institute.</p>



<p class="wp-block-paragraph">24. SailPoint, Horizons 2025-2026, Exhibit 7.</p>



<p class="wp-block-paragraph">25. IBM Security, Cost of a Data Breach Report 2025, Industry Analysis section.</p>



<p class="wp-block-paragraph">26. Simeio, State of Identity 2024.</p>



<p class="wp-block-paragraph">27. Gartner, IAM Program Maturity Model (September 2025). Recommends outcome-driven metrics (ODMs).</p>



<p class="wp-block-paragraph">28. CyberArk, The Urgent Reality of Machine Identity Security in 2025 (CyberArk, 2025), 2,600 decision-makers.</p>



<h2 class="wp-block-heading"><br><br>About the Author</h2>



<div class="wp-block-columns is-layout-flex wp-container-core-columns-is-layout-8f761849 wp-block-columns-is-layout-flex">
<div class="wp-block-column is-layout-flow wp-block-column-is-layout-flow" style="flex-basis:100%">
<figure class="wp-block-image size-full is-resized"><img fetchpriority="high" decoding="async" width="400" height="400" src="https://idpro.org/wp-content/uploads/2026/05/image-3.png" alt="" class="wp-image-3037" style="width:361px;height:auto" srcset="https://idpro.org/wp-content/uploads/2026/05/image-3.png 400w, https://idpro.org/wp-content/uploads/2026/05/image-3-300x300.png 300w, https://idpro.org/wp-content/uploads/2026/05/image-3-150x150.png 150w, https://idpro.org/wp-content/uploads/2026/05/image-3-320x320.png 320w" sizes="(max-width: 400px) 100vw, 400px" /></figure>
</div>
</div>



<p class="wp-block-paragraph">Vidyaa Ganesh is a Senior IAM Engineer and a solutions architect with over six years of experience delivering identity governance programs for financial services, energy, telecommunications, and public sector clients. She holds a Master of Engineering from Concordia University, is a member of IDPro, and is the creator of AXIS (axis.identara.ca), an open IAM maturity assessment framework.</p>



<p class="wp-block-paragraph"></p>



<figure class="wp-block-gallery has-nested-images columns-2 is-cropped wp-block-gallery-1 is-layout-flex wp-block-gallery-is-layout-flex">
<figure class="wp-block-image size-large"><img decoding="async" width="346" height="350" data-id="2898" src="https://idpro.org/wp-content/uploads/2025/11/image-2.png" alt="" class="wp-image-2898" srcset="https://idpro.org/wp-content/uploads/2025/11/image-2.png 346w, https://idpro.org/wp-content/uploads/2025/11/image-2-297x300.png 297w" sizes="(max-width: 346px) 100vw, 346px" /></figure>



<figure class="wp-block-image size-full"><img decoding="async" width="600" height="600" data-id="2390" src="https://idpro.org/wp-content/uploads/2023/10/IDPro_BoK_Badges_R5__Newsletter_Author.png" alt="" class="wp-image-2390" srcset="https://idpro.org/wp-content/uploads/2023/10/IDPro_BoK_Badges_R5__Newsletter_Author.png 600w, https://idpro.org/wp-content/uploads/2023/10/IDPro_BoK_Badges_R5__Newsletter_Author-300x300.png 300w, https://idpro.org/wp-content/uploads/2023/10/IDPro_BoK_Badges_R5__Newsletter_Author-150x150.png 150w, https://idpro.org/wp-content/uploads/2023/10/IDPro_BoK_Badges_R5__Newsletter_Author-320x320.png 320w" sizes="(max-width: 600px) 100vw, 600px" /></figure>
</figure>



<p class="wp-block-paragraph"></p>
<p>The post <a href="https://idpro.org/what-good-iam-measurement-looks-like/">What Good IAM Measurement Looks Like</a> appeared first on <a href="https://idpro.org">IDPro</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>The Measurement Problem</title>
		<link>https://idpro.org/the-measurement-problem/</link>
		
		<dc:creator><![CDATA[Elizabeth Garber]]></dc:creator>
		<pubDate>Sun, 31 May 2026 02:56:07 +0000</pubDate>
				<category><![CDATA[Blog]]></category>
		<category><![CDATA[Newsletter]]></category>
		<category><![CDATA[iam]]></category>
		<category><![CDATA[iam maturity]]></category>
		<category><![CDATA[identity and access management]]></category>
		<category><![CDATA[measurement]]></category>
		<guid isPermaLink="false">https://idpro.org/?p=3033</guid>

					<description><![CDATA[<p>Five independent sources, 2,000+ respondents, one conclusion: most organizations cannot measure their IAM maturity. And that is a problem.</p>
<p>The post <a href="https://idpro.org/the-measurement-problem/">The Measurement Problem</a> appeared first on <a href="https://idpro.org">IDPro</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p class="wp-block-paragraph"><strong>NEWSLETTER SERIES: WE STILL DON&#8217;T HAVE A STANDARD WAY TO MEASURE IAM MATURITY</strong></p>



<p class="wp-block-paragraph">Part 1 of 3</p>



<p class="wp-block-paragraph">By Vidyaa Ganesh</p>



<p class="wp-block-paragraph"><em>Five independent sources, 2,000+ respondents, one conclusion: most organizations cannot measure their IAM maturity. And that is a problem.</em></p>



<p class="wp-block-paragraph">Identity and access management has become one of the most consequential areas of enterprise security. The IDSA&#8217;s 2024 survey of 521 security professionals found that 90% of organizations experienced at least one identity-related security incident in the prior 12 months, with 84% reporting direct business impact. IBM&#8217;s 2025 Cost of a Data Breach report, based on 600 organizations and over 3,400 interviews, puts the global average breach cost at $4.88 million, with compromised credentials remaining the most common initial attack vector.</p>



<p class="wp-block-paragraph">These numbers create obvious pressure for organizations to invest in IAM. And they are investing. But a harder question follows: how do you know whether your IAM program is actually working? How do you measure where you stand relative to your industry, track improvement over time, or communicate your posture to a board of directors in terms that hold up to scrutiny?</p>



<p class="wp-block-paragraph">The honest answer, as of early 2026, is that most organizations cannot do any of these things reliably. There is no widely accepted, vendor-neutral framework for measuring IAM maturity. What exists instead is a patchwork of vendor-specific models, consultant-developed scorecards, and ad hoc approaches that vary from one engagement to the next. The measurements produced by these approaches cannot be compared across organizations, across time, or even across different consultants assessing the same organization.</p>



<p class="wp-block-paragraph">This is the first installment in a three-part series examining this problem. In this piece, we look at what the published research actually says about where organizations stand. In Part 2, we survey the frameworks currently in use and analyze why no standard has emerged. In Part 3, we propose design principles that a credible, community-adopted standard would need to follow.</p>



<h2 class="wp-block-heading"><strong>What Published Research Tells Us</strong></h2>



<p class="wp-block-paragraph">Before discussing what a standard should look like, it is worth understanding what the data actually says about where organizations stand. Several independent research efforts have attempted to measure IAM maturity across large populations, and their findings tell a remarkably consistent story.</p>



<h2 class="wp-block-heading"><strong>SailPoint Horizons of Identity Security (2025-2026)</strong></h2>



<p class="wp-block-paragraph">SailPoint&#8217;s annual Horizons research surveyed 375 IAM decision-makers across North America, Europe, Asia, and Latin America. The study evaluates organizations across four enablement areas (strategy, technology and tools, operating model, and talent) covering 60 IAM capabilities, then assigns each organization to one of five maturity horizons using a clustering algorithm.</p>



<p class="wp-block-paragraph">The headline finding is striking: over 40% of organizations remain at Horizon 1, the lowest maturity level. These are organizations where identity is not a strategic focus, capabilities are highly immature, and there is no centralized operating model for managing identities across the organization. When you include Horizon 2, the number climbs to roughly 63% of organizations stuck at the bottom two tiers.</p>



<p class="wp-block-paragraph">Industry breakdowns reveal meaningful variation. In financial services, 34% are at Horizon 1, with 13% reaching Horizon 4 or above. In technology, the distribution is bimodal: 46% at Horizon 1, but 15% at Horizon 4 or higher, reflecting a split between early-stage companies with minimal IAM investment and mature enterprises with sophisticated programs.</p>



<h2 class="wp-block-heading"><strong>Ponemon Institute and GuidePoint Security (2025)</strong></h2>



<p class="wp-block-paragraph">The Ponemon Institute, in partnership with GuidePoint Security, surveyed 626 IT professionals on the state of IAM maturity in 2025. On a 10-point effectiveness scale, only 50% of respondents rated their IAM tools as effective (scoring 7 or higher). Just 23% qualified as high performers, rating their effectiveness at 9 or 10.</p>



<p class="wp-block-paragraph">The study also found that 50% of organizations experienced an identity-related incident in the prior 12 months. Even among high performers, 39% still experienced incidents, compared to 58% for others. Manual processes remain dominant: 34% of organizations still use spreadsheets for access reviews, and only 17% use an identity governance platform for this purpose.</p>



<h2 class="wp-block-heading"><strong>IDSA Trends in Identity Security (2024)</strong></h2>



<p class="wp-block-paragraph">The Identity Defined Security Alliance surveyed 521 qualified security professionals at organizations with 1,000 or more employees. The findings reinforce the pattern: 90% experienced an identity-related incident, 84% reported direct business impact, and 91% invoked their incident response plans for identity-related events.</p>



<p class="wp-block-paragraph">When asked to self-assess their maturity, only 8% of respondents placed their organization at the highest level. The majority clustered in the middle tiers, suggesting widespread acknowledgment that current capabilities are insufficient.</p>



<h2 class="wp-block-heading"><strong>Other Sources</strong></h2>



<p class="wp-block-paragraph">Bravura Security, in partnership with Gartner Peer Insights, conducted a smaller study of 100 IT leaders across North America and EMEA using a four-level maturity scale. Their finding: the average organization falls between levels 2 and 3 on a four-point scale, consistent with the other sources.</p>



<p class="wp-block-paragraph">Simeio&#8217;s State of Identity research, covering 80 measures across industries, found a cross-industry average maturity of 2.4 on a five-point scale. Financial services scored highest at approximately 2.6, with healthcare and public sector trailing.</p>



<h2 class="wp-block-heading"><strong>What the Data Tells Us</strong></h2>



<p class="wp-block-paragraph">Five independent research efforts, using different scales, different sample sizes, and different methodologies, converge on the same conclusion: the majority of organizations, somewhere between 60% and 70%, remain at early-to-mid stages of IAM maturity. The consistency across sources is significant. This is not one vendor telling a convenient story. It is a pattern that holds up regardless of who is asking the question or how they frame it.</p>



<p class="wp-block-paragraph"><strong>Table 1. </strong><em>Cross-source validation of IAM maturity findings</em></p>



<figure class="wp-block-table"><table class="has-fixed-layout"><thead><tr><th><strong>Source</strong></th><th><strong>Sample Size</strong></th><th><strong>Scale</strong></th><th><strong>Key Finding</strong></th></tr></thead><tbody><tr><td>SailPoint Horizons 2025-2026</td><td>375</td><td>5-horizon</td><td>63% at Horizons 1-2</td></tr><tr><td>Ponemon/GuidePoint 2025</td><td>626</td><td>10-point</td><td>50% rate tools effective; 23% high performers</td></tr><tr><td>IDSA 2024</td><td>521</td><td>5-level self-assessment</td><td>90% had incidents; 8% at highest maturity</td></tr><tr><td>Bravura/Gartner 2024</td><td>100</td><td>4-level</td><td>Average between levels 2-3</td></tr><tr><td>Simeio (Kaleru 2025)</td><td>80 measures</td><td>5-point</td><td>Cross-industry average: 2.4</td></tr></tbody></table></figure>



<p class="wp-block-paragraph"><strong>NEXT IN THIS SERIES</strong></p>



<p class="wp-block-paragraph"><strong>Part 2: A Landscape of Incompatible Approaches</strong></p>



<p class="wp-block-paragraph"><em>Several maturity frameworks exist in the IAM space. Each offers something useful. None has achieved the status of a shared standard. We examine why.</em></p>



<p class="wp-block-paragraph"><strong>Endnotes</strong></p>



<p class="wp-block-paragraph">1. Identity Defined Security Alliance, 2024 Trends in Securing Digital Identities (IDSA, 2024), 521 respondents.</p>



<p class="wp-block-paragraph">2. IBM Security, Cost of a Data Breach Report 2025 (Ponemon Institute Research, 2025), 600 organizations, 3,470 interviews.</p>



<p class="wp-block-paragraph">3. SailPoint Technologies, The Horizons of Identity Security 2025-2026 (SailPoint, July 2025), 375 IAM decision-makers.</p>



<p class="wp-block-paragraph">4. SailPoint, Horizons 2025-2026, Exhibit 7, p. 15.</p>



<p class="wp-block-paragraph">5. Ponemon Institute and GuidePoint Security, The State of Identity and Access Management (IAM) Maturity (May 2025), 626 IT professionals.</p>



<p class="wp-block-paragraph">6. Identity Defined Security Alliance, 2024 Trends in Securing Digital Identities (IDSA, 2024).</p>



<p class="wp-block-paragraph">7. Bravura Security and Gartner Peer Insights, IAM &amp; PAM Maturity Survey (Bravura Security, 2024), 100 IT leaders.</p>



<p class="wp-block-paragraph">8. Simeio, State of Identity 2024 (Simeio Solutions, 2024).<br><br><em>Disclaimer: The views expressed in the content are solely those of the author and do not necessarily reflect the views of the IDPro organization.</em></p>



<h2 class="wp-block-heading"><br><br>About the Author</h2>



<div class="wp-block-columns is-layout-flex wp-container-core-columns-is-layout-8f761849 wp-block-columns-is-layout-flex">
<div class="wp-block-column is-layout-flow wp-block-column-is-layout-flow" style="flex-basis:100%">
<figure class="wp-block-image size-full is-resized"><img loading="lazy" decoding="async" width="400" height="400" src="https://idpro.org/wp-content/uploads/2026/05/image-3.png" alt="" class="wp-image-3037" style="width:361px;height:auto" srcset="https://idpro.org/wp-content/uploads/2026/05/image-3.png 400w, https://idpro.org/wp-content/uploads/2026/05/image-3-300x300.png 300w, https://idpro.org/wp-content/uploads/2026/05/image-3-150x150.png 150w, https://idpro.org/wp-content/uploads/2026/05/image-3-320x320.png 320w" sizes="auto, (max-width: 400px) 100vw, 400px" /></figure>
</div>
</div>



<p class="wp-block-paragraph">Vidyaa Ganesh is a Senior IAM Engineer and a solutions architect with over six years of experience delivering identity governance programs for financial services, energy, telecommunications, and public sector clients. She holds a Master of Engineering from Concordia University, is a member of IDPro, and is the creator of AXIS (axis.identara.ca), an open IAM maturity assessment framework.</p>



<p class="wp-block-paragraph"></p>



<figure class="wp-block-gallery has-nested-images columns-2 is-cropped wp-block-gallery-2 is-layout-flex wp-block-gallery-is-layout-flex">
<figure class="wp-block-image size-large"><img loading="lazy" decoding="async" width="346" height="350" data-id="2898" src="https://idpro.org/wp-content/uploads/2025/11/image-2.png" alt="" class="wp-image-2898" srcset="https://idpro.org/wp-content/uploads/2025/11/image-2.png 346w, https://idpro.org/wp-content/uploads/2025/11/image-2-297x300.png 297w" sizes="auto, (max-width: 346px) 100vw, 346px" /></figure>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="600" height="600" data-id="2390" src="https://idpro.org/wp-content/uploads/2023/10/IDPro_BoK_Badges_R5__Newsletter_Author.png" alt="" class="wp-image-2390" srcset="https://idpro.org/wp-content/uploads/2023/10/IDPro_BoK_Badges_R5__Newsletter_Author.png 600w, https://idpro.org/wp-content/uploads/2023/10/IDPro_BoK_Badges_R5__Newsletter_Author-300x300.png 300w, https://idpro.org/wp-content/uploads/2023/10/IDPro_BoK_Badges_R5__Newsletter_Author-150x150.png 150w, https://idpro.org/wp-content/uploads/2023/10/IDPro_BoK_Badges_R5__Newsletter_Author-320x320.png 320w" sizes="auto, (max-width: 600px) 100vw, 600px" /></figure>
</figure>



<p class="wp-block-paragraph"></p>
<p>The post <a href="https://idpro.org/the-measurement-problem/">The Measurement Problem</a> appeared first on <a href="https://idpro.org">IDPro</a>.</p>
]]></content:encoded>
					
		
		
			</item>
	</channel>
</rss>

<!--
Performance optimized by W3 Total Cache. Learn more: https://www.boldgrid.com/w3-total-cache/?utm_source=w3tc&utm_medium=footer_comment&utm_campaign=free_plugin

Page Caching using Disk: Enhanced 
Lazy Loading (feed)
Minified using Disk

Served from: idpro.org @ 2026-07-31 13:38:48 by W3 Total Cache
-->