The ASD Essential Eight Maturity Model
The Australian Signals Directorate has recently published the Essential Eight Maturity Model, which breaks down each of the eight mitigation strategies into discrete “Maturity Levels”.
ASD is known for publishing excellent, pragmatic security advice. This maturity model is another example, because it recognises that an organisation achieving a mitigation like “daily backups” can mean many different things depending on how mature their policies and practices are.
Well worth bookmarking and reading in full. Also worth noting that most organisations in Australia would be at maturity level 0 or 1.
Note: for a description of each of the Essential Eight, and what they actually mean in practice: https://www.asd.gov.au/publications/protect/essential-eight-explained.htm