The Program Review for Information Security Assistance (PRISMA) project was last updated in 2007; NIST Interagency Report (IR) 7358 and the corresponding PRISMA tool continue to serve as useful resources for high-level guidance and as a general framework, but may not be fully consistent with changes to requirements, standards and guidelines for securing systems.
The PRISMA review is based upon five levels of maturity: policy, procedures, implementation, test, and integration. A brief description of each level is provided below.
The PRISMA team assesses the maturity level for each of the review criteria. A higher maturity level can only be attained if the previous maturity level is attained. Therefore, if there is an implementation, but there isn't a policy for a specific criteria, none of the maturity levels are attained for the specific criteria.
IT Security Maturity Level 1: Policies
IT Security Maturity Level 2: Procedures
IT Security Maturity Level 3: Implementation
IT Security Maturity Level 4: Test
IT Security Maturity Level 5: Integration
Security and Privacy: assurance, program management