Technology Capability Models

Technology Capability Models: Survey, Comparison, and Recommendation for Multi-Level IT Capability Mapping

2026-03-22 · ai-architecture knowledge-management governance-policy · medium · source → · wiki →
key claims
  1. No surveyed public framework is simultaneously a modern enterprise-wide technical capability taxonomy and a robust maturity model, so organisations that need both outcomes must combine at least one classification framework with at least one maturity overlay. Sources: `https://www.opengroup.org/togaf`; `https://ivi.ie/it-capability-maturity-framework/`; `https://cmmiinstitute.com/learning/appraisals/levels`
  2. TOGAF's Technical Reference Model and Integrated Information Infrastructure Reference Model are the best general-purpose public backbone in the set because they provide reusable cross-industry structural categories without binding the capability map to specific vendors or implementations. Sources: `https://www.opengroup.org/togaf`; `https://www.opengroup.org/architecture/0210can/togaf8/doc-review/togaf8cr/c/p3/iii-rm/concepts.htm`
  3. IT-CMF is the strongest enterprise-level maturity companion in the survey because IVI explicitly positions it as a 37-capability framework with maturity profiles, assessments, and improvement roadmaps that complement other domain-specific frameworks rather than replace them. Source: `https://ivi.ie/it-capability-maturity-framework/`
  4. DoDAF, NAF, BIAN, and TM Forum TAM all provide meaningful multi-level decomposition or traceability, but each does so inside a bounded defence, banking, or telecom context rather than as a neutral enterprise technology stack. Sources: `https://dodcio.defense.gov/Portals/0/Documents/DODAF/DoDAF_v2-02_web.pdf`; `https://fachglossar.platinus.at/assets/files/NAFv4_2020.09-ed0964cf26fb5f5d0c23a54bc073b5ea.pdf`; `https://bian.org/service-landscape/`; `https://www.tmforum.org/open-digital-architecture/process-framework-etom/`
  5. SABSA, NIST CSF 2.0, and ZTA are valuable security overlays because they describe security attributes, outcomes, or logical security components, but they do not attempt to describe the full technical capability stack for the rest of enterprise IT. Sources: `https://sabsa.org/sabsa-executive-summary/`; `https://csrc.nist.gov/pubs/cswp/29/the-nist-cybersecurity-framework-csf-20/final`; `https://csrc.nist.gov/pubs/sp/800/207/final`
  6. Team Topologies, DORA, Wardley Mapping, and the well-architected frameworks contribute team-design, performance, strategy, or review discipline rather than a canonical enterprise capability taxonomy, so they should challenge and improve the map instead of defining it. Sources: `https://teamtopologies.com/key-concepts`; `https://dora.dev/`; `https://learnwardleymapping.com/`; `https://docs.aws.amazon.com/wellarchitected/latest/framework/welcome.html`; `https://learn.microsoft.com/en-us/azure/well-architected/`; `https://cloud.google.com/architecture/framework`
  7. CSDM should be used as the operational representation layer for the capability map, with shared technical capabilities anchored first to Technical Services and then traced down to Configuration Items, because prior repository work shows that CSDM is strong on traceability but not on capability definition. Sources: `https://github.com/davidamitchell/Research/blob/main/Research/completed/2026-03-08-servicenow-csdm-data-modelling.md`; `https://github.com/davidamitchell/Research/blob/main/Research/completed/2026-03-08-servicenow-platform-strategy.md`
  8. The most defensible rollout path is to stabilise CSDM ownership and service layers first, define a small implementation-agnostic enterprise capability backbone next, map Technical Services and Application Services onto it, and only then apply IT-CMF and targeted overlays for maturity and design review. Sources: `https://github.com/davidamitchell/Research/blob/main/Research/completed/2026-03-08-servicenow-csdm-data-modelling.md`; `https://github.com/davidamitchell/Research/blob/main/Research/completed/2026-03-08-servicenow-platform-strategy.md`; `https://ivi.ie/it-capability-maturity-framework/`

Research Question

What established and emerging IT capability models define a complete, multi-level set of technical capabilities - such as authentication, networking, Application Programming Interface (API) gateways, and data storage - and which model or combination of models best supports: (a) designing new and existing solutions without tying to specific implementation details, and (b) assessing capability maturity against a standardised framework to identify where investment is needed?

Supporting questions:

Findings

(Populated from Section 6 Synthesis above.)

Executive Summary

[inference] No single surveyed public framework can serve as both the enterprise-wide technical capability taxonomy and the maturity model, so the strongest answer is a layered stack that combines a generic taxonomy backbone, a maturity overlay, and an operational traceability model. Sources: TOGAF Standard (10th Edition, 2022) - The Open Group; ivi.ie; cmmiinstitute.com.

[inference] The most defensible composition is a TOGAF-style backbone plus IT-CMF plus CSDM, because TOGAF contributes reusable implementation-agnostic structure, IT-CMF contributes maturity mechanics, and prior repository work shows that CSDM contributes the operational traceability layers needed to anchor the model in ServiceNow. Sources: TOGAF Standard (10th Edition, 2022) - The Open Group; www.opengroup.org; ivi.ie; github.com; github.com.

[inference] Sector, security, and engineering frameworks such as BIAN, TM Forum TAM, SABSA, NIST CSF 2.0, ZTA, DORA, Team Topologies, Wardley Mapping, and the cloud well-architected frameworks should improve or specialise the map rather than replace the enterprise-wide backbone. Sources: bian.org; www.tmforum.org; sabsa.org; csrc.nist.gov; csrc.nist.gov; dora.dev; teamtopologies.com; learnwardleymapping.com; docs.aws.amazon.com; Azure Well-Architected Framework (2024) - Microsoft; Google Cloud Architecture Framework (2024) - Google.

Key Findings

  1. [inference][high] No surveyed public framework is simultaneously a modern enterprise-wide technical capability taxonomy and a robust maturity model, so organisations that need both outcomes must combine at least one classification framework with at least one maturity overlay. Sources: TOGAF Standard (10th Edition, 2022) - The Open Group; ivi.ie; cmmiinstitute.com.
  2. [inference][medium] TOGAF's Technical Reference Model and Integrated Information Infrastructure Reference Model are the best general-purpose public backbone in the set because they provide reusable cross-industry structural categories without binding the capability map to specific vendors or implementations. Sources: TOGAF Standard (10th Edition, 2022) - The Open Group; www.opengroup.org.
  3. [inference][high] IT-CMF is the strongest enterprise-level maturity companion in the survey because IVI explicitly positions it as a 37-capability framework with maturity profiles, assessments, and improvement roadmaps that complement other domain-specific frameworks rather than replace them. Source: ivi.ie.
  4. [fact][medium] DoDAF, NAF, BIAN, and TM Forum TAM all provide meaningful multi-level decomposition or traceability, but each does so inside a bounded defence, banking, or telecom context rather than as a neutral enterprise technology stack. Sources: dodcio.defense.gov; fachglossar.platinus.at; bian.org; www.tmforum.org.
  5. [fact][high] SABSA, NIST CSF 2.0, and ZTA are valuable security overlays because they describe security attributes, outcomes, or logical security components, but they do not attempt to describe the full technical capability stack for the rest of enterprise IT. Sources: sabsa.org; csrc.nist.gov; csrc.nist.gov.
  6. [fact][high] Team Topologies, DORA, Wardley Mapping, and the well-architected frameworks contribute team-design, performance, strategy, or review discipline rather than a canonical enterprise capability taxonomy, so they should challenge and improve the map instead of defining it. Sources: teamtopologies.com; dora.dev; learnwardleymapping.com; docs.aws.amazon.com; Azure Well-Architected Framework (2024) - Microsoft; Google Cloud Architecture Framework (2024) - Google.
  7. [inference][high] CSDM should be used as the operational representation layer for the capability map, with shared technical capabilities anchored first to Technical Services and then traced down to Configuration Items, because prior repository work shows that CSDM is strong on traceability but not on capability definition. Sources: github.com; github.com.
  8. [inference][high] The most defensible rollout path is to stabilise CSDM ownership and service layers first, define a small implementation-agnostic enterprise capability backbone next, map Technical Services and Application Services onto it, and only then apply IT-CMF and targeted overlays for maturity and design review. Sources: github.com; github.com; ivi.ie.

Assumptions

Analysis

Risks, Gaps, and Uncertainties

Open Questions


sources


Connected items

Loading…

View full knowledge graph →