UCSMM self-assessment

Where your organisation actually stands on cognitive security: four dimensions, five levels, twenty questions answered with evidence rather than opinion.

4capability dimensions
5maturity levels
20assessment items
3ISO 27001 · 42001 · 45003
  • 1

    Twenty statements

    Score each one from 1 to 5, one at a time.

  • 2

    The evidence rule

    No document, record or number to point to? The score is capped at 2.

  • 3

    Your level

    Set by your weakest dimension, with one priority to fix first.

Three ideas, one model

The philosophy, what it protects, and how you build it.

Three ideas that grew up together. The full explanation is in the UCSMM Field Guide.

  • 1 · The philosophy

    Invisible Engineering

    Security that works quietly and protects the freedom to think and choose.

  • 2 · What it protects

    The Cognitive Shield

    The human mind is the new perimeter: judgement, attention and choice. Human-factor anchor: ISO 45003.

  • 3 · How you build it

    UCSMM

    Four dimensions, five levels, one honest assessment, a clear next step.

The core logic

Buying AI does not make you resilient. Building the capability to protect it does.

Adopting AI turns into resilience only once you build the capability to protect it — and governance is what makes that turn happen.

  1. AI adoption intensity
  2. β = 0.56Cognitive security capability
  3. β = 0.62Enterprise security resilience
AI governance strengthens the link from capability to resilienceβ = 0.21
Indirect effect of adoption through capability
β = 0.35
Adoption also adds operational complexity
β = 0.48
Standardised path coefficients (β) from the doctoral thesis. All paths supported at p < 0.001; the governance effect (H5) at p = 0.002.

Self-assessment

Where do you stand right now?

Score each statement from 1 to 5. Be honest: if you can't point to a document, a record or a number, the score stays at 2. Your answers stay in your browser.

Before you begin

What this assessment is, and what it is not.

The assessment is a self-assessment against the model. Begin it and you are taking it on these terms:

  1. 1It is educational. It is not an audit, a certification, or legal or security advice for any particular organisation, and what you do with the result is your own responsibility.
  2. 2Your answers stay in this browser. Nothing is sent anywhere unless you choose to share the result yourself, at the end.
  3. 3The model is my work, given for you to measure yourself against and to teach from, naming its source — not to be sold, licensed, or issued as a certificate in its name.

Explore the model

Four dimensions, five levels, one roadmap.

Pick a tab, then click any item to read it. Short by design: the full detail is in the field guide.

Dimensions · A
A

AI governance

Who owns each decision across the model lifecycle, under which document, and with what authority to stop. Not an ethics committee but a traceable accountability path: who authorised deployment, who reviews impact, and who can withdraw a model this week.

Maturity evidence
  • ISO/IEC 42001 AI management system
  • Approved model register
  • Roles & responsibilities matrix
  • Pre-deployment impact assessment
  • Documented stop authority

About the model

My doctoral research, set out in the Applied Research Study (2026) · registered with the UAE Ministry of Economy and Tourism, certificate 3414-2026.

How to cite

Elgendi, M. F. (2026). UCSMM: An applied research study for the AI-powered post-digital enterprise (Registration No. 3414-2026). Fawzooz. https://fawzooz.ai/ucsmm