The Enterprise Security Profile Model (ESPM) is:
- The vertical mapping of security controls
- The operational level measurements of control implementations
- The risk-based metrics aggregated into an executive perspective
- The prioritized management of the results for allocating resources in response to the risk