The document presents an Information Security Maturity Model (ISMM) developed to evaluate organizational security capabilities, linking security requirements to business goals through a domain-based approach that considers governance, culture, system architecture, and service management. The proposed model outlines five levels of compliance, detailing specific characteristics and processes at each level to guide organizations in enhancing their security practices. The ISMM aims to narrow the gap between theoretical security frameworks and practical implementation, promoting continuous improvement in organizational security.