Governance Definitions
As discussed in the Governance Twin Factor, your governance definitions should be a created as a set of structured entities, managed alongside the sensitive activity in question.
For machine-readable shapes, see the Gemara schemas.
How the definitions connect
The diagram below shows how definition catalogs relate: principles, vectors and guidance feed controls and risks; policy imports those controls and treats the risks.
Definition artifacts
Principle
Foundational values that guide governance, design, and operational decisions.
Vector
Attack vectors and techniques used to compromise information systems.
Guidance
High-level guidance on cybersecurity measures from industry groups and standards bodies.
Capability
Capabilities are the features or elements of useful behaviour provided by a sensitive activity.
Threat
A specifically-scoped opportunity for a negative impact to the organization.
Control
Technology-specific, threat-informed security controls for protecting information systems.
Risk
Organizational risk categories, severity levels, and risk appetite definitions.
Policy
Risk-informed guidance tailored to your organization's specific needs and risk appetite.