Skip to main content

Governance Definitions

As discussed in the Governance Twin Factor, your governance definitions should be a created as a set of structured entities, managed alongside the sensitive activity in question.

For machine-readable shapes, see the Gemara schemas.

How the definitions connect

The diagram below shows how definition catalogs relate: principles, vectors and guidance feed controls and risks; policy imports those controls and treats the risks.

Definition artifacts

  1. Principle

    Foundational values that guide governance, design, and operational decisions.

  2. Vector

    Attack vectors and techniques used to compromise information systems.

  3. Guidance

    High-level guidance on cybersecurity measures from industry groups and standards bodies.

  4. Capability

    Capabilities are the features or elements of useful behaviour provided by a sensitive activity.

  5. Threat

    A specifically-scoped opportunity for a negative impact to the organization.

  6. Control

    Technology-specific, threat-informed security controls for protecting information systems.

  7. Risk

    Organizational risk categories, severity levels, and risk appetite definitions.

  8. Policy

    Risk-informed guidance tailored to your organization's specific needs and risk appetite.