Audit Log
Review of organizational policy and conformance.
Review of organizational policy and conformance.
Capabilities are the features or elements of useful behaviour provided by a sensitive activity.
Technology-specific, threat-informed security controls for protecting information systems.
Prevention or remediation based on assessment findings.
The results of evaluating a control's assessment requirements.
High-level guidance on cybersecurity measures from industry groups and standards bodies.
Risk-informed guidance tailored to your organization's specific needs and risk appetite.
Foundational values that guide governance, design, and operational decisions.
Organizational risk categories, severity levels, and risk appetite definitions.
Actions that might introduce risk—the hinge between definition and measurement.
A specifically-scoped opportunity for a negative impact to the organization.
Attack vectors and techniques used to compromise information systems.