Skip to main content

12 docs tagged with "Artifact"

View all tags

Audit Log

Review of organizational policy and conformance.

Capability

Capabilities are the features or elements of useful behaviour provided by a sensitive activity.

Control

Technology-specific, threat-informed security controls for protecting information systems.

Evaluation Log

The results of evaluating a control's assessment requirements.

Guidance

High-level guidance on cybersecurity measures from industry groups and standards bodies.

Policy

Risk-informed guidance tailored to your organization's specific needs and risk appetite.

Principle

Foundational values that guide governance, design, and operational decisions.

Risk

Organizational risk categories, severity levels, and risk appetite definitions.

Sensitive Activity

Actions that might introduce risk—the hinge between definition and measurement.

Threat

A specifically-scoped opportunity for a negative impact to the organization.

Vector

Attack vectors and techniques used to compromise information systems.