Skip to main content

Technologies in the Maturity Assessment

Understand how linked technology assets contribute to maturity scoring in the Cye Exposure Management Platform.

Overview

In the Cye Exposure Management Platform, technologies such as EDR or SIEM can be linked to NIST subcategories to reflect the organization's security tooling. These linked technologies contribute positively to the maturity score — as long as they genuinely enhance coverage. This article explains how linked technologies are scored, how to add them, and when to create a finding instead.


How Technologies Affect Maturity Scores

  • Linked technologies are assigned a default maturity level of 3

  • This value is editable

  • The Cye platform incorporates this score only if it increases the subcategory's existing score

    • Example: If a subcategory score is 2.5, a linked technology with a value of 3 will raise it

    • If the subcategory score is already above 3, the technology will be ignored to avoid lowering the score

  • Changing a technology's maturity level updates all subcategories it's linked to


When to Use a Finding Instead

If a technology provides only partial coverage or needs to be supplemented with additional tools:

  • Create a finding to represent the shortfall

  • This helps reflect the gap accurately and ensures the maturity score isn't overestimated

  • Once the gap is resolved and the finding is marked fixed, the technology's full positive impact on the maturity score is restored


Adding Technology Assets

Option 2: From the Maturity Screen

Asset creation can also be started directly from a subcategory, instead of from the Assets page:

  • In the Linked Technologies section of a subcategory, click the + button to start the asset creation process:

Option 1: From the Assets Page

  1. Go to the Assets page

    • Use the Unmapped Framework filter to find technologies not assigned to a NIST framework:

    • Select a framework to view unmapped technology and process assets:

  2. Add a Suggested Technology

    • If the Cye platform detects a relevant subcategory without a linked technology, it will suggest assets to add:

    • Click the + button to add (grayed out if permissions are insufficient)

    • A new technology can also be manually added if no suggestions are listed

  3. Complete the Asset Form

    • Fill out required fields, including:

      • Technology type (e.g., SIEM) — see the full list of supported types below

      • Tool name

      • Engagement (choose one or use a dedicated one for separation)

      • Function, Category, Subcategory (under the primary framework only)

    • Click Create

Note: One technology asset can be applied to multiple subcategories if relevant. Only one asset can be created at a time — repeat as needed.


Using a technology that isn't in the predefined list?

If your organization uses a security tool that isn't listed among the predefined technology types on the Assets page, it can still be represented and contribute to maturity scoring:

  • Select Security Technology as the asset type — this flags it as a custom technology for maturity scoring

  • Enter a tool name (e.g., "Internal Threat Analytics")

  • Choose an engagement, and assign the asset to a NIST subcategory under the primary framework, the same as above

  • Click Create — the custom technology will appear as a linked technology on the maturity assessment screen for the selected subcategory


Full List of Technology Asset Types

  • API Security

  • Asset Management

  • Backup and Recovery Systems

  • BAS (Breach and Attack Simulation)

  • BMS (Building Management System)

  • CASB (Cloud Access Security Broker)

  • CDR (Content Disarm and Reconstruction)

  • CNAPP (Cloud Native Application Protection Platform)

  • CRQ (Cyber Risk Quantification)

  • CSPM (Cloud Security Posture Management)

  • DAST (Dynamic Application Security Testing)

  • Data Flow Mapping Tool

  • Database Firewall

  • Database Web Application Firewall

  • Deception Tools

  • Digital Forensic Software

  • DLP (Data Loss Prevention)

  • DNS Security Tools

  • EDR or XDR (Endpoint Detection and Response)

  • EFSS (Enterprise File Sync and Share)

  • Email Security

  • Firewall

  • Firewall Analyzer

  • GRC (Governance, Risk & Compliance)

  • IDP or IAM (Identity and Access Management)

  • IDS or IPS (Intrusion Detection and Prevention System)

  • KMS (Key Management Service)

  • MDM (Mobile Device Management)

  • MDR (Managed Detection and Response)

  • NAC (Network Access Control)

  • PAM (Privileged Access Management)

  • Password Management Vault

  • Patch Management

  • Reverse Proxy

  • Safe Browsing

  • SAST (Static Application Security Testing)

  • Secure Web Gateway

  • SIEM (Security Information and Event Management)

  • SOAR System (Security Orchestration, Automation and Response) & Automated Playbooks

  • SSO (Single Sign On)

  • TIP (Threat Intelligence Platform)

  • URL Filtering

  • Vendor Management

  • VM (Vulnerability Management)

  • Vulnerability Assessment and Network Scanning

  • WAF (Web Application Firewall)

  • Zero Trust Network Access (ZTNA)


Important Notes

  • Technology assets directly influence maturity scoring in Cye

  • Cye itself is automatically added as a CRQ (Cyber Risk Quantification) technology asset:

  • You can edit or remove NIST subcategory assignments later if needed


Wrap-up / Next Steps

Linking technologies is a smart way to show investment in protective tools and improve the maturity score — but only when the tools are meaningful and mapped correctly. Review assets regularly and make sure they reflect the real state of the security posture.

For the full list of technologies Cye supports and their NIST mappings, see the Appendix: Supported Mitigations and Their NIST Mapping.

Did this answer your question?