Skip to main content

Processes in the Maturity Assessment

Use process assets to strengthen subcategory maturity scores in the Cye Exposure Management Platform.

Overview

Processes play a key role in shaping cybersecurity maturity. In the Cye Exposure Management Platform, structured security processes — like alert handling or postmortems — can be linked to specific NIST subcategories. These linked processes help improve the maturity score when used appropriately.


What Is a Process Asset?

A process is a collection of structured activities or tasks designed to achieve a security-related outcome. Examples include:

  • Two-factor authentication enforcement

  • Incident postmortem reviews

  • Vulnerability triage workflows

In the Cye Exposure Management Platform, these are added as assets and linked to NIST subcategories to reflect their contribution to the security posture.


How Process Assets Affect Maturity Scoring

  • Linked processes are assigned a default maturity level of 3

  • This value is editable

  • The score is only used if it increases the current subcategory maturity score

    • Example: If a subcategory's score is 2.5, a process score of 3 will help raise it

    • If the score is already above 3, the process asset is ignored to avoid lowering the score

  • Changing a process's maturity level updates all subcategories it's linked to

⚠️ If a process provides partial coverage, or requires additional processes to be effective, create a finding to reflect that gap.


How to Add a Process Asset

Starting From the Maturity Screen

Asset creation can also be started directly from a subcategory, instead of from the Assets page:

  • In the Processes section of a subcategory, click the + button to launch the asset creation form:

Option 1: Add a Suggested Process

  • If a subcategory is missing a mapped process, the Cye platform will suggest relevant ones:

  • Click the + button (if asset creation permissions are available):

  • Fill in the asset details:

    • Process type — see the full list of supported types below

    • Process name

    • Engagement

    • Primary NIST subcategory (required)

  • Click Create


Option 2: Add a Process You Define

  • Use this when the security process is specific to your organization and isn't listed among the predefined process types

  • If no suggestions appear, a custom process can be created

  • In the Asset creation screen, select Security Process as the type

  • Enter a process name (e.g., "Quarterly Access Review Workflow")

  • Follow the same steps to define and save the asset

Only one process asset can be added at a time, but the same asset can apply to multiple subcategories.


Managing Process Assets

  • Go to the Assets page

  • Use the Unmapped Framework filter to find process assets not linked to NIST CSF

  • To view or edit linked subcategories:

    • Open the asset and go to the Standards tab in the right-hand pane:

    • The primary framework (set by an admin) must be completed for scoring impact


Full List of Process Asset Types

  • Alert handling process

  • Alert improvement process

  • Annual risk management review committee

  • Annual tabletop exercise

  • Authentication enforcement

  • BCP (Business Continuity Plan) drills

  • BCP (Business Continuity Planning) policy

  • BCP annual update and approval

  • BCP is communicated

  • Block network access

  • C-level management sponsorship

  • C-level tabletop drills

  • Central management (centralized security management)

  • Change Management

  • Change management procedure

  • Cloud governance policy

  • Conditional access policy review

  • Crown jewels analysis

  • CTI signals handling process

  • DAM (Database activity monitoring)

  • Data disposal procedure

  • Data mapping

  • Data protection policy

  • Data source health verification process

  • DDOS response process

  • Device onboarding offboarding

  • DR (Disaster Recovery) procedure

  • DRP (Digital risk protection) annual review

  • Employee internal mobility procedure

  • Employee onboarding offboarding Process

  • Escalation procedure

  • Event handling process

  • Forensics and mitigation planning

  • Forensics package collection process

  • GPOs (Deploying hardened Group Policy Objects)

  • Host and network isolation process

  • Implement and enforce a strong password policy

  • Inactive users review

  • Incident management and response

  • Incident management procedure

  • Incident reporting procedure

  • Information security policy review and annual approval

  • Information sharing policy

  • Information sharing procedure

  • IR (Incident response) drills

  • IR tabletop drills

  • IRP (Incident Response Plan) annual review

  • IRP (Incident Response Plan) annual update and approval

  • IRP (Incident Response Plan) Is communicated

  • KPIs are defined

  • KPIs communication policy

  • Legal implications analysis

  • Legal security communication process

  • Maintenance procedures

  • Network agent review process

  • Network segmentation and segregation

  • New initiative security approval

  • New security initiative approval

  • OT environment security strategy

  • OT security

  • Patching practice

  • Periodic application security bug analysis

  • Periodic awareness training

  • Phishing campaigns program

  • Physical security dispatch policies & procedures

  • Physical security policy and procedure

  • Policy communication to the organization

  • Post-mortem process

  • Privileged accounts hardening

  • PT (Penetration testing)

  • Purple team drills

  • Red team drills

  • Remote support procedure

  • Response plan drills

  • Restore drills

  • Restore process

  • Risk management process

  • Risk matrix annual review

  • Role based awareness training

  • Roles and responsibilities definition

  • RTO RPO policy

  • SAAS and on prem product catalog

  • Screening procedure

  • Secure Software Development Life Cycle (SDLC)

  • Security controls roles and responsibilities

  • Security monitoring policy

  • Security steering committee

  • Sensitive data removal and credentials rotation

  • Severity criteria

  • SIEM change management process

  • SOC playbooks and investigation procedure

  • SOC tiering structure

  • SOD (Segregation of duties)

  • Supply chain self assessment

  • System capacity testing

  • System hardening procedure

  • Temporary folders in file shares created

  • User access review

  • Vendor management Processes

  • Vendor on site support procedure

  • Vendor remote connection approval process

  • Vendors management procedure

  • Vendors onboarding procedure

  • Vendors remote access procedure

  • Vendors remote connection process

  • Visitors to physical sites procedure

  • Vulnerability KPI tracking

  • Web asset hardening


Wrap-up / Next Steps

Processes are a powerful way to reflect real-world implementation of security practices. By mapping them to the right subcategories, maturity scores will align with what's actually being done — not just what's on paper.

For the full list of processes Cye supports and their NIST mappings, see the Appendix: Supported Mitigations and Their NIST Mapping.

Did this answer your question?