Measure frameworks
Administrators only: This page describes a setting reserved for organisation administrators.
Measure frameworks (or catalogues) gather reusable security controls. They feed the AI when generating remediation measures in projects.
Role of the frameworks
When an analyst generates the measures of a project, the platform relies on the catalogues assigned to that project to suggest controls aligned with a recognised standard or with the organisation's internal policy.
A catalogue can have a Global scope (available for all projects of the organisation) or a Per project scope (assigned on demand).
Default catalogues
Three catalogues are delivered by default by CyberLift Software:
- MITRE ATT&CK Enterprise
- MITRE ATT&CK ICS
- MITRE ATT&CK Mobile
The default catalogues are neither editable nor deletable. To have a custom framework, create a new catalogue via the dedicated button.
Frameworks table
The page presents all the catalogues available in the organisation:
| Column | Content |
|---|---|
| Reference | Short code of the catalogue |
| Scope | Global or Per project |
| Title | Catalogue label |
| Description | Detailed description |
| Number of measures | Size of the catalogue |
| Action | Measures |
Measures action
The Measures action opens a window listing all the measures of the catalogue, each with its Reference and Description. This view lets you quickly browse the content of the catalogue before assigning it to a project.
Create a custom catalogue
You can create a catalogue specific to your organisation to reflect an internal policy or a specific framework (ISO 27002, NIST CSF, etc.).
The creation form requires three pieces of information:
- Title — catalogue label
- Reference — short code used in the measure references
- Description — catalogue presentation
Once the catalogue is created, you add measures one by one, providing the Reference and Description for each.
Adding measures is currently a manual process. Bulk import is not available; plan the time needed to build a complete catalogue.