Overview
Processes play a key role in shaping cybersecurity maturity. In the Cye Exposure Management Platform, structured security processes — like alert handling or postmortems — can be linked to specific NIST subcategories. These linked processes help improve the maturity score when used appropriately.
What Is a Process Asset?
A process is a collection of structured activities or tasks designed to achieve a security-related outcome. Examples include:
Two-factor authentication enforcement
Incident postmortem reviews
Vulnerability triage workflows
In the Cye Exposure Management Platform, these are added as assets and linked to NIST subcategories to reflect their contribution to the security posture.
How Process Assets Affect Maturity Scoring
Linked processes are assigned a default maturity level of 3
This value is editable
The score is only used if it increases the current subcategory maturity score
Example: If a subcategory's score is 2.5, a process score of 3 will help raise it
If the score is already above 3, the process asset is ignored to avoid lowering the score
Changing a process's maturity level updates all subcategories it's linked to
⚠️ If a process provides partial coverage, or requires additional processes to be effective, create a finding to reflect that gap.
How to Add a Process Asset
Starting From the Maturity Screen
Asset creation can also be started directly from a subcategory, instead of from the Assets page:
Option 1: Add a Suggested Process
If a subcategory is missing a mapped process, the Cye platform will suggest relevant ones:
Click the + button (if asset creation permissions are available):
Fill in the asset details:
Process type — see the full list of supported types below
Process name
Engagement
Primary NIST subcategory (required)
Click Create
Option 2: Add a Process You Define
Use this when the security process is specific to your organization and isn't listed among the predefined process types
If no suggestions appear, a custom process can be created
In the Asset creation screen, select Security Process as the type
Enter a process name (e.g., "Quarterly Access Review Workflow")
Follow the same steps to define and save the asset
Only one process asset can be added at a time, but the same asset can apply to multiple subcategories.
Managing Process Assets
Go to the Assets page
Use the Unmapped Framework filter to find process assets not linked to NIST CSF
To view or edit linked subcategories:
Full List of Process Asset Types
Alert handling process
Alert improvement process
Annual risk management review committee
Annual tabletop exercise
Authentication enforcement
BCP (Business Continuity Plan) drills
BCP (Business Continuity Planning) policy
BCP annual update and approval
BCP is communicated
Block network access
C-level management sponsorship
C-level tabletop drills
Central management (centralized security management)
Change Management
Change management procedure
Cloud governance policy
Conditional access policy review
Crown jewels analysis
CTI signals handling process
DAM (Database activity monitoring)
Data disposal procedure
Data mapping
Data protection policy
Data source health verification process
DDOS response process
Device onboarding offboarding
DR (Disaster Recovery) procedure
DRP (Digital risk protection) annual review
Employee internal mobility procedure
Employee onboarding offboarding Process
Escalation procedure
Event handling process
Forensics and mitigation planning
Forensics package collection process
GPOs (Deploying hardened Group Policy Objects)
Host and network isolation process
Implement and enforce a strong password policy
Inactive users review
Incident management and response
Incident management procedure
Incident reporting procedure
Information security policy review and annual approval
Information sharing policy
Information sharing procedure
IR (Incident response) drills
IR tabletop drills
IRP (Incident Response Plan) annual review
IRP (Incident Response Plan) annual update and approval
IRP (Incident Response Plan) Is communicated
KPIs are defined
KPIs communication policy
Legal implications analysis
Legal security communication process
Maintenance procedures
Network agent review process
Network segmentation and segregation
New initiative security approval
New security initiative approval
OT environment security strategy
OT security
Patching practice
Periodic application security bug analysis
Periodic awareness training
Phishing campaigns program
Physical security dispatch policies & procedures
Physical security policy and procedure
Policy communication to the organization
Post-mortem process
Privileged accounts hardening
PT (Penetration testing)
Purple team drills
Red team drills
Remote support procedure
Response plan drills
Restore drills
Restore process
Risk management process
Risk matrix annual review
Role based awareness training
Roles and responsibilities definition
RTO RPO policy
SAAS and on prem product catalog
Screening procedure
Secure Software Development Life Cycle (SDLC)
Security controls roles and responsibilities
Security monitoring policy
Security steering committee
Sensitive data removal and credentials rotation
Severity criteria
SIEM change management process
SOC playbooks and investigation procedure
SOC tiering structure
SOD (Segregation of duties)
Supply chain self assessment
System capacity testing
System hardening procedure
Temporary folders in file shares created
User access review
Vendor management Processes
Vendor on site support procedure
Vendor remote connection approval process
Vendors management procedure
Vendors onboarding procedure
Vendors remote access procedure
Vendors remote connection process
Visitors to physical sites procedure
Vulnerability KPI tracking
Web asset hardening
Wrap-up / Next Steps
Processes are a powerful way to reflect real-world implementation of security practices. By mapping them to the right subcategories, maturity scores will align with what's actually being done — not just what's on paper.
For the full list of processes Cye supports and their NIST mappings, see the Appendix: Supported Mitigations and Their NIST Mapping.






