Skip to main content

Processes in the Maturity Assessment

Use process assets to strengthen subcategory maturity scores in the Cye Exposure Management Platform.

Updated this week

Overview

Processes play a key role in shaping cybersecurity maturity. In the Cye Exposure Management Platform, structured security processes — like alert handling or postmortems — can be linked to specific NIST subcategories. These linked processes help improve the maturity score when used appropriately.


What Is a Process Asset?

A process is a collection of structured activities or tasks designed to achieve a security-related outcome. Examples include:

  • Two-factor authentication enforcement

  • Incident postmortem reviews

  • Vulnerability triage workflows

In the Cye Exposure Management Platform, these are added as assets and linked to NIST subcategories to reflect their contribution to the security posture.


How Process Assets Affect Maturity Scoring

  • Linked processes are assigned a default maturity level of 3

  • This value is editable

  • The score is only used if it increases the current subcategory maturity score

    • Example: If a subcategory's score is 2.5, a process score of 3 will help raise it

    • If the score is already above 3, the process asset is ignored to avoid lowering the score

  • Changing a process's maturity level updates all subcategories it's linked to

⚠️ If a process provides partial coverage, or requires additional processes to be effective, create a finding to reflect that gap.


How to Add a Process Asset

Option 1: Add a Suggested Process

  • If a subcategory is missing a mapped process, the Cye platform will suggest relevant ones:

  • Click the + button (if asset creation permissions are available):

  • Fill in the asset details:

    • Process type

    • Process name

    • Engagement

    • Primary NIST subcategory (required)

  • Click Create


Option 2: Add a Process You Define

  • If no suggestions appear, a custom process can be created

  • In the Asset creation screen, click + New next to the type dropdown

  • Follow the same steps to define and save the asset

Only one process asset can be added at a time, but the same asset can apply to multiple subcategories.


Managing Process Assets

  • Go to the Assets page

  • Use the Unmapped Framework filter to find process assets not linked to NIST CSF

  • To view or edit linked subcategories:

    • Open the asset and go to the Standards tab in the right-hand pane:

    • The primary framework (set by an admin) must be completed for scoring impact


Wrap-up / Next Steps

Processes are a powerful way to reflect real-world implementation of security practices. By mapping them to the right subcategories, maturity scores will align with what's actually being done — not just what's on paper.

Did this answer your question?