Skip to main content

Custom Process in Maturity Assessment

Create and assign custom security processes to NIST subcategories in the Cye Exposure Management Platform.

Overview

Not all organizations use off-the-shelf security processes. If an internal process has been developed — such as a unique audit protocol or custom compliance workflow — it can be represented in the Cye Exposure Management Platform by creating a custom process asset. This article explains how to add and link custom processes so they contribute to maturity scoring.


When to Use a Custom Process

Use a custom process when:

  • The security process is specific to the organization

  • It's not listed among predefined process types

  • It still needs to be reflected in the maturity assessment


How to Create a Custom Security Process

Option 1: From the Assets Page

  1. Go to the Assets page

  2. Click the + button to add a new asset:


Option 2: From the Maturity Screen

  1. In the Processes section of a subcategory

  2. Click the + button to launch the asset creation form:


Completing the Asset Form

  1. Select "Security Process" as the asset type

    • This flags it as a process for maturity scoring:

  2. Enter a process name (e.g., "Quarterly Access Review Workflow"):

  3. Choose the appropriate engagement

  4. Assign the asset to a NIST subcategory under the primary framework

    • Completing the section for other frameworks is optional:

  5. Click Create

Once saved, the custom process appears as a linked process for the selected subcategory in the maturity screen:


Wrap-up / Next Steps

Custom processes ensure internal best practices are represented in the maturity score — even if they don't follow a template. Map them to the right subcategories to ensure they are included in maturity calculations.

For the full list of processes Cye supports out of the box and their NIST mappings, see the Appendix: Supported Mitigations and Their NIST Mapping.

Did this answer your question?