Overview
In some cases, Hyver automatically assigns a maturity level to specific subcategories based on your organization’s association with CYE. This article outlines which subcategories receive default scores, under what conditions, and how you can update them if needed.
When Are Automatic Ratings Applied?
Hyver auto-assigns a maturity level of 3 to certain subcategories for organizations associated with CYE, due to built-in security controls provided as part of the engagement.
Subcategories that receive default scores:
ID.AM-4 – External information systems are cataloged
ID.RA-1 through ID.RA-6 – Risk assessment-related controls
DE.CM-8 – Vulnerability scans are performed
DE.DP-3 – Notifications from detection systems are investigated
Key Behavior
Default level: Assigned score is 3
Override: Users can manually change the score if needed
No overwrite: If a subcategory already has a maturity score, the auto-assigned value will not apply
Wrap-up / Next Steps
Automatic ratings provide a useful starting point but are always editable. If you believe your organization’s implementation differs from the default, you can update the score at any time to ensure your maturity assessment reflects your actual posture.
