The Systems module is the centralised catalogue of your systems in a cybersecurity context. It documents what each system is, what data it handles, how it is hosted and what it depends on, so every risk decision rests on accurate knowledge of the estate.
1. What you document per system
- System overview: the system's role and organisational attributes, such as country, functional domain, business unit, criticality and internet-facing status.
- System details: architectural and management information, including system type, accessibility, hosting method and cloud configuration.
- Data information: whether the system handles sensitive information such as Personally Identifiable Information (PII) or Protected Health Information (PHI).
- CIA levels of processed data: classify the processed information types on Confidentiality, Integrity and Availability; CSFaaS derives the Security Objectives and the Overall System Security Categorization.
- Recovery objectives: Recovery Time Objective (RTO) and Recovery Point Objective (RPO), essential for resilience and business continuity.
- Related systems: connect dependent systems to understand how dependencies shape the risk landscape.
- Lifecycle status: move the system through its stages, from Concept and Development to Production or Decommissioned.
The dropdown values across these sections come from your workspace's configuration catalogues (Databases module), and advanced filters keep large inventories manageable.
2. Assessment, sharing and evidence
From a system you can trigger and track risk assessments, send forms to collect classification information, attach evidences, and invite individual stakeholders with Read or Write access to that system only, without opening the whole module to them.
The systems chapter of this documentation details the attributes, the CIA classification and the links to the risk modules.
Privacy note. Personal details in this revision have been removed, masked or replaced for privacy. The original is retained privately.