Catalogues supply the choices used to describe risks, controls, systems, third parties and the business environment. A shared list helps two teams use the same term for the same thing, making filtering and comparisons more useful.
Start with meaning
Agree what each catalogue is intended to describe before changing its entries. A risk category describes a class of risk; an impact type describes a consequence domain. A system's criticality and its recovery time objective answer different questions. Keeping those distinctions clear matters more than adding a long list of options.
Reference vocabulary can support an organisation's chosen framework, but selecting a term does not demonstrate conformity with that framework. Record the relevant publication and edition in your methodology when a classification has a specific external meaning. Use the source's definitions when assessing against it.
Adapt the vocabulary to your workspace
Open Databases and use the Configuration section of its left index. Catalogues are grouped under Risk, Policies, Systems, Third parties and Cross-module. The filter searches the catalogue index; selecting a catalogue opens its entries.
Where editing is allowed, adapt wording, add workspace entries, and hide choices that the team should no longer select. Workspace wording stays within your workspace. Where a row provides View original, use it to compare the local wording with its reference source.
Hide a value when it should leave future pickers but remain understandable in existing records. Existing records can retain their stored value. Hiding a catalogue entry does not delete every system, risk or other record that uses it.
Maintain useful definitions
For each important entry, write a short definition and one practical boundary. For example, explain which operations belong in a business unit or when a system qualifies as critical. Avoid near-duplicate values whose difference assessors cannot explain.
Assign responsibility for reviewing shared lists. A change to a cross-module catalogue can affect the choices shown in several workflows. Review those uses before changing a familiar term, and tell the team when its meaning changes.
Catalogues, risk matrices and permissions have separate purposes. Catalogues provide vocabulary; matrices define assessment criteria; roles determine who can view or change information. Configure all three consistently.