Workspace catalogues are the reference lists behind CSFaaS: risk categories, impact types, system criticality levels, third-party tiers and dozens more. They are designed to support taxonomies derived from well-established industry standards and frameworks, ensuring consistency and interoperability across your cybersecurity and risk management practices.
1. Baseline Taxonomies
ENISA (European Union Agency for Cybersecurity)
ENISA provides cybersecurity guidance tailored to European regulatory and operational contexts. It develops taxonomies for cyber threats, attack techniques, risk management methodologies and incident classification (for example the ENISA Threat Taxonomy), helping organisations align with EU policies such as the NIS2 Directive and GDPR.
NIST (National Institute of Standards and Technology)
NIST publishes cybersecurity frameworks and guidelines widely adopted for risk management and compliance. The NIST Cybersecurity Framework (CSF) and Special Publications such as 800-53 (Security and Privacy Controls) and 800-30 (Risk Management Guide) define structured taxonomies for threats, vulnerabilities, risk impacts and mitigation strategies.
ISO (International Organization for Standardization)
ISO develops globally recognised standards across industries, including cybersecurity. Key frameworks such as ISO/IEC 27001 (information security management systems) and ISO/IEC 31000 (risk management) provide structured taxonomies for classifying security controls, risk categories and governance practices.
SABSA (Sherwood Applied Business Security Architecture)
SABSA is a security architecture and risk management framework that aligns security decisions with business objectives. It provides structured taxonomies for security domains, risk categories, governance models and control objectives, so security architectures integrate with enterprise business processes.
VERIS (Vocabulary for Event Recording and Incident Sharing)
VERIS is a structured framework for categorising cybersecurity incidents consistently. Developed by Verizon, it underpins the Verizon Data Breach Investigations Report (DBIR) and defines taxonomies for threat actors, attack actions, impact categories and incident attributes, making it valuable for cybersecurity analytics and reporting.
2. Why Catalogue Flexibility Matters
These taxonomies give your catalogues a foundation aligned with industry best practice and regulatory expectations. On top of that foundation, you can adapt each catalogue to your organisation: show or hide entries, modify them, and maintain them as your context evolves.
This flexibility is important for several reasons:
- Customisation: tailor catalogues to reflect your organisation's own vocabulary, processes and goals.
- Scalability: adapt catalogues as your organisation grows or changes.
- Alignment: stay consistent with industry standards and regulatory requirements.
- Efficiency: keep every module's dropdowns and properties fed from one maintained set of reference data.
3. Where Catalogues Are Managed
Catalogue configuration lives in the Databases module (left menu), under the Configuration Catalogs tab, alongside the Controls Database and the Threat Attacks Database. Editing is governed by the Catalogs permission in your workspace roles.
The next two pages describe how the catalogue editor works and walk through the catalogues module by module.