Beyond the cross-module lists, most catalogues belong to a single module. In the Databases module, Configuration Catalogs tab, they are grouped under the module they power: Risks Module, Policy Module, Systems Module and Third Parties Module. This page gives you a tour of what you will find in each group.


1. Risks Module Catalogues

These catalogues shape risk demands, assessments and the qualitative analysis:

  • Impact Types: the impact domains an organisation may face. This catalogue also drives the rows of the Qualitative Matrix (Settings, Qualitative Matrix).
  • Risk Categories and Risk Origins: classify the nature and source of each risk.
  • Request Priority Levels: the urgency scale for demands. It also drives the default SLA per priority (Settings, Risk Demand).
  • Threat Actors, Threat Actions, Threat Vectors and Threat Actor Motivations: standardised threat characterisation used in risk profiling.
  • Business Attributes, Business Drivers for Security, Business Goals and Objectives (and their Timelines): SABSA-derived lists linking security work to business strategy.
  • Plan Types, Project Phase Levels, Data State Options, Victim Quantification: supporting classifications for assessments and remediation planning.

2. Policy Module Catalogues

These catalogues provide the control properties used across Policies and Controls:

  • Control Function (NIST) and Privacy Control Function: the primary function of each control.
  • Control Types (ISO): control classification by how they manage risk.
  • Information Security Properties: the security properties a control safeguards.
  • Maturity Levels (CMM): the maturity scale used when evaluating controls.
  • Operational Capabilities and Security Domains (ISO): structure controls by capability and domain.
  • Security Control Baseline: benchmark levels of control implementation.
  • Periodicity Review Options: the review frequencies offered wherever periodic reviews apply.

3. Systems Module Catalogues

These catalogues describe your asset inventory:

  • CIA Levels: the confidentiality, integrity and availability scale applied to the data a system or third party processes.
  • System Types, System Domains, System Criticality Options: classify what a system is and how much it matters.
  • System Hosting Options, System Management Options, System Accessibility Options: where a system runs, who manages it and who can reach it.
  • Cloud Types and Cloud Stack Components: cloud service models and stack layers.
  • RPO and RTO: recovery point and recovery time objectives for continuity planning.

4. Third Party Module Catalogues

  • Third Party Types: segments third parties by their relationship to your organisation.
  • Third Party Tier Levels: ranks third parties by criticality to your operations.
  • Third Party IT Providers: the kinds of external IT product and service providers you track.

5. Catalogues with Dedicated Editors

A few catalogues get a purpose-built editor instead of the generic entry list:

  • Weighting Levels: defines the weighting scale used across frameworks and policies. Choose how many levels the scale has (3, 5 or 10), then give each level a label and description. Changing the scale adds or removes levels while keeping existing labels; reducing it removes the highest levels.

Note: demands and remediation plans no longer use periodic review schedules; they track deadlines with due dates and SLAs instead. The Periodicity Review Options catalogue applies to the modules that still offer periodic reviews, such as policies and controls.