Beyond the cross-module lists, most catalogues belong to a single module. In the Databases module, Configuration Catalogs tab, they are grouped under the module they power: Risks Module, Policy Module, Systems Module and Third Parties Module. This page gives you a tour of what you will find in each group.
1. Risks Module Catalogues
These catalogues shape risk demands, assessments and the qualitative analysis:
- Impact Types: the impact domains an organisation may face. This catalogue also drives the rows of the Qualitative Matrix (Settings, Qualitative Matrix).
- Risk Categories and Risk Origins: classify the nature and source of each risk.
- Request Priority Levels: the urgency scale for demands. It also drives the default SLA per priority (Settings, Risk Demand).
- Threat Actors, Threat Actions, Threat Vectors and Threat Actor Motivations: standardised threat characterisation used in risk profiling.
- Business Attributes, Business Drivers for Security, Business Goals and Objectives (and their Timelines): SABSA-derived lists linking security work to business strategy.
- Plan Types, Project Phase Levels, Data State Options, Victim Quantification: supporting classifications for assessments and remediation planning.
2. Policy Module Catalogues
These catalogues provide the control properties used across Policies and Controls:
- Control Function (NIST) and Privacy Control Function: the primary function of each control.
- Control Types (ISO): control classification by how they manage risk.
- Information Security Properties: the security properties a control safeguards.
- Maturity Levels (CMM): the maturity scale used when evaluating controls.
- Operational Capabilities and Security Domains (ISO): structure controls by capability and domain.
- Security Control Baseline: benchmark levels of control implementation.
- Periodicity Review Options: the review frequencies offered wherever periodic reviews apply.
3. Systems Module Catalogues
These catalogues describe your asset inventory:
- CIA Levels: the confidentiality, integrity and availability scale applied to the data a system or third party processes.
- System Types, System Domains, System Criticality Options: classify what a system is and how much it matters.
- System Hosting Options, System Management Options, System Accessibility Options: where a system runs, who manages it and who can reach it.
- Cloud Types and Cloud Stack Components: cloud service models and stack layers.
- RPO and RTO: recovery point and recovery time objectives for continuity planning.
4. Third Party Module Catalogues
- Third Party Types: segments third parties by their relationship to your organisation.
- Third Party Tier Levels: ranks third parties by criticality to your operations.
- Third Party IT Providers: the kinds of external IT product and service providers you track.
5. Catalogues with Dedicated Editors
A few catalogues get a purpose-built editor instead of the generic entry list:
- Weighting Levels: defines the weighting scale used across frameworks and policies. Choose how many levels the scale has (3, 5 or 10), then give each level a label and description. Changing the scale adds or removes levels while keeping existing labels; reducing it removes the highest levels.
Note: demands and remediation plans no longer use periodic review schedules; they track deadlines with due dates and SLAs instead. The Periodicity Review Options catalogue applies to the modules that still offer periodic reviews, such as policies and controls.