Skip to content

Features overview

CyberGuard is organized around the way security and compliance work actually flows: you describe your organization, load the standards you answer to, inventory what you protect, run assessments against it, and track the controls and evidence that close the gaps. The sidebar mirrors that flow — each category below is one group in the application, and each page in this section documents one screen inside it.

Two ideas run through everything. Domains scope who sees what and how numbers roll up, so nearly every object you create belongs to a domain. Feature flags decide which categories appear at all — an administrator turns modules on and off under Extra → Settings → Feature flags, so your sidebar may be shorter than the list below. Pages documenting a module that is off by default carry a Flag badge and name the flag at the top. See Feature flags for the full catalog of switches.

If a term is unfamiliar, the Glossary defines it in one line, and The data model shows how the objects connect.

  • Overview — the landing surfaces. Analytics rolls up governance, risk, compliance and operations into one dashboard; Assignments answers “what is on my plate”; custom dashboards and journeys live here too.
  • Organization — the structure everything else hangs off. Domains, perimeters, users, user groups and role assignments define your hierarchy and who can act inside it.
  • Catalog — the reference content you import rather than write. Frameworks, threats, reference controls, cross-framework mappings, risk matrices, security advisories, CWEs and document templates.
  • Asset management — the inventory of what is worth protecting, plus business impact analysis to establish how long each asset can be unavailable.
  • Operations — the daily work. Applied controls, recurring tasks, documents, the calendar, incidents, X-rays consistency checks and automation workflows.
  • Governance — the decisions and the paperwork around them. Libraries, policies, risk acceptances, security exceptions and follow-up binders.
  • Risk — qualitative risk assessments and scenarios, EBIOS RM studies, quantitative studies, the scoring assistant and vulnerability tracking.
  • Compliance — audits against a framework, requirement-by-requirement assessment, evidence collection and the cross-audit recap.
  • Third parties — vendor and supplier risk. Entities, their representatives and solutions, and the questionnaires you send them.
  • Privacy — the records of processing, personal data categories, purposes, data subject right requests and data breaches.
  • Project management — projects, collections, accreditations and responsibility matrices for running security work as a programme.
  • Extra — cross-cutting tools and administration. Labels, terminologies, object classifications, asset classes, settings, the data wizard and backup and restore.

Every page in this section follows the same shape: a short statement of what the module is for, a Where to find it line giving the exact sidebar path, then the concepts, fields and workflows you need to operate it. Links at the bottom point to the sibling screens the module talks to most.