Skip to content

Libraries

A library is a bundle of catalog content distributed as a single file: a framework, a risk matrix, a threat catalogue, a set of reference controls, a mapping between two frameworks, or several of these at once. Libraries are how content gets into CyberGuard — until a library is loaded, none of the content it carries is available anywhere else in the platform.

Governance → Libraries in the sidebar. The page is visible to users who can add catalog objects; only administrators can load or unload.

Every library on the page is in one of two states:

  • Stored — the file has been parsed and registered, but its content is inactive. It sits in the libraries store waiting to be loaded.
  • Loaded — the content is live. A loaded framework can be picked when creating an audit, a loaded risk matrix can scale a risk assessment, loaded threats appear in the threats list, and loaded reference controls start suggesting applied controls.

Loading is deliberate, not automatic: the built-in catalogue ships with the platform in the stored state so your instance only carries the frameworks you actually work against.

Each row shows the library’s Provider, whether it is Built-in, its Reference ID, Name, Description, Language, Publication date, and an Overview of the objects it will contribute. Opening a row shows its full content and its URN — an immutable identifier that survives renames and re-imports, and the key that lets CyberGuard recognise a later version of the same library.

A library may declare dependencies on other libraries; loading it loads what it depends on. A framework library, for example, commonly depends on its companion reference-control catalogue.

Use the quick filters above the table to narrow the store by object type — Frameworks, Reference controls, Risk matrices, Threats, TTP catalogs, Metric definitions, Requirement mapping sets, Workflows, Journeys — or by Update available. The search bar matches on name, reference ID and provider.

The import icon on a stored row loads the library. Once loaded, the row’s actions change:

  • Unload appears only while nothing references the library. A framework used by an audit, or a matrix used by a risk assessment, cannot be unloaded until those objects are gone — this is what keeps past audits readable.
  • Loading and unloading are restricted to administrators, so catalog content stays consistent across every domain.

Add your own library uploads a custom library file, in either YAML or Excel format. Use it for internal frameworks, house control catalogues, or a crosswalk you maintain yourself. Custom libraries behave exactly like built-in ones once loaded, including versioning.

When a newer version of a loaded library becomes available, the row is flagged and an Update this library action appears. Applying it pulls the increment in place — corrected wording, new implementation groups, added requirements — without recreating the library.