X-rays
X-rays is CyberGuard’s standing quality-control surface: a single page that scans every audit and risk assessment you have access to and surfaces inconsistencies, missing data and likely modelling mistakes. It’s how you find the things you forgot at the end of an assessment campaign without opening each assessment one by one. The page runs on every load — there is no trigger button.
Where to find it
Section titled “Where to find it”Operations → X-rays in the sidebar. Findings are grouped by domain, with a tab for audits and a tab for risk assessments in each, and badges showing the count of findings per severity so the worst-affected domains stand out.
Severity tiers
Section titled “Severity tiers”Every finding carries one of three severities:
- Errors (red) — modelling inconsistencies to fix before an assessment counts as complete.
- Warnings (amber) — likely gaps the analyst should confirm or fill in.
- Info (blue) — non-blocking hints and hygiene reminders.
Findings are grouped by issue type first, so seventeen controls missing an ETA read as one section with seventeen entries, each linking straight to the object’s edit page.
What gets checked
Section titled “What gets checked”Risk assessment checks
Section titled “Risk assessment checks”- Assessment level — the assessment is still in progress, or has no author (info); the assessment is empty, with no risk scenario declared yet (warning).
- Risk scenarios — errors for broken risk logic: residual level not assessed while the current level is, residual level, probability or impact higher than the current one, residual lowered without any measure applied, a control listed in both existing and additional controls, or an existing control whose status is not active. Warnings flag a scenario with no current level, or a risk accepted without a risk acceptance attached.
- Applied controls — an ETA in the past is an error; a non-active control with no ETA, no estimated effort or no estimated cost is a warning; a missing external link is info.
- Risk acceptances — an expired acceptance is an error; an acceptance without an expiry date is a warning.
Compliance assessment checks
Section titled “Compliance assessment checks”- Assessment level — in progress, or no author assigned (info).
- Requirement assessments — a requirement marked compliant with no evidence attached, or compliant / partially compliant with no applied control (warnings).
- Applied controls — no reference control selected (info).
- Evidences — an evidence with no file or link uploaded (warning).
The fix loop
Section titled “The fix loop”- Open X-rays and pick the domain with the most red.
- Switch to the right tab and skim the issue-type groups.
- Click a finding — it opens the offending object’s edit form directly.
- Fix, save, return: the finding disappears on the next refresh.
Related
Section titled “Related”- Applied controls — the ETA, effort, cost and link fields several checks target.
- Tasks — schedule the recurring hygiene work X-rays reveals.
