Skip to content

Extra tools

Beyond the modules that hold your data, CyberGuard ships two small tools that exist purely to improve the quality of what is already in there. Neither creates objects; both answer a question you would otherwise have to answer by reading everything.

X-rays sweeps your assessments for inconsistencies and reports what it finds, grouped by domain. It is the fastest way to answer “is this assessment actually finished, or does it just look finished?”

Where to find it: Operations → X-rays.

Results are grouped per domain, with separate tabs for Compliance assessments and Risk assessments, and a count badge on each. Within a tab, every finding carries one of three levels:

LevelMeaning
ErrorSomething that must be corrected. The assessment is inconsistent as it stands.
WarningA probable problem that needs a human to judge.
InfoAdvice or a reminder — a status left at its default, a relevant field left empty.

Typical catches are an audit whose requirements are answered but whose applied controls have no owner or ETA, a risk scenario with no assets attached, a control whose ETA has passed while its status is still in progress, or an assessment with no author.

Deciding a probability and an impact for a risk scenario is the part where teams argue longest and converge least. The scoring assistant turns that judgement into a set of small, concrete questions and derives a risk level from the answers.

Where to find it: Risk → Scoring assistant.

It follows the OWASP Risk Rating Methodology. Pick the risk matrix to score against, then work through four groups of factors:

  • Threat agent factors — how skilled, motivated, resourced and numerous the attacker would have to be.
  • Vulnerability factors — how easy the weakness is to discover and exploit, and how likely the attempt is to be noticed.
  • Business impact factors — what it costs the organisation: financial damage, reputation, non-compliance, privacy.
  • Technical impact factors — what it costs the system: loss of confidentiality, integrity, availability, accountability.

Each group produces an average, and the matrix derives a level from the combination. Business impact is used by default; tick Ignore on that panel to score on technical impact instead, which is the right choice when the business consequences genuinely are not known yet.

Treat the result as a considered starting point rather than a verdict. Its real value is that two people scoring the same scenario separately will land close to each other, and can see exactly which factor they disagreed on.

  • Applied controls — where most X-rays findings point.
  • Audits — the compliance side of an X-rays sweep.
  • General tips — where these checks fit into a routine.
  • Glossary — the vocabulary behind the scores.