Skip to content

Library upgrade

Libraries are versioned. When the publisher issues a correction — a fixed typo, a clarified requirement, a new implementation group, an extra reference control — CyberGuard can pull that version into the content you already loaded, and the audits built on it follow along. This is how a framework stays current without anyone recreating an assessment from scratch.

Governance → Libraries. The list carries a set of quick filters across the top; Update available narrows it to exactly the libraries where a newer version is waiting.

  1. Go to Governance → Libraries and select the Update available quick filter.

  2. Find the library you want. Rows with an upgrade show a green circle-up action, Update this library.

  3. Select it. The new version is loaded and the objects it contains — requirements, reference controls, threats, matrices — are refreshed in place.

Upgrades are designed to be non-destructive. Your answers, scores, observations, evidence and applied-control links stay attached to the requirements they were recorded against.

Some upgrades move the score boundaries of a framework — a 0-to-5 scale becoming 0-to-100, for example. That cannot be resolved automatically, so CyberGuard stops and asks. A Score change detected dialog appears, naming the framework and the number of affected assessments, and offers three strategies:

StrategyWhat it does
Rule of ThreeScales every existing score proportionally from the old range into the new one.
ClampKeeps each score as-is, pulling anything outside the new bounds back to the nearest limit.
ResetClears all scores on the affected assessments so they are scored again from scratch.

Rule of Three preserves relative standing and is the usual choice. Clamp suits a boundary that barely moved. Reset is the honest option when the new scale means something genuinely different from the old one.

If an upgrade removes or renames an implementation group, CyberGuard cannot tell the two cases apart, so it drops the stale entries from every audit that had selected them. Those audits fall back to covering all requirements until someone re-selects. After upgrading a framework that reworked its groups, open the affected audits and set Selected implementation groups again.

The same mechanism works for content you authored yourself, provided you respect the versioning contract: publish the new file with an incremented version and the same URN, and it shows up as an available update on the library that is already loaded.

  • Libraries — loading, browsing and unloading library content.
  • Frameworks — what a framework library contains.
  • Multi-level frameworks — re-selecting implementation groups after an upgrade.
  • Audits — the assessments an upgrade flows into.