Apply · Practices
The practice model
Every virtue, four bands, twenty practices. Foundation makes the behaviour explicit; Controlled embeds it into the operating model; Measured verifies it happens; Adaptive changes it when the evidence says it is no longer enough.
A band is not a maturity score. A team can be strong in one virtue and weak in another. Read a virtue upward: each band assumes the one before it.
- 01Virtue
- 02Behaviour
- 03Practice
- 04Control
- 05Evidence
- 06Assessment
The model at a glance
Table scrolls horizontally.
| Virtue | 1 · Foundation | 2 · Controlled | 3 · Measured | 4 · Adaptive |
|---|---|---|---|---|
| 義Gi | Make ownership explicit | Control decisions and privilege | Measure attribution | Improve accountability |
| 勇Yū | Enable investigation | Formalise response | Measure investigation | Adapt detection and response |
| 仁Jin | Understand users | Design usable controls | Measure friction | Continuously redesign |
| 礼Rei | Define boundaries | Enforce least privilege | Test boundaries | Continuously re-authorise |
| 誠Makoto | Define truth | Control data quality | Measure accuracy | Automate trust and uncertainty |
| 名誉Meiyo | Define the standard | Assure the controls | Measure effectiveness | Raise and adapt the standard |
| 忠義Chūgi | Define responsibility | Embed stewardship | Measure participation | Distribute responsibility |
| 自制Jisei | Define discipline | Control actions | Measure exceptions | Design for pressure |
01 / 08
Gi
Integrity / rectitude
In one line · Own your actions.
1 / 4 Foundation
Make the behaviour explicit and repeatable.
Record security decisions
Keep a decision record for significant changes, exceptions and risk acceptances.
Discipline: KatanaAnalyse
2 / 4 Controlled
Embed the behaviour into processes and ownership.
Preserve audit trails
Ensure administrative actions cannot be altered or deleted by the same identity that performs them.
Discipline: KatanaAnalyse
3 / 4 Measured
Verify that the behaviour is happening and that it works.
Audit attribution
Periodically test whether consequential administrative actions can actually be attributed to an individual.
Discipline: KatanaAnalyse
Test decision records
Sample architecture and security decisions and verify that the stated owner, evidence and approval exist.
Discipline: KatanaAnalyse
4 / 4 Adaptive
Use evidence to improve the behaviour and respond to change.
Reduce manual attribution
Automate identity correlation across PAM, IAM, SIEM and infrastructure platforms.
Discipline: KatanaAnalyse
02 / 08
Yū
Courage
In one line · Act under uncertainty.
1 / 4 Foundation
Make the behaviour explicit and repeatable.
Define escalation thresholds
Give analysts clear conditions under which suspicious activity must be escalated.
Discipline: KatanaAnalyse
Run basic threat hunts
Regularly investigate behaviours that existing detections may miss.
Discipline: KatanaAnalyse
Document uncertainty
Allow incident teams to record hypotheses as hypotheses instead of forcing premature conclusions.
Discipline: KatanaAnalyse
2 / 4 Controlled
Embed the behaviour into processes and ownership.
Establish independent escalation
Allow analysts to escalate significant concerns without requiring approval from the team being investigated.
Discipline: KatanaAnalyse
3 / 4 Measured
Verify that the behaviour is happening and that it works.
Measure detection-to-investigation time
Track how quickly suspicious signals receive meaningful investigation.
Discipline: KatanaAnalyse
Measure investigation outcomes
Record how many hunts produce new detections, vulnerabilities, compromised assets or useful negative findings.
Discipline: KatanaAnalyse
Review closed alerts
Sample alerts closed as benign and test whether the reasoning was sound.
Discipline: KatanaAnalyse
03 / 08
Jin
Benevolence
In one line · Design for the people using the control.
2 / 4 Controlled
Embed the behaviour into processes and ownership.
Measure friction
Track access-request time, authentication failures, exception requests and security-related support demand.
Discipline: KatanaAnalyse
3 / 4 Measured
Verify that the behaviour is happening and that it works.
Measure abandonment
Identify security workflows that users start but do not complete.
Discipline: KatanaAnalyse
Measure secure-path adoption
Determine whether users actually use the approved workflow.
Discipline: KatanaAnalyse
Correlate friction with incidents
Look for relationships between difficult controls and unsafe workarounds.
Discipline: KatanaAnalyse
4 / 4 Adaptive
Use evidence to improve the behaviour and respond to change.
Measure security by behaviour
Include user adoption and workaround rates when evaluating whether a control is successful.
Discipline: KatanaAnalyse
04 / 08
Rei
Respect
In one line · Respect boundaries.
3 / 4 Measured
Verify that the behaviour is happening and that it works.
Test access paths
Verify that users cannot reach resources outside their intended scope.
Discipline: KatanaAnalyse
Test segmentation
Verify that prohibited network paths are actually blocked.
Discipline: KatanaAnalyse
Audit access exceptions
Measure how many access decisions bypass the normal process.
Discipline: KatanaAnalyse
05 / 08
Makoto
Sincerity
In one line · Verify reality.
1 / 4 Foundation
Make the behaviour explicit and repeatable.
Distinguish unknown from compliant
Do not treat missing telemetry as a passing result.
Discipline: KatanaAnalyse
Document measurement limits
State what each security metric includes and excludes.
Discipline: KatanaAnalyse
2 / 4 Controlled
Embed the behaviour into processes and ownership.
Validate critical metrics
Check the underlying data behind important dashboards.
Discipline: KatanaAnalyse
Protect security records
Restrict modification and deletion of logs, evidence and audit records.
Discipline: KatanaAnalyse
3 / 4 Measured
Verify that the behaviour is happening and that it works.
Sample compliance claims
Test whether reported compliance matches actual configuration.
Discipline: KatanaAnalyse
4 / 4 Adaptive
Use evidence to improve the behaviour and respond to change.
Link metrics to evidence
Allow important security claims to be traced back to the underlying records.
Discipline: KatanaAnalyse
06 / 08
Meiyo
Honour
In one line · Maintain the standard without supervision.
1 / 4 Foundation
Make the behaviour explicit and repeatable.
Define evidence
Specify what demonstrates that a control operates.
Discipline: KatanaAnalyse
3 / 4 Measured
Verify that the behaviour is happening and that it works.
Measure control effectiveness
Measure whether controls produce the intended result, not only whether they exist.
Discipline: KatanaAnalyse
Report control failures
Include failed controls in management reporting.
Discipline: KatanaAnalyse
Compare internal and external findings
Identify problems that internal assurance should have found earlier.
Discipline: KatanaAnalyse
4 / 4 Adaptive
Use evidence to improve the behaviour and respond to change.
Automate control assurance
Use technical evidence where possible instead of manual evidence collection.
Discipline: KatanaAnalyse
Test before the audit
Use internal assurance to establish the actual state before external scrutiny arrives.
Discipline: KatanaAnalyse
07 / 08
Chūgi
Loyalty
In one line · Treat access as responsibility.
3 / 4 Measured
Verify that the behaviour is happening and that it works.
Review privileged stewardship
Sample privileged users and verify that access remains justified and understood.
Discipline: KatanaAnalyse
08 / 08
Jisei
Self-control
In one line · Control your actions under pressure.
1 / 4 Foundation
Make the behaviour explicit and repeatable.
Record privileged actions
Capture administrative activity in critical environments.
Discipline: KatanaAnalyse
3 / 4 Measured
Verify that the behaviour is happening and that it works.
Measure rollback
Track changes that require rollback and identify recurring causes.
Discipline: KatanaAnalyse
Review manual changes
Identify production changes performed outside approved mechanisms.
Discipline: KatanaAnalyse