Skip to content
CyberBushido

Apply · Practices

The practice model

Every virtue, four bands, twenty practices. Foundation makes the behaviour explicit; Controlled embeds it into the operating model; Measured verifies it happens; Adaptive changes it when the evidence says it is no longer enough.

A band is not a maturity score. A team can be strong in one virtue and weak in another. Read a virtue upward: each band assumes the one before it.

  1. 01Virtue
  2. 02Behaviour
  3. 03Practice
  4. 04Control
  5. 05Evidence
  6. 06Assessment

The model at a glance

Table scrolls horizontally.

Each virtue across the four bands, one line per cell.
Virtue1 · Foundation2 · Controlled3 · Measured4 · Adaptive
義GiMake ownership explicitControl decisions and privilegeMeasure attributionImprove accountability
勇YūEnable investigationFormalise responseMeasure investigationAdapt detection and response
仁JinUnderstand usersDesign usable controlsMeasure frictionContinuously redesign
礼ReiDefine boundariesEnforce least privilegeTest boundariesContinuously re-authorise
誠MakotoDefine truthControl data qualityMeasure accuracyAutomate trust and uncertainty
名誉MeiyoDefine the standardAssure the controlsMeasure effectivenessRaise and adapt the standard
忠義ChūgiDefine responsibilityEmbed stewardshipMeasure participationDistribute responsibility
自制JiseiDefine disciplineControl actionsMeasure exceptionsDesign for pressure
Clear

Showing 36 of 160 practices.

義

01 / 08

Gi

Integrity / rectitude

In one line · Own your actions.

1 / 4 Foundation

Make the behaviour explicit and repeatable.

  1. Record security decisions

    Keep a decision record for significant changes, exceptions and risk acceptances.

    Discipline: KatanaAnalyse

2 / 4 Controlled

Embed the behaviour into processes and ownership.

  1. Preserve audit trails

    Ensure administrative actions cannot be altered or deleted by the same identity that performs them.

    Discipline: KatanaAnalyse

3 / 4 Measured

Verify that the behaviour is happening and that it works.

  1. Audit attribution

    Periodically test whether consequential administrative actions can actually be attributed to an individual.

    Discipline: KatanaAnalyse

  2. Test decision records

    Sample architecture and security decisions and verify that the stated owner, evidence and approval exist.

    Discipline: KatanaAnalyse

4 / 4 Adaptive

Use evidence to improve the behaviour and respond to change.

  1. Reduce manual attribution

    Automate identity correlation across PAM, IAM, SIEM and infrastructure platforms.

    Discipline: KatanaAnalyse

Read the full argument
勇

02 / 08

Yū

Courage

In one line · Act under uncertainty.

1 / 4 Foundation

Make the behaviour explicit and repeatable.

  1. Define escalation thresholds

    Give analysts clear conditions under which suspicious activity must be escalated.

    Discipline: KatanaAnalyse

  2. Run basic threat hunts

    Regularly investigate behaviours that existing detections may miss.

    Discipline: KatanaAnalyse

  3. Document uncertainty

    Allow incident teams to record hypotheses as hypotheses instead of forcing premature conclusions.

    Discipline: KatanaAnalyse

2 / 4 Controlled

Embed the behaviour into processes and ownership.

  1. Establish independent escalation

    Allow analysts to escalate significant concerns without requiring approval from the team being investigated.

    Discipline: KatanaAnalyse

3 / 4 Measured

Verify that the behaviour is happening and that it works.

  1. Measure detection-to-investigation time

    Track how quickly suspicious signals receive meaningful investigation.

    Discipline: KatanaAnalyse

  2. Measure investigation outcomes

    Record how many hunts produce new detections, vulnerabilities, compromised assets or useful negative findings.

    Discipline: KatanaAnalyse

  3. Review closed alerts

    Sample alerts closed as benign and test whether the reasoning was sound.

    Discipline: KatanaAnalyse

Read the full argument
仁

03 / 08

Jin

Benevolence

In one line · Design for the people using the control.

2 / 4 Controlled

Embed the behaviour into processes and ownership.

  1. Measure friction

    Track access-request time, authentication failures, exception requests and security-related support demand.

    Discipline: KatanaAnalyse

3 / 4 Measured

Verify that the behaviour is happening and that it works.

  1. Measure abandonment

    Identify security workflows that users start but do not complete.

    Discipline: KatanaAnalyse

  2. Measure secure-path adoption

    Determine whether users actually use the approved workflow.

    Discipline: KatanaAnalyse

  3. Correlate friction with incidents

    Look for relationships between difficult controls and unsafe workarounds.

    Discipline: KatanaAnalyse

4 / 4 Adaptive

Use evidence to improve the behaviour and respond to change.

  1. Measure security by behaviour

    Include user adoption and workaround rates when evaluating whether a control is successful.

    Discipline: KatanaAnalyse

Read the full argument
礼

04 / 08

Rei

Respect

In one line · Respect boundaries.

3 / 4 Measured

Verify that the behaviour is happening and that it works.

  1. Test access paths

    Verify that users cannot reach resources outside their intended scope.

    Discipline: KatanaAnalyse

  2. Test segmentation

    Verify that prohibited network paths are actually blocked.

    Discipline: KatanaAnalyse

  3. Audit access exceptions

    Measure how many access decisions bypass the normal process.

    Discipline: KatanaAnalyse

Read the full argument
誠

05 / 08

Makoto

Sincerity

In one line · Verify reality.

1 / 4 Foundation

Make the behaviour explicit and repeatable.

  1. Distinguish unknown from compliant

    Do not treat missing telemetry as a passing result.

    Discipline: KatanaAnalyse

  2. Document measurement limits

    State what each security metric includes and excludes.

    Discipline: KatanaAnalyse

2 / 4 Controlled

Embed the behaviour into processes and ownership.

  1. Validate critical metrics

    Check the underlying data behind important dashboards.

    Discipline: KatanaAnalyse

  2. Protect security records

    Restrict modification and deletion of logs, evidence and audit records.

    Discipline: KatanaAnalyse

3 / 4 Measured

Verify that the behaviour is happening and that it works.

  1. Sample compliance claims

    Test whether reported compliance matches actual configuration.

    Discipline: KatanaAnalyse

4 / 4 Adaptive

Use evidence to improve the behaviour and respond to change.

  1. Link metrics to evidence

    Allow important security claims to be traced back to the underlying records.

    Discipline: KatanaAnalyse

Read the full argument
名誉

06 / 08

Meiyo

Honour

In one line · Maintain the standard without supervision.

1 / 4 Foundation

Make the behaviour explicit and repeatable.

  1. Define evidence

    Specify what demonstrates that a control operates.

    Discipline: KatanaAnalyse

3 / 4 Measured

Verify that the behaviour is happening and that it works.

  1. Measure control effectiveness

    Measure whether controls produce the intended result, not only whether they exist.

    Discipline: KatanaAnalyse

  2. Report control failures

    Include failed controls in management reporting.

    Discipline: KatanaAnalyse

  3. Compare internal and external findings

    Identify problems that internal assurance should have found earlier.

    Discipline: KatanaAnalyse

4 / 4 Adaptive

Use evidence to improve the behaviour and respond to change.

  1. Automate control assurance

    Use technical evidence where possible instead of manual evidence collection.

    Discipline: KatanaAnalyse

  2. Test before the audit

    Use internal assurance to establish the actual state before external scrutiny arrives.

    Discipline: KatanaAnalyse

Read the full argument
忠義

07 / 08

Chūgi

Loyalty

In one line · Treat access as responsibility.

3 / 4 Measured

Verify that the behaviour is happening and that it works.

  1. Review privileged stewardship

    Sample privileged users and verify that access remains justified and understood.

    Discipline: KatanaAnalyse

Read the full argument
自制

08 / 08

Jisei

Self-control

In one line · Control your actions under pressure.

1 / 4 Foundation

Make the behaviour explicit and repeatable.

  1. Record privileged actions

    Capture administrative activity in critical environments.

    Discipline: KatanaAnalyse

3 / 4 Measured

Verify that the behaviour is happening and that it works.

  1. Measure rollback

    Track changes that require rollback and identify recurring causes.

    Discipline: KatanaAnalyse

  2. Review manual changes

    Identify production changes performed outside approved mechanisms.

    Discipline: KatanaAnalyse

Read the full argument
The practice model — CyberBushido