Apply · Practices
The practice model
Every virtue, four bands, twenty practices. Foundation makes the behaviour explicit; Controlled embeds it into the operating model; Measured verifies it happens; Adaptive changes it when the evidence says it is no longer enough.
A band is not a maturity score. A team can be strong in one virtue and weak in another. Read a virtue upward: each band assumes the one before it.
- 01Virtue
- 02Behaviour
- 03Practice
- 04Control
- 05Evidence
- 06Assessment
The model at a glance
Table scrolls horizontally.
| Virtue | 1 · Foundation | 2 · Controlled | 3 · Measured | 4 · Adaptive |
|---|---|---|---|---|
| 義Gi | Make ownership explicit | Control decisions and privilege | Measure attribution | Improve accountability |
| 勇Yū | Enable investigation | Formalise response | Measure investigation | Adapt detection and response |
| 仁Jin | Understand users | Design usable controls | Measure friction | Continuously redesign |
| 礼Rei | Define boundaries | Enforce least privilege | Test boundaries | Continuously re-authorise |
| 誠Makoto | Define truth | Control data quality | Measure accuracy | Automate trust and uncertainty |
| 名誉Meiyo | Define the standard | Assure the controls | Measure effectiveness | Raise and adapt the standard |
| 忠義Chūgi | Define responsibility | Embed stewardship | Measure participation | Distribute responsibility |
| 自制Jisei | Define discipline | Control actions | Measure exceptions | Design for pressure |
01 / 08
Gi
Integrity / rectitude
In one line · Own your actions.
1 / 4 Foundation
Make the behaviour explicit and repeatable.
Name the decision owner
Every security exception, risk acceptance and material architecture decision has one accountable owner.
Discipline: MetsukePerceive
Define ownership
Every critical security control has an accountable owner and an operational owner.
Discipline: MetsukePerceive
Make escalation explicit
Define who must be informed when a security decision exceeds the team's authority.
Discipline: MetsukePerceive
2 / 4 Controlled
Embed the behaviour into processes and ownership.
Formalise risk acceptance
Define who can accept which level of security risk and for how long.
Discipline: MetsukePerceive
3 / 4 Measured
Verify that the behaviour is happening and that it works.
Review shared accounts
Search for shared, generic and service identities that create attribution gaps.
Discipline: MetsukePerceive
02 / 08
Yū
Courage
In one line · Act under uncertainty.
1 / 4 Foundation
Make the behaviour explicit and repeatable.
Create challenge points
Require security review for architectures and changes that introduce material exposure.
Discipline: MetsukePerceive
2 / 4 Controlled
Embed the behaviour into processes and ownership.
Maintain hunting hypotheses
Turn intelligence, incidents and unusual telemetry into repeatable hunting questions.
Discipline: MetsukePerceive
Protect useful challenge
Create a process for challenging high-risk decisions without turning disagreement into personal conflict.
Discipline: MetsukePerceive
3 / 4 Measured
Verify that the behaviour is happening and that it works.
Test blind spots
Periodically simulate activity that existing detection rules should not identify.
Discipline: MetsukePerceive
4 / 4 Adaptive
Use evidence to improve the behaviour and respond to change.
Challenge detection assumptions
Regularly ask what the SOC cannot currently see and what an attacker could do without generating an alert.
Discipline: MetsukePerceive
03 / 08
Jin
Benevolence
In one line · Design for the people using the control.
1 / 4 Foundation
Make the behaviour explicit and repeatable.
Identify the user
For every important control, identify who operates it and what legitimate task they need to complete.
Discipline: MetsukePerceive
2 / 4 Controlled
Embed the behaviour into processes and ownership.
Design with users
Test security workflows with administrators, developers and business users before deployment.
Discipline: MetsukePerceive
04 / 08
Rei
Respect
In one line · Respect boundaries.
1 / 4 Foundation
Make the behaviour explicit and repeatable.
Define access requirements
Document what access each role actually requires.
Discipline: MetsukePerceive
Identify trust boundaries
Document important identity, network, application and data boundaries.
Discipline: MetsukePerceive
Establish access owners
Every sensitive resource has an owner responsible for access decisions.
Discipline: MetsukePerceive
Classify sensitive information
Define which information requires additional access restrictions.
Discipline: MetsukePerceive
3 / 4 Measured
Verify that the behaviour is happening and that it works.
Measure excessive privilege
Identify users, service accounts and applications with broader access than required.
Discipline: MetsukePerceive
05 / 08
Makoto
Sincerity
In one line · Verify reality.
1 / 4 Foundation
Make the behaviour explicit and repeatable.
Define authoritative sources
Identify which system is authoritative for assets, identities, vulnerabilities, configurations and other security data.
Discipline: MetsukePerceive
Define data ownership
Assign owners to important security datasets.
Discipline: MetsukePerceive
2 / 4 Controlled
Embed the behaviour into processes and ownership.
Reconcile inventories
Compare CMDB, cloud inventories, endpoint platforms, vulnerability scanners and network discovery.
Discipline: MetsukePerceive
3 / 4 Measured
Verify that the behaviour is happening and that it works.
Measure inventory coverage
Track the percentage of assets represented across required security systems.
Discipline: MetsukePerceive
Measure telemetry coverage
Track which critical systems are actually producing the expected logs.
Discipline: MetsukePerceive
4 / 4 Adaptive
Use evidence to improve the behaviour and respond to change.
Make uncertainty operational
Use confidence and coverage information when prioritising security decisions.
Discipline: MetsukePerceive
06 / 08
Meiyo
Honour
In one line · Maintain the standard without supervision.
1 / 4 Foundation
Make the behaviour explicit and repeatable.
Assign control owners
Give every important control a responsible owner.
Discipline: MetsukePerceive
2 / 4 Controlled
Embed the behaviour into processes and ownership.
Separate compliance from security
Track regulatory compliance and internal security objectives separately.
Discipline: MetsukePerceive
07 / 08
Chūgi
Loyalty
In one line · Treat access as responsibility.
1 / 4 Foundation
Make the behaviour explicit and repeatable.
Assign system ownership
Every important system has a named business or technology owner.
Discipline: MetsukePerceive
Define security responsibilities
Make security duties part of relevant roles.
Discipline: MetsukePerceive
2 / 4 Controlled
Embed the behaviour into processes and ownership.
Include security in role definitions
Make security responsibilities explicit for administrators, developers, engineers and system owners.
Discipline: MetsukePerceive
Establish vendor responsibility
Define security responsibilities for third parties with access to company systems.
Discipline: MetsukePerceive
3 / 4 Measured
Verify that the behaviour is happening and that it works.
Measure ownership coverage
Track systems and controls without an accountable owner.
Discipline: MetsukePerceive
Measure unresolved ownership
Identify security issues waiting because responsibility is unclear.
Discipline: MetsukePerceive
08 / 08
Jisei
Self-control
In one line · Control your actions under pressure.
3 / 4 Measured
Verify that the behaviour is happening and that it works.
Measure standing privilege
Identify elevated access that remains active beyond operational need.
Discipline: MetsukePerceive