Skip to content
CyberBushido

Apply · Practices

The practice model

Every virtue, four bands, twenty practices. Foundation makes the behaviour explicit; Controlled embeds it into the operating model; Measured verifies it happens; Adaptive changes it when the evidence says it is no longer enough.

A band is not a maturity score. A team can be strong in one virtue and weak in another. Read a virtue upward: each band assumes the one before it.

  1. 01Virtue
  2. 02Behaviour
  3. 03Practice
  4. 04Control
  5. 05Evidence
  6. 06Assessment

The model at a glance

Table scrolls horizontally.

Each virtue across the four bands, one line per cell.
Virtue1 · Foundation2 · Controlled3 · Measured4 · Adaptive
義GiMake ownership explicitControl decisions and privilegeMeasure attributionImprove accountability
勇YūEnable investigationFormalise responseMeasure investigationAdapt detection and response
仁JinUnderstand usersDesign usable controlsMeasure frictionContinuously redesign
礼ReiDefine boundariesEnforce least privilegeTest boundariesContinuously re-authorise
誠MakotoDefine truthControl data qualityMeasure accuracyAutomate trust and uncertainty
名誉MeiyoDefine the standardAssure the controlsMeasure effectivenessRaise and adapt the standard
忠義ChūgiDefine responsibilityEmbed stewardshipMeasure participationDistribute responsibility
自制JiseiDefine disciplineControl actionsMeasure exceptionsDesign for pressure
Clear

Showing 32 of 160 practices.

義

01 / 08

Gi

Integrity / rectitude

In one line · Own your actions.

1 / 4 Foundation

Make the behaviour explicit and repeatable.

  1. Name the decision owner

    Every security exception, risk acceptance and material architecture decision has one accountable owner.

    Discipline: MetsukePerceive

  2. Define ownership

    Every critical security control has an accountable owner and an operational owner.

    Discipline: MetsukePerceive

  3. Make escalation explicit

    Define who must be informed when a security decision exceeds the team's authority.

    Discipline: MetsukePerceive

2 / 4 Controlled

Embed the behaviour into processes and ownership.

  1. Formalise risk acceptance

    Define who can accept which level of security risk and for how long.

    Discipline: MetsukePerceive

3 / 4 Measured

Verify that the behaviour is happening and that it works.

  1. Review shared accounts

    Search for shared, generic and service identities that create attribution gaps.

    Discipline: MetsukePerceive

Read the full argument
勇

02 / 08

Yū

Courage

In one line · Act under uncertainty.

1 / 4 Foundation

Make the behaviour explicit and repeatable.

  1. Create challenge points

    Require security review for architectures and changes that introduce material exposure.

    Discipline: MetsukePerceive

2 / 4 Controlled

Embed the behaviour into processes and ownership.

  1. Maintain hunting hypotheses

    Turn intelligence, incidents and unusual telemetry into repeatable hunting questions.

    Discipline: MetsukePerceive

  2. Protect useful challenge

    Create a process for challenging high-risk decisions without turning disagreement into personal conflict.

    Discipline: MetsukePerceive

3 / 4 Measured

Verify that the behaviour is happening and that it works.

  1. Test blind spots

    Periodically simulate activity that existing detection rules should not identify.

    Discipline: MetsukePerceive

4 / 4 Adaptive

Use evidence to improve the behaviour and respond to change.

  1. Challenge detection assumptions

    Regularly ask what the SOC cannot currently see and what an attacker could do without generating an alert.

    Discipline: MetsukePerceive

Read the full argument
仁

03 / 08

Jin

Benevolence

In one line · Design for the people using the control.

1 / 4 Foundation

Make the behaviour explicit and repeatable.

  1. Identify the user

    For every important control, identify who operates it and what legitimate task they need to complete.

    Discipline: MetsukePerceive

2 / 4 Controlled

Embed the behaviour into processes and ownership.

  1. Design with users

    Test security workflows with administrators, developers and business users before deployment.

    Discipline: MetsukePerceive

Read the full argument
礼

04 / 08

Rei

Respect

In one line · Respect boundaries.

1 / 4 Foundation

Make the behaviour explicit and repeatable.

  1. Define access requirements

    Document what access each role actually requires.

    Discipline: MetsukePerceive

  2. Identify trust boundaries

    Document important identity, network, application and data boundaries.

    Discipline: MetsukePerceive

  3. Establish access owners

    Every sensitive resource has an owner responsible for access decisions.

    Discipline: MetsukePerceive

  4. Classify sensitive information

    Define which information requires additional access restrictions.

    Discipline: MetsukePerceive

3 / 4 Measured

Verify that the behaviour is happening and that it works.

  1. Measure excessive privilege

    Identify users, service accounts and applications with broader access than required.

    Discipline: MetsukePerceive

Read the full argument
誠

05 / 08

Makoto

Sincerity

In one line · Verify reality.

1 / 4 Foundation

Make the behaviour explicit and repeatable.

  1. Define authoritative sources

    Identify which system is authoritative for assets, identities, vulnerabilities, configurations and other security data.

    Discipline: MetsukePerceive

  2. Define data ownership

    Assign owners to important security datasets.

    Discipline: MetsukePerceive

2 / 4 Controlled

Embed the behaviour into processes and ownership.

  1. Reconcile inventories

    Compare CMDB, cloud inventories, endpoint platforms, vulnerability scanners and network discovery.

    Discipline: MetsukePerceive

3 / 4 Measured

Verify that the behaviour is happening and that it works.

  1. Measure inventory coverage

    Track the percentage of assets represented across required security systems.

    Discipline: MetsukePerceive

  2. Measure telemetry coverage

    Track which critical systems are actually producing the expected logs.

    Discipline: MetsukePerceive

4 / 4 Adaptive

Use evidence to improve the behaviour and respond to change.

  1. Make uncertainty operational

    Use confidence and coverage information when prioritising security decisions.

    Discipline: MetsukePerceive

Read the full argument
名誉

06 / 08

Meiyo

Honour

In one line · Maintain the standard without supervision.

1 / 4 Foundation

Make the behaviour explicit and repeatable.

  1. Assign control owners

    Give every important control a responsible owner.

    Discipline: MetsukePerceive

2 / 4 Controlled

Embed the behaviour into processes and ownership.

  1. Separate compliance from security

    Track regulatory compliance and internal security objectives separately.

    Discipline: MetsukePerceive

Read the full argument
忠義

07 / 08

Chūgi

Loyalty

In one line · Treat access as responsibility.

1 / 4 Foundation

Make the behaviour explicit and repeatable.

  1. Assign system ownership

    Every important system has a named business or technology owner.

    Discipline: MetsukePerceive

  2. Define security responsibilities

    Make security duties part of relevant roles.

    Discipline: MetsukePerceive

2 / 4 Controlled

Embed the behaviour into processes and ownership.

  1. Include security in role definitions

    Make security responsibilities explicit for administrators, developers, engineers and system owners.

    Discipline: MetsukePerceive

  2. Establish vendor responsibility

    Define security responsibilities for third parties with access to company systems.

    Discipline: MetsukePerceive

3 / 4 Measured

Verify that the behaviour is happening and that it works.

  1. Measure ownership coverage

    Track systems and controls without an accountable owner.

    Discipline: MetsukePerceive

  2. Measure unresolved ownership

    Identify security issues waiting because responsibility is unclear.

    Discipline: MetsukePerceive

Read the full argument
自制

08 / 08

Jisei

Self-control

In one line · Control your actions under pressure.

3 / 4 Measured

Verify that the behaviour is happening and that it works.

  1. Measure standing privilege

    Identify elevated access that remains active beyond operational need.

    Discipline: MetsukePerceive

Read the full argument
The practice model — CyberBushido