Apply · Practices
The practice model
Every virtue, four bands, twenty practices. Foundation makes the behaviour explicit; Controlled embeds it into the operating model; Measured verifies it happens; Adaptive changes it when the evidence says it is no longer enough.
A band is not a maturity score. A team can be strong in one virtue and weak in another. Read a virtue upward: each band assumes the one before it.
- 01Virtue
- 02Behaviour
- 03Practice
- 04Control
- 05Evidence
- 06Assessment
The model at a glance
Table scrolls horizontally.
| Virtue | 1 · Foundation | 2 · Controlled | 3 · Measured | 4 · Adaptive |
|---|---|---|---|---|
| 義Gi | Make ownership explicit | Control decisions and privilege | Measure attribution | Improve accountability |
| 勇Yū | Enable investigation | Formalise response | Measure investigation | Adapt detection and response |
| 仁Jin | Understand users | Design usable controls | Measure friction | Continuously redesign |
| 礼Rei | Define boundaries | Enforce least privilege | Test boundaries | Continuously re-authorise |
| 誠Makoto | Define truth | Control data quality | Measure accuracy | Automate trust and uncertainty |
| 名誉Meiyo | Define the standard | Assure the controls | Measure effectiveness | Raise and adapt the standard |
| 忠義Chūgi | Define responsibility | Embed stewardship | Measure participation | Distribute responsibility |
| 自制Jisei | Define discipline | Control actions | Measure exceptions | Design for pressure |
01 / 08
Gi
Integrity / rectitude
In one line · Own your actions.
1 / 4 Foundation
Make the behaviour explicit and repeatable.
Use named privileged access
Eliminate shared administrative identities. Record who elevated, what they accessed and when the privilege ended.
Discipline: TateProtect
2 / 4 Controlled
Embed the behaviour into processes and ownership.
Time-bound exceptions
Every exception has a reason, risk owner, compensating control and expiry date.
Discipline: TateProtect
Review consequential changes
Require independent review for high-impact firewall, identity, security-policy and production changes.
Discipline: TateProtect
Separate approval from execution
Where risk warrants it, the person implementing a sensitive action should not be the sole person approving it.
Discipline: TateProtect
4 / 4 Adaptive
Use evidence to improve the behaviour and respond to change.
Make accountability part of architecture
Design new platforms so that identity, action and evidence remain linked by default.
Discipline: TateProtect
02 / 08
Yū
Courage
In one line · Act under uncertainty.
1 / 4 Foundation
Make the behaviour explicit and repeatable.
Establish incident authority
Define who can isolate a device, disable an account or block traffic during an incident.
Discipline: TateProtect
2 / 4 Controlled
Embed the behaviour into processes and ownership.
Exercise incident response
Run tabletop and technical exercises where information is deliberately incomplete.
Discipline: TateProtect
Define containment playbooks
Pre-authorise common containment actions so teams do not need to negotiate authority during an incident.
Discipline: TateProtect
4 / 4 Adaptive
Use evidence to improve the behaviour and respond to change.
Rehearse decision-making under pressure
Run exercises where business impact and incomplete evidence compete for attention.
Discipline: TateProtect
03 / 08
Jin
Benevolence
In one line · Design for the people using the control.
1 / 4 Foundation
Make the behaviour explicit and repeatable.
Document the secure path
Make the approved way to perform common tasks clear and accessible.
Discipline: TateProtect
Provide a security support path
Give users a practical way to resolve security-related blockers.
Discipline: TateProtect
Explain the reason
Tell users what a control protects and what behaviour is expected.
Discipline: TateProtect
2 / 4 Controlled
Embed the behaviour into processes and ownership.
Automate the safe path
Automate access requests, credential rotation, approved software deployment and similar repetitive tasks.
Discipline: TateProtect
Build approved alternatives
When blocking a risky activity, provide a supported way to accomplish the legitimate business requirement.
Discipline: TateProtect
4 / 4 Adaptive
Use evidence to improve the behaviour and respond to change.
Remove recurring friction
Prioritise engineering work that eliminates repeated security workarounds.
Discipline: TateProtect
Use risk-based controls
Apply stronger controls where risk requires them and reduce unnecessary friction elsewhere.
Discipline: TateProtect
04 / 08
Rei
Respect
In one line · Respect boundaries.
1 / 4 Foundation
Make the behaviour explicit and repeatable.
Establish temporary-access rules
Define how project, vendor, emergency and privileged access is granted and removed.
Discipline: TateProtect
2 / 4 Controlled
Embed the behaviour into processes and ownership.
Review privileged access
Regularly remove access that is no longer required.
Discipline: TateProtect
Expire temporary access
Make temporary access expire automatically wherever possible.
Discipline: TateProtect
Enforce least privilege
Grant access according to role, task and necessity.
Discipline: TateProtect
Separate duties
Prevent one person from controlling sensitive approval and execution paths where risk warrants it.
Discipline: TateProtect
Enforce segmentation
Restrict communication between systems according to documented requirements.
Discipline: TateProtect
4 / 4 Adaptive
Use evidence to improve the behaviour and respond to change.
Reduce standing privilege
Replace permanent access with just-in-time or task-based access where appropriate.
Discipline: TateProtect
Automate entitlement removal
Connect joiner-mover-leaver events to access removal.
Discipline: TateProtect
05 / 08
Makoto
Sincerity
In one line · Verify reality.
4 / 4 Adaptive
Use evidence to improve the behaviour and respond to change.
Propagate data quality
Prevent incomplete or stale source data from being presented as authoritative downstream.
Discipline: TateProtect
06 / 08
Meiyo
Honour
In one line · Maintain the standard without supervision.
1 / 4 Foundation
Make the behaviour explicit and repeatable.
Define internal standards
Set security expectations that are clear and operational.
Discipline: TateProtect
Define control frequency
State how often important controls must operate or be tested.
Discipline: TateProtect
2 / 4 Controlled
Embed the behaviour into processes and ownership.
Fix internally discovered issues
Do not wait for an audit or regulator to identify known weaknesses.
Discipline: TateProtect
4 / 4 Adaptive
Use evidence to improve the behaviour and respond to change.
Raise the internal standard
Increase expectations when the organisation can support them and the risk warrants it.
Discipline: TateProtect
07 / 08
Chūgi
Loyalty
In one line · Treat access as responsibility.
1 / 4 Foundation
Make the behaviour explicit and repeatable.
Define stewardship expectations
Make clear what responsibility comes with privileged or sensitive access.
Discipline: TateProtect
2 / 4 Controlled
Embed the behaviour into processes and ownership.
Review responsibility with access
When sensitive access is renewed, confirm the user's continuing responsibility.
Discipline: TateProtect
Build security into operational processes
Include security checks in deployment, onboarding, change and decommissioning workflows.
Discipline: TateProtect
4 / 4 Adaptive
Use evidence to improve the behaviour and respond to change.
Push responsibility toward the edge
Move appropriate security decisions closer to the teams operating the systems.
Discipline: TateProtect
Integrate security into engineering
Make security part of normal engineering workflows rather than a separate approval stage.
Discipline: TateProtect
Build security into performance expectations
Where appropriate, include security responsibilities in team and role objectives.
Discipline: TateProtect
08 / 08
Jisei
Self-control
In one line · Control your actions under pressure.
1 / 4 Foundation
Make the behaviour explicit and repeatable.
Define change classes
Distinguish normal, standard, emergency and high-risk changes.
Discipline: TateProtect
Establish emergency procedures
Define what can be changed during an incident and who can authorise it.
Discipline: TateProtect
Define temporary exceptions
Give temporary changes and exclusions an explicit end condition.
Discipline: TateProtect
Establish rollback expectations
Define how high-impact changes can be reversed.
Discipline: TateProtect
2 / 4 Controlled
Embed the behaviour into processes and ownership.
Use just-in-time privilege
Grant elevated access for the task and remove it when the task ends.
Discipline: TateProtect
Require peer review
Use independent review for high-impact changes where risk warrants it.
Discipline: TateProtect
Automate expiry
Automatically remove temporary firewall rules, exclusions, privileges and exceptions where possible.
Discipline: TateProtect
Protect emergency access
Log and restrict emergency administrative capabilities.
Discipline: TateProtect
Use infrastructure as code
Prefer controlled, repeatable changes over undocumented manual modification.
Discipline: TateProtect
4 / 4 Adaptive
Use evidence to improve the behaviour and respond to change.
Automate controlled remediation
Where the action is predictable, make the safe response repeatable.
Discipline: TateProtect
Improve rollback capability
Invest in reversible deployments and configuration recovery where failure has material impact.
Discipline: TateProtect
Design for pressure
Test whether security processes still work during outages, incidents and high business pressure.
Discipline: TateProtect