Skip to content
CyberBushido

Apply · Practices

The practice model

Every virtue, four bands, twenty practices. Foundation makes the behaviour explicit; Controlled embeds it into the operating model; Measured verifies it happens; Adaptive changes it when the evidence says it is no longer enough.

A band is not a maturity score. A team can be strong in one virtue and weak in another. Read a virtue upward: each band assumes the one before it.

  1. 01Virtue
  2. 02Behaviour
  3. 03Practice
  4. 04Control
  5. 05Evidence
  6. 06Assessment

The model at a glance

Table scrolls horizontally.

Each virtue across the four bands, one line per cell.
Virtue1 · Foundation2 · Controlled3 · Measured4 · Adaptive
義GiMake ownership explicitControl decisions and privilegeMeasure attributionImprove accountability
勇YūEnable investigationFormalise responseMeasure investigationAdapt detection and response
仁JinUnderstand usersDesign usable controlsMeasure frictionContinuously redesign
礼ReiDefine boundariesEnforce least privilegeTest boundariesContinuously re-authorise
誠MakotoDefine truthControl data qualityMeasure accuracyAutomate trust and uncertainty
名誉MeiyoDefine the standardAssure the controlsMeasure effectivenessRaise and adapt the standard
忠義ChūgiDefine responsibilityEmbed stewardshipMeasure participationDistribute responsibility
自制JiseiDefine disciplineControl actionsMeasure exceptionsDesign for pressure
Clear

Showing 47 of 160 practices.

義

01 / 08

Gi

Integrity / rectitude

In one line · Own your actions.

1 / 4 Foundation

Make the behaviour explicit and repeatable.

  1. Use named privileged access

    Eliminate shared administrative identities. Record who elevated, what they accessed and when the privilege ended.

    Discipline: TateProtect

2 / 4 Controlled

Embed the behaviour into processes and ownership.

  1. Time-bound exceptions

    Every exception has a reason, risk owner, compensating control and expiry date.

    Discipline: TateProtect

  2. Review consequential changes

    Require independent review for high-impact firewall, identity, security-policy and production changes.

    Discipline: TateProtect

  3. Separate approval from execution

    Where risk warrants it, the person implementing a sensitive action should not be the sole person approving it.

    Discipline: TateProtect

4 / 4 Adaptive

Use evidence to improve the behaviour and respond to change.

  1. Make accountability part of architecture

    Design new platforms so that identity, action and evidence remain linked by default.

    Discipline: TateProtect

Read the full argument
勇

02 / 08

Yū

Courage

In one line · Act under uncertainty.

1 / 4 Foundation

Make the behaviour explicit and repeatable.

  1. Establish incident authority

    Define who can isolate a device, disable an account or block traffic during an incident.

    Discipline: TateProtect

2 / 4 Controlled

Embed the behaviour into processes and ownership.

  1. Exercise incident response

    Run tabletop and technical exercises where information is deliberately incomplete.

    Discipline: TateProtect

  2. Define containment playbooks

    Pre-authorise common containment actions so teams do not need to negotiate authority during an incident.

    Discipline: TateProtect

4 / 4 Adaptive

Use evidence to improve the behaviour and respond to change.

  1. Rehearse decision-making under pressure

    Run exercises where business impact and incomplete evidence compete for attention.

    Discipline: TateProtect

Read the full argument
仁

03 / 08

Jin

Benevolence

In one line · Design for the people using the control.

1 / 4 Foundation

Make the behaviour explicit and repeatable.

  1. Document the secure path

    Make the approved way to perform common tasks clear and accessible.

    Discipline: TateProtect

  2. Provide a security support path

    Give users a practical way to resolve security-related blockers.

    Discipline: TateProtect

  3. Explain the reason

    Tell users what a control protects and what behaviour is expected.

    Discipline: TateProtect

2 / 4 Controlled

Embed the behaviour into processes and ownership.

  1. Automate the safe path

    Automate access requests, credential rotation, approved software deployment and similar repetitive tasks.

    Discipline: TateProtect

  2. Build approved alternatives

    When blocking a risky activity, provide a supported way to accomplish the legitimate business requirement.

    Discipline: TateProtect

4 / 4 Adaptive

Use evidence to improve the behaviour and respond to change.

  1. Remove recurring friction

    Prioritise engineering work that eliminates repeated security workarounds.

    Discipline: TateProtect

  2. Use risk-based controls

    Apply stronger controls where risk requires them and reduce unnecessary friction elsewhere.

    Discipline: TateProtect

Read the full argument
礼

04 / 08

Rei

Respect

In one line · Respect boundaries.

1 / 4 Foundation

Make the behaviour explicit and repeatable.

  1. Establish temporary-access rules

    Define how project, vendor, emergency and privileged access is granted and removed.

    Discipline: TateProtect

2 / 4 Controlled

Embed the behaviour into processes and ownership.

  1. Review privileged access

    Regularly remove access that is no longer required.

    Discipline: TateProtect

  2. Expire temporary access

    Make temporary access expire automatically wherever possible.

    Discipline: TateProtect

  3. Enforce least privilege

    Grant access according to role, task and necessity.

    Discipline: TateProtect

  4. Separate duties

    Prevent one person from controlling sensitive approval and execution paths where risk warrants it.

    Discipline: TateProtect

  5. Enforce segmentation

    Restrict communication between systems according to documented requirements.

    Discipline: TateProtect

4 / 4 Adaptive

Use evidence to improve the behaviour and respond to change.

  1. Reduce standing privilege

    Replace permanent access with just-in-time or task-based access where appropriate.

    Discipline: TateProtect

  2. Automate entitlement removal

    Connect joiner-mover-leaver events to access removal.

    Discipline: TateProtect

Read the full argument
誠

05 / 08

Makoto

Sincerity

In one line · Verify reality.

4 / 4 Adaptive

Use evidence to improve the behaviour and respond to change.

  1. Propagate data quality

    Prevent incomplete or stale source data from being presented as authoritative downstream.

    Discipline: TateProtect

Read the full argument
名誉

06 / 08

Meiyo

Honour

In one line · Maintain the standard without supervision.

1 / 4 Foundation

Make the behaviour explicit and repeatable.

  1. Define internal standards

    Set security expectations that are clear and operational.

    Discipline: TateProtect

  2. Define control frequency

    State how often important controls must operate or be tested.

    Discipline: TateProtect

2 / 4 Controlled

Embed the behaviour into processes and ownership.

  1. Fix internally discovered issues

    Do not wait for an audit or regulator to identify known weaknesses.

    Discipline: TateProtect

4 / 4 Adaptive

Use evidence to improve the behaviour and respond to change.

  1. Raise the internal standard

    Increase expectations when the organisation can support them and the risk warrants it.

    Discipline: TateProtect

Read the full argument
忠義

07 / 08

Chūgi

Loyalty

In one line · Treat access as responsibility.

1 / 4 Foundation

Make the behaviour explicit and repeatable.

  1. Define stewardship expectations

    Make clear what responsibility comes with privileged or sensitive access.

    Discipline: TateProtect

2 / 4 Controlled

Embed the behaviour into processes and ownership.

  1. Review responsibility with access

    When sensitive access is renewed, confirm the user's continuing responsibility.

    Discipline: TateProtect

  2. Build security into operational processes

    Include security checks in deployment, onboarding, change and decommissioning workflows.

    Discipline: TateProtect

4 / 4 Adaptive

Use evidence to improve the behaviour and respond to change.

  1. Push responsibility toward the edge

    Move appropriate security decisions closer to the teams operating the systems.

    Discipline: TateProtect

  2. Integrate security into engineering

    Make security part of normal engineering workflows rather than a separate approval stage.

    Discipline: TateProtect

  3. Build security into performance expectations

    Where appropriate, include security responsibilities in team and role objectives.

    Discipline: TateProtect

Read the full argument
自制

08 / 08

Jisei

Self-control

In one line · Control your actions under pressure.

1 / 4 Foundation

Make the behaviour explicit and repeatable.

  1. Define change classes

    Distinguish normal, standard, emergency and high-risk changes.

    Discipline: TateProtect

  2. Establish emergency procedures

    Define what can be changed during an incident and who can authorise it.

    Discipline: TateProtect

  3. Define temporary exceptions

    Give temporary changes and exclusions an explicit end condition.

    Discipline: TateProtect

  4. Establish rollback expectations

    Define how high-impact changes can be reversed.

    Discipline: TateProtect

2 / 4 Controlled

Embed the behaviour into processes and ownership.

  1. Use just-in-time privilege

    Grant elevated access for the task and remove it when the task ends.

    Discipline: TateProtect

  2. Require peer review

    Use independent review for high-impact changes where risk warrants it.

    Discipline: TateProtect

  3. Automate expiry

    Automatically remove temporary firewall rules, exclusions, privileges and exceptions where possible.

    Discipline: TateProtect

  4. Protect emergency access

    Log and restrict emergency administrative capabilities.

    Discipline: TateProtect

  5. Use infrastructure as code

    Prefer controlled, repeatable changes over undocumented manual modification.

    Discipline: TateProtect

4 / 4 Adaptive

Use evidence to improve the behaviour and respond to change.

  1. Automate controlled remediation

    Where the action is predictable, make the safe response repeatable.

    Discipline: TateProtect

  2. Improve rollback capability

    Invest in reversible deployments and configuration recovery where failure has material impact.

    Discipline: TateProtect

  3. Design for pressure

    Test whether security processes still work during outages, incidents and high business pressure.

    Discipline: TateProtect

Read the full argument
The practice model — CyberBushido