Decision principles
Start from enterprise objectives and bounded risk scenarios rather than isolated technical findings.Keep observed evidence, assumptions, estimates and management judgement distinguishable.Record accountable ownership and decision authority for treatment, acceptance and exceptions.Connect risk treatment to implementation evidence and reassess residual risk after material change.Assess controls with explicit objective, scope, method, period, evidence and limitations.Preserve contradictory evidence and known gaps rather than optimising records for a favourable conclusion.Use aggregation for governance while retaining material lower-level context that could be hidden by averages.Treat assurance as evidence-supported confidence, not as a synonym for compliance or absence of risk.
Explicit non-claims
Cybatar does not calculate a universally correct cyber-risk score.Cybatar does not determine an organisation’s legitimate risk appetite or tolerance.A recorded risk acceptance does not make the exposure safe, compliant or acceptable to external stakeholders.A control assessment record is not an independent audit opinion or certification.A framework mapping is not proof that a control is implemented or effective.Evidence stored in Cybatar is not automatically complete, authentic, legally sufficient or regulator-approved.NIST references do not imply NIST certification, endorsement or validation of Cybatar.
Primary external sources
NIST IR 8286 Rev. 1Current final foundation for integrating cybersecurity risk information with enterprise risk management.NIST IR 8286A Rev. 1Current final guidance for risk direction, identification, appetite, tolerance and estimation.NIST IR 8286B Update 1Current final guidance for cyber-risk prioritisation and response selection.NIST IR 8286C Rev. 1Current final guidance for staging cybersecurity risk into enterprise risk and governance oversight.NIST IR 8286D Update 1Current final guidance for using business impact analysis to inform cybersecurity risk prioritisation and response.NIST SP 800-53A Rev. 5Current NIST control-assessment methodology; Release 5.2.0 was issued in August 2025.