Skip to content

MIS.Enterprise

MIS 10.0 — Continuous Cyber Resilience

CVE to Governed Enterprise Risk

MIS 10.0 connects vulnerability intelligence to the assets, services and owners that determine your response. Each CVE is traced to the enterprise assets that carry it, the business services that depend on them and the accountable owner who decides — and closure counts only when it is independently verified.

  • 01Do we have it?Match affected products and versions to the asset inventory, CMDB and SBOM evidence.
  • 02Can it be exploited here?Assess reachable code, access paths and verified controls in your environment.
  • 03What happens if it is?Identify affected services, sensitive data and accountable owners. Assess reporting duties if an incident occurs.
Foundation MIS 9.0 governance principlesProposed MIS 10.0 enterprise operating model — not verified deployment statusIllustrative conceptual example, not customer data

MIS 9.0 foundationFoundation

Governed decisions across Know, Reason, Act, Prove and Learn

MIS 9.0 supplies the governing principles. MIS 10.0 extends the evidence and the enterprise context — it does not relax the rules.

  1. 01KnowEstablish what exists, what is exposed and which evidence supports it.
  2. 02ReasonCombine threat, exposure and business context through versioned policy.
  3. 03ActExecute only what an accountable owner has authorised.
  4. 04ProveVerify the outcome independently before crediting risk reduction.
  5. 05LearnFeed residual risk and evidence gaps into the next assessment.

AI advises

AI advice stays separate from security truth. A model output never becomes an established fact.

People authorise

Human authorisation stays separate from execution. Nothing runs without an accountable approver.

Verification proves

Independent verification supports closure. Executing a change is not the same as proving it worked.


CVE-to-enterprise correlationProposed

Three evidence layers inside one governed chain

Severity, exploit evidence and local exposure stay visible as separate inputs. Every record retains its source, retrieval time and scoring version.

Layer 1

Vulnerability intelligence

Is it real and is it being exploited?

CVE
Identifier from the CVE Program
CPE
Names the affected products and versions
CWE
Classifies the underlying software weakness
CVSS
Technical severity, scoring version and vector
EPSS
30-day exploitation probability in the wild
CISA KEV
Records vulnerabilities with evidence of exploitation
MITRE ATT&CK
Technique context from supported mappings

Layer 2

Enterprise exposure

Do we have it, and can it be exploited here?

Inventory & CMDB
Resolve findings to canonical assets
SBOM
Match affected components to what is deployed
VEX
Treated as evidence to assess, not as a verdict
Reachability
Internet-facing, authentication required, callable code
Control evidence
Segmentation, WAF and EDR effectiveness, with evidence age

Layer 3

Business impact & governance

What happens if it is?

Dependent services
Business services the asset supports, directly or downstream
Sensitive data
Personal, financial, health or critical-infrastructure data
Accountable owners
Named owners for the asset and the decision
Applicable policy
Jurisdiction, sector and policy version

Governed enterprise priority — with its evidence and policy version attached

What the evidence can say

  • ConfirmedObserved directly and backed by current evidence.
  • InferredDerived from relationships or paths; shown separately from observations.
  • StaleEvidence older than its freshness window; visible as a coverage gap.
  • UnknownNot established. Remains an evidence gap until validated — never treated as safe.

A missing feed or missing CVE must never imply that an asset is safe. Unmatched assets, missing relationships and stale evidence remain visible as coverage gaps.

Illustrative Business impact gives the risk an owner
“CVE-X on server Y”Potential disruption to online lending, exposure of customer data and an accountable service owner

Proposed ingestion controls Proposed

  1. IngestCVE Program, NVD, EUVD, FIRST CVSS / EPSS, CISA KEV and vendor advisories — with source provenance
  2. ReconcileDeduplicate records and surface conflicting product matches
  3. MonitorFreshness, failed connectors and explicit degraded status

Continuous resilience workflowProposed

Continuous reassessment with verified closure

New intelligence and environment changes trigger reassessment. The loop never closes on execution alone.

Resilience loop: trigger, assess, authorise, act, verify, carry forward, then trigger againTriggerAssessAuthoriseActVerifyCarry fwdGOVERNEDLOOP
  1. 1
    Trigger

    New exploit evidence, asset changes, firewall changes or control failures start a reassessment.

  2. 2
    Assess

    Correlate intelligence, exposure and business impact. Evidence supports the priority and recommendation.

  3. 3
    Authorise

    An accountable owner decides under versioned policy. The agent cannot authorise itself.

  4. 4
    Act

    Execute the authorised change, isolation or recorded, expiring risk acceptance.

  5. 5
    Verify

    Independent verification establishes the result before any risk reduction is credited.

  6. 6
    Carry forward

    Residual risk and evidence gaps feed the next assessment.

Freshness

Show the last successful assessment, any processing delay and missed events. Evidence carries its age; a result is only as current as its oldest input.

Coverage

Report which assets, services and feeds were assessed — and which were not. Unknown reachability or impact stays an evidence gap until validated.


Governance and explainabilityProposed

An explainable decision model

Combine separate dimensions through a versioned policy and preserve the decision trace.

Deterministic core

Decisions based on versioned rules and evidence. Replayable from the evidence snapshot and policy version.

Predictive analytics

Labelled as prediction. A forecast never appears as an established fact.

AI advisories

Labelled as advisory and non-authoritative. Advice cannot approve, execute or verify.

Conceptual decision flow, not a calibrated risk formula. Ordinal scores are not multiplied, and EPSS is not the probability that your organisation will be breached — it estimates exploitation activity in the wild. SSVC can guide urgency: Track, Track*, Attend or Act.

Named owners for each evidence dimension

Threat

Owner: Threat Intelligence

  • CISA KEV listing
  • EPSS exploitation probability
  • Public exploit code
  • ATT&CK-mapped actor intelligence
  • Regional / sector intelligence

Exposure

Owner: Infrastructure, Cloud & Platform

  • Internet-facing / partner / internal only
  • Authentication required to reach it
  • Code reachability (SBOM, VEX, runtime)
  • Compensating controls (WAF, EDR)
  • EASM and CSPM observations with timestamps

Blast radius

Owner: Enterprise Architecture + Business

  • Technical: attack paths, hops to Tier-0
  • Business: dependent services, cost
  • Data scope and potentially applicable obligations
  • Service relationships with confidence and evidence age
Illustrative One CVE, three enterprise response decisions
AssetThreatExposureBlast radiusOutcome
Internet-facing VPN gateway, connected to ADHigh (KEV, ransomware-linked)High (unauthenticated, public)High (path to domain admin, critical data at risk)Emergency patch or isolation under approved policy. Notify CISO.
Internal app server, segmented subnetHighMedium (requires internal access)Medium (one business service, limited data)Remediate within the approved critical SLA.
Isolated lab systemHighLow (no network path)Low (no production data)Patch in the normal cycle or record an approved, expiring acceptance.

Illustrative response policy only. The timeframes are examples, not universal or regulatory deadlines. Validate asset reachability and business impact before acting.

Decision ownership, approvals, expiry and provenance

  • Risk-based SLAsVersion response policy using exploit evidence and local impact
  • Canonical inventoryResolve asset identity and retain SBOM and VEX provenance
  • Ownership at service levelRisk acceptance signed by a business owner, with an expiry
  • Formal exception processRecord controls, approver, expiry and review triggers
  • Source provenanceRetain source timestamps and expose conflicting intelligence
  • Control evidence mappingLink evidence to applicable controls with review ownership
  • Extend to third partiesTrack supplier components and dependencies by service
  • Business risk reportingShow critical-service exposure and accepted-risk trends
  • Automate & verifyAuthorise execution, verify independently, then reassess

Regulatory clocks require an incident trigger Reference

EU

24 hours

  • NIS2: early warning after awareness of a significant incident, for in-scope entities
  • Assess national implementation and applicable sector rules

India

6 hours

  • CERT-In: specified incidents, from noticing or being brought to notice
  • Assess entity and sector-specific duties separately

US

Rule-specific

  • BOD 22-01: KEV remediation due dates for FCEB agencies
  • SEC domestic registrants: generally 4 business days after determining materiality

Proposed policy overlay: record applicability, event trigger, owner and deadline. A CVE finding alone does not start every reporting clock. Route reporting decisions to the accountable legal and incident teams.


Enterprise outcomesProposed

Board visibility into exposure and residual risk

The measures MIS.Enterprise is designed to report. They are definitions, not live figures — no customer or production data is shown on this page.

  • Critical-service exposureShare of critical services with confirmed exploitable exposure, with coverage gaps.
  • Time to verified closureFor KEV on critical assets — measured to independent verification, not to ticket closure.
  • Overdue actions & expiring acceptancesMissed deadlines and risk acceptances approaching expiry, by owner.
  • Residual-risk trendsVerified change and accepted risk compared across assessments.
  • Assessment history & evidence coverageWhat changed and why, by run, service and owner — with evidence gaps visible.

Decision trace — what changed, and why? Compare assessments by run, service and owner. Show verified change, accepted risk and evidence gaps.


MIS.Enterprise engagement

Begin with one critical service

Connect its assets, validate exposure, assign decision owners and demonstrate independently verified closure.

  1. 1Assess one critical serviceConnect its assets and validate real exposure with evidence.
  2. 2Demonstrate the governed workflowAssign decision owners, authorise action and verify closure independently.
  3. 3Agree the enterprise rolloutExtend service by service, with the evidence and policy you have seen work.

MIS 10.0 describes the proposed enterprise operating model. Release readiness requires connector, security and end-to-end validation.