Skip to main content

Interpret the differences between the initial measure and my measure

Understand the Differences view: compare the measures in your security base with those in the Tenacy catalog and interpret the color code.

The Differences view lets you, as a pilot, compare the security measures in your security base with those in the Tenacy catalog. You get an at-a-glance view of what diverges between your environment and the catalog, then you decide what you want to handle.

💡 The catalog is Tenacy's reference library of security measures. Your security base is the set of measures actually implemented on a given perimeter. Over time, the two can diverge: the catalog evolves, and you customize your measures.

Accessing the Differences view

Open your Security base, then click the View differences button in the top right of the screen.

Reading the color code

The reading base is always the catalog. Each item is colored according to where it is located:

  • Red: the item is present in your environment but not in the Tenacy catalog. Example: you use a public measure and you have associated a private indicator with it; that indicator appears in red.

  • Green: the item is present in the Tenacy catalog but not in your environment.

  • White: the item exists on both sides but has a content difference, most often a modified description or a change in coverage rate on the catalog side but not on the environment side.

💡 Example: in the "Corporate IT" perimeter, the implemented security measure "Asset management" has 4 items in red (present in your environment but absent from the "Asset management" measure in the catalog) and 5 items in green (present in the catalog measure but absent from yours).

Asset Management

Handling the differences

Once the differences are identified, you select the relevant items, then you click the Apply differences button. The effect of this action depends on the color of the selected items.

Applying a green difference

Applying a green difference means instantiating in your measure an item that is present in the catalog but absent from yours.

If your selection contains only differences of type indicator, content (title, description) or requirement: select the items, then click Apply differences. The items are instantiated directly.

If your selection contains a difference of type recurring task, an additional configuration step is required, because a recurring task must be attached to a register and have an owner:

  • click the Choose task settings button;

  • select the register to which the created recurring tasks will be attached;

  • set a start date;

  • assign an owner (a user or a group);

  • confirm by clicking Apply differences.

Applying a red difference

A red difference corresponds to an item present in your measure but absent from the catalog. Applying a red difference never modifies the catalog: it modifies your measure in your security base to align it with the catalog.

⚠️ Applying a red difference is a destructive action. If you select a recurring task that is present in your measure but absent from the catalog, then click Apply differences, that recurring task is disassociated from your measure and deleted. Check your selection before confirming.

What the differences cover

The comparison covers all the links and content of a measure:

  • links to the security requirements of policies;

  • links to risks;

  • associated indicators and recurring tasks;

  • text elements: title and descriptions.


Frequently asked questions

Why does an item appear in red even though it works correctly for me?

Red does not indicate an error. It simply means that this item exists in your environment but not in the reference catalog. This is common when you have customized a measure, for example by associating a private indicator with it.

What happens if I apply a red difference on a recurring task?

The recurring task concerned is disassociated from your measure and then deleted. Applying a red difference aligns your measure with the catalog and therefore removes what is not in it. Only apply a red difference if you genuinely want to remove the item from your measure.

Why does Tenacy ask me for a register and an owner when I apply a green recurring task?

Because a recurring task cannot exist on its own: it must be attached to a register and have an owner who takes charge of it. These settings are therefore requested at the time of instantiation, via the Choose task settings button.

Will a green item be added to my security base automatically?

No. The Differences view is a comparative reading. It shows you what diverges, but it is you who selects the items and clicks Apply differences to instantiate them.

What does a white item mean?

It exists on both sides but its content is not identical. The difference usually comes from a modified description or a coverage rate updated in the catalog and not yet reflected in your environment.

Did this answer your question?