Skip to main content

Create a private security measure

Learn how to create a private security measure when none of the catalog measures fit your needs, and understand why public measures are usually the better option.

Why create a private measure?

If you manage the security base of your perimeter and none of the measures in the Tenacy catalog match an existing internal control, you can create a new measure as a private measure.

Unlike a public measure, which is maintained by Tenacy and mapped to the catalog's various regulatory texts and risks, a private measure only exists within your organization's context: you lose these mappings, as well as the indicators and recurring tasks associated with the public catalog.

⚠️ Before creating a private measure, we recommend contacting your Customer Success Manager (CSM):

  • The catalog already includes a wide range of public measures; it's likely one of them fits your need.

  • Public measures are linked to all the policies in our catalog and let you track your multi-compliance.

  • A private measure can only be associated with private policies or objects: it cannot be linked to a public policy from the Tenacy catalog.

Your CSM can help you:

  • find the closest public measure to your need, or

  • forward your proposal to our team to create a new public measure, if relevant to other organizations, and have it linked to the relevant policies.

Steps to create a private measure

  1. Click the cog wheel icon at the top right of the screen.

  2. Go to Catalog > Measures tab.

  3. Click "Add a proposed measure".

  4. Fill in:

    • a name for your measure,

    • an ID (optional — it will be generated automatically if left blank),

    • and a category.

💡 Your private measure is automatically attached to the perimeter you created it from (a perimeter is an entity within your organization, such as a subsidiary or a process, on which you manage compliance and risk). You can extend it to other perimeters afterward.

Declaring your measure's implementation

Once your measure is created, hover over its row and use the actions available on the right:

  • Select the "Implement" icon if this measure is already in place in your organization: it will be declared implemented for this perimeter.

  • Select "Add implementation action" if it isn't in place yet and you want to build it from scratch: it will be declared in implementation for this perimeter, with an associated implementation action to track progress.

🔎 You can repeat this for each of your perimeters, but a measure cannot be declared both implemented and in implementation on the same perimeter.

💡 Best practices

  • Always check the public measures catalog before creating a private measure.

  • Contact your CSM to get help and ensure your measure is taken into account in your compliance analyses.


Frequently asked questions

Can a private measure be shared with other perimeters?
Yes. Once created, a private measure can be extended to other perimeters in your organization, the same way a public measure can.

What's the difference between a private measure and a public measure from the catalog?
A public measure is part of the catalog maintained by Tenacy: it's linked to catalog policies, which lets you see its contribution across several frameworks at once (multi-compliance). A private measure only exists within your organization's context and can only be associated with private policies or objects.

What happens if my private measure is linked to a risk?
If your private measure is part of a risk's treatment plan, make sure to link it explicitly to that risk once created, so the risk correctly reflects the associated treatment action. If you delete the measure or its association, remove that link as well.

Can I turn my private measure into a public catalog measure?
Not directly. If you think your private measure could be relevant to regulatory text coverage, forward your request to your CSM: our team will review adding it to the public catalog maintained by Tenacy.

Did this answer your question?