If you pilot an internal perimeter, this guide walks you through declaring its security base. The security base groups, for that perimeter, all the security measures expected in light of the policies and risks associated with it. Declaring your base means going through these measures one by one to indicate whether they are already in place in your organization.
💡 To understand how Tenacy and its modules work in general, see this article.
⚠️ A perimeter's security base only displays measures if a policy is associated with that perimeter. If that isn't the case yet, see this article before continuing.
Step 1: Access the measures to be handled for your perimeter
Go to Strategy > Security Bases, then filter by the policy and perimeter you want to work on.
On the selected perimeter, measures still "to be handled" are those for which no implementation status has been set yet: Tenacy doesn't yet know whether they are in place in your organization or not.
Step 2: Decide the status of each measure
For each measure "to be handled", ask yourself: "Is this measure currently in place in my organization?"
⚠️ There are only two status buttons: "Implemented" and "Not implemented". A measure that is only partially in place must therefore also be declared "Implemented", just like a fully implemented one: it's the creation of an improvement action, not a third status, that reflects the partial nature of its implementation.
If the measure is in place: click "Implemented"
If the measure is partially in place: click "Implemented" as well
If the measure is not in place: click "Not implemented"
Case 1: The measure is fully implemented in my organization
By declaring the measure "Implemented", you can also add the associated controls: recurring tasks and indicators (Operations section > Add control). By default, Tenacy suggests the ones defined in its Catalog.
💡 You can also add your own indicators and recurring tasks.
Case 2: The measure is partially implemented in my organization
Declare the measure "Implemented" to confirm it is indeed in place. To reflect the fact that it still needs to be optimized, create an improvement action directly from that measure: this action reduces the measure's current efficiency by the gain you choose, and that gain is returned to it once the action is completed.
💡 For the difference between efficiency and performance of a measure, see this article.
If controls already exist in your organization for this measure, you can also add indicators and recurring tasks directly to the measure.
Case 3: The measure is not implemented
Declare the measure "Not implemented". You can then decide, if you wish, to create an implementation action: it is not mandatory, but becomes necessary as soon as you decide to start putting this measure in place in your organization.
💡 To better distinguish between the different types of actions in Tenacy, see this article.
Frequently asked questions
Do I have to create an action if my measure is not implemented?
No. Creating an implementation action is optional: it's only necessary if you decide to start putting the measure in place.
What happens if I click "Implemented" when the measure is only partially in place?
This is the expected behavior: the "Implemented" status covers both full and partial implementation. Creating an improvement action, with its associated efficiency gain, is what accounts for the partial nature.
Can I add indicators and recurring tasks without creating an action?
Yes. Whether the measure is fully or partially implemented, you can add indicators and recurring tasks directly to the measure, independently of creating an action.
What is the difference between an implementation action and an improvement action?
An implementation action aims to put in place a measure that doesn't yet exist in your organization. An improvement action, on the other hand, aims to increase the efficiency of a measure that is already in place.



