These domains exist in the corpus and their scaffolds have not been written. They are listed rather than linked, because a link that leads to a promise is exactly what this tool was rebuilt to stop doing.
Application SecurityBuilding and maintaining secure systems and software through secure development lifecycle practices, code review, application testing, and change management. This domain also covers application hardening and restricting user-facing application features that can be exploited.26 controlsNot yet written
Asset ManagementIdentifying, inventorying, classifying, and managing information assets including hardware, software, data, and cloud services throughout their lifecycle. Proper asset management is foundational — you cannot protect what you do not know you have.25 controlsNot yet written
Security TestingValidating the effectiveness of security controls through penetration testing, red teaming, vulnerability assessments, and security audits. Regular testing provides assurance that controls work as intended and helps identify gaps before attackers do.23 controlsNot yet written
Compliance and AuditEnsuring ongoing conformance with legal, regulatory, and contractual obligations through internal audits, management reviews, and compliance monitoring. This domain supports accountability and provides evidence of security programme effectiveness to stakeholders and regulators.22 controlsNot yet written
Physical SecurityProtecting physical premises, equipment, and media from unauthorised access, damage, and interference. This includes facility access controls, environmental protections, equipment security, and physical monitoring such as CCTV.18 controlsNot yet written
Network SecurityProtecting network infrastructure through segmentation, firewalls, intrusion detection and prevention, and secure architecture design. This domain covers controls that restrict unauthorised network access and monitor network traffic for threats.17 controlsNot yet written
Malware DefencePreventing, detecting, and responding to malicious software including viruses, ransomware, and spyware. This domain encompasses anti-malware tools, application control (whitelisting), email and web filtering, and macro restrictions.13 controlsNot yet written
Vulnerability ManagementContinuously identifying, assessing, prioritising, and remediating vulnerabilities across systems and applications. This includes patch management for operating systems and applications, vulnerability scanning, and penetration testing.12 controlsNot yet written
Email and Web SecurityProtecting against threats delivered via email and web browsing including phishing, drive-by downloads, and malicious attachments. Controls include email filtering, URL reputation, browser hardening, DNS security, and restricting Office macros.8 controlsNot yet written
Cloud SecurityDefining and implementing security controls specific to cloud service usage including shared responsibility models, cloud configuration management, cloud identity controls, and monitoring of cloud environments. As organisations migrate to cloud, this domain addresses the unique risks of multi-tenant and distributed infrastructure.4 controlsNot yet written
Threat IntelligenceCollecting, analysing, and acting on information about current and emerging cyber threats to inform defensive decisions. This includes understanding threat actors, tactics, techniques, and procedures (TTPs), and integrating threat intelligence into security operations.4 controlsNot yet written
Privacy & Data RightsLawful handling of personal information and the rights of data subjects/individuals — collection limitation, purpose, use and disclosure, access and correction, data-subject rights, lawful basis, and cross-border transfers.2 controlsNot yet written