Skip to main content

Three Catalogs, One Complete Picture

Each cloud service is covered by three interlocking catalog types — Capabilities, Threats, and Controls — because real-world governance requires all three layers to be explicit and independently reusable.

Keeping them separate means your team can import only what is relevant, compose new service catalogs from existing building blocks, and map controls directly to the threats they mitigate — without carrying the weight of definitions you don't need.

CCC catalog structure diagram

What can each service do?

Capabilities

What might go wrong when we use this service?

Threats

How can we prevent negative outcomes?

Controls

Contribute to the Next Release

Catalogs are maintained as versioned YAML files. Generated artifacts are published here as each release is cut.

View on GitHub →