Three Catalogs, One Complete Picture
Each cloud service is covered by three interlocking catalog types — Capabilities, Threats, and Controls — because real-world governance requires all three layers to be explicit and independently reusable.
Keeping them separate means your team can import only what is relevant, compose new service catalogs from existing building blocks, and map controls directly to the threats they mitigate — without carrying the weight of definitions you don't need.
What can each service do?
Capabilities
What might go wrong when we use this service?
Threats
How can we prevent negative outcomes?
Controls
Contribute to the Next Release
Catalogs are maintained as versioned YAML files. Generated artifacts are published here as each release is cut.
View on GitHub →