· intuitem · News · 8 min read
What's New in CISO Assistant — Week 43, 2026 (v4.1.1)
v4.1.1 adds vendor tiering backed by scored criticality forms, outcome rules on frameworks that check the CyFun 2025 conformity criteria, an export to the official CCB CyFun tools, paginated external APIs and bulk writes in workflows, an experimental domain compliance tree, more MCP coverage (advanced EBIOS RM, assets, teams), and new libraries: China PIPL, OWASP SAMM v2.2, ISO 27001 ↔ HDS and IEC 62443 ↔ ANSSI mappings.
This post covers v4.1.1, published on October 9. It is labelled a patch, but it is a large one. Third-party risk management gets vendor tiering. Framework outcome rules can now compute scores and check conformity criteria, and CyFun 2025 is the first framework to use them. Workflows can page through external APIs and write objects in bulk. There is no breaking change in this release.
Vendor Tiering (TPRM)
Vendors could be assessed, but not ranked. v4.1.1 adds an org-wide tier scale and a way to set a vendor’s tier from a scored questionnaire (PR #4973).
- Tier scale — an ordered scale, by default critical, high, medium and low, edited from Third parties → Tier scale by administrators and domain managers of Global. Tiers can be renamed, recoloured, reordered and hidden. Built-in tiers cannot be deleted.
- Tier on vendors — the entity page and table show the tier, its source (manual, assessment or override), its date and its score. You can set it from the edit form, with a batch action or with a right-click on Change tier, and filter entities by tier, including those with no tier.
- Criticality forms — quick forms can now score pages (sum, max or average) and compute values with number rules. A form can name its subject, such as the vendor being assessed, and a publication can set the vendor’s tier when a response is accepted, from score bands, outcome floors or both. The highest result wins.
- Assessment flow — Assess tier on the vendor page starts a response about that vendor. The projected tier can be shown while the form is filled in. A self-assessment applies the tier on submit when the submitter can edit the vendor, otherwise it goes to review. A publication can also always require review. The reviewer sees what accepting will write and can override it with a justification.
- Starter library — a bilingual Vendor tiering form (business impact and data exposure) comes with a suggested tier setup that is pre-filled when you publish it.
- Library builder — quick forms can be published from their page, number rules can use a page’s score, tier bands are pre-filled from the scale, and Ctrl/Cmd+S saves. URNs are no longer re-minted on every save.
Thanks to @ab-smith.
Outcome Rules on Frameworks, and CyFun 2025
The CEL rules that quick forms use can now run on frameworks too (PR #5012).
- Number rules compute a value that other rules can read. Labelled ones are shown on the audit page next to the outcomes.
- Rules run in order, so a yes/no rule can build on the rules above it, for example “criteria met” when every criterion above is met. Quick forms follow the same order now.
- Rules can be limited to implementation groups, and they apply to audits whose scope includes one of those groups.
- Rules can read scores — the audit’s implementation, documentation and maturity scores and its target; each requirement’s documentation and maturity scores and groups; and per-section and per-group scores, computed with the audit’s calculation method.
- Outcomes are refreshed when scores, scope or scoring settings change, or when a library update changes the rules. A rule that names an unknown requirement, section or group refuses the library load.
CyFun 2025 audits use these rules to show the CCB conformity criteria for their level: total maturity (2.5 for BASIC, 3 for IMPORTANT, 3.5 for ESSENTIAL), every key measure, every category at 3 or more for ESSENTIAL, and the exclusion limits. Each audit then gets an overall “CCB conformity criteria met” result. Labels are in English, French and Dutch.
PR #4994 aligns CyFun scoring with the CCB’s own tools:
- Scores are rounded once, at the end, to two decimals. Maturity used to be truncated three times.
- CyFun 2023 and 2025 audits default to Average of averages, and CyFun 2025 counts N/A at the level’s target. The 1–5 scale is locked, and an unset documentation score counts as the scale minimum, not 0. These defaults are declared by the framework. Existing audits are not changed.
- Export to the official CCB tool — CyFun 2023 audits export to the CCB CyFun 2023 workbook, and CyFun 2025 audits export to the BASIC, IMPORTANT or ESSENTIAL workbook based on their implementation groups. The workbook’s charts and dropdowns are kept.
- The CyFun 2025 library is aligned with the 2026 CCB booklets in English, Dutch and French, and the CyFun 2023 → 2025 mapping follows the CCB transposition table.
- A new setting, Show the documentation score first, applies wherever both scores are shown.
Thanks to @ab-smith.
Workflows: Paginated APIs and Bulk Writes
Workflows that pull data from security tools now handle the volumes those tools return (PR #5027).
- HTTP requests support OAuth client-credentials authentication and pagination, with safeguards on the number of pages and a pagination status in the output.
- A bulk action creates or updates objects from a list, with a configurable item limit and errors handled per item.
- Run lists show output previews, and output size limits can be configured.
- New templates — Microsoft Entra ID identity metrics, Microsoft Defender device inventory and SentinelOne coverage.
Thanks to @ab-smith.
MCP: Advanced EBIOS RM, Assets and Teams
- Advanced EBIOS RM — the MCP server catches up with v4.1.0: study likelihood methods, the study frame, operating-mode likelihood, kill-chain steps with techniques, success probability, difficulty and supporting assets, and target-objective categories on RO/TO couples (PR #5007). Thanks to @ab-smith.
- Assets —
update_assetno longer resets security objectives it was not asked to change. Asset tools now cover all security criteria, capabilities and recovery objectives, and durations can be written as2hor1h30m. A newget_asset_security_gapstool compares objectives with capabilities. Entities gainrelationshipandaddress(PR #4981). Thanks to @JohnGanem. - Teams — new tools list, create and update teams, including leader, deputies and members, so risk owners can be managed as teams. Users can be given by name, ID or email (PR #4983). Thanks to @jledoze.
Audits, Documents and Import
- Exclude N/A from the tree — a toggle on the audit page and in table mode removes not-applicable requirements from the percentages (PR #4853). Thanks to @monsieurswag.
- Global evidences in the audit’s evidence list — evidence attached to the audit itself now appears there, along with evidence linked through applied controls and task templates (PR #4845). Thanks to @Axxiar.
- Pending document revisions — a v2 still in review used to be invisible while v1 was in force. The documents list now shows it as a badge, and the document header shows both revisions (PR #4817). Thanks to @Claquetteuuuh.
- Domains in the data wizard — domains can be imported and exported with their filtering labels and IAM-group setting, and an export re-imports as is. Each imported row is now written in its own transaction (PR #5006). Thanks to @Spaghetto784.
- Threats in risk imports — a
threatscolumn links imported risk scenarios to threats by ref_id or name (PR #5017). Thanks to @martinzerty. - Findings exports — recommendation and priority are now included in the Markdown, PDF and XLSX exports (PR #5001). Welcome to @theluckystrike, who makes their first contribution with this fix.
- Domain compliance tree (experimental) — a new view of audit results across domains, by compliance or score, with filters for implementation group, section and campaign, and a shortcut to the weakest audited areas (PR #5029). Thanks to @ab-smith.
Framework & Library Updates
- China PIPL — the Personal Information Protection Law, with its compliance audit measures, plus Chinese labels for more of the interface (PR #5024).
- OWASP SAMM v2.2 — the Software Assurance Maturity Model, with maturity scoring by function and practice and target levels (PR #5031).
- ISO/IEC 27001:2022 ↔ HDS v2.0 — mappings in both directions, with annotated HDS requirements (PR #5000).
- IEC 62443 ↔ ANSSI — mappings between the ANSSI detailed measures guide for industrial systems (v2) and six parts of IEC 62443 (PR #5028).
Thanks to @ab-smith.
Security
- Score visibility on inherited results — when field visibility hid an audit’s scores from a role, the inheritance overlay in the framework report and combined tree still carried them, so “Apply domain inheritance” showed them anyway. The overlay is now redacted with the same rules, including values coming from ancestor audits (PR #4899). Thanks to @nas-tabchiche.
- Risk acceptance approvers must now be able to approve both in the acceptance’s domain and in the domain of every linked scenario (PR #5020).
- CRQ budget overview now respects the user’s permissions and no longer exposes hidden control owners (PR #5019).
Bug Fixes
- Scores saved without user input — on the auditee page, opening an unscored requirement saved it as 0 and marked it scored. Scores are now saved only when you move the slider (PR #5002).
- Deselected EBIOS RM operational scenarios were still copied into the synced risk assessment through their attack path (PR #4958).
- Risk assessment import left every impact and probability unrated when the matrix came from the library builder. Labels now match level positions, and unknown values raise a warning instead of erasing the rating (PR #4987).
- Library import/export now carries visibility expressions, importance, target, min and max scores, and score definitions (PR #5022). Thanks to @eric-intuitem.
- ServiceNow — the table picker shows scoped app tables such as
sn_customerservice_case, and both pickers keep paging past pages that ACLs shortened (PRs #4993, #4998). Existing integrations need a schema refresh in the field mapper. Thanks to @nas-tabchiche. - Embedded table filters are now remembered per page (PR #4630), and the evidence attachment hash is shown and backfilled for older revisions (PR #4785).
- Smaller fixes: risk-level filter labels across several matrices, multi-value domain and perimeter filters on risk scenarios, the “current view” export including the search, tooltips in dark mode, library quick filters, and the CSV/XLSX format on public snapshot exports (PRs #5020, #4990, #4982).
Thanks to @Spaghetto784 and @martinzerty for many of these fixes.
Localisation
- Polish — the Polish localisation is updated (PR #4968). Welcome to @amrutadotorg, who makes their first contribution with this update.
For full details, see the v4.1.1 release notes on GitHub.