RESOURCES / CYBERCORIA
Practical guides.
Professional resources for turning a framework or technical finding into an actionable approach. Each guide is presented with context, limits and official sources.
Framing sources verified on August 25, 2026
Context and references are visible before any resource request.
A resource structures an approach; it does not certify an organisation or its information system.
Framing documents can be consulted directly from this page.
01 GUIDE · INFORMATION SYSTEM MAPPING
The information system mapping guide
A working resource for building a map that architecture, security, continuity and compliance teams can actually use — rather than a collection of diagrams.
Resource provided by Cartographit
Information-system mapping becomes useful when it connects business activities, applications, data, infrastructure and dependencies. ANSSI explicitly links mapping to protection, defence and resilience and provides a progressive five-step approach.
This guide is offered as a complementary resource for turning that methodological framing into operational modelling, data collection and maintenance. Cybercoria does not present the resource as a regulatory requirement or evidence of compliance.
QUESTIONS TO FRAME
- Which scope should be mapped first, and for which decision?
- Which objects and relationships are needed to explain critical dependencies?
- How can the right level of detail be chosen without making the repository unmanageable?
- How should data governance and ongoing maintenance be organised?
FRAMING SOURCES
2018-11-21ANSSI — Information system mappingOfficial guide presenting a practical five-step approach and linking mapping to information-system protection, defence and resilience.↗2018-12-13ANSSI — Five-step information system mapping guide (PDF)Detailed ANSSI methodology for building an information-system map that supports operational cybersecurity needs.↗2022-12-14EUR-Lex — Directive (EU) 2022/2555, NIS2Consolidated directive, notably Article 20 on governance and Article 21 on cybersecurity risk-management measures.↗2022-12-14EUR-Lex — Regulation (EU) 2022/2554, DORAOfficial Digital Operational Resilience Act text, notably Articles 5, 6 and 28.↗02 GUIDE · CLOUD SECURITY
Practical cloud security audit guide
A resource for scoping a cloud audit around identities, exposure, data and dependencies, then turning technical findings into understandable remediation priorities.
Resource provided by Livodit AI
Cloud posture cannot be reduced to a score. Security depends on provider assurances, the chosen architecture and the way the customer configures, administers and operates its services. ANSSI notably states that a SecNumCloud-qualified offering does not by itself determine the security level of the digital service hosted on it.
The guide is presented as a practical resource for structuring analysis and prioritisation. It does not replace an audit tailored to the actual scope, a risk assessment or the organisation’s applicable obligations.
QUESTIONS TO FRAME
- What is actually in scope: accounts, projects, subscriptions, tenants and regions?
- Which identities or administration interfaces can materially change security posture?
- Which findings create credible exposure or attack paths in the information-system context?
- How should technical urgency, business criticality and remediation effort be separated?
FRAMING SOURCES
2022-03-08ANSSI — SecNumCloud requirements baseline v3.2Cloud-provider qualification baseline covering technical, organisational and provider requirements; it can also be used as a good-practice reference.↗2024-08-14ANSSI — Cloud hosting recommendations and SecNumCloud focusANSSI notes that qualification provides assurance about the cloud offering and its operation, but does not determine the security level of the customer services deployed on it.↗METHOD
A useful resource starts with a clear scope and verifiable references.
Cybercoria separates official-source statements, editorial analysis and resources provided by vendors.
Read the editorial method →