• cyber-suite-single-tenant-v2.6.105 bd515d9278

    gandetl_admin released this 2026-10-02 10:24:45 +00:00 | 0 commits to main since this release

    Cyber Suite — single-tenant export

    Version: v2.6.105
    Built (UTC): 2026-10-02T10:23:28Z
    Source tag: v2.6.105
    Image digest: sha256:ebd31ac7d44dadfdb1021920e7be60e0e1d734a9ee245166afdb10da33ccac73
    Target: linux/amd64 (CGO_ENABLED=0, static)
    Provenance: binary extracted from the cosign-verified image build.yml
    published for this commit — never rebuilt here.

    Notable since v2.6.103 (54 commits):

    SCF 2026.3 — please read this one

    • The control catalogue moves to SCF 2026.3. The 34 domains are unchanged, but
      the SCF Council renumbered most controls and REUSED the vacated numbers: the
      control that was GOV-01 is now GOV-02, and GOV-01 now means something else.
      1,534 controls become 1,591, assessment objectives 5,956 become 6,446, and
      none of the old controls were dropped.
    • Upgrading refreshes the shipped catalogue on its own, with no action from
      you. Your own control register does NOT move until somebody presses
      Reset to SCF — until then it carries the numbering you already had.
    • So the order matters: upgrade, confirm the suite is running this version,
      then Reset to SCF in each workspace. Run the preview first — it lists
      exactly what will be deleted. If it shows evidence, applicability decisions
      or control testing you want to keep, do not reset: tell us, because those
      records are keyed to the old control numbers and need translating rather
      than deleting.
    • Risks and threats are now graded per control as Likely or Possible rather
      than simply mapped, so a control carries the dozen or so risks that actually
      bear on it instead of nearly the whole catalogue.

    Reset to SCF

    • An install with its own authored policy library now gets THAT library back
      after a reset. It previously restored the generic SCF documents over the
      top, and nothing in the product could put the authored ones back.

    Policies, standards and the control register

    • The policies and standards tables drop the summary column, so several times
      as many rows fit on a screen. The summary is still searchable and still on
      the document; hover a name to read it.
    • The control register and the RACI matrix filter by SCF domain, so working
      inside one domain is a single selection rather than a search term that also
      matches any control mentioning it.

    Elsewhere in the suite

    • Cyber Risk Assessment rescales the register from 5x5 to 4x4.
    • Exceptions in GRC become tabs, on both the list and the detail page.
    • Cyber Advisory gains a Designs tab holding all three design documents for an
      engagement — high level, detailed and data flow — and a Components tab under
      Threats. A finished threat model leads with View rather than offering to run
      it again, and the Word download no longer 404s.

    Design history

    • Each design keeps its versions. Uploading a replacement no longer displaces
      the one before it: the newest is shown as current and the earlier ones
      collapse behind it, each still downloadable.
    • Regenerating a High-Level Design keeps the generation it supersedes, marked
      AI generated so it is never mistaken for a document somebody attached.
      Uploaded and generated designs are numbered separately.
    • Versions are fixed at upload rather than counted from a position in a list,
      so a version you cite in an assessment keeps pointing at the same file.
      Documents that predate this carry no number rather than a misleading v1.
    Downloads