Suspect a breach? Report it immediately — response within 1 hour.Report an incident

Standards applied

EBH Security's methodologies are built on a set of recognized standards, applied by area of intervention.

Methodological framework

A foundation of recognized standards

Each of EBH Security's own methodologies — PIBD, TRACE, UCM, ORBIT — is built on recognized public standards rather than isolated proprietary practices. The table below lists the standards applied by area of intervention.

DomainStandards applied
Threat modelingMITRE ATT&CK, MITRE D3FEND, Cyber Kill Chain, Diamond Model, STRIDE
Risk managementISO/IEC 27005, EBIOS Risk Manager, FAIR, NIST SP 800-30
Security managementISO/IEC 27001:2022, ISO/IEC 27002:2022, NIST CSF 2.0
AuditISO/IEC 19011, PASSI DGSSI V2.1 standard, DGSSI audit guide
Penetration testingPTES, OSSTMM, NIST SP 800-115, OWASP WSTG
Application securityOWASP ASVS, OWASP MASVS, OWASP SAMM, CWE Top 25
HardeningCIS Controls v8.1, CIS Benchmarks, NIST SP 800-53
Industrial systemsIEC 62443, NIST SP 800-82, MITRE ATT&CK for ICS
Incident responseNIST SP 800-61r2, ISO/IEC 27035, SANS Incident Handling
Threat intelligenceSTIX/TAXII, Traffic Light Protocol, Sigma, YARA
Vulnerability scoringCVSS v4.0, EPSS
CloudCSA Cloud Controls Matrix, CIS Benchmarks for cloud

Understand how these standards apply

The detail of how these standards are applied is presented on each of our methodologies — PIBD, TRACE, UCM, ORBIT — and on each dedicated service page.