EBH Security's methodologies are built on a set of recognized standards, applied by area of intervention.
Methodological framework
Each of EBH Security's own methodologies — PIBD, TRACE, UCM, ORBIT — is built on recognized public standards rather than isolated proprietary practices. The table below lists the standards applied by area of intervention.
| Domain | Standards applied |
|---|---|
| Threat modeling | MITRE ATT&CK, MITRE D3FEND, Cyber Kill Chain, Diamond Model, STRIDE |
| Risk management | ISO/IEC 27005, EBIOS Risk Manager, FAIR, NIST SP 800-30 |
| Security management | ISO/IEC 27001:2022, ISO/IEC 27002:2022, NIST CSF 2.0 |
| Audit | ISO/IEC 19011, PASSI DGSSI V2.1 standard, DGSSI audit guide |
| Penetration testing | PTES, OSSTMM, NIST SP 800-115, OWASP WSTG |
| Application security | OWASP ASVS, OWASP MASVS, OWASP SAMM, CWE Top 25 |
| Hardening | CIS Controls v8.1, CIS Benchmarks, NIST SP 800-53 |
| Industrial systems | IEC 62443, NIST SP 800-82, MITRE ATT&CK for ICS |
| Incident response | NIST SP 800-61r2, ISO/IEC 27035, SANS Incident Handling |
| Threat intelligence | STIX/TAXII, Traffic Light Protocol, Sigma, YARA |
| Vulnerability scoring | CVSS v4.0, EPSS |
| Cloud | CSA Cloud Controls Matrix, CIS Benchmarks for cloud |
The detail of how these standards are applied is presented on each of our methodologies — PIBD, TRACE, UCM, ORBIT — and on each dedicated service page.