Running the programme · 2.2

Running it as a project rather than as a document

Running it as a project rather than as a document. What it costs, who decides, and what usually goes wrong.

For an independent reference point, see ISACA governance resources.

The distinction

A document that gets updated, or a project with a date

Most suppliers treat compliance as a folder somebody refreshes when an audit is announced. That works while the requirement is self-attested and stops working when somebody comes to check.

A project has a scope, a plan, milestones that can be verified, a budget, an owner and a risk register. Compliance preparation has all of those available to it and is rarely given them.

The phases

Seven, in order, and the order matters

  • Define the boundary.
  • Analyse the gap against the standard.
  • Remediate, in the order the gap analysis gives.
  • Document: the plan and its supporting procedures.
  • Collect evidence.
  • Check readiness, internally or with somebody external.
  • Be assessed.

Attempting them out of order is the commonest cause of rework. Remediating before the boundary is drawn secures systems that need not have been in scope; documenting before remediating produces a plan describing an environment that no longer exists by the time anybody reads it.

Milestones

Checkable, not proportional

"Eighty per cent complete" is not a milestone. "The boundary diagram is signed off by the sponsor" is. "All access control requirements have evidence dated within ninety days" is.

A milestone somebody outside the project can verify prevents the slow drift where everything is nearly done for five months.

Dependencies

Three that are outside your control

Assessor availability. The number of accredited assessors is finite and demand is not evenly spread. Booking is a lead time measured in months and it belongs in the plan as a dependency rather than as a final step.

Vendor lead times. Network equipment, controller upgrades and professional services all queue.

Machine downtime. Anything requiring a machine to stop competes with production, and production wins. Get the windows booked early and treat them as fixed.

The risk register

Five entries, reviewed monthly, actually used

Most registers are written once and never opened. A short one that gets read is worth more: the discovery finds more than expected, the owner leaves, an assessor cannot be booked, a machine cannot be remediated, a key vendor slips.

Each with a named response rather than a probability score. The score is documentation; the response is management.

Grouping the work

Not a list of every requirement

A plan with a line per requirement is unmanageable and hides the structure. Group by control family and by system: what has to happen to the enclave, what has to happen on the floor, what has to be written.

The requirements then become a checklist inside each group rather than the plan itself.

What makes this different

The deliverable is evidence and the deadline is external

In most internal projects the deadline is negotiable and the deliverable is a working thing. Here the deadline sits in somebody else's contract and the deliverable is a demonstration that things were true over a period.

Which means work cannot be compressed at the end. Evidence covering ninety days requires ninety days, and no amount of effort in the final month produces it.

The kickoff

Half a day, with the people who will be asked for things

Production, quality, IT, whoever handles contracts. What is happening, why, what will be asked of each of them, and when. It costs half a day and it prevents the pattern where the compliance owner spends six months explaining themselves one conversation at a time.

Tracking

Use whatever the business already uses

A new tool for this project means one more place to look and a licence to justify. Whatever tracks work elsewhere in the business is adequate, and it has the advantage that people already open it.

Contingency in the plan

Put the float where the risk is

Not a fortnight at the end, which gets consumed by whatever ran late first. Float belongs after discovery and after shop-floor remediation, because those are the two phases that overrun.

A plan with float at the end has a date that moves. One with float in the right two places has a date that holds through the ordinary surprises.

Closing a phase

Say when something is finished

Phases that are never formally closed stay open, and work drifts back into them for months. A short written statement that the boundary is agreed, dated and signed by the sponsor, is what allows the next phase to proceed on a stable base.

Also

Elsewhere in running the programme