Running the programme · 2.6

Working to two standards at once

Working to two standards at once. What it costs, who decides, and what usually goes wrong.

For an independent reference point, see PMI project-management resources.

The situation

Most suppliers meet more than one

A defence manufacturer may face the certification requirement, a customer's own security schedule, an information security management standard demanded by a commercial client, and requirements attached to handling export-controlled technical data.

The overlap between them is substantial and it is not identity, and the difference between treating them as one programme and as several is most of the cost.

One control set

Implement once, evidence once, map to each

The working approach is a single set of controls implemented in your environment, a single evidence store, and a mapping showing which control satisfies which requirement in which framework.

The alternative, running two programmes, produces two sets of documents describing the same environment, two evidence collections that diverge, and an obvious question from whichever assessor notices.

The mapping

An aid, not an authority

Published crosswalks between frameworks exist and are useful for planning. They are approximate: a control that satisfies one framework's requirement may satisfy only part of another's, and the wording of the underlying obligation governs.

Use a mapping to avoid duplicate work and never to argue with an assessor. They assess against their standard and a crosswalk is not a defence.

Where they conflict

Three real frictions

Scope. Frameworks define their boundaries differently, and a scope drawn for one may be wrong for another. This is the conflict that costs most and it is worth resolving before implementing anything.

Evidence format. One auditor wants a policy, another wants a record of the policy operating. Collecting both from the start is cheaper than retrofitting.

Cycles. Different validity periods and audit dates mean the evidence has to be continuously current rather than assembled before a known date, which is better practice anyway and is more work.

Who owns the mapping

The same person who owns the programme

Splitting frameworks between owners recreates the two-programme problem with a co-ordination meeting attached. One owner, one control set, one mapping document that is maintained rather than produced once.

Order of attack

Do the strictest first, usually

Where one framework is a superset in a given area, satisfying it tends to satisfy the others there. That is not universal and it is a reasonable default.

The exception is where a contractual date makes one framework urgent and the others are not. Then the date governs and the mapping tells you what you have incidentally achieved for the rest.

Not advice

Which regimes apply to you

This entry describes the shape of running several at once. Which apply to your organisation, and what each obliges, depends on your contracts and on the nature of your technical data, including whether export control regimes are engaged.

Those are questions for qualified advisers in each area. Nothing here is legal, export or compliance advice, and the interaction between these regimes is exactly where a general summary is least safe to rely on.

The evidence store

One place, organised by control rather than by framework

Filing evidence under the framework that prompted it guarantees duplication. Filing it under the control it demonstrates, with tags for the frameworks it serves, means one artefact answers several auditors.

This is a decision taken in the first fortnight and expensive to reverse in year two.

Talking to two auditors

Do not let them meet your documents cold

Where the same environment is examined against two frameworks, give each auditor the mapping and say plainly which controls you are presenting against their requirement. That is helpful and it is also protective: it prevents an artefact written for one framework being read as an answer to the other and found wanting.

The overlap dividend

It is real and it arrives late

The second framework costs far less than the first, and the saving appears only if the first was implemented with mapping in mind. A supplier who expects to face several should say so at the start, because the decisions that produce the saving are all taken early.

Starting with the mapping

Build it before implementing, not after

A mapping produced at the end is an exercise in explaining what you did. Produced at the start it changes what you do: controls get implemented in the form that satisfies the strictest framework, and evidence gets collected in the format each will want.

It takes a few days with the standards open and it is the single highest-return document in a multi-framework programme.

Also

Elsewhere in running the programme