The wider regime · 5.1

The other frameworks you have also met

The other frameworks you have also met. What it costs, who decides, and what usually goes wrong.

For an independent reference point, see Google Cloud compliance resources.

The landscape

What a defence manufacturer typically meets

The certification programme and the NIST publication behind it are the ones with a contractual date attached. Around them sit several others that arrive from different directions.

An information security management standard, usually demanded by a commercial customer rather than by government, certifying that you run a management system rather than that you meet a specified control set.

Service organisation reporting, requested by customers who buy a service from you and want assurance about how you operate it.

Cloud authorisation requirements, which reach you indirectly: not something you hold, but something your providers must satisfy for you to use them for covered information.

Export control, which is not a security framework at all and which constrains the same decisions. The next entry names it and declines to advise on it.

Customer security schedules, which are bespoke, proliferate, and are the ones nobody counts.

How they differ

Three axes worth keeping straight

What is certified. A control set, a management system, or a report on operating effectiveness. These are different claims and customers frequently ask for one while meaning another.

Who assesses. An accredited body, an auditor of your choosing, a government agency, or you.

What compels it. A contract clause, a customer preference, or a market expectation. The first has a date; the others have leverage.

The overlap

Substantial, and never total

Access control, logging, incident response and configuration management appear in all of them and are written differently in each. The controls you implement can serve several; the wording you evidence against cannot be shared blindly.

The entry on working to two standards sets out how to run this without duplicating the programme.

Which to pursue

Contract first, market second

Anything with a clause and a date comes first, because failing it has a defined consequence. Anything requested by a customer without a clause is a commercial decision: what revenue depends on it, and what it costs against the alternatives.

Suppliers frequently pursue a well-known certification because it is well known, ahead of the one their contracts actually require. It is an expensive way to be diligent.

The customer questionnaire

The framework nobody names

The two-hundred-question spreadsheet that arrives from a customer's procurement team is, in practice, a framework you have to satisfy. It has no standard, no assessor and no certificate, and it consumes real time several times a year.

The defence against it is a maintained set of answers, kept current with the evidence, so that each new questionnaire is an editing job rather than a research project.

What certification does not buy

Holding one does not answer another

A customer asking for a specific standard is rarely satisfied by a different one, even where the coverage is comparable. Offering a mapping sometimes works and is worth trying; assuming it will is not.

The register

Keep a list of what you are subject to

Framework, what compels it, who assesses, when it expires, who owns it. One page, reviewed annually.

Most suppliers cannot produce this and discover an obligation when a customer asks about it, which is the worst moment to begin finding out.

Also

Elsewhere in the wider regime