Getting assessed · 4.3
The findings that recur
The findings that recur. What the requirement says, what it means in practice, and what an assessor will ask.
For a related human-factors concept, further details provides additional context for interpreting behaviour without jumping to conclusions.
For an independent reference point, see NIST Cybersecurity Framework.
The pattern
Most findings are about evidence, not about controls
The recurring theme across reported assessment outcomes is not that suppliers lack security. It is that they cannot demonstrate it operating over time, which is the distinction this whole section keeps returning to.
Eight that recur
Commonly reported
The plan does not describe the environment. Outdated, generic, or written for a system that has changed.
No evidence of operation over a period. The control exists; the record does not.
The asset inventory is incomplete. Almost always the shop floor.
Access reviews not performed. Documented as quarterly, occurring occasionally.
Logs not retained or not reviewed. Collection without review is a common half-measure.
Departures not evidenced. Access removed, no record that it was.
External and vendor access uncontrolled. The standing connection, the shared vendor account.
Cryptography not validated. Encryption in use that does not meet the validation requirement where one applies. This surprises suppliers because the encryption is real and the specific requirement is about the module, not about whether data is encrypted.
The security requirements in the NIST publication, including those concerning audit records, access review, media protection and the use of validated cryptographic modules where required.
The list here describes patterns commonly reported rather than statistics, and no figures are quoted.
Why the same ones
Three reasons
They are the requirements that need something to happen repeatedly rather than once. They are the ones no product satisfies by being installed. And they are the ones a supplier can believe are met without checking, because the underlying activity does genuinely happen.
Finding yours first
Check these eight before anybody else does
For each: what does the plan say, what does the person say, and what does the record show. Where the three disagree, you have found what an assessor would find, several months earlier and at no cost.
Most suppliers running this exercise find three or four of the eight and fix them in a quarter.
The shop floor ones
Where a manufacturer differs from an office
The inventory, the media protection, the physical access and the machine controllers. Assessors familiar with manufacturing look here first because it is where the requirement fits worst, and the entry on choosing an assessor suggests asking whether they have assessed organisations like yours.
The finding that is not fatal
Honest gaps with a plan
A requirement recorded as not yet met, with a plan, a date and an owner, is a different thing from one claimed as met and found otherwise.
Depending on the requirement and the rules in force, the first may be manageable and the second rarely is. Which is the argument for accuracy in the plan, made once more.
Also
Elsewhere in getting assessed
- What the three levels are, and which appliesThe level is set by your contract, not by your size. Most suppliers handling controlled unclassified information are at the second.
- Reading the clause that binds youReading the clause that binds you. What the requirement says, what it means in practice, and what an assessor will ask.
- Which systems are in scopeWhich systems are in scope. What the requirement says, what it means in practice, and what an assessor will ask.
- Self-assessment, and why the scores driftedSelf-assessment, and why the scores drifted. What the requirement says, what it means in practice, and what an assessor will ask.
- Who assesses you, and how each kind worksWho assesses you, and how each kind works. What the requirement says, what it means in practice, and what an assessor will ask.
- What the standard does not requireWhat the standard does not require. What the requirement says, what it means in practice, and what an assessor will ask.
- Machines older than the requirementsA control written for a server, applied to a lathe with a shared login, a decade-old operating system and a USB port.
- Drawings, job packets and paperDrawings, job packets and paper. What the requirement says, what it means in practice, and what an assessor will ask.
- Removable media, and why bans failRemovable media, and why bans fail. What the requirement says, what it means in practice, and what an assessor will ask.
- Vendor remote accessVendor remote access. What the requirement says, what it means in practice, and what an assessor will ask.
- Technical data packages and what they containTechnical data packages and what they contain. What the requirement says, what it means in practice, and what an assessor will ask.
- Segmentation, and what it does not solveSegmentation, and what it does not solve. What the requirement says, what it means in practice, and what an assessor will ask.
- What insider risk actually coversWhat insider risk actually covers. What the requirement says, what it means in practice, and what an assessor will ask.
- What detection can and cannot establishWhat detection can and cannot establish. What the requirement says, what it means in practice, and what an assessor will ask.
- Monitoring, and where the law constrains itMonitoring, and where the law constrains it. What the requirement says, what it means in practice, and what an assessor will ask.
- The fortnight around a departureThe fortnight around a departure. What the requirement says, what it means in practice, and what an assessor will ask.
- Privileged access, and who reviews itPrivileged access, and who reviews it. What the requirement says, what it means in practice, and what an assessor will ask.
- False positives, and what they costFalse positives, and what they cost. What the requirement says, what it means in practice, and what an assessor will ask.
- The documents an assessor reads firstThe documents an assessor reads first. What the requirement says, what it means in practice, and what an assessor will ask.
- What counts as evidenceWhat counts as evidence. What the requirement says, what it means in practice, and what an assessor will ask.
- Plans of action, and their limitsPlans of action, and their limits. What the requirement says, what it means in practice, and what an assessor will ask.
- What the assessment week is likeWhat the assessment week is like. What the requirement says, what it means in practice, and what an assessor will ask.
- The certificate, and what it coversThe certificate, and what it covers. What the requirement says, what it means in practice, and what an assessor will ask.