Getting assessed · 4.3

The findings that recur

The findings that recur. What the requirement says, what it means in practice, and what an assessor will ask.

For an independent reference point, see NIST Cybersecurity Framework.

The pattern

Most findings are about evidence, not about controls

The recurring theme across reported assessment outcomes is not that suppliers lack security. It is that they cannot demonstrate it operating over time, which is the distinction this whole section keeps returning to.

Eight that recur

Commonly reported

The plan does not describe the environment. Outdated, generic, or written for a system that has changed.

No evidence of operation over a period. The control exists; the record does not.

The asset inventory is incomplete. Almost always the shop floor.

Access reviews not performed. Documented as quarterly, occurring occasionally.

Logs not retained or not reviewed. Collection without review is a common half-measure.

Departures not evidenced. Access removed, no record that it was.

External and vendor access uncontrolled. The standing connection, the shared vendor account.

Cryptography not validated. Encryption in use that does not meet the validation requirement where one applies. This surprises suppliers because the encryption is real and the specific requirement is about the module, not about whether data is encrypted.

Rests on

The security requirements in the NIST publication, including those concerning audit records, access review, media protection and the use of validated cryptographic modules where required.

The list here describes patterns commonly reported rather than statistics, and no figures are quoted.

Why the same ones

Three reasons

They are the requirements that need something to happen repeatedly rather than once. They are the ones no product satisfies by being installed. And they are the ones a supplier can believe are met without checking, because the underlying activity does genuinely happen.

Finding yours first

Check these eight before anybody else does

For each: what does the plan say, what does the person say, and what does the record show. Where the three disagree, you have found what an assessor would find, several months earlier and at no cost.

Most suppliers running this exercise find three or four of the eight and fix them in a quarter.

The shop floor ones

Where a manufacturer differs from an office

The inventory, the media protection, the physical access and the machine controllers. Assessors familiar with manufacturing look here first because it is where the requirement fits worst, and the entry on choosing an assessor suggests asking whether they have assessed organisations like yours.

The finding that is not fatal

Honest gaps with a plan

A requirement recorded as not yet met, with a plan, a date and an owner, is a different thing from one claimed as met and found otherwise.

Depending on the requirement and the rules in force, the first may be manageable and the second rarely is. Which is the argument for accuracy in the plan, made once more.

Also

Elsewhere in getting assessed