Getting assessed · 4.1

The documents an assessor reads first

The documents an assessor reads first. What the requirement says, what it means in practice, and what an assessor will ask.

For an independent reference point, see CIS Controls.

The central document

The system security plan

One document describing the environment and stating, for each security requirement, how it is met. It is the thing the assessment is conducted against: an assessor reads it, then examines whether what it says is true.

Which has a consequence suppliers underestimate. A plan that overstates produces findings across every family it touches. A plan that is accurate about a gap, with a documented route to closing it, is in a far better position than one that claims the gap does not exist.

What it contains

Five parts

A description of the system and what it does. The boundary, with the diagram and the reasoning. An inventory of what is inside it. For each requirement, how it is implemented in this environment. And the references to where the evidence for each sits.

The fourth part is where templates fail. A sentence restating the requirement is not a description of implementation, and an assessor reads several plans a month and recognises the pattern immediately.

The other documents

Four that are read alongside it

The plan of action, covering unmet requirements.

Network and data flow diagrams, which should agree with the boundary description rather than approximately resemble it.

The asset inventory, which is the document most often incomplete, usually because the shop floor was omitted.

Policies and procedures, which need to describe what the organisation does rather than what a template author imagined.

Writing it

By somebody who works there

A plan written entirely by an outside consultant describes a generic organisation, and the interviews will not match it. A plan written internally with specialist help on the structure describes this business, and the interviews confirm it.

The difference is visible in the first ten pages and it is the single strongest predictor of how the week goes.

Keeping it true

A living document, awkwardly

Environments change and plans do not update themselves. A plan describing a system that was decommissioned last year is a finding, and it is also a signal to the assessor about everything else.

Attach plan review to the change process from the blog entry on staying compliant, and review the whole thing annually regardless.

Length

As long as it needs and no longer

Plans of several hundred pages are common and much of the bulk is restated requirement text. It makes the document harder to maintain, harder to read and no more persuasive.

What the assessor wants for each requirement is a short, specific, true description of what happens here and where to see it.

The index

The document that makes the week work

A table mapping each requirement to the evidence and where it lives. It is not glamorous, it takes a day to build, and it converts an assessment from a search into a review.

Assessors notice its absence more than its presence.

Also

Elsewhere in getting assessed