What the requirement actually says · 1.6

What the standard does not require

What the standard does not require. What the requirement says, what it means in practice, and what an assessor will ask.

For an independent reference point, see DFARS 252.204-7012.

Why this entry exists

Half of what suppliers fear is not required

A large amount of received wisdom about this requirement is wrong in the direction of severity, some of it repeated by people selling remedies. Knowing what is not asked for saves money and it also makes the genuine requirements easier to take seriously.

Five things not required

Common beliefs that do not survive the text

That your whole company must be in scope. The requirement applies to systems handling covered information. A documented boundary is the intended approach, not an evasion.

That everything must be in a government cloud. Where a cloud service is used for covered information it must meet a specified baseline. That is not the same as a requirement to move everything, and on-premises arrangements remain available.

That you need a security operations centre. The requirements concern capability and evidence rather than a particular organisational structure. Small suppliers satisfy monitoring requirements with modest arrangements, documented.

That every control needs a product. A documented manual process, actually performed and recorded, satisfies many requirements.

That certification is required before you may bid. What is required, and when, is stated in the solicitation. It varies, and assuming the strictest reading has led suppliers to decline work they were eligible for.

What is genuinely demanding

Three things that are as hard as feared

Evidence over time. Not a snapshot: records showing controls operating across a period.

The documentation. A plan that describes your environment accurately and is maintained as it changes.

The shop floor. Equipment that cannot implement the controls the standard assumes, which is the subject of the next part of this section.

Where the myths come from

Three sources

Vendors, whose interest is in the broadest reading. Consultants quoting a scope. And other suppliers, repeating what they were told, which is how a misreading propagates through a supply chain faster than a correction.

The remedy is the one this section keeps recommending: read the source. Both documents are published and free.

Checking a claim

Two questions for anybody who tells you something is required

Which document says so, and which section? And does it say required or does it say recommended?

Most claims that fail these are not deceptions. They are somebody repeating a summary of a summary, which is what this page is, and which is why it names its sources.

Rests on

The NIST publication containing the security requirements, and the programme documentation describing assessment. Both are published in full and free to read.

Every statement in this entry about what is not required should be checked against those documents rather than against this page.

The proportionality principle

The standard expects judgement

Several requirements are written to permit implementation appropriate to the organisation and the risk. That is deliberate, it is what allows a ten-person shop and a large prime to satisfy the same requirement differently, and it is the part vendors are least likely to mention.

Judgement must be documented. An undocumented judgement is indistinguishable from an omission.

Where to be careful

Two places the flexible reading is wrong

Requirements written in absolute terms, which do not admit proportionality. And anything your specific contract makes stricter than the baseline, which a prime's schedule frequently does.

Check both against the text before relying on a flexible interpretation.

Cost of over-reading

What suppliers spend on things not asked for

Whole-company scope where a boundary would do. Cloud migrations that were not necessary. Tooling bought for controls that a documented manual process satisfies. Declining eligible work.

Each of these is common and each is avoidable by reading the requirement rather than a description of it.

Cost of under-reading

And the other direction

Assuming flexibility where the text is absolute, treating the prime's stricter schedule as decoration, or reading a recommendation as optional when the contract made it binding.

Both errors come from the same habit, which is trusting a summary.

The honest summary

It is demanding and it is finite

There is a defined set of requirements, published, free to read, with a defined assessment against it. That is a considerable amount of work and it is a bounded amount, which distinguishes it from most things described as an ongoing security posture.

Suppliers who read the source find it smaller than the version they had been told about, and harder than the version they had hoped for.

What to do with this entry

Take the list to whoever is advising you

Ask, for each of the five, whether they agree and where the text says otherwise. A good adviser will agree with most and correct one, and the correction will be specific to your contracts.

An adviser who insists all five are required is worth a second opinion.

One more that is not required

A consultant is not mandatory

Nothing in the requirement obliges you to engage anybody. Suppliers have prepared and passed with internal effort, external help for specific parts, and the free published guidance.

Help is frequently worth buying and it is a commercial choice rather than an obligation, and it is presented as an obligation often enough to be worth saying.

Also

Elsewhere in what the requirement actually says