What the requirement actually says · 1.6
What the standard does not require
What the standard does not require. What the requirement says, what it means in practice, and what an assessor will ask.
For an adjacent operational perspective, this resource explains the topic in a practical workplace context.
For an independent reference point, see DFARS 252.204-7012.
Why this entry exists
Half of what suppliers fear is not required
A large amount of received wisdom about this requirement is wrong in the direction of severity, some of it repeated by people selling remedies. Knowing what is not asked for saves money and it also makes the genuine requirements easier to take seriously.
Five things not required
Common beliefs that do not survive the text
That your whole company must be in scope. The requirement applies to systems handling covered information. A documented boundary is the intended approach, not an evasion.
That everything must be in a government cloud. Where a cloud service is used for covered information it must meet a specified baseline. That is not the same as a requirement to move everything, and on-premises arrangements remain available.
That you need a security operations centre. The requirements concern capability and evidence rather than a particular organisational structure. Small suppliers satisfy monitoring requirements with modest arrangements, documented.
That every control needs a product. A documented manual process, actually performed and recorded, satisfies many requirements.
That certification is required before you may bid. What is required, and when, is stated in the solicitation. It varies, and assuming the strictest reading has led suppliers to decline work they were eligible for.
What is genuinely demanding
Three things that are as hard as feared
Evidence over time. Not a snapshot: records showing controls operating across a period.
The documentation. A plan that describes your environment accurately and is maintained as it changes.
The shop floor. Equipment that cannot implement the controls the standard assumes, which is the subject of the next part of this section.
Where the myths come from
Three sources
Vendors, whose interest is in the broadest reading. Consultants quoting a scope. And other suppliers, repeating what they were told, which is how a misreading propagates through a supply chain faster than a correction.
The remedy is the one this section keeps recommending: read the source. Both documents are published and free.
Checking a claim
Two questions for anybody who tells you something is required
Which document says so, and which section? And does it say required or does it say recommended?
Most claims that fail these are not deceptions. They are somebody repeating a summary of a summary, which is what this page is, and which is why it names its sources.
The NIST publication containing the security requirements, and the programme documentation describing assessment. Both are published in full and free to read.
Every statement in this entry about what is not required should be checked against those documents rather than against this page.
The proportionality principle
The standard expects judgement
Several requirements are written to permit implementation appropriate to the organisation and the risk. That is deliberate, it is what allows a ten-person shop and a large prime to satisfy the same requirement differently, and it is the part vendors are least likely to mention.
Judgement must be documented. An undocumented judgement is indistinguishable from an omission.
Where to be careful
Two places the flexible reading is wrong
Requirements written in absolute terms, which do not admit proportionality. And anything your specific contract makes stricter than the baseline, which a prime's schedule frequently does.
Check both against the text before relying on a flexible interpretation.
Cost of over-reading
What suppliers spend on things not asked for
Whole-company scope where a boundary would do. Cloud migrations that were not necessary. Tooling bought for controls that a documented manual process satisfies. Declining eligible work.
Each of these is common and each is avoidable by reading the requirement rather than a description of it.
Cost of under-reading
And the other direction
Assuming flexibility where the text is absolute, treating the prime's stricter schedule as decoration, or reading a recommendation as optional when the contract made it binding.
Both errors come from the same habit, which is trusting a summary.
The honest summary
It is demanding and it is finite
There is a defined set of requirements, published, free to read, with a defined assessment against it. That is a considerable amount of work and it is a bounded amount, which distinguishes it from most things described as an ongoing security posture.
Suppliers who read the source find it smaller than the version they had been told about, and harder than the version they had hoped for.
What to do with this entry
Take the list to whoever is advising you
Ask, for each of the five, whether they agree and where the text says otherwise. A good adviser will agree with most and correct one, and the correction will be specific to your contracts.
An adviser who insists all five are required is worth a second opinion.
One more that is not required
A consultant is not mandatory
Nothing in the requirement obliges you to engage anybody. Suppliers have prepared and passed with internal effort, external help for specific parts, and the free published guidance.
Help is frequently worth buying and it is a commercial choice rather than an obligation, and it is presented as an obligation often enough to be worth saying.
Also
Elsewhere in what the requirement actually says
- What the three levels are, and which appliesThe level is set by your contract, not by your size. Most suppliers handling controlled unclassified information are at the second.
- Reading the clause that binds youReading the clause that binds you. What the requirement says, what it means in practice, and what an assessor will ask.
- Which systems are in scopeWhich systems are in scope. What the requirement says, what it means in practice, and what an assessor will ask.
- Self-assessment, and why the scores driftedSelf-assessment, and why the scores drifted. What the requirement says, what it means in practice, and what an assessor will ask.
- Who assesses you, and how each kind worksWho assesses you, and how each kind works. What the requirement says, what it means in practice, and what an assessor will ask.
- Machines older than the requirementsA control written for a server, applied to a lathe with a shared login, a decade-old operating system and a USB port.
- Drawings, job packets and paperDrawings, job packets and paper. What the requirement says, what it means in practice, and what an assessor will ask.
- Removable media, and why bans failRemovable media, and why bans fail. What the requirement says, what it means in practice, and what an assessor will ask.
- Vendor remote accessVendor remote access. What the requirement says, what it means in practice, and what an assessor will ask.
- Technical data packages and what they containTechnical data packages and what they contain. What the requirement says, what it means in practice, and what an assessor will ask.
- Segmentation, and what it does not solveSegmentation, and what it does not solve. What the requirement says, what it means in practice, and what an assessor will ask.
- What insider risk actually coversWhat insider risk actually covers. What the requirement says, what it means in practice, and what an assessor will ask.
- What detection can and cannot establishWhat detection can and cannot establish. What the requirement says, what it means in practice, and what an assessor will ask.
- Monitoring, and where the law constrains itMonitoring, and where the law constrains it. What the requirement says, what it means in practice, and what an assessor will ask.
- The fortnight around a departureThe fortnight around a departure. What the requirement says, what it means in practice, and what an assessor will ask.
- Privileged access, and who reviews itPrivileged access, and who reviews it. What the requirement says, what it means in practice, and what an assessor will ask.
- False positives, and what they costFalse positives, and what they cost. What the requirement says, what it means in practice, and what an assessor will ask.
- The documents an assessor reads firstThe documents an assessor reads first. What the requirement says, what it means in practice, and what an assessor will ask.
- What counts as evidenceWhat counts as evidence. What the requirement says, what it means in practice, and what an assessor will ask.
- The findings that recurThe findings that recur. What the requirement says, what it means in practice, and what an assessor will ask.
- Plans of action, and their limitsPlans of action, and their limits. What the requirement says, what it means in practice, and what an assessor will ask.
- What the assessment week is likeWhat the assessment week is like. What the requirement says, what it means in practice, and what an assessor will ask.
- The certificate, and what it coversThe certificate, and what it covers. What the requirement says, what it means in practice, and what an assessor will ask.