Blog

Most Compliance Work Stops When the Policy Is Signed

There is a moment in most compliance engagements that feels like completion and is not. The policy suite is finished, the governing body has approved it, the consultant’s invoice is settled, and the business reasonably concludes that the matter has been dealt with.

What has actually happened is that a position has been established at a single point in time, in an environment that will not hold still, under standards that expect the position to be maintained and evidenced continuously rather than declared once. From that day forward the documentation and the reality begin separating, slowly at first and then not slowly at all.

The decay is predictable

It follows a recognisable timeline, and having watched it in a number of environments it is worth setting out plainly.

Within the first quarter, the committee has not met. The charter exists, the terms of reference are written, the members were named, and no meeting has been convened because convening it was somebody’s responsibility in principle and nobody’s in practice. This is the earliest and most reliable indicator, and it matters because the committee is the mechanism through which everything else is supposed to be reviewed.

By the second quarter, staff have changed. People have joined and left, and the access review that would have caught the departures has not happened. The new arrivals were issued equipment that the endpoint deployment did not automatically cover, so the coverage figure quoted in the evidence at signature is now wrong.

By the third quarter, the environment has moved. A system has been replaced, a supplier has changed, something has been migrated to a cloud service that nobody assessed against the policy suite. The policies still describe the environment as it was at the point of writing, which means they now describe something that no longer exists.

By the fourth quarter, the logs required by the standard have either not been collected or have been collected and never reviewed, which for evidentiary purposes amounts to the same thing. And the annual audit that the policy suite commits the business to has not been scheduled, because it too was somebody’s responsibility in principle.

Twelve months after a substantial and expensive piece of work, the business holds a document set describing a compliance position it no longer occupies, and does not know that this is the case.

Why willingness is not the issue

It is tempting to attribute this to a lack of seriousness, and that is almost never the explanation. The providers we see in this position took the obligation seriously enough to spend real money on it.

The problem is that maintaining a compliance position is a function rather than a project, and functions require somebody whose job they are. In a firm of twenty people where every role is fully occupied, the tasks that keep a compliance position current do not attach themselves to anyone. They are quarterly rather than daily, they are not urgent in any given week, and they produce no visible consequence when skipped. That combination guarantees deferral, regardless of intent.

This is also precisely why the standards are framed around continuous obligations rather than one time submissions. Joint Standard 2 asks for regular controls assurance, ongoing awareness programmes and incident response capability that is maintained. The regulatory expectation is a running function, and a policy suite is not one.

What interrupts the decay

Only one thing does, which is a defined cycle owned by somebody who is accountable for it. The specific mechanisms are unremarkable individually and effective collectively.

A committee meeting that is scheduled, prepared and facilitated by a party whose job that is, so it happens whether or not the business remembers. A quarterly log review that produces a written output, because an output creates a record and a record creates evidence. A quarterly spot check against the technical controls, so that the endpoint coverage figure and the authentication position are current rather than historical. A policy version cycle that updates the documents when the environment changes rather than when somebody notices. And an annual audit that is booked rather than intended.

None of this is intellectually difficult. All of it is easy to defer, which is the entire reason it needs to sit with somebody external who is contractually obliged to turn up.

The test

If you have a policy suite that was produced more than six months ago, there is a short exercise that will tell you where you actually are.

Find the date of the last Information Security Committee meeting. Find the date of the last access review. Find the date of the last restoration test. Find the last quarterly log review output.

If you can produce all four dates, your position is being maintained and you can stop reading. If you cannot produce any of them, the document set on your server describes a compliance position that no longer exists, and the gap has been widening every quarter since it was signed.

Siyaxhuma IT Governance exists to be the party that turns up. The engagement begins with a gap analysis that establishes your current position honestly. Get in touch.

Recent Posts

Most Compliance Work Stops When the Policy Is Signed

What Compliance Actually Costs, and What You Get for It

Introducing Siyaxhuma IT Governance

Your Policy Says MFA Is Enabled. Has Anyone Checked?

Three Things We Find in Almost Every Environment We Assess

The Faults That Live Between Systems

Siyaxhuma Image

GET IN TOUCH

Solutions