Academyby Dasow

Stop 3 of 9 · Weekly

Security stack against the frame

The control list on one side, the client stack on the other, and a gap list with an owner, a cost band and a date that an assessor could read.

Watch first · 0:58

The mapping nobody has time for

Two of Hazem clients are bound by a frame. Okonjo and Fahy take public defender work and touch criminal justice information, so CJIS applies. Northgate Family Health is HIPAA bound. Both clients ask the same question once a year, usually two weeks before an assessment: are we compliant, and what is it going to cost to be.

Answering it by hand means reading a control list, then reading a tenant, then holding both in your head. Claude reads both and holds them side by side. What it cannot do is know your tenant, so this stop is entirely about what you feed it and what you check afterwards.

What goes in, and in what form

Side What you attach
The frame The published policy document, current version, as a file
The stack Conditional access export, Intune configuration profiles, Meraki firewall rules, backup schedule, joiner and leaver process, training records
The history Last assessment findings and what was closed

Config exports are safe to attach once you have removed public addresses, tenant identifiers and anything that names a person. Nothing from the vulnerability scanner goes in here. That output is a target list, and it belongs in the workflow in stop 4 where it is handled under its own rules.

Map the stack to the frame
[attach the policy document and the config exports with public addresses and tenant identifiers removed]
For Okonjo and Fahy, work through the attached policy document control by control. For each control give me four columns: the control identifier and its exact wording from the document, what our current configuration does about it, the evidence in the attached exports that proves it, and a status of met, partial or gap.

Rules: quote the control wording from the attached document only, never from memory. If nothing in the exports proves a control, the status is gap, not met. Where you are inferring, say so in the evidence column.

The last rule is the one that matters. A model asked whether a client is compliant will drift towards yes. Forcing every green status to point at a line in an attached file removes the drift, and the controls with no evidence are exactly the list Hazem needed.

Turn the gaps into a work list
From the mapping above, produce the gap list. One row per gap with: control identifier, what is missing in one sentence a partner would understand, owner as either us or the client, effort in engineer days, a cost band of under one thousand, one to five thousand, or over five thousand, and a target date given the assessment is in March.

Sort by risk, and put anything the client must do themselves in a separate section at the end so I can hand them their half.
Rehearse the assessor questions
You are the assessor arriving at Okonjo and Fahy in March. From the mapping above, ask me the ten questions you would ask first, hardest ones first, and for each one say what evidence you would expect me to produce on the spot. Do not accept a policy document as evidence that a control is operating.

The artefact

The control-by-control mapping with an evidence column, and the gap list split into your work and the client work, each line carrying an owner, a cost band and a date. That pair is what goes to the client and, if asked, to the assessor.

Quick check

Try it

Report a bug or share feedback