Stop 3 of 9 · Weekly
Security stack against the frame
The control list on one side, the client stack on the other, and a gap list with an owner, a cost band and a date that an assessor could read.
The mapping nobody has time for
Two of Hazem clients are bound by a frame. Okonjo and Fahy take public defender work and touch criminal justice information, so CJIS applies. Northgate Family Health is HIPAA bound. Both clients ask the same question once a year, usually two weeks before an assessment: are we compliant, and what is it going to cost to be.
Answering it by hand means reading a control list, then reading a tenant, then holding both in your head. Claude reads both and holds them side by side. What it cannot do is know your tenant, so this stop is entirely about what you feed it and what you check afterwards.
What goes in, and in what form
| Side | What you attach |
|---|---|
| The frame | The published policy document, current version, as a file |
| The stack | Conditional access export, Intune configuration profiles, Meraki firewall rules, backup schedule, joiner and leaver process, training records |
| The history | Last assessment findings and what was closed |
Config exports are safe to attach once you have removed public addresses, tenant identifiers and anything that names a person. Nothing from the vulnerability scanner goes in here. That output is a target list, and it belongs in the workflow in stop 4 where it is handled under its own rules.
[attach the policy document and the config exports with public addresses and tenant identifiers removed] For Okonjo and Fahy, work through the attached policy document control by control. For each control give me four columns: the control identifier and its exact wording from the document, what our current configuration does about it, the evidence in the attached exports that proves it, and a status of met, partial or gap. Rules: quote the control wording from the attached document only, never from memory. If nothing in the exports proves a control, the status is gap, not met. Where you are inferring, say so in the evidence column.
The last rule is the one that matters. A model asked whether a client is compliant will drift towards yes. Forcing every green status to point at a line in an attached file removes the drift, and the controls with no evidence are exactly the list Hazem needed.
From the mapping above, produce the gap list. One row per gap with: control identifier, what is missing in one sentence a partner would understand, owner as either us or the client, effort in engineer days, a cost band of under one thousand, one to five thousand, or over five thousand, and a target date given the assessment is in March. Sort by risk, and put anything the client must do themselves in a separate section at the end so I can hand them their half.
You are the assessor arriving at Okonjo and Fahy in March. From the mapping above, ask me the ten questions you would ask first, hardest ones first, and for each one say what evidence you would expect me to produce on the spot. Do not accept a policy document as evidence that a control is operating.
The artefact
The control-by-control mapping with an evidence column, and the gap list split into your work and the client work, each line carrying an owner, a cost band and a date. That pair is what goes to the client and, if asked, to the assessor.