At a glance
- Part of
- Knowing which obligations apply, and being able to evidence them when somebody asks.
- Engaged as
- A defined piece of work, or as part of an ongoing vCISO engagement.
- Sits under
- Executive ownership of the cybersecurity program.
The service
What this engagement is
Who it is for
- Organizations facing a named framework in a customer contract or a regulatory obligation.
- Companies subject to several frameworks that are currently satisfying each separately.
- Businesses with an assessment date set and no clear owner for preparation.
- Leadership teams whose previous assessment produced findings that were never closed.
Work that starts by establishing which obligations genuinely apply and to which parts of the business, then builds the control and evidence base once so it can serve several frameworks at the same time.
Where obligations overlap, and they overlap far more than the separate assessment processes suggest, controls and evidence are mapped rather than duplicated. The saving is not cosmetic: it is usually the difference between a program that is maintained and one that is rebuilt annually.
- NIST CSF
- A widely used structure for organizing a security program around outcomes rather than products. Its current version adds an explicit governance function, which is why it maps well onto executive-level work.
- ISO 27001
- An international standard for an information security management system: the governance, risk treatment and continual improvement processes around security, rather than a fixed control list.
- SOC 2
- An examination performed by a licensed CPA firm against the AICPA trust services criteria. Security is always in scope; availability, confidentiality, processing integrity and privacy are added when relevant.
- CMMC
- NIST SP 800-171 sets the security requirements for protecting controlled unclassified information in non-federal systems. CMMC is the program under which contractors demonstrate that implementation, by self-assessment or third-party assessment depending on level.
- HIPAA
- The HIPAA Security Rule requires administrative, physical and technical safeguards for electronic protected health information, including a documented risk analysis and risk management process. The Breach Notification Rule sets defined duties and timelines once a breach is discovered. HITECH extended enforcement and applies obligations directly to business associates.
- PCI DSS
- Prescriptive control requirements imposed through payment brand agreements wherever cardholder data is stored, processed or transmitted. Scope reduction is usually the highest-leverage decision available.
- SOX
- Access, change management and IT operations controls supporting the reliability of financial reporting. Assessed annually as part of internal control over financial reporting.
- HITRUST
- A prescriptive framework that maps to several underlying regulations and standards, with a graded certification. Requested by some healthcare payers and partners as a single piece of evidence.
Why this comes up
Compliance work goes wrong in two directions. Some organizations treat a framework as a checklist and end up with documentation that does not describe how anything actually operates. Others treat every framework as equally applicable and spend against obligations that were never theirs.
Both produce the same experience at assessment time: a scramble to assemble evidence that should have been accumulating all year.
Scope
What Heights does
-
Obligation mapping
Which regulations, frameworks and contractual security commitments actually apply, and to which parts of the business.
-
Control mapping across frameworks
Where obligations overlap, controls and evidence are built once and mapped to each framework rather than maintained in parallel.
-
Evidence and artifact readiness
The documentation, records and operational evidence an assessor will request, prepared before the assessment window rather than during it.
-
Gap remediation planning
A plan for the gaps that remain, with sequencing and effort stated honestly.
-
Audit and assessment support
Preparation for the assessment itself, including how findings, evidence requests and follow-ups are handled.
-
Between-cycle maintenance
Keeping control operation and evidence current after the assessment, so the next one does not start from zero.
Timing
When organizations engage this
- A contract requires SOC 2, CMMC, ISO 27001 or a specific framework alignment.
- A regulator, auditor or major customer has set an assessment date.
- The organization is subject to several frameworks and is duplicating the same work for each.
- A previous assessment produced findings that remain open.
- A cyber insurance application or renewal has asked questions the organization cannot currently answer.
What you receive
- Applicability analysis for the frameworks in scope
- Control-to-framework mapping showing where obligations overlap
- Evidence register and collection plan
- Remediation plan with owners and target dates
How this fits under vCISO leadership
Readiness projects have an end date; regulatory obligations do not. A vCISO keeps control operation and evidence current between assessment cycles, and handles the questions that arrive in between.
Where this comes up most
- Healthcare Statutory obligations for protected health information, clinical availability requirements that constrain how controls can be applied, and growing security scrutiny from payers and partners.
- Financial Services Several supervisory regimes at once, and several of them expecting a named individual to be accountable for the information security program.
- Government and Defense Contractors Contractual security requirements that determine eligibility to bid, and assessment regimes that verify them before an award rather than after an incident.
- Technology and SaaS Companies assessed by their own customers, where security maturity shows up in the sales cycle long before it shows up in an audit.
Getting started
How an engagement begins
The same three steps whichever service you start with.
-
A confidential conversation
What prompted the enquiry, what you are obliged to do, and what leadership is being asked to answer for. No cost, no obligation.
-
Scope agreed in writing
What Heights will do, what stays with you, the working rhythm, and how progress will be reported.
-
Work begins
Delivered by your team, your providers or Heights, with expectations and acceptance criteria stated up front.
Questions we are asked about this
Broader questions about executive security leadership are answered on the vCISO page.
Does Heights perform the audit or examination itself?
No, and that separation matters. A SOC 2 examination is performed by a licensed CPA firm; ISO 27001 certification is issued by an accredited certification body; a CMMC assessment at higher levels is performed by an authorized third party.
Heights prepares your organization for those engagements and supports you through them. An adviser who also assessed their own work would not produce a credible result.
Does being compliant mean we are secure?
No. A framework represents an agreed floor, assessed at a point in time and against a defined scope. Organizations pass assessments and still suffer incidents, usually in areas the scope did not reach.
Compliance is worth pursuing on its own terms, it opens contracts and satisfies obligations, but it is a component of a security program rather than a substitute for one.
We are subject to several frameworks. Do we need separate programs?
Almost never. The requirements overlap substantially, access control, change management, logging, incident response and vendor management appear in some form in nearly all of them.
Mapping controls once and satisfying multiple frameworks from the same evidence base is normally where the largest efficiency in a compliance program comes from.
How early should we start before an assessment date?
Earlier than most organizations expect, because the constraint is rarely the documentation. Several frameworks expect controls to have been operating over a period, which means evidence has to accumulate before it can be presented.
Where a date is already fixed and the runway is short, we will say so plainly and help you decide between preparing properly and moving the date.
Related reading
-
Governance
Answering Customer Security Questionnaires Without Slowing Down Sales
Security questionnaires arrive with enterprise deals and the answers become contractual representations. Treating them as a sales task produces inconsistency; treating them as a governance task produces answers you can stand behind and reuse.
Related services
- Security Program Assessment A documented picture of what your security program actually covers, measured against a recognized framework, with the gaps ranked by business consequence.
- Cyber Risk Management One register of the risks that could genuinely disrupt the business, rated consistently, owned by name, and reviewed on a schedule leadership can rely on.
- Security Policy, Standards and Awareness Policies written to match how your organization actually operates, with the standards that make them workable and the training that makes them understood.
Talk through Regulatory and Framework Readiness with us.
Tell us what prompted the enquiry and what the organization is working toward. You will get a straight view of the right scope, including when that is smaller than you expected.
Or reach us directly at (407) 908-7001 or info@heightscg.com.