| Order | Tab | Content in the tab |
|---|---|---|
| 1 | Business Context | What does LondonBuild do? → Construction company → services → locations → customers → critical systems/data. |
| 2 | Legal & Regulatory Requirements | Identify laws/regulations that apply. Example: UK GDPR, Data Protection Act 2018, Health & Safety legislation. |
| 3 | Contractual Requirements | Identify requirements imposed by customers, suppliers, insurers or contracts. |
| 4 | Industry Requirements | Identify standards/frameworks relevant to the industry or activities. |
| 5 | Security / Compliance Objectives | What is LondonBuild trying to achieve? Example: information security, privacy, cyber resilience, customer assurance. |
| 6 | Framework Candidates | List potentially applicable frameworks. Example: ISO 27001, NIST CSF, SOC 2. |
| 7 | Applicability Assessment | For each framework ask: Does this framework actually apply to LondonBuild? Why? |
| 8 | Framework Selection | Select the frameworks/standards that will be used for the assessment. |
| 9 | Framework Version | Record the exact version being assessed against. |
| 10 | Scope | Define which parts of LondonBuild are covered by the framework. |
| 11 | Framework Requirements | Extract the applicable requirements/controls from the selected framework. |
| 12 | Framework Register | Record all selected frameworks in one central register. |
| 13 | Approval | Obtain management/compliance approval of the selected frameworks and scope. |
Example
For LondonBuild:
Business Context
↓
Construction company handling employee/customer information
↓
Legal Requirements
UK GDPR + Data Protection Act 2018
↓
Customer Requirements
Major customer requires ISO 27001
↓
Industry / Security Needs
Cybersecurity and information security
↓
Framework Candidates
ISO 27001 + NIST CSF
↓
Applicability Assessment
ISO 27001 → Applicable
NIST CSF → Useful/selected as supporting framework
↓
Selected Frameworks
ISO 27001 + NIST CSF
↓
Requirements/Controls
Extract the relevant controls
↓
Requirement Process
So your overall GRC process becomes:
1. Identify Framework That Applies
→ 2. Identify Requirement
→ 3. Interpret Requirement
→ 4. Identify Control
→ 5. Collect Evidence
→ 6. Test
→ 7. Gap
→ 8. Risk
→ 9. Remediation
→ 10. Reporting
Important: Framework identification comes before requirement identification because you need to know which framework you’re assessing against before you can determine which requirements apply.