Identify Framework that applies

OrderTabContent in the tab
1Business ContextWhat does LondonBuild do? → Construction company → services → locations → customers → critical systems/data.
2Legal & Regulatory RequirementsIdentify laws/regulations that apply. Example: UK GDPR, Data Protection Act 2018, Health & Safety legislation.
3Contractual RequirementsIdentify requirements imposed by customers, suppliers, insurers or contracts.
4Industry RequirementsIdentify standards/frameworks relevant to the industry or activities.
5Security / Compliance ObjectivesWhat is LondonBuild trying to achieve? Example: information security, privacy, cyber resilience, customer assurance.
6Framework CandidatesList potentially applicable frameworks. Example: ISO 27001, NIST CSF, SOC 2.
7Applicability AssessmentFor each framework ask: Does this framework actually apply to LondonBuild? Why?
8Framework SelectionSelect the frameworks/standards that will be used for the assessment.
9Framework VersionRecord the exact version being assessed against.
10ScopeDefine which parts of LondonBuild are covered by the framework.
11Framework RequirementsExtract the applicable requirements/controls from the selected framework.
12Framework RegisterRecord all selected frameworks in one central register.
13ApprovalObtain management/compliance approval of the selected frameworks and scope.

Example

For LondonBuild:

Business Context

Construction company handling employee/customer information

Legal Requirements
UK GDPR + Data Protection Act 2018

Customer Requirements
Major customer requires ISO 27001

Industry / Security Needs
Cybersecurity and information security

Framework Candidates
ISO 27001 + NIST CSF

Applicability Assessment
ISO 27001 → Applicable
NIST CSF → Useful/selected as supporting framework

Selected Frameworks
ISO 27001 + NIST CSF

Requirements/Controls
Extract the relevant controls

Requirement Process

So your overall GRC process becomes:

1. Identify Framework That Applies
2. Identify Requirement
3. Interpret Requirement
4. Identify Control
5. Collect Evidence
6. Test
7. Gap
8. Risk
9. Remediation
10. Reporting

Important: Framework identification comes before requirement identification because you need to know which framework you’re assessing against before you can determine which requirements apply.