Governance and workforce

Is the InfoSec policy aligned with NIST CSF, ISO 27001, or other framework?

Alignment is a weaker claim than certification and it still means something, provided you can show which framework and what the gaps are.

Attested, not tenant-verifiable

What the carrier is actually asking

The carrier is asking whether your security programme follows a recognised framework, and which one. Alignment means you use its structure and control set. Certification means an external party verified it, which the independent assessment question covers separately.

Why it is underwritten

A framework gives coverage without depending on any individual remembering a control category. It also gives the underwriter a shorthand for the shape of your programme. Organisations without one tend to have deep strength in some areas and no coverage in others.

Where the answer lives in Microsoft 365, Entra ID, and Azure

Framework alignment is evidenced by a mapping and an assessment, which is attested.

PlatformWhere the setting livesWhat has to be true
DocumentsControl mapping from the framework to your implemented controlsA mapping that identifies gaps rather than asserting completeness. Attested
AssessmentA self or external assessment against the framework, with a dateA dated assessment showing current maturity per domain
RoadmapGaps with owners and target datesA plan, which is the part that makes alignment credible rather than decorative
PolicyWhether the policy structure follows the frameworkConsistency between the framework claimed and the document that implements it
EvidenceControl evidence collected per framework requirementEvidence per control, which is what a certification effort would require anyway
Name the gaps

Aligned with gaps identified and a roadmap is a stronger answer than aligned without qualification, because the first is checkable and the second is a claim. Underwriters read the roadmap as evidence that the programme is managed.

What a defensible yes requires

  • A specific framework is named rather than a general claim of best practice.
  • A mapping exists between framework controls and your implementation.
  • Gaps are identified with owners and dates.
  • The policy structure follows the framework.
  • Assessment against it happens on a cadence rather than once.

How this answer goes wrong

The policy cites a framework in its introduction and no mapping exists, so nobody can say which controls are implemented. If a claim leads to scrutiny, the citation becomes a statement about a standard the organisation cannot demonstrate it followed.

Frequently asked

Which framework should we choose?

Whichever fits your obligations and customers. The cybersecurity framework is approachable and outcome-focused; the international standard suits organisations seeking certification.

Is alignment enough without certification?

For this question yes. The independent assessment question is where certification carries its weight.

Can we align to more than one?

Common, and worth mapping rather than maintaining separately. Most frameworks overlap heavily.

What if we follow no framework?

Say so. It is honest and it flags a structural gap worth closing, since frameworks are how you find the categories you have not thought about.

Related questions

Stop answering this from memory

Connect Microsoft 365, Entra ID, and Azure read-only. Insurance Posture reads the live configuration behind each application answer and shows you which ones you can prove before you sign.

Assess your posture