Is the InfoSec policy aligned with NIST CSF, ISO 27001, or other framework?
Alignment is a weaker claim than certification and it still means something, provided you can show which framework and what the gaps are.
What the carrier is actually asking
The carrier is asking whether your security programme follows a recognised framework, and which one. Alignment means you use its structure and control set. Certification means an external party verified it, which the independent assessment question covers separately.
Why it is underwritten
A framework gives coverage without depending on any individual remembering a control category. It also gives the underwriter a shorthand for the shape of your programme. Organisations without one tend to have deep strength in some areas and no coverage in others.
Where the answer lives in Microsoft 365, Entra ID, and Azure
Framework alignment is evidenced by a mapping and an assessment, which is attested.
| Platform | Where the setting lives | What has to be true |
|---|---|---|
| Documents | Control mapping from the framework to your implemented controls | A mapping that identifies gaps rather than asserting completeness. Attested |
| Assessment | A self or external assessment against the framework, with a date | A dated assessment showing current maturity per domain |
| Roadmap | Gaps with owners and target dates | A plan, which is the part that makes alignment credible rather than decorative |
| Policy | Whether the policy structure follows the framework | Consistency between the framework claimed and the document that implements it |
| Evidence | Control evidence collected per framework requirement | Evidence per control, which is what a certification effort would require anyway |
Aligned with gaps identified and a roadmap is a stronger answer than aligned without qualification, because the first is checkable and the second is a claim. Underwriters read the roadmap as evidence that the programme is managed.
What a defensible yes requires
- A specific framework is named rather than a general claim of best practice.
- A mapping exists between framework controls and your implementation.
- Gaps are identified with owners and dates.
- The policy structure follows the framework.
- Assessment against it happens on a cadence rather than once.
How this answer goes wrong
The policy cites a framework in its introduction and no mapping exists, so nobody can say which controls are implemented. If a claim leads to scrutiny, the citation becomes a statement about a standard the organisation cannot demonstrate it followed.
Frequently asked
Which framework should we choose?
Whichever fits your obligations and customers. The cybersecurity framework is approachable and outcome-focused; the international standard suits organisations seeking certification.
Is alignment enough without certification?
For this question yes. The independent assessment question is where certification carries its weight.
Can we align to more than one?
Common, and worth mapping rather than maintaining separately. Most frameworks overlap heavily.
What if we follow no framework?
Say so. It is honest and it flags a structural gap worth closing, since frameworks are how you find the categories you have not thought about.
Related questions
Stop answering this from memory
Connect Microsoft 365, Entra ID, and Azure read-only. Insurance Posture reads the live configuration behind each application answer and shows you which ones you can prove before you sign.
Assess your posture