Information security policies
Direction set at the top, and the review cycle that keeps it current.
- Approval
- Review cycle
- Communication
The management-system standard most groups use as their anchor. Its value in a multi-framework programme is that almost everything else maps to it, which makes it a sensible primary standard for a shared control library.
Published by ISO and IEC. Commonly the standard a control is marked primary against, with national and sector frameworks mapped onto it.
Control
Privileged access is reviewed each quarter by the system owner
PPTDF applicability
One owner · one procedure · one evidence trail
Annex A
Control set
0 to 5
Maturity scored
Primary
Standard per control
Graded
Mapping to other standards
Structure
A sample of the control areas. The full set lives in the library, where each control carries its own mappings.
Direction set at the top, and the review cycle that keeps it current.
Defined roles, separation of conflicting duties, and contact with authorities.
Inventory, ownership, classification, and acceptable use.
Who holds which rights, how that is reviewed, and how privilege is contained.
Security in supplier agreements and monitoring of delivery against them.
Reporting, assessment, response, and learning from what happened.
Platform mapping
A control appears once in the tree under its primary standard, which stops the same requirement being maintained in several places.
National and sector frameworks map to the same controls, each mapping carrying a level rather than a tick.
Where two standards express the same requirement differently, the equivalence is recorded and applied rather than rediscovered.
Requirements of your own become company-scoped controls with generated identifiers and a full authorship trail.
Which frameworks apply is a property of the company record, so a group can run different scopes across its entities.
Domain-level maturity shows where a programme stands. Sentinel Unity is not a certification body and does not claim to be one.
Maturity
Every Annex A control is scored on the platform's six-level scale, each level carrying a written descriptor so a score means the same thing in two different business units.
Level 0
Not Performed
The practice does not happen. Recorded as an explicit level rather than a blank.
Level 1
Performed Informally
It happens, but it depends on individuals and is neither planned nor tracked.
Level 2
Planned & Tracked
Planned, resourced, and monitored, though practice still varies between teams.
Level 3
Well Defined
A defined standard process, applied consistently across the organisation.
Level 4
Quantitatively Controlled
Measured against targets, with deviation detected from the measurements themselves.
Level 5
Continuously Improving
Improvement is fed by the measurements, changing the process rather than the reporting.
Book a walkthrough with our GRC specialists and see the platform run against the frameworks you are held to.
No commitment required. A typical demo runs 45 minutes.