Each control has an objective, an owner, and an assessment state
(Implemented / Partially / Not implemented / Not applicable). Assess with evidence, not opinion.
| Framework family | What it drives |
|---|---|
| NCA ECC v2 | Saudi national baseline (binding) |
| ISO 27001:2022 | ISMS certification |
| NIST CSF 2.0 | Outcome-based programs |
| SOC 2 | Trust-services attestation |
| PCI-DSS v4 | Card data |
| PDPL / NDMO | Privacy & data governance |
Attach machine-generated evidence where possible (scan output, logs, screenshots with metadata).
Every artifact is hashed (SHA-256) and stored in the evidence repository with the control reference.
When coverage is incomplete, open a gap with an owner and a remediation plan (action, cost,
deadline). Track to closure; re-assess after remediation.
Compliance is a byproduct of good controls, not a paperwork exercise. Evidence first.