No asset inventory
Almost nothing in the framework can be evidenced without one, and it is the single most common thing missing. Building it usually surfaces systems nobody owns.
The Pakistan Information Security Framework asks what you have in place and expects you to show it. We run the gap assessment, build the evidence model and stay with it until the record holds on the day somebody asks.
They fail on the bookkeeping. A control that genuinely operates every quarter, in a meeting nobody minutes, is a real control and an unevidenced one. Only one of those survives an assessment.
Almost nothing in the framework can be evidenced without one, and it is the single most common thing missing. Building it usually surfaces systems nobody owns.
Config exports in one drive, review decisions in email, corrective actions in a project tool. Each maintained well on its own. The relationships between them living in somebody's head.
The same control explained separately for PISF, for ISO 27001 and for a customer questionnaire, then drifting apart until the three descriptions disagree.
What is in scope, who owns each system, and what data each one holds. Where an inventory already exists we check it rather than rebuild it. Where it does not, this stage is the bulk of the early work and we say so up front rather than discovering it in month three.
Domain by domain, against the framework as published rather than against a summary. The output separates controls that are absent from controls that operate and have never been recorded operating, because those need very different work.
Evidence attached to the control it satisfies at the moment it is produced, with a named person who accepted it. Remediation sequenced so the controls protecting the most consequential systems close first.
A walkthrough against the questions an assessor actually asks, and a dry run of retrieving evidence under time pressure. The aim is that audit day is a retrieval exercise rather than an archaeology project.
PISF was built to sit alongside the international standards rather than compete with them, so your policies, risk methodology, asset register and management review map across with editing rather than rewriting.
What tends not to map is the evidence expectation. We produce the mapping explicitly, so you can see which obligations a control you already run answers, and which gaps are genuinely new. That mapping is the deliverable most organisations tell us they wanted and could not find anywhere.
Every engagement starts from the systems whose failure would be felt outside your own balance sheet.
A control is counted when it can be shown operating, with a named acceptance.
If you supply into a regulated organisation, the obligation reaches you through the contract. We cover that case too.
The questions that come up most often, answered the way we would answer them on a call.
Government and regulatory bodies, critical national infrastructure across sectors such as energy, telecommunications and transport, and financial services. Suppliers to those organisations are pulled in through contracts even where the framework does not name them directly.
A large share. PISF was built to sit alongside the international standards, so policies, risk methodology, asset register and management review map across with editing rather than rewriting. What tends not to map is the evidence expectation, and that is usually where the real work is.
It depends almost entirely on whether you have an asset inventory and a habit of keeping evidence. With both, months. With neither, expect the inventory alone to take a meaningful part of the first quarter, and plan around that rather than against it.
No. We prepare you and we are not an accredited body. Keeping those separate is the point, because the people who help you get ready should not be the people who judge whether you are.
Not with the control list, which produces a spreadsheet nobody finishes. Start with an asset inventory, then evidence ten controls properly, and use what that costs to plan the rest honestly.
The first conversation exists to scope the work and to establish whether we are the right people for it. If we are not, we would rather say so on the call than three weeks into a proposal.