PISF compliance

A national floor you can evidence.

The Pakistan Information Security Framework asks what you have in place and expects you to show it. We run the gap assessment, build the evidence model and stay with it until the record holds on the day somebody asks.

Gap assessmentEvidence modelISO 27001 mappingAudit readiness
Where organisations actually get stuck

Almost nobody fails on the technology.

They fail on the bookkeeping. A control that genuinely operates every quarter, in a meeting nobody minutes, is a real control and an unevidenced one. Only one of those survives an assessment.

No asset inventory

Almost nothing in the framework can be evidenced without one, and it is the single most common thing missing. Building it usually surfaces systems nobody owns.

Evidence scattered

Config exports in one drive, review decisions in email, corrective actions in a project tool. Each maintained well on its own. The relationships between them living in somebody's head.

Work counted once

The same control explained separately for PISF, for ISO 27001 and for a customer questionnaire, then drifting apart until the three descriptions disagree.

How the engagement runs

Four stages, scoped to what you already have.

01

Scope and inventory

What is in scope, who owns each system, and what data each one holds. Where an inventory already exists we check it rather than rebuild it. Where it does not, this stage is the bulk of the early work and we say so up front rather than discovering it in month three.

02

Gap assessment against the control set

Domain by domain, against the framework as published rather than against a summary. The output separates controls that are absent from controls that operate and have never been recorded operating, because those need very different work.

03

Evidence model and remediation

Evidence attached to the control it satisfies at the moment it is produced, with a named person who accepted it. Remediation sequenced so the controls protecting the most consequential systems close first.

04

Audit readiness

A walkthrough against the questions an assessor actually asks, and a dry run of retrieving evidence under time pressure. The aim is that audit day is a retrieval exercise rather than an archaeology project.

If you already hold ISO 27001

Most of the work already counts.

PISF was built to sit alongside the international standards rather than compete with them, so your policies, risk methodology, asset register and management review map across with editing rather than rewriting.

What tends not to map is the evidence expectation. We produce the mapping explicitly, so you can see which obligations a control you already run answers, and which gaps are genuinely new. That mapping is the deliverable most organisations tell us they wanted and could not find anywhere.

SCOPE FIRST

Every engagement starts from the systems whose failure would be felt outside your own balance sheet.

EVIDENCE, NOT ASSERTION

A control is counted when it can be shown operating, with a named acceptance.

SUPPLIERS IN SCOPE

If you supply into a regulated organisation, the obligation reaches you through the contract. We cover that case too.

Questions we get asked

Before you get in touch

The questions that come up most often, answered the way we would answer them on a call.

Who has to comply with PISF?

Government and regulatory bodies, critical national infrastructure across sectors such as energy, telecommunications and transport, and financial services. Suppliers to those organisations are pulled in through contracts even where the framework does not name them directly.

We already hold ISO 27001. How much of it counts?

A large share. PISF was built to sit alongside the international standards, so policies, risk methodology, asset register and management review map across with editing rather than rewriting. What tends not to map is the evidence expectation, and that is usually where the real work is.

How long does a PISF programme take?

It depends almost entirely on whether you have an asset inventory and a habit of keeping evidence. With both, months. With neither, expect the inventory alone to take a meaningful part of the first quarter, and plan around that rather than against it.

Do you certify us?

No. We prepare you and we are not an accredited body. Keeping those separate is the point, because the people who help you get ready should not be the people who judge whether you are.

Where should we start?

Not with the control list, which produces a spreadsheet nobody finishes. Start with an asset inventory, then evidence ten controls properly, and use what that costs to plan the rest honestly.

Start with the gap, not the platform

Tell us where you are and we will tell you honestly how far it is.

The first conversation exists to scope the work and to establish whether we are the right people for it. If we are not, we would rather say so on the call than three weeks into a proposal.