Start with your organisation's activities, information, systems, customers and jurisdictions. Determine which obligations and reference methods should guide the programme before importing a framework.

Separate the reasons for selection

ReasonWhat to establish
Legal or regulatory obligationThe applicable text, entity scope, national measures where relevant and responsible reviewer.
Contractual requirementThe contract, required edition, scope and evidence expected by the counterparty.
Management-system objectiveThe system boundary, intended assurance outcome and accountable leadership.
Risk-management guidanceThe risks and decisions the reference is intended to support.
Specialist control needsThe technologies or activities that require more detailed controls.

These reasons can overlap. A reference's country of origin does not by itself determine where it applies, and a catalogue entry does not establish a legal obligation.

Define a manageable scope

Record the business activities, systems, third parties and information covered by the assessment. Identify the source edition and the reason for any exclusions. Assign people who can validate both the interpretation and the implementation evidence.

Several frameworks may address the same subject using different wording and assessment criteria. Use policy-control links to explain relevant coverage, but verify each requirement before treating the same evidence as sufficient for several references.

Check the available reference

Open Frameworks → Add framework → Reference library. Inspect the exact name, language and edition. Compare it with the publisher's current material and the edition your organisation must use.

If the required reference is absent or older than your intended baseline, resolve that difference before beginning a large assessment. Create a clearly identified custom framework where appropriate, or contact CSFaaS about the missing reference. Keep the publisher's requirements separate from your workspace adaptations.