Sector view

Government and public sector

National assurance expectations, information classification, and suppliers pulled into scope by contract.

The reality

Public sector entities across the region operate under national assurance regimes, and those regimes reach their suppliers through procurement rather than through regulation. A private company frequently meets one of these standards for the first time as a condition in a tender, with a deadline set by the bid rather than by the business.

How the work is organised

Where an information classification scheme drives the regime, classify first and let control depth follow from it. Where an existing ISO 27001 management system is in place, use it as the foundation and address the national obligations as a distinct layer rather than a separate programme.

The trap we see most often

Answering a tender requirement with a policy document. National assurance regimes ask for evidence of operation and governance oversight, and a policy with no operating record satisfies neither.