1. Purpose
This document describes how the CIAO Standard organises its body of knowledge, and how access to that knowledge deepens with membership. It is an architectural instrument: it defines the shape of the Standard rather than any single requirement within it.
Two ideas run throughout. First, the Standard is a single, layered structure rather than a collection of separate documents. Second, access to that structure deepens progressively — every member stands on the same foundation and sees further into it as their engagement grows.
2. How the Standard organises knowledge
The Standard resolves a single subject — Information Assurance — into a coherent, navigable structure. Each level refines the one above it.
| Level | What it holds |
|---|---|
| Domain | A coherent area of the subject (nine in total). |
| Sub-policy | A policy area within a domain — the level at which an organisation maintains a policy. |
| Sub-sub-policy | An organisational-control area within a sub-policy — the objectives of the sub-policy. |
| Control objective | A single, framework-neutral requirement — the objectives of the sub-sub-policy, each one normative statement. |
| Technical control | The implementation that gives effect to an objective. |
| Data control | The handling of data within an implementation, gathering into the Information & Data Framework. |
Recognised standards converge onto the control objectives: where many frameworks require the same thing, the Standard expresses it once, and records which sources it harmonises. A member therefore meets one coherent body of knowledge, not a pile of overlapping documents.
3. The Management System
The Standard is presented as an Integrated Management System — a single management system spanning all nine domains, with a management system for each domain rolling up into it. Rather than reproduce external clause structures, the Standard groups its content under three plain control layers:
| Control layer | Purpose |
|---|---|
| Strategy Layer Controls | Context and leadership — why the area exists and who is accountable. |
| Tactical Layer Controls | Planning, support and improvement — how the area is resourced and matured. |
| Operational Layer Controls | Operation and evaluation — how the area runs and is measured. |
Each Domain Manual is built on these three layers, with the domain’s sub-policies grouped beneath the layer they serve. The nine Domain Manuals roll up into the Standard Manual — the integrated management system of the Standard as a whole.
4. Progressive access
Access to the Standard deepens by membership level. Each level grants everything below it and opens the next layer of depth, so the structure unfolds further the deeper a member engages.
| Level | What it opens |
|---|---|
| Open web | The Standard’s general pages and the Standard itself. |
| Commons | The Standard Manual — the integrated management system. |
| Core | The nine Domain Manuals and a first set of sub-policies for each domain. |
| Essential | The full set of sub-policies, and the sub-sub-policies beneath them. |
| Professional | The policy framework for each domain, the full sub-sub-policy detail, and the first technical controls. |
| Enterprise | The Standard’s overall policy framework, the full technical-control detail, the control framework for each domain, and a first view of the data framework. |
| Conglomerate | The Standard’s overall control framework, the complete Information & Data Framework, and the full supporting documentation. |
The same principle governs the Manuals themselves: a Manual opens one layer deeper at each level — from domains, to sub-policies, to sub-sub-policies, to technical and data controls and their supporting records — so a single Manual serves every member at the depth their level affords.
5. The three frameworks
The Standard is expressed through three complementary frameworks that rise in parallel:
- Organisational Policy Framework (OPF) — the policy view, formed of the organisational-controls layer.
- Enterprise Controls Framework (ECF) — the implementation view, formed of the technical-controls layer.
- Information & Data Framework (IDF) — the data view, formed of the data-controls layer: how data is handled efficiently in producing information and knowledge, to increase organisational value.
The three nest naturally: organisational controls give rise to technical controls, and technical controls give rise to data controls — while data controls, in turn, gather back into the organisational-control groupings they serve. The policy view is reached first; the implementation and data views complete the picture at the deepest levels.
6. Terms
- Sub-policy — a policy area within a domain.
- Sub-sub-policy — an organisational-control area; the objectives of a sub-policy.
- Control objective — a single framework-neutral requirement; the objectives of a sub-sub-policy.
- OPF / ECF / IDF — the policy, implementation, and data views of the Standard.
- Integrated Management System — the Standard’s management system, spanning all domains.
