Institution

CIAO COMMONS — ARCHITECTURAL INSTRUMENT
C-AO/INS/001:2026 PUBLIC
Institution
The Architectural Instrument of the CIAO Standard — how the Standard is organised and accessed
Date Issued  22 June 2026
Review Date  22 June 2029
Cite as: CIAO Standard. (2026). Institution. v1.1.3.7. C-AO/INS/001:2026. www.c-ao.com

1. Purpose

This document describes how the CIAO Standard organises its body of knowledge, and how access to that knowledge deepens with membership. It is an architectural instrument: it defines the shape of the Standard rather than any single requirement within it.

Two ideas run throughout. First, the Standard is a single, layered structure rather than a collection of separate documents. Second, access to that structure deepens progressively — every member stands on the same foundation and sees further into it as their engagement grows.

2. How the Standard organises knowledge

The Standard resolves a single subject — Information Assurance — into a coherent, navigable structure. Each level refines the one above it.

Level What it holds
Domain A coherent area of the subject (nine in total).
Sub-policy A policy area within a domain — the level at which an organisation maintains a policy.
Sub-sub-policy An organisational-control area within a sub-policy — the objectives of the sub-policy.
Control objective A single, framework-neutral requirement — the objectives of the sub-sub-policy, each one normative statement.
Technical control The implementation that gives effect to an objective.
Data control The handling of data within an implementation, gathering into the Information & Data Framework.

Recognised standards converge onto the control objectives: where many frameworks require the same thing, the Standard expresses it once, and records which sources it harmonises. A member therefore meets one coherent body of knowledge, not a pile of overlapping documents.

3. The Management System

The Standard is presented as an Integrated Management System — a single management system spanning all nine domains, with a management system for each domain rolling up into it. Rather than reproduce external clause structures, the Standard groups its content under three plain control layers:

Control layer Purpose
Strategy Layer Controls Context and leadership — why the area exists and who is accountable.
Tactical Layer Controls Planning, support and improvement — how the area is resourced and matured.
Operational Layer Controls Operation and evaluation — how the area runs and is measured.

Each Domain Manual is built on these three layers, with the domain’s sub-policies grouped beneath the layer they serve. The nine Domain Manuals roll up into the Standard Manual — the integrated management system of the Standard as a whole.

4. Progressive access

Access to the Standard deepens by membership level. Each level grants everything below it and opens the next layer of depth, so the structure unfolds further the deeper a member engages.

Level What it opens
Open web The Standard’s general pages and the Standard itself.
Commons The Standard Manual — the integrated management system.
Core The nine Domain Manuals and a first set of sub-policies for each domain.
Essential The full set of sub-policies, and the sub-sub-policies beneath them.
Professional The policy framework for each domain, the full sub-sub-policy detail, and the first technical controls.
Enterprise The Standard’s overall policy framework, the full technical-control detail, the control framework for each domain, and a first view of the data framework.
Conglomerate The Standard’s overall control framework, the complete Information & Data Framework, and the full supporting documentation.

The same principle governs the Manuals themselves: a Manual opens one layer deeper at each level — from domains, to sub-policies, to sub-sub-policies, to technical and data controls and their supporting records — so a single Manual serves every member at the depth their level affords.

5. The three frameworks

The Standard is expressed through three complementary frameworks that rise in parallel:

The three nest naturally: organisational controls give rise to technical controls, and technical controls give rise to data controls — while data controls, in turn, gather back into the organisational-control groupings they serve. The policy view is reached first; the implementation and data views complete the picture at the deepest levels.

6. Terms

● LIVE CONTENT  ·  Verified 22 July 2026 at 23:07 UTC  ·  Version 1.1.3.7  ·  Always current at c-ao.com  ·  © CIAO Standard Secretariat 2026
Notices1 JulThe Monthly Standard release is scheduled for 2026-07-16.1 JulThe Annual Major release is scheduled for 2027-02-01.1 JulThe Monthly Standard release is scheduled for 2026-07-16.1 JulThe Annual Major release is scheduled for 2027-02-01.

Cite this page (APA)