1. Purpose & Authority
This descriptor sets out how the CIAO Standard organises knowledge. It is the conceptual companion to two existing foundational instruments: the Source Standards Register (which records what the Standard recognises and references) and the Standard Architecture (which sets out how the Standard’s content is structured into documents and tiers). Where those describe the catalogue and the document architecture, this descriptor describes the structure of meaning — the way concepts and control objectives relate to one another and locate themselves within the Standard.
It carries Class B — Foundational authority. It defines a frame; it does not restate the architecture or the register, which it references.
2. How the Standard sees knowledge
The CIAO Standard treats Information Assurance as a body of knowledge that can be structured as a layered graph. At the widest level sits the subject itself; beneath it, the Standard’s domains; within each domain, a conceptual frame that fixes scope and terminology; and beneath the frame, the concepts and control objectives that the domain governs — drawn from many recognised sources and harmonised into a single coherent view, so that where many sources converge on one objective, the member sees one statement, not many.
This is the organising idea behind the whole Standard: a member should meet one coherent body of knowledge, not a pile of overlapping documents.
3. The layers of the knowledge structure
Layer 0 — Subject. The widest frame is a field of knowledge. The Standard addresses one named subject: Information Assurance. Other fields of knowledge exist; the Standard does not enumerate them — it situates Information Assurance as its subject and builds downward from there.
Layer 1 — Domains. Information Assurance resolves into the Standard’s content domains — nine coherent areas of the subject, held together by a meta-domain that governs the Standard itself. Each domain is a distinct region of the knowledge graph.
Layer 2 — Domain conceptual frame. Within each domain, a foundational frame defines scope, terminology, and core concepts — the lens through which every other artefact in that domain is interpreted. In the content architecture, this is the Manual level: the foundational reference document for the domain, which sets the conceptual frame against which all other artefacts within the domain are interpreted.
Layer 3 — Sub-policies. Within a domain’s frame sit its sub-policies — a bounded set of policy areas. This is the layer a member governs directly: a small, coherent set per domain rather than a sprawling library.
Layer 4 — Control objectives. Beneath each sub-policy sit the harmonised control objectives the domain governs — drawn from many recognised sources and shown here in anonymised, illustrative form. This is the layer at which a recognised source that names a required policy resolves to a single objective. Where multiple sources converge, the graph carries one node with many connections; where a single source adds a genuine exception, that remains a distinct, visible node. The implementation controls that satisfy each objective sit one level deeper again.
Deeper layers. Finer artefacts and the detailed relationships between objectives are developed progressively and surfaced through the Standard’s content tiers. This descriptor establishes the frame; depth follows the tier ladder.
4. One structure, four mirrors
The knowledge structure is not a separate invention — it mirrors the structures the Standard already uses. But the mirrors are coupled on two axes, not one: each layer is first glimpsed a tier early and becomes a member’s full set at its home tier, while within any single document the same structure unfolds in greater depth as membership rises. Breadth and depth advance together — a member always sees a little further than they have yet climbed.
| Knowledge layer | Becomes, in the content | Framework lens | Full set unlocked at | Organisational maturity |
|---|---|---|---|---|
| Subject — Information | The Standard as a whole | — | Commons (free, registered) | Awareness |
| Domains — nine, held by a meta-domain | A Manual per domain (the management-system frame) | IMS-OPF | Core | Foundational |
| Sub-policies — a bounded set per domain | The policy (the document a member governs) | OPF | Essential | Defined & repeatable |
| Sub-sub-policies — harmonised control objectives | In-page within each policy; indexed at Professional | OPF | Professional | Measurable & scalable |
| Granular objectives — beneath each control objective | In-page, deeper | OPF-ECF | Enterprise | Managed & assured |
| Implementation controls — technical, process, operational | The control framework, per-domain then whole-Standard | ECF-IDF | Conglomerate | Optimising & leading |
The three lenses climb in parallel: the OPF (Organisational Policy Framework) gathers the policy layers, the ECF (Control Framework) the technical and process controls, and the IDF (Information & Data Framework) the data-handling layer — each lens rolling up one tier above its components. The architecture already built needs no modification to parallel this graph: knowledge layer, content artefact, framework lens, tier and maturity move together, yet each arrives as a taste before it arrives in full, and deepens in place as a member climbs.
5. A simplified view (illustrative)
Click a domain, a sub-policy, then a control objective — the selected path lights up. Hover a box for its full title. Live from the ontology.
Read it top to bottom: one subject → nine domains → a handful of policies per domain → the control objectives beneath them → the technical controls that implement each. The point is the middle: instead of reading every standard separately, many standards meet on one objective.
Illustrative only. Domains and connections are shown to convey shape, not to enumerate the live structure, which members navigate through the Standard’s content surfaces.
6. Reference-only positioning
The Standard does not reproduce the text of the source standards it recognises. The concepts shown here are CIAO’s own harmonised expression, presented illustratively and without attribution to any single source’s wording. Members consult their own authorised copies of any source standard directly. The Standard provides the architectural layer above those sources, by which their requirements are organised and related — not a substitute for them.
7. Relationship to other instruments
- Source Standards Register — what the Standard recognises and references.
- Standard Architecture — how content is organised into documents, classes, and tiers.
- Glossary of Base Concepts — the definitions of the concepts this graph relates.
- Knowledge Base Graph (this page) — how those concepts fit together as a structure of meaning.
Each refers up to the others rather than restating them.
8. Scope of this edition
This inaugural edition describes the knowledge structure at the foundational level — the layers and their mirrors. Finer relationship detail is developed progressively and surfaced through the Standard’s higher content tiers.
