4 MIN READ
Picture the compliance framework that the audit committee approved last quarter. SOC 2, ISO 27001, PCI DSS, NIST CSF, external audit signed off, the board read the executive summary, the regulator accepted the report as evidence of due diligence. The framework was the document the CISO office pointed to whenever the question came up about whether the security programme worked. Then the breach happened, and the postmortem read the way postmortems read when the framework was the only thing the security org had built: the breach happened through a control the framework did not test, SOC 2 audit did not look at the control because the framework said the control was out of scope, and the company discovered in the disclosure call that the framework had been the answer to a question nobody had asked. The honest framing is this: a compliance framework amounts to a baseline, and a baseline is the floor, not the ceiling, and treating it as the ceiling is how the security org gets surprised.
Lineage worth knowing. Target in 2013 had the framework, external audit signed off, the breach came through the HVAC vendor. Equifax in 2017 had the framework, external audit signed off, the breach came through an unpatched Apache Struts the patch management control missed. SolarWinds in 2020 had the framework, external audit signed off, the breach came through the build pipeline the framework did not test. Capital One in 2019 had the framework, external audit signed off, the breach came through a misconfigured IAM role the framework did not flag. The pattern repeats. The framework measures what the framework was written to measure, and the threats the framework does not measure are the threats that land.
What the framework is for
Each of those uses is genuinely useful when the framework is applied to what it does. The baseline matters because SOC 2, ISO 27001, PCI DSS, and NIST CSF define the minimum control set the regulated entity should have, and the external audit verifies the controls exist in the document trail. The control the audit finds missing gets remediated before the next audit cycle, and the remediation cycle produces a security posture that no greenfield programme would have built from scratch. The due diligence evidence sits as the second use, and the procurement team knows it well. The SOC 2 Type II report answers the security questionnaire an enterprise customer sends. The ISO 27001 certificate answers the same questionnaire in Europe. The PCI DSS attestation answers the same questionnaire for any company that touches card data. The evidence the framework generates automatically fills the spreadsheet, and the spreadsheet lands the contract. Operational discipline counts as the third use, and the security org feels it in the operational cadence. The framework imposes the patching cycle, drives the access review cadence, and makes the vulnerability scan non-negotiable. The security org that resents the framework in March usually appreciates the framework in December, because the discipline the framework imposed is the discipline the operations team would have skipped without the audit deadline.
What it does not do
Three gaps, and the gap matters more than the framework itself in the postmortem. Detection sits as the first gap, and the gap is structural. SOC 2 does not say the breach will be caught. SOC 2 says the control is in place. The control can be a written policy, a quarterly review, a documented procedure, and the framework considers the control satisfied even if the control has never been tested against the actual threat actor. The SOC 2 auditor signs off on the policy, the breach lands through a gap the policy did not cover, and the postmortem says the same thing every postmortem says. The zero day amounts to the second gap, and the gap is mathematical. The framework was written in 2017, revised in 2020, the threat landscape moves every quarter, and the controls the framework lists are the controls the industry knew about when the framework was last revised. A zero day that lands in 2026 was unknown when the framework was written, and the framework will not know about it until the next revision cycle, which lands 18 to 36 months later. Threat intelligence rounds out the gap, and the gap is the one the SOC team feels most directly. SOC 2 does not say which threat actor to worry about. ISO 27001 does not say which attack pattern to defend against. PCI DSS does not include the threat intelligence the SOC team needs to triage the alert at 2am. The framework is the floor, and the threat intelligence the security org buys separately stands as the actual defence the framework does not provide.
How to use it for what it is good for
Three moves, and the moves together close the gap the framework leaves open. Use the framework for the baseline, which is what it is for. The CISO office runs the audit cycle, the audit committee signs off, the board reads the executive summary, and the regulated entity points to the framework when the regulator asks. The framework serves the procurement questionnaire, the insurance carrier, and the audit committee, and the CISO office should let it serve those three without pretending it serves anything else.
Layer the threat informed defence on top. MITRE ATT&CK coverage, red team validation, threat intelligence driven detection, all of it running as a separate layer that the framework does not test and the external auditor does not sign off on. The threat informed defence serves as the layer that catches the breach the framework did not, and the security org that ships the layer stands as the org that stops pretending the framework is the whole programme.
Be honest with the board. The board that hears the CISO say the framework means the security org is secure sits as the board that gets surprised by the breach. The CISO should be telling the board that the framework runs as the floor, not the ceiling. The honest framing produces a board that asks the right questions, the right questions produce the threat informed defence, and the threat informed defence sits as the layer the framework was never going to provide.

The bottom line
Use the framework for the baseline, layer the threat informed defence, be honest with the board. The framework runs as the floor, not the ceiling, and the CISO office that stops pretending otherwise sits as the one that ships the layer the framework was never going to provide.
Sources & Further Reading
All claims in this article are sourced from primary documentation, vendor advisories, and reputable security researchers.
Spotted an error? Email the editor. Corrections are issued with a visible correction note.
Editorial standards. Every article on humanrequired.org is reviewed by a human editor before publication. AI may assist with drafting or research; final editorial control is human. Read the full standards.



