What each audience is actually asking for
| Who asks | What they are really asking | What certification gives you |
|---|---|---|
| Your board or committee of management | Can we say we have discharged our duty of care over resident information? | A dated certificate against a named standard, with a defined scope and expiry |
| Commission Quality Auditors | How does your information management system manage cyber security risks? | An assessed control set mapped to Outcome 2.4 and Outcome 2.7 |
| Cyber and professional indemnity insurers | Is this risk priceable, and are the declarations on the proposal true? | Independent verification rather than self-declaration |
| Government and tender panels | Does this provider meet a minimum security bar? | A recognised credential that answers the question without a bespoke response |
| Families and prospective residents | Is my information safe with you? | Something specific to point to, rather than a general assurance |
These audiences are the reason certification is worth more than an equivalent amount of unverified security work. The controls reduce your risk. The certificate is what lets somebody else accept that you have.