Services Framework Engagement Model Who We Serve FAQ Get Your Score CCISO Training Contact

Home / Framework

Our methodology

The CSISC Command Model™

Six Directives for security leadership. Not a repaint of a technical checklist — a governance cycle built around the one thing every standards framework treats as an afterthought: who's accountable.

Illustration of the six directives arranged as a hexagon, with Decide and Demonstrate as governance bookends

The insight behind it

NIST agrees with us — it just took until 2024 to say so

The Cybersecurity Framework ran for a decade on five functions — Identify, Protect, Detect, Respond, Recover — all technical, all silent on who's accountable. In 2024, NIST CSF 2.0 finally added a sixth function, Govern, at the centre of the wheel.

  • That's an admission a framework without leadership built in was incomplete the whole time.
  • CSISC didn't wait for the standard to catch up — being the "Govern" function is the entire reason an Executive Cyber Leader exists.
  • The Command Model doesn't replace NIST, ISO 27001 or Cyber Essentials — it's the operating rhythm that sits around them.
Compatible with
NIST CSF 2.0 NCSC CAF ISO/IEC 27001 NCSC Cyber Essentials GDPR / UK DPA DORA SOC 2

How it maps

Fully compatible with the standards you already report against

The Command Model isn't a replacement for NIST, ISO 27001 or Cyber Essentials — it's the leadership layer wrapped around them. Every directive traces back to a recognised control area.

DirectiveWhat it meansStandard equivalent
DecideThe board sets risk appetite and prioritiesNIST CSF 2.0 — Govern
DiscoverMap the real risk: assets, data, third parties, obligationsNIST CSF — Identify
DirectTurn the decision into a costed, sequenced roadmapNIST CSF — Protect
DefendLive monitoring, detection, and incident responseNIST CSF — Detect + Respond
DebriefFormal review after every incident, real or simulatedNIST CSF — Recover
DemonstrateEvidence: board packs, audit readiness, certification proofNIST CSF 2.0 — Govern

Public sector, critical-service and healthcare organisations: the same six directives map cleanly onto the NCSC Cyber Assessment Framework's four objectives too — Decide and Demonstrate sit under CAF Objective A (managing security risk), Direct under Objective B (protecting against attack), and Defend and Debrief span Objectives C and D (detecting events and minimising impact).

Why it's different

This isn't NIST with new labels

Directives, not pillars

Pillars are static — built once, leaned on. Directives are active and ongoing, issued by leadership — language that matches what an Executive Cyber Leader actually does.

A genuinely different shape

Two governance directives bracket four operational ones. That structure is the IP — not a synonym swap for Identify/Protect/Detect/Respond/Recover.

Teachable in one sentence

Decide what matters, discover and direct the response, defend and debrief when something happens, demonstrate it to the board — then decide again.

Illustration of a shield representing assurance scoring

Coming from the Command Model

The Board Assurance Score™

A short diagnostic across the Six Directives, scored 0–100 — a single, board-ready number for how ready your organisation's leadership, not just its technology, is for a security incident.

How maturity is scored

Three stages, assessed against each directive

The goal isn't maximum security everywhere — it's the right level of maturity for your organisation's actual risk profile.

Stage 01

Foundation

Basic capability exists, but it's informal, undocumented, or dependent on one person.

Stage 02

Managed

Ownership, process and controls are established, documented, and consistently followed.

Stage 03

Advanced

Risk is continuously measured, governed and improved — evidenced, not just believed.

See how the Command Model applies to your organisation