Quality, Expert-Derived Cybersecurity Documentation To Keep Organizations Secure, Compliant & Resilient  |  Got Questions? +1-307-241-8740
ComplianceForge

Compliance Decision Making Process (CDMP)

Solving a unique compliance problem is the driving reason for cybersecurity planning processes (e.g., How do I comply with NIST 800-171 R3?).

ComplianceForge created the Compliance Decision Making Process (CDMP) as a free guide to help compliance staff come up with viable Courses of Action (COA) based on:

  • Facts;
  • Assumptions; and
  • Contraints.
Key Takeaways - Compliance Decision-Making Process
  • The CDMP adapts the US Military Decision Making Process (MDMP) for cybersecurity compliance, using the DIRT framework. Decisions, Intent, Risk and Triggers.
  • Five structured steps. (1) Awareness of obligations, (2) Identify facts and assumptions, (3) Define a problem statement, (4) Determine constraints, (5) Identify courses of action with advantages and disadvantages.
  • Compliance intent captures executive leadership's direction, providing the basis for unity of effort and justifying costs and changes necessary to comply.
  • The guide includes a practical NIST 800-171 example walking through all five steps with real facts, assumptions, constraints and three courses of action.
  • Also covers risk management fundamentals, risk appetite versus tolerance versus threshold, plus how negligence applies to cybersecurity and data privacy.
5 Simple Steps

5 Simple Steps To Compliance Decision Making

The CDMP is designed to be simple and efficient. It identifies sub-steps, as well as inputs and outputs associated with each step in the decision making process. The five (5) steps are:

  • Awareness of compliance obligations;
  • Identify facts & assumptions;
  • Define a problem statement;
  • Determine constraints; and
  • Identify possible Courses of Action (COA).

The PDF beloiw also includes a practical example of using the CDMP for NIST 800-171 compliance.

Compliance decision making process example
Compliance Decision Making Process Diagram
Proactive Approach

Proactive Approach To Compliance Decision Making

Compliance with cybersecurity and date protection laws, regulations and contractual obligations requires a proactive approach to be efficient and effective. Proactive compliance can be thought of as having four (4) distinct components, which comes from the broader Military Decision Making Process (MDMP) used by the US military. The common military planning acronym associated with this is DIRT:

D

Decisions

There are many compliance-related decisions that organizations face. Decisions are often “forks in the road” where there is a binary option to take one path or the other, but not both. This is where the decisions are expected to be based on compliance intent and risk analysis. Examples of decisions that impact compliance operations include:

  • The organization accepts a contract to store, process and/or transmit Controlled Unclassified Information (CUI) as part of a contract with a third party (e.g., government, prime contractor, partner, etc.);
  • Action is taken to restructure supporting business processes to support the broader corporate strategy; and
  • The organization’s CUI enclave is onsite in its own segmented environment.
I

Intent

The compliance intent captures your organization’s executive leadership’s intent for compliance operations. Decisions should be formed, based on compliance intent. Compliance intent:

  • Provides the basis for unity of effort throughout the organization to justify cost/changes necessary to comply;
  • Is meant to support the organization’s broader mission and strategy; and
  • Allows stakeholders to gain insight into what is expected of them, what constraints apply, and most importantly, why the compliance operations are being conducted.
R

Risk

A clear understanding of compliance intent directly influences risk analysis. Understanding the nuances of compliance-related risk can lead to better decision making and that can lead to proper technology alignment, less unexpected change, etc. Examples of understanding risk include:

  • The organization must avoid business engagements with third parties that store/process/transmit CUI that are not able to obtain and maintain Level 2 Cybersecurity Maturity Model Certification (CMMC).
  • While Security Protection Data (SPD) is unlikely to be designated as a CUI category by the US National Archives (NARA), the DoD is unlikely to alter its course that SPD must be protected in a manner that limits technology options.
  • The majority of False Claims Act (FCA) submissions are made from insiders (often recently separated individuals), so compliance operations must have appropriate evidence of due diligence and due care to demonstrate the organization’s compliance efforts.
T

Triggers

Compliance operations are rarely static. Identifying triggers in the compliance landscape can refine risk management analysis and lead to proper decision making that stays inline with compliance intent. Examples of compliance triggers include:

  • NIST released NIST SP 800-171 R3;
  • DoD issues a class deviation to remain aligned with NIST SP 800-171 R2; and
  • 32 CFR § 170.19(c)(2) designates External Service Providers (ESPs) as being considered in scope for CMMC requirements if it meets CUI Asset and/or Security Protection Asset (SPA) criteria (e.g., stores, processes and/or transmits CUI or Security Protection Data (SPD).
Understanding of Risk

Compliance Decsion Making

The CDMP clearly shows you how to make compliance-related decision making efficient and straightforward to develop viable COAs. However, there is an absolute need for risk management practices to exist and be understood by the stakeholders involved in compliance decision making. The CDMP includes a section on baselining risk management terminology and understanding the concept of negligence.

The alternative to risk management is crisis management. The information on this page exists to provide practical risk management guidance for cybersecurity and data privacy practitioners, specifically focused on how to align risk appetite, risk tolerance and risk thresholds with an organization's strategic, operational and tactical business planning activities. What is presented is a holistic approach that has practical applications. There are a lot of terms in cybersecurity and three (3) of the top misused terms are:

  • Risk Tolerance;
  • Risk Threshold; and
  • Risk Appetite.

The concepts of risk appetite, risk tolerance and risk thresholds are not independent terms that are meant to stand by themselves, since they share a dependency that needs to be understood to create a coherent risk management strategy. Likewise, those terms are also directly linked to strategic, operational and tactical decision making.

Risk Threshold vs Risk Tolerance

Organizations invest in cybersecurity and data privacy as a necessity. This necessity is driven in large part by statutory, regulatory and contractual requirements. It is also driven by the desire to protect the organization's brand from acts that would harm its public image. Regardless of the reason, the base expectation is that those charged with developing, implementing and governing the cybersecurity and data privacy functions are doing so in a reasonable manner that would withstand scrutiny that could take the form as an external auditor, regulator or prosecuting attorney.

Common Questions

Frequently-Asked Questions

Here are answers to common questions about making compliance decisions:

What is the Compliance Decision Making Process (CDMP)?
The Compliance Decision Making Process (CDMP) is a free ComplianceForge guide that helps compliance teams develop viable Courses of Action (COA) based on facts, assumptions and constraints. It adapts the US military decision making process to cybersecurity compliance and uses the DIRT concept of decisions, intent, risk and triggers. The process moves from awareness of an obligation to a clear problem statement and a set of options that leadership can choose between.
What are the five steps of the compliance decision making process?
The CDMP has five steps: become aware of compliance obligations, identify facts and assumptions, define a problem statement, determine constraints, and identify possible Courses of Action (COA). Working through the steps in order helps teams understand the requirement and what limits their options before choosing a solution. Applied to a NIST 800-171 requirement, for example, the process can produce three courses of action, each with its own advantages and disadvantages.
What does DIRT stand for in compliance decision making?
DIRT stands for Decisions, Intent, Risk and Triggers. Decisions are the forks in the road where an organization must choose one path or the other. Intent captures executive leadership's intent for compliance operations and provides the basis for unity of effort. Risk reflects how a clear understanding of that intent shapes risk analysis. Triggers are changes that refine risk analysis, such as NIST releasing SP 800-171 R3 or DoD issuing a class deviation.
How is the CDMP based on the military decision making process?
The CDMP adapts the US Army's military decision making process (MDMP) to cybersecurity compliance. The Army publishes the MDMP in Field Manual (FM) 5-0, Planning and Orders Production, alongside troop leading procedures and orders formats. The CDMP applies the same planning discipline to compliance by grounding each option in documented facts, assumptions and constraints, so your leadership can choose between documented courses of action.
How do you develop a compliance course of action?
A compliance course of action (COA) is developed by working from documented facts, stated assumptions and known constraints toward a set of viable options. In the CDMP, teams first confirm the obligation, separate verified facts from assumptions, write a clear problem statement and list constraints such as budget, staffing or deadlines. Each option should then be weighed against the organization's risk appetite, risk tolerance and risk threshold so leadership can make an informed choice.