The audit is only one part of the path to CCN-STIC 896 certification. For a SOC considering starting the process, much of the work begins earlier: defining which services it wants to certify, reviewing how it is providing them, and verifying that it has sufficient procedures and evidence to demonstrate its capabilities.
The CCN-STIC 896, which establishes the Specific Compliance Profile for Managed Security Services (PCE-SSG), evaluates the operational capabilities and technical skills necessary to provide these services, as well as the security of the systems from which they are delivered.
The starting point, therefore, lies in the SOC's own operations and its ability to demonstrate them.
Knowing what we want to certify
The CCN-STIC 896 includes five categories of Services Managed Security: Prevention, Protection, Detection, Response, and Management of Cybersecurity.
Defining which of these aspects you want to certify allows you to narrow down the applicable requirements and begin reviewing the organization's level of preparedness.
Here, a relevant issue arises: doing something routinely and being able to certify it are not always the same. A procedure may be perfectly ingrained by a team and yet not be sufficiently documented. Certain tasks may depend on the knowledge of specific analysts or have been incorporated into operations without updating the corresponding documentation.
These are situations worth identifying before pursuing certification.
The review should encompass both the team providing the service and the procedures they use, as well as the systems that support it. The CCN-STIC 896 standard establishes requirements in these three areas, so preparing for certification requires looking beyond purely technical capabilities.
Here are some questions that can help you make an initial check:
- Are the Managed Security Services to be certified clearly identified?
- Are there documented and up-to-date procedures for providing these services?
- Is the way of working sufficiently consistent among the different team members?
- Is there evidence to demonstrate how the processes are executed?
- Can the qualifications and capabilities of the staff be verified?
- Do the systems supporting these services meet the established security requirements?
This isn't yet a formal self-assessment, but answering these questions allows you to anticipate some of the points that may be required. work.
The last point deserves special attention. The information systems that support Managed Security Services must have Certification of Conformity with the National Security Scheme (ENS) at the MEDIUM level or higher. For those cases where this conformity has not yet been achieved, CCN-STIC 896 establishes an alternative: implement a minimum set of 36 security measures and make a formal commitment to obtain it within a maximum period of 12 months.
Self-assessment is for more than just getting a score
The National Network of Schools (RNS) has a specific self-assessment tool based on the CCN-STIC 896 Guide. To request an audit, it is necessary to obtain a score higher than 50% in each of the applicable sections.
The percentage indicates whether the established threshold has been reached, but the most interesting information is probably elsewhere: in the requirements that are not met.
These are the specific shortcomings that need to be addressed before continuing with the process. This could be a procedure that needs updating, evidence that isn't being generated or properly maintained, a capability that needs strengthening, or a requirement related to the systems that support the service.
Therefore, it's advisable to read the self-assessment as a roadmap of the current situation and not just as a test to be passed.
This perspective also avoids one of the mistakes that can occur in any certification process: preparing documentation solely for the audit. If a procedure exists on paper but is not part of the SOC's daily work, it is unlikely to be fulfilling the objective for which it was defined.
The CCN-STIC 896 thus offers an opportunity to review, using common criteria, capabilities that are already part of the SOC's daily activity and to identify those that still need to evolve.
Before starting the process, there is a rather revealing check: take one of the services to be certified and try to reconstruct how it is provided, who is involved, what procedure is followed, and what evidence remains of its execution.
If this is easy to do, there is probably a good foundation to work from. If gaps, dependencies on individual knowledge, or processes that are difficult to accredit appear, we have already identified some of the first points that should be addressed.