Why mature security programs think in controls, not frameworks — and where “many frameworks, one operating model” breaks down if you take it too literally.

By the time a security program matures, you don’t have one framework anymore. You have several. A customer wants SOC 2. Another asks if you’re ISO 27001 certified. A cloud client sends a questionnaire. A regulator has its own expectations. None of them replace the others — they accumulate. Left unmanaged, that pile becomes what every experienced security leader dreads: framework sprawl.

How it starts

It almost always starts with good intentions. Each new framework becomes its own initiative — separate policies, separate evidence folders, separate audit calendars, separate owners. After a few years, you’re no longer running one security program. You’re running five administrative versions of the same one.

Here’s the cruel part: almost none of that duplication makes you safer. Multi-factor authentication was deployed once. The access review happened once. But each framework wants that same control documented in its own dialect. The work multiplies. The security doesn’t.

Where compliance and security quietly diverge

That’s where a compliance program and a security program part ways — the unit of thought. Immature programs think in frameworks. Mature ones think in controls, risks, and obligations, and let the frameworks read them. Build one program, operate one, improve one — then describe it in whatever language your customer, regulator, auditor, or board expects. Many frameworks, one operating model. One implementation, many mappings.

The shift that unlocks it: a framework isn’t your security program — it’s a window onto it. ISO looks through a management system; CIS through prioritized safeguards. The house doesn’t change; only the window does. Add a framework, and you’re not building another house — you’re cutting another window into the one you already live in.

The part the tidy version skips

But the lenses aren’t fully interchangeable, and that’s the correction that actually matters. Each framework keeps obligations that belong to it alone, and no amount of mapping makes them disappear. ISO still wants its management review. A regulator still wants notification inside its own deadline. So the honest version has three beats, not two: implement once, describe many — and preserve what each one uniquely demands. Unification reduces duplication. It never dissolves obligation.

Which is why the real tell is a quiet one. Immature organizations celebrate adding another certificate. Mature ones celebrate avoiding another duplicate control. Sprawl masquerades as rigor — it’s what rigor looks like with no architecture underneath it. The fix is almost never more effort. It’s more structure.


Vikas Khandelwal is the Founder & Principal Consultant at Secalyx Technologies, helping organizations build one operating model that satisfies many frameworks.

Leave a Reply

Your email address will not be published. Required fields are marked *