Join our Newsletter — 33% off our NHI Course

Information and Communication

Information and communication is the control component that ensures the right people receive accurate, timely, and usable information about their responsibilities. In identity and compliance programmes, it is what makes control ownership, exceptions, and remediation visible enough to govern.

What Information and Communication Does in Governance

Information and communication turns a control from a design into an operating reality. It ensures that owners, reviewers, approvers, and responders actually receive the information they need, in time to act on exceptions, remediation, and accountability decisions.

In practice, this is the layer that makes policies, exceptions, evidence requests, and remediation deadlines visible enough to govern. Without it, control ownership exists on paper but not in day-to-day execution.

Why It Matters for Control Ownership

Good information flow clarifies who is responsible for a control, what evidence is required, and when an issue has moved from acceptable exception to unresolved exposure. It also reduces the common failure mode where remediation tasks are assigned but not understood, tracked, or escalated.

For identity and compliance programmes, this is especially important because ownership often spans security, platform, audit, and application teams. Clear communication keeps one team from assuming another has accepted the risk or completed the fix.

How It Supports Remediation and Accountability

This control component supports the full remediation chain: identify the issue, notify the right people, record the decision, and confirm closure. It is as much about traceability as it is about message delivery.

A strong communication process should preserve enough context for a reviewer to see what failed, why it matters, and what has been done about it. That is what makes exceptions auditable and repeatable instead of informal and lost in inboxes or meetings.

Where It Breaks Down

Information and communication fails when reporting is too late, too vague, or routed to the wrong audience. It also fails when teams share status but not ownership, or when exceptions are documented without a clear remediation path and deadline.

In mature programmes, the problem is rarely the absence of data. It is the absence of the right data, in the right format, reaching the right decision-maker soon enough to change the outcome.

Risk and Threat Considerations

Weak information and communication creates governance blind spots. Control gaps can persist because no one can see unresolved exceptions clearly enough to challenge them, and delayed escalation gives routine misses time to become repeat findings or broader exposure.

Failure mechanism: Owners do not receive accurate or timely control status, exceptions are not routed to accountable parties, and remediation stalls without visible escalation or closure.

Impact: Organisations lose traceability, let exceptions accumulate, and increase the chance that unresolved control weaknesses remain active long enough to affect audit outcomes, operational resilience, or access governance.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST CSF 2.0, NIST SP 800-53 Rev 5 and CIS Controls v8 set the technical controls, while ISO/IEC 27001:2022 defines the regulatory obligations.

Framework Control / Reference Relevance
NIST CSF 2.0 GV.OV-01 — Oversight of risk management strategy and outcomes Information and communication make control ownership and exception handling visible for oversight.
Recommendation — Tie exception reporting to oversight reviews so unresolved control gaps are escalated and closed.
NIST SP 800-53 Rev 5 CA-7 — Continuous Monitoring Continuous monitoring depends on timely reporting of control status and exceptions to accountable staff.
Recommendation — Route control-status and exception updates into continuous monitoring so gaps are tracked until closure.
ISO/IEC 27001:2022 A.5.24 — Information security incident management planning and preparation Prepared incident communication requires the right people to receive timely, usable information.
Recommendation — Define who must be notified, when, and with what evidence so incident communication is consistent.
CIS Controls v8 CIS-17 — Incident Response Management Incident and remediation communication are core to making response responsibilities visible and actionable.
Recommendation — Use incident-response communications to assign, track, and confirm remediation ownership.

Practitioner Guidance

Governance implication: Treat this as a control-enablement function, not a courtesy layer. If ownership, exception handling, or remediation tracking is ambiguous, the communication process is not working, even if the underlying control design is sound.

What to watch for: Repeated status drift, unclear ownership, and exception records that never produce a decision are strong signs that the control communication path needs tightening.