Skip to content

KCSIE & framework controls

For the helpdesk team

A control is a specific thing the trust does to meet a regulatory or framework requirement. The compliance module lets you catalogue controls against any framework you adopt — KCSIE, ISO 27001, Cyber Essentials, GDPR or your own — and tracks evidence and status against each.

This is where “are we doing what we said we’d do?” gets answered with evidence rather than confidence.

The compliance engine is bring-your-own-framework: you create a framework (name, code, version) and author its controls, or import them. Out of the box, Keystone ships one starter pack you can install in a click:

  • DfE Academies Trust Handbook — a starter slice of the Handbook’s financial-governance, accountability and referenced-safeguarding controls. A starting point to flesh out, not a full transcription.

Frameworks trusts commonly build on top of that starter:

  • KCSIE — Keeping Children Safe in Education; the safeguarding gold standard
  • GDPR / DPA 2018 — data protection
  • Cyber Essentials / Cyber Essentials Plus — government cyber baseline
  • NCSC schools guidance — national cyber security centre advisory
  • ISO 27001 — for trusts that need formal security certification

These are not shipped as pre-authored control content — you map them to your own posture. Trusts can also add wholly custom frameworks (e.g. “Trust internal information security policy”).

  • Reference — the framework’s identifier (e.g. KCSIE Part 5, ISO 27001 A.5.1)
  • Title — short summary
  • Description — what the control requires
  • Owner — who’s accountable (DSL, DPO, IT lead)
  • Compliance result — Compliant / Partial / Non-compliant / Exempt
  • Evidence — uploaded files, screenshots, links to procedures
  • Last reviewed — date + reviewer
  • Next review date — typically annual
  • Linked items — policies, risks, tickets, projects that contribute

Each control needs evidence that it’s actually in place. Not “yes we do this” but “here’s the screenshot / signed document / training record proving it”.

Common evidence types:

  • A screenshot of the configured setting in the relevant system
  • A signed-off policy that references the control
  • A training completion report
  • A meeting minute referring to the control
  • A test result (e.g. quarterly phishing simulation)

Evidence ages — the framework will say “reviewed in the last 12 months”. The compliance dashboard surfaces evidence older than its review interval.

The compliance dashboard scores the trust’s coverage:

  • “KCSIE: 47/52 controls compliant (90%)”
  • “Cyber Essentials: 23/25 (92%)”

Drill into the non-compliant and partial ones. Each gap is either a real gap (we’re not doing this) or a documentation gap (we’re doing it, but the evidence isn’t here yet).

Don’t pad the score by marking gaps as “Exempt” without justification — the auditor will check.

Controls cross-reference everything:

  • Risks that the control mitigates
  • Policies that document the control
  • Tickets that operationalise the control (e.g. *“complete safeguarding training” tickets to all staff)
  • Compliance schedules in Estates that satisfy parts of the control

A well-linked control is easy to defend. An isolated control is just a tick.