KCSIE & framework controls
For the helpdesk teamKCSIE & framework controls
Section titled “KCSIE & framework controls”A control is a specific thing the trust does to meet a regulatory or framework requirement. The compliance module lets you catalogue controls against any framework you adopt — KCSIE, ISO 27001, Cyber Essentials, GDPR or your own — and tracks evidence and status against each.
This is where “are we doing what we said we’d do?” gets answered with evidence rather than confidence.
Frameworks
Section titled “Frameworks”The compliance engine is bring-your-own-framework: you create a framework (name, code, version) and author its controls, or import them. Out of the box, Keystone ships one starter pack you can install in a click:
- DfE Academies Trust Handbook — a starter slice of the Handbook’s financial-governance, accountability and referenced-safeguarding controls. A starting point to flesh out, not a full transcription.
Frameworks trusts commonly build on top of that starter:
- KCSIE — Keeping Children Safe in Education; the safeguarding gold standard
- GDPR / DPA 2018 — data protection
- Cyber Essentials / Cyber Essentials Plus — government cyber baseline
- NCSC schools guidance — national cyber security centre advisory
- ISO 27001 — for trusts that need formal security certification
These are not shipped as pre-authored control content — you map them to your own posture. Trusts can also add wholly custom frameworks (e.g. “Trust internal information security policy”).
Anatomy of a control
Section titled “Anatomy of a control”- Reference — the framework’s identifier (e.g. KCSIE Part 5, ISO 27001 A.5.1)
- Title — short summary
- Description — what the control requires
- Owner — who’s accountable (DSL, DPO, IT lead)
- Compliance result — Compliant / Partial / Non-compliant / Exempt
- Evidence — uploaded files, screenshots, links to procedures
- Last reviewed — date + reviewer
- Next review date — typically annual
- Linked items — policies, risks, tickets, projects that contribute
Evidence
Section titled “Evidence”Each control needs evidence that it’s actually in place. Not “yes we do this” but “here’s the screenshot / signed document / training record proving it”.
Common evidence types:
- A screenshot of the configured setting in the relevant system
- A signed-off policy that references the control
- A training completion report
- A meeting minute referring to the control
- A test result (e.g. quarterly phishing simulation)
Evidence ages — the framework will say “reviewed in the last 12 months”. The compliance dashboard surfaces evidence older than its review interval.
Reporting
Section titled “Reporting”The compliance dashboard scores the trust’s coverage:
- “KCSIE: 47/52 controls compliant (90%)”
- “Cyber Essentials: 23/25 (92%)”
Drill into the non-compliant and partial ones. Each gap is either a real gap (we’re not doing this) or a documentation gap (we’re doing it, but the evidence isn’t here yet).
Don’t pad the score by marking gaps as “Exempt” without justification — the auditor will check.
Linking back
Section titled “Linking back”Controls cross-reference everything:
- Risks that the control mitigates
- Policies that document the control
- Tickets that operationalise the control (e.g. *“complete safeguarding training” tickets to all staff)
- Compliance schedules in Estates that satisfy parts of the control
A well-linked control is easy to defend. An isolated control is just a tick.