All articles
Product

Answer once, reuse everywhere: the capability ledger for service providers

5 min readVictor Pettersson, IT-säkerhetschef, Sokigo

If you sell software or services, you answer the same security questions for the rest of your company's life. An ISO 27001 audit asks how you handle access control. Every customer's procurement questionnaire asks it again, in different words. Add a second framework and it asks a third time.

Most organizations answer each of these from scratch, in a fresh spreadsheet, and the versions slowly diverge until nobody's sure which one is true. Aquil's Requirement Tracker is designed to end that repetition.

The capability is the unit of reuse

Instead of answering requirements one by one, you describe what your product does once ("we encrypt data at rest with AES-256-GCM, per tenant") as a capability, and attach the evidence that proves it. That single capability can then satisfy the matching ISO control, the clause in one customer's questionnaire, and the near-identical clause in the next.

This is the deliberate break from the old way of working, where the same answer was entered against every requirement it touched, effectively answering the same question a hundred times. Here you answer it once, and reuse it everywhere it applies.

One library, many demands

Requirements reach you from three directions: framework controls like ISO 27001, security lines pulled from customer deals, and your own internal policies. In Aquil they are all the same kind of thing, a demand, and they are all answered from the same library of capabilities.

The payoff compounds: the work you do to stand up your ISO posture also pre-answers the next procurement questionnaire, because both draw on the same evidence-backed capabilities.

A library that scales with your teams

Capabilities belong to solutions and have owners. A teammate with access can suggest a change or a new capability; the owner approves it. Scopes keep each team working within what's theirs. So the library can grow across several products and departments without becoming an unaccountable free-for-all: every entry has someone responsible for it.

Build the library without staring at a blank page

To bootstrap, the compliance wizard groups a framework's controls into a handful of themes and, for each, proposes a capability from what Aquil already knows. You confirm more than you author. A whole framework becomes a set of reusable capabilities in one focused sitting, and nothing is official until you confirm it.

When every answer is a reusable object instead of a one-off cell, compliance stops being a cost that repeats itself. It becomes an asset, one that gets more valuable every time you are asked the same question again.

See what Aquil can do for your team