Summary
- LACNIC’s board unanimously approved information-security framework DIR-POL-019.01 on 24 May 2026.
- The minutes say outside experts would then measure current maturity, after which LACNIC could determine a target; a versioned transition receipt would make those states auditable without pretending the public minutes contain an assessment.
A board can approve the ruler before anyone takes the measurement. That is what LACNIC’s approved minutes for 24 May 2026 describe. The proposed institutional framework is meant to protect the registry, its information and the critical services needed for LACNIC’s mission, while sustaining member and community trust. Implementation and evaluation are described as progressive steps toward a more formal, sustainable and continuously improving management system.
The revealing sentence comes during the discussion. Once the board approved the framework, the minutes say, external experts would measure the current maturity level; LACNIC could then determine the level it wanted to reach. On the following page, the directors present unanimously approve version DIR-POL-019.01.
That sequence supplies governance authority. It does not supply an operational score. A framework can define vocabulary, scope and decision rights before a baseline exists. The important discipline is not to let one state borrow the meaning of another.
Seven states that should not collapse into one
The public record supports “framework approved” and records an intended next sequence. It does not publish the framework itself, the assessment scale, the evaluator’s identity, the system boundary, a baseline score, a target score, a gap owner, a deadline or a residual-risk decision.
This is a boundary on what the reviewed documents show, not a claim about what LACNIC holds internally. The same boundary prevents two tempting assertions: the record does not establish that an external assessment remained unfinished at publication, and it does not establish that a target remained unset. It also says nothing conclusive about whether LACNIC holds or lacks an ISO/IEC 27001 certificate.
There are at least seven distinct states:
- a governing body authorizes a framework;
- teams map the relevant assets, services and safeguards;
- an assessor measures a dated baseline;
- an authorized body selects a target and target date;
- owners accept and execute a gap plan;
- named authorities accept any residual risk; and
- if certification is claimed, a conformity-assessment body certifies a defined scope for a defined period.
A maturity statement becomes useful only when a reader can tell which state it describes.
The framework, the measurement and the certificate
The minutes record a shorthand distinction: CIS does not certify, while ISO does. The underlying documents make the boundary more exact.
The CIS Critical Security Controls are prioritized cybersecurity practices. Implementation Groups help an organization sequence safeguards according to its resources and risk profile. The CIS Controls Assessment Specification supplies measures and metrics for determining whether safeguards are implemented and how well they operate. Together, these can support a baseline. They do not, by themselves, establish an organization-wide certificate.
ISO/IEC 27001:2022 specifies requirements for an information security management system. ISO’s own overview says an organization may implement the standard without seeking certification; certification by a conformity-assessment body is a separate, optional route to added confidence. “Uses ISO,” “operates an ISMS” and “holds a valid certificate for this scope” therefore remain different claims.
The distinction matters because maturity and certification answer different questions. A maturity assessment can show how far particular safeguards are implemented. A management-system standard tests whether risk is governed through a defined system. Certification adds an external attestation to a specified scope and period. None is a synonym for perfect security.
Scope is part of the result
LACNIC’s 2026–2029 strategy names information security as an internal capability that protects the integrity and resilience of processes and systems. The LACNIC CSIRT description, meanwhile, says its target community is LACNIC members and that it has no authority to operate community systems apart from LACNIC’s own internal systems. The May minutes record a discussion about how CSIRT capabilities might be integrated into the internal security work.
Those lines do not reveal the assessment boundary. They show why a boundary must be stated. “Registry,” “critical services,” corporate systems, member-facing services and a community-response function are related, but they are not automatically the same assessment population. Moving a system in or out of scope can change a maturity result even when no safeguard changes.
An editorial proposal: the maturity-transition receipt
Rather than publish a floating score, LACNIC could attach a compact, versioned receipt to each transition. This is an editorial recommendation, not a reported LACNIC commitment.
| Transition | Receipt fields |
|---|---|
| Approval | Framework name and version, decision date, approving authority and authorized scope |
| Baseline | As-of date, external assessor, independence, method and version, included systems, scale and evidence by control |
| Target | Approved level, approving authority, target date and priority rationale |
| Gap plan | Unmet safeguard, owner, milestone, dependency, exception and compensating measure |
| Residual risk | Risk left open, acceptance authority, expiry and review trigger |
| Remeasurement | Next date and any method or scope change that affects comparability |
| Certification, if asserted | Standard, certificate, certified scope, assessment body and validity period |
Versioning is not administrative decoration. CIS may revise a control, LACNIC may change the applicable implementation group, an assessor may alter the scoring method, or the inventory may expand. Two identical scores under different rules are not the same result. The receipt should preserve the denominator as carefully as the number.
What the May resolution actually gives
DIR-POL-019.01 provides a dated point of authority. The intended external baseline would provide a dated point of observation. A target would reveal a risk-and-resource choice. A gap plan would allocate work. Residual-risk acceptance would identify who owns what remains. A certificate, if ever cited, would need its own scope and evidence.
That grammar is valuable for a regional registry because confidence rests partly on knowing what a record proves. The board’s approval should be read as a beginning with a version number—not as an all-purpose claim about operational maturity.
Sources
Member Briefing
Deeper Profile Context
Sign in with the right membership level to unlock the full briefing and source notes.
Only for Strategic Circle
Strategic Circle
Open to all readers. Unlock profile briefings after joining and signing in.
Join Strategic CircleOnly for Leadership Alliance
Leadership Alliance
For qualified IP-asset owners and management; sign in to unlock alliance briefings.
Join Leadership Alliance
