Version: 4.0
Published: 18 April 2024
Reviewed: 6 August 2025
Objectives
Principles
The organisation has appropriate management policies, processes and procedures in place to govern its approach to the security of network and information systems.
Description
error determining description
Guidance
Your organisation's approach to security governance needs to be an appropriate fit for your organisation. Good security governance is integrated with your business's usual decision making structures and processes.
Decisions about risk can be made at all levels of your organisation when delegated effectively to people with the right security, business and technical knowledge, skills and experience. Clear lines of communication are also necessary.
Contributing Outcomes
A1.a Board Direction
- You have effective organisational security management led at board level and articulated clearly in corresponding policies.
- You have effective organisational security management led at board level and articulated clearly in corresponding policies.
- The security of network and information systems related to the operation of essential function(s) is not discussed or reported on regularly at board-level.
- Board-level discussions on the security of network and information systems are based on partial or out-of-date information, without the benefit of expert guidance.
- The security of network and information systems supporting your essential function(s) are not driven effectively by the direction set at board-level.
- Senior management or other pockets of the organisation consider themselves exempt from some policies or expect special accommodations to be made.
- Your organisation's approach and policy relating to the security of network and information systems supporting the operation of essential function(s) are owned and managed at board-level. These are communicated, in a meaningful way, to risk management decision-makers across the organisation.
- Regular board-level discussions on the security of network and information systems supporting the operation of your essential function(s) take place, based on timely and accurate information and informed by expert guidance.
- There is a board-level individual who has overall accountability for the security of network and information systems and drives regular discussion at board-level.
- Direction set at board-level is translated into effective organisational practices that direct and control the security of the network and information systems supporting your essential functions(s).
- The board has the information and understanding needed in order to effectively discuss how the security and resilience of network and information systems contributes to the delivery of essential function(s) and what the potential impact from compromise of those systems would be.
- Security is recognised as an important enabler for the resilience of your essential function(s) and considered in all relevant discussions.
Not achieved - At least one of the following statements is true:
- The security of network and information systems related to the operation of essential function(s) is not discussed or reported on regularly at board-level.
- Board-level discussions on the security of network and information systems are based on partial or out-of-date information, without the benefit of expert guidance.
- The security of network and information systems supporting your essential function(s) are not driven effectively by the direction set at board-level.
- Senior management or other pockets of the organisation consider themselves exempt from some policies or expect special accommodations to be made.
Achieved - All the following statements are true:
- Your organisation's approach and policy relating to the security of network and information systems supporting the operation of essential function(s) are owned and managed at board-level. These are communicated, in a meaningful way, to risk management decision-makers across the organisation.
- Regular board-level discussions on the security of network and information systems supporting the operation of your essential function(s) take place, based on timely and accurate information and informed by expert guidance.
- There is a board-level individual who has overall accountability for the security of network and information systems and drives regular discussion at board-level.
- Direction set at board-level is translated into effective organisational practices that direct and control the security of the network and information systems supporting your essential functions(s).
- The board has the information and understanding needed in order to effectively discuss how the security and resilience of network and information systems contributes to the delivery of essential function(s) and what the potential impact from compromise of those systems would be.
- Security is recognised as an important enabler for the resilience of your essential function(s) and considered in all relevant discussions.
A1.b Roles and Responsibilities
- Your organisation has established roles and responsibilities for the security of network and information systems at all levels, with clear and well-understood channels for communicating and escalating risks.
- Your organisation has established roles and responsibilities for the security of network and information systems at all levels, with clear and well-understood channels for communicating and escalating risks.
- Key roles are missing, left vacant, or fulfilled on an ad-hoc or informal basis.
- Staff are assigned security responsibilities but without adequate authority or resources to fulfil them.
- Staff are unsure what their responsibilities are for the security of the essential function(s).
- Key roles and responsibilities for the security of network and information systems supporting your essential function(s) have been identified. These are reviewed regularly to ensure they remain fit for purpose.
- Appropriately capable and knowledgeable staff fill those roles and are given the time, authority, and resources to carry out their duties.
- There is clarity on who in your organisation has overall accountability for the security of the network and information systems supporting your essential function(s).
Not achieved - At least one of the following statements is true:
- Key roles are missing, left vacant, or fulfilled on an ad-hoc or informal basis.
- Staff are assigned security responsibilities but without adequate authority or resources to fulfil them.
- Staff are unsure what their responsibilities are for the security of the essential function(s).
Achieved - All the following statements are true:
- Key roles and responsibilities for the security of network and information systems supporting your essential function(s) have been identified. These are reviewed regularly to ensure they remain fit for purpose.
- Appropriately capable and knowledgeable staff fill those roles and are given the time, authority, and resources to carry out their duties.
- There is clarity on who in your organisation has overall accountability for the security of the network and information systems supporting your essential function(s).
A1.c Decision-making
- You have senior-level accountability for the security of network and information systems, and delegate decision-making authority appropriately and effectively. Risks to network and information systems related to the operation of the essential function(s) are considered in the context of other organisational risks
.
- You have senior-level accountability for the security of network and information systems, and delegate decision-making authority appropriately and effectively. Risks to network and information systems related to the operation of the essential function(s) are considered in the context of other organisational risks
- What should be relatively straightforward risk decisions are constantly referred up the chain, or not made.
- Risks are resolved informally (or ignored) at a local level when the use of a more formal risk reporting mechanism would be more appropriate.
- Decision-makers are unsure of what senior management's risk appetite is, or only understand it in vague terms such as "averse" or "cautious".
- Decision-makers are unable to justify their risk management decisions.
- Organisational structure causes risk decisions to be made in isolation. (e.g. engineering and IT don't talk to each other about risk).
- Risk priorities are too vague to make meaningful distinctions between them. (e.g. almost all risks are rated 'medium' or 'amber').
- Senior management have visibility of key risk decisions made throughout the organisation.
- Risk management decision-makers understand their responsibilities for making effective and timely decisions in the context of the risk appetite regarding the essential function(s), as set by senior management.
- Risk management decision-making is delegated and escalated where necessary, across the organisation, to people who have the skills, knowledge, tools and authority they need.
- Risk management decisions are regularly reviewed to ensure their continued relevance and validity.
Not achieved - At least one of the following statements is true:
- What should be relatively straightforward risk decisions are constantly referred up the chain, or not made.
- Risks are resolved informally (or ignored) at a local level when the use of a more formal risk reporting mechanism would be more appropriate.
- Decision-makers are unsure of what senior management's risk appetite is, or only understand it in vague terms such as "averse" or "cautious".
- Decision-makers are unable to justify their risk management decisions.
- Organisational structure causes risk decisions to be made in isolation. (e.g. engineering and IT don't talk to each other about risk).
- Risk priorities are too vague to make meaningful distinctions between them. (e.g. almost all risks are rated 'medium' or 'amber').
Achieved - All the following statements are true:
- Senior management have visibility of key risk decisions made throughout the organisation.
- Risk management decision-makers understand their responsibilities for making effective and timely decisions in the context of the risk appetite regarding the essential function(s), as set by senior management.
- Risk management decision-making is delegated and escalated where necessary, across the organisation, to people who have the skills, knowledge, tools and authority they need.
- Risk management decisions are regularly reviewed to ensure their continued relevance and validity.
The organisation has appropriate management policies, processes and procedures in place to govern its approach to the security of network and information systems.
Description
error determining description
Guidance
Your organisation's approach to security governance needs to be an appropriate fit for your organisation. Good security governance is integrated with your business's usual decision making structures and processes.
Decisions about risk can be made at all levels of your organisation when delegated effectively to people with the right security, business and technical knowledge, skills and experience. Clear lines of communication are also necessary.
Contributing Outcomes
A1.a Board Direction
- You have effective organisational security management led at board level and articulated clearly in corresponding policies.
- You have effective organisational security management led at board level and articulated clearly in corresponding policies.
- The security of network and information systems related to the operation of essential function(s) is not discussed or reported on regularly at board-level.
- Board-level discussions on the security of network and information systems are based on partial or out-of-date information, without the benefit of expert guidance.
- The security of network and information systems supporting your essential function(s) are not driven effectively by the direction set at board-level.
- Senior management or other pockets of the organisation consider themselves exempt from some policies or expect special accommodations to be made.
- Your organisation's approach and policy relating to the security of network and information systems supporting the operation of essential function(s) are owned and managed at board-level. These are communicated, in a meaningful way, to risk management decision-makers across the organisation.
- Regular board-level discussions on the security of network and information systems supporting the operation of your essential function(s) take place, based on timely and accurate information and informed by expert guidance.
- There is a board-level individual who has overall accountability for the security of network and information systems and drives regular discussion at board-level.
- Direction set at board-level is translated into effective organisational practices that direct and control the security of the network and information systems supporting your essential functions(s).
- The board has the information and understanding needed in order to effectively discuss how the security and resilience of network and information systems contributes to the delivery of essential function(s) and what the potential impact from compromise of those systems would be.
- Security is recognised as an important enabler for the resilience of your essential function(s) and considered in all relevant discussions.
Not achieved - At least one of the following statements is true:
- The security of network and information systems related to the operation of essential function(s) is not discussed or reported on regularly at board-level.
- Board-level discussions on the security of network and information systems are based on partial or out-of-date information, without the benefit of expert guidance.
- The security of network and information systems supporting your essential function(s) are not driven effectively by the direction set at board-level.
- Senior management or other pockets of the organisation consider themselves exempt from some policies or expect special accommodations to be made.
Achieved - All the following statements are true:
- Your organisation's approach and policy relating to the security of network and information systems supporting the operation of essential function(s) are owned and managed at board-level. These are communicated, in a meaningful way, to risk management decision-makers across the organisation.
- Regular board-level discussions on the security of network and information systems supporting the operation of your essential function(s) take place, based on timely and accurate information and informed by expert guidance.
- There is a board-level individual who has overall accountability for the security of network and information systems and drives regular discussion at board-level.
- Direction set at board-level is translated into effective organisational practices that direct and control the security of the network and information systems supporting your essential functions(s).
- The board has the information and understanding needed in order to effectively discuss how the security and resilience of network and information systems contributes to the delivery of essential function(s) and what the potential impact from compromise of those systems would be.
- Security is recognised as an important enabler for the resilience of your essential function(s) and considered in all relevant discussions.
A1.b Roles and Responsibilities
- Your organisation has established roles and responsibilities for the security of network and information systems at all levels, with clear and well-understood channels for communicating and escalating risks.
- Your organisation has established roles and responsibilities for the security of network and information systems at all levels, with clear and well-understood channels for communicating and escalating risks.
- Key roles are missing, left vacant, or fulfilled on an ad-hoc or informal basis.
- Staff are assigned security responsibilities but without adequate authority or resources to fulfil them.
- Staff are unsure what their responsibilities are for the security of the essential function(s).
- Key roles and responsibilities for the security of network and information systems supporting your essential function(s) have been identified. These are reviewed regularly to ensure they remain fit for purpose.
- Appropriately capable and knowledgeable staff fill those roles and are given the time, authority, and resources to carry out their duties.
- There is clarity on who in your organisation has overall accountability for the security of the network and information systems supporting your essential function(s).
Not achieved - At least one of the following statements is true:
- Key roles are missing, left vacant, or fulfilled on an ad-hoc or informal basis.
- Staff are assigned security responsibilities but without adequate authority or resources to fulfil them.
- Staff are unsure what their responsibilities are for the security of the essential function(s).
Achieved - All the following statements are true:
- Key roles and responsibilities for the security of network and information systems supporting your essential function(s) have been identified. These are reviewed regularly to ensure they remain fit for purpose.
- Appropriately capable and knowledgeable staff fill those roles and are given the time, authority, and resources to carry out their duties.
- There is clarity on who in your organisation has overall accountability for the security of the network and information systems supporting your essential function(s).
A1.c Decision-making
- You have senior-level accountability for the security of network and information systems, and delegate decision-making authority appropriately and effectively. Risks to network and information systems related to the operation of the essential function(s) are considered in the context of other organisational risks
.
- You have senior-level accountability for the security of network and information systems, and delegate decision-making authority appropriately and effectively. Risks to network and information systems related to the operation of the essential function(s) are considered in the context of other organisational risks
- What should be relatively straightforward risk decisions are constantly referred up the chain, or not made.
- Risks are resolved informally (or ignored) at a local level when the use of a more formal risk reporting mechanism would be more appropriate.
- Decision-makers are unsure of what senior management's risk appetite is, or only understand it in vague terms such as "averse" or "cautious".
- Decision-makers are unable to justify their risk management decisions.
- Organisational structure causes risk decisions to be made in isolation. (e.g. engineering and IT don't talk to each other about risk).
- Risk priorities are too vague to make meaningful distinctions between them. (e.g. almost all risks are rated 'medium' or 'amber').
- Senior management have visibility of key risk decisions made throughout the organisation.
- Risk management decision-makers understand their responsibilities for making effective and timely decisions in the context of the risk appetite regarding the essential function(s), as set by senior management.
- Risk management decision-making is delegated and escalated where necessary, across the organisation, to people who have the skills, knowledge, tools and authority they need.
- Risk management decisions are regularly reviewed to ensure their continued relevance and validity.
Not achieved - At least one of the following statements is true:
- What should be relatively straightforward risk decisions are constantly referred up the chain, or not made.
- Risks are resolved informally (or ignored) at a local level when the use of a more formal risk reporting mechanism would be more appropriate.
- Decision-makers are unsure of what senior management's risk appetite is, or only understand it in vague terms such as "averse" or "cautious".
- Decision-makers are unable to justify their risk management decisions.
- Organisational structure causes risk decisions to be made in isolation. (e.g. engineering and IT don't talk to each other about risk).
- Risk priorities are too vague to make meaningful distinctions between them. (e.g. almost all risks are rated 'medium' or 'amber').
Achieved - All the following statements are true:
- Senior management have visibility of key risk decisions made throughout the organisation.
- Risk management decision-makers understand their responsibilities for making effective and timely decisions in the context of the risk appetite regarding the essential function(s), as set by senior management.
- Risk management decision-making is delegated and escalated where necessary, across the organisation, to people who have the skills, knowledge, tools and authority they need.
- Risk management decisions are regularly reviewed to ensure their continued relevance and validity.
The organisation has appropriate management policies, processes and procedures in place to govern its approach to the security of network and information systems.
Description
error determining description
Guidance
Your organisation's approach to security governance needs to be an appropriate fit for your organisation. Good security governance is integrated with your business's usual decision making structures and processes.
Decisions about risk can be made at all levels of your organisation when delegated effectively to people with the right security, business and technical knowledge, skills and experience. Clear lines of communication are also necessary.
Contributing Outcomes
A1.a Board Direction
- You have effective organisational security management led at board level and articulated clearly in corresponding policies.
- You have effective organisational security management led at board level and articulated clearly in corresponding policies.
- The security of network and information systems related to the operation of essential function(s) is not discussed or reported on regularly at board-level.
- Board-level discussions on the security of network and information systems are based on partial or out-of-date information, without the benefit of expert guidance.
- The security of network and information systems supporting your essential function(s) are not driven effectively by the direction set at board-level.
- Senior management or other pockets of the organisation consider themselves exempt from some policies or expect special accommodations to be made.
- Your organisation's approach and policy relating to the security of network and information systems supporting the operation of essential function(s) are owned and managed at board-level. These are communicated, in a meaningful way, to risk management decision-makers across the organisation.
- Regular board-level discussions on the security of network and information systems supporting the operation of your essential function(s) take place, based on timely and accurate information and informed by expert guidance.
- There is a board-level individual who has overall accountability for the security of network and information systems and drives regular discussion at board-level.
- Direction set at board-level is translated into effective organisational practices that direct and control the security of the network and information systems supporting your essential functions(s).
- The board has the information and understanding needed in order to effectively discuss how the security and resilience of network and information systems contributes to the delivery of essential function(s) and what the potential impact from compromise of those systems would be.
- Security is recognised as an important enabler for the resilience of your essential function(s) and considered in all relevant discussions.
Not achieved - At least one of the following statements is true:
- The security of network and information systems related to the operation of essential function(s) is not discussed or reported on regularly at board-level.
- Board-level discussions on the security of network and information systems are based on partial or out-of-date information, without the benefit of expert guidance.
- The security of network and information systems supporting your essential function(s) are not driven effectively by the direction set at board-level.
- Senior management or other pockets of the organisation consider themselves exempt from some policies or expect special accommodations to be made.
Achieved - All the following statements are true:
- Your organisation's approach and policy relating to the security of network and information systems supporting the operation of essential function(s) are owned and managed at board-level. These are communicated, in a meaningful way, to risk management decision-makers across the organisation.
- Regular board-level discussions on the security of network and information systems supporting the operation of your essential function(s) take place, based on timely and accurate information and informed by expert guidance.
- There is a board-level individual who has overall accountability for the security of network and information systems and drives regular discussion at board-level.
- Direction set at board-level is translated into effective organisational practices that direct and control the security of the network and information systems supporting your essential functions(s).
- The board has the information and understanding needed in order to effectively discuss how the security and resilience of network and information systems contributes to the delivery of essential function(s) and what the potential impact from compromise of those systems would be.
- Security is recognised as an important enabler for the resilience of your essential function(s) and considered in all relevant discussions.
A1.b Roles and Responsibilities
- Your organisation has established roles and responsibilities for the security of network and information systems at all levels, with clear and well-understood channels for communicating and escalating risks.
- Your organisation has established roles and responsibilities for the security of network and information systems at all levels, with clear and well-understood channels for communicating and escalating risks.
- Key roles are missing, left vacant, or fulfilled on an ad-hoc or informal basis.
- Staff are assigned security responsibilities but without adequate authority or resources to fulfil them.
- Staff are unsure what their responsibilities are for the security of the essential function(s).
- Key roles and responsibilities for the security of network and information systems supporting your essential function(s) have been identified. These are reviewed regularly to ensure they remain fit for purpose.
- Appropriately capable and knowledgeable staff fill those roles and are given the time, authority, and resources to carry out their duties.
- There is clarity on who in your organisation has overall accountability for the security of the network and information systems supporting your essential function(s).
Not achieved - At least one of the following statements is true:
- Key roles are missing, left vacant, or fulfilled on an ad-hoc or informal basis.
- Staff are assigned security responsibilities but without adequate authority or resources to fulfil them.
- Staff are unsure what their responsibilities are for the security of the essential function(s).
Achieved - All the following statements are true:
- Key roles and responsibilities for the security of network and information systems supporting your essential function(s) have been identified. These are reviewed regularly to ensure they remain fit for purpose.
- Appropriately capable and knowledgeable staff fill those roles and are given the time, authority, and resources to carry out their duties.
- There is clarity on who in your organisation has overall accountability for the security of the network and information systems supporting your essential function(s).
A1.c Decision-making
- You have senior-level accountability for the security of network and information systems, and delegate decision-making authority appropriately and effectively. Risks to network and information systems related to the operation of the essential function(s) are considered in the context of other organisational risks
.
- You have senior-level accountability for the security of network and information systems, and delegate decision-making authority appropriately and effectively. Risks to network and information systems related to the operation of the essential function(s) are considered in the context of other organisational risks
- What should be relatively straightforward risk decisions are constantly referred up the chain, or not made.
- Risks are resolved informally (or ignored) at a local level when the use of a more formal risk reporting mechanism would be more appropriate.
- Decision-makers are unsure of what senior management's risk appetite is, or only understand it in vague terms such as "averse" or "cautious".
- Decision-makers are unable to justify their risk management decisions.
- Organisational structure causes risk decisions to be made in isolation. (e.g. engineering and IT don't talk to each other about risk).
- Risk priorities are too vague to make meaningful distinctions between them. (e.g. almost all risks are rated 'medium' or 'amber').
- Senior management have visibility of key risk decisions made throughout the organisation.
- Risk management decision-makers understand their responsibilities for making effective and timely decisions in the context of the risk appetite regarding the essential function(s), as set by senior management.
- Risk management decision-making is delegated and escalated where necessary, across the organisation, to people who have the skills, knowledge, tools and authority they need.
- Risk management decisions are regularly reviewed to ensure their continued relevance and validity.
Not achieved - At least one of the following statements is true:
- What should be relatively straightforward risk decisions are constantly referred up the chain, or not made.
- Risks are resolved informally (or ignored) at a local level when the use of a more formal risk reporting mechanism would be more appropriate.
- Decision-makers are unsure of what senior management's risk appetite is, or only understand it in vague terms such as "averse" or "cautious".
- Decision-makers are unable to justify their risk management decisions.
- Organisational structure causes risk decisions to be made in isolation. (e.g. engineering and IT don't talk to each other about risk).
- Risk priorities are too vague to make meaningful distinctions between them. (e.g. almost all risks are rated 'medium' or 'amber').
Achieved - All the following statements are true:
- Senior management have visibility of key risk decisions made throughout the organisation.
- Risk management decision-makers understand their responsibilities for making effective and timely decisions in the context of the risk appetite regarding the essential function(s), as set by senior management.
- Risk management decision-making is delegated and escalated where necessary, across the organisation, to people who have the skills, knowledge, tools and authority they need.
- Risk management decisions are regularly reviewed to ensure their continued relevance and validity.
The organisation takes appropriate steps to identify, assess and understand security risks to network and information systems supporting the operation of essential functions. This includes an overall organisational approach to risk management.
Description
error determining description
Guidance
Our
Risk Management guidance
aims to help you to choose an approach that's right for your organisation. Organisations responsible for essential functions are likely to benefit from a combination of a
system-based approach
, which looks at the interactions between components of the function, and a
component-driven analysis
, which considers the threats, vulnerabilities, and impacts relevant to particular critical components.
Your organisation should choose a method or framework for managing risk that fits with the organisation's business and technology needs.
Whichever approach you choose, the scope of your programme must include all systems relevant to the operation of essential functions. Simply following the minimum requirements of a standard or applying blanket controls across the organisation is unlikely to adequately manage risks to critical systems.
Where industrial control and automation systems are in scope of the essential function, you should keep in mind that controls suitable for managing risks on the corporate IT network may be inappropriate or damaging in an operational technology environment. These systems will likely require a more tailored approach, and some frameworks and standards address specific concerns relating to such systems.
Cyber threats continue to evolve and develop, putting each organisation’s operational continuity and services at significant risk. By identifying and understanding cyber threats, and the steps a threat actor may take to compromise systems supporting essential functions, an organisation can implement effective security measures to counter malicious attacks and breaches. Various methods can be used to better understand threat which are discussed in our
Risk Management guidance
.
Ultimately, a detailed understanding of current cyber threats helps organisations to mitigate risks, ensuring the security and resilience of network and information systems in an increasingly hostile world.
Various means are available to gain confidence in the effectiveness of the security of technologies, processes and people. The NCSC Risk Management guidance discusses
how to gain and maintain assurance
in your risk treatments.
The NCSC assurance guidance provides some examples that may be useful to understand cyber security confidence in your organisation and there are some specific technical NCSC guides:
The
NCSC Penetration guidance
will help you understand the proper use and commissioning of penetration tests to gain assurance in the security of an IT system.
Our
Cloud Security collection
provides guidance on managing the risks involved with using cloud services, and some of the principles and guidance are more broadly applicable. The cloud guidance for having confidence in cyber security provides principles that are useful for assuring cyber security of essential functions. The collection will be of particular interest if your organisation hosts any part of your essential function infrastructure on a cloud service.
The
NCSC Penetration guidance
will help you understand the proper use and commissioning of penetration tests to gain assurance in the security of an IT system.
Contributing Outcomes
A2.a Risk Management Process
- Your organisation has effective internal processes for managing risks to the security and resilience of network and information systems related to the operation of your essential function(s) and communicating associated activities.
- Your organisation has effective internal processes for managing risks to the security and resilience of network and information systems related to the operation of your essential function(s) and communicating associated activities.
- Risk assessments are not based on a clearly defined set of threat assumptions.
- Risk assessment outputs are too complex or unwieldy to be consumed by decision-makers and are not effectively communicated in a clear and timely manner.
- Risk assessments for network and information systems that support your essential function(s) are a "one-off" activity or not done at all.
- The security elements of projects or programmes are solely dependent on the completion of a risk management assessment without any regard to the outcomes.
- There is no systematic process in place to ensure that identified security risks are managed effectively.
- Systems are assessed in isolation, without consideration of dependencies and interactions with other systems. (e.g. interactions between IT and OT environments).
- Security requirements and mitigations are arbitrary or are applied from a control catalogue without consideration of how they contribute to the security of the essential function(s).
- Risks remain unresolved on a register for prolonged periods of time awaiting senior decision-making or resource allocation to resolve.
- Your organisational process ensures that security risks to network and information systems relevant to essential function(s) are identified, analysed, prioritised, and managed.
- Your risk assessments are informed by an understanding of the vulnerabilities in the network and information systems supporting your essential function(s).
- The output from your risk management process is a clear set of security requirements that will address the risks in line with your organisational approach to security.
- Significant conclusions reached in the course of your risk management process are communicated to key security decision-makers and accountable individuals.
- You conduct risk assessments when significant events potentially affect the essential function(s), such as replacing a system, introducing new or emergent technologies or a change in the cyber security threat.
- Your organisational process ensures that security risks to network and information systems relevant to essential function(s) are identified, analysed, prioritised, and managed.
- Your approach to risk is focused on the possibility of adverse impact to your essential function(s), leading to a detailed understanding of how such impact might arise as a consequence of possible attacker actions and the security properties of your network and information systems.
- Your risk assessments are based on a clearly understood set of threat assumptions, informed by an up-to-date understanding of security threats to your essential function(s) and your sector.
- Your risk assessments are informed by an understanding of the vulnerabilities in the network and information systems supporting your essential function(s).
- The output from your risk management process is a clear set of security requirements that will address the risks in line with your organisational approach to security.
- Significant conclusions reached in the course of your risk management process are communicated to key security decision-makers and accountable individuals.
- Your risk assessments are dynamic and updated in the light of relevant changes which may include technical changes to network and information systems, change of use and new threat information.
- The effectiveness of your risk management process is reviewed regularly, and improvements made as required.
- You anticipate technological developments that could be used to adversely impact network and information systems supporting your essential function(s).
Not achieved - At least one of the following statements is true:
- Risk assessments are not based on a clearly defined set of threat assumptions.
- Risk assessment outputs are too complex or unwieldy to be consumed by decision-makers and are not effectively communicated in a clear and timely manner.
- Risk assessments for network and information systems that support your essential function(s) are a "one-off" activity or not done at all.
- The security elements of projects or programmes are solely dependent on the completion of a risk management assessment without any regard to the outcomes.
- There is no systematic process in place to ensure that identified security risks are managed effectively.
- Systems are assessed in isolation, without consideration of dependencies and interactions with other systems. (e.g. interactions between IT and OT environments).
- Security requirements and mitigations are arbitrary or are applied from a control catalogue without consideration of how they contribute to the security of the essential function(s).
- Risks remain unresolved on a register for prolonged periods of time awaiting senior decision-making or resource allocation to resolve.
Partially achieved - All the following statements are true:
- Your organisational process ensures that security risks to network and information systems relevant to essential function(s) are identified, analysed, prioritised, and managed.
- Your risk assessments are informed by an understanding of the vulnerabilities in the network and information systems supporting your essential function(s).
- The output from your risk management process is a clear set of security requirements that will address the risks in line with your organisational approach to security.
- Significant conclusions reached in the course of your risk management process are communicated to key security decision-makers and accountable individuals.
- You conduct risk assessments when significant events potentially affect the essential function(s), such as replacing a system, introducing new or emergent technologies or a change in the cyber security threat.
Achieved - All the following statements are true:
- Your organisational process ensures that security risks to network and information systems relevant to essential function(s) are identified, analysed, prioritised, and managed.
- Your approach to risk is focused on the possibility of adverse impact to your essential function(s), leading to a detailed understanding of how such impact might arise as a consequence of possible attacker actions and the security properties of your network and information systems.
- Your risk assessments are based on a clearly understood set of threat assumptions, informed by an up-to-date understanding of security threats to your essential function(s) and your sector.
- Your risk assessments are informed by an understanding of the vulnerabilities in the network and information systems supporting your essential function(s).
- The output from your risk management process is a clear set of security requirements that will address the risks in line with your organisational approach to security.
- Significant conclusions reached in the course of your risk management process are communicated to key security decision-makers and accountable individuals.
- Your risk assessments are dynamic and updated in the light of relevant changes which may include technical changes to network and information systems, change of use and new threat information.
- The effectiveness of your risk management process is reviewed regularly, and improvements made as required.
- You anticipate technological developments that could be used to adversely impact network and information systems supporting your essential function(s).
A2.b Understanding Threat
- You understand the capabilities, methods and techniques of threat actors and what network and information systems they may compromise to adversely impact your essential function(s). This information is used to inform security and resilience risk management decisions, adjusting, enhancing or adding security measures to better defend against threats.
- You understand the capabilities, methods and techniques of threat actors and what network and information systems they may compromise to adversely impact your essential function(s). This information is used to inform security and resilience risk management decisions, adjusting, enhancing or adding security measures to better defend against threats.
- You are unable to perform threat analysis.
- You do not understand the threats to network and information systems supporting your essential function(s).
- You do not have a clearly defined set of threat assumptions.
- You do not use your understanding of threat to inform your risk management decisions.
- You perform threat analysis and understand how common threats apply to network and information systems supporting your essential function(s).
- You understand common types of cyber attacks, including the methods and techniques, and how these might apply to network and information systems supporting your essential function(s). This understanding is kept up to date.
- You anticipate what threat actors might target in network and information systems to cause an adverse impact to your essential function(s).
- Your understanding of threat is informed by common incidents.
- You apply your understanding of threat to inform your risk management decision-making.
- You perform detailed threat analysis and understand how this applies to network and information systems supporting your essential function(s), in the context of your sector and wider national infrastructure.
- Your detailed understanding of threat includes the methods and techniques available to capable and well-resourced threat actors and how they could be used systematically against network and information systems supporting your essential function(s).
- You use appropriate techniques to develop an understanding of network and information systems supporting your essential function(s) from a threat actor’s perspective. You anticipate probable attack methods and techniques, targets and objectives, and develop plausible scenarios.
- You understand the different steps a capable and well-resourced threat actor would need to take to reach the probable target(s).
- You identify and justify what measures can be used at each step to reduce the likelihood of the threat actor reaching the probable target(s) or achieving their objective(s).
- You maintain a detailed understanding of current threats (e.g. by threat intelligence and proactive research).
- You apply your detailed understanding of threat to inform your risk management decision-making.
- You have documented the steps required to undertake detailed threat analysis.
Not achieved - At least one of the following statements is true:
- You are unable to perform threat analysis.
- You do not understand the threats to network and information systems supporting your essential function(s).
- You do not have a clearly defined set of threat assumptions.
- You do not use your understanding of threat to inform your risk management decisions.
Partially achieved - All the following statements are true:
- You perform threat analysis and understand how common threats apply to network and information systems supporting your essential function(s).
- You understand common types of cyber attacks, including the methods and techniques, and how these might apply to network and information systems supporting your essential function(s). This understanding is kept up to date.
- You anticipate what threat actors might target in network and information systems to cause an adverse impact to your essential function(s).
- Your understanding of threat is informed by common incidents.
- You apply your understanding of threat to inform your risk management decision-making.
Achieved - All the following statements are true:
- You perform detailed threat analysis and understand how this applies to network and information systems supporting your essential function(s), in the context of your sector and wider national infrastructure.
- Your detailed understanding of threat includes the methods and techniques available to capable and well-resourced threat actors and how they could be used systematically against network and information systems supporting your essential function(s).
- You use appropriate techniques to develop an understanding of network and information systems supporting your essential function(s) from a threat actor’s perspective. You anticipate probable attack methods and techniques, targets and objectives, and develop plausible scenarios.
- You understand the different steps a capable and well-resourced threat actor would need to take to reach the probable target(s).
- You identify and justify what measures can be used at each step to reduce the likelihood of the threat actor reaching the probable target(s) or achieving their objective(s).
- You maintain a detailed understanding of current threats (e.g. by threat intelligence and proactive research).
- You apply your detailed understanding of threat to inform your risk management decision-making.
- You have documented the steps required to undertake detailed threat analysis.
A2.c Assurance
- You have gained confidence in the effectiveness of the security of your technology, people, and processes relevant to the operation of network and information systems supporting your essential function(s).
- You have gained confidence in the effectiveness of the security of your technology, people, and processes relevant to the operation of network and information systems supporting your essential function(s).
- A particular product or service is seen as a "silver bullet" and vendor claims are taken at face value.
- Assurance methods are applied without appreciation of their strengths and limitations, such as the risks of penetration testing in operational environments.
- Assurance is assumed because there have been no known problems to date.
- You validate that the security measures in place to protect the network and information systems are effective and remain effective for the lifetime over which they are needed.
- You understand the assurance methods available to you and choose appropriate methods to gain confidence in the security of essential function(s).
- Your confidence in the security as it relates to your technology, people, and processes can be justified to, and verified by, a third party.
- Security deficiencies uncovered by assurance activities are assessed, prioritised and remedied when necessary in a timely and effective way.
- The methods used for assurance are reviewed to ensure they are working as intended and remain the most appropriate method to use.
Not achieved - At least one of the following statements is true:
- A particular product or service is seen as a "silver bullet" and vendor claims are taken at face value.
- Assurance methods are applied without appreciation of their strengths and limitations, such as the risks of penetration testing in operational environments.
- Assurance is assumed because there have been no known problems to date.
Achieved - All the following statements are true:
- You validate that the security measures in place to protect the network and information systems are effective and remain effective for the lifetime over which they are needed.
- You understand the assurance methods available to you and choose appropriate methods to gain confidence in the security of essential function(s).
- Your confidence in the security as it relates to your technology, people, and processes can be justified to, and verified by, a third party.
- Security deficiencies uncovered by assurance activities are assessed, prioritised and remedied when necessary in a timely and effective way.
- The methods used for assurance are reviewed to ensure they are working as intended and remain the most appropriate method to use.
The organisation takes appropriate steps to identify, assess and understand security risks to network and information systems supporting the operation of essential functions. This includes an overall organisational approach to risk management.
Description
error determining description
Guidance
Our
Risk Management guidance
aims to help you to choose an approach that's right for your organisation. Organisations responsible for essential functions are likely to benefit from a combination of a
system-based approach
, which looks at the interactions between components of the function, and a
component-driven analysis
, which considers the threats, vulnerabilities, and impacts relevant to particular critical components.
Your organisation should choose a method or framework for managing risk that fits with the organisation's business and technology needs.
Whichever approach you choose, the scope of your programme must include all systems relevant to the operation of essential functions. Simply following the minimum requirements of a standard or applying blanket controls across the organisation is unlikely to adequately manage risks to critical systems.
Where industrial control and automation systems are in scope of the essential function, you should keep in mind that controls suitable for managing risks on the corporate IT network may be inappropriate or damaging in an operational technology environment. These systems will likely require a more tailored approach, and some frameworks and standards address specific concerns relating to such systems.
Cyber threats continue to evolve and develop, putting each organisation’s operational continuity and services at significant risk. By identifying and understanding cyber threats, and the steps a threat actor may take to compromise systems supporting essential functions, an organisation can implement effective security measures to counter malicious attacks and breaches. Various methods can be used to better understand threat which are discussed in our
Risk Management guidance
.
Ultimately, a detailed understanding of current cyber threats helps organisations to mitigate risks, ensuring the security and resilience of network and information systems in an increasingly hostile world.
Various means are available to gain confidence in the effectiveness of the security of technologies, processes and people. The NCSC Risk Management guidance discusses
how to gain and maintain assurance
in your risk treatments.
The NCSC assurance guidance provides some examples that may be useful to understand cyber security confidence in your organisation and there are some specific technical NCSC guides:
The
NCSC Penetration guidance
will help you understand the proper use and commissioning of penetration tests to gain assurance in the security of an IT system.
Our
Cloud Security collection
provides guidance on managing the risks involved with using cloud services, and some of the principles and guidance are more broadly applicable. The cloud guidance for having confidence in cyber security provides principles that are useful for assuring cyber security of essential functions. The collection will be of particular interest if your organisation hosts any part of your essential function infrastructure on a cloud service.
The
NCSC Penetration guidance
will help you understand the proper use and commissioning of penetration tests to gain assurance in the security of an IT system.
Contributing Outcomes
A2.a Risk Management Process
- Your organisation has effective internal processes for managing risks to the security and resilience of network and information systems related to the operation of your essential function(s) and communicating associated activities.
- Your organisation has effective internal processes for managing risks to the security and resilience of network and information systems related to the operation of your essential function(s) and communicating associated activities.
- Risk assessments are not based on a clearly defined set of threat assumptions.
- Risk assessment outputs are too complex or unwieldy to be consumed by decision-makers and are not effectively communicated in a clear and timely manner.
- Risk assessments for network and information systems that support your essential function(s) are a "one-off" activity or not done at all.
- The security elements of projects or programmes are solely dependent on the completion of a risk management assessment without any regard to the outcomes.
- There is no systematic process in place to ensure that identified security risks are managed effectively.
- Systems are assessed in isolation, without consideration of dependencies and interactions with other systems. (e.g. interactions between IT and OT environments).
- Security requirements and mitigations are arbitrary or are applied from a control catalogue without consideration of how they contribute to the security of the essential function(s).
- Risks remain unresolved on a register for prolonged periods of time awaiting senior decision-making or resource allocation to resolve.
- Your organisational process ensures that security risks to network and information systems relevant to essential function(s) are identified, analysed, prioritised, and managed.
- Your risk assessments are informed by an understanding of the vulnerabilities in the network and information systems supporting your essential function(s).
- The output from your risk management process is a clear set of security requirements that will address the risks in line with your organisational approach to security.
- Significant conclusions reached in the course of your risk management process are communicated to key security decision-makers and accountable individuals.
- You conduct risk assessments when significant events potentially affect the essential function(s), such as replacing a system, introducing new or emergent technologies or a change in the cyber security threat.
- Your organisational process ensures that security risks to network and information systems relevant to essential function(s) are identified, analysed, prioritised, and managed.
- Your approach to risk is focused on the possibility of adverse impact to your essential function(s), leading to a detailed understanding of how such impact might arise as a consequence of possible attacker actions and the security properties of your network and information systems.
- Your risk assessments are based on a clearly understood set of threat assumptions, informed by an up-to-date understanding of security threats to your essential function(s) and your sector.
- Your risk assessments are informed by an understanding of the vulnerabilities in the network and information systems supporting your essential function(s).
- The output from your risk management process is a clear set of security requirements that will address the risks in line with your organisational approach to security.
- Significant conclusions reached in the course of your risk management process are communicated to key security decision-makers and accountable individuals.
- Your risk assessments are dynamic and updated in the light of relevant changes which may include technical changes to network and information systems, change of use and new threat information.
- The effectiveness of your risk management process is reviewed regularly, and improvements made as required.
- You anticipate technological developments that could be used to adversely impact network and information systems supporting your essential function(s).
Not achieved - At least one of the following statements is true:
- Risk assessments are not based on a clearly defined set of threat assumptions.
- Risk assessment outputs are too complex or unwieldy to be consumed by decision-makers and are not effectively communicated in a clear and timely manner.
- Risk assessments for network and information systems that support your essential function(s) are a "one-off" activity or not done at all.
- The security elements of projects or programmes are solely dependent on the completion of a risk management assessment without any regard to the outcomes.
- There is no systematic process in place to ensure that identified security risks are managed effectively.
- Systems are assessed in isolation, without consideration of dependencies and interactions with other systems. (e.g. interactions between IT and OT environments).
- Security requirements and mitigations are arbitrary or are applied from a control catalogue without consideration of how they contribute to the security of the essential function(s).
- Risks remain unresolved on a register for prolonged periods of time awaiting senior decision-making or resource allocation to resolve.
Partially achieved - All the following statements are true:
- Your organisational process ensures that security risks to network and information systems relevant to essential function(s) are identified, analysed, prioritised, and managed.
- Your risk assessments are informed by an understanding of the vulnerabilities in the network and information systems supporting your essential function(s).
- The output from your risk management process is a clear set of security requirements that will address the risks in line with your organisational approach to security.
- Significant conclusions reached in the course of your risk management process are communicated to key security decision-makers and accountable individuals.
- You conduct risk assessments when significant events potentially affect the essential function(s), such as replacing a system, introducing new or emergent technologies or a change in the cyber security threat.
Achieved - All the following statements are true:
- Your organisational process ensures that security risks to network and information systems relevant to essential function(s) are identified, analysed, prioritised, and managed.
- Your approach to risk is focused on the possibility of adverse impact to your essential function(s), leading to a detailed understanding of how such impact might arise as a consequence of possible attacker actions and the security properties of your network and information systems.
- Your risk assessments are based on a clearly understood set of threat assumptions, informed by an up-to-date understanding of security threats to your essential function(s) and your sector.
- Your risk assessments are informed by an understanding of the vulnerabilities in the network and information systems supporting your essential function(s).
- The output from your risk management process is a clear set of security requirements that will address the risks in line with your organisational approach to security.
- Significant conclusions reached in the course of your risk management process are communicated to key security decision-makers and accountable individuals.
- Your risk assessments are dynamic and updated in the light of relevant changes which may include technical changes to network and information systems, change of use and new threat information.
- The effectiveness of your risk management process is reviewed regularly, and improvements made as required.
- You anticipate technological developments that could be used to adversely impact network and information systems supporting your essential function(s).
A2.b Understanding Threat
- You understand the capabilities, methods and techniques of threat actors and what network and information systems they may compromise to adversely impact your essential function(s). This information is used to inform security and resilience risk management decisions, adjusting, enhancing or adding security measures to better defend against threats.
- You understand the capabilities, methods and techniques of threat actors and what network and information systems they may compromise to adversely impact your essential function(s). This information is used to inform security and resilience risk management decisions, adjusting, enhancing or adding security measures to better defend against threats.
- You are unable to perform threat analysis.
- You do not understand the threats to network and information systems supporting your essential function(s).
- You do not have a clearly defined set of threat assumptions.
- You do not use your understanding of threat to inform your risk management decisions.
- You perform threat analysis and understand how common threats apply to network and information systems supporting your essential function(s).
- You understand common types of cyber attacks, including the methods and techniques, and how these might apply to network and information systems supporting your essential function(s). This understanding is kept up to date.
- You anticipate what threat actors might target in network and information systems to cause an adverse impact to your essential function(s).
- Your understanding of threat is informed by common incidents.
- You apply your understanding of threat to inform your risk management decision-making.
- You perform detailed threat analysis and understand how this applies to network and information systems supporting your essential function(s), in the context of your sector and wider national infrastructure.
- Your detailed understanding of threat includes the methods and techniques available to capable and well-resourced threat actors and how they could be used systematically against network and information systems supporting your essential function(s).
- You use appropriate techniques to develop an understanding of network and information systems supporting your essential function(s) from a threat actor’s perspective. You anticipate probable attack methods and techniques, targets and objectives, and develop plausible scenarios.
- You understand the different steps a capable and well-resourced threat actor would need to take to reach the probable target(s).
- You identify and justify what measures can be used at each step to reduce the likelihood of the threat actor reaching the probable target(s) or achieving their objective(s).
- You maintain a detailed understanding of current threats (e.g. by threat intelligence and proactive research).
- You apply your detailed understanding of threat to inform your risk management decision-making.
- You have documented the steps required to undertake detailed threat analysis.
Not achieved - At least one of the following statements is true:
- You are unable to perform threat analysis.
- You do not understand the threats to network and information systems supporting your essential function(s).
- You do not have a clearly defined set of threat assumptions.
- You do not use your understanding of threat to inform your risk management decisions.
Partially achieved - All the following statements are true:
- You perform threat analysis and understand how common threats apply to network and information systems supporting your essential function(s).
- You understand common types of cyber attacks, including the methods and techniques, and how these might apply to network and information systems supporting your essential function(s). This understanding is kept up to date.
- You anticipate what threat actors might target in network and information systems to cause an adverse impact to your essential function(s).
- Your understanding of threat is informed by common incidents.
- You apply your understanding of threat to inform your risk management decision-making.
Achieved - All the following statements are true:
- You perform detailed threat analysis and understand how this applies to network and information systems supporting your essential function(s), in the context of your sector and wider national infrastructure.
- Your detailed understanding of threat includes the methods and techniques available to capable and well-resourced threat actors and how they could be used systematically against network and information systems supporting your essential function(s).
- You use appropriate techniques to develop an understanding of network and information systems supporting your essential function(s) from a threat actor’s perspective. You anticipate probable attack methods and techniques, targets and objectives, and develop plausible scenarios.
- You understand the different steps a capable and well-resourced threat actor would need to take to reach the probable target(s).
- You identify and justify what measures can be used at each step to reduce the likelihood of the threat actor reaching the probable target(s) or achieving their objective(s).
- You maintain a detailed understanding of current threats (e.g. by threat intelligence and proactive research).
- You apply your detailed understanding of threat to inform your risk management decision-making.
- You have documented the steps required to undertake detailed threat analysis.
A2.c Assurance
- You have gained confidence in the effectiveness of the security of your technology, people, and processes relevant to the operation of network and information systems supporting your essential function(s).
- You have gained confidence in the effectiveness of the security of your technology, people, and processes relevant to the operation of network and information systems supporting your essential function(s).
- A particular product or service is seen as a "silver bullet" and vendor claims are taken at face value.
- Assurance methods are applied without appreciation of their strengths and limitations, such as the risks of penetration testing in operational environments.
- Assurance is assumed because there have been no known problems to date.
- You validate that the security measures in place to protect the network and information systems are effective and remain effective for the lifetime over which they are needed.
- You understand the assurance methods available to you and choose appropriate methods to gain confidence in the security of essential function(s).
- Your confidence in the security as it relates to your technology, people, and processes can be justified to, and verified by, a third party.
- Security deficiencies uncovered by assurance activities are assessed, prioritised and remedied when necessary in a timely and effective way.
- The methods used for assurance are reviewed to ensure they are working as intended and remain the most appropriate method to use.
Not achieved - At least one of the following statements is true:
- A particular product or service is seen as a "silver bullet" and vendor claims are taken at face value.
- Assurance methods are applied without appreciation of their strengths and limitations, such as the risks of penetration testing in operational environments.
- Assurance is assumed because there have been no known problems to date.
Achieved - All the following statements are true:
- You validate that the security measures in place to protect the network and information systems are effective and remain effective for the lifetime over which they are needed.
- You understand the assurance methods available to you and choose appropriate methods to gain confidence in the security of essential function(s).
- Your confidence in the security as it relates to your technology, people, and processes can be justified to, and verified by, a third party.
- Security deficiencies uncovered by assurance activities are assessed, prioritised and remedied when necessary in a timely and effective way.
- The methods used for assurance are reviewed to ensure they are working as intended and remain the most appropriate method to use.
Everything required to deliver, maintain or support networks and information systems necessary for the operation of essential functions is determined and understood. This includes data, people and systems, as well as any supporting infrastructure (such as power or cooling).
Description
error determining description
Guidance
Whichever risk management method your organisation uses, asset management will play a key role as you cannot effectively manage risks without understanding what assets are part of the essential function. Your asset management regime should consider all relevant assets, and dependencies between them. Dependencies may be identified between assets under your organisation's control (including IT and OT domains), elements of the supply chain (including power), and key staff who are critical to operations. Assets in an operational technology environment may need a more tailored approach than the corporate IT assets.
For asset management to be effective, up to date knowledge of your assets must be maintained throughout their lifecycle.
Asset management is part of an ISO 27001 Information Security Management System (ISMS), but management of critical assets may require a tailored approach.
If your organisation is using an ISMS as a tool for compliance with cyber regulation, you must ensure the scope includes all systems relevant to the operation of the essential function covered by the regulation. Asset management is a key part of an ISMS, although critical services may need more attention than the minimum requirements of the standard.
This standard aligns with ISO 27001 and can be used in conjunction with it or independent of it. It outlines requirements for a generic asset management system. An organisation following this standard as a tool for compliance with cyber regulation must ensure the scope encompasses all the relevant systems. The standard covers needs and expectations of stakeholders, which must include any requirements from regulators.
ITIL is an IT service management framework that outlines best practices for delivering IT services. It recommends a staged approach to IT Asset Management (ITAM). You may find this useful for improving management of your IT assets, but must keep in mind that there may be assets and dependencies beyond the corporate IT domain as outlined above.
Asset management is part of an ISO 27001 Information Security Management System (ISMS), but management of critical assets may require a tailored approach.
If your organisation is using an ISMS as a tool for compliance with cyber regulation, you must ensure the scope includes all systems relevant to the operation of the essential function covered by the regulation. Asset management is a key part of an ISMS, although critical services may need more attention than the minimum requirements of the standard.
Contributing Outcomes
A3.a Asset Management
- Inventories of assets relevant to the essential function(s) are incomplete, non-existent, or inadequately detailed.
- Only certain domains or types of asset are documented and understood. Dependencies between assets are not understood (such as the dependencies between IT and OT).
- Information assets, which could include personally identifiable information and / or important / critical data, are stored for long periods of time with no clear business need or retention policy.
- Knowledge critical to the management, operation, or recovery of the essential function(s) is held by one or two key individuals with no succession plan.
- Asset inventories are neglected and out of date.
- All assets relevant to the secure operation of essential function(s) are identified and inventoried (at a suitable level of detail). The inventory is kept up-to-date.
- Dependencies on supporting infrastructure (e.g. power, cooling etc) are recognised and recorded.
- You have prioritised your assets according to their importance to the operation of the essential function(s).
- You have assigned responsibility for managing all assets, including physical assets, relevant to the operation of the essential function(s).
- Assets relevant to the essential function(s) are managed with cyber security in mind throughout their lifecycle, from creation through to eventual decommissioning or disposal.
Not achieved - At least one of the following statements is true:
- Inventories of assets relevant to the essential function(s) are incomplete, non-existent, or inadequately detailed.
- Only certain domains or types of asset are documented and understood. Dependencies between assets are not understood (such as the dependencies between IT and OT).
- Information assets, which could include personally identifiable information and / or important / critical data, are stored for long periods of time with no clear business need or retention policy.
- Knowledge critical to the management, operation, or recovery of the essential function(s) is held by one or two key individuals with no succession plan.
- Asset inventories are neglected and out of date.
Achieved - All the following statements are true:
- All assets relevant to the secure operation of essential function(s) are identified and inventoried (at a suitable level of detail). The inventory is kept up-to-date.
- Dependencies on supporting infrastructure (e.g. power, cooling etc) are recognised and recorded.
- You have prioritised your assets according to their importance to the operation of the essential function(s).
- You have assigned responsibility for managing all assets, including physical assets, relevant to the operation of the essential function(s).
- Assets relevant to the essential function(s) are managed with cyber security in mind throughout their lifecycle, from creation through to eventual decommissioning or disposal.
Everything required to deliver, maintain or support networks and information systems necessary for the operation of essential functions is determined and understood. This includes data, people and systems, as well as any supporting infrastructure (such as power or cooling).
Description
error determining description
Guidance
Whichever risk management method your organisation uses, asset management will play a key role as you cannot effectively manage risks without understanding what assets are part of the essential function. Your asset management regime should consider all relevant assets, and dependencies between them. Dependencies may be identified between assets under your organisation's control (including IT and OT domains), elements of the supply chain (including power), and key staff who are critical to operations. Assets in an operational technology environment may need a more tailored approach than the corporate IT assets.
For asset management to be effective, up to date knowledge of your assets must be maintained throughout their lifecycle.
Asset management is part of an ISO 27001 Information Security Management System (ISMS), but management of critical assets may require a tailored approach.
If your organisation is using an ISMS as a tool for compliance with cyber regulation, you must ensure the scope includes all systems relevant to the operation of the essential function covered by the regulation. Asset management is a key part of an ISMS, although critical services may need more attention than the minimum requirements of the standard.
This standard aligns with ISO 27001 and can be used in conjunction with it or independent of it. It outlines requirements for a generic asset management system. An organisation following this standard as a tool for compliance with cyber regulation must ensure the scope encompasses all the relevant systems. The standard covers needs and expectations of stakeholders, which must include any requirements from regulators.
ITIL is an IT service management framework that outlines best practices for delivering IT services. It recommends a staged approach to IT Asset Management (ITAM). You may find this useful for improving management of your IT assets, but must keep in mind that there may be assets and dependencies beyond the corporate IT domain as outlined above.
Asset management is part of an ISO 27001 Information Security Management System (ISMS), but management of critical assets may require a tailored approach.
If your organisation is using an ISMS as a tool for compliance with cyber regulation, you must ensure the scope includes all systems relevant to the operation of the essential function covered by the regulation. Asset management is a key part of an ISMS, although critical services may need more attention than the minimum requirements of the standard.
Contributing Outcomes
A3.a Asset Management
- Inventories of assets relevant to the essential function(s) are incomplete, non-existent, or inadequately detailed.
- Only certain domains or types of asset are documented and understood. Dependencies between assets are not understood (such as the dependencies between IT and OT).
- Information assets, which could include personally identifiable information and / or important / critical data, are stored for long periods of time with no clear business need or retention policy.
- Knowledge critical to the management, operation, or recovery of the essential function(s) is held by one or two key individuals with no succession plan.
- Asset inventories are neglected and out of date.
- All assets relevant to the secure operation of essential function(s) are identified and inventoried (at a suitable level of detail). The inventory is kept up-to-date.
- Dependencies on supporting infrastructure (e.g. power, cooling etc) are recognised and recorded.
- You have prioritised your assets according to their importance to the operation of the essential function(s).
- You have assigned responsibility for managing all assets, including physical assets, relevant to the operation of the essential function(s).
- Assets relevant to the essential function(s) are managed with cyber security in mind throughout their lifecycle, from creation through to eventual decommissioning or disposal.
Not achieved - At least one of the following statements is true:
- Inventories of assets relevant to the essential function(s) are incomplete, non-existent, or inadequately detailed.
- Only certain domains or types of asset are documented and understood. Dependencies between assets are not understood (such as the dependencies between IT and OT).
- Information assets, which could include personally identifiable information and / or important / critical data, are stored for long periods of time with no clear business need or retention policy.
- Knowledge critical to the management, operation, or recovery of the essential function(s) is held by one or two key individuals with no succession plan.
- Asset inventories are neglected and out of date.
Achieved - All the following statements are true:
- All assets relevant to the secure operation of essential function(s) are identified and inventoried (at a suitable level of detail). The inventory is kept up-to-date.
- Dependencies on supporting infrastructure (e.g. power, cooling etc) are recognised and recorded.
- You have prioritised your assets according to their importance to the operation of the essential function(s).
- You have assigned responsibility for managing all assets, including physical assets, relevant to the operation of the essential function(s).
- Assets relevant to the essential function(s) are managed with cyber security in mind throughout their lifecycle, from creation through to eventual decommissioning or disposal.
The organisation understands and manages security risks to networks and information systems supporting the operation of essential functions that arise as a result of dependencies on suppliers. This includes ensuring that appropriate measures are employed where third party services are used.
Description
error determining description
Guidance
Organisations responsible for essential functions need to ensure that when third party suppliers are used, all relevant security requirements are met. This means that a number of specific supply chain related security considerations should be addressed where relevant to the provision of the essential function. This might include:
Ensuring the protection of data shared with a third party. This includes protecting data from actions such as unauthorised access, modification, or deletion that may cause an adverse impact on any essential functions (see
Principle B3
).
Effective specification of the security properties of products or services procured from an external third party, or sourced internally from another part of the organisation, that are important for the protection of the essential function. This should include the security requirements derived from the rest of these Principles.
Ensure that any network connections or data sharing with third parties do not introduce unmanaged vulnerabilities that have the potential to affect the security of the essential function.
Confidence that third party suppliers are trustworthy such that malicious attempts to subvert the security of products or systems that could affect the essential function are managed.
Ensuring the protection of data shared with a third party. This includes protecting data from actions such as unauthorised access, modification, or deletion that may cause an adverse impact on any essential functions (see
Principle B3
).
Contributing Outcomes
A4.a Supply Chain
- You understand and effectively manage the risks associated with suppliers to the security of network and information systems supporting the operation of your essential function(s).
- You understand and effectively manage the risks associated with suppliers to the security of network and information systems supporting the operation of your essential function(s).
- You do not know what data belonging to you is held by suppliers, or how it is managed.
- Elements of the supply chain for essential function(s) are subcontracted and you have little or no visibility of the sub-contractors.
- You have no understanding of which contracts are relevant and / or relevant contracts do not specify appropriate security obligations.
- Suppliers have access to systems that provide your essential function(s) that is unrestricted, not monitored or bypasses your own security controls.
- You understand the general risks suppliers may pose to your essential function(s).
- You know the extent of your supply chain that supports your essential function(s), including sub-contractors.
- Suppliers to network and information systems that support your essential function(s) can demonstrate appropriate and proportionate levels of cyber security within the context of common threats.
- You understand which contracts are relevant and you include appropriate security obligations in relevant contracts.
- You are aware of all third-party connections and have assurance that they meet your organisation’s security requirements.
- Your approach to security incident management considers incidents that might arise in your supply chain.
- You have confidence that information shared with suppliers that is necessary for the operation of your essential function(s) is appropriately protected from common threats.
- You have a deep understanding of your supply chain, including sub-contractors and the wider risks it faces.
- You consider factors such as your supplier’s ownership, nationality, partnerships, competitors, other organisations with which they sub-contract and their approach to cyber security. These factors inform your risk assessment and are fully considered in your procurement lifecycle processes and purchasing decisions.
- Your approach to supply chain risk management considers the risks to network and information systems supporting your essential function(s) arising from supply chain subversion by capable and well-resourced threat actors.
- Critical suppliers to network and information systems supporting your essential functions(s) can demonstrate appropriate and proportionate levels of cyber security within the context of capable and well-resourced threat actors.
- You have confidence that information held by suppliers that is essential to the operation of network and information systems supporting your essential function(s) is appropriately protected from capable and well-resourced threat actors.
- You understand which contracts are relevant and you include appropriate security obligations, in relevant contracts.
- You have a proactive approach to contract management which may include a contract management plan for relevant contracts.
- Customer / supplier ownership of responsibilities is defined in contracts.
- All network connections and data sharing with third parties are managed effectively and proportionately.
- When appropriate, your incident management process and that of your suppliers provide mutual support in the resolution of incidents.
Not achieved - At least one of the following statements is true:
- You do not know what data belonging to you is held by suppliers, or how it is managed.
- Elements of the supply chain for essential function(s) are subcontracted and you have little or no visibility of the sub-contractors.
- You have no understanding of which contracts are relevant and / or relevant contracts do not specify appropriate security obligations.
- Suppliers have access to systems that provide your essential function(s) that is unrestricted, not monitored or bypasses your own security controls.
Partially achieved - All the following statements are true:
- You understand the general risks suppliers may pose to your essential function(s).
- You know the extent of your supply chain that supports your essential function(s), including sub-contractors.
- Suppliers to network and information systems that support your essential function(s) can demonstrate appropriate and proportionate levels of cyber security within the context of common threats.
- You understand which contracts are relevant and you include appropriate security obligations in relevant contracts.
- You are aware of all third-party connections and have assurance that they meet your organisation’s security requirements.
- Your approach to security incident management considers incidents that might arise in your supply chain.
- You have confidence that information shared with suppliers that is necessary for the operation of your essential function(s) is appropriately protected from common threats.
Achieved - All the following statements are true:
- You have a deep understanding of your supply chain, including sub-contractors and the wider risks it faces.
- You consider factors such as your supplier’s ownership, nationality, partnerships, competitors, other organisations with which they sub-contract and their approach to cyber security. These factors inform your risk assessment and are fully considered in your procurement lifecycle processes and purchasing decisions.
- Your approach to supply chain risk management considers the risks to network and information systems supporting your essential function(s) arising from supply chain subversion by capable and well-resourced threat actors.
- Critical suppliers to network and information systems supporting your essential functions(s) can demonstrate appropriate and proportionate levels of cyber security within the context of capable and well-resourced threat actors.
- You have confidence that information held by suppliers that is essential to the operation of network and information systems supporting your essential function(s) is appropriately protected from capable and well-resourced threat actors.
- You understand which contracts are relevant and you include appropriate security obligations, in relevant contracts.
- You have a proactive approach to contract management which may include a contract management plan for relevant contracts.
- Customer / supplier ownership of responsibilities is defined in contracts.
- All network connections and data sharing with third parties are managed effectively and proportionately.
- When appropriate, your incident management process and that of your suppliers provide mutual support in the resolution of incidents.
A4.b Secure Software Development and Support
- You actively maximise the use of secure and supported software, whether developed internally or sourced externally, within network and information systems supporting the operation of your essential function(s).
- You actively maximise the use of secure and supported software, whether developed internally or sourced externally, within network and information systems supporting the operation of your essential function(s).
- Your software supplier(s) is unaware of the composition and provenance of software provided to you.
- Software, including updates and patches, undergoes little to no testing.
- Updates and patches often introduce new problems or fail to address existing issues.
- Vulnerabilities are discovered in software despite the negligible difficulty of implementing mitigations.
- Your software supplier leverages secure development principles and practices.
- Your software supplier(s) can demonstrate a limited understanding of the composition and provenance of software provided to you.
- You consider the security of environments (e.g. development, test and production), including source code and repositories, used in the production of software to be appropriate and proportionate within the context of common threats.
- The testing regime uses a range of different approaches (e.g. static and dynamic analysis, unit and integration testing and point in time assessments) that verify all aspects of the development lifecycle covering both functional and non-functional testing.
- You have arrangements in place with your software supplier to receive timely security updates, patches and notifications.
- Software, including updates and patches, is obtained from your supplier(s) via secure channels.
- Your software supplier(s) has processes in place to identify, report and mitigate security vulnerabilities.
- You have arrangements in place with your software supplier to be notified of any significant events that may adversely impact network and information systems supporting your essential function(s).
- If open-source software is used, you have taken appropriate and proportionate steps to establish and maintain sufficient confidence in its security for its use.
- You have appropriate support and maintenance arrangements in place.
- Your software supplier(s) leverages an established secure software development framework (e.g. NIST Secure Software Development Framework (SSDF), Microsoft Secure Development Lifecycle (SDL)).
- Your software supplier can demonstrate a thorough understanding of the composition and provenance of software provided to you, including any third-party components used in the development of that software, and those components are being monitored for new vulnerabilities throughout the lifespan of the product.
- You consider the security of environments (e.g. development, test, and production), including source code and repositories, used in the production of software to be appropriate and proportionate within the context of capable and well-resourced threat actors.
- The software development lifecycle is informed by a detailed and up to date understanding of threat and applies appropriate techniques, such as threat modelling, to identify and assess potential vulnerabilities and attack vectors.
- You can attest to the authenticity and integrity of software, including updates and patches.
Not achieved - At least one of the following statements is true:
- Your software supplier(s) is unaware of the composition and provenance of software provided to you.
- Software, including updates and patches, undergoes little to no testing.
- Updates and patches often introduce new problems or fail to address existing issues.
- Vulnerabilities are discovered in software despite the negligible difficulty of implementing mitigations.
Partially achieved - All the following statements are true:
- Your software supplier leverages secure development principles and practices.
- Your software supplier(s) can demonstrate a limited understanding of the composition and provenance of software provided to you.
- You consider the security of environments (e.g. development, test and production), including source code and repositories, used in the production of software to be appropriate and proportionate within the context of common threats.
- The testing regime uses a range of different approaches (e.g. static and dynamic analysis, unit and integration testing and point in time assessments) that verify all aspects of the development lifecycle covering both functional and non-functional testing.
- You have arrangements in place with your software supplier to receive timely security updates, patches and notifications.
- Software, including updates and patches, is obtained from your supplier(s) via secure channels.
- Your software supplier(s) has processes in place to identify, report and mitigate security vulnerabilities.
- You have arrangements in place with your software supplier to be notified of any significant events that may adversely impact network and information systems supporting your essential function(s).
- If open-source software is used, you have taken appropriate and proportionate steps to establish and maintain sufficient confidence in its security for its use.
- You have appropriate support and maintenance arrangements in place.
Achieved - All the following statements are true:
- Your software supplier(s) leverages an established secure software development framework (e.g. NIST Secure Software Development Framework (SSDF), Microsoft Secure Development Lifecycle (SDL)).
- Your software supplier can demonstrate a thorough understanding of the composition and provenance of software provided to you, including any third-party components used in the development of that software, and those components are being monitored for new vulnerabilities throughout the lifespan of the product.
- You consider the security of environments (e.g. development, test, and production), including source code and repositories, used in the production of software to be appropriate and proportionate within the context of capable and well-resourced threat actors.
- The software development lifecycle is informed by a detailed and up to date understanding of threat and applies appropriate techniques, such as threat modelling, to identify and assess potential vulnerabilities and attack vectors.
- You can attest to the authenticity and integrity of software, including updates and patches.
The organisation understands and manages security risks to networks and information systems supporting the operation of essential functions that arise as a result of dependencies on suppliers. This includes ensuring that appropriate measures are employed where third party services are used.
Description
error determining description
Guidance
Organisations responsible for essential functions need to ensure that when third party suppliers are used, all relevant security requirements are met. This means that a number of specific supply chain related security considerations should be addressed where relevant to the provision of the essential function. This might include:
Ensuring the protection of data shared with a third party. This includes protecting data from actions such as unauthorised access, modification, or deletion that may cause an adverse impact on any essential functions (see
Principle B3
).
Effective specification of the security properties of products or services procured from an external third party, or sourced internally from another part of the organisation, that are important for the protection of the essential function. This should include the security requirements derived from the rest of these Principles.
Ensure that any network connections or data sharing with third parties do not introduce unmanaged vulnerabilities that have the potential to affect the security of the essential function.
Confidence that third party suppliers are trustworthy such that malicious attempts to subvert the security of products or systems that could affect the essential function are managed.
Ensuring the protection of data shared with a third party. This includes protecting data from actions such as unauthorised access, modification, or deletion that may cause an adverse impact on any essential functions (see
Principle B3
).
Contributing Outcomes
A4.a Supply Chain
- You understand and effectively manage the risks associated with suppliers to the security of network and information systems supporting the operation of your essential function(s).
- You understand and effectively manage the risks associated with suppliers to the security of network and information systems supporting the operation of your essential function(s).
- You do not know what data belonging to you is held by suppliers, or how it is managed.
- Elements of the supply chain for essential function(s) are subcontracted and you have little or no visibility of the sub-contractors.
- You have no understanding of which contracts are relevant and / or relevant contracts do not specify appropriate security obligations.
- Suppliers have access to systems that provide your essential function(s) that is unrestricted, not monitored or bypasses your own security controls.
- You understand the general risks suppliers may pose to your essential function(s).
- You know the extent of your supply chain that supports your essential function(s), including sub-contractors.
- Suppliers to network and information systems that support your essential function(s) can demonstrate appropriate and proportionate levels of cyber security within the context of common threats.
- You understand which contracts are relevant and you include appropriate security obligations in relevant contracts.
- You are aware of all third-party connections and have assurance that they meet your organisation’s security requirements.
- Your approach to security incident management considers incidents that might arise in your supply chain.
- You have confidence that information shared with suppliers that is necessary for the operation of your essential function(s) is appropriately protected from common threats.
- You have a deep understanding of your supply chain, including sub-contractors and the wider risks it faces.
- You consider factors such as your supplier’s ownership, nationality, partnerships, competitors, other organisations with which they sub-contract and their approach to cyber security. These factors inform your risk assessment and are fully considered in your procurement lifecycle processes and purchasing decisions.
- Your approach to supply chain risk management considers the risks to network and information systems supporting your essential function(s) arising from supply chain subversion by capable and well-resourced threat actors.
- Critical suppliers to network and information systems supporting your essential functions(s) can demonstrate appropriate and proportionate levels of cyber security within the context of capable and well-resourced threat actors.
- You have confidence that information held by suppliers that is essential to the operation of network and information systems supporting your essential function(s) is appropriately protected from capable and well-resourced threat actors.
- You understand which contracts are relevant and you include appropriate security obligations, in relevant contracts.
- You have a proactive approach to contract management which may include a contract management plan for relevant contracts.
- Customer / supplier ownership of responsibilities is defined in contracts.
- All network connections and data sharing with third parties are managed effectively and proportionately.
- When appropriate, your incident management process and that of your suppliers provide mutual support in the resolution of incidents.
Not achieved - At least one of the following statements is true:
- You do not know what data belonging to you is held by suppliers, or how it is managed.
- Elements of the supply chain for essential function(s) are subcontracted and you have little or no visibility of the sub-contractors.
- You have no understanding of which contracts are relevant and / or relevant contracts do not specify appropriate security obligations.
- Suppliers have access to systems that provide your essential function(s) that is unrestricted, not monitored or bypasses your own security controls.
Partially achieved - All the following statements are true:
- You understand the general risks suppliers may pose to your essential function(s).
- You know the extent of your supply chain that supports your essential function(s), including sub-contractors.
- Suppliers to network and information systems that support your essential function(s) can demonstrate appropriate and proportionate levels of cyber security within the context of common threats.
- You understand which contracts are relevant and you include appropriate security obligations in relevant contracts.
- You are aware of all third-party connections and have assurance that they meet your organisation’s security requirements.
- Your approach to security incident management considers incidents that might arise in your supply chain.
- You have confidence that information shared with suppliers that is necessary for the operation of your essential function(s) is appropriately protected from common threats.
Achieved - All the following statements are true:
- You have a deep understanding of your supply chain, including sub-contractors and the wider risks it faces.
- You consider factors such as your supplier’s ownership, nationality, partnerships, competitors, other organisations with which they sub-contract and their approach to cyber security. These factors inform your risk assessment and are fully considered in your procurement lifecycle processes and purchasing decisions.
- Your approach to supply chain risk management considers the risks to network and information systems supporting your essential function(s) arising from supply chain subversion by capable and well-resourced threat actors.
- Critical suppliers to network and information systems supporting your essential functions(s) can demonstrate appropriate and proportionate levels of cyber security within the context of capable and well-resourced threat actors.
- You have confidence that information held by suppliers that is essential to the operation of network and information systems supporting your essential function(s) is appropriately protected from capable and well-resourced threat actors.
- You understand which contracts are relevant and you include appropriate security obligations, in relevant contracts.
- You have a proactive approach to contract management which may include a contract management plan for relevant contracts.
- Customer / supplier ownership of responsibilities is defined in contracts.
- All network connections and data sharing with third parties are managed effectively and proportionately.
- When appropriate, your incident management process and that of your suppliers provide mutual support in the resolution of incidents.
A4.b Secure Software Development and Support
- You actively maximise the use of secure and supported software, whether developed internally or sourced externally, within network and information systems supporting the operation of your essential function(s).
- You actively maximise the use of secure and supported software, whether developed internally or sourced externally, within network and information systems supporting the operation of your essential function(s).
- Your software supplier(s) is unaware of the composition and provenance of software provided to you.
- Software, including updates and patches, undergoes little to no testing.
- Updates and patches often introduce new problems or fail to address existing issues.
- Vulnerabilities are discovered in software despite the negligible difficulty of implementing mitigations.
- Your software supplier leverages secure development principles and practices.
- Your software supplier(s) can demonstrate a limited understanding of the composition and provenance of software provided to you.
- You consider the security of environments (e.g. development, test and production), including source code and repositories, used in the production of software to be appropriate and proportionate within the context of common threats.
- The testing regime uses a range of different approaches (e.g. static and dynamic analysis, unit and integration testing and point in time assessments) that verify all aspects of the development lifecycle covering both functional and non-functional testing.
- You have arrangements in place with your software supplier to receive timely security updates, patches and notifications.
- Software, including updates and patches, is obtained from your supplier(s) via secure channels.
- Your software supplier(s) has processes in place to identify, report and mitigate security vulnerabilities.
- You have arrangements in place with your software supplier to be notified of any significant events that may adversely impact network and information systems supporting your essential function(s).
- If open-source software is used, you have taken appropriate and proportionate steps to establish and maintain sufficient confidence in its security for its use.
- You have appropriate support and maintenance arrangements in place.
- Your software supplier(s) leverages an established secure software development framework (e.g. NIST Secure Software Development Framework (SSDF), Microsoft Secure Development Lifecycle (SDL)).
- Your software supplier can demonstrate a thorough understanding of the composition and provenance of software provided to you, including any third-party components used in the development of that software, and those components are being monitored for new vulnerabilities throughout the lifespan of the product.
- You consider the security of environments (e.g. development, test, and production), including source code and repositories, used in the production of software to be appropriate and proportionate within the context of capable and well-resourced threat actors.
- The software development lifecycle is informed by a detailed and up to date understanding of threat and applies appropriate techniques, such as threat modelling, to identify and assess potential vulnerabilities and attack vectors.
- You can attest to the authenticity and integrity of software, including updates and patches.
Not achieved - At least one of the following statements is true:
- Your software supplier(s) is unaware of the composition and provenance of software provided to you.
- Software, including updates and patches, undergoes little to no testing.
- Updates and patches often introduce new problems or fail to address existing issues.
- Vulnerabilities are discovered in software despite the negligible difficulty of implementing mitigations.
Partially achieved - All the following statements are true:
- Your software supplier leverages secure development principles and practices.
- Your software supplier(s) can demonstrate a limited understanding of the composition and provenance of software provided to you.
- You consider the security of environments (e.g. development, test and production), including source code and repositories, used in the production of software to be appropriate and proportionate within the context of common threats.
- The testing regime uses a range of different approaches (e.g. static and dynamic analysis, unit and integration testing and point in time assessments) that verify all aspects of the development lifecycle covering both functional and non-functional testing.
- You have arrangements in place with your software supplier to receive timely security updates, patches and notifications.
- Software, including updates and patches, is obtained from your supplier(s) via secure channels.
- Your software supplier(s) has processes in place to identify, report and mitigate security vulnerabilities.
- You have arrangements in place with your software supplier to be notified of any significant events that may adversely impact network and information systems supporting your essential function(s).
- If open-source software is used, you have taken appropriate and proportionate steps to establish and maintain sufficient confidence in its security for its use.
- You have appropriate support and maintenance arrangements in place.
Achieved - All the following statements are true:
- Your software supplier(s) leverages an established secure software development framework (e.g. NIST Secure Software Development Framework (SSDF), Microsoft Secure Development Lifecycle (SDL)).
- Your software supplier can demonstrate a thorough understanding of the composition and provenance of software provided to you, including any third-party components used in the development of that software, and those components are being monitored for new vulnerabilities throughout the lifespan of the product.
- You consider the security of environments (e.g. development, test, and production), including source code and repositories, used in the production of software to be appropriate and proportionate within the context of capable and well-resourced threat actors.
- The software development lifecycle is informed by a detailed and up to date understanding of threat and applies appropriate techniques, such as threat modelling, to identify and assess potential vulnerabilities and attack vectors.
- You can attest to the authenticity and integrity of software, including updates and patches.
The organisation defines, implements, communicates and enforces appropriate policies, processes and procedures that direct its overall approach to securing systems and data that support the operation of essential functions.
Description
error determining description
Guidance
The policies, processes and procedures needed by an organisation depend upon its function and should integrate with the organisation’s approach to governance and risk management. Organisations responsible for essential functions should have a range of policies, processes and procedures, including:
An organisational security or service protection policy: endorsed by senior management, this high-level policy should include the organisation’s overarching approach to governing security and managing risks, the organisation’s aims and intents for security and what is of key concern.
Supporting policies, processes and procedures: contextual lower-level definitions controlling, directing and communicating organisational security practice.
Compliance policies and processes for sector regulations, standards, etc.: specific policies and processes appropriate to the compliance regime; these may be defined by the regulation, standard, etc. For example, to comply with ISO/IEC 27001, organisations should have in place certain security policies and procedures relevant to what the organisation does, how it does it, and what their ISO/IEC 27001 information security management system covers (see ISO/IEC 27002 for detail).
An organisational security or service protection policy: endorsed by senior management, this high-level policy should include the organisation’s overarching approach to governing security and managing risks, the organisation’s aims and intents for security and what is of key concern.
Contributing Outcomes
B1.a Policy, Process and Procedure Development
- You have developed and continue to improve a set of cyber security and resilience policies, processes and procedures that manage and mitigate the risk of adverse impact on your essential function(s).
- You have developed and continue to improve a set of cyber security and resilience policies, processes and procedures that manage and mitigate the risk of adverse impact on your essential function(s).
- Your policies, processes and procedures are absent or incomplete.
- Policies, processes and procedures are not applied universally or consistently.
- People often or routinely circumvent policies, processes and procedures to achieve business objectives.
- Your organisation’s security governance and risk management approach has no bearing on your policies, processes and procedures.
- System security is totally reliant on users' careful and consistent application of manual security processes.
- Policies, processes and procedures have not been reviewed in response to major changes (e.g. technology or regulatory framework), or within a suitable period.
- Policies, processes and procedures are not readily available to staff, too detailed to remember, or too hard to understand.
- Your policies, processes and procedures document your overarching security governance and risk management approach, technical security practice and specific regulatory compliance.
- You review and update policies, processes and procedures in response to major cyber security incidents.
- You fully document your overarching security governance and risk management approach, technical security practice and specific regulatory compliance.
- Cyber security is integrated and embedded throughout policies, processes and procedures and key performance indicators are reported to your executive management.
- Your organisation’s policies, processes and procedures are developed to be practical, usable and appropriate to mitigate the risk of adverse impact to network and information systems supporting your essential function(s).
- Policies, processes and procedures that rely on user behaviour are practical, appropriate and achievable.
- You review and update policies, processes and procedures at suitably regular intervals to ensure they remain relevant. This is in addition to reviews following a major cyber security incident.
- Any changes to the essential function(s) or the threat it faces triggers a review of policies, processes and procedures.
- Your systems are designed so that they remain secure even when user security policies, processes and procedures are not always followed.
Not achieved - At least one of the following statements is true:
- Your policies, processes and procedures are absent or incomplete.
- Policies, processes and procedures are not applied universally or consistently.
- People often or routinely circumvent policies, processes and procedures to achieve business objectives.
- Your organisation’s security governance and risk management approach has no bearing on your policies, processes and procedures.
- System security is totally reliant on users' careful and consistent application of manual security processes.
- Policies, processes and procedures have not been reviewed in response to major changes (e.g. technology or regulatory framework), or within a suitable period.
- Policies, processes and procedures are not readily available to staff, too detailed to remember, or too hard to understand.
Partially achieved - All the following statements are true:
- Your policies, processes and procedures document your overarching security governance and risk management approach, technical security practice and specific regulatory compliance.
- You review and update policies, processes and procedures in response to major cyber security incidents.
Achieved - All the following statements are true:
- You fully document your overarching security governance and risk management approach, technical security practice and specific regulatory compliance.
- Cyber security is integrated and embedded throughout policies, processes and procedures and key performance indicators are reported to your executive management.
- Your organisation’s policies, processes and procedures are developed to be practical, usable and appropriate to mitigate the risk of adverse impact to network and information systems supporting your essential function(s).
- Policies, processes and procedures that rely on user behaviour are practical, appropriate and achievable.
- You review and update policies, processes and procedures at suitably regular intervals to ensure they remain relevant. This is in addition to reviews following a major cyber security incident.
- Any changes to the essential function(s) or the threat it faces triggers a review of policies, processes and procedures.
- Your systems are designed so that they remain secure even when user security policies, processes and procedures are not always followed.
B1.b Policy, Process and Procedure Implementation
- You have successfully implemented your security policies, processes and procedures and can demonstrate the security benefits achieved.
- You have successfully implemented your security policies, processes and procedures and can demonstrate the security benefits achieved.
- Policies, processes and procedures are ignored or only partially followed.
- How your policies support the resilience of your essential function(s) is not well understood.
- Staff are unaware of their responsibilities under your policies, processes and procedures.
- You do not attempt to detect breaches of policies, processes and procedures.
- Policies, processes and procedures lack integration with other organisational policies, processes and procedures.
- Your policies, processes and procedures are not well communicated across your organisation.
- Most of your policies, processes and procedures are followed and their application is monitored.
- Your policies, processes and procedures are integrated with other organisational policies, processes and procedures, including HR assessments of individuals' trustworthiness.
- All staff are aware of their responsibilities under your policies, processes and procedures.
- All breaches of policies, processes and procedures with the potential to adversely impact the essential function(s) are fully investigated. Other breaches are tracked, assessed for trends and action is taken to understand and address.
- All your policies, processes and procedures are followed, their correct application and security effectiveness is evaluated.
- Your policies, processes and procedures are integrated with other organisational policies, processes and procedures, including HR assessments of individuals' trustworthiness.
- Your policies, processes and procedures are effectively and appropriately communicated across all levels of the organisation resulting in good staff awareness of their responsibilities.
- Appropriate action is taken to address all breaches of policies, processes and procedures with potential to adversely impact the essential function(s) including aggregated breaches.
Not achieved - At least one of the following statements is true:
- Policies, processes and procedures are ignored or only partially followed.
- How your policies support the resilience of your essential function(s) is not well understood.
- Staff are unaware of their responsibilities under your policies, processes and procedures.
- You do not attempt to detect breaches of policies, processes and procedures.
- Policies, processes and procedures lack integration with other organisational policies, processes and procedures.
- Your policies, processes and procedures are not well communicated across your organisation.
Partially achieved - All the following statements are true:
- Most of your policies, processes and procedures are followed and their application is monitored.
- Your policies, processes and procedures are integrated with other organisational policies, processes and procedures, including HR assessments of individuals' trustworthiness.
- All staff are aware of their responsibilities under your policies, processes and procedures.
- All breaches of policies, processes and procedures with the potential to adversely impact the essential function(s) are fully investigated. Other breaches are tracked, assessed for trends and action is taken to understand and address.
Achieved - All the following statements are true:
- All your policies, processes and procedures are followed, their correct application and security effectiveness is evaluated.
- Your policies, processes and procedures are integrated with other organisational policies, processes and procedures, including HR assessments of individuals' trustworthiness.
- Your policies, processes and procedures are effectively and appropriately communicated across all levels of the organisation resulting in good staff awareness of their responsibilities.
- Appropriate action is taken to address all breaches of policies, processes and procedures with potential to adversely impact the essential function(s) including aggregated breaches.
The organisation understands, documents and manages access to networks and information systems and supporting the operation of essential functions. Users (or automated functions) that can access data or services are appropriately verified, authenticated and authorised.
Description
It is important that the organisation is clear about who (or what in the case of automated functions) has authorisation to interact with the network and information systems supporting an essential function in any way or access associated sensitive data. Access rights granted should be carefully controlled, especially where those rights provide an ability to materially affect the operation of the essential function. Access rights granted should be periodically reviewed and technically removed when no longer required such as when an individual changes role or leaves the organisation.
Users, devices and systems should be appropriately verified, authenticated and authorised before access to data or services is granted. Verification of a user’s identity (they are who they say they are) is a prerequisite for issuing credentials, authentication and access management. For highly privileged access it might be appropriate to include approaches such as multi-factor or hardware authentication.
Unauthorised individuals should be prevented from accessing data or services at all points within the system. This includes system users without the appropriate permissions, unauthorised individuals attempting to interact with any online service or individuals with unauthorised access to user devices (for example if a user device were lost or stolen).
Guidance
The
Introduction to identity and access management
sets out security fundamentals that operators should consider in designing and managing identity and access management systems. Identity and access control should be robust enough that essential functions are not adversely affected by unauthorised access.
In addition to technical security, organisations should protect physical access to networks and information systems supporting the essential function, to prevent unauthorised access, tampering or data deletion. Some organisations may already have physical security measures in place to comply with non-cyber regulatory frameworks. See
NPSA guidance on Control Access
for further information.
Contributing Outcomes
B2.a Identity Verification, Authentication and Authorisation
- You robustly verify, authenticate and authorise access to the network and information systems supporting your essential function(s).
- You robustly verify, authenticate and authorise access to the network and information systems supporting your essential function(s).
- Initial identity verification is not robust enough to provide an acceptable level of confidence of a user’s identity profile.
- Authorised users and systems with access to networks or information systems on which your essential function(s) depends cannot be individually identified.
- Unauthorised individuals or devices can access your network or information systems on which your essential function(s) depends.
- The number of authorised users and systems that have access to your network and information systems are not limited to the minimum necessary.
- Your approach to authenticating users, devices and systems does not follow up to date best practice.
- Your process of initial identity verification is robust enough to provide a reasonable level of confidence of a user’s identity profile before allowing an authorised user access to network and information systems that support your essential function(s).
- All authorised users and systems with access to network or information systems on which your essential function(s) depends are individually identified and authenticated.
- The number of authorised users and systems that have access to essential function(s) network and information systems is limited to the minimum necessary.
- You use additional authentication mechanisms, such as multi-factor (MFA), for privileged access to all network and information systems that operate or support your essential function(s).
- You individually authenticate and authorise all remote access to all your network and information systems that support your essential function(s).
- The list of users and systems with access to network and information systems supporting and delivering the essential function(s) is reviewed on a regular basis, at least annually.
- Your approach to authenticating users, devices and systems follows up to date best practice.
- Your process of initial identity verification is robust enough to provide a high level of confidence of a user’s identity profile before allowing an authorised user access to network and information systems that support your essential function(s).
- Only authorised and individually authenticated users can physically access and logically connect to your network or information systems on which your essential function(s) depends.
- The number of authorised users and systems that have access to all your network and information systems supporting the essential function(s) is limited to the minimum necessary.
- You use additional authentication mechanisms, such as multi-factor (MFA), for all user access, including remote access, to all network and information systems that operate or support your essential function(s).
- The list of users and systems with access to network and information systems supporting and delivering the essential function(s) is reviewed on a regular basis, at least every six months.
- Your approach to authenticating users, devices and systems follows up to date best practice.
Not achieved - At least one of the following statements is true:
- Initial identity verification is not robust enough to provide an acceptable level of confidence of a user’s identity profile.
- Authorised users and systems with access to networks or information systems on which your essential function(s) depends cannot be individually identified.
- Unauthorised individuals or devices can access your network or information systems on which your essential function(s) depends.
- The number of authorised users and systems that have access to your network and information systems are not limited to the minimum necessary.
- Your approach to authenticating users, devices and systems does not follow up to date best practice.
Partially achieved - All the following statements are true:
- Your process of initial identity verification is robust enough to provide a reasonable level of confidence of a user’s identity profile before allowing an authorised user access to network and information systems that support your essential function(s).
- All authorised users and systems with access to network or information systems on which your essential function(s) depends are individually identified and authenticated.
- The number of authorised users and systems that have access to essential function(s) network and information systems is limited to the minimum necessary.
- You use additional authentication mechanisms, such as multi-factor (MFA), for privileged access to all network and information systems that operate or support your essential function(s).
- You individually authenticate and authorise all remote access to all your network and information systems that support your essential function(s).
- The list of users and systems with access to network and information systems supporting and delivering the essential function(s) is reviewed on a regular basis, at least annually.
- Your approach to authenticating users, devices and systems follows up to date best practice.
Achieved - All the following statements are true:
- Your process of initial identity verification is robust enough to provide a high level of confidence of a user’s identity profile before allowing an authorised user access to network and information systems that support your essential function(s).
- Only authorised and individually authenticated users can physically access and logically connect to your network or information systems on which your essential function(s) depends.
- The number of authorised users and systems that have access to all your network and information systems supporting the essential function(s) is limited to the minimum necessary.
- You use additional authentication mechanisms, such as multi-factor (MFA), for all user access, including remote access, to all network and information systems that operate or support your essential function(s).
- The list of users and systems with access to network and information systems supporting and delivering the essential function(s) is reviewed on a regular basis, at least every six months.
- Your approach to authenticating users, devices and systems follows up to date best practice.
B2.b Device Management
- You fully know and have trust in the devices that are used to access your networks, information systems and data that support your essential function(s).
- You fully know and have trust in the devices that are used to access your networks, information systems and data that support your essential function(s).
- Users can connect to your essential function(s)'s network and information systems using devices that are not corporately owned and managed.
- Privileged users can perform privileged operations from devices that are not corporately owned and managed.
- You have not gained assurance in the security of any third-party devices or networks connected to your systems.
- Physically connecting a device to your network and information systems gives that device access without device or user authentication.
- Only corporately owned and managed devices can access your essential function(s)'s network and information systems.
- All privileged operations are performed from corporately owned and managed devices. These devices provide sufficient separation, using a risk-based approach, from the activities of standard users.
- You have sought to understand the security properties of third-party devices and networks before they can be connected to your systems. You have taken appropriate steps to mitigate any risks identified.
- The act of connecting to a network port or cable does not grant access to any systems.
- You are able to detect unknown devices being connected to your network and information systems and investigate such incidents.
- All privileged operations performed on your network and information systems supporting your essential function(s) are conducted from highly trusted devices, such as Privileged Access Workstations, dedicated solely to those operations.
- You either obtain independent and professional assurance of the security of third-party devices or networks before they connect to your network and information systems, or you only allow third-party devices or networks that are dedicated to supporting your network and information systems to connect.
- You perform certificate-based device identity management and only allow known devices to access systems necessary for the operation of your essential function(s).
- You perform regular scans to detect unknown devices and investigate any findings.
Not achieved - At least one of the following statements is true:
- Users can connect to your essential function(s)'s network and information systems using devices that are not corporately owned and managed.
- Privileged users can perform privileged operations from devices that are not corporately owned and managed.
- You have not gained assurance in the security of any third-party devices or networks connected to your systems.
- Physically connecting a device to your network and information systems gives that device access without device or user authentication.
Partially achieved - All the following statements are true:
- Only corporately owned and managed devices can access your essential function(s)'s network and information systems.
- All privileged operations are performed from corporately owned and managed devices. These devices provide sufficient separation, using a risk-based approach, from the activities of standard users.
- You have sought to understand the security properties of third-party devices and networks before they can be connected to your systems. You have taken appropriate steps to mitigate any risks identified.
- The act of connecting to a network port or cable does not grant access to any systems.
- You are able to detect unknown devices being connected to your network and information systems and investigate such incidents.
Achieved - All the following statements are true:
- All privileged operations performed on your network and information systems supporting your essential function(s) are conducted from highly trusted devices, such as Privileged Access Workstations, dedicated solely to those operations.
- You either obtain independent and professional assurance of the security of third-party devices or networks before they connect to your network and information systems, or you only allow third-party devices or networks that are dedicated to supporting your network and information systems to connect.
- You perform certificate-based device identity management and only allow known devices to access systems necessary for the operation of your essential function(s).
- You perform regular scans to detect unknown devices and investigate any findings.
B2.c Privileged User Management
- You closely manage privileged user access to network and information systems supporting the essential function(s).
- You closely manage privileged user access to network and information systems supporting the essential function(s).
- The identities of the individuals with privileged access to your essential function(s) network and information systems (infrastructure, platforms, software, configuration, etc) are not known or not managed.
- Privileged user access to your essential function(s) network and information systems is via weak authentication mechanisms (e.g. only simple passwords).
- The list of privileged users has not been reviewed recently (e.g. within the last 12 months).
- Privileged user access is granted on a system-wide basis rather than by role or function(s).
- Privileged user access to your essential function(s) is via generic, shared or default name accounts.
- Where there are “always on” terminals which can perform privileged actions (such as in a control room), there are no additional controls (e.g. physical controls) to ensure access is appropriately restricted.
- There is no logical separation between roles that an individual may have and hence the actions they perform. (e.g. access to corporate email and privilege user actions).
- All privileged user access to your network and information systems requires strong authentication, such as multi-factor (MFA).
- The identities of the individuals with privileged access to your essential function(s) network and information systems (infrastructure, platforms, software, configuration, etc) are known and managed. This includes third parties.
- Activity by privileged users is routinely reviewed and validated. (e.g. at least annually).
- Privileged users are only granted specific privileged user access rights which are essential to their business role or function.
- Privileged user access to your essential function(s) systems is carried out from dedicated separate accounts that are closely monitored and managed.
- The issuing of temporary, time-bound rights for privileged user access and / or external third-party support access is in place.
- Privileged user access rights are regularly reviewed and always updated as part of your joiners, movers and leavers process.
- All privileged user activity is routinely reviewed, validated and recorded for offline analysis and investigation.
Not achieved - At least one of the following statements is true:
- The identities of the individuals with privileged access to your essential function(s) network and information systems (infrastructure, platforms, software, configuration, etc) are not known or not managed.
- Privileged user access to your essential function(s) network and information systems is via weak authentication mechanisms (e.g. only simple passwords).
- The list of privileged users has not been reviewed recently (e.g. within the last 12 months).
- Privileged user access is granted on a system-wide basis rather than by role or function(s).
- Privileged user access to your essential function(s) is via generic, shared or default name accounts.
- Where there are “always on” terminals which can perform privileged actions (such as in a control room), there are no additional controls (e.g. physical controls) to ensure access is appropriately restricted.
- There is no logical separation between roles that an individual may have and hence the actions they perform. (e.g. access to corporate email and privilege user actions).
Partially achieved - All of the following statements are true:
- All privileged user access to your network and information systems requires strong authentication, such as multi-factor (MFA).
- The identities of the individuals with privileged access to your essential function(s) network and information systems (infrastructure, platforms, software, configuration, etc) are known and managed. This includes third parties.
- Activity by privileged users is routinely reviewed and validated. (e.g. at least annually).
- Privileged users are only granted specific privileged user access rights which are essential to their business role or function.
Achieved - All of the following statements are true:
- Privileged user access to your essential function(s) systems is carried out from dedicated separate accounts that are closely monitored and managed.
- The issuing of temporary, time-bound rights for privileged user access and / or external third-party support access is in place.
- Privileged user access rights are regularly reviewed and always updated as part of your joiners, movers and leavers process.
- All privileged user activity is routinely reviewed, validated and recorded for offline analysis and investigation.
B2.d Identity and Access Management (IdAM)
- You closely manage and maintain identity and access control for users, devices and systems accessing the network and information systems supporting the essential function(s).
- You closely manage and maintain identity and access control for users, devices and systems accessing the network and information systems supporting the essential function(s).
- Greater access rights are granted than necessary.
- Identity validation and requirement for access of a user, device or systems is not carried out.
- User access rights are not reviewed when users change roles.
- User access rights remain active when users leave your organisation.
- Access rights granted to devices or systems to access other devices and systems are not reviewed on a regular basis (at least annually).
- You follow a robust procedure to verify each user and issue the minimum required access rights.
- You regularly review access rights and those no longer needed are revoked.
- User access rights are reviewed when users change roles via your joiners, leavers and movers process.
- All user, device and system access to the systems supporting the essential function(s) is logged and monitored, but it is not compared to other log data or access records.
- You follow a robust procedure to verify each user and issue the minimum required access rights, and the application of the procedure is regularly audited.
- User access rights are reviewed both when people change roles via your joiners, leavers and movers process and at regular intervals - at least annually.
- All user, device and systems access to the systems supporting the essential function(s) is logged and monitored.
- You regularly review access logs and correlate this data with other access records and expected activity.
- Attempts by unauthorised users, devices or systems to connect to the systems supporting the essential function(s) are alerted, promptly assessed and investigated.
Not achieved - At least one of the following statements is true:
- Greater access rights are granted than necessary.
- Identity validation and requirement for access of a user, device or systems is not carried out.
- User access rights are not reviewed when users change roles.
- User access rights remain active when users leave your organisation.
- Access rights granted to devices or systems to access other devices and systems are not reviewed on a regular basis (at least annually).
Partially achieved - All of the following statements are true:
- You follow a robust procedure to verify each user and issue the minimum required access rights.
- You regularly review access rights and those no longer needed are revoked.
- User access rights are reviewed when users change roles via your joiners, leavers and movers process.
- All user, device and system access to the systems supporting the essential function(s) is logged and monitored, but it is not compared to other log data or access records.
Achieved - All of the following statements are true:
- You follow a robust procedure to verify each user and issue the minimum required access rights, and the application of the procedure is regularly audited.
- User access rights are reviewed both when people change roles via your joiners, leavers and movers process and at regular intervals - at least annually.
- All user, device and systems access to the systems supporting the essential function(s) is logged and monitored.
- You regularly review access logs and correlate this data with other access records and expected activity.
- Attempts by unauthorised users, devices or systems to connect to the systems supporting the essential function(s) are alerted, promptly assessed and investigated.
Data stored or transmitted electronically is protected from actions such as unauthorised access, modification, or deletion that may cause an adverse impact on essential functions. Such protection extends to the means by which authorised users, devices and systems access critical data necessary for the operation of essential functions. It also covers information that would assist an attacker, such as design details of networks and information systems.
Description
error determining description
Guidance
Networks and information systems should be designed to protect important data, for example:
protecting the confidentiality of sensitive data by minimising the number of copies of data, the detail these include and by retaining operationally sensitive data on segregated systems (this includes design documentation)
removing functionality that could allow greater access than has been authorised
protecting the integrity of data essential to the operation of the function by providing a read-only copy for non-essential business system consumption
only deploying well-tested cryptographic suites in common use by your chosen software stack
protecting availability through
resilience
measures such as multiple network paths and tested automatic backup systems
consider suitable means to retain access to essential information in the event of an incident. For example, network diagrams needed for restoration, safety-critical information or essential forecasting data
protecting the confidentiality of sensitive data by minimising the number of copies of data, the detail these include and by retaining operationally sensitive data on segregated systems (this includes design documentation)
Contributing Outcomes
B3.a Understanding Data
- You have a good understanding of data important to the operation of network and information systems supporting your essential function(s), where it is stored, where it travels and how unavailability or unauthorised access, uncontrolled release, modification or deletion would adversely impact the essential function(s). This also applies to third parties storing or accessing data important to the operation of essential function(s).
- You have a good understanding of data important to the operation of network and information systems supporting your essential function(s), where it is stored, where it travels and how unavailability or unauthorised access, uncontrolled release, modification or deletion would adversely impact the essential function(s). This also applies to third parties storing or accessing data important to the operation of essential function(s).
- You have incomplete knowledge of what data is used by and produced in the operation of network and information systems supporting your essential function(s).
- You have not identified the important data on which network and information systems supporting your essential function(s) relies.
- You have not identified who has access to data important to the operation of network and information systems supporting your essential function(s).
- You have not clearly articulated the impact of data compromise or lack of availability.
- You have identified and catalogued all the data important to the operation of network and information systems supporting your essential function(s), or that would assist a threat actor.
- You have identified and catalogued who has access to the data important to the operation of network and information systems supporting your essential function(s).
- You regularly review location, transmission, quantity and quality of data important to the operation of network and information systems supporting your essential function(s).
- You have identified all mobile devices and media that hold data important to the operation of network and information systems supporting your essential function(s).
- You understand and document the impact on your essential function(s) of all relevant scenarios, including unauthorised data access, uncontrolled release, modification or deletion, or when authorised users are unable to appropriately access this data.
- You occasionally validate these documented impact statements.
- You have identified and catalogued all the data important to the operation of network and information systems supporting your essential function(s), or that would assist a threat actor.
- You have identified and catalogued who has access to the data important to the operation of network and information systems supporting your essential function(s).
- You maintain a current understanding of the location, quantity and quality of data important to the operation of network and information systems supporting your essential function(s).
- You take steps to remove or minimise unnecessary copies or unneeded historic data.
- You have identified all mobile devices and media that may hold data important to the operation of network and information systems supporting your essential function(s).
- You maintain a current understanding of the data links used to transmit data that is important to network and information systems supporting your essential function(s).
- You understand the context, limitations and dependencies of your important data.
- You understand and document the impact on your essential function(s) of all relevant scenarios, including unauthorised data access, uncontrolled release, modification or deletion, or when authorised users are unable to appropriately access this data.
- You validate these documented impact statements regularly, at least annually.
Not achieved - At least one of the following statements is true:
- You have incomplete knowledge of what data is used by and produced in the operation of network and information systems supporting your essential function(s).
- You have not identified the important data on which network and information systems supporting your essential function(s) relies.
- You have not identified who has access to data important to the operation of network and information systems supporting your essential function(s).
- You have not clearly articulated the impact of data compromise or lack of availability.
Partially achieved - All of the following statements are true:
- You have identified and catalogued all the data important to the operation of network and information systems supporting your essential function(s), or that would assist a threat actor.
- You have identified and catalogued who has access to the data important to the operation of network and information systems supporting your essential function(s).
- You regularly review location, transmission, quantity and quality of data important to the operation of network and information systems supporting your essential function(s).
- You have identified all mobile devices and media that hold data important to the operation of network and information systems supporting your essential function(s).
- You understand and document the impact on your essential function(s) of all relevant scenarios, including unauthorised data access, uncontrolled release, modification or deletion, or when authorised users are unable to appropriately access this data.
- You occasionally validate these documented impact statements.
Achieved - All of the following statements are true:
- You have identified and catalogued all the data important to the operation of network and information systems supporting your essential function(s), or that would assist a threat actor.
- You have identified and catalogued who has access to the data important to the operation of network and information systems supporting your essential function(s).
- You maintain a current understanding of the location, quantity and quality of data important to the operation of network and information systems supporting your essential function(s).
- You take steps to remove or minimise unnecessary copies or unneeded historic data.
- You have identified all mobile devices and media that may hold data important to the operation of network and information systems supporting your essential function(s).
- You maintain a current understanding of the data links used to transmit data that is important to network and information systems supporting your essential function(s).
- You understand the context, limitations and dependencies of your important data.
- You understand and document the impact on your essential function(s) of all relevant scenarios, including unauthorised data access, uncontrolled release, modification or deletion, or when authorised users are unable to appropriately access this data.
- You validate these documented impact statements regularly, at least annually.
B3.b Data in Transit
- You have protected the transit of data important to the operation of network and information systems supporting your essential function(s). This includes the transfer of data to third parties.
- You have protected the transit of data important to the operation of network and information systems supporting your essential function(s). This includes the transfer of data to third parties.
- You do not know what all your data links are, or which carry data important to the operation of the essential function(s).
- Data important to the operation of the essential function(s) travels without technical protection over non-trusted or openly accessible carriers.
- Critical data paths that could fail, be jammed, be overloaded, etc. have no alternative path.
- You have identified and protected (effectively and proportionately) all the data links that carry data important to the operation of your essential function(s).
- You apply appropriate technical means (e.g. cryptography) to protect data that travels over non-trusted or openly accessible carriers, but you have limited or no confidence in the robustness of the protection applied.
- You have identified and protected (effectively and proportionately) all the data links that carry data important to the operation of your essential function(s).
- You apply appropriate physical and/or technical means to protect data that travels over non-trusted or openly accessible carriers, with justified confidence in the robustness of the protection applied.
- Suitable alternative transmission paths are available where there is a significant risk of impact on the operation of the essential function(s) due to resource limitation (e.g. transmission equipment or function failure, or important data being blocked or jammed).
Not achieved - At least one of the following statements is true:
- You do not know what all your data links are, or which carry data important to the operation of the essential function(s).
- Data important to the operation of the essential function(s) travels without technical protection over non-trusted or openly accessible carriers.
- Critical data paths that could fail, be jammed, be overloaded, etc. have no alternative path.
Partially achieved - All the following statements are true:
- You have identified and protected (effectively and proportionately) all the data links that carry data important to the operation of your essential function(s).
- You apply appropriate technical means (e.g. cryptography) to protect data that travels over non-trusted or openly accessible carriers, but you have limited or no confidence in the robustness of the protection applied.
Achieved - All the following statements are true:
- You have identified and protected (effectively and proportionately) all the data links that carry data important to the operation of your essential function(s).
- You apply appropriate physical and/or technical means to protect data that travels over non-trusted or openly accessible carriers, with justified confidence in the robustness of the protection applied.
- Suitable alternative transmission paths are available where there is a significant risk of impact on the operation of the essential function(s) due to resource limitation (e.g. transmission equipment or function failure, or important data being blocked or jammed).
B3.c Stored Data
- You have protected stored soft and hard copy data important to the operation of network and information systems supporting your essential function(s).
- You have protected stored soft and hard copy data important to the operation of network and information systems supporting your essential function(s).
- You have no, or limited, knowledge of where data important to the operation of the essential function(s) is stored.
- You have not protected vulnerable stored data important to the operation of the essential function(s) in a suitable way.
- Backups are incomplete, untested, not adequately secured or could be inaccessible in a disaster recovery or business continuity situation.
- All copies of data important to the operation of your essential function(s) are necessary. Where this important data is transferred to less secure systems, the data is provided with limited detail and / or as a read-only copy.
- You have applied suitable physical and / or technical means to protect this important stored data from unauthorised access, modification or deletion.
- If cryptographic protections are used, you apply suitable technical and procedural means, but you have limited or no confidence in the robustness of the protection applied.
- You have suitable, secured backups of data to allow the operation of the essential function(s) to continue should the original data not be available. This may include off-line or segregated backups, or appropriate alternative forms such as paper copies.
- All copies of data important to the operation of your essential function(s) are necessary. Where this important data is transferred to less secure systems, the data is provided with limited detail and / or as a read-only copy.
- You have applied suitable physical and / or technical means to protect this important stored data from unauthorised access, modification or deletion.
- If cryptographic protections are used you apply suitable technical and procedural means, and you have justified confidence in the robustness of the protection applied.
- You have suitable, secured backups of data to allow the operation of the essential function(s) to continue should the original data not be available. This may include off-line or segregated backups, or appropriate alternative forms such as paper copies.
- Necessary historic or archive data is suitably secured in storage.
Not achieved - At least one of the following statements is true:
- You have no, or limited, knowledge of where data important to the operation of the essential function(s) is stored.
- You have not protected vulnerable stored data important to the operation of the essential function(s) in a suitable way.
- Backups are incomplete, untested, not adequately secured or could be inaccessible in a disaster recovery or business continuity situation.
Partially achieved - All of the following statements are true:
- All copies of data important to the operation of your essential function(s) are necessary. Where this important data is transferred to less secure systems, the data is provided with limited detail and / or as a read-only copy.
- You have applied suitable physical and / or technical means to protect this important stored data from unauthorised access, modification or deletion.
- If cryptographic protections are used, you apply suitable technical and procedural means, but you have limited or no confidence in the robustness of the protection applied.
- You have suitable, secured backups of data to allow the operation of the essential function(s) to continue should the original data not be available. This may include off-line or segregated backups, or appropriate alternative forms such as paper copies.
Achieved - All of the following statements are true:
- All copies of data important to the operation of your essential function(s) are necessary. Where this important data is transferred to less secure systems, the data is provided with limited detail and / or as a read-only copy.
- You have applied suitable physical and / or technical means to protect this important stored data from unauthorised access, modification or deletion.
- If cryptographic protections are used you apply suitable technical and procedural means, and you have justified confidence in the robustness of the protection applied.
- You have suitable, secured backups of data to allow the operation of the essential function(s) to continue should the original data not be available. This may include off-line or segregated backups, or appropriate alternative forms such as paper copies.
- Necessary historic or archive data is suitably secured in storage.
B3.d Mobile Data
- You have protected data important to the operation of network and information systems supporting your essential function(s) on mobile devices (e.g. smartphones, tablets and laptops).
- You have protected data important to the operation of network and information systems supporting your essential function(s) on mobile devices (e.g. smartphones, tablets and laptops).
- You don’t know which mobile devices may hold data important to the operation of the essential function(s).
- You allow data important to the operation of the essential function(s) to be stored on devices not managed by your organisation, or to at least equivalent standard.
- Data on mobile devices is not technically secured, or only some is secured.
- You know which mobile devices hold data important to the operation of the essential function(s).
- Data important to the operation of the essential function(s) is stored on mobile devices only when they have at least the security standard aligned to your overarching security policies.
- Data on mobile devices is technically secured.
- Mobile devices that hold data that is important to the operation of the essential function(s) are catalogued, are under your organisation's control and configured according to best practice for the platform, with appropriate technical and procedural policies in place.
- Your organisation can remotely wipe all mobile devices holding data important to the operation of the essential function(s).
- You have minimised this data on these mobile devices. Some data may be automatically deleted off mobile devices after a certain period.
Not achieved - At least one of the following statements is true:
- You don’t know which mobile devices may hold data important to the operation of the essential function(s).
- You allow data important to the operation of the essential function(s) to be stored on devices not managed by your organisation, or to at least equivalent standard.
- Data on mobile devices is not technically secured, or only some is secured.
Partially achieved - All of the following statements are true:
- You know which mobile devices hold data important to the operation of the essential function(s).
- Data important to the operation of the essential function(s) is stored on mobile devices only when they have at least the security standard aligned to your overarching security policies.
- Data on mobile devices is technically secured.
Achieved - All of the following statements are true:
- Mobile devices that hold data that is important to the operation of the essential function(s) are catalogued, are under your organisation's control and configured according to best practice for the platform, with appropriate technical and procedural policies in place.
- Your organisation can remotely wipe all mobile devices holding data important to the operation of the essential function(s).
- You have minimised this data on these mobile devices. Some data may be automatically deleted off mobile devices after a certain period.
B3.e Media/Equipment Sanitisation
- Before reuse and / or disposal you appropriately sanitise devices, equipment and removable media holding data important to the operation of network and information systems supporting your essential function(s).
- Before reuse and / or disposal you appropriately sanitise devices, equipment and removable media holding data important to the operation of network and information systems supporting your essential function(s).
- You catalogue and track all devices that contain data important to the operation of the essential function(s) (whether a specific storage device or one with integral storage).
- Data important to the operation of the essential function(s) is removed from all devices, equipment and removable media before reuse and / or disposal using an assured product or service.
Not achieved - At least one of the following statements is true:
Partially achieved - All of the following statements are true:
Achieved - All of the following statements are true:
- You catalogue and track all devices that contain data important to the operation of the essential function(s) (whether a specific storage device or one with integral storage).
- Data important to the operation of the essential function(s) is removed from all devices, equipment and removable media before reuse and / or disposal using an assured product or service.
Network and information systems and technology critical for the operation of essential functions are protected from cyber attack. An organisational understanding of risk to essential functions informs the use of robust and reliable protective security measures to effectively limit opportunities for threat actors to compromise networks and systems.
Description
error determining description
Guidance
The majority of cyber security incidents can be traced to
common cyber attack
vectors. The opportunity for successful attack can be minimised by managing the known vulnerabilities which these attacks exploit. Many opportunities for user error can be reduced by technical means.
Attempts to circumvent the measures described below should be detected by
security monitoring
. Together with
data security
and
resilience measures
, the impact of any attempts to circumvent security on the operation of the essential function should be limited.
Contributing Outcomes
B4.a Secure by Design
- You design security into the network and information systems that support the operation of the essential function(s). You minimise their attack surface and ensure that the operation of the essential function(s) should not be impacted by the exploitation of any single vulnerability.
- You design security into the network and information systems that support the operation of the essential function(s). You minimise their attack surface and ensure that the operation of the essential function(s) should not be impacted by the exploitation of any single vulnerability.
- Network and information systems supporting the operation of the essential function(s) are not appropriately segregated from other systems.
- Internet services, such as browsing and email are accessible from network and information systems supporting your essential function(s).
- Data flows between network and information systems supporting your essential function(s) and other systems are complex, making it hard to discriminate between legitimate and illegitimate / malicious traffic.
- Remote or third-party accesses circumvent some network controls to gain more direct access to network and information systems supporting the essential function(s).
- You employ appropriate expertise to design network and information systems supporting your essential function(s).
- You design strong boundary defences where your network and information systems interface with other organisations or the world at large.
- You design simple data flows between your network and information systems and any external interface to enable effective monitoring.
- You design to make network and information system recovery simple.
- All inputs to network and information systems are checked and validated at the network boundary where possible, or additional monitoring is in place for content-based attacks.
- You employ appropriate expertise to design network and information systems supporting your essential function(s).
- Network and information systems are segregated into appropriate security zones (e.g. systems supporting the essential function(s) are segregated in a highly trusted, more secure zone).
- The network and information systems supporting your essential function(s) are designed to have simple data flows between components to support effective security monitoring.
- The network and information systems supporting your essential function(s) are designed to be easy to recover.
- Content-based attacks are mitigated for all inputs to network and information systems that affect the essential function(s) (e.g. via transformation and inspection / sanitisation and validation).
- If automated decision-making technologies are in use, you design and apply appropriate restrictions to prevent actions that could have an adverse impact on network and information systems supporting your essential function(s).
Not achieved - At least one of the following statements is true:
- Network and information systems supporting the operation of the essential function(s) are not appropriately segregated from other systems.
- Internet services, such as browsing and email are accessible from network and information systems supporting your essential function(s).
- Data flows between network and information systems supporting your essential function(s) and other systems are complex, making it hard to discriminate between legitimate and illegitimate / malicious traffic.
- Remote or third-party accesses circumvent some network controls to gain more direct access to network and information systems supporting the essential function(s).
Partially achieved - All the following statements are true:
- You employ appropriate expertise to design network and information systems supporting your essential function(s).
- You design strong boundary defences where your network and information systems interface with other organisations or the world at large.
- You design simple data flows between your network and information systems and any external interface to enable effective monitoring.
- You design to make network and information system recovery simple.
- All inputs to network and information systems are checked and validated at the network boundary where possible, or additional monitoring is in place for content-based attacks.
Achieved - All the following statements are true:
- You employ appropriate expertise to design network and information systems supporting your essential function(s).
- Network and information systems are segregated into appropriate security zones (e.g. systems supporting the essential function(s) are segregated in a highly trusted, more secure zone).
- The network and information systems supporting your essential function(s) are designed to have simple data flows between components to support effective security monitoring.
- The network and information systems supporting your essential function(s) are designed to be easy to recover.
- Content-based attacks are mitigated for all inputs to network and information systems that affect the essential function(s) (e.g. via transformation and inspection / sanitisation and validation).
- If automated decision-making technologies are in use, you design and apply appropriate restrictions to prevent actions that could have an adverse impact on network and information systems supporting your essential function(s).
B4.b Secure Configuration
- You securely configure network and information systems that support the operation of your essential function(s).
- You securely configure network and information systems that support the operation of your essential function(s).
- You haven't identified the assets that need to be carefully configured to maintain the security of the essential function(s).
- Policies relating to the security of operating system builds or configuration are not applied consistently across your network and information systems relating to your essential function(s).
- Configuration details are not recorded or lack enough information to be able to rebuild the system or device.
- The recording of security changes or adjustments that affect your essential function(s) is lacking or inconsistent.
- Generic, shared, default name and built-in accounts have not been removed or disabled.
- Standard users are able to change settings that would adversely impact the security of network and information systems supporting your essential function(s).
- You have identified and documented the assets that need to be carefully configured to maintain the security of the essential function(s).
- Secure platform and device builds are used across the estate.
- Consistent, secure and minimal system and device configurations are applied across the same types of environment.
- Changes and adjustments to security configuration at security boundaries with the network and information systems supporting your essential function(s) are approved and documented.
- You verify software before installation is permitted.
- Generic, shared, default name and built-in accounts have been removed or disabled. Where this is not possible, credentials to these accounts have been changed. Service accounts are appropriately protected.
- Standard users are not able to change settings that would adversely impact the security of network and information systems supporting your essential function(s).
- You have identified, documented and actively manage (e.g. maintain security configurations, patching, updating according to good practice) the assets that need to be carefully configured to maintain the security of the essential function(s).
- All platforms conform to your secure, defined baseline build, or the latest known good configuration version for that environment.
- You closely and effectively manage changes in your environment, ensuring that network and system configurations are secure and documented.
- You regularly review and validate that your network and information systems have the expected, secure settings and configuration.
- Only permitted software can be installed.
- If automated decision-making technologies are in use, their operation is well understood, and decisions can be replicated.
- Generic, shared, default name and built-in accounts have been removed or disabled. Where this is not possible, credentials to these accounts have been changed. Service accounts are appropriately protected.
Not achieved - At least one of the following statements is true:
- You haven't identified the assets that need to be carefully configured to maintain the security of the essential function(s).
- Policies relating to the security of operating system builds or configuration are not applied consistently across your network and information systems relating to your essential function(s).
- Configuration details are not recorded or lack enough information to be able to rebuild the system or device.
- The recording of security changes or adjustments that affect your essential function(s) is lacking or inconsistent.
- Generic, shared, default name and built-in accounts have not been removed or disabled.
- Standard users are able to change settings that would adversely impact the security of network and information systems supporting your essential function(s).
Partially achieved - All of the following statements are true:
- You have identified and documented the assets that need to be carefully configured to maintain the security of the essential function(s).
- Secure platform and device builds are used across the estate.
- Consistent, secure and minimal system and device configurations are applied across the same types of environment.
- Changes and adjustments to security configuration at security boundaries with the network and information systems supporting your essential function(s) are approved and documented.
- You verify software before installation is permitted.
- Generic, shared, default name and built-in accounts have been removed or disabled. Where this is not possible, credentials to these accounts have been changed. Service accounts are appropriately protected.
- Standard users are not able to change settings that would adversely impact the security of network and information systems supporting your essential function(s).
Achieved - All of the following statements are true:
- You have identified, documented and actively manage (e.g. maintain security configurations, patching, updating according to good practice) the assets that need to be carefully configured to maintain the security of the essential function(s).
- All platforms conform to your secure, defined baseline build, or the latest known good configuration version for that environment.
- You closely and effectively manage changes in your environment, ensuring that network and system configurations are secure and documented.
- You regularly review and validate that your network and information systems have the expected, secure settings and configuration.
- Only permitted software can be installed.
- If automated decision-making technologies are in use, their operation is well understood, and decisions can be replicated.
- Generic, shared, default name and built-in accounts have been removed or disabled. Where this is not possible, credentials to these accounts have been changed. Service accounts are appropriately protected.
B4.c Secure Management
- You manage your organisation's network and information systems that support the operation of your essential function(s) to enable and maintain security.
- You manage your organisation's network and information systems that support the operation of your essential function(s) to enable and maintain security.
- Your systems and devices supporting the operation of the essential function(s) are administered or maintained from devices that are not corporately owned and managed.
- You do not have good or current technical documentation of your network and information systems.
- Your systems and devices supporting the operation of the essential function(s) are only administered or maintained by authorised privileged users from devices sufficiently separated, using a risk-based approach, from the activities of standard users.
- Technical knowledge about network and information systems, such as documentation and network diagrams, is regularly reviewed and updated.
- You prevent, detect and remove malware or unauthorised software. You use technical, procedural and physical measures as necessary.
- Your systems and devices supporting the operation of the essential function(s) are only administered or maintained by authorised privileged users from highly trusted devices, such as Privileged Access Workstations, dedicated solely to those operations.
- You regularly review and update technical knowledge about network and information systems, such as documentation and network diagrams, and ensure they are securely stored.
- You prevent, detect and remove malware or unauthorised software. You use technical, procedural and physical measures as necessary.
Not achieved - At least one of the following statements is true:
- Your systems and devices supporting the operation of the essential function(s) are administered or maintained from devices that are not corporately owned and managed.
- You do not have good or current technical documentation of your network and information systems.
Partially achieved - All of the following statements are true:
- Your systems and devices supporting the operation of the essential function(s) are only administered or maintained by authorised privileged users from devices sufficiently separated, using a risk-based approach, from the activities of standard users.
- Technical knowledge about network and information systems, such as documentation and network diagrams, is regularly reviewed and updated.
- You prevent, detect and remove malware or unauthorised software. You use technical, procedural and physical measures as necessary.
Achieved - All of the following statements are true:
- Your systems and devices supporting the operation of the essential function(s) are only administered or maintained by authorised privileged users from highly trusted devices, such as Privileged Access Workstations, dedicated solely to those operations.
- You regularly review and update technical knowledge about network and information systems, such as documentation and network diagrams, and ensure they are securely stored.
- You prevent, detect and remove malware or unauthorised software. You use technical, procedural and physical measures as necessary.
B4.d Vulnerability Management
- You manage known vulnerabilities in network and information systems to prevent adverse impact on your essential function(s).
- You manage known vulnerabilities in network and information systems to prevent adverse impact on your essential function(s).
- You do not understand the exposure of your essential function(s) to publicly-known vulnerabilities.
- You do not mitigate externally exposed vulnerabilities promptly.
- You have not recently tested to verify your understanding of the vulnerabilities of the network and information systems that support your essential function(s).
- You have not suitably mitigated systems or software that is no longer supported.
- You are not pursuing replacement for unsupported systems or software.
- You maintain a current understanding of the exposure of your essential function(s) to publicly-known vulnerabilities.
- Announced vulnerabilities for all software packages, network and information systems used to support your essential function(s) are tracked, prioritised and externally exposed vulnerabilities are mitigated (e.g. by patching) promptly.
- Some vulnerabilities that are not externally exposed have temporary mitigations for an extended period.
- You have temporary mitigations for unsupported systems and software while pursuing migration to supported technology.
- You regularly test to fully understand the vulnerabilities of the network and information systems that support the operation of your essential function(s).
- You maintain a current understanding of the exposure of your essential function(s) to publicly-known vulnerabilities.
- Announced vulnerabilities for all software packages, network and information systems used to support your essential function(s) are tracked, prioritised and mitigated (e.g. by patching) promptly.
- You regularly test to fully understand the vulnerabilities of the network and information systems that support the operation of your essential function(s) and verify this understanding with third-party testing.
- You actively maximise the use of supported software, firmware and hardware in your network and information systems supporting your essential function(s).
Not achieved - At least one of the following statements is true:
- You do not understand the exposure of your essential function(s) to publicly-known vulnerabilities.
- You do not mitigate externally exposed vulnerabilities promptly.
- You have not recently tested to verify your understanding of the vulnerabilities of the network and information systems that support your essential function(s).
- You have not suitably mitigated systems or software that is no longer supported.
- You are not pursuing replacement for unsupported systems or software.
Partially achieved - All of the following statements are true:
- You maintain a current understanding of the exposure of your essential function(s) to publicly-known vulnerabilities.
- Announced vulnerabilities for all software packages, network and information systems used to support your essential function(s) are tracked, prioritised and externally exposed vulnerabilities are mitigated (e.g. by patching) promptly.
- Some vulnerabilities that are not externally exposed have temporary mitigations for an extended period.
- You have temporary mitigations for unsupported systems and software while pursuing migration to supported technology.
- You regularly test to fully understand the vulnerabilities of the network and information systems that support the operation of your essential function(s).
Achieved - All of the following statements are true:
- You maintain a current understanding of the exposure of your essential function(s) to publicly-known vulnerabilities.
- Announced vulnerabilities for all software packages, network and information systems used to support your essential function(s) are tracked, prioritised and mitigated (e.g. by patching) promptly.
- You regularly test to fully understand the vulnerabilities of the network and information systems that support the operation of your essential function(s) and verify this understanding with third-party testing.
- You actively maximise the use of supported software, firmware and hardware in your network and information systems supporting your essential function(s).
The organisation builds resilience against cyber attack and system failure into the design, implementation, operation and management of systems that support the operation of your essential function(s).
Description
error determining description
Guidance
It's important to be prepared to respond to significant disruption by having business continuity and disaster recovery planning in place. This should include a definition of your most critical resources and an understanding of the order of actions needed to restore service(s). Test that these plans work, for example through manually triggering failover testing, carrying out table-top scenario walk-throughs, red-teaming or Cyber adversary simulation testing. You should be ready to adjust the security measures in place in response to changes in risk. For example, if threat intelligence indicates an increased likelihood of your organisation or sector being targeted you may decide to isolate operational networks until the threat has decreased. Alternatively, in the event of public disclosure of an unpatched vulnerability in equipment that you use, with reported use of exploits targeting the vulnerability, you may respond by elevating your protective monitoring, changing your configuration to avoid being susceptible, or taking other mitigating action in the period until a patch is made available and can be deployed.
You should reduce the likelihood of failure or attack by taking all reasonable measures to maintain networks, information systems and necessary technologies in good working order. Exceptions should be appropriately managed.
In the event of an incident, it is more likely that an essential function will be able to continue where the networks and information systems that support it are segregated from other business and external systems. Separation of system architecture, remote access and privileged access are some key principles that can protect more critical systems from external compromise.
Some sectors responsible for the operation of essential functions may apply the industrial automation and control system security standard IEC 62443, which applies a reference model that separates systems into different logical layers. The standard's architecture model segregates equipment into security zones.
Limitations of networks and information systems, or external services or resources, such as network bandwidth, processing capability, or data storage capacity, should be understood and managed with suitable mitigations to avoid disruption through resource overload.
Make appropriate use of diverse technologies, geographic locations and so on, to provide resilience. You should understand and manage external or lower-priority dependencies to ensure that alternative means are suitable for continuation of the essential function.
In the event of an adverse event, you should be able to revert to backups of hardware and data that are known to be functioning and accessible. Organisations should maintain secured offline, potentially off-site, backups of the operational data, equipment configurations, gold builds, etc. needed to recover from an extreme event.
Suitable alternative backups may include paper-based information and manual processes. Other essential backups may include personnel with appropriate knowledge and access to up-to-date documentation. Consider how to make it easy to recover following an incident or compromise.
You should have adequate policies and measures to ensure the physical and environmental security of your network and information systems. This can be achieved through measures such as physical access controls, alarm systems, environmental controls and automated fire systems etc.
When planning physical upgrades or changes to network and information systems (such as moving to new hardware installations, installing new equipment or power supplies), you should take steps to avoid unnecessary or unplanned interruptions to the services that your network and information systems support.
You should also ensure that you have adequate policies to protect supporting utilities such as electricity, fuel, heating, ventilation, and air conditioning. This can be achieved by having alternative sources, such as back-up generators or uninterruptible power supplies, active temperature monitoring, redundant cooling systems etc.
Contributing Outcomes
B5.a Resilience Preparation
- You are prepared to restore the operation of your essential function(s) following adverse impact to network and information systems.
- You are prepared to restore the operation of your essential function(s) following adverse impact to network and information systems.
- You have limited understanding of all the elements that are required to restore operation of the essential function(s).
- You have not completed business continuity and disaster recovery plans for network and information systems, including their dependencies, supporting the operation of the essential function(s).
- You have not fully assessed the practical implementation of your business continuity and disaster recovery plans.
- You know all network and information systems, and underlying technologies that are necessary to restore the operation of the essential function(s) and understand their interdependence.
- You know the order in which systems need to be recovered to efficiently and effectively restore the operation of the essential function(s).
- You have business continuity and disaster recovery plans that have been tested for practicality, effectiveness and completeness. Appropriate use is made of different test methods (e.g. manual fail-over, table-top exercises, or red-teaming).
- You use your security awareness and threat intelligence sources to identify new or heightened levels of risk, which result in immediate and potentially temporary security measures to enhance the security of your network and information systems (e.g. in response to a widespread outbreak of very damaging malware).
Not achieved - Any of the following statements are true:
- You have limited understanding of all the elements that are required to restore operation of the essential function(s).
- You have not completed business continuity and disaster recovery plans for network and information systems, including their dependencies, supporting the operation of the essential function(s).
- You have not fully assessed the practical implementation of your business continuity and disaster recovery plans.
Partially achieved - All of the following statements are true:
- You know all network and information systems, and underlying technologies that are necessary to restore the operation of the essential function(s) and understand their interdependence.
- You know the order in which systems need to be recovered to efficiently and effectively restore the operation of the essential function(s).
Achieved - All of the following statements are true:
- You have business continuity and disaster recovery plans that have been tested for practicality, effectiveness and completeness. Appropriate use is made of different test methods (e.g. manual fail-over, table-top exercises, or red-teaming).
- You use your security awareness and threat intelligence sources to identify new or heightened levels of risk, which result in immediate and potentially temporary security measures to enhance the security of your network and information systems (e.g. in response to a widespread outbreak of very damaging malware).
B5.b Design for Resilience
- You design the network and information systems supporting your essential function(s) to be resilient to cyber security incidents. Systems are appropriately segregated and resource limitations are mitigated.
- You design the network and information systems supporting your essential function(s) to be resilient to cyber security incidents. Systems are appropriately segregated and resource limitations are mitigated.
- Network and information systems supporting the operation of your essential function(s) are not appropriately segregated.
- Internet services, such as browsing and email, are accessible from network and information systems supporting the essential function(s).
- You do not understand or lack plans to mitigate all resource limitations that could adversely affect your essential function(s).
- Network and information systems supporting the operation of your essential function(s) are logically separated from your business systems (e.g. they reside on the same network as the rest of the organisation but within a DMZ).
- Internet services, such as browsing and email, are not accessible from network and information systems supporting the essential function(s).
- Resource limitations (e.g. network bandwidth, single network paths) have been identified but not fully mitigated.
- Network and information systems supporting the operation of your essential function(s) are segregated from other business and external systems by appropriate technical and physical means (e.g. separate network and system infrastructure with independent user administration).
- Internet services, such as browsing and email, are not accessible from network and information systems supporting the essential function(s).
- You have identified and mitigated all resource limitations (e.g. bandwidth limitations and single network paths).
- You have identified and mitigated any geographical constraints or weaknesses. (e.g. systems that your essential function(s) depends upon are replicated in another location, important network connectivity has alternative physical paths and service providers).
- You review and update assessments of dependencies, resource and geographical limitations and mitigations when necessary.
Not achieved - At least one of the following statements is true:
- Network and information systems supporting the operation of your essential function(s) are not appropriately segregated.
- Internet services, such as browsing and email, are accessible from network and information systems supporting the essential function(s).
- You do not understand or lack plans to mitigate all resource limitations that could adversely affect your essential function(s).
Partially achieved - All of the following statements are true:
- Network and information systems supporting the operation of your essential function(s) are logically separated from your business systems (e.g. they reside on the same network as the rest of the organisation but within a DMZ).
- Internet services, such as browsing and email, are not accessible from network and information systems supporting the essential function(s).
- Resource limitations (e.g. network bandwidth, single network paths) have been identified but not fully mitigated.
Achieved - All of the following statements are true:
- Network and information systems supporting the operation of your essential function(s) are segregated from other business and external systems by appropriate technical and physical means (e.g. separate network and system infrastructure with independent user administration).
- Internet services, such as browsing and email, are not accessible from network and information systems supporting the essential function(s).
- You have identified and mitigated all resource limitations (e.g. bandwidth limitations and single network paths).
- You have identified and mitigated any geographical constraints or weaknesses. (e.g. systems that your essential function(s) depends upon are replicated in another location, important network connectivity has alternative physical paths and service providers).
- You review and update assessments of dependencies, resource and geographical limitations and mitigations when necessary.
B5.c Backups
- You hold accessible and secured current backups of data and information needed to recover operation of your essential function(s) following an adverse impact to network and information systems.
- You hold accessible and secured current backups of data and information needed to recover operation of your essential function(s) following an adverse impact to network and information systems.
- Backup coverage is incomplete and does not include all relevant data and information needed to restore the operation of your essential function(s).
- Backups are not frequent enough for the operation of your essential function(s) to be restored effectively.
- Your restoration process does not restore your essential function(s) in a suitable time frame.
- You have appropriately secured backups (including data, configuration information, software, equipment, processes and knowledge). These backups will be accessible to recover from an extreme event.
- You routinely test backups to ensure that the backup process function(s) correctly and the backups are usable.
- Your comprehensive, automatic and tested technical and procedural backups are secured at centrally accessible or secondary sites to recover from an extreme event.
- Backups of all important data and information needed to recover the essential function(s) are made, tested, documented and routinely reviewed
Not achieved - At least one of the following statements is true:
- Backup coverage is incomplete and does not include all relevant data and information needed to restore the operation of your essential function(s).
- Backups are not frequent enough for the operation of your essential function(s) to be restored effectively.
- Your restoration process does not restore your essential function(s) in a suitable time frame.
Partially achieved - All of the following statements are true:
- You have appropriately secured backups (including data, configuration information, software, equipment, processes and knowledge). These backups will be accessible to recover from an extreme event.
- You routinely test backups to ensure that the backup process function(s) correctly and the backups are usable.
Achieved - All of the following statements are true:
- Your comprehensive, automatic and tested technical and procedural backups are secured at centrally accessible or secondary sites to recover from an extreme event.
- Backups of all important data and information needed to recover the essential function(s) are made, tested, documented and routinely reviewed
Staff have appropriate awareness, knowledge and skills to carry out their organisational roles effectively in relation to the security of network and information systems supporting the operation of your essential function(s).
Description
error determining description
Guidance
The people who operate and support essential functions should be provided with all they need to carry out their job while supporting the organisation's cyber security. In line with the design of
service protection policies and processes
, you should apply the same people-focussed approach to staff awareness and training.
Training and awareness activities should provide appropriate cyber security skills for the job role based on an understanding of how people
really
work with the systems, with ongoing reminders and top-up training to maintain skills.
Using a range of approaches to training and awareness can improve understanding and information retention, from briefings, online courses and blogs to simulated cyber attack. You may achieve the widest uptake of training and awareness by accommodating different learning preferences and using various delivery methods. Organisations may find the
GCHQ certified training scheme
useful when considering commercial offerings.
Organisations responsible for essential functions should aim to create a positive security culture, where people are aware of their role in maintaining security and actively take part and contribute to improving security. This is particularly important where a technical solution is not possible, so security relies on people making the right cyber security decisions. Developing a positive security culture is likely to take some time, with some changes possibly taking years to become established and is unlikely to be achieved simply through written guidance or training events.
These outcomes are best achieved when organisations actively engage with staff and communicate effectively with them about network and information system security and how it relates to their jobs. This should be more easily achieved where organisations create and promote a long-term security culture vision that is endorsed and supported by senior management, then make incremental, focused changes to address specific business issues. In some cases, particularly where an essential function is safety-related, an organisation may be able to draw on activities supporting positive safety culture to build up the organisation's cyber security culture.
Contributing Outcomes
B6.a Cyber Security Culture
- You develop and maintain a positive cyber security culture and a shared sense of responsibility.
- You develop and maintain a positive cyber security culture and a shared sense of responsibility.
- People in your organisation do not understand what they contribute to the cyber security of network and information systems supporting your essential function(s).
- People in your organisation do not know how to raise a concern about cyber security.
- People believe that reporting issues may get them into trouble.
- Your organisation's approach to cyber security is perceived by staff as hindering the business of the organisation and may encourage poor security behaviours.
- Formal or informal incentives and rewards conflict with the promotion of positive security outcomes.
- Your executive management understand and widely communicate the importance of a positive cyber security culture. Positive attitudes, behaviours and expectations are described for your organisation.
- All people in your organisation understand the contribution they make to the cyber security of network and information systems supporting your essential function(s).
- All individuals in your organisation know who to contact and where to access more information about cyber security. They know how to raise a cyber security issue.
- You identify and address issues that inhibit people from behaving in a manner that supports your intended cyber security outcomes.
- Your executive management clearly and effectively communicates the organisation's cyber security priorities and objectives to all staff. Your organisation displays positive cyber security attitudes, behaviours, expectations.
- People in your organisation raising potential cyber security incidents and issues are treated positively.
- Individuals at all levels in your organisation routinely report concerns or issues about cyber security and are recognised for their contribution to keeping the organisation secure.
- Your management is seen to be committed to and actively involved in cyber security.
- Your organisation communicates openly about cyber security, with any concern being taken seriously.
- People across your organisation participate in cyber security activities and improvements, building joint ownership and bringing knowledge of their area of expertise.
Not achieved - At least one of the following statements is true:
- People in your organisation do not understand what they contribute to the cyber security of network and information systems supporting your essential function(s).
- People in your organisation do not know how to raise a concern about cyber security.
- People believe that reporting issues may get them into trouble.
- Your organisation's approach to cyber security is perceived by staff as hindering the business of the organisation and may encourage poor security behaviours.
- Formal or informal incentives and rewards conflict with the promotion of positive security outcomes.
Partially achieved - All the following statements are true:
- Your executive management understand and widely communicate the importance of a positive cyber security culture. Positive attitudes, behaviours and expectations are described for your organisation.
- All people in your organisation understand the contribution they make to the cyber security of network and information systems supporting your essential function(s).
- All individuals in your organisation know who to contact and where to access more information about cyber security. They know how to raise a cyber security issue.
- You identify and address issues that inhibit people from behaving in a manner that supports your intended cyber security outcomes.
Achieved - All the following statements are true:
- Your executive management clearly and effectively communicates the organisation's cyber security priorities and objectives to all staff. Your organisation displays positive cyber security attitudes, behaviours, expectations.
- People in your organisation raising potential cyber security incidents and issues are treated positively.
- Individuals at all levels in your organisation routinely report concerns or issues about cyber security and are recognised for their contribution to keeping the organisation secure.
- Your management is seen to be committed to and actively involved in cyber security.
- Your organisation communicates openly about cyber security, with any concern being taken seriously.
- People across your organisation participate in cyber security activities and improvements, building joint ownership and bringing knowledge of their area of expertise.
B6.b Cyber Security Training
- The people who support the operation of network and information systems supporting your essential function(s) are appropriately trained in cyber security.
- The people who support the operation of network and information systems supporting your essential function(s) are appropriately trained in cyber security.
- There are teams who operate and support your essential function(s) that lack any cyber security training.
- Cyber security training is restricted to specific roles in your organisation.
- Cyber security training records for your organisation are lacking or incomplete.
- Training is used as a “silver bullet” for all user security behaviours.
- The success of training is only measured by the number of people reached, rather than assessing whether it has a positive impact on security behaviours.
- Training materials contain out of date or contradictory information, or information that conflicts with other policies, processes or procedures.
- You have defined appropriate cyber security training and awareness activities for all roles in your organisation, from executives to the most junior roles.
- You use a range of teaching and communication techniques for cyber security training and awareness to reach the widest audience effectively.
- Cyber security information is easily available.
- All people in your organisation, from the most senior to the most junior, follow appropriate cyber security training paths.
- Each individuals cyber security training is tracked and refreshed at suitable intervals.
- You routinely evaluate your cyber security training and awareness activities to ensure they reach the widest audience and are effective.
- You make cyber security information and good practice guidance easily accessible, widely available and you know it is referenced and used within your organisation.
Not achieved - At least one of the following statements is true:
- There are teams who operate and support your essential function(s) that lack any cyber security training.
- Cyber security training is restricted to specific roles in your organisation.
- Cyber security training records for your organisation are lacking or incomplete.
- Training is used as a “silver bullet” for all user security behaviours.
- The success of training is only measured by the number of people reached, rather than assessing whether it has a positive impact on security behaviours.
- Training materials contain out of date or contradictory information, or information that conflicts with other policies, processes or procedures.
Partially achieved - All the following statements are true:
- You have defined appropriate cyber security training and awareness activities for all roles in your organisation, from executives to the most junior roles.
- You use a range of teaching and communication techniques for cyber security training and awareness to reach the widest audience effectively.
- Cyber security information is easily available.
Achieved - All the following statements are true:
- All people in your organisation, from the most senior to the most junior, follow appropriate cyber security training paths.
- Each individuals cyber security training is tracked and refreshed at suitable intervals.
- You routinely evaluate your cyber security training and awareness activities to ensure they reach the widest audience and are effective.
- You make cyber security information and good practice guidance easily accessible, widely available and you know it is referenced and used within your organisation.
The organisation monitors the security status of network and information systems supporting the operation of essential function(s) in order to detect security events indicative of a security incident.
Description
error determining description
Guidance
One clear focus of your security monitoring should be the detection of incidents or activity that is likely to have an adverse impact on the network and information systems that support the operation of essential functions. Log data collection, secure storage, analysis tools, understanding your network and information systems that support your essential function(s), threat intelligence and personnel skills should all be used to build an effective security monitoring capability.
An organisation's automated monitoring capability should be able to find threats within their network and information systems by using both signature-based detections and, behavioural and anomaly-based detections.
Examples of signature-based detections are detecting when known command and control traffic is communicating to the internet, or an AV signature is present in a file. Organisations should endeavour to understand what automated detections and alerting do and how best to use them, to ensure they are making the most of the monitoring solution / as well as being as effective as possible.
Organisations should also have the capability to find threats by using behavioural and anomaly-based detections, for example by detecting an abnormally large amount of data being exfiltrated or AV detecting unusual changes to start up registry keys.
Both signature and, anomaly and behaviour-based detections rely on an understanding of indicators of compromise, your network and information systems, user behaviour and threats.
Contributing Outcomes
C1.a Sources and Tools for Logging and Monitoring
- The data sources that you include in your logging and monitoring allow for timely identification of events which might adversely affect the resiliency of network and information system(s) supporting the operation of your essential function(s).
- The data sources that you include in your logging and monitoring allow for timely identification of events which might adversely affect the resiliency of network and information system(s) supporting the operation of your essential function(s).
- Data relating to the security and operation of network and information systems supporting your essential function(s) is not collected.
- You are not able to audit the activities of users and systems in relation to network and information systems supporting your essential function(s).
- You do not monitor traffic crossing your network boundary.
- Log data cannot be synchronised using an accurate common time source.
- Logs are stored in locations where they are not readily available to authorised users and systems.
- Your monitoring tools cannot be configured to make use of new log streams as they come online.
- Your monitoring tools are only able to make use of a fraction of the log data being collected.
- You do not understand where log data is stored or how long it should be stored for.
- You have no way of ensuring log data is being captured as expected and available when needed.
- Data relating to the security and operation of some areas of network and information systems supporting your essential function(s) is collected but coverage is not comprehensive.
- Some user and system monitoring is done, but not covering a fully agreed list of suspicious or undesirable behaviour.
- You monitor traffic crossing your network boundary (including IP address connections as a minimum).
- Some but not all log datasets can be easily queried with search tools to aid in investigations.
- Your monitoring tools work with most log data, with some configuration.
- Your monitoring tools can make use of log data that would capture all common threats.
- You ensure log data is available for analysis when needed.
- Monitoring is based on a thorough understanding of network and information systems supporting your essential function(s), techniques used by threat actors, and awareness of what logging and monitoring is required to detect events and incidents that could affect the operation of your essential function(s).
- Your monitoring data provides enough detail to promptly and reliably detect security events, incidents and support investigations. This is reviewed regularly and after a significant security event.
- Extensive monitoring of user and system activity in relation to network and information systems that support your essential function(s) enables you to promptly detect policy violations, suspicious or undesirable user and system behaviour, deviations from normal / routine behaviour or abnormalities indicative of adverse activity.
- Your logging and monitoring capability includes host-based and network monitoring.
- All new network and information systems supporting your essential function(s) are considered as potential logging and monitoring data sources to maintain a comprehensive monitoring capability.
- Log datasets are synchronised including using an accurate common time source so that separate datasets can be correlated in appropriate ways.
- You enrich log data with other network and information systems data to provide a more comprehensive picture of actions and behaviours.
- Your monitoring tools make use of log data to pinpoint activity.
- You regularly review the data sources and tools included in your logging and monitoring strategy to ensure it remains effective.
Not achieved - At least one of the following statements is true:
- Data relating to the security and operation of network and information systems supporting your essential function(s) is not collected.
- You are not able to audit the activities of users and systems in relation to network and information systems supporting your essential function(s).
- You do not monitor traffic crossing your network boundary.
- Log data cannot be synchronised using an accurate common time source.
- Logs are stored in locations where they are not readily available to authorised users and systems.
- Your monitoring tools cannot be configured to make use of new log streams as they come online.
- Your monitoring tools are only able to make use of a fraction of the log data being collected.
- You do not understand where log data is stored or how long it should be stored for.
- You have no way of ensuring log data is being captured as expected and available when needed.
Partially achieved - All the following statements are true:
- Data relating to the security and operation of some areas of network and information systems supporting your essential function(s) is collected but coverage is not comprehensive.
- Some user and system monitoring is done, but not covering a fully agreed list of suspicious or undesirable behaviour.
- You monitor traffic crossing your network boundary (including IP address connections as a minimum).
- Some but not all log datasets can be easily queried with search tools to aid in investigations.
- Your monitoring tools work with most log data, with some configuration.
- Your monitoring tools can make use of log data that would capture all common threats.
- You ensure log data is available for analysis when needed.
Achieved - All the following statements are true:
- Monitoring is based on a thorough understanding of network and information systems supporting your essential function(s), techniques used by threat actors, and awareness of what logging and monitoring is required to detect events and incidents that could affect the operation of your essential function(s).
- Your monitoring data provides enough detail to promptly and reliably detect security events, incidents and support investigations. This is reviewed regularly and after a significant security event.
- Extensive monitoring of user and system activity in relation to network and information systems that support your essential function(s) enables you to promptly detect policy violations, suspicious or undesirable user and system behaviour, deviations from normal / routine behaviour or abnormalities indicative of adverse activity.
- Your logging and monitoring capability includes host-based and network monitoring.
- All new network and information systems supporting your essential function(s) are considered as potential logging and monitoring data sources to maintain a comprehensive monitoring capability.
- Log datasets are synchronised including using an accurate common time source so that separate datasets can be correlated in appropriate ways.
- You enrich log data with other network and information systems data to provide a more comprehensive picture of actions and behaviours.
- Your monitoring tools make use of log data to pinpoint activity.
- You regularly review the data sources and tools included in your logging and monitoring strategy to ensure it remains effective.
C1.b Securing Logs
- You hold log data securely and grant appropriate user and system access only to accounts with a business need. Log data is held for a suitable retention period, after which it is deleted.
- You hold log data securely and grant appropriate user and system access only to accounts with a business need. Log data is held for a suitable retention period, after which it is deleted.
- It is possible for log data to be easily edited or deleted by unauthorised users or malicious attackers.
- There is no controlled list of the users and systems that can view and query log data.
- There is no monitoring of the access to log data.
- There are no policies for accessing to log data.
- Only authorised users and systems can access log data.
- There is some monitoring of access to log data (e.g. copying, deleting or modification, or even viewing).
- You have defined and implemented retention periods for log data.
- You have given legitimate reasons for accessing log data in your policies.
- Appropriate access to log data is limited to those users and systems with a business need.
- The logging architecture has mechanisms, policies, processes and procedures to ensure that it can protect itself from threats comparable to those that it is trying to identify. This includes protecting the function itself and the data within it.
- Log data analysis and normalisation is only performed on copies of the log data keeping the master copy unaltered.
- All actions involving log data (e.g. copying, deleting, modification, or even viewing) can be traced back to a unique user or system.
- The integrity of log data is protected, verified and any modification, including deletion, is detected and attributed.
Not achieved - At least one of the following is true:
- It is possible for log data to be easily edited or deleted by unauthorised users or malicious attackers.
- There is no controlled list of the users and systems that can view and query log data.
- There is no monitoring of the access to log data.
- There are no policies for accessing to log data.
Partially achieved - All the following statements are true:
- Only authorised users and systems can access log data.
- There is some monitoring of access to log data (e.g. copying, deleting or modification, or even viewing).
- You have defined and implemented retention periods for log data.
- You have given legitimate reasons for accessing log data in your policies.
Achieved - All the following statements are true:
- Appropriate access to log data is limited to those users and systems with a business need.
- The logging architecture has mechanisms, policies, processes and procedures to ensure that it can protect itself from threats comparable to those that it is trying to identify. This includes protecting the function itself and the data within it.
- Log data analysis and normalisation is only performed on copies of the log data keeping the master copy unaltered.
- All actions involving log data (e.g. copying, deleting, modification, or even viewing) can be traced back to a unique user or system.
- The integrity of log data is protected, verified and any modification, including deletion, is detected and attributed.
C1.c Generating Alerts
- Evidence of potential security incidents contained in your monitoring data is reliably identified and where appropriate triggers alerts.
- Evidence of potential security incidents contained in your monitoring data is reliably identified and where appropriate triggers alerts.
- You do not apply updates to your detection security technologies in a timely way, after receiving them (e.g. AV signature updates, other threat signatures or Indicators of Compromise (IoCs)).
- Security alerts relating to network and information systems supporting your essential function(s) are not prioritised.
- The enrichment of security alerts within network and information systems supporting your essential function(s) cannot be performed.
- You do not confidently detect the presence of IoCs on network and information systems supporting your essential function(s), such as known malicious command and control signatures (e.g. because applying the indicator is difficult or your log data is not sufficiently detailed).
- You do not monitor for user or system abnormalities indicative of adverse activity.
- Logs are monitored infrequently.
- You easily detect the presence of Indicators of Compromise (IoCs) on network and information systems supporting your essential function(s), such as known malicious command and control signatures.
- You apply some updates, new signatures and IoCs in a timely way.
- Security alerts relating to network and information systems that support your essential function(s) are prioritised.
- The enrichment of alerts within network and information systems supporting your essential function(s) is performed but not as part of the original alert.
- Detections and alerting rely on off the shelf tooling without customisation or users reporting events and potential incidents.
- There is a documented and shared process for all users who support the operation of the essential function to report events and potential security incidents.
- Where appropriate, detections and alerting result in automated actions being taken. (e.g. malware identified by AV is quarantined).
- You monitor on an irregular basis for user or system abnormalities indicative of adverse activity.
- Logs are monitored at regular intervals.
- You easily detect the presence of Indicators of Compromise (IoCs) on network and information systems supporting your essential function(s), such as known malicious command and control signatures, as well as abnormalities or behaviours indicative of adverse activity.
- You apply all updates, new signatures and IoCs promptly.
- Security alerts relating to all network and information systems supporting your essential function(s) are prioritised and this information is used to support incident management.
- Alerts are routinely enriched within network and information systems supporting your essential function(s). The enrichment of these alerts is performed in almost real time and as part of the original alert.
- Alerts and the underlying detections are regularly reviewed and tested to ensure they are generated promptly and reliably, and it is possible to distinguish genuine security incidents from false alarms.
- Alerts and the underlying detection rules are customisable and tuned to reduce false positives as well as optimising responses.
- Detections and alerting may use off the shelf tooling and rules as well as custom tooling and / or rules.
- You continuously monitor for user and system abnormalities indicative of adverse activity generating alerts based on the results of such monitoring.
- Logs are monitored continuously in near real time.
Not achieved - At least one of the following is true:
- You do not apply updates to your detection security technologies in a timely way, after receiving them (e.g. AV signature updates, other threat signatures or Indicators of Compromise (IoCs)).
- Security alerts relating to network and information systems supporting your essential function(s) are not prioritised.
- The enrichment of security alerts within network and information systems supporting your essential function(s) cannot be performed.
- You do not confidently detect the presence of IoCs on network and information systems supporting your essential function(s), such as known malicious command and control signatures (e.g. because applying the indicator is difficult or your log data is not sufficiently detailed).
- You do not monitor for user or system abnormalities indicative of adverse activity.
- Logs are monitored infrequently.
Partially achieved - All the following statements are true:
- You easily detect the presence of Indicators of Compromise (IoCs) on network and information systems supporting your essential function(s), such as known malicious command and control signatures.
- You apply some updates, new signatures and IoCs in a timely way.
- Security alerts relating to network and information systems that support your essential function(s) are prioritised.
- The enrichment of alerts within network and information systems supporting your essential function(s) is performed but not as part of the original alert.
- Detections and alerting rely on off the shelf tooling without customisation or users reporting events and potential incidents.
- There is a documented and shared process for all users who support the operation of the essential function to report events and potential security incidents.
- Where appropriate, detections and alerting result in automated actions being taken. (e.g. malware identified by AV is quarantined).
- You monitor on an irregular basis for user or system abnormalities indicative of adverse activity.
- Logs are monitored at regular intervals.
Achieved - All the following statements are true:
- You easily detect the presence of Indicators of Compromise (IoCs) on network and information systems supporting your essential function(s), such as known malicious command and control signatures, as well as abnormalities or behaviours indicative of adverse activity.
- You apply all updates, new signatures and IoCs promptly.
- Security alerts relating to all network and information systems supporting your essential function(s) are prioritised and this information is used to support incident management.
- Alerts are routinely enriched within network and information systems supporting your essential function(s). The enrichment of these alerts is performed in almost real time and as part of the original alert.
- Alerts and the underlying detections are regularly reviewed and tested to ensure they are generated promptly and reliably, and it is possible to distinguish genuine security incidents from false alarms.
- Alerts and the underlying detection rules are customisable and tuned to reduce false positives as well as optimising responses.
- Detections and alerting may use off the shelf tooling and rules as well as custom tooling and / or rules.
- You continuously monitor for user and system abnormalities indicative of adverse activity generating alerts based on the results of such monitoring.
- Logs are monitored continuously in near real time.
C1.d Triage of Security Alerts
- You contextualise alerts with knowledge of the threat and your systems, to identify those security incidents as well as responding to all alerts appropriately.
- You contextualise alerts with knowledge of the threat and your systems, to identify those security incidents as well as responding to all alerts appropriately.
- You do not triage alerts from your detection security technologies (e.g. AV, IDS).
- You do not categorise alerts and incidents by type and priority / severity level.
- You do not have Standard Operating Procedures (SOPs) / Playbooks / Runbooks available for use during triage.
- You do not keep records of triage performed.
- You do not have a sufficient understanding of normal user or system behaviour to make effective decisions within triage.
- You investigate and triage alerts from some security tools and take action.
- You have created, made available and use when appropriate, Standard Operating Procedures (SOPs) / Playbooks / Runbooks covering the most common use cases. These are regularly reviewed to ensure they remain effective.
- You perform some triage and actions taken by monitoring and detection personnel are recorded.
- You categorise alerts and incidents by type and priority / severity level.
- Your understanding of normal user or system behaviour informs your decision making within triage.
- You investigate and triage alerts from all security tools and take action.
- You have created, made available and use when appropriate, Standard Operating Procedures (SOPs) / Playbooks / Runbooks covering all plausible use cases. These are regularly reviewed to ensure they remain effective.
- You categorise alerts and incidents by type and priority / severity level.
- You document all triage related activities performed by monitoring and detection personnel and these are used to drive improvements
- Triage provides enough information for subsequent activities to be prioritised (e.g. the containment of damaging malware).
- Your understanding of normal user and system behaviour, and threats, is sufficient for effective decision making within triage.
Not achieved - At least one of the following is true:
- You do not triage alerts from your detection security technologies (e.g. AV, IDS).
- You do not categorise alerts and incidents by type and priority / severity level.
- You do not have Standard Operating Procedures (SOPs) / Playbooks / Runbooks available for use during triage.
- You do not keep records of triage performed.
- You do not have a sufficient understanding of normal user or system behaviour to make effective decisions within triage.
Partially achieved - All the following statements are true:
- You investigate and triage alerts from some security tools and take action.
- You have created, made available and use when appropriate, Standard Operating Procedures (SOPs) / Playbooks / Runbooks covering the most common use cases. These are regularly reviewed to ensure they remain effective.
- You perform some triage and actions taken by monitoring and detection personnel are recorded.
- You categorise alerts and incidents by type and priority / severity level.
- Your understanding of normal user or system behaviour informs your decision making within triage.
Achieved - All the following statements are true:
- You investigate and triage alerts from all security tools and take action.
- You have created, made available and use when appropriate, Standard Operating Procedures (SOPs) / Playbooks / Runbooks covering all plausible use cases. These are regularly reviewed to ensure they remain effective.
- You categorise alerts and incidents by type and priority / severity level.
- You document all triage related activities performed by monitoring and detection personnel and these are used to drive improvements
- Triage provides enough information for subsequent activities to be prioritised (e.g. the containment of damaging malware).
- Your understanding of normal user and system behaviour, and threats, is sufficient for effective decision making within triage.
C1.e Personnel Skills for Monitoring Tools and Detection
- Monitoring and detection personnel skills and roles, including those outsourced, reflect governance and reporting requirements, expected threats and the complexities of the network or system data they need to use. Monitoring and detection personnel have sufficient knowledge of network and information systems and the essential function(s) they need to protect.
- Monitoring and detection personnel skills and roles, including those outsourced, reflect governance and reporting requirements, expected threats and the complexities of the network or system data they need to use. Monitoring and detection personnel have sufficient knowledge of network and information systems and the essential function(s) they need to protect.
- There are no personnel who perform a monitoring and detection function.
- Monitoring and detection personnel do not have the correct specialist skills.
- Monitoring and detection personnel are not capable of reporting against governance requirements.
- Monitoring and detection personnel have a lack of awareness of the essential function(s) the organisation provides, what assets relate to those functions and hence the importance of the log data and security events.
- Monitoring and detection personnel have no awareness of other roles or tasks outside of security monitoring and detection that are relevant to the operation of your essential function(s).
- Monitoring and detection personnel are overwhelmed with the amount of data and alerts they have to work with. Alert / triage fatigue is present.
- Monitoring and detection personnel have some investigative skills and a basic understanding of the data they need to work with.
- Monitoring and detection personnel can report to other parts of the organisation (e.g. security directors, resilience managers).
- Monitoring and detection personnel are capable of following most of the required workflow(s).
- Monitoring and detection personnel are aware of some of the network and information systems and your essential function(s), and can manage alerts relating to them.
- Monitoring and detection personnel have some understanding of the operational context (e.g. people, processes, network and information systems that support your essential function(s)) to enhance the security monitoring function.
- Monitoring and detection personnel deal with their workload and cases effectively.
- You have monitoring and detection personnel who are responsible for the proactive and reactive analysis, investigation and reporting of monitoring alerts including both security and performance.
- Monitoring and detection personnel have defined roles and skills that cover all parts of the monitoring and investigation process.
- Monitoring and detection personnel follow policies, processes and procedures that address all governance reporting requirements, internal and external.
- Monitoring and detection personnel are empowered to look beyond the fixed process to investigate and understand non-standard threats.
- Monitoring and detection personnel are aware of the network and information systems and your essential function(s), related assets and can identify and prioritise alerts and investigations that relate to them.
- Monitoring and detection personnel drive and shape new log data collection and can make effective use of it.
- Monitoring and detection personnel are capable of following all of the required workflow(s).
- Monitoring and detection personnel have a sufficient understanding of the operational context (e.g. people, processes, network and information systems that support your essential function) to enhance the security monitoring function.
- Monitoring and detection personnel deal with their workload and cases effectively as well as identifying areas for improvement.
Not achieved - At least one of the following is true:
- There are no personnel who perform a monitoring and detection function.
- Monitoring and detection personnel do not have the correct specialist skills.
- Monitoring and detection personnel are not capable of reporting against governance requirements.
- Monitoring and detection personnel have a lack of awareness of the essential function(s) the organisation provides, what assets relate to those functions and hence the importance of the log data and security events.
- Monitoring and detection personnel have no awareness of other roles or tasks outside of security monitoring and detection that are relevant to the operation of your essential function(s).
- Monitoring and detection personnel are overwhelmed with the amount of data and alerts they have to work with. Alert / triage fatigue is present.
Partially achieved - All the following statements are true:
- Monitoring and detection personnel have some investigative skills and a basic understanding of the data they need to work with.
- Monitoring and detection personnel can report to other parts of the organisation (e.g. security directors, resilience managers).
- Monitoring and detection personnel are capable of following most of the required workflow(s).
- Monitoring and detection personnel are aware of some of the network and information systems and your essential function(s), and can manage alerts relating to them.
- Monitoring and detection personnel have some understanding of the operational context (e.g. people, processes, network and information systems that support your essential function(s)) to enhance the security monitoring function.
- Monitoring and detection personnel deal with their workload and cases effectively.
Achieved - All the following statements are true:
- You have monitoring and detection personnel who are responsible for the proactive and reactive analysis, investigation and reporting of monitoring alerts including both security and performance.
- Monitoring and detection personnel have defined roles and skills that cover all parts of the monitoring and investigation process.
- Monitoring and detection personnel follow policies, processes and procedures that address all governance reporting requirements, internal and external.
- Monitoring and detection personnel are empowered to look beyond the fixed process to investigate and understand non-standard threats.
- Monitoring and detection personnel are aware of the network and information systems and your essential function(s), related assets and can identify and prioritise alerts and investigations that relate to them.
- Monitoring and detection personnel drive and shape new log data collection and can make effective use of it.
- Monitoring and detection personnel are capable of following all of the required workflow(s).
- Monitoring and detection personnel have a sufficient understanding of the operational context (e.g. people, processes, network and information systems that support your essential function) to enhance the security monitoring function.
- Monitoring and detection personnel deal with their workload and cases effectively as well as identifying areas for improvement.
C1.f Understanding User's and System's Behaviour, and Threat Intelligence (within Security Monitoring)
- Threats to the operation of network and information systems, and corresponding user and system behaviour, are sufficiently understood. These are used to detect cyber security incidents.
- Threats to the operation of network and information systems, and corresponding user and system behaviour, are sufficiently understood. These are used to detect cyber security incidents.
- Your organisation has no sources of threat intelligence.
- You do not evaluate the usefulness of your threat intelligence or share feedback with providers or other users.
- You have no awareness of the steps necessary to make best use of threat intelligence for security monitoring.
- Threat intelligence is unreliable and / or is not actioned by the appropriate users or systems in a timely manner.
- You have no established understanding of what abnormalities to look for that might signify adverse activities.
- You do not receive updates for all your detection security technologies (e.g. AV, IDS).
- You do not understand normal user and system behaviour sufficiently to be able to use abnormalities to detect adverse activity.
- You know how effective your threat intelligence is (e.g. by tracking how threat intelligence helps you identify security incidents).
- Your organisation may use threat intelligence services, but you do not necessarily choose sources or providers specifically because of your business needs, or specific threats in your sector (e.g. sector-based infoshare, software vendors, anti-virus providers, specialist threat intel firms, special interest groups).
- The user and system abnormalities from past attacks and threat intelligence, on your
- and other network and information systems, are used to signify adverse activity.
- You receive regular updates for all of your detection security technologies (e.g. AV, IDS).
- You track the effectiveness of your threat intelligence and actively share feedback on the usefulness of Indicators of Compromise (IoCs) and other intelligence with the threat community (e.g. sector partners, threat intelligence providers, government agencies).
- When using threat intelligence feeds, these have been selected using risk-based and threat-informed decisions based on your business needs and sector.
- You make relevant, reliable and actionable threat intelligence available to the necessary users and systems promptly.
- You contextualise threat intelligence and link it to the why and / or how attacks take place for security monitoring.
- You understand normal user and system abnormalities fully, to such an extent that searching for system abnormalities is an effective way of detecting adverse activity (e.g. you fully understand which systems should and should not communicate and when).
- The user and system abnormalities you monitor for are based on the nature of adverse activities likely to impact network and information systems supporting the operation of your essential function(s).
- The user and system abnormalities indicative of adverse activity you use are regularly updated to reflect changes in network and information systems supporting your essential function(s) and current threat intelligence.
- You possess the capability to share threat intelligence (e.g. ways to effectively detect adversaries) with the threat community / defender community (sector partners, threat intelligence providers, government agencies) when required.
Not achieved - At least one of the following is true:
- Your organisation has no sources of threat intelligence.
- You do not evaluate the usefulness of your threat intelligence or share feedback with providers or other users.
- You have no awareness of the steps necessary to make best use of threat intelligence for security monitoring.
- Threat intelligence is unreliable and / or is not actioned by the appropriate users or systems in a timely manner.
- You have no established understanding of what abnormalities to look for that might signify adverse activities.
- You do not receive updates for all your detection security technologies (e.g. AV, IDS).
- You do not understand normal user and system behaviour sufficiently to be able to use abnormalities to detect adverse activity.
Partially achieved - All the following statements are true:
- You know how effective your threat intelligence is (e.g. by tracking how threat intelligence helps you identify security incidents).
- Your organisation may use threat intelligence services, but you do not necessarily choose sources or providers specifically because of your business needs, or specific threats in your sector (e.g. sector-based infoshare, software vendors, anti-virus providers, specialist threat intel firms, special interest groups).
- The user and system abnormalities from past attacks and threat intelligence, on your
- and other network and information systems, are used to signify adverse activity.
- You receive regular updates for all of your detection security technologies (e.g. AV, IDS).
Achieved - All the following statements are true:
- You track the effectiveness of your threat intelligence and actively share feedback on the usefulness of Indicators of Compromise (IoCs) and other intelligence with the threat community (e.g. sector partners, threat intelligence providers, government agencies).
- When using threat intelligence feeds, these have been selected using risk-based and threat-informed decisions based on your business needs and sector.
- You make relevant, reliable and actionable threat intelligence available to the necessary users and systems promptly.
- You contextualise threat intelligence and link it to the why and / or how attacks take place for security monitoring.
- You understand normal user and system abnormalities fully, to such an extent that searching for system abnormalities is an effective way of detecting adverse activity (e.g. you fully understand which systems should and should not communicate and when).
- The user and system abnormalities you monitor for are based on the nature of adverse activities likely to impact network and information systems supporting the operation of your essential function(s).
- The user and system abnormalities indicative of adverse activity you use are regularly updated to reflect changes in network and information systems supporting your essential function(s) and current threat intelligence.
- You possess the capability to share threat intelligence (e.g. ways to effectively detect adversaries) with the threat community / defender community (sector partners, threat intelligence providers, government agencies) when required.
The organisation proactively seeks to detect, within networks and information systems, adverse activity affecting, or with the potential to affect, the operation of essential functions even when the activity evades standard security prevent/detect solutions (or when standard solutions are not deployable).
Description
error determining description
Guidance
Threat hunting is more difficult than standard security monitoring because it looks beyond the known Indicators of Compromise (IOCs) that can be leveraged by automated detections and alerting covered in
C1 Security Monitoring
.
The aim is to build on what is known of both past and plausible attacks to hypothesise what intrusions might look like in. Threat hunting requires more experienced knowledge of network and system behaviour and of the general characteristics that an intrusion might exhibit. This sort of proactive monitoring or threat discovery would normally involve:
A good understanding of normal system behaviour (e.g. what software is authorised and how it would normally behave, how user accounts normally access network resources or how network components connect to each other and transfer data).
A good understanding of the ways that different types of threats maybe realised within your environment(s) based on a comprehensive and advanced understanding of threat intelligence.
A good understanding of normal system behaviour (e.g. what software is authorised and how it would normally behave, how user accounts normally access network resources or how network components connect to each other and transfer data).
Contributing Outcomes
C2.a Threat Hunting
- You do not know the resources required for threat hunting.
- You do not have access to an effective threat hunting capability.
- Your threat hunts do not follow any structure and few if any records are created.
- You have identified the resources required to perform threat hunting and are able to deploy these, in a timely manner, on an occasional basis.
- You deploy an effective threat hunting capability but not frequent enough to match the risks posed to network and information systems supporting your essential function(s) (e.g. you perform threat hunts in response to a tip off from a reputable source).
- Your threat hunts follow pre-determined and documented methods (e.g. hypothesis driven, data driven, entity driven) designed to identify adverse activity not detected by automated detections.
- You document details of threat hunts and post hunt analysis.
- You understand the resources required to perform threat hunting and these are deployed as part of business as usual.
- You deploy threat hunting resources at a frequency that matches the risks posed to network and information systems supporting your essential function(s).
- Your threat hunts follow pre-determined and documented methods (e.g. hypothesis driven, data driven, entity driven) designed to identify adverse activity not detected by automated detections.
- You turn threat hunts into automated detections and alerting where appropriate.
- You routinely record details of previous threat hunts and post hunt activities. You use these to drive improvements in your threat hunting and security posture.
- You have justified confidence in the effectiveness of your threat hunts and the threat hunting process is reviewed and updated to match the risks posed to network and information systems supporting your essential function(s).
- You leverage automation to improve threat hunts where appropriate (e.g. some stages of the threat hunting process are automated).
- Your threat hunts focus on the tactics, techniques and procedures (TTPs) of threats over atomic IoCs (e.g. hashes, IP addresses, domain names etc).
Not achieved - At least one of the following statements is true:
- You do not know the resources required for threat hunting.
- You do not have access to an effective threat hunting capability.
- Your threat hunts do not follow any structure and few if any records are created.
Partially achieved - All the following statements are true:
- You have identified the resources required to perform threat hunting and are able to deploy these, in a timely manner, on an occasional basis.
- You deploy an effective threat hunting capability but not frequent enough to match the risks posed to network and information systems supporting your essential function(s) (e.g. you perform threat hunts in response to a tip off from a reputable source).
- Your threat hunts follow pre-determined and documented methods (e.g. hypothesis driven, data driven, entity driven) designed to identify adverse activity not detected by automated detections.
- You document details of threat hunts and post hunt analysis.
Achieved - All the following statements are true:
- You understand the resources required to perform threat hunting and these are deployed as part of business as usual.
- You deploy threat hunting resources at a frequency that matches the risks posed to network and information systems supporting your essential function(s).
- Your threat hunts follow pre-determined and documented methods (e.g. hypothesis driven, data driven, entity driven) designed to identify adverse activity not detected by automated detections.
- You turn threat hunts into automated detections and alerting where appropriate.
- You routinely record details of previous threat hunts and post hunt activities. You use these to drive improvements in your threat hunting and security posture.
- You have justified confidence in the effectiveness of your threat hunts and the threat hunting process is reviewed and updated to match the risks posed to network and information systems supporting your essential function(s).
- You leverage automation to improve threat hunts where appropriate (e.g. some stages of the threat hunting process are automated).
- Your threat hunts focus on the tactics, techniques and procedures (TTPs) of threats over atomic IoCs (e.g. hashes, IP addresses, domain names etc).
There are well-defined and tested incident management processes in place, that aim to ensure continuity of essential function(s) in the event of system or service failure. Mitigation activities designed to contain or limit the impact of compromise are also in place.
Description
error determining description
Guidance
The 10 Steps to Cyber Security: Incident Management has concise guidance, but organisations should use other more detailed guidance as and when appropriate. Other authoritative guidance pieces are referenced below.
In addition to meeting the expectations of 10 Steps to Cyber Security, you should ensure that your organisation's incident response plans are grounded in thorough and comprehensive risk assessments. Response plans should prioritise essential functions along with the assets and systems that are required to ensure their continued effective operation, such as operational technologies, or key datasets.
The business continuity implications of any compromise should also be taken into account and your cyber incident response plans should link to other business response functions. You should form a cyber response team that is capable of implementing the plan, with the appropriate skills, tools and reach into other parts of your organisation, such as security monitoring and business continuity.
In practice, the Incident Response function should interoperate with the security monitoring function. The Incident Response function needn't be a dedicated team and some members may have non-response related roles. Collectively, the team should have knowledge of IT security, IT infrastructure and Business Management, any specialist technologies (e.g. Operational Technologies or datacentres), incident reporting requirements, and communications plans.
Your plan should cover all relevant potential incidents. It should be auditable and testable (
via exercises
) across a range of incident scenarios and should encompass all realistic descriptions of what might constitute an incident and its severity. Your test scenarios should draw on threat intelligence, past incidents, exercises and the ways in which security capabilities (e.g. security monitoring and alerting) would feature in your response options. Your scenarios should also consider incidents that involve suppliers and your wider supply chain e.g. incidents arising through supplier relations or relying on suppliers as part of your response.
These scenarios could include, but is not limited to:
The scenarios should be incorporated into exercises, which should be run to test your ability to respond to incidents that could affect the operation of essential functions. These exercises should reflect past experience, red-teaming/scenario planning, or threat intelligence and should draw heavily on your risk assessment, considering all relevant assets and vulnerabilities, especially where they relate to essential functions.
Exercises should record lessons learned, covering governance, roles and internal communication, quality of network and security monitoring data, containment and recovery strategies, or any other factors relevant to their effectiveness. This should integrate with lessons learned activities (see
Principle D2 Lessons Learned
).
Your plans should work seamlessly with other system management and security functions. Changes and improvements to response plans should reflect changes to these functions and vice versa, where appropriate.
Plans should articulate clear governance frameworks and roles with procedures for reporting to relevant internal or external stakeholders, such as regulators and competent authorities.
Your plan should also set out a comprehensive range of containment, eradication and recovery strategies, specifying how and when they should be used.
Your organisation should be able to describe its own state of readiness, using any criteria or expected standards from regulators or competent authorities, or from your internal governance arrangements, where appropriate.
In order to report coherently on incidents when required, your plan should set out reporting thresholds (i.e. what does and does not need to be reported) and standards (i.e. the level of detail that should be reported) and which authorities to report to.
More detailed guidance on developing an incident response plan, and the underlying capability to implement it, can be found in the
NIST Computer Security Incident Handling Guide
, CREST publications (see references) or
ISO/IEC 27035-1
.
Contributing Outcomes
D1.a Response Plan
- You have an up-to-date incident response plan that is grounded in a thorough risk assessment that takes account of network and information systems supporting the operation of your essential function(s) and covers a range of incident scenarios.
- You have an up-to-date incident response plan that is grounded in a thorough risk assessment that takes account of network and information systems supporting the operation of your essential function(s) and covers a range of incident scenarios.
- Your incident response plan is not documented.
- Your incident response plan does not include your organisations identified essential function(s).
- Your incident response plan is not well understood by relevant staff.
- Your incident response plan covers network and information systems supporting your essential function(s).
- Your incident response plan comprehensively covers scenarios that are focused on likely impacts of known and well understood attacks only.
- Your incident response plan is understood by all staff who are involved with your organisation's response function.
- Your incident response plan is documented and shared with all relevant stakeholders.
- Your incident response plan is readily accessible, even when your organisations IT systems have been adversely affected by an incident.
- Your incident response plan is regularly reviewed to ensure it remains effective.
- Your incident response plan is based on a clear understanding of the security risks to the network and information systems supporting your essential function(s).
- Your incident response plan is comprehensive (i.e. covers the complete lifecycle of an incident, roles and responsibilities, and reporting) and covers likely impacts of both known attack patterns and of possible attacks, previously unseen.
- Your incident response plan is documented and integrated with wider organisational business plans and supply chain response plans as well as dependencies on supporting infrastructure (e.g. power, cooling etc).
- Your incident response plan is communicated and understood by the business areas involved with the operation of your essential function(s).
Not achieved - At least one of the following is true:
- Your incident response plan is not documented.
- Your incident response plan does not include your organisations identified essential function(s).
- Your incident response plan is not well understood by relevant staff.
Partially Achieved - All the following statements are true:
- Your incident response plan covers network and information systems supporting your essential function(s).
- Your incident response plan comprehensively covers scenarios that are focused on likely impacts of known and well understood attacks only.
- Your incident response plan is understood by all staff who are involved with your organisation's response function.
- Your incident response plan is documented and shared with all relevant stakeholders.
- Your incident response plan is readily accessible, even when your organisations IT systems have been adversely affected by an incident.
- Your incident response plan is regularly reviewed to ensure it remains effective.
Achieved - All the following statements are true:
- Your incident response plan is based on a clear understanding of the security risks to the network and information systems supporting your essential function(s).
- Your incident response plan is comprehensive (i.e. covers the complete lifecycle of an incident, roles and responsibilities, and reporting) and covers likely impacts of both known attack patterns and of possible attacks, previously unseen.
- Your incident response plan is documented and integrated with wider organisational business plans and supply chain response plans as well as dependencies on supporting infrastructure (e.g. power, cooling etc).
- Your incident response plan is communicated and understood by the business areas involved with the operation of your essential function(s).
D1.b Response and Recovery Capability
- You have the capability to enact your incident response plan, including effective limitation of impact on the operation of your essential function(s). During an incident, you have access to timely information on which to base your response decisions.
- You have the capability to enact your incident response plan, including effective limitation of impact on the operation of your essential function(s). During an incident, you have access to timely information on which to base your response decisions.
- Inadequate arrangements have been made to make the right resources available to implement your response plan.
- Your response team members are not equipped to make good response decisions and put them into effect.
- Inadequate back-up mechanisms exist to allow the continued operation of your essential function(s) during an incident.
- You understand the resources that will likely be needed to carry out any required response activities, and arrangements are in place to make these resources available.
- You understand the types of information that will likely be needed to inform response decisions and arrangements are in place to make this information available.
- Your response team members have the skills and knowledge required to decide on the response actions necessary to limit harm, and the authority to carry them out.
- Key roles are duplicated, and operational delivery knowledge is shared with all individuals involved in the operations and recovery of the essential function(s).
- Back-up mechanisms are available that can be readily activated to allow continued operation of your essential function(s), although possibly at a reduced level, if primary network and information systems fail or are unavailable.
- Arrangements exist to augment your organisation’s incident response capabilities with external support if necessary (e.g. specialist cyber incident responders).
Not Achieved - At least one of the following is true:
- Inadequate arrangements have been made to make the right resources available to implement your response plan.
- Your response team members are not equipped to make good response decisions and put them into effect.
- Inadequate back-up mechanisms exist to allow the continued operation of your essential function(s) during an incident.
Achieved - All the following statements are true:
- You understand the resources that will likely be needed to carry out any required response activities, and arrangements are in place to make these resources available.
- You understand the types of information that will likely be needed to inform response decisions and arrangements are in place to make this information available.
- Your response team members have the skills and knowledge required to decide on the response actions necessary to limit harm, and the authority to carry them out.
- Key roles are duplicated, and operational delivery knowledge is shared with all individuals involved in the operations and recovery of the essential function(s).
- Back-up mechanisms are available that can be readily activated to allow continued operation of your essential function(s), although possibly at a reduced level, if primary network and information systems fail or are unavailable.
- Arrangements exist to augment your organisation’s incident response capabilities with external support if necessary (e.g. specialist cyber incident responders).
D1.c Testing and Exercising
- Your organisation carries out exercises to test response plans, using past incidents that affected your (and other) organisation, and scenarios that draw on threat intelligence and your risk assessment.
- Your organisation carries out exercises to test response plans, using past incidents that affected your (and other) organisation, and scenarios that draw on threat intelligence and your risk assessment.
- Exercises test only a discrete part of the process (e.g. that backups are working), but do not consider all areas.
- Incident response exercises are not routinely carried out or are carried out in an ad-hoc way.
- Outputs from exercises are not fed into the organisation's lessons learned process.
- Exercises do not test all parts of the response cycle.
- Exercise scenarios are based on incidents experienced by your and other organisations or are composed using experience or threat intelligence.
- Exercise scenarios are documented, regularly reviewed, and validated.
- Exercises are routinely run, with the findings documented and used to refine incident response plans and protective security, in line with the lessons learned.
- Exercises test all parts of your response cycle relating to your essential function(s) (e.g. restoration of normal function(s) levels).
Not Achieved - At least one of the following is true:
- Exercises test only a discrete part of the process (e.g. that backups are working), but do not consider all areas.
- Incident response exercises are not routinely carried out or are carried out in an ad-hoc way.
- Outputs from exercises are not fed into the organisation's lessons learned process.
- Exercises do not test all parts of the response cycle.
Achieved - All the following statements are true:
- Exercise scenarios are based on incidents experienced by your and other organisations or are composed using experience or threat intelligence.
- Exercise scenarios are documented, regularly reviewed, and validated.
- Exercises are routinely run, with the findings documented and used to refine incident response plans and protective security, in line with the lessons learned.
- Exercises test all parts of your response cycle relating to your essential function(s) (e.g. restoration of normal function(s) levels).
When an incident occurs, steps are taken to understand its causes and to ensure remediating action is taken to protect against future incidents.
Description
error determining description
Guidance
You should use the guidance points below to learn lessons and address shortfalls in:
your overall protective security (see
Objectives A - C
) and
your incident response plan (see
Response and Recovery Planning
)
your overall protective security (see
Objectives A - C
) and
Contributing Outcomes
D2.a Post Incident Analysis
- When an incident occurs, your organisation takes steps to understand its causes, informing appropriate remediating action.
- When an incident occurs, your organisation takes steps to understand its causes, informing appropriate remediating action.
- You are not usually able to resolve incidents to a root cause or identify the contributing factors within a broader systems context.
- You do not have a formal process for investigating causes.
- Investigators form theories early in the process and only seek evidence that affirms their belief.
- Investigations are solely focused on identifying the person(s) who can be held responsible for the incident.
- Post incident analysis is conducted routinely as a key part of your lessons learned activities following an incident.
- Your post incident analysis is comprehensive, considering organisational factors (e.g. policies, processes and procedures), technical factors (e.g. system design, vulnerabilities), human factors (e.g. training, security culture) and any changes to threat.
- All relevant incident data is made available to the analysis team to perform post incident analysis.
- Your analysis considers what could have happened under plausible, alternative circumstances (e.g. ‘what if’ / ’if only’ scenarios).
Not Achieved - At least one of the following statements is true:
- You are not usually able to resolve incidents to a root cause or identify the contributing factors within a broader systems context.
- You do not have a formal process for investigating causes.
- Investigators form theories early in the process and only seek evidence that affirms their belief.
- Investigations are solely focused on identifying the person(s) who can be held responsible for the incident.
Achieved - All the following statements are true:
- Post incident analysis is conducted routinely as a key part of your lessons learned activities following an incident.
- Your post incident analysis is comprehensive, considering organisational factors (e.g. policies, processes and procedures), technical factors (e.g. system design, vulnerabilities), human factors (e.g. training, security culture) and any changes to threat.
- All relevant incident data is made available to the analysis team to perform post incident analysis.
- Your analysis considers what could have happened under plausible, alternative circumstances (e.g. ‘what if’ / ’if only’ scenarios).
D2.b Using Incidents to Drive Improvements
- Your organisation uses lessons learned from incidents to improve your security measures.
- Your organisation uses lessons learned from incidents to improve your security measures.
- Improvements arising from lessons learned following an incident are not implemented or not given sufficient organisational priority.
- Changes are made as a ‘knee jerk’ reaction to an incident without proper analysis and testing to ensure the change is appropriate.
- You wait until a severe or high-profile incident has occurred before you take steps to improve.
- You have a documented incident review process / policy which ensures that lessons learned from each incident, including near misses, are identified, captured, and acted upon.
- Lessons learned cover issues with reporting, roles, governance, skills and organisational policies, processes and procedures as well as technical aspects of network and information systems.
- You use lessons learned to improve security measures, including updating and retesting response plans when necessary.
- Security improvements identified as a result of lessons learned are prioritised, with the highest priority improvements completed promptly.
- Analysis is fed to senior management and incorporated into risk management and continuous improvement.
- Your organisation maximises the lessons learned by using the analysis into ‘what if’ / ’if only’ scenarios.
- Your organisation learns from reported incidents in your sector and the wider national infrastructure.
Not Achieved - At least one of the following is true:
- Improvements arising from lessons learned following an incident are not implemented or not given sufficient organisational priority.
- Changes are made as a ‘knee jerk’ reaction to an incident without proper analysis and testing to ensure the change is appropriate.
- You wait until a severe or high-profile incident has occurred before you take steps to improve.
Achieved - All the following statements are true:
- You have a documented incident review process / policy which ensures that lessons learned from each incident, including near misses, are identified, captured, and acted upon.
- Lessons learned cover issues with reporting, roles, governance, skills and organisational policies, processes and procedures as well as technical aspects of network and information systems.
- You use lessons learned to improve security measures, including updating and retesting response plans when necessary.
- Security improvements identified as a result of lessons learned are prioritised, with the highest priority improvements completed promptly.
- Analysis is fed to senior management and incorporated into risk management and continuous improvement.
- Your organisation maximises the lessons learned by using the analysis into ‘what if’ / ’if only’ scenarios.
- Your organisation learns from reported incidents in your sector and the wider national infrastructure.
Principles
The organisation has appropriate management policies, processes and procedures in place to govern its approach to the security of network and information systems.
Description
error determining description
Guidance
Your organisation's approach to security governance needs to be an appropriate fit for your organisation. Good security governance is integrated with your business's usual decision making structures and processes.
Decisions about risk can be made at all levels of your organisation when delegated effectively to people with the right security, business and technical knowledge, skills and experience. Clear lines of communication are also necessary.
Contributing Outcomes
A1.a Board Direction
- You have effective organisational security management led at board level and articulated clearly in corresponding policies.
- You have effective organisational security management led at board level and articulated clearly in corresponding policies.
- The security of network and information systems related to the operation of essential function(s) is not discussed or reported on regularly at board-level.
- Board-level discussions on the security of network and information systems are based on partial or out-of-date information, without the benefit of expert guidance.
- The security of network and information systems supporting your essential function(s) are not driven effectively by the direction set at board-level.
- Senior management or other pockets of the organisation consider themselves exempt from some policies or expect special accommodations to be made.
- Your organisation's approach and policy relating to the security of network and information systems supporting the operation of essential function(s) are owned and managed at board-level. These are communicated, in a meaningful way, to risk management decision-makers across the organisation.
- Regular board-level discussions on the security of network and information systems supporting the operation of your essential function(s) take place, based on timely and accurate information and informed by expert guidance.
- There is a board-level individual who has overall accountability for the security of network and information systems and drives regular discussion at board-level.
- Direction set at board-level is translated into effective organisational practices that direct and control the security of the network and information systems supporting your essential functions(s).
- The board has the information and understanding needed in order to effectively discuss how the security and resilience of network and information systems contributes to the delivery of essential function(s) and what the potential impact from compromise of those systems would be.
- Security is recognised as an important enabler for the resilience of your essential function(s) and considered in all relevant discussions.
Not achieved - At least one of the following statements is true:
- The security of network and information systems related to the operation of essential function(s) is not discussed or reported on regularly at board-level.
- Board-level discussions on the security of network and information systems are based on partial or out-of-date information, without the benefit of expert guidance.
- The security of network and information systems supporting your essential function(s) are not driven effectively by the direction set at board-level.
- Senior management or other pockets of the organisation consider themselves exempt from some policies or expect special accommodations to be made.
Achieved - All the following statements are true:
- Your organisation's approach and policy relating to the security of network and information systems supporting the operation of essential function(s) are owned and managed at board-level. These are communicated, in a meaningful way, to risk management decision-makers across the organisation.
- Regular board-level discussions on the security of network and information systems supporting the operation of your essential function(s) take place, based on timely and accurate information and informed by expert guidance.
- There is a board-level individual who has overall accountability for the security of network and information systems and drives regular discussion at board-level.
- Direction set at board-level is translated into effective organisational practices that direct and control the security of the network and information systems supporting your essential functions(s).
- The board has the information and understanding needed in order to effectively discuss how the security and resilience of network and information systems contributes to the delivery of essential function(s) and what the potential impact from compromise of those systems would be.
- Security is recognised as an important enabler for the resilience of your essential function(s) and considered in all relevant discussions.
A1.b Roles and Responsibilities
- Your organisation has established roles and responsibilities for the security of network and information systems at all levels, with clear and well-understood channels for communicating and escalating risks.
- Your organisation has established roles and responsibilities for the security of network and information systems at all levels, with clear and well-understood channels for communicating and escalating risks.
- Key roles are missing, left vacant, or fulfilled on an ad-hoc or informal basis.
- Staff are assigned security responsibilities but without adequate authority or resources to fulfil them.
- Staff are unsure what their responsibilities are for the security of the essential function(s).
- Key roles and responsibilities for the security of network and information systems supporting your essential function(s) have been identified. These are reviewed regularly to ensure they remain fit for purpose.
- Appropriately capable and knowledgeable staff fill those roles and are given the time, authority, and resources to carry out their duties.
- There is clarity on who in your organisation has overall accountability for the security of the network and information systems supporting your essential function(s).
Not achieved - At least one of the following statements is true:
- Key roles are missing, left vacant, or fulfilled on an ad-hoc or informal basis.
- Staff are assigned security responsibilities but without adequate authority or resources to fulfil them.
- Staff are unsure what their responsibilities are for the security of the essential function(s).
Achieved - All the following statements are true:
- Key roles and responsibilities for the security of network and information systems supporting your essential function(s) have been identified. These are reviewed regularly to ensure they remain fit for purpose.
- Appropriately capable and knowledgeable staff fill those roles and are given the time, authority, and resources to carry out their duties.
- There is clarity on who in your organisation has overall accountability for the security of the network and information systems supporting your essential function(s).
A1.c Decision-making
- You have senior-level accountability for the security of network and information systems, and delegate decision-making authority appropriately and effectively. Risks to network and information systems related to the operation of the essential function(s) are considered in the context of other organisational risks
.
- You have senior-level accountability for the security of network and information systems, and delegate decision-making authority appropriately and effectively. Risks to network and information systems related to the operation of the essential function(s) are considered in the context of other organisational risks
- What should be relatively straightforward risk decisions are constantly referred up the chain, or not made.
- Risks are resolved informally (or ignored) at a local level when the use of a more formal risk reporting mechanism would be more appropriate.
- Decision-makers are unsure of what senior management's risk appetite is, or only understand it in vague terms such as "averse" or "cautious".
- Decision-makers are unable to justify their risk management decisions.
- Organisational structure causes risk decisions to be made in isolation. (e.g. engineering and IT don't talk to each other about risk).
- Risk priorities are too vague to make meaningful distinctions between them. (e.g. almost all risks are rated 'medium' or 'amber').
- Senior management have visibility of key risk decisions made throughout the organisation.
- Risk management decision-makers understand their responsibilities for making effective and timely decisions in the context of the risk appetite regarding the essential function(s), as set by senior management.
- Risk management decision-making is delegated and escalated where necessary, across the organisation, to people who have the skills, knowledge, tools and authority they need.
- Risk management decisions are regularly reviewed to ensure their continued relevance and validity.
Not achieved - At least one of the following statements is true:
- What should be relatively straightforward risk decisions are constantly referred up the chain, or not made.
- Risks are resolved informally (or ignored) at a local level when the use of a more formal risk reporting mechanism would be more appropriate.
- Decision-makers are unsure of what senior management's risk appetite is, or only understand it in vague terms such as "averse" or "cautious".
- Decision-makers are unable to justify their risk management decisions.
- Organisational structure causes risk decisions to be made in isolation. (e.g. engineering and IT don't talk to each other about risk).
- Risk priorities are too vague to make meaningful distinctions between them. (e.g. almost all risks are rated 'medium' or 'amber').
Achieved - All the following statements are true:
- Senior management have visibility of key risk decisions made throughout the organisation.
- Risk management decision-makers understand their responsibilities for making effective and timely decisions in the context of the risk appetite regarding the essential function(s), as set by senior management.
- Risk management decision-making is delegated and escalated where necessary, across the organisation, to people who have the skills, knowledge, tools and authority they need.
- Risk management decisions are regularly reviewed to ensure their continued relevance and validity.
The organisation takes appropriate steps to identify, assess and understand security risks to network and information systems supporting the operation of essential functions. This includes an overall organisational approach to risk management.
Description
error determining description
Guidance
Our
Risk Management guidance
aims to help you to choose an approach that's right for your organisation. Organisations responsible for essential functions are likely to benefit from a combination of a
system-based approach
, which looks at the interactions between components of the function, and a
component-driven analysis
, which considers the threats, vulnerabilities, and impacts relevant to particular critical components.
Your organisation should choose a method or framework for managing risk that fits with the organisation's business and technology needs.
Whichever approach you choose, the scope of your programme must include all systems relevant to the operation of essential functions. Simply following the minimum requirements of a standard or applying blanket controls across the organisation is unlikely to adequately manage risks to critical systems.
Where industrial control and automation systems are in scope of the essential function, you should keep in mind that controls suitable for managing risks on the corporate IT network may be inappropriate or damaging in an operational technology environment. These systems will likely require a more tailored approach, and some frameworks and standards address specific concerns relating to such systems.
Cyber threats continue to evolve and develop, putting each organisation’s operational continuity and services at significant risk. By identifying and understanding cyber threats, and the steps a threat actor may take to compromise systems supporting essential functions, an organisation can implement effective security measures to counter malicious attacks and breaches. Various methods can be used to better understand threat which are discussed in our
Risk Management guidance
.
Ultimately, a detailed understanding of current cyber threats helps organisations to mitigate risks, ensuring the security and resilience of network and information systems in an increasingly hostile world.
Various means are available to gain confidence in the effectiveness of the security of technologies, processes and people. The NCSC Risk Management guidance discusses
how to gain and maintain assurance
in your risk treatments.
The NCSC assurance guidance provides some examples that may be useful to understand cyber security confidence in your organisation and there are some specific technical NCSC guides:
The
NCSC Penetration guidance
will help you understand the proper use and commissioning of penetration tests to gain assurance in the security of an IT system.
Our
Cloud Security collection
provides guidance on managing the risks involved with using cloud services, and some of the principles and guidance are more broadly applicable. The cloud guidance for having confidence in cyber security provides principles that are useful for assuring cyber security of essential functions. The collection will be of particular interest if your organisation hosts any part of your essential function infrastructure on a cloud service.
The
NCSC Penetration guidance
will help you understand the proper use and commissioning of penetration tests to gain assurance in the security of an IT system.
Contributing Outcomes
A2.a Risk Management Process
- Your organisation has effective internal processes for managing risks to the security and resilience of network and information systems related to the operation of your essential function(s) and communicating associated activities.
- Your organisation has effective internal processes for managing risks to the security and resilience of network and information systems related to the operation of your essential function(s) and communicating associated activities.
- Risk assessments are not based on a clearly defined set of threat assumptions.
- Risk assessment outputs are too complex or unwieldy to be consumed by decision-makers and are not effectively communicated in a clear and timely manner.
- Risk assessments for network and information systems that support your essential function(s) are a "one-off" activity or not done at all.
- The security elements of projects or programmes are solely dependent on the completion of a risk management assessment without any regard to the outcomes.
- There is no systematic process in place to ensure that identified security risks are managed effectively.
- Systems are assessed in isolation, without consideration of dependencies and interactions with other systems. (e.g. interactions between IT and OT environments).
- Security requirements and mitigations are arbitrary or are applied from a control catalogue without consideration of how they contribute to the security of the essential function(s).
- Risks remain unresolved on a register for prolonged periods of time awaiting senior decision-making or resource allocation to resolve.
- Your organisational process ensures that security risks to network and information systems relevant to essential function(s) are identified, analysed, prioritised, and managed.
- Your risk assessments are informed by an understanding of the vulnerabilities in the network and information systems supporting your essential function(s).
- The output from your risk management process is a clear set of security requirements that will address the risks in line with your organisational approach to security.
- Significant conclusions reached in the course of your risk management process are communicated to key security decision-makers and accountable individuals.
- You conduct risk assessments when significant events potentially affect the essential function(s), such as replacing a system, introducing new or emergent technologies or a change in the cyber security threat.
- Your organisational process ensures that security risks to network and information systems relevant to essential function(s) are identified, analysed, prioritised, and managed.
- Your approach to risk is focused on the possibility of adverse impact to your essential function(s), leading to a detailed understanding of how such impact might arise as a consequence of possible attacker actions and the security properties of your network and information systems.
- Your risk assessments are based on a clearly understood set of threat assumptions, informed by an up-to-date understanding of security threats to your essential function(s) and your sector.
- Your risk assessments are informed by an understanding of the vulnerabilities in the network and information systems supporting your essential function(s).
- The output from your risk management process is a clear set of security requirements that will address the risks in line with your organisational approach to security.
- Significant conclusions reached in the course of your risk management process are communicated to key security decision-makers and accountable individuals.
- Your risk assessments are dynamic and updated in the light of relevant changes which may include technical changes to network and information systems, change of use and new threat information.
- The effectiveness of your risk management process is reviewed regularly, and improvements made as required.
- You anticipate technological developments that could be used to adversely impact network and information systems supporting your essential function(s).
Not achieved - At least one of the following statements is true:
- Risk assessments are not based on a clearly defined set of threat assumptions.
- Risk assessment outputs are too complex or unwieldy to be consumed by decision-makers and are not effectively communicated in a clear and timely manner.
- Risk assessments for network and information systems that support your essential function(s) are a "one-off" activity or not done at all.
- The security elements of projects or programmes are solely dependent on the completion of a risk management assessment without any regard to the outcomes.
- There is no systematic process in place to ensure that identified security risks are managed effectively.
- Systems are assessed in isolation, without consideration of dependencies and interactions with other systems. (e.g. interactions between IT and OT environments).
- Security requirements and mitigations are arbitrary or are applied from a control catalogue without consideration of how they contribute to the security of the essential function(s).
- Risks remain unresolved on a register for prolonged periods of time awaiting senior decision-making or resource allocation to resolve.
Partially achieved - All the following statements are true:
- Your organisational process ensures that security risks to network and information systems relevant to essential function(s) are identified, analysed, prioritised, and managed.
- Your risk assessments are informed by an understanding of the vulnerabilities in the network and information systems supporting your essential function(s).
- The output from your risk management process is a clear set of security requirements that will address the risks in line with your organisational approach to security.
- Significant conclusions reached in the course of your risk management process are communicated to key security decision-makers and accountable individuals.
- You conduct risk assessments when significant events potentially affect the essential function(s), such as replacing a system, introducing new or emergent technologies or a change in the cyber security threat.
Achieved - All the following statements are true:
- Your organisational process ensures that security risks to network and information systems relevant to essential function(s) are identified, analysed, prioritised, and managed.
- Your approach to risk is focused on the possibility of adverse impact to your essential function(s), leading to a detailed understanding of how such impact might arise as a consequence of possible attacker actions and the security properties of your network and information systems.
- Your risk assessments are based on a clearly understood set of threat assumptions, informed by an up-to-date understanding of security threats to your essential function(s) and your sector.
- Your risk assessments are informed by an understanding of the vulnerabilities in the network and information systems supporting your essential function(s).
- The output from your risk management process is a clear set of security requirements that will address the risks in line with your organisational approach to security.
- Significant conclusions reached in the course of your risk management process are communicated to key security decision-makers and accountable individuals.
- Your risk assessments are dynamic and updated in the light of relevant changes which may include technical changes to network and information systems, change of use and new threat information.
- The effectiveness of your risk management process is reviewed regularly, and improvements made as required.
- You anticipate technological developments that could be used to adversely impact network and information systems supporting your essential function(s).
A2.b Understanding Threat
- You understand the capabilities, methods and techniques of threat actors and what network and information systems they may compromise to adversely impact your essential function(s). This information is used to inform security and resilience risk management decisions, adjusting, enhancing or adding security measures to better defend against threats.
- You understand the capabilities, methods and techniques of threat actors and what network and information systems they may compromise to adversely impact your essential function(s). This information is used to inform security and resilience risk management decisions, adjusting, enhancing or adding security measures to better defend against threats.
- You are unable to perform threat analysis.
- You do not understand the threats to network and information systems supporting your essential function(s).
- You do not have a clearly defined set of threat assumptions.
- You do not use your understanding of threat to inform your risk management decisions.
- You perform threat analysis and understand how common threats apply to network and information systems supporting your essential function(s).
- You understand common types of cyber attacks, including the methods and techniques, and how these might apply to network and information systems supporting your essential function(s). This understanding is kept up to date.
- You anticipate what threat actors might target in network and information systems to cause an adverse impact to your essential function(s).
- Your understanding of threat is informed by common incidents.
- You apply your understanding of threat to inform your risk management decision-making.
- You perform detailed threat analysis and understand how this applies to network and information systems supporting your essential function(s), in the context of your sector and wider national infrastructure.
- Your detailed understanding of threat includes the methods and techniques available to capable and well-resourced threat actors and how they could be used systematically against network and information systems supporting your essential function(s).
- You use appropriate techniques to develop an understanding of network and information systems supporting your essential function(s) from a threat actor’s perspective. You anticipate probable attack methods and techniques, targets and objectives, and develop plausible scenarios.
- You understand the different steps a capable and well-resourced threat actor would need to take to reach the probable target(s).
- You identify and justify what measures can be used at each step to reduce the likelihood of the threat actor reaching the probable target(s) or achieving their objective(s).
- You maintain a detailed understanding of current threats (e.g. by threat intelligence and proactive research).
- You apply your detailed understanding of threat to inform your risk management decision-making.
- You have documented the steps required to undertake detailed threat analysis.
Not achieved - At least one of the following statements is true:
- You are unable to perform threat analysis.
- You do not understand the threats to network and information systems supporting your essential function(s).
- You do not have a clearly defined set of threat assumptions.
- You do not use your understanding of threat to inform your risk management decisions.
Partially achieved - All the following statements are true:
- You perform threat analysis and understand how common threats apply to network and information systems supporting your essential function(s).
- You understand common types of cyber attacks, including the methods and techniques, and how these might apply to network and information systems supporting your essential function(s). This understanding is kept up to date.
- You anticipate what threat actors might target in network and information systems to cause an adverse impact to your essential function(s).
- Your understanding of threat is informed by common incidents.
- You apply your understanding of threat to inform your risk management decision-making.
Achieved - All the following statements are true:
- You perform detailed threat analysis and understand how this applies to network and information systems supporting your essential function(s), in the context of your sector and wider national infrastructure.
- Your detailed understanding of threat includes the methods and techniques available to capable and well-resourced threat actors and how they could be used systematically against network and information systems supporting your essential function(s).
- You use appropriate techniques to develop an understanding of network and information systems supporting your essential function(s) from a threat actor’s perspective. You anticipate probable attack methods and techniques, targets and objectives, and develop plausible scenarios.
- You understand the different steps a capable and well-resourced threat actor would need to take to reach the probable target(s).
- You identify and justify what measures can be used at each step to reduce the likelihood of the threat actor reaching the probable target(s) or achieving their objective(s).
- You maintain a detailed understanding of current threats (e.g. by threat intelligence and proactive research).
- You apply your detailed understanding of threat to inform your risk management decision-making.
- You have documented the steps required to undertake detailed threat analysis.
A2.c Assurance
- You have gained confidence in the effectiveness of the security of your technology, people, and processes relevant to the operation of network and information systems supporting your essential function(s).
- You have gained confidence in the effectiveness of the security of your technology, people, and processes relevant to the operation of network and information systems supporting your essential function(s).
- A particular product or service is seen as a "silver bullet" and vendor claims are taken at face value.
- Assurance methods are applied without appreciation of their strengths and limitations, such as the risks of penetration testing in operational environments.
- Assurance is assumed because there have been no known problems to date.
- You validate that the security measures in place to protect the network and information systems are effective and remain effective for the lifetime over which they are needed.
- You understand the assurance methods available to you and choose appropriate methods to gain confidence in the security of essential function(s).
- Your confidence in the security as it relates to your technology, people, and processes can be justified to, and verified by, a third party.
- Security deficiencies uncovered by assurance activities are assessed, prioritised and remedied when necessary in a timely and effective way.
- The methods used for assurance are reviewed to ensure they are working as intended and remain the most appropriate method to use.
Not achieved - At least one of the following statements is true:
- A particular product or service is seen as a "silver bullet" and vendor claims are taken at face value.
- Assurance methods are applied without appreciation of their strengths and limitations, such as the risks of penetration testing in operational environments.
- Assurance is assumed because there have been no known problems to date.
Achieved - All the following statements are true:
- You validate that the security measures in place to protect the network and information systems are effective and remain effective for the lifetime over which they are needed.
- You understand the assurance methods available to you and choose appropriate methods to gain confidence in the security of essential function(s).
- Your confidence in the security as it relates to your technology, people, and processes can be justified to, and verified by, a third party.
- Security deficiencies uncovered by assurance activities are assessed, prioritised and remedied when necessary in a timely and effective way.
- The methods used for assurance are reviewed to ensure they are working as intended and remain the most appropriate method to use.
Everything required to deliver, maintain or support networks and information systems necessary for the operation of essential functions is determined and understood. This includes data, people and systems, as well as any supporting infrastructure (such as power or cooling).
Description
error determining description
Guidance
Whichever risk management method your organisation uses, asset management will play a key role as you cannot effectively manage risks without understanding what assets are part of the essential function. Your asset management regime should consider all relevant assets, and dependencies between them. Dependencies may be identified between assets under your organisation's control (including IT and OT domains), elements of the supply chain (including power), and key staff who are critical to operations. Assets in an operational technology environment may need a more tailored approach than the corporate IT assets.
For asset management to be effective, up to date knowledge of your assets must be maintained throughout their lifecycle.
Asset management is part of an ISO 27001 Information Security Management System (ISMS), but management of critical assets may require a tailored approach.
If your organisation is using an ISMS as a tool for compliance with cyber regulation, you must ensure the scope includes all systems relevant to the operation of the essential function covered by the regulation. Asset management is a key part of an ISMS, although critical services may need more attention than the minimum requirements of the standard.
This standard aligns with ISO 27001 and can be used in conjunction with it or independent of it. It outlines requirements for a generic asset management system. An organisation following this standard as a tool for compliance with cyber regulation must ensure the scope encompasses all the relevant systems. The standard covers needs and expectations of stakeholders, which must include any requirements from regulators.
ITIL is an IT service management framework that outlines best practices for delivering IT services. It recommends a staged approach to IT Asset Management (ITAM). You may find this useful for improving management of your IT assets, but must keep in mind that there may be assets and dependencies beyond the corporate IT domain as outlined above.
Asset management is part of an ISO 27001 Information Security Management System (ISMS), but management of critical assets may require a tailored approach.
If your organisation is using an ISMS as a tool for compliance with cyber regulation, you must ensure the scope includes all systems relevant to the operation of the essential function covered by the regulation. Asset management is a key part of an ISMS, although critical services may need more attention than the minimum requirements of the standard.
Contributing Outcomes
A3.a Asset Management
- Inventories of assets relevant to the essential function(s) are incomplete, non-existent, or inadequately detailed.
- Only certain domains or types of asset are documented and understood. Dependencies between assets are not understood (such as the dependencies between IT and OT).
- Information assets, which could include personally identifiable information and / or important / critical data, are stored for long periods of time with no clear business need or retention policy.
- Knowledge critical to the management, operation, or recovery of the essential function(s) is held by one or two key individuals with no succession plan.
- Asset inventories are neglected and out of date.
- All assets relevant to the secure operation of essential function(s) are identified and inventoried (at a suitable level of detail). The inventory is kept up-to-date.
- Dependencies on supporting infrastructure (e.g. power, cooling etc) are recognised and recorded.
- You have prioritised your assets according to their importance to the operation of the essential function(s).
- You have assigned responsibility for managing all assets, including physical assets, relevant to the operation of the essential function(s).
- Assets relevant to the essential function(s) are managed with cyber security in mind throughout their lifecycle, from creation through to eventual decommissioning or disposal.
Not achieved - At least one of the following statements is true:
- Inventories of assets relevant to the essential function(s) are incomplete, non-existent, or inadequately detailed.
- Only certain domains or types of asset are documented and understood. Dependencies between assets are not understood (such as the dependencies between IT and OT).
- Information assets, which could include personally identifiable information and / or important / critical data, are stored for long periods of time with no clear business need or retention policy.
- Knowledge critical to the management, operation, or recovery of the essential function(s) is held by one or two key individuals with no succession plan.
- Asset inventories are neglected and out of date.
Achieved - All the following statements are true:
- All assets relevant to the secure operation of essential function(s) are identified and inventoried (at a suitable level of detail). The inventory is kept up-to-date.
- Dependencies on supporting infrastructure (e.g. power, cooling etc) are recognised and recorded.
- You have prioritised your assets according to their importance to the operation of the essential function(s).
- You have assigned responsibility for managing all assets, including physical assets, relevant to the operation of the essential function(s).
- Assets relevant to the essential function(s) are managed with cyber security in mind throughout their lifecycle, from creation through to eventual decommissioning or disposal.
The organisation understands and manages security risks to networks and information systems supporting the operation of essential functions that arise as a result of dependencies on suppliers. This includes ensuring that appropriate measures are employed where third party services are used.
Description
error determining description
Guidance
Organisations responsible for essential functions need to ensure that when third party suppliers are used, all relevant security requirements are met. This means that a number of specific supply chain related security considerations should be addressed where relevant to the provision of the essential function. This might include:
Ensuring the protection of data shared with a third party. This includes protecting data from actions such as unauthorised access, modification, or deletion that may cause an adverse impact on any essential functions (see
Principle B3
).
Effective specification of the security properties of products or services procured from an external third party, or sourced internally from another part of the organisation, that are important for the protection of the essential function. This should include the security requirements derived from the rest of these Principles.
Ensure that any network connections or data sharing with third parties do not introduce unmanaged vulnerabilities that have the potential to affect the security of the essential function.
Confidence that third party suppliers are trustworthy such that malicious attempts to subvert the security of products or systems that could affect the essential function are managed.
Ensuring the protection of data shared with a third party. This includes protecting data from actions such as unauthorised access, modification, or deletion that may cause an adverse impact on any essential functions (see
Principle B3
).
Contributing Outcomes
A4.a Supply Chain
- You understand and effectively manage the risks associated with suppliers to the security of network and information systems supporting the operation of your essential function(s).
- You understand and effectively manage the risks associated with suppliers to the security of network and information systems supporting the operation of your essential function(s).
- You do not know what data belonging to you is held by suppliers, or how it is managed.
- Elements of the supply chain for essential function(s) are subcontracted and you have little or no visibility of the sub-contractors.
- You have no understanding of which contracts are relevant and / or relevant contracts do not specify appropriate security obligations.
- Suppliers have access to systems that provide your essential function(s) that is unrestricted, not monitored or bypasses your own security controls.
- You understand the general risks suppliers may pose to your essential function(s).
- You know the extent of your supply chain that supports your essential function(s), including sub-contractors.
- Suppliers to network and information systems that support your essential function(s) can demonstrate appropriate and proportionate levels of cyber security within the context of common threats.
- You understand which contracts are relevant and you include appropriate security obligations in relevant contracts.
- You are aware of all third-party connections and have assurance that they meet your organisation’s security requirements.
- Your approach to security incident management considers incidents that might arise in your supply chain.
- You have confidence that information shared with suppliers that is necessary for the operation of your essential function(s) is appropriately protected from common threats.
- You have a deep understanding of your supply chain, including sub-contractors and the wider risks it faces.
- You consider factors such as your supplier’s ownership, nationality, partnerships, competitors, other organisations with which they sub-contract and their approach to cyber security. These factors inform your risk assessment and are fully considered in your procurement lifecycle processes and purchasing decisions.
- Your approach to supply chain risk management considers the risks to network and information systems supporting your essential function(s) arising from supply chain subversion by capable and well-resourced threat actors.
- Critical suppliers to network and information systems supporting your essential functions(s) can demonstrate appropriate and proportionate levels of cyber security within the context of capable and well-resourced threat actors.
- You have confidence that information held by suppliers that is essential to the operation of network and information systems supporting your essential function(s) is appropriately protected from capable and well-resourced threat actors.
- You understand which contracts are relevant and you include appropriate security obligations, in relevant contracts.
- You have a proactive approach to contract management which may include a contract management plan for relevant contracts.
- Customer / supplier ownership of responsibilities is defined in contracts.
- All network connections and data sharing with third parties are managed effectively and proportionately.
- When appropriate, your incident management process and that of your suppliers provide mutual support in the resolution of incidents.
Not achieved - At least one of the following statements is true:
- You do not know what data belonging to you is held by suppliers, or how it is managed.
- Elements of the supply chain for essential function(s) are subcontracted and you have little or no visibility of the sub-contractors.
- You have no understanding of which contracts are relevant and / or relevant contracts do not specify appropriate security obligations.
- Suppliers have access to systems that provide your essential function(s) that is unrestricted, not monitored or bypasses your own security controls.
Partially achieved - All the following statements are true:
- You understand the general risks suppliers may pose to your essential function(s).
- You know the extent of your supply chain that supports your essential function(s), including sub-contractors.
- Suppliers to network and information systems that support your essential function(s) can demonstrate appropriate and proportionate levels of cyber security within the context of common threats.
- You understand which contracts are relevant and you include appropriate security obligations in relevant contracts.
- You are aware of all third-party connections and have assurance that they meet your organisation’s security requirements.
- Your approach to security incident management considers incidents that might arise in your supply chain.
- You have confidence that information shared with suppliers that is necessary for the operation of your essential function(s) is appropriately protected from common threats.
Achieved - All the following statements are true:
- You have a deep understanding of your supply chain, including sub-contractors and the wider risks it faces.
- You consider factors such as your supplier’s ownership, nationality, partnerships, competitors, other organisations with which they sub-contract and their approach to cyber security. These factors inform your risk assessment and are fully considered in your procurement lifecycle processes and purchasing decisions.
- Your approach to supply chain risk management considers the risks to network and information systems supporting your essential function(s) arising from supply chain subversion by capable and well-resourced threat actors.
- Critical suppliers to network and information systems supporting your essential functions(s) can demonstrate appropriate and proportionate levels of cyber security within the context of capable and well-resourced threat actors.
- You have confidence that information held by suppliers that is essential to the operation of network and information systems supporting your essential function(s) is appropriately protected from capable and well-resourced threat actors.
- You understand which contracts are relevant and you include appropriate security obligations, in relevant contracts.
- You have a proactive approach to contract management which may include a contract management plan for relevant contracts.
- Customer / supplier ownership of responsibilities is defined in contracts.
- All network connections and data sharing with third parties are managed effectively and proportionately.
- When appropriate, your incident management process and that of your suppliers provide mutual support in the resolution of incidents.
A4.b Secure Software Development and Support
- You actively maximise the use of secure and supported software, whether developed internally or sourced externally, within network and information systems supporting the operation of your essential function(s).
- You actively maximise the use of secure and supported software, whether developed internally or sourced externally, within network and information systems supporting the operation of your essential function(s).
- Your software supplier(s) is unaware of the composition and provenance of software provided to you.
- Software, including updates and patches, undergoes little to no testing.
- Updates and patches often introduce new problems or fail to address existing issues.
- Vulnerabilities are discovered in software despite the negligible difficulty of implementing mitigations.
- Your software supplier leverages secure development principles and practices.
- Your software supplier(s) can demonstrate a limited understanding of the composition and provenance of software provided to you.
- You consider the security of environments (e.g. development, test and production), including source code and repositories, used in the production of software to be appropriate and proportionate within the context of common threats.
- The testing regime uses a range of different approaches (e.g. static and dynamic analysis, unit and integration testing and point in time assessments) that verify all aspects of the development lifecycle covering both functional and non-functional testing.
- You have arrangements in place with your software supplier to receive timely security updates, patches and notifications.
- Software, including updates and patches, is obtained from your supplier(s) via secure channels.
- Your software supplier(s) has processes in place to identify, report and mitigate security vulnerabilities.
- You have arrangements in place with your software supplier to be notified of any significant events that may adversely impact network and information systems supporting your essential function(s).
- If open-source software is used, you have taken appropriate and proportionate steps to establish and maintain sufficient confidence in its security for its use.
- You have appropriate support and maintenance arrangements in place.
- Your software supplier(s) leverages an established secure software development framework (e.g. NIST Secure Software Development Framework (SSDF), Microsoft Secure Development Lifecycle (SDL)).
- Your software supplier can demonstrate a thorough understanding of the composition and provenance of software provided to you, including any third-party components used in the development of that software, and those components are being monitored for new vulnerabilities throughout the lifespan of the product.
- You consider the security of environments (e.g. development, test, and production), including source code and repositories, used in the production of software to be appropriate and proportionate within the context of capable and well-resourced threat actors.
- The software development lifecycle is informed by a detailed and up to date understanding of threat and applies appropriate techniques, such as threat modelling, to identify and assess potential vulnerabilities and attack vectors.
- You can attest to the authenticity and integrity of software, including updates and patches.
Not achieved - At least one of the following statements is true:
- Your software supplier(s) is unaware of the composition and provenance of software provided to you.
- Software, including updates and patches, undergoes little to no testing.
- Updates and patches often introduce new problems or fail to address existing issues.
- Vulnerabilities are discovered in software despite the negligible difficulty of implementing mitigations.
Partially achieved - All the following statements are true:
- Your software supplier leverages secure development principles and practices.
- Your software supplier(s) can demonstrate a limited understanding of the composition and provenance of software provided to you.
- You consider the security of environments (e.g. development, test and production), including source code and repositories, used in the production of software to be appropriate and proportionate within the context of common threats.
- The testing regime uses a range of different approaches (e.g. static and dynamic analysis, unit and integration testing and point in time assessments) that verify all aspects of the development lifecycle covering both functional and non-functional testing.
- You have arrangements in place with your software supplier to receive timely security updates, patches and notifications.
- Software, including updates and patches, is obtained from your supplier(s) via secure channels.
- Your software supplier(s) has processes in place to identify, report and mitigate security vulnerabilities.
- You have arrangements in place with your software supplier to be notified of any significant events that may adversely impact network and information systems supporting your essential function(s).
- If open-source software is used, you have taken appropriate and proportionate steps to establish and maintain sufficient confidence in its security for its use.
- You have appropriate support and maintenance arrangements in place.
Achieved - All the following statements are true:
- Your software supplier(s) leverages an established secure software development framework (e.g. NIST Secure Software Development Framework (SSDF), Microsoft Secure Development Lifecycle (SDL)).
- Your software supplier can demonstrate a thorough understanding of the composition and provenance of software provided to you, including any third-party components used in the development of that software, and those components are being monitored for new vulnerabilities throughout the lifespan of the product.
- You consider the security of environments (e.g. development, test, and production), including source code and repositories, used in the production of software to be appropriate and proportionate within the context of capable and well-resourced threat actors.
- The software development lifecycle is informed by a detailed and up to date understanding of threat and applies appropriate techniques, such as threat modelling, to identify and assess potential vulnerabilities and attack vectors.
- You can attest to the authenticity and integrity of software, including updates and patches.
The organisation understands and manages security risks to networks and information systems supporting the operation of essential functions that arise as a result of dependencies on suppliers. This includes ensuring that appropriate measures are employed where third party services are used.
Description
error determining description
Guidance
Organisations responsible for essential functions need to ensure that when third party suppliers are used, all relevant security requirements are met. This means that a number of specific supply chain related security considerations should be addressed where relevant to the provision of the essential function. This might include:
Ensuring the protection of data shared with a third party. This includes protecting data from actions such as unauthorised access, modification, or deletion that may cause an adverse impact on any essential functions (see
Principle B3
).
Effective specification of the security properties of products or services procured from an external third party, or sourced internally from another part of the organisation, that are important for the protection of the essential function. This should include the security requirements derived from the rest of these Principles.
Ensure that any network connections or data sharing with third parties do not introduce unmanaged vulnerabilities that have the potential to affect the security of the essential function.
Confidence that third party suppliers are trustworthy such that malicious attempts to subvert the security of products or systems that could affect the essential function are managed.
Ensuring the protection of data shared with a third party. This includes protecting data from actions such as unauthorised access, modification, or deletion that may cause an adverse impact on any essential functions (see
Principle B3
).
Contributing Outcomes
A4.a Supply Chain
- You understand and effectively manage the risks associated with suppliers to the security of network and information systems supporting the operation of your essential function(s).
- You understand and effectively manage the risks associated with suppliers to the security of network and information systems supporting the operation of your essential function(s).
- You do not know what data belonging to you is held by suppliers, or how it is managed.
- Elements of the supply chain for essential function(s) are subcontracted and you have little or no visibility of the sub-contractors.
- You have no understanding of which contracts are relevant and / or relevant contracts do not specify appropriate security obligations.
- Suppliers have access to systems that provide your essential function(s) that is unrestricted, not monitored or bypasses your own security controls.
- You understand the general risks suppliers may pose to your essential function(s).
- You know the extent of your supply chain that supports your essential function(s), including sub-contractors.
- Suppliers to network and information systems that support your essential function(s) can demonstrate appropriate and proportionate levels of cyber security within the context of common threats.
- You understand which contracts are relevant and you include appropriate security obligations in relevant contracts.
- You are aware of all third-party connections and have assurance that they meet your organisation’s security requirements.
- Your approach to security incident management considers incidents that might arise in your supply chain.
- You have confidence that information shared with suppliers that is necessary for the operation of your essential function(s) is appropriately protected from common threats.
- You have a deep understanding of your supply chain, including sub-contractors and the wider risks it faces.
- You consider factors such as your supplier’s ownership, nationality, partnerships, competitors, other organisations with which they sub-contract and their approach to cyber security. These factors inform your risk assessment and are fully considered in your procurement lifecycle processes and purchasing decisions.
- Your approach to supply chain risk management considers the risks to network and information systems supporting your essential function(s) arising from supply chain subversion by capable and well-resourced threat actors.
- Critical suppliers to network and information systems supporting your essential functions(s) can demonstrate appropriate and proportionate levels of cyber security within the context of capable and well-resourced threat actors.
- You have confidence that information held by suppliers that is essential to the operation of network and information systems supporting your essential function(s) is appropriately protected from capable and well-resourced threat actors.
- You understand which contracts are relevant and you include appropriate security obligations, in relevant contracts.
- You have a proactive approach to contract management which may include a contract management plan for relevant contracts.
- Customer / supplier ownership of responsibilities is defined in contracts.
- All network connections and data sharing with third parties are managed effectively and proportionately.
- When appropriate, your incident management process and that of your suppliers provide mutual support in the resolution of incidents.
Not achieved - At least one of the following statements is true:
- You do not know what data belonging to you is held by suppliers, or how it is managed.
- Elements of the supply chain for essential function(s) are subcontracted and you have little or no visibility of the sub-contractors.
- You have no understanding of which contracts are relevant and / or relevant contracts do not specify appropriate security obligations.
- Suppliers have access to systems that provide your essential function(s) that is unrestricted, not monitored or bypasses your own security controls.
Partially achieved - All the following statements are true:
- You understand the general risks suppliers may pose to your essential function(s).
- You know the extent of your supply chain that supports your essential function(s), including sub-contractors.
- Suppliers to network and information systems that support your essential function(s) can demonstrate appropriate and proportionate levels of cyber security within the context of common threats.
- You understand which contracts are relevant and you include appropriate security obligations in relevant contracts.
- You are aware of all third-party connections and have assurance that they meet your organisation’s security requirements.
- Your approach to security incident management considers incidents that might arise in your supply chain.
- You have confidence that information shared with suppliers that is necessary for the operation of your essential function(s) is appropriately protected from common threats.
Achieved - All the following statements are true:
- You have a deep understanding of your supply chain, including sub-contractors and the wider risks it faces.
- You consider factors such as your supplier’s ownership, nationality, partnerships, competitors, other organisations with which they sub-contract and their approach to cyber security. These factors inform your risk assessment and are fully considered in your procurement lifecycle processes and purchasing decisions.
- Your approach to supply chain risk management considers the risks to network and information systems supporting your essential function(s) arising from supply chain subversion by capable and well-resourced threat actors.
- Critical suppliers to network and information systems supporting your essential functions(s) can demonstrate appropriate and proportionate levels of cyber security within the context of capable and well-resourced threat actors.
- You have confidence that information held by suppliers that is essential to the operation of network and information systems supporting your essential function(s) is appropriately protected from capable and well-resourced threat actors.
- You understand which contracts are relevant and you include appropriate security obligations, in relevant contracts.
- You have a proactive approach to contract management which may include a contract management plan for relevant contracts.
- Customer / supplier ownership of responsibilities is defined in contracts.
- All network connections and data sharing with third parties are managed effectively and proportionately.
- When appropriate, your incident management process and that of your suppliers provide mutual support in the resolution of incidents.
A4.b Secure Software Development and Support
- You actively maximise the use of secure and supported software, whether developed internally or sourced externally, within network and information systems supporting the operation of your essential function(s).
- You actively maximise the use of secure and supported software, whether developed internally or sourced externally, within network and information systems supporting the operation of your essential function(s).
- Your software supplier(s) is unaware of the composition and provenance of software provided to you.
- Software, including updates and patches, undergoes little to no testing.
- Updates and patches often introduce new problems or fail to address existing issues.
- Vulnerabilities are discovered in software despite the negligible difficulty of implementing mitigations.
- Your software supplier leverages secure development principles and practices.
- Your software supplier(s) can demonstrate a limited understanding of the composition and provenance of software provided to you.
- You consider the security of environments (e.g. development, test and production), including source code and repositories, used in the production of software to be appropriate and proportionate within the context of common threats.
- The testing regime uses a range of different approaches (e.g. static and dynamic analysis, unit and integration testing and point in time assessments) that verify all aspects of the development lifecycle covering both functional and non-functional testing.
- You have arrangements in place with your software supplier to receive timely security updates, patches and notifications.
- Software, including updates and patches, is obtained from your supplier(s) via secure channels.
- Your software supplier(s) has processes in place to identify, report and mitigate security vulnerabilities.
- You have arrangements in place with your software supplier to be notified of any significant events that may adversely impact network and information systems supporting your essential function(s).
- If open-source software is used, you have taken appropriate and proportionate steps to establish and maintain sufficient confidence in its security for its use.
- You have appropriate support and maintenance arrangements in place.
- Your software supplier(s) leverages an established secure software development framework (e.g. NIST Secure Software Development Framework (SSDF), Microsoft Secure Development Lifecycle (SDL)).
- Your software supplier can demonstrate a thorough understanding of the composition and provenance of software provided to you, including any third-party components used in the development of that software, and those components are being monitored for new vulnerabilities throughout the lifespan of the product.
- You consider the security of environments (e.g. development, test, and production), including source code and repositories, used in the production of software to be appropriate and proportionate within the context of capable and well-resourced threat actors.
- The software development lifecycle is informed by a detailed and up to date understanding of threat and applies appropriate techniques, such as threat modelling, to identify and assess potential vulnerabilities and attack vectors.
- You can attest to the authenticity and integrity of software, including updates and patches.
Not achieved - At least one of the following statements is true:
- Your software supplier(s) is unaware of the composition and provenance of software provided to you.
- Software, including updates and patches, undergoes little to no testing.
- Updates and patches often introduce new problems or fail to address existing issues.
- Vulnerabilities are discovered in software despite the negligible difficulty of implementing mitigations.
Partially achieved - All the following statements are true:
- Your software supplier leverages secure development principles and practices.
- Your software supplier(s) can demonstrate a limited understanding of the composition and provenance of software provided to you.
- You consider the security of environments (e.g. development, test and production), including source code and repositories, used in the production of software to be appropriate and proportionate within the context of common threats.
- The testing regime uses a range of different approaches (e.g. static and dynamic analysis, unit and integration testing and point in time assessments) that verify all aspects of the development lifecycle covering both functional and non-functional testing.
- You have arrangements in place with your software supplier to receive timely security updates, patches and notifications.
- Software, including updates and patches, is obtained from your supplier(s) via secure channels.
- Your software supplier(s) has processes in place to identify, report and mitigate security vulnerabilities.
- You have arrangements in place with your software supplier to be notified of any significant events that may adversely impact network and information systems supporting your essential function(s).
- If open-source software is used, you have taken appropriate and proportionate steps to establish and maintain sufficient confidence in its security for its use.
- You have appropriate support and maintenance arrangements in place.
Achieved - All the following statements are true:
- Your software supplier(s) leverages an established secure software development framework (e.g. NIST Secure Software Development Framework (SSDF), Microsoft Secure Development Lifecycle (SDL)).
- Your software supplier can demonstrate a thorough understanding of the composition and provenance of software provided to you, including any third-party components used in the development of that software, and those components are being monitored for new vulnerabilities throughout the lifespan of the product.
- You consider the security of environments (e.g. development, test, and production), including source code and repositories, used in the production of software to be appropriate and proportionate within the context of capable and well-resourced threat actors.
- The software development lifecycle is informed by a detailed and up to date understanding of threat and applies appropriate techniques, such as threat modelling, to identify and assess potential vulnerabilities and attack vectors.
- You can attest to the authenticity and integrity of software, including updates and patches.
The organisation defines, implements, communicates and enforces appropriate policies, processes and procedures that direct its overall approach to securing systems and data that support the operation of essential functions.
Description
error determining description
Guidance
The policies, processes and procedures needed by an organisation depend upon its function and should integrate with the organisation’s approach to governance and risk management. Organisations responsible for essential functions should have a range of policies, processes and procedures, including:
An organisational security or service protection policy: endorsed by senior management, this high-level policy should include the organisation’s overarching approach to governing security and managing risks, the organisation’s aims and intents for security and what is of key concern.
Supporting policies, processes and procedures: contextual lower-level definitions controlling, directing and communicating organisational security practice.
Compliance policies and processes for sector regulations, standards, etc.: specific policies and processes appropriate to the compliance regime; these may be defined by the regulation, standard, etc. For example, to comply with ISO/IEC 27001, organisations should have in place certain security policies and procedures relevant to what the organisation does, how it does it, and what their ISO/IEC 27001 information security management system covers (see ISO/IEC 27002 for detail).
An organisational security or service protection policy: endorsed by senior management, this high-level policy should include the organisation’s overarching approach to governing security and managing risks, the organisation’s aims and intents for security and what is of key concern.
Contributing Outcomes
B1.a Policy, Process and Procedure Development
- You have developed and continue to improve a set of cyber security and resilience policies, processes and procedures that manage and mitigate the risk of adverse impact on your essential function(s).
- You have developed and continue to improve a set of cyber security and resilience policies, processes and procedures that manage and mitigate the risk of adverse impact on your essential function(s).
- Your policies, processes and procedures are absent or incomplete.
- Policies, processes and procedures are not applied universally or consistently.
- People often or routinely circumvent policies, processes and procedures to achieve business objectives.
- Your organisation’s security governance and risk management approach has no bearing on your policies, processes and procedures.
- System security is totally reliant on users' careful and consistent application of manual security processes.
- Policies, processes and procedures have not been reviewed in response to major changes (e.g. technology or regulatory framework), or within a suitable period.
- Policies, processes and procedures are not readily available to staff, too detailed to remember, or too hard to understand.
- Your policies, processes and procedures document your overarching security governance and risk management approach, technical security practice and specific regulatory compliance.
- You review and update policies, processes and procedures in response to major cyber security incidents.
- You fully document your overarching security governance and risk management approach, technical security practice and specific regulatory compliance.
- Cyber security is integrated and embedded throughout policies, processes and procedures and key performance indicators are reported to your executive management.
- Your organisation’s policies, processes and procedures are developed to be practical, usable and appropriate to mitigate the risk of adverse impact to network and information systems supporting your essential function(s).
- Policies, processes and procedures that rely on user behaviour are practical, appropriate and achievable.
- You review and update policies, processes and procedures at suitably regular intervals to ensure they remain relevant. This is in addition to reviews following a major cyber security incident.
- Any changes to the essential function(s) or the threat it faces triggers a review of policies, processes and procedures.
- Your systems are designed so that they remain secure even when user security policies, processes and procedures are not always followed.
Not achieved - At least one of the following statements is true:
- Your policies, processes and procedures are absent or incomplete.
- Policies, processes and procedures are not applied universally or consistently.
- People often or routinely circumvent policies, processes and procedures to achieve business objectives.
- Your organisation’s security governance and risk management approach has no bearing on your policies, processes and procedures.
- System security is totally reliant on users' careful and consistent application of manual security processes.
- Policies, processes and procedures have not been reviewed in response to major changes (e.g. technology or regulatory framework), or within a suitable period.
- Policies, processes and procedures are not readily available to staff, too detailed to remember, or too hard to understand.
Partially achieved - All the following statements are true:
- Your policies, processes and procedures document your overarching security governance and risk management approach, technical security practice and specific regulatory compliance.
- You review and update policies, processes and procedures in response to major cyber security incidents.
Achieved - All the following statements are true:
- You fully document your overarching security governance and risk management approach, technical security practice and specific regulatory compliance.
- Cyber security is integrated and embedded throughout policies, processes and procedures and key performance indicators are reported to your executive management.
- Your organisation’s policies, processes and procedures are developed to be practical, usable and appropriate to mitigate the risk of adverse impact to network and information systems supporting your essential function(s).
- Policies, processes and procedures that rely on user behaviour are practical, appropriate and achievable.
- You review and update policies, processes and procedures at suitably regular intervals to ensure they remain relevant. This is in addition to reviews following a major cyber security incident.
- Any changes to the essential function(s) or the threat it faces triggers a review of policies, processes and procedures.
- Your systems are designed so that they remain secure even when user security policies, processes and procedures are not always followed.
B1.b Policy, Process and Procedure Implementation
- You have successfully implemented your security policies, processes and procedures and can demonstrate the security benefits achieved.
- You have successfully implemented your security policies, processes and procedures and can demonstrate the security benefits achieved.
- Policies, processes and procedures are ignored or only partially followed.
- How your policies support the resilience of your essential function(s) is not well understood.
- Staff are unaware of their responsibilities under your policies, processes and procedures.
- You do not attempt to detect breaches of policies, processes and procedures.
- Policies, processes and procedures lack integration with other organisational policies, processes and procedures.
- Your policies, processes and procedures are not well communicated across your organisation.
- Most of your policies, processes and procedures are followed and their application is monitored.
- Your policies, processes and procedures are integrated with other organisational policies, processes and procedures, including HR assessments of individuals' trustworthiness.
- All staff are aware of their responsibilities under your policies, processes and procedures.
- All breaches of policies, processes and procedures with the potential to adversely impact the essential function(s) are fully investigated. Other breaches are tracked, assessed for trends and action is taken to understand and address.
- All your policies, processes and procedures are followed, their correct application and security effectiveness is evaluated.
- Your policies, processes and procedures are integrated with other organisational policies, processes and procedures, including HR assessments of individuals' trustworthiness.
- Your policies, processes and procedures are effectively and appropriately communicated across all levels of the organisation resulting in good staff awareness of their responsibilities.
- Appropriate action is taken to address all breaches of policies, processes and procedures with potential to adversely impact the essential function(s) including aggregated breaches.
Not achieved - At least one of the following statements is true:
- Policies, processes and procedures are ignored or only partially followed.
- How your policies support the resilience of your essential function(s) is not well understood.
- Staff are unaware of their responsibilities under your policies, processes and procedures.
- You do not attempt to detect breaches of policies, processes and procedures.
- Policies, processes and procedures lack integration with other organisational policies, processes and procedures.
- Your policies, processes and procedures are not well communicated across your organisation.
Partially achieved - All the following statements are true:
- Most of your policies, processes and procedures are followed and their application is monitored.
- Your policies, processes and procedures are integrated with other organisational policies, processes and procedures, including HR assessments of individuals' trustworthiness.
- All staff are aware of their responsibilities under your policies, processes and procedures.
- All breaches of policies, processes and procedures with the potential to adversely impact the essential function(s) are fully investigated. Other breaches are tracked, assessed for trends and action is taken to understand and address.
Achieved - All the following statements are true:
- All your policies, processes and procedures are followed, their correct application and security effectiveness is evaluated.
- Your policies, processes and procedures are integrated with other organisational policies, processes and procedures, including HR assessments of individuals' trustworthiness.
- Your policies, processes and procedures are effectively and appropriately communicated across all levels of the organisation resulting in good staff awareness of their responsibilities.
- Appropriate action is taken to address all breaches of policies, processes and procedures with potential to adversely impact the essential function(s) including aggregated breaches.
The organisation defines, implements, communicates and enforces appropriate policies, processes and procedures that direct its overall approach to securing systems and data that support the operation of essential functions.
Description
error determining description
Guidance
The policies, processes and procedures needed by an organisation depend upon its function and should integrate with the organisation’s approach to governance and risk management. Organisations responsible for essential functions should have a range of policies, processes and procedures, including:
An organisational security or service protection policy: endorsed by senior management, this high-level policy should include the organisation’s overarching approach to governing security and managing risks, the organisation’s aims and intents for security and what is of key concern.
Supporting policies, processes and procedures: contextual lower-level definitions controlling, directing and communicating organisational security practice.
Compliance policies and processes for sector regulations, standards, etc.: specific policies and processes appropriate to the compliance regime; these may be defined by the regulation, standard, etc. For example, to comply with ISO/IEC 27001, organisations should have in place certain security policies and procedures relevant to what the organisation does, how it does it, and what their ISO/IEC 27001 information security management system covers (see ISO/IEC 27002 for detail).
An organisational security or service protection policy: endorsed by senior management, this high-level policy should include the organisation’s overarching approach to governing security and managing risks, the organisation’s aims and intents for security and what is of key concern.
Contributing Outcomes
B1.a Policy, Process and Procedure Development
- You have developed and continue to improve a set of cyber security and resilience policies, processes and procedures that manage and mitigate the risk of adverse impact on your essential function(s).
- You have developed and continue to improve a set of cyber security and resilience policies, processes and procedures that manage and mitigate the risk of adverse impact on your essential function(s).
- Your policies, processes and procedures are absent or incomplete.
- Policies, processes and procedures are not applied universally or consistently.
- People often or routinely circumvent policies, processes and procedures to achieve business objectives.
- Your organisation’s security governance and risk management approach has no bearing on your policies, processes and procedures.
- System security is totally reliant on users' careful and consistent application of manual security processes.
- Policies, processes and procedures have not been reviewed in response to major changes (e.g. technology or regulatory framework), or within a suitable period.
- Policies, processes and procedures are not readily available to staff, too detailed to remember, or too hard to understand.
- Your policies, processes and procedures document your overarching security governance and risk management approach, technical security practice and specific regulatory compliance.
- You review and update policies, processes and procedures in response to major cyber security incidents.
- You fully document your overarching security governance and risk management approach, technical security practice and specific regulatory compliance.
- Cyber security is integrated and embedded throughout policies, processes and procedures and key performance indicators are reported to your executive management.
- Your organisation’s policies, processes and procedures are developed to be practical, usable and appropriate to mitigate the risk of adverse impact to network and information systems supporting your essential function(s).
- Policies, processes and procedures that rely on user behaviour are practical, appropriate and achievable.
- You review and update policies, processes and procedures at suitably regular intervals to ensure they remain relevant. This is in addition to reviews following a major cyber security incident.
- Any changes to the essential function(s) or the threat it faces triggers a review of policies, processes and procedures.
- Your systems are designed so that they remain secure even when user security policies, processes and procedures are not always followed.
Not achieved - At least one of the following statements is true:
- Your policies, processes and procedures are absent or incomplete.
- Policies, processes and procedures are not applied universally or consistently.
- People often or routinely circumvent policies, processes and procedures to achieve business objectives.
- Your organisation’s security governance and risk management approach has no bearing on your policies, processes and procedures.
- System security is totally reliant on users' careful and consistent application of manual security processes.
- Policies, processes and procedures have not been reviewed in response to major changes (e.g. technology or regulatory framework), or within a suitable period.
- Policies, processes and procedures are not readily available to staff, too detailed to remember, or too hard to understand.
Partially achieved - All the following statements are true:
- Your policies, processes and procedures document your overarching security governance and risk management approach, technical security practice and specific regulatory compliance.
- You review and update policies, processes and procedures in response to major cyber security incidents.
Achieved - All the following statements are true:
- You fully document your overarching security governance and risk management approach, technical security practice and specific regulatory compliance.
- Cyber security is integrated and embedded throughout policies, processes and procedures and key performance indicators are reported to your executive management.
- Your organisation’s policies, processes and procedures are developed to be practical, usable and appropriate to mitigate the risk of adverse impact to network and information systems supporting your essential function(s).
- Policies, processes and procedures that rely on user behaviour are practical, appropriate and achievable.
- You review and update policies, processes and procedures at suitably regular intervals to ensure they remain relevant. This is in addition to reviews following a major cyber security incident.
- Any changes to the essential function(s) or the threat it faces triggers a review of policies, processes and procedures.
- Your systems are designed so that they remain secure even when user security policies, processes and procedures are not always followed.
B1.b Policy, Process and Procedure Implementation
- You have successfully implemented your security policies, processes and procedures and can demonstrate the security benefits achieved.
- You have successfully implemented your security policies, processes and procedures and can demonstrate the security benefits achieved.
- Policies, processes and procedures are ignored or only partially followed.
- How your policies support the resilience of your essential function(s) is not well understood.
- Staff are unaware of their responsibilities under your policies, processes and procedures.
- You do not attempt to detect breaches of policies, processes and procedures.
- Policies, processes and procedures lack integration with other organisational policies, processes and procedures.
- Your policies, processes and procedures are not well communicated across your organisation.
- Most of your policies, processes and procedures are followed and their application is monitored.
- Your policies, processes and procedures are integrated with other organisational policies, processes and procedures, including HR assessments of individuals' trustworthiness.
- All staff are aware of their responsibilities under your policies, processes and procedures.
- All breaches of policies, processes and procedures with the potential to adversely impact the essential function(s) are fully investigated. Other breaches are tracked, assessed for trends and action is taken to understand and address.
- All your policies, processes and procedures are followed, their correct application and security effectiveness is evaluated.
- Your policies, processes and procedures are integrated with other organisational policies, processes and procedures, including HR assessments of individuals' trustworthiness.
- Your policies, processes and procedures are effectively and appropriately communicated across all levels of the organisation resulting in good staff awareness of their responsibilities.
- Appropriate action is taken to address all breaches of policies, processes and procedures with potential to adversely impact the essential function(s) including aggregated breaches.
Not achieved - At least one of the following statements is true:
- Policies, processes and procedures are ignored or only partially followed.
- How your policies support the resilience of your essential function(s) is not well understood.
- Staff are unaware of their responsibilities under your policies, processes and procedures.
- You do not attempt to detect breaches of policies, processes and procedures.
- Policies, processes and procedures lack integration with other organisational policies, processes and procedures.
- Your policies, processes and procedures are not well communicated across your organisation.
Partially achieved - All the following statements are true:
- Most of your policies, processes and procedures are followed and their application is monitored.
- Your policies, processes and procedures are integrated with other organisational policies, processes and procedures, including HR assessments of individuals' trustworthiness.
- All staff are aware of their responsibilities under your policies, processes and procedures.
- All breaches of policies, processes and procedures with the potential to adversely impact the essential function(s) are fully investigated. Other breaches are tracked, assessed for trends and action is taken to understand and address.
Achieved - All the following statements are true:
- All your policies, processes and procedures are followed, their correct application and security effectiveness is evaluated.
- Your policies, processes and procedures are integrated with other organisational policies, processes and procedures, including HR assessments of individuals' trustworthiness.
- Your policies, processes and procedures are effectively and appropriately communicated across all levels of the organisation resulting in good staff awareness of their responsibilities.
- Appropriate action is taken to address all breaches of policies, processes and procedures with potential to adversely impact the essential function(s) including aggregated breaches.
The organisation defines, implements, communicates and enforces appropriate policies, processes and procedures that direct its overall approach to securing systems and data that support the operation of essential functions.
Description
error determining description
Guidance
The policies, processes and procedures needed by an organisation depend upon its function and should integrate with the organisation’s approach to governance and risk management. Organisations responsible for essential functions should have a range of policies, processes and procedures, including:
An organisational security or service protection policy: endorsed by senior management, this high-level policy should include the organisation’s overarching approach to governing security and managing risks, the organisation’s aims and intents for security and what is of key concern.
Supporting policies, processes and procedures: contextual lower-level definitions controlling, directing and communicating organisational security practice.
Compliance policies and processes for sector regulations, standards, etc.: specific policies and processes appropriate to the compliance regime; these may be defined by the regulation, standard, etc. For example, to comply with ISO/IEC 27001, organisations should have in place certain security policies and procedures relevant to what the organisation does, how it does it, and what their ISO/IEC 27001 information security management system covers (see ISO/IEC 27002 for detail).
An organisational security or service protection policy: endorsed by senior management, this high-level policy should include the organisation’s overarching approach to governing security and managing risks, the organisation’s aims and intents for security and what is of key concern.
Contributing Outcomes
B1.a Policy, Process and Procedure Development
- You have developed and continue to improve a set of cyber security and resilience policies, processes and procedures that manage and mitigate the risk of adverse impact on your essential function(s).
- You have developed and continue to improve a set of cyber security and resilience policies, processes and procedures that manage and mitigate the risk of adverse impact on your essential function(s).
- Your policies, processes and procedures are absent or incomplete.
- Policies, processes and procedures are not applied universally or consistently.
- People often or routinely circumvent policies, processes and procedures to achieve business objectives.
- Your organisation’s security governance and risk management approach has no bearing on your policies, processes and procedures.
- System security is totally reliant on users' careful and consistent application of manual security processes.
- Policies, processes and procedures have not been reviewed in response to major changes (e.g. technology or regulatory framework), or within a suitable period.
- Policies, processes and procedures are not readily available to staff, too detailed to remember, or too hard to understand.
- Your policies, processes and procedures document your overarching security governance and risk management approach, technical security practice and specific regulatory compliance.
- You review and update policies, processes and procedures in response to major cyber security incidents.
- You fully document your overarching security governance and risk management approach, technical security practice and specific regulatory compliance.
- Cyber security is integrated and embedded throughout policies, processes and procedures and key performance indicators are reported to your executive management.
- Your organisation’s policies, processes and procedures are developed to be practical, usable and appropriate to mitigate the risk of adverse impact to network and information systems supporting your essential function(s).
- Policies, processes and procedures that rely on user behaviour are practical, appropriate and achievable.
- You review and update policies, processes and procedures at suitably regular intervals to ensure they remain relevant. This is in addition to reviews following a major cyber security incident.
- Any changes to the essential function(s) or the threat it faces triggers a review of policies, processes and procedures.
- Your systems are designed so that they remain secure even when user security policies, processes and procedures are not always followed.
Not achieved - At least one of the following statements is true:
- Your policies, processes and procedures are absent or incomplete.
- Policies, processes and procedures are not applied universally or consistently.
- People often or routinely circumvent policies, processes and procedures to achieve business objectives.
- Your organisation’s security governance and risk management approach has no bearing on your policies, processes and procedures.
- System security is totally reliant on users' careful and consistent application of manual security processes.
- Policies, processes and procedures have not been reviewed in response to major changes (e.g. technology or regulatory framework), or within a suitable period.
- Policies, processes and procedures are not readily available to staff, too detailed to remember, or too hard to understand.
Partially achieved - All the following statements are true:
- Your policies, processes and procedures document your overarching security governance and risk management approach, technical security practice and specific regulatory compliance.
- You review and update policies, processes and procedures in response to major cyber security incidents.
Achieved - All the following statements are true:
- You fully document your overarching security governance and risk management approach, technical security practice and specific regulatory compliance.
- Cyber security is integrated and embedded throughout policies, processes and procedures and key performance indicators are reported to your executive management.
- Your organisation’s policies, processes and procedures are developed to be practical, usable and appropriate to mitigate the risk of adverse impact to network and information systems supporting your essential function(s).
- Policies, processes and procedures that rely on user behaviour are practical, appropriate and achievable.
- You review and update policies, processes and procedures at suitably regular intervals to ensure they remain relevant. This is in addition to reviews following a major cyber security incident.
- Any changes to the essential function(s) or the threat it faces triggers a review of policies, processes and procedures.
- Your systems are designed so that they remain secure even when user security policies, processes and procedures are not always followed.
B1.b Policy, Process and Procedure Implementation
- You have successfully implemented your security policies, processes and procedures and can demonstrate the security benefits achieved.
- You have successfully implemented your security policies, processes and procedures and can demonstrate the security benefits achieved.
- Policies, processes and procedures are ignored or only partially followed.
- How your policies support the resilience of your essential function(s) is not well understood.
- Staff are unaware of their responsibilities under your policies, processes and procedures.
- You do not attempt to detect breaches of policies, processes and procedures.
- Policies, processes and procedures lack integration with other organisational policies, processes and procedures.
- Your policies, processes and procedures are not well communicated across your organisation.
- Most of your policies, processes and procedures are followed and their application is monitored.
- Your policies, processes and procedures are integrated with other organisational policies, processes and procedures, including HR assessments of individuals' trustworthiness.
- All staff are aware of their responsibilities under your policies, processes and procedures.
- All breaches of policies, processes and procedures with the potential to adversely impact the essential function(s) are fully investigated. Other breaches are tracked, assessed for trends and action is taken to understand and address.
- All your policies, processes and procedures are followed, their correct application and security effectiveness is evaluated.
- Your policies, processes and procedures are integrated with other organisational policies, processes and procedures, including HR assessments of individuals' trustworthiness.
- Your policies, processes and procedures are effectively and appropriately communicated across all levels of the organisation resulting in good staff awareness of their responsibilities.
- Appropriate action is taken to address all breaches of policies, processes and procedures with potential to adversely impact the essential function(s) including aggregated breaches.
Not achieved - At least one of the following statements is true:
- Policies, processes and procedures are ignored or only partially followed.
- How your policies support the resilience of your essential function(s) is not well understood.
- Staff are unaware of their responsibilities under your policies, processes and procedures.
- You do not attempt to detect breaches of policies, processes and procedures.
- Policies, processes and procedures lack integration with other organisational policies, processes and procedures.
- Your policies, processes and procedures are not well communicated across your organisation.
Partially achieved - All the following statements are true:
- Most of your policies, processes and procedures are followed and their application is monitored.
- Your policies, processes and procedures are integrated with other organisational policies, processes and procedures, including HR assessments of individuals' trustworthiness.
- All staff are aware of their responsibilities under your policies, processes and procedures.
- All breaches of policies, processes and procedures with the potential to adversely impact the essential function(s) are fully investigated. Other breaches are tracked, assessed for trends and action is taken to understand and address.
Achieved - All the following statements are true:
- All your policies, processes and procedures are followed, their correct application and security effectiveness is evaluated.
- Your policies, processes and procedures are integrated with other organisational policies, processes and procedures, including HR assessments of individuals' trustworthiness.
- Your policies, processes and procedures are effectively and appropriately communicated across all levels of the organisation resulting in good staff awareness of their responsibilities.
- Appropriate action is taken to address all breaches of policies, processes and procedures with potential to adversely impact the essential function(s) including aggregated breaches.
The organisation understands, documents and manages access to networks and information systems and supporting the operation of essential functions. Users (or automated functions) that can access data or services are appropriately verified, authenticated and authorised.
Description
It is important that the organisation is clear about who (or what in the case of automated functions) has authorisation to interact with the network and information systems supporting an essential function in any way or access associated sensitive data. Access rights granted should be carefully controlled, especially where those rights provide an ability to materially affect the operation of the essential function. Access rights granted should be periodically reviewed and technically removed when no longer required such as when an individual changes role or leaves the organisation.
Users, devices and systems should be appropriately verified, authenticated and authorised before access to data or services is granted. Verification of a user’s identity (they are who they say they are) is a prerequisite for issuing credentials, authentication and access management. For highly privileged access it might be appropriate to include approaches such as multi-factor or hardware authentication.
Unauthorised individuals should be prevented from accessing data or services at all points within the system. This includes system users without the appropriate permissions, unauthorised individuals attempting to interact with any online service or individuals with unauthorised access to user devices (for example if a user device were lost or stolen).
Guidance
The
Introduction to identity and access management
sets out security fundamentals that operators should consider in designing and managing identity and access management systems. Identity and access control should be robust enough that essential functions are not adversely affected by unauthorised access.
In addition to technical security, organisations should protect physical access to networks and information systems supporting the essential function, to prevent unauthorised access, tampering or data deletion. Some organisations may already have physical security measures in place to comply with non-cyber regulatory frameworks. See
NPSA guidance on Control Access
for further information.
Contributing Outcomes
B2.a Identity Verification, Authentication and Authorisation
- You robustly verify, authenticate and authorise access to the network and information systems supporting your essential function(s).
- You robustly verify, authenticate and authorise access to the network and information systems supporting your essential function(s).
- Initial identity verification is not robust enough to provide an acceptable level of confidence of a user’s identity profile.
- Authorised users and systems with access to networks or information systems on which your essential function(s) depends cannot be individually identified.
- Unauthorised individuals or devices can access your network or information systems on which your essential function(s) depends.
- The number of authorised users and systems that have access to your network and information systems are not limited to the minimum necessary.
- Your approach to authenticating users, devices and systems does not follow up to date best practice.
- Your process of initial identity verification is robust enough to provide a reasonable level of confidence of a user’s identity profile before allowing an authorised user access to network and information systems that support your essential function(s).
- All authorised users and systems with access to network or information systems on which your essential function(s) depends are individually identified and authenticated.
- The number of authorised users and systems that have access to essential function(s) network and information systems is limited to the minimum necessary.
- You use additional authentication mechanisms, such as multi-factor (MFA), for privileged access to all network and information systems that operate or support your essential function(s).
- You individually authenticate and authorise all remote access to all your network and information systems that support your essential function(s).
- The list of users and systems with access to network and information systems supporting and delivering the essential function(s) is reviewed on a regular basis, at least annually.
- Your approach to authenticating users, devices and systems follows up to date best practice.
- Your process of initial identity verification is robust enough to provide a high level of confidence of a user’s identity profile before allowing an authorised user access to network and information systems that support your essential function(s).
- Only authorised and individually authenticated users can physically access and logically connect to your network or information systems on which your essential function(s) depends.
- The number of authorised users and systems that have access to all your network and information systems supporting the essential function(s) is limited to the minimum necessary.
- You use additional authentication mechanisms, such as multi-factor (MFA), for all user access, including remote access, to all network and information systems that operate or support your essential function(s).
- The list of users and systems with access to network and information systems supporting and delivering the essential function(s) is reviewed on a regular basis, at least every six months.
- Your approach to authenticating users, devices and systems follows up to date best practice.
Not achieved - At least one of the following statements is true:
- Initial identity verification is not robust enough to provide an acceptable level of confidence of a user’s identity profile.
- Authorised users and systems with access to networks or information systems on which your essential function(s) depends cannot be individually identified.
- Unauthorised individuals or devices can access your network or information systems on which your essential function(s) depends.
- The number of authorised users and systems that have access to your network and information systems are not limited to the minimum necessary.
- Your approach to authenticating users, devices and systems does not follow up to date best practice.
Partially achieved - All the following statements are true:
- Your process of initial identity verification is robust enough to provide a reasonable level of confidence of a user’s identity profile before allowing an authorised user access to network and information systems that support your essential function(s).
- All authorised users and systems with access to network or information systems on which your essential function(s) depends are individually identified and authenticated.
- The number of authorised users and systems that have access to essential function(s) network and information systems is limited to the minimum necessary.
- You use additional authentication mechanisms, such as multi-factor (MFA), for privileged access to all network and information systems that operate or support your essential function(s).
- You individually authenticate and authorise all remote access to all your network and information systems that support your essential function(s).
- The list of users and systems with access to network and information systems supporting and delivering the essential function(s) is reviewed on a regular basis, at least annually.
- Your approach to authenticating users, devices and systems follows up to date best practice.
Achieved - All the following statements are true:
- Your process of initial identity verification is robust enough to provide a high level of confidence of a user’s identity profile before allowing an authorised user access to network and information systems that support your essential function(s).
- Only authorised and individually authenticated users can physically access and logically connect to your network or information systems on which your essential function(s) depends.
- The number of authorised users and systems that have access to all your network and information systems supporting the essential function(s) is limited to the minimum necessary.
- You use additional authentication mechanisms, such as multi-factor (MFA), for all user access, including remote access, to all network and information systems that operate or support your essential function(s).
- The list of users and systems with access to network and information systems supporting and delivering the essential function(s) is reviewed on a regular basis, at least every six months.
- Your approach to authenticating users, devices and systems follows up to date best practice.
B2.b Device Management
- You fully know and have trust in the devices that are used to access your networks, information systems and data that support your essential function(s).
- You fully know and have trust in the devices that are used to access your networks, information systems and data that support your essential function(s).
- Users can connect to your essential function(s)'s network and information systems using devices that are not corporately owned and managed.
- Privileged users can perform privileged operations from devices that are not corporately owned and managed.
- You have not gained assurance in the security of any third-party devices or networks connected to your systems.
- Physically connecting a device to your network and information systems gives that device access without device or user authentication.
- Only corporately owned and managed devices can access your essential function(s)'s network and information systems.
- All privileged operations are performed from corporately owned and managed devices. These devices provide sufficient separation, using a risk-based approach, from the activities of standard users.
- You have sought to understand the security properties of third-party devices and networks before they can be connected to your systems. You have taken appropriate steps to mitigate any risks identified.
- The act of connecting to a network port or cable does not grant access to any systems.
- You are able to detect unknown devices being connected to your network and information systems and investigate such incidents.
- All privileged operations performed on your network and information systems supporting your essential function(s) are conducted from highly trusted devices, such as Privileged Access Workstations, dedicated solely to those operations.
- You either obtain independent and professional assurance of the security of third-party devices or networks before they connect to your network and information systems, or you only allow third-party devices or networks that are dedicated to supporting your network and information systems to connect.
- You perform certificate-based device identity management and only allow known devices to access systems necessary for the operation of your essential function(s).
- You perform regular scans to detect unknown devices and investigate any findings.
Not achieved - At least one of the following statements is true:
- Users can connect to your essential function(s)'s network and information systems using devices that are not corporately owned and managed.
- Privileged users can perform privileged operations from devices that are not corporately owned and managed.
- You have not gained assurance in the security of any third-party devices or networks connected to your systems.
- Physically connecting a device to your network and information systems gives that device access without device or user authentication.
Partially achieved - All the following statements are true:
- Only corporately owned and managed devices can access your essential function(s)'s network and information systems.
- All privileged operations are performed from corporately owned and managed devices. These devices provide sufficient separation, using a risk-based approach, from the activities of standard users.
- You have sought to understand the security properties of third-party devices and networks before they can be connected to your systems. You have taken appropriate steps to mitigate any risks identified.
- The act of connecting to a network port or cable does not grant access to any systems.
- You are able to detect unknown devices being connected to your network and information systems and investigate such incidents.
Achieved - All the following statements are true:
- All privileged operations performed on your network and information systems supporting your essential function(s) are conducted from highly trusted devices, such as Privileged Access Workstations, dedicated solely to those operations.
- You either obtain independent and professional assurance of the security of third-party devices or networks before they connect to your network and information systems, or you only allow third-party devices or networks that are dedicated to supporting your network and information systems to connect.
- You perform certificate-based device identity management and only allow known devices to access systems necessary for the operation of your essential function(s).
- You perform regular scans to detect unknown devices and investigate any findings.
B2.c Privileged User Management
- You closely manage privileged user access to network and information systems supporting the essential function(s).
- You closely manage privileged user access to network and information systems supporting the essential function(s).
- The identities of the individuals with privileged access to your essential function(s) network and information systems (infrastructure, platforms, software, configuration, etc) are not known or not managed.
- Privileged user access to your essential function(s) network and information systems is via weak authentication mechanisms (e.g. only simple passwords).
- The list of privileged users has not been reviewed recently (e.g. within the last 12 months).
- Privileged user access is granted on a system-wide basis rather than by role or function(s).
- Privileged user access to your essential function(s) is via generic, shared or default name accounts.
- Where there are “always on” terminals which can perform privileged actions (such as in a control room), there are no additional controls (e.g. physical controls) to ensure access is appropriately restricted.
- There is no logical separation between roles that an individual may have and hence the actions they perform. (e.g. access to corporate email and privilege user actions).
- All privileged user access to your network and information systems requires strong authentication, such as multi-factor (MFA).
- The identities of the individuals with privileged access to your essential function(s) network and information systems (infrastructure, platforms, software, configuration, etc) are known and managed. This includes third parties.
- Activity by privileged users is routinely reviewed and validated. (e.g. at least annually).
- Privileged users are only granted specific privileged user access rights which are essential to their business role or function.
- Privileged user access to your essential function(s) systems is carried out from dedicated separate accounts that are closely monitored and managed.
- The issuing of temporary, time-bound rights for privileged user access and / or external third-party support access is in place.
- Privileged user access rights are regularly reviewed and always updated as part of your joiners, movers and leavers process.
- All privileged user activity is routinely reviewed, validated and recorded for offline analysis and investigation.
Not achieved - At least one of the following statements is true:
- The identities of the individuals with privileged access to your essential function(s) network and information systems (infrastructure, platforms, software, configuration, etc) are not known or not managed.
- Privileged user access to your essential function(s) network and information systems is via weak authentication mechanisms (e.g. only simple passwords).
- The list of privileged users has not been reviewed recently (e.g. within the last 12 months).
- Privileged user access is granted on a system-wide basis rather than by role or function(s).
- Privileged user access to your essential function(s) is via generic, shared or default name accounts.
- Where there are “always on” terminals which can perform privileged actions (such as in a control room), there are no additional controls (e.g. physical controls) to ensure access is appropriately restricted.
- There is no logical separation between roles that an individual may have and hence the actions they perform. (e.g. access to corporate email and privilege user actions).
Partially achieved - All of the following statements are true:
- All privileged user access to your network and information systems requires strong authentication, such as multi-factor (MFA).
- The identities of the individuals with privileged access to your essential function(s) network and information systems (infrastructure, platforms, software, configuration, etc) are known and managed. This includes third parties.
- Activity by privileged users is routinely reviewed and validated. (e.g. at least annually).
- Privileged users are only granted specific privileged user access rights which are essential to their business role or function.
Achieved - All of the following statements are true:
- Privileged user access to your essential function(s) systems is carried out from dedicated separate accounts that are closely monitored and managed.
- The issuing of temporary, time-bound rights for privileged user access and / or external third-party support access is in place.
- Privileged user access rights are regularly reviewed and always updated as part of your joiners, movers and leavers process.
- All privileged user activity is routinely reviewed, validated and recorded for offline analysis and investigation.
B2.d Identity and Access Management (IdAM)
- You closely manage and maintain identity and access control for users, devices and systems accessing the network and information systems supporting the essential function(s).
- You closely manage and maintain identity and access control for users, devices and systems accessing the network and information systems supporting the essential function(s).
- Greater access rights are granted than necessary.
- Identity validation and requirement for access of a user, device or systems is not carried out.
- User access rights are not reviewed when users change roles.
- User access rights remain active when users leave your organisation.
- Access rights granted to devices or systems to access other devices and systems are not reviewed on a regular basis (at least annually).
- You follow a robust procedure to verify each user and issue the minimum required access rights.
- You regularly review access rights and those no longer needed are revoked.
- User access rights are reviewed when users change roles via your joiners, leavers and movers process.
- All user, device and system access to the systems supporting the essential function(s) is logged and monitored, but it is not compared to other log data or access records.
- You follow a robust procedure to verify each user and issue the minimum required access rights, and the application of the procedure is regularly audited.
- User access rights are reviewed both when people change roles via your joiners, leavers and movers process and at regular intervals - at least annually.
- All user, device and systems access to the systems supporting the essential function(s) is logged and monitored.
- You regularly review access logs and correlate this data with other access records and expected activity.
- Attempts by unauthorised users, devices or systems to connect to the systems supporting the essential function(s) are alerted, promptly assessed and investigated.
Not achieved - At least one of the following statements is true:
- Greater access rights are granted than necessary.
- Identity validation and requirement for access of a user, device or systems is not carried out.
- User access rights are not reviewed when users change roles.
- User access rights remain active when users leave your organisation.
- Access rights granted to devices or systems to access other devices and systems are not reviewed on a regular basis (at least annually).
Partially achieved - All of the following statements are true:
- You follow a robust procedure to verify each user and issue the minimum required access rights.
- You regularly review access rights and those no longer needed are revoked.
- User access rights are reviewed when users change roles via your joiners, leavers and movers process.
- All user, device and system access to the systems supporting the essential function(s) is logged and monitored, but it is not compared to other log data or access records.
Achieved - All of the following statements are true:
- You follow a robust procedure to verify each user and issue the minimum required access rights, and the application of the procedure is regularly audited.
- User access rights are reviewed both when people change roles via your joiners, leavers and movers process and at regular intervals - at least annually.
- All user, device and systems access to the systems supporting the essential function(s) is logged and monitored.
- You regularly review access logs and correlate this data with other access records and expected activity.
- Attempts by unauthorised users, devices or systems to connect to the systems supporting the essential function(s) are alerted, promptly assessed and investigated.
The organisation understands, documents and manages access to networks and information systems and supporting the operation of essential functions. Users (or automated functions) that can access data or services are appropriately verified, authenticated and authorised.
Description
It is important that the organisation is clear about who (or what in the case of automated functions) has authorisation to interact with the network and information systems supporting an essential function in any way or access associated sensitive data. Access rights granted should be carefully controlled, especially where those rights provide an ability to materially affect the operation of the essential function. Access rights granted should be periodically reviewed and technically removed when no longer required such as when an individual changes role or leaves the organisation.
Users, devices and systems should be appropriately verified, authenticated and authorised before access to data or services is granted. Verification of a user’s identity (they are who they say they are) is a prerequisite for issuing credentials, authentication and access management. For highly privileged access it might be appropriate to include approaches such as multi-factor or hardware authentication.
Unauthorised individuals should be prevented from accessing data or services at all points within the system. This includes system users without the appropriate permissions, unauthorised individuals attempting to interact with any online service or individuals with unauthorised access to user devices (for example if a user device were lost or stolen).
Guidance
The
Introduction to identity and access management
sets out security fundamentals that operators should consider in designing and managing identity and access management systems. Identity and access control should be robust enough that essential functions are not adversely affected by unauthorised access.
In addition to technical security, organisations should protect physical access to networks and information systems supporting the essential function, to prevent unauthorised access, tampering or data deletion. Some organisations may already have physical security measures in place to comply with non-cyber regulatory frameworks. See
NPSA guidance on Control Access
for further information.
Contributing Outcomes
B2.a Identity Verification, Authentication and Authorisation
- You robustly verify, authenticate and authorise access to the network and information systems supporting your essential function(s).
- You robustly verify, authenticate and authorise access to the network and information systems supporting your essential function(s).
- Initial identity verification is not robust enough to provide an acceptable level of confidence of a user’s identity profile.
- Authorised users and systems with access to networks or information systems on which your essential function(s) depends cannot be individually identified.
- Unauthorised individuals or devices can access your network or information systems on which your essential function(s) depends.
- The number of authorised users and systems that have access to your network and information systems are not limited to the minimum necessary.
- Your approach to authenticating users, devices and systems does not follow up to date best practice.
- Your process of initial identity verification is robust enough to provide a reasonable level of confidence of a user’s identity profile before allowing an authorised user access to network and information systems that support your essential function(s).
- All authorised users and systems with access to network or information systems on which your essential function(s) depends are individually identified and authenticated.
- The number of authorised users and systems that have access to essential function(s) network and information systems is limited to the minimum necessary.
- You use additional authentication mechanisms, such as multi-factor (MFA), for privileged access to all network and information systems that operate or support your essential function(s).
- You individually authenticate and authorise all remote access to all your network and information systems that support your essential function(s).
- The list of users and systems with access to network and information systems supporting and delivering the essential function(s) is reviewed on a regular basis, at least annually.
- Your approach to authenticating users, devices and systems follows up to date best practice.
- Your process of initial identity verification is robust enough to provide a high level of confidence of a user’s identity profile before allowing an authorised user access to network and information systems that support your essential function(s).
- Only authorised and individually authenticated users can physically access and logically connect to your network or information systems on which your essential function(s) depends.
- The number of authorised users and systems that have access to all your network and information systems supporting the essential function(s) is limited to the minimum necessary.
- You use additional authentication mechanisms, such as multi-factor (MFA), for all user access, including remote access, to all network and information systems that operate or support your essential function(s).
- The list of users and systems with access to network and information systems supporting and delivering the essential function(s) is reviewed on a regular basis, at least every six months.
- Your approach to authenticating users, devices and systems follows up to date best practice.
Not achieved - At least one of the following statements is true:
- Initial identity verification is not robust enough to provide an acceptable level of confidence of a user’s identity profile.
- Authorised users and systems with access to networks or information systems on which your essential function(s) depends cannot be individually identified.
- Unauthorised individuals or devices can access your network or information systems on which your essential function(s) depends.
- The number of authorised users and systems that have access to your network and information systems are not limited to the minimum necessary.
- Your approach to authenticating users, devices and systems does not follow up to date best practice.
Partially achieved - All the following statements are true:
- Your process of initial identity verification is robust enough to provide a reasonable level of confidence of a user’s identity profile before allowing an authorised user access to network and information systems that support your essential function(s).
- All authorised users and systems with access to network or information systems on which your essential function(s) depends are individually identified and authenticated.
- The number of authorised users and systems that have access to essential function(s) network and information systems is limited to the minimum necessary.
- You use additional authentication mechanisms, such as multi-factor (MFA), for privileged access to all network and information systems that operate or support your essential function(s).
- You individually authenticate and authorise all remote access to all your network and information systems that support your essential function(s).
- The list of users and systems with access to network and information systems supporting and delivering the essential function(s) is reviewed on a regular basis, at least annually.
- Your approach to authenticating users, devices and systems follows up to date best practice.
Achieved - All the following statements are true:
- Your process of initial identity verification is robust enough to provide a high level of confidence of a user’s identity profile before allowing an authorised user access to network and information systems that support your essential function(s).
- Only authorised and individually authenticated users can physically access and logically connect to your network or information systems on which your essential function(s) depends.
- The number of authorised users and systems that have access to all your network and information systems supporting the essential function(s) is limited to the minimum necessary.
- You use additional authentication mechanisms, such as multi-factor (MFA), for all user access, including remote access, to all network and information systems that operate or support your essential function(s).
- The list of users and systems with access to network and information systems supporting and delivering the essential function(s) is reviewed on a regular basis, at least every six months.
- Your approach to authenticating users, devices and systems follows up to date best practice.
B2.b Device Management
- You fully know and have trust in the devices that are used to access your networks, information systems and data that support your essential function(s).
- You fully know and have trust in the devices that are used to access your networks, information systems and data that support your essential function(s).
- Users can connect to your essential function(s)'s network and information systems using devices that are not corporately owned and managed.
- Privileged users can perform privileged operations from devices that are not corporately owned and managed.
- You have not gained assurance in the security of any third-party devices or networks connected to your systems.
- Physically connecting a device to your network and information systems gives that device access without device or user authentication.
- Only corporately owned and managed devices can access your essential function(s)'s network and information systems.
- All privileged operations are performed from corporately owned and managed devices. These devices provide sufficient separation, using a risk-based approach, from the activities of standard users.
- You have sought to understand the security properties of third-party devices and networks before they can be connected to your systems. You have taken appropriate steps to mitigate any risks identified.
- The act of connecting to a network port or cable does not grant access to any systems.
- You are able to detect unknown devices being connected to your network and information systems and investigate such incidents.
- All privileged operations performed on your network and information systems supporting your essential function(s) are conducted from highly trusted devices, such as Privileged Access Workstations, dedicated solely to those operations.
- You either obtain independent and professional assurance of the security of third-party devices or networks before they connect to your network and information systems, or you only allow third-party devices or networks that are dedicated to supporting your network and information systems to connect.
- You perform certificate-based device identity management and only allow known devices to access systems necessary for the operation of your essential function(s).
- You perform regular scans to detect unknown devices and investigate any findings.
Not achieved - At least one of the following statements is true:
- Users can connect to your essential function(s)'s network and information systems using devices that are not corporately owned and managed.
- Privileged users can perform privileged operations from devices that are not corporately owned and managed.
- You have not gained assurance in the security of any third-party devices or networks connected to your systems.
- Physically connecting a device to your network and information systems gives that device access without device or user authentication.
Partially achieved - All the following statements are true:
- Only corporately owned and managed devices can access your essential function(s)'s network and information systems.
- All privileged operations are performed from corporately owned and managed devices. These devices provide sufficient separation, using a risk-based approach, from the activities of standard users.
- You have sought to understand the security properties of third-party devices and networks before they can be connected to your systems. You have taken appropriate steps to mitigate any risks identified.
- The act of connecting to a network port or cable does not grant access to any systems.
- You are able to detect unknown devices being connected to your network and information systems and investigate such incidents.
Achieved - All the following statements are true:
- All privileged operations performed on your network and information systems supporting your essential function(s) are conducted from highly trusted devices, such as Privileged Access Workstations, dedicated solely to those operations.
- You either obtain independent and professional assurance of the security of third-party devices or networks before they connect to your network and information systems, or you only allow third-party devices or networks that are dedicated to supporting your network and information systems to connect.
- You perform certificate-based device identity management and only allow known devices to access systems necessary for the operation of your essential function(s).
- You perform regular scans to detect unknown devices and investigate any findings.
B2.c Privileged User Management
- You closely manage privileged user access to network and information systems supporting the essential function(s).
- You closely manage privileged user access to network and information systems supporting the essential function(s).
- The identities of the individuals with privileged access to your essential function(s) network and information systems (infrastructure, platforms, software, configuration, etc) are not known or not managed.
- Privileged user access to your essential function(s) network and information systems is via weak authentication mechanisms (e.g. only simple passwords).
- The list of privileged users has not been reviewed recently (e.g. within the last 12 months).
- Privileged user access is granted on a system-wide basis rather than by role or function(s).
- Privileged user access to your essential function(s) is via generic, shared or default name accounts.
- Where there are “always on” terminals which can perform privileged actions (such as in a control room), there are no additional controls (e.g. physical controls) to ensure access is appropriately restricted.
- There is no logical separation between roles that an individual may have and hence the actions they perform. (e.g. access to corporate email and privilege user actions).
- All privileged user access to your network and information systems requires strong authentication, such as multi-factor (MFA).
- The identities of the individuals with privileged access to your essential function(s) network and information systems (infrastructure, platforms, software, configuration, etc) are known and managed. This includes third parties.
- Activity by privileged users is routinely reviewed and validated. (e.g. at least annually).
- Privileged users are only granted specific privileged user access rights which are essential to their business role or function.
- Privileged user access to your essential function(s) systems is carried out from dedicated separate accounts that are closely monitored and managed.
- The issuing of temporary, time-bound rights for privileged user access and / or external third-party support access is in place.
- Privileged user access rights are regularly reviewed and always updated as part of your joiners, movers and leavers process.
- All privileged user activity is routinely reviewed, validated and recorded for offline analysis and investigation.
Not achieved - At least one of the following statements is true:
- The identities of the individuals with privileged access to your essential function(s) network and information systems (infrastructure, platforms, software, configuration, etc) are not known or not managed.
- Privileged user access to your essential function(s) network and information systems is via weak authentication mechanisms (e.g. only simple passwords).
- The list of privileged users has not been reviewed recently (e.g. within the last 12 months).
- Privileged user access is granted on a system-wide basis rather than by role or function(s).
- Privileged user access to your essential function(s) is via generic, shared or default name accounts.
- Where there are “always on” terminals which can perform privileged actions (such as in a control room), there are no additional controls (e.g. physical controls) to ensure access is appropriately restricted.
- There is no logical separation between roles that an individual may have and hence the actions they perform. (e.g. access to corporate email and privilege user actions).
Partially achieved - All of the following statements are true:
- All privileged user access to your network and information systems requires strong authentication, such as multi-factor (MFA).
- The identities of the individuals with privileged access to your essential function(s) network and information systems (infrastructure, platforms, software, configuration, etc) are known and managed. This includes third parties.
- Activity by privileged users is routinely reviewed and validated. (e.g. at least annually).
- Privileged users are only granted specific privileged user access rights which are essential to their business role or function.
Achieved - All of the following statements are true:
- Privileged user access to your essential function(s) systems is carried out from dedicated separate accounts that are closely monitored and managed.
- The issuing of temporary, time-bound rights for privileged user access and / or external third-party support access is in place.
- Privileged user access rights are regularly reviewed and always updated as part of your joiners, movers and leavers process.
- All privileged user activity is routinely reviewed, validated and recorded for offline analysis and investigation.
B2.d Identity and Access Management (IdAM)
- You closely manage and maintain identity and access control for users, devices and systems accessing the network and information systems supporting the essential function(s).
- You closely manage and maintain identity and access control for users, devices and systems accessing the network and information systems supporting the essential function(s).
- Greater access rights are granted than necessary.
- Identity validation and requirement for access of a user, device or systems is not carried out.
- User access rights are not reviewed when users change roles.
- User access rights remain active when users leave your organisation.
- Access rights granted to devices or systems to access other devices and systems are not reviewed on a regular basis (at least annually).
- You follow a robust procedure to verify each user and issue the minimum required access rights.
- You regularly review access rights and those no longer needed are revoked.
- User access rights are reviewed when users change roles via your joiners, leavers and movers process.
- All user, device and system access to the systems supporting the essential function(s) is logged and monitored, but it is not compared to other log data or access records.
- You follow a robust procedure to verify each user and issue the minimum required access rights, and the application of the procedure is regularly audited.
- User access rights are reviewed both when people change roles via your joiners, leavers and movers process and at regular intervals - at least annually.
- All user, device and systems access to the systems supporting the essential function(s) is logged and monitored.
- You regularly review access logs and correlate this data with other access records and expected activity.
- Attempts by unauthorised users, devices or systems to connect to the systems supporting the essential function(s) are alerted, promptly assessed and investigated.
Not achieved - At least one of the following statements is true:
- Greater access rights are granted than necessary.
- Identity validation and requirement for access of a user, device or systems is not carried out.
- User access rights are not reviewed when users change roles.
- User access rights remain active when users leave your organisation.
- Access rights granted to devices or systems to access other devices and systems are not reviewed on a regular basis (at least annually).
Partially achieved - All of the following statements are true:
- You follow a robust procedure to verify each user and issue the minimum required access rights.
- You regularly review access rights and those no longer needed are revoked.
- User access rights are reviewed when users change roles via your joiners, leavers and movers process.
- All user, device and system access to the systems supporting the essential function(s) is logged and monitored, but it is not compared to other log data or access records.
Achieved - All of the following statements are true:
- You follow a robust procedure to verify each user and issue the minimum required access rights, and the application of the procedure is regularly audited.
- User access rights are reviewed both when people change roles via your joiners, leavers and movers process and at regular intervals - at least annually.
- All user, device and systems access to the systems supporting the essential function(s) is logged and monitored.
- You regularly review access logs and correlate this data with other access records and expected activity.
- Attempts by unauthorised users, devices or systems to connect to the systems supporting the essential function(s) are alerted, promptly assessed and investigated.
Data stored or transmitted electronically is protected from actions such as unauthorised access, modification, or deletion that may cause an adverse impact on essential functions. Such protection extends to the means by which authorised users, devices and systems access critical data necessary for the operation of essential functions. It also covers information that would assist an attacker, such as design details of networks and information systems.
Description
error determining description
Guidance
Networks and information systems should be designed to protect important data, for example:
protecting the confidentiality of sensitive data by minimising the number of copies of data, the detail these include and by retaining operationally sensitive data on segregated systems (this includes design documentation)
removing functionality that could allow greater access than has been authorised
protecting the integrity of data essential to the operation of the function by providing a read-only copy for non-essential business system consumption
only deploying well-tested cryptographic suites in common use by your chosen software stack
protecting availability through
resilience
measures such as multiple network paths and tested automatic backup systems
consider suitable means to retain access to essential information in the event of an incident. For example, network diagrams needed for restoration, safety-critical information or essential forecasting data
protecting the confidentiality of sensitive data by minimising the number of copies of data, the detail these include and by retaining operationally sensitive data on segregated systems (this includes design documentation)
Contributing Outcomes
B3.a Understanding Data
- You have a good understanding of data important to the operation of network and information systems supporting your essential function(s), where it is stored, where it travels and how unavailability or unauthorised access, uncontrolled release, modification or deletion would adversely impact the essential function(s). This also applies to third parties storing or accessing data important to the operation of essential function(s).
- You have a good understanding of data important to the operation of network and information systems supporting your essential function(s), where it is stored, where it travels and how unavailability or unauthorised access, uncontrolled release, modification or deletion would adversely impact the essential function(s). This also applies to third parties storing or accessing data important to the operation of essential function(s).
- You have incomplete knowledge of what data is used by and produced in the operation of network and information systems supporting your essential function(s).
- You have not identified the important data on which network and information systems supporting your essential function(s) relies.
- You have not identified who has access to data important to the operation of network and information systems supporting your essential function(s).
- You have not clearly articulated the impact of data compromise or lack of availability.
- You have identified and catalogued all the data important to the operation of network and information systems supporting your essential function(s), or that would assist a threat actor.
- You have identified and catalogued who has access to the data important to the operation of network and information systems supporting your essential function(s).
- You regularly review location, transmission, quantity and quality of data important to the operation of network and information systems supporting your essential function(s).
- You have identified all mobile devices and media that hold data important to the operation of network and information systems supporting your essential function(s).
- You understand and document the impact on your essential function(s) of all relevant scenarios, including unauthorised data access, uncontrolled release, modification or deletion, or when authorised users are unable to appropriately access this data.
- You occasionally validate these documented impact statements.
- You have identified and catalogued all the data important to the operation of network and information systems supporting your essential function(s), or that would assist a threat actor.
- You have identified and catalogued who has access to the data important to the operation of network and information systems supporting your essential function(s).
- You maintain a current understanding of the location, quantity and quality of data important to the operation of network and information systems supporting your essential function(s).
- You take steps to remove or minimise unnecessary copies or unneeded historic data.
- You have identified all mobile devices and media that may hold data important to the operation of network and information systems supporting your essential function(s).
- You maintain a current understanding of the data links used to transmit data that is important to network and information systems supporting your essential function(s).
- You understand the context, limitations and dependencies of your important data.
- You understand and document the impact on your essential function(s) of all relevant scenarios, including unauthorised data access, uncontrolled release, modification or deletion, or when authorised users are unable to appropriately access this data.
- You validate these documented impact statements regularly, at least annually.
Not achieved - At least one of the following statements is true:
- You have incomplete knowledge of what data is used by and produced in the operation of network and information systems supporting your essential function(s).
- You have not identified the important data on which network and information systems supporting your essential function(s) relies.
- You have not identified who has access to data important to the operation of network and information systems supporting your essential function(s).
- You have not clearly articulated the impact of data compromise or lack of availability.
Partially achieved - All of the following statements are true:
- You have identified and catalogued all the data important to the operation of network and information systems supporting your essential function(s), or that would assist a threat actor.
- You have identified and catalogued who has access to the data important to the operation of network and information systems supporting your essential function(s).
- You regularly review location, transmission, quantity and quality of data important to the operation of network and information systems supporting your essential function(s).
- You have identified all mobile devices and media that hold data important to the operation of network and information systems supporting your essential function(s).
- You understand and document the impact on your essential function(s) of all relevant scenarios, including unauthorised data access, uncontrolled release, modification or deletion, or when authorised users are unable to appropriately access this data.
- You occasionally validate these documented impact statements.
Achieved - All of the following statements are true:
- You have identified and catalogued all the data important to the operation of network and information systems supporting your essential function(s), or that would assist a threat actor.
- You have identified and catalogued who has access to the data important to the operation of network and information systems supporting your essential function(s).
- You maintain a current understanding of the location, quantity and quality of data important to the operation of network and information systems supporting your essential function(s).
- You take steps to remove or minimise unnecessary copies or unneeded historic data.
- You have identified all mobile devices and media that may hold data important to the operation of network and information systems supporting your essential function(s).
- You maintain a current understanding of the data links used to transmit data that is important to network and information systems supporting your essential function(s).
- You understand the context, limitations and dependencies of your important data.
- You understand and document the impact on your essential function(s) of all relevant scenarios, including unauthorised data access, uncontrolled release, modification or deletion, or when authorised users are unable to appropriately access this data.
- You validate these documented impact statements regularly, at least annually.
B3.b Data in Transit
- You have protected the transit of data important to the operation of network and information systems supporting your essential function(s). This includes the transfer of data to third parties.
- You have protected the transit of data important to the operation of network and information systems supporting your essential function(s). This includes the transfer of data to third parties.
- You do not know what all your data links are, or which carry data important to the operation of the essential function(s).
- Data important to the operation of the essential function(s) travels without technical protection over non-trusted or openly accessible carriers.
- Critical data paths that could fail, be jammed, be overloaded, etc. have no alternative path.
- You have identified and protected (effectively and proportionately) all the data links that carry data important to the operation of your essential function(s).
- You apply appropriate technical means (e.g. cryptography) to protect data that travels over non-trusted or openly accessible carriers, but you have limited or no confidence in the robustness of the protection applied.
- You have identified and protected (effectively and proportionately) all the data links that carry data important to the operation of your essential function(s).
- You apply appropriate physical and/or technical means to protect data that travels over non-trusted or openly accessible carriers, with justified confidence in the robustness of the protection applied.
- Suitable alternative transmission paths are available where there is a significant risk of impact on the operation of the essential function(s) due to resource limitation (e.g. transmission equipment or function failure, or important data being blocked or jammed).
Not achieved - At least one of the following statements is true:
- You do not know what all your data links are, or which carry data important to the operation of the essential function(s).
- Data important to the operation of the essential function(s) travels without technical protection over non-trusted or openly accessible carriers.
- Critical data paths that could fail, be jammed, be overloaded, etc. have no alternative path.
Partially achieved - All the following statements are true:
- You have identified and protected (effectively and proportionately) all the data links that carry data important to the operation of your essential function(s).
- You apply appropriate technical means (e.g. cryptography) to protect data that travels over non-trusted or openly accessible carriers, but you have limited or no confidence in the robustness of the protection applied.
Achieved - All the following statements are true:
- You have identified and protected (effectively and proportionately) all the data links that carry data important to the operation of your essential function(s).
- You apply appropriate physical and/or technical means to protect data that travels over non-trusted or openly accessible carriers, with justified confidence in the robustness of the protection applied.
- Suitable alternative transmission paths are available where there is a significant risk of impact on the operation of the essential function(s) due to resource limitation (e.g. transmission equipment or function failure, or important data being blocked or jammed).
B3.c Stored Data
- You have protected stored soft and hard copy data important to the operation of network and information systems supporting your essential function(s).
- You have protected stored soft and hard copy data important to the operation of network and information systems supporting your essential function(s).
- You have no, or limited, knowledge of where data important to the operation of the essential function(s) is stored.
- You have not protected vulnerable stored data important to the operation of the essential function(s) in a suitable way.
- Backups are incomplete, untested, not adequately secured or could be inaccessible in a disaster recovery or business continuity situation.
- All copies of data important to the operation of your essential function(s) are necessary. Where this important data is transferred to less secure systems, the data is provided with limited detail and / or as a read-only copy.
- You have applied suitable physical and / or technical means to protect this important stored data from unauthorised access, modification or deletion.
- If cryptographic protections are used, you apply suitable technical and procedural means, but you have limited or no confidence in the robustness of the protection applied.
- You have suitable, secured backups of data to allow the operation of the essential function(s) to continue should the original data not be available. This may include off-line or segregated backups, or appropriate alternative forms such as paper copies.
- All copies of data important to the operation of your essential function(s) are necessary. Where this important data is transferred to less secure systems, the data is provided with limited detail and / or as a read-only copy.
- You have applied suitable physical and / or technical means to protect this important stored data from unauthorised access, modification or deletion.
- If cryptographic protections are used you apply suitable technical and procedural means, and you have justified confidence in the robustness of the protection applied.
- You have suitable, secured backups of data to allow the operation of the essential function(s) to continue should the original data not be available. This may include off-line or segregated backups, or appropriate alternative forms such as paper copies.
- Necessary historic or archive data is suitably secured in storage.
Not achieved - At least one of the following statements is true:
- You have no, or limited, knowledge of where data important to the operation of the essential function(s) is stored.
- You have not protected vulnerable stored data important to the operation of the essential function(s) in a suitable way.
- Backups are incomplete, untested, not adequately secured or could be inaccessible in a disaster recovery or business continuity situation.
Partially achieved - All of the following statements are true:
- All copies of data important to the operation of your essential function(s) are necessary. Where this important data is transferred to less secure systems, the data is provided with limited detail and / or as a read-only copy.
- You have applied suitable physical and / or technical means to protect this important stored data from unauthorised access, modification or deletion.
- If cryptographic protections are used, you apply suitable technical and procedural means, but you have limited or no confidence in the robustness of the protection applied.
- You have suitable, secured backups of data to allow the operation of the essential function(s) to continue should the original data not be available. This may include off-line or segregated backups, or appropriate alternative forms such as paper copies.
Achieved - All of the following statements are true:
- All copies of data important to the operation of your essential function(s) are necessary. Where this important data is transferred to less secure systems, the data is provided with limited detail and / or as a read-only copy.
- You have applied suitable physical and / or technical means to protect this important stored data from unauthorised access, modification or deletion.
- If cryptographic protections are used you apply suitable technical and procedural means, and you have justified confidence in the robustness of the protection applied.
- You have suitable, secured backups of data to allow the operation of the essential function(s) to continue should the original data not be available. This may include off-line or segregated backups, or appropriate alternative forms such as paper copies.
- Necessary historic or archive data is suitably secured in storage.
B3.d Mobile Data
- You have protected data important to the operation of network and information systems supporting your essential function(s) on mobile devices (e.g. smartphones, tablets and laptops).
- You have protected data important to the operation of network and information systems supporting your essential function(s) on mobile devices (e.g. smartphones, tablets and laptops).
- You don’t know which mobile devices may hold data important to the operation of the essential function(s).
- You allow data important to the operation of the essential function(s) to be stored on devices not managed by your organisation, or to at least equivalent standard.
- Data on mobile devices is not technically secured, or only some is secured.
- You know which mobile devices hold data important to the operation of the essential function(s).
- Data important to the operation of the essential function(s) is stored on mobile devices only when they have at least the security standard aligned to your overarching security policies.
- Data on mobile devices is technically secured.
- Mobile devices that hold data that is important to the operation of the essential function(s) are catalogued, are under your organisation's control and configured according to best practice for the platform, with appropriate technical and procedural policies in place.
- Your organisation can remotely wipe all mobile devices holding data important to the operation of the essential function(s).
- You have minimised this data on these mobile devices. Some data may be automatically deleted off mobile devices after a certain period.
Not achieved - At least one of the following statements is true:
- You don’t know which mobile devices may hold data important to the operation of the essential function(s).
- You allow data important to the operation of the essential function(s) to be stored on devices not managed by your organisation, or to at least equivalent standard.
- Data on mobile devices is not technically secured, or only some is secured.
Partially achieved - All of the following statements are true:
- You know which mobile devices hold data important to the operation of the essential function(s).
- Data important to the operation of the essential function(s) is stored on mobile devices only when they have at least the security standard aligned to your overarching security policies.
- Data on mobile devices is technically secured.
Achieved - All of the following statements are true:
- Mobile devices that hold data that is important to the operation of the essential function(s) are catalogued, are under your organisation's control and configured according to best practice for the platform, with appropriate technical and procedural policies in place.
- Your organisation can remotely wipe all mobile devices holding data important to the operation of the essential function(s).
- You have minimised this data on these mobile devices. Some data may be automatically deleted off mobile devices after a certain period.
B3.e Media/Equipment Sanitisation
- Before reuse and / or disposal you appropriately sanitise devices, equipment and removable media holding data important to the operation of network and information systems supporting your essential function(s).
- Before reuse and / or disposal you appropriately sanitise devices, equipment and removable media holding data important to the operation of network and information systems supporting your essential function(s).
- You catalogue and track all devices that contain data important to the operation of the essential function(s) (whether a specific storage device or one with integral storage).
- Data important to the operation of the essential function(s) is removed from all devices, equipment and removable media before reuse and / or disposal using an assured product or service.
Not achieved - At least one of the following statements is true:
Partially achieved - All of the following statements are true:
Achieved - All of the following statements are true:
- You catalogue and track all devices that contain data important to the operation of the essential function(s) (whether a specific storage device or one with integral storage).
- Data important to the operation of the essential function(s) is removed from all devices, equipment and removable media before reuse and / or disposal using an assured product or service.
Data stored or transmitted electronically is protected from actions such as unauthorised access, modification, or deletion that may cause an adverse impact on essential functions. Such protection extends to the means by which authorised users, devices and systems access critical data necessary for the operation of essential functions. It also covers information that would assist an attacker, such as design details of networks and information systems.
Description
error determining description
Guidance
Networks and information systems should be designed to protect important data, for example:
protecting the confidentiality of sensitive data by minimising the number of copies of data, the detail these include and by retaining operationally sensitive data on segregated systems (this includes design documentation)
removing functionality that could allow greater access than has been authorised
protecting the integrity of data essential to the operation of the function by providing a read-only copy for non-essential business system consumption
only deploying well-tested cryptographic suites in common use by your chosen software stack
protecting availability through
resilience
measures such as multiple network paths and tested automatic backup systems
consider suitable means to retain access to essential information in the event of an incident. For example, network diagrams needed for restoration, safety-critical information or essential forecasting data
protecting the confidentiality of sensitive data by minimising the number of copies of data, the detail these include and by retaining operationally sensitive data on segregated systems (this includes design documentation)
Contributing Outcomes
B3.a Understanding Data
- You have a good understanding of data important to the operation of network and information systems supporting your essential function(s), where it is stored, where it travels and how unavailability or unauthorised access, uncontrolled release, modification or deletion would adversely impact the essential function(s). This also applies to third parties storing or accessing data important to the operation of essential function(s).
- You have a good understanding of data important to the operation of network and information systems supporting your essential function(s), where it is stored, where it travels and how unavailability or unauthorised access, uncontrolled release, modification or deletion would adversely impact the essential function(s). This also applies to third parties storing or accessing data important to the operation of essential function(s).
- You have incomplete knowledge of what data is used by and produced in the operation of network and information systems supporting your essential function(s).
- You have not identified the important data on which network and information systems supporting your essential function(s) relies.
- You have not identified who has access to data important to the operation of network and information systems supporting your essential function(s).
- You have not clearly articulated the impact of data compromise or lack of availability.
- You have identified and catalogued all the data important to the operation of network and information systems supporting your essential function(s), or that would assist a threat actor.
- You have identified and catalogued who has access to the data important to the operation of network and information systems supporting your essential function(s).
- You regularly review location, transmission, quantity and quality of data important to the operation of network and information systems supporting your essential function(s).
- You have identified all mobile devices and media that hold data important to the operation of network and information systems supporting your essential function(s).
- You understand and document the impact on your essential function(s) of all relevant scenarios, including unauthorised data access, uncontrolled release, modification or deletion, or when authorised users are unable to appropriately access this data.
- You occasionally validate these documented impact statements.
- You have identified and catalogued all the data important to the operation of network and information systems supporting your essential function(s), or that would assist a threat actor.
- You have identified and catalogued who has access to the data important to the operation of network and information systems supporting your essential function(s).
- You maintain a current understanding of the location, quantity and quality of data important to the operation of network and information systems supporting your essential function(s).
- You take steps to remove or minimise unnecessary copies or unneeded historic data.
- You have identified all mobile devices and media that may hold data important to the operation of network and information systems supporting your essential function(s).
- You maintain a current understanding of the data links used to transmit data that is important to network and information systems supporting your essential function(s).
- You understand the context, limitations and dependencies of your important data.
- You understand and document the impact on your essential function(s) of all relevant scenarios, including unauthorised data access, uncontrolled release, modification or deletion, or when authorised users are unable to appropriately access this data.
- You validate these documented impact statements regularly, at least annually.
Not achieved - At least one of the following statements is true:
- You have incomplete knowledge of what data is used by and produced in the operation of network and information systems supporting your essential function(s).
- You have not identified the important data on which network and information systems supporting your essential function(s) relies.
- You have not identified who has access to data important to the operation of network and information systems supporting your essential function(s).
- You have not clearly articulated the impact of data compromise or lack of availability.
Partially achieved - All of the following statements are true:
- You have identified and catalogued all the data important to the operation of network and information systems supporting your essential function(s), or that would assist a threat actor.
- You have identified and catalogued who has access to the data important to the operation of network and information systems supporting your essential function(s).
- You regularly review location, transmission, quantity and quality of data important to the operation of network and information systems supporting your essential function(s).
- You have identified all mobile devices and media that hold data important to the operation of network and information systems supporting your essential function(s).
- You understand and document the impact on your essential function(s) of all relevant scenarios, including unauthorised data access, uncontrolled release, modification or deletion, or when authorised users are unable to appropriately access this data.
- You occasionally validate these documented impact statements.
Achieved - All of the following statements are true:
- You have identified and catalogued all the data important to the operation of network and information systems supporting your essential function(s), or that would assist a threat actor.
- You have identified and catalogued who has access to the data important to the operation of network and information systems supporting your essential function(s).
- You maintain a current understanding of the location, quantity and quality of data important to the operation of network and information systems supporting your essential function(s).
- You take steps to remove or minimise unnecessary copies or unneeded historic data.
- You have identified all mobile devices and media that may hold data important to the operation of network and information systems supporting your essential function(s).
- You maintain a current understanding of the data links used to transmit data that is important to network and information systems supporting your essential function(s).
- You understand the context, limitations and dependencies of your important data.
- You understand and document the impact on your essential function(s) of all relevant scenarios, including unauthorised data access, uncontrolled release, modification or deletion, or when authorised users are unable to appropriately access this data.
- You validate these documented impact statements regularly, at least annually.
B3.b Data in Transit
- You have protected the transit of data important to the operation of network and information systems supporting your essential function(s). This includes the transfer of data to third parties.
- You have protected the transit of data important to the operation of network and information systems supporting your essential function(s). This includes the transfer of data to third parties.
- You do not know what all your data links are, or which carry data important to the operation of the essential function(s).
- Data important to the operation of the essential function(s) travels without technical protection over non-trusted or openly accessible carriers.
- Critical data paths that could fail, be jammed, be overloaded, etc. have no alternative path.
- You have identified and protected (effectively and proportionately) all the data links that carry data important to the operation of your essential function(s).
- You apply appropriate technical means (e.g. cryptography) to protect data that travels over non-trusted or openly accessible carriers, but you have limited or no confidence in the robustness of the protection applied.
- You have identified and protected (effectively and proportionately) all the data links that carry data important to the operation of your essential function(s).
- You apply appropriate physical and/or technical means to protect data that travels over non-trusted or openly accessible carriers, with justified confidence in the robustness of the protection applied.
- Suitable alternative transmission paths are available where there is a significant risk of impact on the operation of the essential function(s) due to resource limitation (e.g. transmission equipment or function failure, or important data being blocked or jammed).
Not achieved - At least one of the following statements is true:
- You do not know what all your data links are, or which carry data important to the operation of the essential function(s).
- Data important to the operation of the essential function(s) travels without technical protection over non-trusted or openly accessible carriers.
- Critical data paths that could fail, be jammed, be overloaded, etc. have no alternative path.
Partially achieved - All the following statements are true:
- You have identified and protected (effectively and proportionately) all the data links that carry data important to the operation of your essential function(s).
- You apply appropriate technical means (e.g. cryptography) to protect data that travels over non-trusted or openly accessible carriers, but you have limited or no confidence in the robustness of the protection applied.
Achieved - All the following statements are true:
- You have identified and protected (effectively and proportionately) all the data links that carry data important to the operation of your essential function(s).
- You apply appropriate physical and/or technical means to protect data that travels over non-trusted or openly accessible carriers, with justified confidence in the robustness of the protection applied.
- Suitable alternative transmission paths are available where there is a significant risk of impact on the operation of the essential function(s) due to resource limitation (e.g. transmission equipment or function failure, or important data being blocked or jammed).
B3.c Stored Data
- You have protected stored soft and hard copy data important to the operation of network and information systems supporting your essential function(s).
- You have protected stored soft and hard copy data important to the operation of network and information systems supporting your essential function(s).
- You have no, or limited, knowledge of where data important to the operation of the essential function(s) is stored.
- You have not protected vulnerable stored data important to the operation of the essential function(s) in a suitable way.
- Backups are incomplete, untested, not adequately secured or could be inaccessible in a disaster recovery or business continuity situation.
- All copies of data important to the operation of your essential function(s) are necessary. Where this important data is transferred to less secure systems, the data is provided with limited detail and / or as a read-only copy.
- You have applied suitable physical and / or technical means to protect this important stored data from unauthorised access, modification or deletion.
- If cryptographic protections are used, you apply suitable technical and procedural means, but you have limited or no confidence in the robustness of the protection applied.
- You have suitable, secured backups of data to allow the operation of the essential function(s) to continue should the original data not be available. This may include off-line or segregated backups, or appropriate alternative forms such as paper copies.
- All copies of data important to the operation of your essential function(s) are necessary. Where this important data is transferred to less secure systems, the data is provided with limited detail and / or as a read-only copy.
- You have applied suitable physical and / or technical means to protect this important stored data from unauthorised access, modification or deletion.
- If cryptographic protections are used you apply suitable technical and procedural means, and you have justified confidence in the robustness of the protection applied.
- You have suitable, secured backups of data to allow the operation of the essential function(s) to continue should the original data not be available. This may include off-line or segregated backups, or appropriate alternative forms such as paper copies.
- Necessary historic or archive data is suitably secured in storage.
Not achieved - At least one of the following statements is true:
- You have no, or limited, knowledge of where data important to the operation of the essential function(s) is stored.
- You have not protected vulnerable stored data important to the operation of the essential function(s) in a suitable way.
- Backups are incomplete, untested, not adequately secured or could be inaccessible in a disaster recovery or business continuity situation.
Partially achieved - All of the following statements are true:
- All copies of data important to the operation of your essential function(s) are necessary. Where this important data is transferred to less secure systems, the data is provided with limited detail and / or as a read-only copy.
- You have applied suitable physical and / or technical means to protect this important stored data from unauthorised access, modification or deletion.
- If cryptographic protections are used, you apply suitable technical and procedural means, but you have limited or no confidence in the robustness of the protection applied.
- You have suitable, secured backups of data to allow the operation of the essential function(s) to continue should the original data not be available. This may include off-line or segregated backups, or appropriate alternative forms such as paper copies.
Achieved - All of the following statements are true:
- All copies of data important to the operation of your essential function(s) are necessary. Where this important data is transferred to less secure systems, the data is provided with limited detail and / or as a read-only copy.
- You have applied suitable physical and / or technical means to protect this important stored data from unauthorised access, modification or deletion.
- If cryptographic protections are used you apply suitable technical and procedural means, and you have justified confidence in the robustness of the protection applied.
- You have suitable, secured backups of data to allow the operation of the essential function(s) to continue should the original data not be available. This may include off-line or segregated backups, or appropriate alternative forms such as paper copies.
- Necessary historic or archive data is suitably secured in storage.
B3.d Mobile Data
- You have protected data important to the operation of network and information systems supporting your essential function(s) on mobile devices (e.g. smartphones, tablets and laptops).
- You have protected data important to the operation of network and information systems supporting your essential function(s) on mobile devices (e.g. smartphones, tablets and laptops).
- You don’t know which mobile devices may hold data important to the operation of the essential function(s).
- You allow data important to the operation of the essential function(s) to be stored on devices not managed by your organisation, or to at least equivalent standard.
- Data on mobile devices is not technically secured, or only some is secured.
- You know which mobile devices hold data important to the operation of the essential function(s).
- Data important to the operation of the essential function(s) is stored on mobile devices only when they have at least the security standard aligned to your overarching security policies.
- Data on mobile devices is technically secured.
- Mobile devices that hold data that is important to the operation of the essential function(s) are catalogued, are under your organisation's control and configured according to best practice for the platform, with appropriate technical and procedural policies in place.
- Your organisation can remotely wipe all mobile devices holding data important to the operation of the essential function(s).
- You have minimised this data on these mobile devices. Some data may be automatically deleted off mobile devices after a certain period.
Not achieved - At least one of the following statements is true:
- You don’t know which mobile devices may hold data important to the operation of the essential function(s).
- You allow data important to the operation of the essential function(s) to be stored on devices not managed by your organisation, or to at least equivalent standard.
- Data on mobile devices is not technically secured, or only some is secured.
Partially achieved - All of the following statements are true:
- You know which mobile devices hold data important to the operation of the essential function(s).
- Data important to the operation of the essential function(s) is stored on mobile devices only when they have at least the security standard aligned to your overarching security policies.
- Data on mobile devices is technically secured.
Achieved - All of the following statements are true:
- Mobile devices that hold data that is important to the operation of the essential function(s) are catalogued, are under your organisation's control and configured according to best practice for the platform, with appropriate technical and procedural policies in place.
- Your organisation can remotely wipe all mobile devices holding data important to the operation of the essential function(s).
- You have minimised this data on these mobile devices. Some data may be automatically deleted off mobile devices after a certain period.
B3.e Media/Equipment Sanitisation
- Before reuse and / or disposal you appropriately sanitise devices, equipment and removable media holding data important to the operation of network and information systems supporting your essential function(s).
- Before reuse and / or disposal you appropriately sanitise devices, equipment and removable media holding data important to the operation of network and information systems supporting your essential function(s).
- You catalogue and track all devices that contain data important to the operation of the essential function(s) (whether a specific storage device or one with integral storage).
- Data important to the operation of the essential function(s) is removed from all devices, equipment and removable media before reuse and / or disposal using an assured product or service.
Not achieved - At least one of the following statements is true:
Partially achieved - All of the following statements are true:
Achieved - All of the following statements are true:
- You catalogue and track all devices that contain data important to the operation of the essential function(s) (whether a specific storage device or one with integral storage).
- Data important to the operation of the essential function(s) is removed from all devices, equipment and removable media before reuse and / or disposal using an assured product or service.
Network and information systems and technology critical for the operation of essential functions are protected from cyber attack. An organisational understanding of risk to essential functions informs the use of robust and reliable protective security measures to effectively limit opportunities for threat actors to compromise networks and systems.
Description
error determining description
Guidance
The majority of cyber security incidents can be traced to
common cyber attack
vectors. The opportunity for successful attack can be minimised by managing the known vulnerabilities which these attacks exploit. Many opportunities for user error can be reduced by technical means.
Attempts to circumvent the measures described below should be detected by
security monitoring
. Together with
data security
and
resilience measures
, the impact of any attempts to circumvent security on the operation of the essential function should be limited.
Contributing Outcomes
B4.a Secure by Design
- You design security into the network and information systems that support the operation of the essential function(s). You minimise their attack surface and ensure that the operation of the essential function(s) should not be impacted by the exploitation of any single vulnerability.
- You design security into the network and information systems that support the operation of the essential function(s). You minimise their attack surface and ensure that the operation of the essential function(s) should not be impacted by the exploitation of any single vulnerability.
- Network and information systems supporting the operation of the essential function(s) are not appropriately segregated from other systems.
- Internet services, such as browsing and email are accessible from network and information systems supporting your essential function(s).
- Data flows between network and information systems supporting your essential function(s) and other systems are complex, making it hard to discriminate between legitimate and illegitimate / malicious traffic.
- Remote or third-party accesses circumvent some network controls to gain more direct access to network and information systems supporting the essential function(s).
- You employ appropriate expertise to design network and information systems supporting your essential function(s).
- You design strong boundary defences where your network and information systems interface with other organisations or the world at large.
- You design simple data flows between your network and information systems and any external interface to enable effective monitoring.
- You design to make network and information system recovery simple.
- All inputs to network and information systems are checked and validated at the network boundary where possible, or additional monitoring is in place for content-based attacks.
- You employ appropriate expertise to design network and information systems supporting your essential function(s).
- Network and information systems are segregated into appropriate security zones (e.g. systems supporting the essential function(s) are segregated in a highly trusted, more secure zone).
- The network and information systems supporting your essential function(s) are designed to have simple data flows between components to support effective security monitoring.
- The network and information systems supporting your essential function(s) are designed to be easy to recover.
- Content-based attacks are mitigated for all inputs to network and information systems that affect the essential function(s) (e.g. via transformation and inspection / sanitisation and validation).
- If automated decision-making technologies are in use, you design and apply appropriate restrictions to prevent actions that could have an adverse impact on network and information systems supporting your essential function(s).
Not achieved - At least one of the following statements is true:
- Network and information systems supporting the operation of the essential function(s) are not appropriately segregated from other systems.
- Internet services, such as browsing and email are accessible from network and information systems supporting your essential function(s).
- Data flows between network and information systems supporting your essential function(s) and other systems are complex, making it hard to discriminate between legitimate and illegitimate / malicious traffic.
- Remote or third-party accesses circumvent some network controls to gain more direct access to network and information systems supporting the essential function(s).
Partially achieved - All the following statements are true:
- You employ appropriate expertise to design network and information systems supporting your essential function(s).
- You design strong boundary defences where your network and information systems interface with other organisations or the world at large.
- You design simple data flows between your network and information systems and any external interface to enable effective monitoring.
- You design to make network and information system recovery simple.
- All inputs to network and information systems are checked and validated at the network boundary where possible, or additional monitoring is in place for content-based attacks.
Achieved - All the following statements are true:
- You employ appropriate expertise to design network and information systems supporting your essential function(s).
- Network and information systems are segregated into appropriate security zones (e.g. systems supporting the essential function(s) are segregated in a highly trusted, more secure zone).
- The network and information systems supporting your essential function(s) are designed to have simple data flows between components to support effective security monitoring.
- The network and information systems supporting your essential function(s) are designed to be easy to recover.
- Content-based attacks are mitigated for all inputs to network and information systems that affect the essential function(s) (e.g. via transformation and inspection / sanitisation and validation).
- If automated decision-making technologies are in use, you design and apply appropriate restrictions to prevent actions that could have an adverse impact on network and information systems supporting your essential function(s).
B4.b Secure Configuration
- You securely configure network and information systems that support the operation of your essential function(s).
- You securely configure network and information systems that support the operation of your essential function(s).
- You haven't identified the assets that need to be carefully configured to maintain the security of the essential function(s).
- Policies relating to the security of operating system builds or configuration are not applied consistently across your network and information systems relating to your essential function(s).
- Configuration details are not recorded or lack enough information to be able to rebuild the system or device.
- The recording of security changes or adjustments that affect your essential function(s) is lacking or inconsistent.
- Generic, shared, default name and built-in accounts have not been removed or disabled.
- Standard users are able to change settings that would adversely impact the security of network and information systems supporting your essential function(s).
- You have identified and documented the assets that need to be carefully configured to maintain the security of the essential function(s).
- Secure platform and device builds are used across the estate.
- Consistent, secure and minimal system and device configurations are applied across the same types of environment.
- Changes and adjustments to security configuration at security boundaries with the network and information systems supporting your essential function(s) are approved and documented.
- You verify software before installation is permitted.
- Generic, shared, default name and built-in accounts have been removed or disabled. Where this is not possible, credentials to these accounts have been changed. Service accounts are appropriately protected.
- Standard users are not able to change settings that would adversely impact the security of network and information systems supporting your essential function(s).
- You have identified, documented and actively manage (e.g. maintain security configurations, patching, updating according to good practice) the assets that need to be carefully configured to maintain the security of the essential function(s).
- All platforms conform to your secure, defined baseline build, or the latest known good configuration version for that environment.
- You closely and effectively manage changes in your environment, ensuring that network and system configurations are secure and documented.
- You regularly review and validate that your network and information systems have the expected, secure settings and configuration.
- Only permitted software can be installed.
- If automated decision-making technologies are in use, their operation is well understood, and decisions can be replicated.
- Generic, shared, default name and built-in accounts have been removed or disabled. Where this is not possible, credentials to these accounts have been changed. Service accounts are appropriately protected.
Not achieved - At least one of the following statements is true:
- You haven't identified the assets that need to be carefully configured to maintain the security of the essential function(s).
- Policies relating to the security of operating system builds or configuration are not applied consistently across your network and information systems relating to your essential function(s).
- Configuration details are not recorded or lack enough information to be able to rebuild the system or device.
- The recording of security changes or adjustments that affect your essential function(s) is lacking or inconsistent.
- Generic, shared, default name and built-in accounts have not been removed or disabled.
- Standard users are able to change settings that would adversely impact the security of network and information systems supporting your essential function(s).
Partially achieved - All of the following statements are true:
- You have identified and documented the assets that need to be carefully configured to maintain the security of the essential function(s).
- Secure platform and device builds are used across the estate.
- Consistent, secure and minimal system and device configurations are applied across the same types of environment.
- Changes and adjustments to security configuration at security boundaries with the network and information systems supporting your essential function(s) are approved and documented.
- You verify software before installation is permitted.
- Generic, shared, default name and built-in accounts have been removed or disabled. Where this is not possible, credentials to these accounts have been changed. Service accounts are appropriately protected.
- Standard users are not able to change settings that would adversely impact the security of network and information systems supporting your essential function(s).
Achieved - All of the following statements are true:
- You have identified, documented and actively manage (e.g. maintain security configurations, patching, updating according to good practice) the assets that need to be carefully configured to maintain the security of the essential function(s).
- All platforms conform to your secure, defined baseline build, or the latest known good configuration version for that environment.
- You closely and effectively manage changes in your environment, ensuring that network and system configurations are secure and documented.
- You regularly review and validate that your network and information systems have the expected, secure settings and configuration.
- Only permitted software can be installed.
- If automated decision-making technologies are in use, their operation is well understood, and decisions can be replicated.
- Generic, shared, default name and built-in accounts have been removed or disabled. Where this is not possible, credentials to these accounts have been changed. Service accounts are appropriately protected.
B4.c Secure Management
- You manage your organisation's network and information systems that support the operation of your essential function(s) to enable and maintain security.
- You manage your organisation's network and information systems that support the operation of your essential function(s) to enable and maintain security.
- Your systems and devices supporting the operation of the essential function(s) are administered or maintained from devices that are not corporately owned and managed.
- You do not have good or current technical documentation of your network and information systems.
- Your systems and devices supporting the operation of the essential function(s) are only administered or maintained by authorised privileged users from devices sufficiently separated, using a risk-based approach, from the activities of standard users.
- Technical knowledge about network and information systems, such as documentation and network diagrams, is regularly reviewed and updated.
- You prevent, detect and remove malware or unauthorised software. You use technical, procedural and physical measures as necessary.
- Your systems and devices supporting the operation of the essential function(s) are only administered or maintained by authorised privileged users from highly trusted devices, such as Privileged Access Workstations, dedicated solely to those operations.
- You regularly review and update technical knowledge about network and information systems, such as documentation and network diagrams, and ensure they are securely stored.
- You prevent, detect and remove malware or unauthorised software. You use technical, procedural and physical measures as necessary.
Not achieved - At least one of the following statements is true:
- Your systems and devices supporting the operation of the essential function(s) are administered or maintained from devices that are not corporately owned and managed.
- You do not have good or current technical documentation of your network and information systems.
Partially achieved - All of the following statements are true:
- Your systems and devices supporting the operation of the essential function(s) are only administered or maintained by authorised privileged users from devices sufficiently separated, using a risk-based approach, from the activities of standard users.
- Technical knowledge about network and information systems, such as documentation and network diagrams, is regularly reviewed and updated.
- You prevent, detect and remove malware or unauthorised software. You use technical, procedural and physical measures as necessary.
Achieved - All of the following statements are true:
- Your systems and devices supporting the operation of the essential function(s) are only administered or maintained by authorised privileged users from highly trusted devices, such as Privileged Access Workstations, dedicated solely to those operations.
- You regularly review and update technical knowledge about network and information systems, such as documentation and network diagrams, and ensure they are securely stored.
- You prevent, detect and remove malware or unauthorised software. You use technical, procedural and physical measures as necessary.
B4.d Vulnerability Management
- You manage known vulnerabilities in network and information systems to prevent adverse impact on your essential function(s).
- You manage known vulnerabilities in network and information systems to prevent adverse impact on your essential function(s).
- You do not understand the exposure of your essential function(s) to publicly-known vulnerabilities.
- You do not mitigate externally exposed vulnerabilities promptly.
- You have not recently tested to verify your understanding of the vulnerabilities of the network and information systems that support your essential function(s).
- You have not suitably mitigated systems or software that is no longer supported.
- You are not pursuing replacement for unsupported systems or software.
- You maintain a current understanding of the exposure of your essential function(s) to publicly-known vulnerabilities.
- Announced vulnerabilities for all software packages, network and information systems used to support your essential function(s) are tracked, prioritised and externally exposed vulnerabilities are mitigated (e.g. by patching) promptly.
- Some vulnerabilities that are not externally exposed have temporary mitigations for an extended period.
- You have temporary mitigations for unsupported systems and software while pursuing migration to supported technology.
- You regularly test to fully understand the vulnerabilities of the network and information systems that support the operation of your essential function(s).
- You maintain a current understanding of the exposure of your essential function(s) to publicly-known vulnerabilities.
- Announced vulnerabilities for all software packages, network and information systems used to support your essential function(s) are tracked, prioritised and mitigated (e.g. by patching) promptly.
- You regularly test to fully understand the vulnerabilities of the network and information systems that support the operation of your essential function(s) and verify this understanding with third-party testing.
- You actively maximise the use of supported software, firmware and hardware in your network and information systems supporting your essential function(s).
Not achieved - At least one of the following statements is true:
- You do not understand the exposure of your essential function(s) to publicly-known vulnerabilities.
- You do not mitigate externally exposed vulnerabilities promptly.
- You have not recently tested to verify your understanding of the vulnerabilities of the network and information systems that support your essential function(s).
- You have not suitably mitigated systems or software that is no longer supported.
- You are not pursuing replacement for unsupported systems or software.
Partially achieved - All of the following statements are true:
- You maintain a current understanding of the exposure of your essential function(s) to publicly-known vulnerabilities.
- Announced vulnerabilities for all software packages, network and information systems used to support your essential function(s) are tracked, prioritised and externally exposed vulnerabilities are mitigated (e.g. by patching) promptly.
- Some vulnerabilities that are not externally exposed have temporary mitigations for an extended period.
- You have temporary mitigations for unsupported systems and software while pursuing migration to supported technology.
- You regularly test to fully understand the vulnerabilities of the network and information systems that support the operation of your essential function(s).
Achieved - All of the following statements are true:
- You maintain a current understanding of the exposure of your essential function(s) to publicly-known vulnerabilities.
- Announced vulnerabilities for all software packages, network and information systems used to support your essential function(s) are tracked, prioritised and mitigated (e.g. by patching) promptly.
- You regularly test to fully understand the vulnerabilities of the network and information systems that support the operation of your essential function(s) and verify this understanding with third-party testing.
- You actively maximise the use of supported software, firmware and hardware in your network and information systems supporting your essential function(s).
Network and information systems and technology critical for the operation of essential functions are protected from cyber attack. An organisational understanding of risk to essential functions informs the use of robust and reliable protective security measures to effectively limit opportunities for threat actors to compromise networks and systems.
Description
error determining description
Guidance
The majority of cyber security incidents can be traced to
common cyber attack
vectors. The opportunity for successful attack can be minimised by managing the known vulnerabilities which these attacks exploit. Many opportunities for user error can be reduced by technical means.
Attempts to circumvent the measures described below should be detected by
security monitoring
. Together with
data security
and
resilience measures
, the impact of any attempts to circumvent security on the operation of the essential function should be limited.
Contributing Outcomes
B4.a Secure by Design
- You design security into the network and information systems that support the operation of the essential function(s). You minimise their attack surface and ensure that the operation of the essential function(s) should not be impacted by the exploitation of any single vulnerability.
- You design security into the network and information systems that support the operation of the essential function(s). You minimise their attack surface and ensure that the operation of the essential function(s) should not be impacted by the exploitation of any single vulnerability.
- Network and information systems supporting the operation of the essential function(s) are not appropriately segregated from other systems.
- Internet services, such as browsing and email are accessible from network and information systems supporting your essential function(s).
- Data flows between network and information systems supporting your essential function(s) and other systems are complex, making it hard to discriminate between legitimate and illegitimate / malicious traffic.
- Remote or third-party accesses circumvent some network controls to gain more direct access to network and information systems supporting the essential function(s).
- You employ appropriate expertise to design network and information systems supporting your essential function(s).
- You design strong boundary defences where your network and information systems interface with other organisations or the world at large.
- You design simple data flows between your network and information systems and any external interface to enable effective monitoring.
- You design to make network and information system recovery simple.
- All inputs to network and information systems are checked and validated at the network boundary where possible, or additional monitoring is in place for content-based attacks.
- You employ appropriate expertise to design network and information systems supporting your essential function(s).
- Network and information systems are segregated into appropriate security zones (e.g. systems supporting the essential function(s) are segregated in a highly trusted, more secure zone).
- The network and information systems supporting your essential function(s) are designed to have simple data flows between components to support effective security monitoring.
- The network and information systems supporting your essential function(s) are designed to be easy to recover.
- Content-based attacks are mitigated for all inputs to network and information systems that affect the essential function(s) (e.g. via transformation and inspection / sanitisation and validation).
- If automated decision-making technologies are in use, you design and apply appropriate restrictions to prevent actions that could have an adverse impact on network and information systems supporting your essential function(s).
Not achieved - At least one of the following statements is true:
- Network and information systems supporting the operation of the essential function(s) are not appropriately segregated from other systems.
- Internet services, such as browsing and email are accessible from network and information systems supporting your essential function(s).
- Data flows between network and information systems supporting your essential function(s) and other systems are complex, making it hard to discriminate between legitimate and illegitimate / malicious traffic.
- Remote or third-party accesses circumvent some network controls to gain more direct access to network and information systems supporting the essential function(s).
Partially achieved - All the following statements are true:
- You employ appropriate expertise to design network and information systems supporting your essential function(s).
- You design strong boundary defences where your network and information systems interface with other organisations or the world at large.
- You design simple data flows between your network and information systems and any external interface to enable effective monitoring.
- You design to make network and information system recovery simple.
- All inputs to network and information systems are checked and validated at the network boundary where possible, or additional monitoring is in place for content-based attacks.
Achieved - All the following statements are true:
- You employ appropriate expertise to design network and information systems supporting your essential function(s).
- Network and information systems are segregated into appropriate security zones (e.g. systems supporting the essential function(s) are segregated in a highly trusted, more secure zone).
- The network and information systems supporting your essential function(s) are designed to have simple data flows between components to support effective security monitoring.
- The network and information systems supporting your essential function(s) are designed to be easy to recover.
- Content-based attacks are mitigated for all inputs to network and information systems that affect the essential function(s) (e.g. via transformation and inspection / sanitisation and validation).
- If automated decision-making technologies are in use, you design and apply appropriate restrictions to prevent actions that could have an adverse impact on network and information systems supporting your essential function(s).
B4.b Secure Configuration
- You securely configure network and information systems that support the operation of your essential function(s).
- You securely configure network and information systems that support the operation of your essential function(s).
- You haven't identified the assets that need to be carefully configured to maintain the security of the essential function(s).
- Policies relating to the security of operating system builds or configuration are not applied consistently across your network and information systems relating to your essential function(s).
- Configuration details are not recorded or lack enough information to be able to rebuild the system or device.
- The recording of security changes or adjustments that affect your essential function(s) is lacking or inconsistent.
- Generic, shared, default name and built-in accounts have not been removed or disabled.
- Standard users are able to change settings that would adversely impact the security of network and information systems supporting your essential function(s).
- You have identified and documented the assets that need to be carefully configured to maintain the security of the essential function(s).
- Secure platform and device builds are used across the estate.
- Consistent, secure and minimal system and device configurations are applied across the same types of environment.
- Changes and adjustments to security configuration at security boundaries with the network and information systems supporting your essential function(s) are approved and documented.
- You verify software before installation is permitted.
- Generic, shared, default name and built-in accounts have been removed or disabled. Where this is not possible, credentials to these accounts have been changed. Service accounts are appropriately protected.
- Standard users are not able to change settings that would adversely impact the security of network and information systems supporting your essential function(s).
- You have identified, documented and actively manage (e.g. maintain security configurations, patching, updating according to good practice) the assets that need to be carefully configured to maintain the security of the essential function(s).
- All platforms conform to your secure, defined baseline build, or the latest known good configuration version for that environment.
- You closely and effectively manage changes in your environment, ensuring that network and system configurations are secure and documented.
- You regularly review and validate that your network and information systems have the expected, secure settings and configuration.
- Only permitted software can be installed.
- If automated decision-making technologies are in use, their operation is well understood, and decisions can be replicated.
- Generic, shared, default name and built-in accounts have been removed or disabled. Where this is not possible, credentials to these accounts have been changed. Service accounts are appropriately protected.
Not achieved - At least one of the following statements is true:
- You haven't identified the assets that need to be carefully configured to maintain the security of the essential function(s).
- Policies relating to the security of operating system builds or configuration are not applied consistently across your network and information systems relating to your essential function(s).
- Configuration details are not recorded or lack enough information to be able to rebuild the system or device.
- The recording of security changes or adjustments that affect your essential function(s) is lacking or inconsistent.
- Generic, shared, default name and built-in accounts have not been removed or disabled.
- Standard users are able to change settings that would adversely impact the security of network and information systems supporting your essential function(s).
Partially achieved - All of the following statements are true:
- You have identified and documented the assets that need to be carefully configured to maintain the security of the essential function(s).
- Secure platform and device builds are used across the estate.
- Consistent, secure and minimal system and device configurations are applied across the same types of environment.
- Changes and adjustments to security configuration at security boundaries with the network and information systems supporting your essential function(s) are approved and documented.
- You verify software before installation is permitted.
- Generic, shared, default name and built-in accounts have been removed or disabled. Where this is not possible, credentials to these accounts have been changed. Service accounts are appropriately protected.
- Standard users are not able to change settings that would adversely impact the security of network and information systems supporting your essential function(s).
Achieved - All of the following statements are true:
- You have identified, documented and actively manage (e.g. maintain security configurations, patching, updating according to good practice) the assets that need to be carefully configured to maintain the security of the essential function(s).
- All platforms conform to your secure, defined baseline build, or the latest known good configuration version for that environment.
- You closely and effectively manage changes in your environment, ensuring that network and system configurations are secure and documented.
- You regularly review and validate that your network and information systems have the expected, secure settings and configuration.
- Only permitted software can be installed.
- If automated decision-making technologies are in use, their operation is well understood, and decisions can be replicated.
- Generic, shared, default name and built-in accounts have been removed or disabled. Where this is not possible, credentials to these accounts have been changed. Service accounts are appropriately protected.
B4.c Secure Management
- You manage your organisation's network and information systems that support the operation of your essential function(s) to enable and maintain security.
- You manage your organisation's network and information systems that support the operation of your essential function(s) to enable and maintain security.
- Your systems and devices supporting the operation of the essential function(s) are administered or maintained from devices that are not corporately owned and managed.
- You do not have good or current technical documentation of your network and information systems.
- Your systems and devices supporting the operation of the essential function(s) are only administered or maintained by authorised privileged users from devices sufficiently separated, using a risk-based approach, from the activities of standard users.
- Technical knowledge about network and information systems, such as documentation and network diagrams, is regularly reviewed and updated.
- You prevent, detect and remove malware or unauthorised software. You use technical, procedural and physical measures as necessary.
- Your systems and devices supporting the operation of the essential function(s) are only administered or maintained by authorised privileged users from highly trusted devices, such as Privileged Access Workstations, dedicated solely to those operations.
- You regularly review and update technical knowledge about network and information systems, such as documentation and network diagrams, and ensure they are securely stored.
- You prevent, detect and remove malware or unauthorised software. You use technical, procedural and physical measures as necessary.
Not achieved - At least one of the following statements is true:
- Your systems and devices supporting the operation of the essential function(s) are administered or maintained from devices that are not corporately owned and managed.
- You do not have good or current technical documentation of your network and information systems.
Partially achieved - All of the following statements are true:
- Your systems and devices supporting the operation of the essential function(s) are only administered or maintained by authorised privileged users from devices sufficiently separated, using a risk-based approach, from the activities of standard users.
- Technical knowledge about network and information systems, such as documentation and network diagrams, is regularly reviewed and updated.
- You prevent, detect and remove malware or unauthorised software. You use technical, procedural and physical measures as necessary.
Achieved - All of the following statements are true:
- Your systems and devices supporting the operation of the essential function(s) are only administered or maintained by authorised privileged users from highly trusted devices, such as Privileged Access Workstations, dedicated solely to those operations.
- You regularly review and update technical knowledge about network and information systems, such as documentation and network diagrams, and ensure they are securely stored.
- You prevent, detect and remove malware or unauthorised software. You use technical, procedural and physical measures as necessary.
B4.d Vulnerability Management
- You manage known vulnerabilities in network and information systems to prevent adverse impact on your essential function(s).
- You manage known vulnerabilities in network and information systems to prevent adverse impact on your essential function(s).
- You do not understand the exposure of your essential function(s) to publicly-known vulnerabilities.
- You do not mitigate externally exposed vulnerabilities promptly.
- You have not recently tested to verify your understanding of the vulnerabilities of the network and information systems that support your essential function(s).
- You have not suitably mitigated systems or software that is no longer supported.
- You are not pursuing replacement for unsupported systems or software.
- You maintain a current understanding of the exposure of your essential function(s) to publicly-known vulnerabilities.
- Announced vulnerabilities for all software packages, network and information systems used to support your essential function(s) are tracked, prioritised and externally exposed vulnerabilities are mitigated (e.g. by patching) promptly.
- Some vulnerabilities that are not externally exposed have temporary mitigations for an extended period.
- You have temporary mitigations for unsupported systems and software while pursuing migration to supported technology.
- You regularly test to fully understand the vulnerabilities of the network and information systems that support the operation of your essential function(s).
- You maintain a current understanding of the exposure of your essential function(s) to publicly-known vulnerabilities.
- Announced vulnerabilities for all software packages, network and information systems used to support your essential function(s) are tracked, prioritised and mitigated (e.g. by patching) promptly.
- You regularly test to fully understand the vulnerabilities of the network and information systems that support the operation of your essential function(s) and verify this understanding with third-party testing.
- You actively maximise the use of supported software, firmware and hardware in your network and information systems supporting your essential function(s).
Not achieved - At least one of the following statements is true:
- You do not understand the exposure of your essential function(s) to publicly-known vulnerabilities.
- You do not mitigate externally exposed vulnerabilities promptly.
- You have not recently tested to verify your understanding of the vulnerabilities of the network and information systems that support your essential function(s).
- You have not suitably mitigated systems or software that is no longer supported.
- You are not pursuing replacement for unsupported systems or software.
Partially achieved - All of the following statements are true:
- You maintain a current understanding of the exposure of your essential function(s) to publicly-known vulnerabilities.
- Announced vulnerabilities for all software packages, network and information systems used to support your essential function(s) are tracked, prioritised and externally exposed vulnerabilities are mitigated (e.g. by patching) promptly.
- Some vulnerabilities that are not externally exposed have temporary mitigations for an extended period.
- You have temporary mitigations for unsupported systems and software while pursuing migration to supported technology.
- You regularly test to fully understand the vulnerabilities of the network and information systems that support the operation of your essential function(s).
Achieved - All of the following statements are true:
- You maintain a current understanding of the exposure of your essential function(s) to publicly-known vulnerabilities.
- Announced vulnerabilities for all software packages, network and information systems used to support your essential function(s) are tracked, prioritised and mitigated (e.g. by patching) promptly.
- You regularly test to fully understand the vulnerabilities of the network and information systems that support the operation of your essential function(s) and verify this understanding with third-party testing.
- You actively maximise the use of supported software, firmware and hardware in your network and information systems supporting your essential function(s).
The organisation builds resilience against cyber attack and system failure into the design, implementation, operation and management of systems that support the operation of your essential function(s).
Description
error determining description
Guidance
It's important to be prepared to respond to significant disruption by having business continuity and disaster recovery planning in place. This should include a definition of your most critical resources and an understanding of the order of actions needed to restore service(s). Test that these plans work, for example through manually triggering failover testing, carrying out table-top scenario walk-throughs, red-teaming or Cyber adversary simulation testing. You should be ready to adjust the security measures in place in response to changes in risk. For example, if threat intelligence indicates an increased likelihood of your organisation or sector being targeted you may decide to isolate operational networks until the threat has decreased. Alternatively, in the event of public disclosure of an unpatched vulnerability in equipment that you use, with reported use of exploits targeting the vulnerability, you may respond by elevating your protective monitoring, changing your configuration to avoid being susceptible, or taking other mitigating action in the period until a patch is made available and can be deployed.
You should reduce the likelihood of failure or attack by taking all reasonable measures to maintain networks, information systems and necessary technologies in good working order. Exceptions should be appropriately managed.
In the event of an incident, it is more likely that an essential function will be able to continue where the networks and information systems that support it are segregated from other business and external systems. Separation of system architecture, remote access and privileged access are some key principles that can protect more critical systems from external compromise.
Some sectors responsible for the operation of essential functions may apply the industrial automation and control system security standard IEC 62443, which applies a reference model that separates systems into different logical layers. The standard's architecture model segregates equipment into security zones.
Limitations of networks and information systems, or external services or resources, such as network bandwidth, processing capability, or data storage capacity, should be understood and managed with suitable mitigations to avoid disruption through resource overload.
Make appropriate use of diverse technologies, geographic locations and so on, to provide resilience. You should understand and manage external or lower-priority dependencies to ensure that alternative means are suitable for continuation of the essential function.
In the event of an adverse event, you should be able to revert to backups of hardware and data that are known to be functioning and accessible. Organisations should maintain secured offline, potentially off-site, backups of the operational data, equipment configurations, gold builds, etc. needed to recover from an extreme event.
Suitable alternative backups may include paper-based information and manual processes. Other essential backups may include personnel with appropriate knowledge and access to up-to-date documentation. Consider how to make it easy to recover following an incident or compromise.
You should have adequate policies and measures to ensure the physical and environmental security of your network and information systems. This can be achieved through measures such as physical access controls, alarm systems, environmental controls and automated fire systems etc.
When planning physical upgrades or changes to network and information systems (such as moving to new hardware installations, installing new equipment or power supplies), you should take steps to avoid unnecessary or unplanned interruptions to the services that your network and information systems support.
You should also ensure that you have adequate policies to protect supporting utilities such as electricity, fuel, heating, ventilation, and air conditioning. This can be achieved by having alternative sources, such as back-up generators or uninterruptible power supplies, active temperature monitoring, redundant cooling systems etc.
Contributing Outcomes
B5.a Resilience Preparation
- You are prepared to restore the operation of your essential function(s) following adverse impact to network and information systems.
- You are prepared to restore the operation of your essential function(s) following adverse impact to network and information systems.
- You have limited understanding of all the elements that are required to restore operation of the essential function(s).
- You have not completed business continuity and disaster recovery plans for network and information systems, including their dependencies, supporting the operation of the essential function(s).
- You have not fully assessed the practical implementation of your business continuity and disaster recovery plans.
- You know all network and information systems, and underlying technologies that are necessary to restore the operation of the essential function(s) and understand their interdependence.
- You know the order in which systems need to be recovered to efficiently and effectively restore the operation of the essential function(s).
- You have business continuity and disaster recovery plans that have been tested for practicality, effectiveness and completeness. Appropriate use is made of different test methods (e.g. manual fail-over, table-top exercises, or red-teaming).
- You use your security awareness and threat intelligence sources to identify new or heightened levels of risk, which result in immediate and potentially temporary security measures to enhance the security of your network and information systems (e.g. in response to a widespread outbreak of very damaging malware).
Not achieved - Any of the following statements are true:
- You have limited understanding of all the elements that are required to restore operation of the essential function(s).
- You have not completed business continuity and disaster recovery plans for network and information systems, including their dependencies, supporting the operation of the essential function(s).
- You have not fully assessed the practical implementation of your business continuity and disaster recovery plans.
Partially achieved - All of the following statements are true:
- You know all network and information systems, and underlying technologies that are necessary to restore the operation of the essential function(s) and understand their interdependence.
- You know the order in which systems need to be recovered to efficiently and effectively restore the operation of the essential function(s).
Achieved - All of the following statements are true:
- You have business continuity and disaster recovery plans that have been tested for practicality, effectiveness and completeness. Appropriate use is made of different test methods (e.g. manual fail-over, table-top exercises, or red-teaming).
- You use your security awareness and threat intelligence sources to identify new or heightened levels of risk, which result in immediate and potentially temporary security measures to enhance the security of your network and information systems (e.g. in response to a widespread outbreak of very damaging malware).
B5.b Design for Resilience
- You design the network and information systems supporting your essential function(s) to be resilient to cyber security incidents. Systems are appropriately segregated and resource limitations are mitigated.
- You design the network and information systems supporting your essential function(s) to be resilient to cyber security incidents. Systems are appropriately segregated and resource limitations are mitigated.
- Network and information systems supporting the operation of your essential function(s) are not appropriately segregated.
- Internet services, such as browsing and email, are accessible from network and information systems supporting the essential function(s).
- You do not understand or lack plans to mitigate all resource limitations that could adversely affect your essential function(s).
- Network and information systems supporting the operation of your essential function(s) are logically separated from your business systems (e.g. they reside on the same network as the rest of the organisation but within a DMZ).
- Internet services, such as browsing and email, are not accessible from network and information systems supporting the essential function(s).
- Resource limitations (e.g. network bandwidth, single network paths) have been identified but not fully mitigated.
- Network and information systems supporting the operation of your essential function(s) are segregated from other business and external systems by appropriate technical and physical means (e.g. separate network and system infrastructure with independent user administration).
- Internet services, such as browsing and email, are not accessible from network and information systems supporting the essential function(s).
- You have identified and mitigated all resource limitations (e.g. bandwidth limitations and single network paths).
- You have identified and mitigated any geographical constraints or weaknesses. (e.g. systems that your essential function(s) depends upon are replicated in another location, important network connectivity has alternative physical paths and service providers).
- You review and update assessments of dependencies, resource and geographical limitations and mitigations when necessary.
Not achieved - At least one of the following statements is true:
- Network and information systems supporting the operation of your essential function(s) are not appropriately segregated.
- Internet services, such as browsing and email, are accessible from network and information systems supporting the essential function(s).
- You do not understand or lack plans to mitigate all resource limitations that could adversely affect your essential function(s).
Partially achieved - All of the following statements are true:
- Network and information systems supporting the operation of your essential function(s) are logically separated from your business systems (e.g. they reside on the same network as the rest of the organisation but within a DMZ).
- Internet services, such as browsing and email, are not accessible from network and information systems supporting the essential function(s).
- Resource limitations (e.g. network bandwidth, single network paths) have been identified but not fully mitigated.
Achieved - All of the following statements are true:
- Network and information systems supporting the operation of your essential function(s) are segregated from other business and external systems by appropriate technical and physical means (e.g. separate network and system infrastructure with independent user administration).
- Internet services, such as browsing and email, are not accessible from network and information systems supporting the essential function(s).
- You have identified and mitigated all resource limitations (e.g. bandwidth limitations and single network paths).
- You have identified and mitigated any geographical constraints or weaknesses. (e.g. systems that your essential function(s) depends upon are replicated in another location, important network connectivity has alternative physical paths and service providers).
- You review and update assessments of dependencies, resource and geographical limitations and mitigations when necessary.
B5.c Backups
- You hold accessible and secured current backups of data and information needed to recover operation of your essential function(s) following an adverse impact to network and information systems.
- You hold accessible and secured current backups of data and information needed to recover operation of your essential function(s) following an adverse impact to network and information systems.
- Backup coverage is incomplete and does not include all relevant data and information needed to restore the operation of your essential function(s).
- Backups are not frequent enough for the operation of your essential function(s) to be restored effectively.
- Your restoration process does not restore your essential function(s) in a suitable time frame.
- You have appropriately secured backups (including data, configuration information, software, equipment, processes and knowledge). These backups will be accessible to recover from an extreme event.
- You routinely test backups to ensure that the backup process function(s) correctly and the backups are usable.
- Your comprehensive, automatic and tested technical and procedural backups are secured at centrally accessible or secondary sites to recover from an extreme event.
- Backups of all important data and information needed to recover the essential function(s) are made, tested, documented and routinely reviewed
Not achieved - At least one of the following statements is true:
- Backup coverage is incomplete and does not include all relevant data and information needed to restore the operation of your essential function(s).
- Backups are not frequent enough for the operation of your essential function(s) to be restored effectively.
- Your restoration process does not restore your essential function(s) in a suitable time frame.
Partially achieved - All of the following statements are true:
- You have appropriately secured backups (including data, configuration information, software, equipment, processes and knowledge). These backups will be accessible to recover from an extreme event.
- You routinely test backups to ensure that the backup process function(s) correctly and the backups are usable.
Achieved - All of the following statements are true:
- Your comprehensive, automatic and tested technical and procedural backups are secured at centrally accessible or secondary sites to recover from an extreme event.
- Backups of all important data and information needed to recover the essential function(s) are made, tested, documented and routinely reviewed
The organisation builds resilience against cyber attack and system failure into the design, implementation, operation and management of systems that support the operation of your essential function(s).
Description
error determining description
Guidance
It's important to be prepared to respond to significant disruption by having business continuity and disaster recovery planning in place. This should include a definition of your most critical resources and an understanding of the order of actions needed to restore service(s). Test that these plans work, for example through manually triggering failover testing, carrying out table-top scenario walk-throughs, red-teaming or Cyber adversary simulation testing. You should be ready to adjust the security measures in place in response to changes in risk. For example, if threat intelligence indicates an increased likelihood of your organisation or sector being targeted you may decide to isolate operational networks until the threat has decreased. Alternatively, in the event of public disclosure of an unpatched vulnerability in equipment that you use, with reported use of exploits targeting the vulnerability, you may respond by elevating your protective monitoring, changing your configuration to avoid being susceptible, or taking other mitigating action in the period until a patch is made available and can be deployed.
You should reduce the likelihood of failure or attack by taking all reasonable measures to maintain networks, information systems and necessary technologies in good working order. Exceptions should be appropriately managed.
In the event of an incident, it is more likely that an essential function will be able to continue where the networks and information systems that support it are segregated from other business and external systems. Separation of system architecture, remote access and privileged access are some key principles that can protect more critical systems from external compromise.
Some sectors responsible for the operation of essential functions may apply the industrial automation and control system security standard IEC 62443, which applies a reference model that separates systems into different logical layers. The standard's architecture model segregates equipment into security zones.
Limitations of networks and information systems, or external services or resources, such as network bandwidth, processing capability, or data storage capacity, should be understood and managed with suitable mitigations to avoid disruption through resource overload.
Make appropriate use of diverse technologies, geographic locations and so on, to provide resilience. You should understand and manage external or lower-priority dependencies to ensure that alternative means are suitable for continuation of the essential function.
In the event of an adverse event, you should be able to revert to backups of hardware and data that are known to be functioning and accessible. Organisations should maintain secured offline, potentially off-site, backups of the operational data, equipment configurations, gold builds, etc. needed to recover from an extreme event.
Suitable alternative backups may include paper-based information and manual processes. Other essential backups may include personnel with appropriate knowledge and access to up-to-date documentation. Consider how to make it easy to recover following an incident or compromise.
You should have adequate policies and measures to ensure the physical and environmental security of your network and information systems. This can be achieved through measures such as physical access controls, alarm systems, environmental controls and automated fire systems etc.
When planning physical upgrades or changes to network and information systems (such as moving to new hardware installations, installing new equipment or power supplies), you should take steps to avoid unnecessary or unplanned interruptions to the services that your network and information systems support.
You should also ensure that you have adequate policies to protect supporting utilities such as electricity, fuel, heating, ventilation, and air conditioning. This can be achieved by having alternative sources, such as back-up generators or uninterruptible power supplies, active temperature monitoring, redundant cooling systems etc.
Contributing Outcomes
B5.a Resilience Preparation
- You are prepared to restore the operation of your essential function(s) following adverse impact to network and information systems.
- You are prepared to restore the operation of your essential function(s) following adverse impact to network and information systems.
- You have limited understanding of all the elements that are required to restore operation of the essential function(s).
- You have not completed business continuity and disaster recovery plans for network and information systems, including their dependencies, supporting the operation of the essential function(s).
- You have not fully assessed the practical implementation of your business continuity and disaster recovery plans.
- You know all network and information systems, and underlying technologies that are necessary to restore the operation of the essential function(s) and understand their interdependence.
- You know the order in which systems need to be recovered to efficiently and effectively restore the operation of the essential function(s).
- You have business continuity and disaster recovery plans that have been tested for practicality, effectiveness and completeness. Appropriate use is made of different test methods (e.g. manual fail-over, table-top exercises, or red-teaming).
- You use your security awareness and threat intelligence sources to identify new or heightened levels of risk, which result in immediate and potentially temporary security measures to enhance the security of your network and information systems (e.g. in response to a widespread outbreak of very damaging malware).
Not achieved - Any of the following statements are true:
- You have limited understanding of all the elements that are required to restore operation of the essential function(s).
- You have not completed business continuity and disaster recovery plans for network and information systems, including their dependencies, supporting the operation of the essential function(s).
- You have not fully assessed the practical implementation of your business continuity and disaster recovery plans.
Partially achieved - All of the following statements are true:
- You know all network and information systems, and underlying technologies that are necessary to restore the operation of the essential function(s) and understand their interdependence.
- You know the order in which systems need to be recovered to efficiently and effectively restore the operation of the essential function(s).
Achieved - All of the following statements are true:
- You have business continuity and disaster recovery plans that have been tested for practicality, effectiveness and completeness. Appropriate use is made of different test methods (e.g. manual fail-over, table-top exercises, or red-teaming).
- You use your security awareness and threat intelligence sources to identify new or heightened levels of risk, which result in immediate and potentially temporary security measures to enhance the security of your network and information systems (e.g. in response to a widespread outbreak of very damaging malware).
B5.b Design for Resilience
- You design the network and information systems supporting your essential function(s) to be resilient to cyber security incidents. Systems are appropriately segregated and resource limitations are mitigated.
- You design the network and information systems supporting your essential function(s) to be resilient to cyber security incidents. Systems are appropriately segregated and resource limitations are mitigated.
- Network and information systems supporting the operation of your essential function(s) are not appropriately segregated.
- Internet services, such as browsing and email, are accessible from network and information systems supporting the essential function(s).
- You do not understand or lack plans to mitigate all resource limitations that could adversely affect your essential function(s).
- Network and information systems supporting the operation of your essential function(s) are logically separated from your business systems (e.g. they reside on the same network as the rest of the organisation but within a DMZ).
- Internet services, such as browsing and email, are not accessible from network and information systems supporting the essential function(s).
- Resource limitations (e.g. network bandwidth, single network paths) have been identified but not fully mitigated.
- Network and information systems supporting the operation of your essential function(s) are segregated from other business and external systems by appropriate technical and physical means (e.g. separate network and system infrastructure with independent user administration).
- Internet services, such as browsing and email, are not accessible from network and information systems supporting the essential function(s).
- You have identified and mitigated all resource limitations (e.g. bandwidth limitations and single network paths).
- You have identified and mitigated any geographical constraints or weaknesses. (e.g. systems that your essential function(s) depends upon are replicated in another location, important network connectivity has alternative physical paths and service providers).
- You review and update assessments of dependencies, resource and geographical limitations and mitigations when necessary.
Not achieved - At least one of the following statements is true:
- Network and information systems supporting the operation of your essential function(s) are not appropriately segregated.
- Internet services, such as browsing and email, are accessible from network and information systems supporting the essential function(s).
- You do not understand or lack plans to mitigate all resource limitations that could adversely affect your essential function(s).
Partially achieved - All of the following statements are true:
- Network and information systems supporting the operation of your essential function(s) are logically separated from your business systems (e.g. they reside on the same network as the rest of the organisation but within a DMZ).
- Internet services, such as browsing and email, are not accessible from network and information systems supporting the essential function(s).
- Resource limitations (e.g. network bandwidth, single network paths) have been identified but not fully mitigated.
Achieved - All of the following statements are true:
- Network and information systems supporting the operation of your essential function(s) are segregated from other business and external systems by appropriate technical and physical means (e.g. separate network and system infrastructure with independent user administration).
- Internet services, such as browsing and email, are not accessible from network and information systems supporting the essential function(s).
- You have identified and mitigated all resource limitations (e.g. bandwidth limitations and single network paths).
- You have identified and mitigated any geographical constraints or weaknesses. (e.g. systems that your essential function(s) depends upon are replicated in another location, important network connectivity has alternative physical paths and service providers).
- You review and update assessments of dependencies, resource and geographical limitations and mitigations when necessary.
B5.c Backups
- You hold accessible and secured current backups of data and information needed to recover operation of your essential function(s) following an adverse impact to network and information systems.
- You hold accessible and secured current backups of data and information needed to recover operation of your essential function(s) following an adverse impact to network and information systems.
- Backup coverage is incomplete and does not include all relevant data and information needed to restore the operation of your essential function(s).
- Backups are not frequent enough for the operation of your essential function(s) to be restored effectively.
- Your restoration process does not restore your essential function(s) in a suitable time frame.
- You have appropriately secured backups (including data, configuration information, software, equipment, processes and knowledge). These backups will be accessible to recover from an extreme event.
- You routinely test backups to ensure that the backup process function(s) correctly and the backups are usable.
- Your comprehensive, automatic and tested technical and procedural backups are secured at centrally accessible or secondary sites to recover from an extreme event.
- Backups of all important data and information needed to recover the essential function(s) are made, tested, documented and routinely reviewed
Not achieved - At least one of the following statements is true:
- Backup coverage is incomplete and does not include all relevant data and information needed to restore the operation of your essential function(s).
- Backups are not frequent enough for the operation of your essential function(s) to be restored effectively.
- Your restoration process does not restore your essential function(s) in a suitable time frame.
Partially achieved - All of the following statements are true:
- You have appropriately secured backups (including data, configuration information, software, equipment, processes and knowledge). These backups will be accessible to recover from an extreme event.
- You routinely test backups to ensure that the backup process function(s) correctly and the backups are usable.
Achieved - All of the following statements are true:
- Your comprehensive, automatic and tested technical and procedural backups are secured at centrally accessible or secondary sites to recover from an extreme event.
- Backups of all important data and information needed to recover the essential function(s) are made, tested, documented and routinely reviewed
Staff have appropriate awareness, knowledge and skills to carry out their organisational roles effectively in relation to the security of network and information systems supporting the operation of your essential function(s).
Description
error determining description
Guidance
The people who operate and support essential functions should be provided with all they need to carry out their job while supporting the organisation's cyber security. In line with the design of
service protection policies and processes
, you should apply the same people-focussed approach to staff awareness and training.
Training and awareness activities should provide appropriate cyber security skills for the job role based on an understanding of how people
really
work with the systems, with ongoing reminders and top-up training to maintain skills.
Using a range of approaches to training and awareness can improve understanding and information retention, from briefings, online courses and blogs to simulated cyber attack. You may achieve the widest uptake of training and awareness by accommodating different learning preferences and using various delivery methods. Organisations may find the
GCHQ certified training scheme
useful when considering commercial offerings.
Organisations responsible for essential functions should aim to create a positive security culture, where people are aware of their role in maintaining security and actively take part and contribute to improving security. This is particularly important where a technical solution is not possible, so security relies on people making the right cyber security decisions. Developing a positive security culture is likely to take some time, with some changes possibly taking years to become established and is unlikely to be achieved simply through written guidance or training events.
These outcomes are best achieved when organisations actively engage with staff and communicate effectively with them about network and information system security and how it relates to their jobs. This should be more easily achieved where organisations create and promote a long-term security culture vision that is endorsed and supported by senior management, then make incremental, focused changes to address specific business issues. In some cases, particularly where an essential function is safety-related, an organisation may be able to draw on activities supporting positive safety culture to build up the organisation's cyber security culture.
Contributing Outcomes
B6.a Cyber Security Culture
- You develop and maintain a positive cyber security culture and a shared sense of responsibility.
- You develop and maintain a positive cyber security culture and a shared sense of responsibility.
- People in your organisation do not understand what they contribute to the cyber security of network and information systems supporting your essential function(s).
- People in your organisation do not know how to raise a concern about cyber security.
- People believe that reporting issues may get them into trouble.
- Your organisation's approach to cyber security is perceived by staff as hindering the business of the organisation and may encourage poor security behaviours.
- Formal or informal incentives and rewards conflict with the promotion of positive security outcomes.
- Your executive management understand and widely communicate the importance of a positive cyber security culture. Positive attitudes, behaviours and expectations are described for your organisation.
- All people in your organisation understand the contribution they make to the cyber security of network and information systems supporting your essential function(s).
- All individuals in your organisation know who to contact and where to access more information about cyber security. They know how to raise a cyber security issue.
- You identify and address issues that inhibit people from behaving in a manner that supports your intended cyber security outcomes.
- Your executive management clearly and effectively communicates the organisation's cyber security priorities and objectives to all staff. Your organisation displays positive cyber security attitudes, behaviours, expectations.
- People in your organisation raising potential cyber security incidents and issues are treated positively.
- Individuals at all levels in your organisation routinely report concerns or issues about cyber security and are recognised for their contribution to keeping the organisation secure.
- Your management is seen to be committed to and actively involved in cyber security.
- Your organisation communicates openly about cyber security, with any concern being taken seriously.
- People across your organisation participate in cyber security activities and improvements, building joint ownership and bringing knowledge of their area of expertise.
Not achieved - At least one of the following statements is true:
- People in your organisation do not understand what they contribute to the cyber security of network and information systems supporting your essential function(s).
- People in your organisation do not know how to raise a concern about cyber security.
- People believe that reporting issues may get them into trouble.
- Your organisation's approach to cyber security is perceived by staff as hindering the business of the organisation and may encourage poor security behaviours.
- Formal or informal incentives and rewards conflict with the promotion of positive security outcomes.
Partially achieved - All the following statements are true:
- Your executive management understand and widely communicate the importance of a positive cyber security culture. Positive attitudes, behaviours and expectations are described for your organisation.
- All people in your organisation understand the contribution they make to the cyber security of network and information systems supporting your essential function(s).
- All individuals in your organisation know who to contact and where to access more information about cyber security. They know how to raise a cyber security issue.
- You identify and address issues that inhibit people from behaving in a manner that supports your intended cyber security outcomes.
Achieved - All the following statements are true:
- Your executive management clearly and effectively communicates the organisation's cyber security priorities and objectives to all staff. Your organisation displays positive cyber security attitudes, behaviours, expectations.
- People in your organisation raising potential cyber security incidents and issues are treated positively.
- Individuals at all levels in your organisation routinely report concerns or issues about cyber security and are recognised for their contribution to keeping the organisation secure.
- Your management is seen to be committed to and actively involved in cyber security.
- Your organisation communicates openly about cyber security, with any concern being taken seriously.
- People across your organisation participate in cyber security activities and improvements, building joint ownership and bringing knowledge of their area of expertise.
B6.b Cyber Security Training
- The people who support the operation of network and information systems supporting your essential function(s) are appropriately trained in cyber security.
- The people who support the operation of network and information systems supporting your essential function(s) are appropriately trained in cyber security.
- There are teams who operate and support your essential function(s) that lack any cyber security training.
- Cyber security training is restricted to specific roles in your organisation.
- Cyber security training records for your organisation are lacking or incomplete.
- Training is used as a “silver bullet” for all user security behaviours.
- The success of training is only measured by the number of people reached, rather than assessing whether it has a positive impact on security behaviours.
- Training materials contain out of date or contradictory information, or information that conflicts with other policies, processes or procedures.
- You have defined appropriate cyber security training and awareness activities for all roles in your organisation, from executives to the most junior roles.
- You use a range of teaching and communication techniques for cyber security training and awareness to reach the widest audience effectively.
- Cyber security information is easily available.
- All people in your organisation, from the most senior to the most junior, follow appropriate cyber security training paths.
- Each individuals cyber security training is tracked and refreshed at suitable intervals.
- You routinely evaluate your cyber security training and awareness activities to ensure they reach the widest audience and are effective.
- You make cyber security information and good practice guidance easily accessible, widely available and you know it is referenced and used within your organisation.
Not achieved - At least one of the following statements is true:
- There are teams who operate and support your essential function(s) that lack any cyber security training.
- Cyber security training is restricted to specific roles in your organisation.
- Cyber security training records for your organisation are lacking or incomplete.
- Training is used as a “silver bullet” for all user security behaviours.
- The success of training is only measured by the number of people reached, rather than assessing whether it has a positive impact on security behaviours.
- Training materials contain out of date or contradictory information, or information that conflicts with other policies, processes or procedures.
Partially achieved - All the following statements are true:
- You have defined appropriate cyber security training and awareness activities for all roles in your organisation, from executives to the most junior roles.
- You use a range of teaching and communication techniques for cyber security training and awareness to reach the widest audience effectively.
- Cyber security information is easily available.
Achieved - All the following statements are true:
- All people in your organisation, from the most senior to the most junior, follow appropriate cyber security training paths.
- Each individuals cyber security training is tracked and refreshed at suitable intervals.
- You routinely evaluate your cyber security training and awareness activities to ensure they reach the widest audience and are effective.
- You make cyber security information and good practice guidance easily accessible, widely available and you know it is referenced and used within your organisation.
Staff have appropriate awareness, knowledge and skills to carry out their organisational roles effectively in relation to the security of network and information systems supporting the operation of your essential function(s).
Description
error determining description
Guidance
The people who operate and support essential functions should be provided with all they need to carry out their job while supporting the organisation's cyber security. In line with the design of
service protection policies and processes
, you should apply the same people-focussed approach to staff awareness and training.
Training and awareness activities should provide appropriate cyber security skills for the job role based on an understanding of how people
really
work with the systems, with ongoing reminders and top-up training to maintain skills.
Using a range of approaches to training and awareness can improve understanding and information retention, from briefings, online courses and blogs to simulated cyber attack. You may achieve the widest uptake of training and awareness by accommodating different learning preferences and using various delivery methods. Organisations may find the
GCHQ certified training scheme
useful when considering commercial offerings.
Organisations responsible for essential functions should aim to create a positive security culture, where people are aware of their role in maintaining security and actively take part and contribute to improving security. This is particularly important where a technical solution is not possible, so security relies on people making the right cyber security decisions. Developing a positive security culture is likely to take some time, with some changes possibly taking years to become established and is unlikely to be achieved simply through written guidance or training events.
These outcomes are best achieved when organisations actively engage with staff and communicate effectively with them about network and information system security and how it relates to their jobs. This should be more easily achieved where organisations create and promote a long-term security culture vision that is endorsed and supported by senior management, then make incremental, focused changes to address specific business issues. In some cases, particularly where an essential function is safety-related, an organisation may be able to draw on activities supporting positive safety culture to build up the organisation's cyber security culture.
Contributing Outcomes
B6.a Cyber Security Culture
- You develop and maintain a positive cyber security culture and a shared sense of responsibility.
- You develop and maintain a positive cyber security culture and a shared sense of responsibility.
- People in your organisation do not understand what they contribute to the cyber security of network and information systems supporting your essential function(s).
- People in your organisation do not know how to raise a concern about cyber security.
- People believe that reporting issues may get them into trouble.
- Your organisation's approach to cyber security is perceived by staff as hindering the business of the organisation and may encourage poor security behaviours.
- Formal or informal incentives and rewards conflict with the promotion of positive security outcomes.
- Your executive management understand and widely communicate the importance of a positive cyber security culture. Positive attitudes, behaviours and expectations are described for your organisation.
- All people in your organisation understand the contribution they make to the cyber security of network and information systems supporting your essential function(s).
- All individuals in your organisation know who to contact and where to access more information about cyber security. They know how to raise a cyber security issue.
- You identify and address issues that inhibit people from behaving in a manner that supports your intended cyber security outcomes.
- Your executive management clearly and effectively communicates the organisation's cyber security priorities and objectives to all staff. Your organisation displays positive cyber security attitudes, behaviours, expectations.
- People in your organisation raising potential cyber security incidents and issues are treated positively.
- Individuals at all levels in your organisation routinely report concerns or issues about cyber security and are recognised for their contribution to keeping the organisation secure.
- Your management is seen to be committed to and actively involved in cyber security.
- Your organisation communicates openly about cyber security, with any concern being taken seriously.
- People across your organisation participate in cyber security activities and improvements, building joint ownership and bringing knowledge of their area of expertise.
Not achieved - At least one of the following statements is true:
- People in your organisation do not understand what they contribute to the cyber security of network and information systems supporting your essential function(s).
- People in your organisation do not know how to raise a concern about cyber security.
- People believe that reporting issues may get them into trouble.
- Your organisation's approach to cyber security is perceived by staff as hindering the business of the organisation and may encourage poor security behaviours.
- Formal or informal incentives and rewards conflict with the promotion of positive security outcomes.
Partially achieved - All the following statements are true:
- Your executive management understand and widely communicate the importance of a positive cyber security culture. Positive attitudes, behaviours and expectations are described for your organisation.
- All people in your organisation understand the contribution they make to the cyber security of network and information systems supporting your essential function(s).
- All individuals in your organisation know who to contact and where to access more information about cyber security. They know how to raise a cyber security issue.
- You identify and address issues that inhibit people from behaving in a manner that supports your intended cyber security outcomes.
Achieved - All the following statements are true:
- Your executive management clearly and effectively communicates the organisation's cyber security priorities and objectives to all staff. Your organisation displays positive cyber security attitudes, behaviours, expectations.
- People in your organisation raising potential cyber security incidents and issues are treated positively.
- Individuals at all levels in your organisation routinely report concerns or issues about cyber security and are recognised for their contribution to keeping the organisation secure.
- Your management is seen to be committed to and actively involved in cyber security.
- Your organisation communicates openly about cyber security, with any concern being taken seriously.
- People across your organisation participate in cyber security activities and improvements, building joint ownership and bringing knowledge of their area of expertise.
B6.b Cyber Security Training
- The people who support the operation of network and information systems supporting your essential function(s) are appropriately trained in cyber security.
- The people who support the operation of network and information systems supporting your essential function(s) are appropriately trained in cyber security.
- There are teams who operate and support your essential function(s) that lack any cyber security training.
- Cyber security training is restricted to specific roles in your organisation.
- Cyber security training records for your organisation are lacking or incomplete.
- Training is used as a “silver bullet” for all user security behaviours.
- The success of training is only measured by the number of people reached, rather than assessing whether it has a positive impact on security behaviours.
- Training materials contain out of date or contradictory information, or information that conflicts with other policies, processes or procedures.
- You have defined appropriate cyber security training and awareness activities for all roles in your organisation, from executives to the most junior roles.
- You use a range of teaching and communication techniques for cyber security training and awareness to reach the widest audience effectively.
- Cyber security information is easily available.
- All people in your organisation, from the most senior to the most junior, follow appropriate cyber security training paths.
- Each individuals cyber security training is tracked and refreshed at suitable intervals.
- You routinely evaluate your cyber security training and awareness activities to ensure they reach the widest audience and are effective.
- You make cyber security information and good practice guidance easily accessible, widely available and you know it is referenced and used within your organisation.
Not achieved - At least one of the following statements is true:
- There are teams who operate and support your essential function(s) that lack any cyber security training.
- Cyber security training is restricted to specific roles in your organisation.
- Cyber security training records for your organisation are lacking or incomplete.
- Training is used as a “silver bullet” for all user security behaviours.
- The success of training is only measured by the number of people reached, rather than assessing whether it has a positive impact on security behaviours.
- Training materials contain out of date or contradictory information, or information that conflicts with other policies, processes or procedures.
Partially achieved - All the following statements are true:
- You have defined appropriate cyber security training and awareness activities for all roles in your organisation, from executives to the most junior roles.
- You use a range of teaching and communication techniques for cyber security training and awareness to reach the widest audience effectively.
- Cyber security information is easily available.
Achieved - All the following statements are true:
- All people in your organisation, from the most senior to the most junior, follow appropriate cyber security training paths.
- Each individuals cyber security training is tracked and refreshed at suitable intervals.
- You routinely evaluate your cyber security training and awareness activities to ensure they reach the widest audience and are effective.
- You make cyber security information and good practice guidance easily accessible, widely available and you know it is referenced and used within your organisation.
The organisation monitors the security status of network and information systems supporting the operation of essential function(s) in order to detect security events indicative of a security incident.
Description
error determining description
Guidance
One clear focus of your security monitoring should be the detection of incidents or activity that is likely to have an adverse impact on the network and information systems that support the operation of essential functions. Log data collection, secure storage, analysis tools, understanding your network and information systems that support your essential function(s), threat intelligence and personnel skills should all be used to build an effective security monitoring capability.
An organisation's automated monitoring capability should be able to find threats within their network and information systems by using both signature-based detections and, behavioural and anomaly-based detections.
Examples of signature-based detections are detecting when known command and control traffic is communicating to the internet, or an AV signature is present in a file. Organisations should endeavour to understand what automated detections and alerting do and how best to use them, to ensure they are making the most of the monitoring solution / as well as being as effective as possible.
Organisations should also have the capability to find threats by using behavioural and anomaly-based detections, for example by detecting an abnormally large amount of data being exfiltrated or AV detecting unusual changes to start up registry keys.
Both signature and, anomaly and behaviour-based detections rely on an understanding of indicators of compromise, your network and information systems, user behaviour and threats.
Contributing Outcomes
C1.a Sources and Tools for Logging and Monitoring
- The data sources that you include in your logging and monitoring allow for timely identification of events which might adversely affect the resiliency of network and information system(s) supporting the operation of your essential function(s).
- The data sources that you include in your logging and monitoring allow for timely identification of events which might adversely affect the resiliency of network and information system(s) supporting the operation of your essential function(s).
- Data relating to the security and operation of network and information systems supporting your essential function(s) is not collected.
- You are not able to audit the activities of users and systems in relation to network and information systems supporting your essential function(s).
- You do not monitor traffic crossing your network boundary.
- Log data cannot be synchronised using an accurate common time source.
- Logs are stored in locations where they are not readily available to authorised users and systems.
- Your monitoring tools cannot be configured to make use of new log streams as they come online.
- Your monitoring tools are only able to make use of a fraction of the log data being collected.
- You do not understand where log data is stored or how long it should be stored for.
- You have no way of ensuring log data is being captured as expected and available when needed.
- Data relating to the security and operation of some areas of network and information systems supporting your essential function(s) is collected but coverage is not comprehensive.
- Some user and system monitoring is done, but not covering a fully agreed list of suspicious or undesirable behaviour.
- You monitor traffic crossing your network boundary (including IP address connections as a minimum).
- Some but not all log datasets can be easily queried with search tools to aid in investigations.
- Your monitoring tools work with most log data, with some configuration.
- Your monitoring tools can make use of log data that would capture all common threats.
- You ensure log data is available for analysis when needed.
- Monitoring is based on a thorough understanding of network and information systems supporting your essential function(s), techniques used by threat actors, and awareness of what logging and monitoring is required to detect events and incidents that could affect the operation of your essential function(s).
- Your monitoring data provides enough detail to promptly and reliably detect security events, incidents and support investigations. This is reviewed regularly and after a significant security event.
- Extensive monitoring of user and system activity in relation to network and information systems that support your essential function(s) enables you to promptly detect policy violations, suspicious or undesirable user and system behaviour, deviations from normal / routine behaviour or abnormalities indicative of adverse activity.
- Your logging and monitoring capability includes host-based and network monitoring.
- All new network and information systems supporting your essential function(s) are considered as potential logging and monitoring data sources to maintain a comprehensive monitoring capability.
- Log datasets are synchronised including using an accurate common time source so that separate datasets can be correlated in appropriate ways.
- You enrich log data with other network and information systems data to provide a more comprehensive picture of actions and behaviours.
- Your monitoring tools make use of log data to pinpoint activity.
- You regularly review the data sources and tools included in your logging and monitoring strategy to ensure it remains effective.
Not achieved - At least one of the following statements is true:
- Data relating to the security and operation of network and information systems supporting your essential function(s) is not collected.
- You are not able to audit the activities of users and systems in relation to network and information systems supporting your essential function(s).
- You do not monitor traffic crossing your network boundary.
- Log data cannot be synchronised using an accurate common time source.
- Logs are stored in locations where they are not readily available to authorised users and systems.
- Your monitoring tools cannot be configured to make use of new log streams as they come online.
- Your monitoring tools are only able to make use of a fraction of the log data being collected.
- You do not understand where log data is stored or how long it should be stored for.
- You have no way of ensuring log data is being captured as expected and available when needed.
Partially achieved - All the following statements are true:
- Data relating to the security and operation of some areas of network and information systems supporting your essential function(s) is collected but coverage is not comprehensive.
- Some user and system monitoring is done, but not covering a fully agreed list of suspicious or undesirable behaviour.
- You monitor traffic crossing your network boundary (including IP address connections as a minimum).
- Some but not all log datasets can be easily queried with search tools to aid in investigations.
- Your monitoring tools work with most log data, with some configuration.
- Your monitoring tools can make use of log data that would capture all common threats.
- You ensure log data is available for analysis when needed.
Achieved - All the following statements are true:
- Monitoring is based on a thorough understanding of network and information systems supporting your essential function(s), techniques used by threat actors, and awareness of what logging and monitoring is required to detect events and incidents that could affect the operation of your essential function(s).
- Your monitoring data provides enough detail to promptly and reliably detect security events, incidents and support investigations. This is reviewed regularly and after a significant security event.
- Extensive monitoring of user and system activity in relation to network and information systems that support your essential function(s) enables you to promptly detect policy violations, suspicious or undesirable user and system behaviour, deviations from normal / routine behaviour or abnormalities indicative of adverse activity.
- Your logging and monitoring capability includes host-based and network monitoring.
- All new network and information systems supporting your essential function(s) are considered as potential logging and monitoring data sources to maintain a comprehensive monitoring capability.
- Log datasets are synchronised including using an accurate common time source so that separate datasets can be correlated in appropriate ways.
- You enrich log data with other network and information systems data to provide a more comprehensive picture of actions and behaviours.
- Your monitoring tools make use of log data to pinpoint activity.
- You regularly review the data sources and tools included in your logging and monitoring strategy to ensure it remains effective.
C1.b Securing Logs
- You hold log data securely and grant appropriate user and system access only to accounts with a business need. Log data is held for a suitable retention period, after which it is deleted.
- You hold log data securely and grant appropriate user and system access only to accounts with a business need. Log data is held for a suitable retention period, after which it is deleted.
- It is possible for log data to be easily edited or deleted by unauthorised users or malicious attackers.
- There is no controlled list of the users and systems that can view and query log data.
- There is no monitoring of the access to log data.
- There are no policies for accessing to log data.
- Only authorised users and systems can access log data.
- There is some monitoring of access to log data (e.g. copying, deleting or modification, or even viewing).
- You have defined and implemented retention periods for log data.
- You have given legitimate reasons for accessing log data in your policies.
- Appropriate access to log data is limited to those users and systems with a business need.
- The logging architecture has mechanisms, policies, processes and procedures to ensure that it can protect itself from threats comparable to those that it is trying to identify. This includes protecting the function itself and the data within it.
- Log data analysis and normalisation is only performed on copies of the log data keeping the master copy unaltered.
- All actions involving log data (e.g. copying, deleting, modification, or even viewing) can be traced back to a unique user or system.
- The integrity of log data is protected, verified and any modification, including deletion, is detected and attributed.
Not achieved - At least one of the following is true:
- It is possible for log data to be easily edited or deleted by unauthorised users or malicious attackers.
- There is no controlled list of the users and systems that can view and query log data.
- There is no monitoring of the access to log data.
- There are no policies for accessing to log data.
Partially achieved - All the following statements are true:
- Only authorised users and systems can access log data.
- There is some monitoring of access to log data (e.g. copying, deleting or modification, or even viewing).
- You have defined and implemented retention periods for log data.
- You have given legitimate reasons for accessing log data in your policies.
Achieved - All the following statements are true:
- Appropriate access to log data is limited to those users and systems with a business need.
- The logging architecture has mechanisms, policies, processes and procedures to ensure that it can protect itself from threats comparable to those that it is trying to identify. This includes protecting the function itself and the data within it.
- Log data analysis and normalisation is only performed on copies of the log data keeping the master copy unaltered.
- All actions involving log data (e.g. copying, deleting, modification, or even viewing) can be traced back to a unique user or system.
- The integrity of log data is protected, verified and any modification, including deletion, is detected and attributed.
C1.c Generating Alerts
- Evidence of potential security incidents contained in your monitoring data is reliably identified and where appropriate triggers alerts.
- Evidence of potential security incidents contained in your monitoring data is reliably identified and where appropriate triggers alerts.
- You do not apply updates to your detection security technologies in a timely way, after receiving them (e.g. AV signature updates, other threat signatures or Indicators of Compromise (IoCs)).
- Security alerts relating to network and information systems supporting your essential function(s) are not prioritised.
- The enrichment of security alerts within network and information systems supporting your essential function(s) cannot be performed.
- You do not confidently detect the presence of IoCs on network and information systems supporting your essential function(s), such as known malicious command and control signatures (e.g. because applying the indicator is difficult or your log data is not sufficiently detailed).
- You do not monitor for user or system abnormalities indicative of adverse activity.
- Logs are monitored infrequently.
- You easily detect the presence of Indicators of Compromise (IoCs) on network and information systems supporting your essential function(s), such as known malicious command and control signatures.
- You apply some updates, new signatures and IoCs in a timely way.
- Security alerts relating to network and information systems that support your essential function(s) are prioritised.
- The enrichment of alerts within network and information systems supporting your essential function(s) is performed but not as part of the original alert.
- Detections and alerting rely on off the shelf tooling without customisation or users reporting events and potential incidents.
- There is a documented and shared process for all users who support the operation of the essential function to report events and potential security incidents.
- Where appropriate, detections and alerting result in automated actions being taken. (e.g. malware identified by AV is quarantined).
- You monitor on an irregular basis for user or system abnormalities indicative of adverse activity.
- Logs are monitored at regular intervals.
- You easily detect the presence of Indicators of Compromise (IoCs) on network and information systems supporting your essential function(s), such as known malicious command and control signatures, as well as abnormalities or behaviours indicative of adverse activity.
- You apply all updates, new signatures and IoCs promptly.
- Security alerts relating to all network and information systems supporting your essential function(s) are prioritised and this information is used to support incident management.
- Alerts are routinely enriched within network and information systems supporting your essential function(s). The enrichment of these alerts is performed in almost real time and as part of the original alert.
- Alerts and the underlying detections are regularly reviewed and tested to ensure they are generated promptly and reliably, and it is possible to distinguish genuine security incidents from false alarms.
- Alerts and the underlying detection rules are customisable and tuned to reduce false positives as well as optimising responses.
- Detections and alerting may use off the shelf tooling and rules as well as custom tooling and / or rules.
- You continuously monitor for user and system abnormalities indicative of adverse activity generating alerts based on the results of such monitoring.
- Logs are monitored continuously in near real time.
Not achieved - At least one of the following is true:
- You do not apply updates to your detection security technologies in a timely way, after receiving them (e.g. AV signature updates, other threat signatures or Indicators of Compromise (IoCs)).
- Security alerts relating to network and information systems supporting your essential function(s) are not prioritised.
- The enrichment of security alerts within network and information systems supporting your essential function(s) cannot be performed.
- You do not confidently detect the presence of IoCs on network and information systems supporting your essential function(s), such as known malicious command and control signatures (e.g. because applying the indicator is difficult or your log data is not sufficiently detailed).
- You do not monitor for user or system abnormalities indicative of adverse activity.
- Logs are monitored infrequently.
Partially achieved - All the following statements are true:
- You easily detect the presence of Indicators of Compromise (IoCs) on network and information systems supporting your essential function(s), such as known malicious command and control signatures.
- You apply some updates, new signatures and IoCs in a timely way.
- Security alerts relating to network and information systems that support your essential function(s) are prioritised.
- The enrichment of alerts within network and information systems supporting your essential function(s) is performed but not as part of the original alert.
- Detections and alerting rely on off the shelf tooling without customisation or users reporting events and potential incidents.
- There is a documented and shared process for all users who support the operation of the essential function to report events and potential security incidents.
- Where appropriate, detections and alerting result in automated actions being taken. (e.g. malware identified by AV is quarantined).
- You monitor on an irregular basis for user or system abnormalities indicative of adverse activity.
- Logs are monitored at regular intervals.
Achieved - All the following statements are true:
- You easily detect the presence of Indicators of Compromise (IoCs) on network and information systems supporting your essential function(s), such as known malicious command and control signatures, as well as abnormalities or behaviours indicative of adverse activity.
- You apply all updates, new signatures and IoCs promptly.
- Security alerts relating to all network and information systems supporting your essential function(s) are prioritised and this information is used to support incident management.
- Alerts are routinely enriched within network and information systems supporting your essential function(s). The enrichment of these alerts is performed in almost real time and as part of the original alert.
- Alerts and the underlying detections are regularly reviewed and tested to ensure they are generated promptly and reliably, and it is possible to distinguish genuine security incidents from false alarms.
- Alerts and the underlying detection rules are customisable and tuned to reduce false positives as well as optimising responses.
- Detections and alerting may use off the shelf tooling and rules as well as custom tooling and / or rules.
- You continuously monitor for user and system abnormalities indicative of adverse activity generating alerts based on the results of such monitoring.
- Logs are monitored continuously in near real time.
C1.d Triage of Security Alerts
- You contextualise alerts with knowledge of the threat and your systems, to identify those security incidents as well as responding to all alerts appropriately.
- You contextualise alerts with knowledge of the threat and your systems, to identify those security incidents as well as responding to all alerts appropriately.
- You do not triage alerts from your detection security technologies (e.g. AV, IDS).
- You do not categorise alerts and incidents by type and priority / severity level.
- You do not have Standard Operating Procedures (SOPs) / Playbooks / Runbooks available for use during triage.
- You do not keep records of triage performed.
- You do not have a sufficient understanding of normal user or system behaviour to make effective decisions within triage.
- You investigate and triage alerts from some security tools and take action.
- You have created, made available and use when appropriate, Standard Operating Procedures (SOPs) / Playbooks / Runbooks covering the most common use cases. These are regularly reviewed to ensure they remain effective.
- You perform some triage and actions taken by monitoring and detection personnel are recorded.
- You categorise alerts and incidents by type and priority / severity level.
- Your understanding of normal user or system behaviour informs your decision making within triage.
- You investigate and triage alerts from all security tools and take action.
- You have created, made available and use when appropriate, Standard Operating Procedures (SOPs) / Playbooks / Runbooks covering all plausible use cases. These are regularly reviewed to ensure they remain effective.
- You categorise alerts and incidents by type and priority / severity level.
- You document all triage related activities performed by monitoring and detection personnel and these are used to drive improvements
- Triage provides enough information for subsequent activities to be prioritised (e.g. the containment of damaging malware).
- Your understanding of normal user and system behaviour, and threats, is sufficient for effective decision making within triage.
Not achieved - At least one of the following is true:
- You do not triage alerts from your detection security technologies (e.g. AV, IDS).
- You do not categorise alerts and incidents by type and priority / severity level.
- You do not have Standard Operating Procedures (SOPs) / Playbooks / Runbooks available for use during triage.
- You do not keep records of triage performed.
- You do not have a sufficient understanding of normal user or system behaviour to make effective decisions within triage.
Partially achieved - All the following statements are true:
- You investigate and triage alerts from some security tools and take action.
- You have created, made available and use when appropriate, Standard Operating Procedures (SOPs) / Playbooks / Runbooks covering the most common use cases. These are regularly reviewed to ensure they remain effective.
- You perform some triage and actions taken by monitoring and detection personnel are recorded.
- You categorise alerts and incidents by type and priority / severity level.
- Your understanding of normal user or system behaviour informs your decision making within triage.
Achieved - All the following statements are true:
- You investigate and triage alerts from all security tools and take action.
- You have created, made available and use when appropriate, Standard Operating Procedures (SOPs) / Playbooks / Runbooks covering all plausible use cases. These are regularly reviewed to ensure they remain effective.
- You categorise alerts and incidents by type and priority / severity level.
- You document all triage related activities performed by monitoring and detection personnel and these are used to drive improvements
- Triage provides enough information for subsequent activities to be prioritised (e.g. the containment of damaging malware).
- Your understanding of normal user and system behaviour, and threats, is sufficient for effective decision making within triage.
C1.e Personnel Skills for Monitoring Tools and Detection
- Monitoring and detection personnel skills and roles, including those outsourced, reflect governance and reporting requirements, expected threats and the complexities of the network or system data they need to use. Monitoring and detection personnel have sufficient knowledge of network and information systems and the essential function(s) they need to protect.
- Monitoring and detection personnel skills and roles, including those outsourced, reflect governance and reporting requirements, expected threats and the complexities of the network or system data they need to use. Monitoring and detection personnel have sufficient knowledge of network and information systems and the essential function(s) they need to protect.
- There are no personnel who perform a monitoring and detection function.
- Monitoring and detection personnel do not have the correct specialist skills.
- Monitoring and detection personnel are not capable of reporting against governance requirements.
- Monitoring and detection personnel have a lack of awareness of the essential function(s) the organisation provides, what assets relate to those functions and hence the importance of the log data and security events.
- Monitoring and detection personnel have no awareness of other roles or tasks outside of security monitoring and detection that are relevant to the operation of your essential function(s).
- Monitoring and detection personnel are overwhelmed with the amount of data and alerts they have to work with. Alert / triage fatigue is present.
- Monitoring and detection personnel have some investigative skills and a basic understanding of the data they need to work with.
- Monitoring and detection personnel can report to other parts of the organisation (e.g. security directors, resilience managers).
- Monitoring and detection personnel are capable of following most of the required workflow(s).
- Monitoring and detection personnel are aware of some of the network and information systems and your essential function(s), and can manage alerts relating to them.
- Monitoring and detection personnel have some understanding of the operational context (e.g. people, processes, network and information systems that support your essential function(s)) to enhance the security monitoring function.
- Monitoring and detection personnel deal with their workload and cases effectively.
- You have monitoring and detection personnel who are responsible for the proactive and reactive analysis, investigation and reporting of monitoring alerts including both security and performance.
- Monitoring and detection personnel have defined roles and skills that cover all parts of the monitoring and investigation process.
- Monitoring and detection personnel follow policies, processes and procedures that address all governance reporting requirements, internal and external.
- Monitoring and detection personnel are empowered to look beyond the fixed process to investigate and understand non-standard threats.
- Monitoring and detection personnel are aware of the network and information systems and your essential function(s), related assets and can identify and prioritise alerts and investigations that relate to them.
- Monitoring and detection personnel drive and shape new log data collection and can make effective use of it.
- Monitoring and detection personnel are capable of following all of the required workflow(s).
- Monitoring and detection personnel have a sufficient understanding of the operational context (e.g. people, processes, network and information systems that support your essential function) to enhance the security monitoring function.
- Monitoring and detection personnel deal with their workload and cases effectively as well as identifying areas for improvement.
Not achieved - At least one of the following is true:
- There are no personnel who perform a monitoring and detection function.
- Monitoring and detection personnel do not have the correct specialist skills.
- Monitoring and detection personnel are not capable of reporting against governance requirements.
- Monitoring and detection personnel have a lack of awareness of the essential function(s) the organisation provides, what assets relate to those functions and hence the importance of the log data and security events.
- Monitoring and detection personnel have no awareness of other roles or tasks outside of security monitoring and detection that are relevant to the operation of your essential function(s).
- Monitoring and detection personnel are overwhelmed with the amount of data and alerts they have to work with. Alert / triage fatigue is present.
Partially achieved - All the following statements are true:
- Monitoring and detection personnel have some investigative skills and a basic understanding of the data they need to work with.
- Monitoring and detection personnel can report to other parts of the organisation (e.g. security directors, resilience managers).
- Monitoring and detection personnel are capable of following most of the required workflow(s).
- Monitoring and detection personnel are aware of some of the network and information systems and your essential function(s), and can manage alerts relating to them.
- Monitoring and detection personnel have some understanding of the operational context (e.g. people, processes, network and information systems that support your essential function(s)) to enhance the security monitoring function.
- Monitoring and detection personnel deal with their workload and cases effectively.
Achieved - All the following statements are true:
- You have monitoring and detection personnel who are responsible for the proactive and reactive analysis, investigation and reporting of monitoring alerts including both security and performance.
- Monitoring and detection personnel have defined roles and skills that cover all parts of the monitoring and investigation process.
- Monitoring and detection personnel follow policies, processes and procedures that address all governance reporting requirements, internal and external.
- Monitoring and detection personnel are empowered to look beyond the fixed process to investigate and understand non-standard threats.
- Monitoring and detection personnel are aware of the network and information systems and your essential function(s), related assets and can identify and prioritise alerts and investigations that relate to them.
- Monitoring and detection personnel drive and shape new log data collection and can make effective use of it.
- Monitoring and detection personnel are capable of following all of the required workflow(s).
- Monitoring and detection personnel have a sufficient understanding of the operational context (e.g. people, processes, network and information systems that support your essential function) to enhance the security monitoring function.
- Monitoring and detection personnel deal with their workload and cases effectively as well as identifying areas for improvement.
C1.f Understanding User's and System's Behaviour, and Threat Intelligence (within Security Monitoring)
- Threats to the operation of network and information systems, and corresponding user and system behaviour, are sufficiently understood. These are used to detect cyber security incidents.
- Threats to the operation of network and information systems, and corresponding user and system behaviour, are sufficiently understood. These are used to detect cyber security incidents.
- Your organisation has no sources of threat intelligence.
- You do not evaluate the usefulness of your threat intelligence or share feedback with providers or other users.
- You have no awareness of the steps necessary to make best use of threat intelligence for security monitoring.
- Threat intelligence is unreliable and / or is not actioned by the appropriate users or systems in a timely manner.
- You have no established understanding of what abnormalities to look for that might signify adverse activities.
- You do not receive updates for all your detection security technologies (e.g. AV, IDS).
- You do not understand normal user and system behaviour sufficiently to be able to use abnormalities to detect adverse activity.
- You know how effective your threat intelligence is (e.g. by tracking how threat intelligence helps you identify security incidents).
- Your organisation may use threat intelligence services, but you do not necessarily choose sources or providers specifically because of your business needs, or specific threats in your sector (e.g. sector-based infoshare, software vendors, anti-virus providers, specialist threat intel firms, special interest groups).
- The user and system abnormalities from past attacks and threat intelligence, on your
- and other network and information systems, are used to signify adverse activity.
- You receive regular updates for all of your detection security technologies (e.g. AV, IDS).
- You track the effectiveness of your threat intelligence and actively share feedback on the usefulness of Indicators of Compromise (IoCs) and other intelligence with the threat community (e.g. sector partners, threat intelligence providers, government agencies).
- When using threat intelligence feeds, these have been selected using risk-based and threat-informed decisions based on your business needs and sector.
- You make relevant, reliable and actionable threat intelligence available to the necessary users and systems promptly.
- You contextualise threat intelligence and link it to the why and / or how attacks take place for security monitoring.
- You understand normal user and system abnormalities fully, to such an extent that searching for system abnormalities is an effective way of detecting adverse activity (e.g. you fully understand which systems should and should not communicate and when).
- The user and system abnormalities you monitor for are based on the nature of adverse activities likely to impact network and information systems supporting the operation of your essential function(s).
- The user and system abnormalities indicative of adverse activity you use are regularly updated to reflect changes in network and information systems supporting your essential function(s) and current threat intelligence.
- You possess the capability to share threat intelligence (e.g. ways to effectively detect adversaries) with the threat community / defender community (sector partners, threat intelligence providers, government agencies) when required.
Not achieved - At least one of the following is true:
- Your organisation has no sources of threat intelligence.
- You do not evaluate the usefulness of your threat intelligence or share feedback with providers or other users.
- You have no awareness of the steps necessary to make best use of threat intelligence for security monitoring.
- Threat intelligence is unreliable and / or is not actioned by the appropriate users or systems in a timely manner.
- You have no established understanding of what abnormalities to look for that might signify adverse activities.
- You do not receive updates for all your detection security technologies (e.g. AV, IDS).
- You do not understand normal user and system behaviour sufficiently to be able to use abnormalities to detect adverse activity.
Partially achieved - All the following statements are true:
- You know how effective your threat intelligence is (e.g. by tracking how threat intelligence helps you identify security incidents).
- Your organisation may use threat intelligence services, but you do not necessarily choose sources or providers specifically because of your business needs, or specific threats in your sector (e.g. sector-based infoshare, software vendors, anti-virus providers, specialist threat intel firms, special interest groups).
- The user and system abnormalities from past attacks and threat intelligence, on your
- and other network and information systems, are used to signify adverse activity.
- You receive regular updates for all of your detection security technologies (e.g. AV, IDS).
Achieved - All the following statements are true:
- You track the effectiveness of your threat intelligence and actively share feedback on the usefulness of Indicators of Compromise (IoCs) and other intelligence with the threat community (e.g. sector partners, threat intelligence providers, government agencies).
- When using threat intelligence feeds, these have been selected using risk-based and threat-informed decisions based on your business needs and sector.
- You make relevant, reliable and actionable threat intelligence available to the necessary users and systems promptly.
- You contextualise threat intelligence and link it to the why and / or how attacks take place for security monitoring.
- You understand normal user and system abnormalities fully, to such an extent that searching for system abnormalities is an effective way of detecting adverse activity (e.g. you fully understand which systems should and should not communicate and when).
- The user and system abnormalities you monitor for are based on the nature of adverse activities likely to impact network and information systems supporting the operation of your essential function(s).
- The user and system abnormalities indicative of adverse activity you use are regularly updated to reflect changes in network and information systems supporting your essential function(s) and current threat intelligence.
- You possess the capability to share threat intelligence (e.g. ways to effectively detect adversaries) with the threat community / defender community (sector partners, threat intelligence providers, government agencies) when required.
The organisation proactively seeks to detect, within networks and information systems, adverse activity affecting, or with the potential to affect, the operation of essential functions even when the activity evades standard security prevent/detect solutions (or when standard solutions are not deployable).
Description
error determining description
Guidance
Threat hunting is more difficult than standard security monitoring because it looks beyond the known Indicators of Compromise (IOCs) that can be leveraged by automated detections and alerting covered in
C1 Security Monitoring
.
The aim is to build on what is known of both past and plausible attacks to hypothesise what intrusions might look like in. Threat hunting requires more experienced knowledge of network and system behaviour and of the general characteristics that an intrusion might exhibit. This sort of proactive monitoring or threat discovery would normally involve:
A good understanding of normal system behaviour (e.g. what software is authorised and how it would normally behave, how user accounts normally access network resources or how network components connect to each other and transfer data).
A good understanding of the ways that different types of threats maybe realised within your environment(s) based on a comprehensive and advanced understanding of threat intelligence.
A good understanding of normal system behaviour (e.g. what software is authorised and how it would normally behave, how user accounts normally access network resources or how network components connect to each other and transfer data).
Contributing Outcomes
C2.a Threat Hunting
- You do not know the resources required for threat hunting.
- You do not have access to an effective threat hunting capability.
- Your threat hunts do not follow any structure and few if any records are created.
- You have identified the resources required to perform threat hunting and are able to deploy these, in a timely manner, on an occasional basis.
- You deploy an effective threat hunting capability but not frequent enough to match the risks posed to network and information systems supporting your essential function(s) (e.g. you perform threat hunts in response to a tip off from a reputable source).
- Your threat hunts follow pre-determined and documented methods (e.g. hypothesis driven, data driven, entity driven) designed to identify adverse activity not detected by automated detections.
- You document details of threat hunts and post hunt analysis.
- You understand the resources required to perform threat hunting and these are deployed as part of business as usual.
- You deploy threat hunting resources at a frequency that matches the risks posed to network and information systems supporting your essential function(s).
- Your threat hunts follow pre-determined and documented methods (e.g. hypothesis driven, data driven, entity driven) designed to identify adverse activity not detected by automated detections.
- You turn threat hunts into automated detections and alerting where appropriate.
- You routinely record details of previous threat hunts and post hunt activities. You use these to drive improvements in your threat hunting and security posture.
- You have justified confidence in the effectiveness of your threat hunts and the threat hunting process is reviewed and updated to match the risks posed to network and information systems supporting your essential function(s).
- You leverage automation to improve threat hunts where appropriate (e.g. some stages of the threat hunting process are automated).
- Your threat hunts focus on the tactics, techniques and procedures (TTPs) of threats over atomic IoCs (e.g. hashes, IP addresses, domain names etc).
Not achieved - At least one of the following statements is true:
- You do not know the resources required for threat hunting.
- You do not have access to an effective threat hunting capability.
- Your threat hunts do not follow any structure and few if any records are created.
Partially achieved - All the following statements are true:
- You have identified the resources required to perform threat hunting and are able to deploy these, in a timely manner, on an occasional basis.
- You deploy an effective threat hunting capability but not frequent enough to match the risks posed to network and information systems supporting your essential function(s) (e.g. you perform threat hunts in response to a tip off from a reputable source).
- Your threat hunts follow pre-determined and documented methods (e.g. hypothesis driven, data driven, entity driven) designed to identify adverse activity not detected by automated detections.
- You document details of threat hunts and post hunt analysis.
Achieved - All the following statements are true:
- You understand the resources required to perform threat hunting and these are deployed as part of business as usual.
- You deploy threat hunting resources at a frequency that matches the risks posed to network and information systems supporting your essential function(s).
- Your threat hunts follow pre-determined and documented methods (e.g. hypothesis driven, data driven, entity driven) designed to identify adverse activity not detected by automated detections.
- You turn threat hunts into automated detections and alerting where appropriate.
- You routinely record details of previous threat hunts and post hunt activities. You use these to drive improvements in your threat hunting and security posture.
- You have justified confidence in the effectiveness of your threat hunts and the threat hunting process is reviewed and updated to match the risks posed to network and information systems supporting your essential function(s).
- You leverage automation to improve threat hunts where appropriate (e.g. some stages of the threat hunting process are automated).
- Your threat hunts focus on the tactics, techniques and procedures (TTPs) of threats over atomic IoCs (e.g. hashes, IP addresses, domain names etc).
There are well-defined and tested incident management processes in place, that aim to ensure continuity of essential function(s) in the event of system or service failure. Mitigation activities designed to contain or limit the impact of compromise are also in place.
Description
error determining description
Guidance
The 10 Steps to Cyber Security: Incident Management has concise guidance, but organisations should use other more detailed guidance as and when appropriate. Other authoritative guidance pieces are referenced below.
In addition to meeting the expectations of 10 Steps to Cyber Security, you should ensure that your organisation's incident response plans are grounded in thorough and comprehensive risk assessments. Response plans should prioritise essential functions along with the assets and systems that are required to ensure their continued effective operation, such as operational technologies, or key datasets.
The business continuity implications of any compromise should also be taken into account and your cyber incident response plans should link to other business response functions. You should form a cyber response team that is capable of implementing the plan, with the appropriate skills, tools and reach into other parts of your organisation, such as security monitoring and business continuity.
In practice, the Incident Response function should interoperate with the security monitoring function. The Incident Response function needn't be a dedicated team and some members may have non-response related roles. Collectively, the team should have knowledge of IT security, IT infrastructure and Business Management, any specialist technologies (e.g. Operational Technologies or datacentres), incident reporting requirements, and communications plans.
Your plan should cover all relevant potential incidents. It should be auditable and testable (
via exercises
) across a range of incident scenarios and should encompass all realistic descriptions of what might constitute an incident and its severity. Your test scenarios should draw on threat intelligence, past incidents, exercises and the ways in which security capabilities (e.g. security monitoring and alerting) would feature in your response options. Your scenarios should also consider incidents that involve suppliers and your wider supply chain e.g. incidents arising through supplier relations or relying on suppliers as part of your response.
These scenarios could include, but is not limited to:
The scenarios should be incorporated into exercises, which should be run to test your ability to respond to incidents that could affect the operation of essential functions. These exercises should reflect past experience, red-teaming/scenario planning, or threat intelligence and should draw heavily on your risk assessment, considering all relevant assets and vulnerabilities, especially where they relate to essential functions.
Exercises should record lessons learned, covering governance, roles and internal communication, quality of network and security monitoring data, containment and recovery strategies, or any other factors relevant to their effectiveness. This should integrate with lessons learned activities (see
Principle D2 Lessons Learned
).
Your plans should work seamlessly with other system management and security functions. Changes and improvements to response plans should reflect changes to these functions and vice versa, where appropriate.
Plans should articulate clear governance frameworks and roles with procedures for reporting to relevant internal or external stakeholders, such as regulators and competent authorities.
Your plan should also set out a comprehensive range of containment, eradication and recovery strategies, specifying how and when they should be used.
Your organisation should be able to describe its own state of readiness, using any criteria or expected standards from regulators or competent authorities, or from your internal governance arrangements, where appropriate.
In order to report coherently on incidents when required, your plan should set out reporting thresholds (i.e. what does and does not need to be reported) and standards (i.e. the level of detail that should be reported) and which authorities to report to.
More detailed guidance on developing an incident response plan, and the underlying capability to implement it, can be found in the
NIST Computer Security Incident Handling Guide
, CREST publications (see references) or
ISO/IEC 27035-1
.
Contributing Outcomes
D1.a Response Plan
- You have an up-to-date incident response plan that is grounded in a thorough risk assessment that takes account of network and information systems supporting the operation of your essential function(s) and covers a range of incident scenarios.
- You have an up-to-date incident response plan that is grounded in a thorough risk assessment that takes account of network and information systems supporting the operation of your essential function(s) and covers a range of incident scenarios.
- Your incident response plan is not documented.
- Your incident response plan does not include your organisations identified essential function(s).
- Your incident response plan is not well understood by relevant staff.
- Your incident response plan covers network and information systems supporting your essential function(s).
- Your incident response plan comprehensively covers scenarios that are focused on likely impacts of known and well understood attacks only.
- Your incident response plan is understood by all staff who are involved with your organisation's response function.
- Your incident response plan is documented and shared with all relevant stakeholders.
- Your incident response plan is readily accessible, even when your organisations IT systems have been adversely affected by an incident.
- Your incident response plan is regularly reviewed to ensure it remains effective.
- Your incident response plan is based on a clear understanding of the security risks to the network and information systems supporting your essential function(s).
- Your incident response plan is comprehensive (i.e. covers the complete lifecycle of an incident, roles and responsibilities, and reporting) and covers likely impacts of both known attack patterns and of possible attacks, previously unseen.
- Your incident response plan is documented and integrated with wider organisational business plans and supply chain response plans as well as dependencies on supporting infrastructure (e.g. power, cooling etc).
- Your incident response plan is communicated and understood by the business areas involved with the operation of your essential function(s).
Not achieved - At least one of the following is true:
- Your incident response plan is not documented.
- Your incident response plan does not include your organisations identified essential function(s).
- Your incident response plan is not well understood by relevant staff.
Partially Achieved - All the following statements are true:
- Your incident response plan covers network and information systems supporting your essential function(s).
- Your incident response plan comprehensively covers scenarios that are focused on likely impacts of known and well understood attacks only.
- Your incident response plan is understood by all staff who are involved with your organisation's response function.
- Your incident response plan is documented and shared with all relevant stakeholders.
- Your incident response plan is readily accessible, even when your organisations IT systems have been adversely affected by an incident.
- Your incident response plan is regularly reviewed to ensure it remains effective.
Achieved - All the following statements are true:
- Your incident response plan is based on a clear understanding of the security risks to the network and information systems supporting your essential function(s).
- Your incident response plan is comprehensive (i.e. covers the complete lifecycle of an incident, roles and responsibilities, and reporting) and covers likely impacts of both known attack patterns and of possible attacks, previously unseen.
- Your incident response plan is documented and integrated with wider organisational business plans and supply chain response plans as well as dependencies on supporting infrastructure (e.g. power, cooling etc).
- Your incident response plan is communicated and understood by the business areas involved with the operation of your essential function(s).
D1.b Response and Recovery Capability
- You have the capability to enact your incident response plan, including effective limitation of impact on the operation of your essential function(s). During an incident, you have access to timely information on which to base your response decisions.
- You have the capability to enact your incident response plan, including effective limitation of impact on the operation of your essential function(s). During an incident, you have access to timely information on which to base your response decisions.
- Inadequate arrangements have been made to make the right resources available to implement your response plan.
- Your response team members are not equipped to make good response decisions and put them into effect.
- Inadequate back-up mechanisms exist to allow the continued operation of your essential function(s) during an incident.
- You understand the resources that will likely be needed to carry out any required response activities, and arrangements are in place to make these resources available.
- You understand the types of information that will likely be needed to inform response decisions and arrangements are in place to make this information available.
- Your response team members have the skills and knowledge required to decide on the response actions necessary to limit harm, and the authority to carry them out.
- Key roles are duplicated, and operational delivery knowledge is shared with all individuals involved in the operations and recovery of the essential function(s).
- Back-up mechanisms are available that can be readily activated to allow continued operation of your essential function(s), although possibly at a reduced level, if primary network and information systems fail or are unavailable.
- Arrangements exist to augment your organisation’s incident response capabilities with external support if necessary (e.g. specialist cyber incident responders).
Not Achieved - At least one of the following is true:
- Inadequate arrangements have been made to make the right resources available to implement your response plan.
- Your response team members are not equipped to make good response decisions and put them into effect.
- Inadequate back-up mechanisms exist to allow the continued operation of your essential function(s) during an incident.
Achieved - All the following statements are true:
- You understand the resources that will likely be needed to carry out any required response activities, and arrangements are in place to make these resources available.
- You understand the types of information that will likely be needed to inform response decisions and arrangements are in place to make this information available.
- Your response team members have the skills and knowledge required to decide on the response actions necessary to limit harm, and the authority to carry them out.
- Key roles are duplicated, and operational delivery knowledge is shared with all individuals involved in the operations and recovery of the essential function(s).
- Back-up mechanisms are available that can be readily activated to allow continued operation of your essential function(s), although possibly at a reduced level, if primary network and information systems fail or are unavailable.
- Arrangements exist to augment your organisation’s incident response capabilities with external support if necessary (e.g. specialist cyber incident responders).
D1.c Testing and Exercising
- Your organisation carries out exercises to test response plans, using past incidents that affected your (and other) organisation, and scenarios that draw on threat intelligence and your risk assessment.
- Your organisation carries out exercises to test response plans, using past incidents that affected your (and other) organisation, and scenarios that draw on threat intelligence and your risk assessment.
- Exercises test only a discrete part of the process (e.g. that backups are working), but do not consider all areas.
- Incident response exercises are not routinely carried out or are carried out in an ad-hoc way.
- Outputs from exercises are not fed into the organisation's lessons learned process.
- Exercises do not test all parts of the response cycle.
- Exercise scenarios are based on incidents experienced by your and other organisations or are composed using experience or threat intelligence.
- Exercise scenarios are documented, regularly reviewed, and validated.
- Exercises are routinely run, with the findings documented and used to refine incident response plans and protective security, in line with the lessons learned.
- Exercises test all parts of your response cycle relating to your essential function(s) (e.g. restoration of normal function(s) levels).
Not Achieved - At least one of the following is true:
- Exercises test only a discrete part of the process (e.g. that backups are working), but do not consider all areas.
- Incident response exercises are not routinely carried out or are carried out in an ad-hoc way.
- Outputs from exercises are not fed into the organisation's lessons learned process.
- Exercises do not test all parts of the response cycle.
Achieved - All the following statements are true:
- Exercise scenarios are based on incidents experienced by your and other organisations or are composed using experience or threat intelligence.
- Exercise scenarios are documented, regularly reviewed, and validated.
- Exercises are routinely run, with the findings documented and used to refine incident response plans and protective security, in line with the lessons learned.
- Exercises test all parts of your response cycle relating to your essential function(s) (e.g. restoration of normal function(s) levels).
When an incident occurs, steps are taken to understand its causes and to ensure remediating action is taken to protect against future incidents.
Description
error determining description
Guidance
You should use the guidance points below to learn lessons and address shortfalls in:
your overall protective security (see
Objectives A - C
) and
your incident response plan (see
Response and Recovery Planning
)
your overall protective security (see
Objectives A - C
) and
Contributing Outcomes
D2.a Post Incident Analysis
- When an incident occurs, your organisation takes steps to understand its causes, informing appropriate remediating action.
- When an incident occurs, your organisation takes steps to understand its causes, informing appropriate remediating action.
- You are not usually able to resolve incidents to a root cause or identify the contributing factors within a broader systems context.
- You do not have a formal process for investigating causes.
- Investigators form theories early in the process and only seek evidence that affirms their belief.
- Investigations are solely focused on identifying the person(s) who can be held responsible for the incident.
- Post incident analysis is conducted routinely as a key part of your lessons learned activities following an incident.
- Your post incident analysis is comprehensive, considering organisational factors (e.g. policies, processes and procedures), technical factors (e.g. system design, vulnerabilities), human factors (e.g. training, security culture) and any changes to threat.
- All relevant incident data is made available to the analysis team to perform post incident analysis.
- Your analysis considers what could have happened under plausible, alternative circumstances (e.g. ‘what if’ / ’if only’ scenarios).
Not Achieved - At least one of the following statements is true:
- You are not usually able to resolve incidents to a root cause or identify the contributing factors within a broader systems context.
- You do not have a formal process for investigating causes.
- Investigators form theories early in the process and only seek evidence that affirms their belief.
- Investigations are solely focused on identifying the person(s) who can be held responsible for the incident.
Achieved - All the following statements are true:
- Post incident analysis is conducted routinely as a key part of your lessons learned activities following an incident.
- Your post incident analysis is comprehensive, considering organisational factors (e.g. policies, processes and procedures), technical factors (e.g. system design, vulnerabilities), human factors (e.g. training, security culture) and any changes to threat.
- All relevant incident data is made available to the analysis team to perform post incident analysis.
- Your analysis considers what could have happened under plausible, alternative circumstances (e.g. ‘what if’ / ’if only’ scenarios).
D2.b Using Incidents to Drive Improvements
- Your organisation uses lessons learned from incidents to improve your security measures.
- Your organisation uses lessons learned from incidents to improve your security measures.
- Improvements arising from lessons learned following an incident are not implemented or not given sufficient organisational priority.
- Changes are made as a ‘knee jerk’ reaction to an incident without proper analysis and testing to ensure the change is appropriate.
- You wait until a severe or high-profile incident has occurred before you take steps to improve.
- You have a documented incident review process / policy which ensures that lessons learned from each incident, including near misses, are identified, captured, and acted upon.
- Lessons learned cover issues with reporting, roles, governance, skills and organisational policies, processes and procedures as well as technical aspects of network and information systems.
- You use lessons learned to improve security measures, including updating and retesting response plans when necessary.
- Security improvements identified as a result of lessons learned are prioritised, with the highest priority improvements completed promptly.
- Analysis is fed to senior management and incorporated into risk management and continuous improvement.
- Your organisation maximises the lessons learned by using the analysis into ‘what if’ / ’if only’ scenarios.
- Your organisation learns from reported incidents in your sector and the wider national infrastructure.
Not Achieved - At least one of the following is true:
- Improvements arising from lessons learned following an incident are not implemented or not given sufficient organisational priority.
- Changes are made as a ‘knee jerk’ reaction to an incident without proper analysis and testing to ensure the change is appropriate.
- You wait until a severe or high-profile incident has occurred before you take steps to improve.
Achieved - All the following statements are true:
- You have a documented incident review process / policy which ensures that lessons learned from each incident, including near misses, are identified, captured, and acted upon.
- Lessons learned cover issues with reporting, roles, governance, skills and organisational policies, processes and procedures as well as technical aspects of network and information systems.
- You use lessons learned to improve security measures, including updating and retesting response plans when necessary.
- Security improvements identified as a result of lessons learned are prioritised, with the highest priority improvements completed promptly.
- Analysis is fed to senior management and incorporated into risk management and continuous improvement.
- Your organisation maximises the lessons learned by using the analysis into ‘what if’ / ’if only’ scenarios.
- Your organisation learns from reported incidents in your sector and the wider national infrastructure.
Principles
The organisation has appropriate management policies, processes and procedures in place to govern its approach to the security of network and information systems.
Description
error determining description
Guidance
Your organisation's approach to security governance needs to be an appropriate fit for your organisation. Good security governance is integrated with your business's usual decision making structures and processes.
Decisions about risk can be made at all levels of your organisation when delegated effectively to people with the right security, business and technical knowledge, skills and experience. Clear lines of communication are also necessary.
Contributing Outcomes
A1.a Board Direction
- You have effective organisational security management led at board level and articulated clearly in corresponding policies.
- You have effective organisational security management led at board level and articulated clearly in corresponding policies.
- The security of network and information systems related to the operation of essential function(s) is not discussed or reported on regularly at board-level.
- Board-level discussions on the security of network and information systems are based on partial or out-of-date information, without the benefit of expert guidance.
- The security of network and information systems supporting your essential function(s) are not driven effectively by the direction set at board-level.
- Senior management or other pockets of the organisation consider themselves exempt from some policies or expect special accommodations to be made.
- Your organisation's approach and policy relating to the security of network and information systems supporting the operation of essential function(s) are owned and managed at board-level. These are communicated, in a meaningful way, to risk management decision-makers across the organisation.
- Regular board-level discussions on the security of network and information systems supporting the operation of your essential function(s) take place, based on timely and accurate information and informed by expert guidance.
- There is a board-level individual who has overall accountability for the security of network and information systems and drives regular discussion at board-level.
- Direction set at board-level is translated into effective organisational practices that direct and control the security of the network and information systems supporting your essential functions(s).
- The board has the information and understanding needed in order to effectively discuss how the security and resilience of network and information systems contributes to the delivery of essential function(s) and what the potential impact from compromise of those systems would be.
- Security is recognised as an important enabler for the resilience of your essential function(s) and considered in all relevant discussions.
Not achieved - At least one of the following statements is true:
- The security of network and information systems related to the operation of essential function(s) is not discussed or reported on regularly at board-level.
- Board-level discussions on the security of network and information systems are based on partial or out-of-date information, without the benefit of expert guidance.
- The security of network and information systems supporting your essential function(s) are not driven effectively by the direction set at board-level.
- Senior management or other pockets of the organisation consider themselves exempt from some policies or expect special accommodations to be made.
Achieved - All the following statements are true:
- Your organisation's approach and policy relating to the security of network and information systems supporting the operation of essential function(s) are owned and managed at board-level. These are communicated, in a meaningful way, to risk management decision-makers across the organisation.
- Regular board-level discussions on the security of network and information systems supporting the operation of your essential function(s) take place, based on timely and accurate information and informed by expert guidance.
- There is a board-level individual who has overall accountability for the security of network and information systems and drives regular discussion at board-level.
- Direction set at board-level is translated into effective organisational practices that direct and control the security of the network and information systems supporting your essential functions(s).
- The board has the information and understanding needed in order to effectively discuss how the security and resilience of network and information systems contributes to the delivery of essential function(s) and what the potential impact from compromise of those systems would be.
- Security is recognised as an important enabler for the resilience of your essential function(s) and considered in all relevant discussions.
A1.b Roles and Responsibilities
- Your organisation has established roles and responsibilities for the security of network and information systems at all levels, with clear and well-understood channels for communicating and escalating risks.
- Your organisation has established roles and responsibilities for the security of network and information systems at all levels, with clear and well-understood channels for communicating and escalating risks.
- Key roles are missing, left vacant, or fulfilled on an ad-hoc or informal basis.
- Staff are assigned security responsibilities but without adequate authority or resources to fulfil them.
- Staff are unsure what their responsibilities are for the security of the essential function(s).
- Key roles and responsibilities for the security of network and information systems supporting your essential function(s) have been identified. These are reviewed regularly to ensure they remain fit for purpose.
- Appropriately capable and knowledgeable staff fill those roles and are given the time, authority, and resources to carry out their duties.
- There is clarity on who in your organisation has overall accountability for the security of the network and information systems supporting your essential function(s).
Not achieved - At least one of the following statements is true:
- Key roles are missing, left vacant, or fulfilled on an ad-hoc or informal basis.
- Staff are assigned security responsibilities but without adequate authority or resources to fulfil them.
- Staff are unsure what their responsibilities are for the security of the essential function(s).
Achieved - All the following statements are true:
- Key roles and responsibilities for the security of network and information systems supporting your essential function(s) have been identified. These are reviewed regularly to ensure they remain fit for purpose.
- Appropriately capable and knowledgeable staff fill those roles and are given the time, authority, and resources to carry out their duties.
- There is clarity on who in your organisation has overall accountability for the security of the network and information systems supporting your essential function(s).
A1.c Decision-making
- You have senior-level accountability for the security of network and information systems, and delegate decision-making authority appropriately and effectively. Risks to network and information systems related to the operation of the essential function(s) are considered in the context of other organisational risks
.
- You have senior-level accountability for the security of network and information systems, and delegate decision-making authority appropriately and effectively. Risks to network and information systems related to the operation of the essential function(s) are considered in the context of other organisational risks
- What should be relatively straightforward risk decisions are constantly referred up the chain, or not made.
- Risks are resolved informally (or ignored) at a local level when the use of a more formal risk reporting mechanism would be more appropriate.
- Decision-makers are unsure of what senior management's risk appetite is, or only understand it in vague terms such as "averse" or "cautious".
- Decision-makers are unable to justify their risk management decisions.
- Organisational structure causes risk decisions to be made in isolation. (e.g. engineering and IT don't talk to each other about risk).
- Risk priorities are too vague to make meaningful distinctions between them. (e.g. almost all risks are rated 'medium' or 'amber').
- Senior management have visibility of key risk decisions made throughout the organisation.
- Risk management decision-makers understand their responsibilities for making effective and timely decisions in the context of the risk appetite regarding the essential function(s), as set by senior management.
- Risk management decision-making is delegated and escalated where necessary, across the organisation, to people who have the skills, knowledge, tools and authority they need.
- Risk management decisions are regularly reviewed to ensure their continued relevance and validity.
Not achieved - At least one of the following statements is true:
- What should be relatively straightforward risk decisions are constantly referred up the chain, or not made.
- Risks are resolved informally (or ignored) at a local level when the use of a more formal risk reporting mechanism would be more appropriate.
- Decision-makers are unsure of what senior management's risk appetite is, or only understand it in vague terms such as "averse" or "cautious".
- Decision-makers are unable to justify their risk management decisions.
- Organisational structure causes risk decisions to be made in isolation. (e.g. engineering and IT don't talk to each other about risk).
- Risk priorities are too vague to make meaningful distinctions between them. (e.g. almost all risks are rated 'medium' or 'amber').
Achieved - All the following statements are true:
- Senior management have visibility of key risk decisions made throughout the organisation.
- Risk management decision-makers understand their responsibilities for making effective and timely decisions in the context of the risk appetite regarding the essential function(s), as set by senior management.
- Risk management decision-making is delegated and escalated where necessary, across the organisation, to people who have the skills, knowledge, tools and authority they need.
- Risk management decisions are regularly reviewed to ensure their continued relevance and validity.
The organisation takes appropriate steps to identify, assess and understand security risks to network and information systems supporting the operation of essential functions. This includes an overall organisational approach to risk management.
Description
error determining description
Guidance
Our
Risk Management guidance
aims to help you to choose an approach that's right for your organisation. Organisations responsible for essential functions are likely to benefit from a combination of a
system-based approach
, which looks at the interactions between components of the function, and a
component-driven analysis
, which considers the threats, vulnerabilities, and impacts relevant to particular critical components.
Your organisation should choose a method or framework for managing risk that fits with the organisation's business and technology needs.
Whichever approach you choose, the scope of your programme must include all systems relevant to the operation of essential functions. Simply following the minimum requirements of a standard or applying blanket controls across the organisation is unlikely to adequately manage risks to critical systems.
Where industrial control and automation systems are in scope of the essential function, you should keep in mind that controls suitable for managing risks on the corporate IT network may be inappropriate or damaging in an operational technology environment. These systems will likely require a more tailored approach, and some frameworks and standards address specific concerns relating to such systems.
Cyber threats continue to evolve and develop, putting each organisation’s operational continuity and services at significant risk. By identifying and understanding cyber threats, and the steps a threat actor may take to compromise systems supporting essential functions, an organisation can implement effective security measures to counter malicious attacks and breaches. Various methods can be used to better understand threat which are discussed in our
Risk Management guidance
.
Ultimately, a detailed understanding of current cyber threats helps organisations to mitigate risks, ensuring the security and resilience of network and information systems in an increasingly hostile world.
Various means are available to gain confidence in the effectiveness of the security of technologies, processes and people. The NCSC Risk Management guidance discusses
how to gain and maintain assurance
in your risk treatments.
The NCSC assurance guidance provides some examples that may be useful to understand cyber security confidence in your organisation and there are some specific technical NCSC guides:
The
NCSC Penetration guidance
will help you understand the proper use and commissioning of penetration tests to gain assurance in the security of an IT system.
Our
Cloud Security collection
provides guidance on managing the risks involved with using cloud services, and some of the principles and guidance are more broadly applicable. The cloud guidance for having confidence in cyber security provides principles that are useful for assuring cyber security of essential functions. The collection will be of particular interest if your organisation hosts any part of your essential function infrastructure on a cloud service.
The
NCSC Penetration guidance
will help you understand the proper use and commissioning of penetration tests to gain assurance in the security of an IT system.
Contributing Outcomes
A2.a Risk Management Process
- Your organisation has effective internal processes for managing risks to the security and resilience of network and information systems related to the operation of your essential function(s) and communicating associated activities.
- Your organisation has effective internal processes for managing risks to the security and resilience of network and information systems related to the operation of your essential function(s) and communicating associated activities.
- Risk assessments are not based on a clearly defined set of threat assumptions.
- Risk assessment outputs are too complex or unwieldy to be consumed by decision-makers and are not effectively communicated in a clear and timely manner.
- Risk assessments for network and information systems that support your essential function(s) are a "one-off" activity or not done at all.
- The security elements of projects or programmes are solely dependent on the completion of a risk management assessment without any regard to the outcomes.
- There is no systematic process in place to ensure that identified security risks are managed effectively.
- Systems are assessed in isolation, without consideration of dependencies and interactions with other systems. (e.g. interactions between IT and OT environments).
- Security requirements and mitigations are arbitrary or are applied from a control catalogue without consideration of how they contribute to the security of the essential function(s).
- Risks remain unresolved on a register for prolonged periods of time awaiting senior decision-making or resource allocation to resolve.
- Your organisational process ensures that security risks to network and information systems relevant to essential function(s) are identified, analysed, prioritised, and managed.
- Your risk assessments are informed by an understanding of the vulnerabilities in the network and information systems supporting your essential function(s).
- The output from your risk management process is a clear set of security requirements that will address the risks in line with your organisational approach to security.
- Significant conclusions reached in the course of your risk management process are communicated to key security decision-makers and accountable individuals.
- You conduct risk assessments when significant events potentially affect the essential function(s), such as replacing a system, introducing new or emergent technologies or a change in the cyber security threat.
- Your organisational process ensures that security risks to network and information systems relevant to essential function(s) are identified, analysed, prioritised, and managed.
- Your approach to risk is focused on the possibility of adverse impact to your essential function(s), leading to a detailed understanding of how such impact might arise as a consequence of possible attacker actions and the security properties of your network and information systems.
- Your risk assessments are based on a clearly understood set of threat assumptions, informed by an up-to-date understanding of security threats to your essential function(s) and your sector.
- Your risk assessments are informed by an understanding of the vulnerabilities in the network and information systems supporting your essential function(s).
- The output from your risk management process is a clear set of security requirements that will address the risks in line with your organisational approach to security.
- Significant conclusions reached in the course of your risk management process are communicated to key security decision-makers and accountable individuals.
- Your risk assessments are dynamic and updated in the light of relevant changes which may include technical changes to network and information systems, change of use and new threat information.
- The effectiveness of your risk management process is reviewed regularly, and improvements made as required.
- You anticipate technological developments that could be used to adversely impact network and information systems supporting your essential function(s).
Not achieved - At least one of the following statements is true:
- Risk assessments are not based on a clearly defined set of threat assumptions.
- Risk assessment outputs are too complex or unwieldy to be consumed by decision-makers and are not effectively communicated in a clear and timely manner.
- Risk assessments for network and information systems that support your essential function(s) are a "one-off" activity or not done at all.
- The security elements of projects or programmes are solely dependent on the completion of a risk management assessment without any regard to the outcomes.
- There is no systematic process in place to ensure that identified security risks are managed effectively.
- Systems are assessed in isolation, without consideration of dependencies and interactions with other systems. (e.g. interactions between IT and OT environments).
- Security requirements and mitigations are arbitrary or are applied from a control catalogue without consideration of how they contribute to the security of the essential function(s).
- Risks remain unresolved on a register for prolonged periods of time awaiting senior decision-making or resource allocation to resolve.
Partially achieved - All the following statements are true:
- Your organisational process ensures that security risks to network and information systems relevant to essential function(s) are identified, analysed, prioritised, and managed.
- Your risk assessments are informed by an understanding of the vulnerabilities in the network and information systems supporting your essential function(s).
- The output from your risk management process is a clear set of security requirements that will address the risks in line with your organisational approach to security.
- Significant conclusions reached in the course of your risk management process are communicated to key security decision-makers and accountable individuals.
- You conduct risk assessments when significant events potentially affect the essential function(s), such as replacing a system, introducing new or emergent technologies or a change in the cyber security threat.
Achieved - All the following statements are true:
- Your organisational process ensures that security risks to network and information systems relevant to essential function(s) are identified, analysed, prioritised, and managed.
- Your approach to risk is focused on the possibility of adverse impact to your essential function(s), leading to a detailed understanding of how such impact might arise as a consequence of possible attacker actions and the security properties of your network and information systems.
- Your risk assessments are based on a clearly understood set of threat assumptions, informed by an up-to-date understanding of security threats to your essential function(s) and your sector.
- Your risk assessments are informed by an understanding of the vulnerabilities in the network and information systems supporting your essential function(s).
- The output from your risk management process is a clear set of security requirements that will address the risks in line with your organisational approach to security.
- Significant conclusions reached in the course of your risk management process are communicated to key security decision-makers and accountable individuals.
- Your risk assessments are dynamic and updated in the light of relevant changes which may include technical changes to network and information systems, change of use and new threat information.
- The effectiveness of your risk management process is reviewed regularly, and improvements made as required.
- You anticipate technological developments that could be used to adversely impact network and information systems supporting your essential function(s).
A2.b Understanding Threat
- You understand the capabilities, methods and techniques of threat actors and what network and information systems they may compromise to adversely impact your essential function(s). This information is used to inform security and resilience risk management decisions, adjusting, enhancing or adding security measures to better defend against threats.
- You understand the capabilities, methods and techniques of threat actors and what network and information systems they may compromise to adversely impact your essential function(s). This information is used to inform security and resilience risk management decisions, adjusting, enhancing or adding security measures to better defend against threats.
- You are unable to perform threat analysis.
- You do not understand the threats to network and information systems supporting your essential function(s).
- You do not have a clearly defined set of threat assumptions.
- You do not use your understanding of threat to inform your risk management decisions.
- You perform threat analysis and understand how common threats apply to network and information systems supporting your essential function(s).
- You understand common types of cyber attacks, including the methods and techniques, and how these might apply to network and information systems supporting your essential function(s). This understanding is kept up to date.
- You anticipate what threat actors might target in network and information systems to cause an adverse impact to your essential function(s).
- Your understanding of threat is informed by common incidents.
- You apply your understanding of threat to inform your risk management decision-making.
- You perform detailed threat analysis and understand how this applies to network and information systems supporting your essential function(s), in the context of your sector and wider national infrastructure.
- Your detailed understanding of threat includes the methods and techniques available to capable and well-resourced threat actors and how they could be used systematically against network and information systems supporting your essential function(s).
- You use appropriate techniques to develop an understanding of network and information systems supporting your essential function(s) from a threat actor’s perspective. You anticipate probable attack methods and techniques, targets and objectives, and develop plausible scenarios.
- You understand the different steps a capable and well-resourced threat actor would need to take to reach the probable target(s).
- You identify and justify what measures can be used at each step to reduce the likelihood of the threat actor reaching the probable target(s) or achieving their objective(s).
- You maintain a detailed understanding of current threats (e.g. by threat intelligence and proactive research).
- You apply your detailed understanding of threat to inform your risk management decision-making.
- You have documented the steps required to undertake detailed threat analysis.
Not achieved - At least one of the following statements is true:
- You are unable to perform threat analysis.
- You do not understand the threats to network and information systems supporting your essential function(s).
- You do not have a clearly defined set of threat assumptions.
- You do not use your understanding of threat to inform your risk management decisions.
Partially achieved - All the following statements are true:
- You perform threat analysis and understand how common threats apply to network and information systems supporting your essential function(s).
- You understand common types of cyber attacks, including the methods and techniques, and how these might apply to network and information systems supporting your essential function(s). This understanding is kept up to date.
- You anticipate what threat actors might target in network and information systems to cause an adverse impact to your essential function(s).
- Your understanding of threat is informed by common incidents.
- You apply your understanding of threat to inform your risk management decision-making.
Achieved - All the following statements are true:
- You perform detailed threat analysis and understand how this applies to network and information systems supporting your essential function(s), in the context of your sector and wider national infrastructure.
- Your detailed understanding of threat includes the methods and techniques available to capable and well-resourced threat actors and how they could be used systematically against network and information systems supporting your essential function(s).
- You use appropriate techniques to develop an understanding of network and information systems supporting your essential function(s) from a threat actor’s perspective. You anticipate probable attack methods and techniques, targets and objectives, and develop plausible scenarios.
- You understand the different steps a capable and well-resourced threat actor would need to take to reach the probable target(s).
- You identify and justify what measures can be used at each step to reduce the likelihood of the threat actor reaching the probable target(s) or achieving their objective(s).
- You maintain a detailed understanding of current threats (e.g. by threat intelligence and proactive research).
- You apply your detailed understanding of threat to inform your risk management decision-making.
- You have documented the steps required to undertake detailed threat analysis.
A2.c Assurance
- You have gained confidence in the effectiveness of the security of your technology, people, and processes relevant to the operation of network and information systems supporting your essential function(s).
- You have gained confidence in the effectiveness of the security of your technology, people, and processes relevant to the operation of network and information systems supporting your essential function(s).
- A particular product or service is seen as a "silver bullet" and vendor claims are taken at face value.
- Assurance methods are applied without appreciation of their strengths and limitations, such as the risks of penetration testing in operational environments.
- Assurance is assumed because there have been no known problems to date.
- You validate that the security measures in place to protect the network and information systems are effective and remain effective for the lifetime over which they are needed.
- You understand the assurance methods available to you and choose appropriate methods to gain confidence in the security of essential function(s).
- Your confidence in the security as it relates to your technology, people, and processes can be justified to, and verified by, a third party.
- Security deficiencies uncovered by assurance activities are assessed, prioritised and remedied when necessary in a timely and effective way.
- The methods used for assurance are reviewed to ensure they are working as intended and remain the most appropriate method to use.
Not achieved - At least one of the following statements is true:
- A particular product or service is seen as a "silver bullet" and vendor claims are taken at face value.
- Assurance methods are applied without appreciation of their strengths and limitations, such as the risks of penetration testing in operational environments.
- Assurance is assumed because there have been no known problems to date.
Achieved - All the following statements are true:
- You validate that the security measures in place to protect the network and information systems are effective and remain effective for the lifetime over which they are needed.
- You understand the assurance methods available to you and choose appropriate methods to gain confidence in the security of essential function(s).
- Your confidence in the security as it relates to your technology, people, and processes can be justified to, and verified by, a third party.
- Security deficiencies uncovered by assurance activities are assessed, prioritised and remedied when necessary in a timely and effective way.
- The methods used for assurance are reviewed to ensure they are working as intended and remain the most appropriate method to use.
Everything required to deliver, maintain or support networks and information systems necessary for the operation of essential functions is determined and understood. This includes data, people and systems, as well as any supporting infrastructure (such as power or cooling).
Description
error determining description
Guidance
Whichever risk management method your organisation uses, asset management will play a key role as you cannot effectively manage risks without understanding what assets are part of the essential function. Your asset management regime should consider all relevant assets, and dependencies between them. Dependencies may be identified between assets under your organisation's control (including IT and OT domains), elements of the supply chain (including power), and key staff who are critical to operations. Assets in an operational technology environment may need a more tailored approach than the corporate IT assets.
For asset management to be effective, up to date knowledge of your assets must be maintained throughout their lifecycle.
Asset management is part of an ISO 27001 Information Security Management System (ISMS), but management of critical assets may require a tailored approach.
If your organisation is using an ISMS as a tool for compliance with cyber regulation, you must ensure the scope includes all systems relevant to the operation of the essential function covered by the regulation. Asset management is a key part of an ISMS, although critical services may need more attention than the minimum requirements of the standard.
This standard aligns with ISO 27001 and can be used in conjunction with it or independent of it. It outlines requirements for a generic asset management system. An organisation following this standard as a tool for compliance with cyber regulation must ensure the scope encompasses all the relevant systems. The standard covers needs and expectations of stakeholders, which must include any requirements from regulators.
ITIL is an IT service management framework that outlines best practices for delivering IT services. It recommends a staged approach to IT Asset Management (ITAM). You may find this useful for improving management of your IT assets, but must keep in mind that there may be assets and dependencies beyond the corporate IT domain as outlined above.
Asset management is part of an ISO 27001 Information Security Management System (ISMS), but management of critical assets may require a tailored approach.
If your organisation is using an ISMS as a tool for compliance with cyber regulation, you must ensure the scope includes all systems relevant to the operation of the essential function covered by the regulation. Asset management is a key part of an ISMS, although critical services may need more attention than the minimum requirements of the standard.
Contributing Outcomes
A3.a Asset Management
- Inventories of assets relevant to the essential function(s) are incomplete, non-existent, or inadequately detailed.
- Only certain domains or types of asset are documented and understood. Dependencies between assets are not understood (such as the dependencies between IT and OT).
- Information assets, which could include personally identifiable information and / or important / critical data, are stored for long periods of time with no clear business need or retention policy.
- Knowledge critical to the management, operation, or recovery of the essential function(s) is held by one or two key individuals with no succession plan.
- Asset inventories are neglected and out of date.
- All assets relevant to the secure operation of essential function(s) are identified and inventoried (at a suitable level of detail). The inventory is kept up-to-date.
- Dependencies on supporting infrastructure (e.g. power, cooling etc) are recognised and recorded.
- You have prioritised your assets according to their importance to the operation of the essential function(s).
- You have assigned responsibility for managing all assets, including physical assets, relevant to the operation of the essential function(s).
- Assets relevant to the essential function(s) are managed with cyber security in mind throughout their lifecycle, from creation through to eventual decommissioning or disposal.
Not achieved - At least one of the following statements is true:
- Inventories of assets relevant to the essential function(s) are incomplete, non-existent, or inadequately detailed.
- Only certain domains or types of asset are documented and understood. Dependencies between assets are not understood (such as the dependencies between IT and OT).
- Information assets, which could include personally identifiable information and / or important / critical data, are stored for long periods of time with no clear business need or retention policy.
- Knowledge critical to the management, operation, or recovery of the essential function(s) is held by one or two key individuals with no succession plan.
- Asset inventories are neglected and out of date.
Achieved - All the following statements are true:
- All assets relevant to the secure operation of essential function(s) are identified and inventoried (at a suitable level of detail). The inventory is kept up-to-date.
- Dependencies on supporting infrastructure (e.g. power, cooling etc) are recognised and recorded.
- You have prioritised your assets according to their importance to the operation of the essential function(s).
- You have assigned responsibility for managing all assets, including physical assets, relevant to the operation of the essential function(s).
- Assets relevant to the essential function(s) are managed with cyber security in mind throughout their lifecycle, from creation through to eventual decommissioning or disposal.
The organisation understands and manages security risks to networks and information systems supporting the operation of essential functions that arise as a result of dependencies on suppliers. This includes ensuring that appropriate measures are employed where third party services are used.
Description
error determining description
Guidance
Organisations responsible for essential functions need to ensure that when third party suppliers are used, all relevant security requirements are met. This means that a number of specific supply chain related security considerations should be addressed where relevant to the provision of the essential function. This might include:
Ensuring the protection of data shared with a third party. This includes protecting data from actions such as unauthorised access, modification, or deletion that may cause an adverse impact on any essential functions (see
Principle B3
).
Effective specification of the security properties of products or services procured from an external third party, or sourced internally from another part of the organisation, that are important for the protection of the essential function. This should include the security requirements derived from the rest of these Principles.
Ensure that any network connections or data sharing with third parties do not introduce unmanaged vulnerabilities that have the potential to affect the security of the essential function.
Confidence that third party suppliers are trustworthy such that malicious attempts to subvert the security of products or systems that could affect the essential function are managed.
Ensuring the protection of data shared with a third party. This includes protecting data from actions such as unauthorised access, modification, or deletion that may cause an adverse impact on any essential functions (see
Principle B3
).
Contributing Outcomes
A4.a Supply Chain
- You understand and effectively manage the risks associated with suppliers to the security of network and information systems supporting the operation of your essential function(s).
- You understand and effectively manage the risks associated with suppliers to the security of network and information systems supporting the operation of your essential function(s).
- You do not know what data belonging to you is held by suppliers, or how it is managed.
- Elements of the supply chain for essential function(s) are subcontracted and you have little or no visibility of the sub-contractors.
- You have no understanding of which contracts are relevant and / or relevant contracts do not specify appropriate security obligations.
- Suppliers have access to systems that provide your essential function(s) that is unrestricted, not monitored or bypasses your own security controls.
- You understand the general risks suppliers may pose to your essential function(s).
- You know the extent of your supply chain that supports your essential function(s), including sub-contractors.
- Suppliers to network and information systems that support your essential function(s) can demonstrate appropriate and proportionate levels of cyber security within the context of common threats.
- You understand which contracts are relevant and you include appropriate security obligations in relevant contracts.
- You are aware of all third-party connections and have assurance that they meet your organisation’s security requirements.
- Your approach to security incident management considers incidents that might arise in your supply chain.
- You have confidence that information shared with suppliers that is necessary for the operation of your essential function(s) is appropriately protected from common threats.
- You have a deep understanding of your supply chain, including sub-contractors and the wider risks it faces.
- You consider factors such as your supplier’s ownership, nationality, partnerships, competitors, other organisations with which they sub-contract and their approach to cyber security. These factors inform your risk assessment and are fully considered in your procurement lifecycle processes and purchasing decisions.
- Your approach to supply chain risk management considers the risks to network and information systems supporting your essential function(s) arising from supply chain subversion by capable and well-resourced threat actors.
- Critical suppliers to network and information systems supporting your essential functions(s) can demonstrate appropriate and proportionate levels of cyber security within the context of capable and well-resourced threat actors.
- You have confidence that information held by suppliers that is essential to the operation of network and information systems supporting your essential function(s) is appropriately protected from capable and well-resourced threat actors.
- You understand which contracts are relevant and you include appropriate security obligations, in relevant contracts.
- You have a proactive approach to contract management which may include a contract management plan for relevant contracts.
- Customer / supplier ownership of responsibilities is defined in contracts.
- All network connections and data sharing with third parties are managed effectively and proportionately.
- When appropriate, your incident management process and that of your suppliers provide mutual support in the resolution of incidents.
Not achieved - At least one of the following statements is true:
- You do not know what data belonging to you is held by suppliers, or how it is managed.
- Elements of the supply chain for essential function(s) are subcontracted and you have little or no visibility of the sub-contractors.
- You have no understanding of which contracts are relevant and / or relevant contracts do not specify appropriate security obligations.
- Suppliers have access to systems that provide your essential function(s) that is unrestricted, not monitored or bypasses your own security controls.
Partially achieved - All the following statements are true:
- You understand the general risks suppliers may pose to your essential function(s).
- You know the extent of your supply chain that supports your essential function(s), including sub-contractors.
- Suppliers to network and information systems that support your essential function(s) can demonstrate appropriate and proportionate levels of cyber security within the context of common threats.
- You understand which contracts are relevant and you include appropriate security obligations in relevant contracts.
- You are aware of all third-party connections and have assurance that they meet your organisation’s security requirements.
- Your approach to security incident management considers incidents that might arise in your supply chain.
- You have confidence that information shared with suppliers that is necessary for the operation of your essential function(s) is appropriately protected from common threats.
Achieved - All the following statements are true:
- You have a deep understanding of your supply chain, including sub-contractors and the wider risks it faces.
- You consider factors such as your supplier’s ownership, nationality, partnerships, competitors, other organisations with which they sub-contract and their approach to cyber security. These factors inform your risk assessment and are fully considered in your procurement lifecycle processes and purchasing decisions.
- Your approach to supply chain risk management considers the risks to network and information systems supporting your essential function(s) arising from supply chain subversion by capable and well-resourced threat actors.
- Critical suppliers to network and information systems supporting your essential functions(s) can demonstrate appropriate and proportionate levels of cyber security within the context of capable and well-resourced threat actors.
- You have confidence that information held by suppliers that is essential to the operation of network and information systems supporting your essential function(s) is appropriately protected from capable and well-resourced threat actors.
- You understand which contracts are relevant and you include appropriate security obligations, in relevant contracts.
- You have a proactive approach to contract management which may include a contract management plan for relevant contracts.
- Customer / supplier ownership of responsibilities is defined in contracts.
- All network connections and data sharing with third parties are managed effectively and proportionately.
- When appropriate, your incident management process and that of your suppliers provide mutual support in the resolution of incidents.
A4.b Secure Software Development and Support
- You actively maximise the use of secure and supported software, whether developed internally or sourced externally, within network and information systems supporting the operation of your essential function(s).
- You actively maximise the use of secure and supported software, whether developed internally or sourced externally, within network and information systems supporting the operation of your essential function(s).
- Your software supplier(s) is unaware of the composition and provenance of software provided to you.
- Software, including updates and patches, undergoes little to no testing.
- Updates and patches often introduce new problems or fail to address existing issues.
- Vulnerabilities are discovered in software despite the negligible difficulty of implementing mitigations.
- Your software supplier leverages secure development principles and practices.
- Your software supplier(s) can demonstrate a limited understanding of the composition and provenance of software provided to you.
- You consider the security of environments (e.g. development, test and production), including source code and repositories, used in the production of software to be appropriate and proportionate within the context of common threats.
- The testing regime uses a range of different approaches (e.g. static and dynamic analysis, unit and integration testing and point in time assessments) that verify all aspects of the development lifecycle covering both functional and non-functional testing.
- You have arrangements in place with your software supplier to receive timely security updates, patches and notifications.
- Software, including updates and patches, is obtained from your supplier(s) via secure channels.
- Your software supplier(s) has processes in place to identify, report and mitigate security vulnerabilities.
- You have arrangements in place with your software supplier to be notified of any significant events that may adversely impact network and information systems supporting your essential function(s).
- If open-source software is used, you have taken appropriate and proportionate steps to establish and maintain sufficient confidence in its security for its use.
- You have appropriate support and maintenance arrangements in place.
- Your software supplier(s) leverages an established secure software development framework (e.g. NIST Secure Software Development Framework (SSDF), Microsoft Secure Development Lifecycle (SDL)).
- Your software supplier can demonstrate a thorough understanding of the composition and provenance of software provided to you, including any third-party components used in the development of that software, and those components are being monitored for new vulnerabilities throughout the lifespan of the product.
- You consider the security of environments (e.g. development, test, and production), including source code and repositories, used in the production of software to be appropriate and proportionate within the context of capable and well-resourced threat actors.
- The software development lifecycle is informed by a detailed and up to date understanding of threat and applies appropriate techniques, such as threat modelling, to identify and assess potential vulnerabilities and attack vectors.
- You can attest to the authenticity and integrity of software, including updates and patches.
Not achieved - At least one of the following statements is true:
- Your software supplier(s) is unaware of the composition and provenance of software provided to you.
- Software, including updates and patches, undergoes little to no testing.
- Updates and patches often introduce new problems or fail to address existing issues.
- Vulnerabilities are discovered in software despite the negligible difficulty of implementing mitigations.
Partially achieved - All the following statements are true:
- Your software supplier leverages secure development principles and practices.
- Your software supplier(s) can demonstrate a limited understanding of the composition and provenance of software provided to you.
- You consider the security of environments (e.g. development, test and production), including source code and repositories, used in the production of software to be appropriate and proportionate within the context of common threats.
- The testing regime uses a range of different approaches (e.g. static and dynamic analysis, unit and integration testing and point in time assessments) that verify all aspects of the development lifecycle covering both functional and non-functional testing.
- You have arrangements in place with your software supplier to receive timely security updates, patches and notifications.
- Software, including updates and patches, is obtained from your supplier(s) via secure channels.
- Your software supplier(s) has processes in place to identify, report and mitigate security vulnerabilities.
- You have arrangements in place with your software supplier to be notified of any significant events that may adversely impact network and information systems supporting your essential function(s).
- If open-source software is used, you have taken appropriate and proportionate steps to establish and maintain sufficient confidence in its security for its use.
- You have appropriate support and maintenance arrangements in place.
Achieved - All the following statements are true:
- Your software supplier(s) leverages an established secure software development framework (e.g. NIST Secure Software Development Framework (SSDF), Microsoft Secure Development Lifecycle (SDL)).
- Your software supplier can demonstrate a thorough understanding of the composition and provenance of software provided to you, including any third-party components used in the development of that software, and those components are being monitored for new vulnerabilities throughout the lifespan of the product.
- You consider the security of environments (e.g. development, test, and production), including source code and repositories, used in the production of software to be appropriate and proportionate within the context of capable and well-resourced threat actors.
- The software development lifecycle is informed by a detailed and up to date understanding of threat and applies appropriate techniques, such as threat modelling, to identify and assess potential vulnerabilities and attack vectors.
- You can attest to the authenticity and integrity of software, including updates and patches.
The organisation defines, implements, communicates and enforces appropriate policies, processes and procedures that direct its overall approach to securing systems and data that support the operation of essential functions.
Description
error determining description
Guidance
The policies, processes and procedures needed by an organisation depend upon its function and should integrate with the organisation’s approach to governance and risk management. Organisations responsible for essential functions should have a range of policies, processes and procedures, including:
An organisational security or service protection policy: endorsed by senior management, this high-level policy should include the organisation’s overarching approach to governing security and managing risks, the organisation’s aims and intents for security and what is of key concern.
Supporting policies, processes and procedures: contextual lower-level definitions controlling, directing and communicating organisational security practice.
Compliance policies and processes for sector regulations, standards, etc.: specific policies and processes appropriate to the compliance regime; these may be defined by the regulation, standard, etc. For example, to comply with ISO/IEC 27001, organisations should have in place certain security policies and procedures relevant to what the organisation does, how it does it, and what their ISO/IEC 27001 information security management system covers (see ISO/IEC 27002 for detail).
An organisational security or service protection policy: endorsed by senior management, this high-level policy should include the organisation’s overarching approach to governing security and managing risks, the organisation’s aims and intents for security and what is of key concern.
Contributing Outcomes
B1.a Policy, Process and Procedure Development
- You have developed and continue to improve a set of cyber security and resilience policies, processes and procedures that manage and mitigate the risk of adverse impact on your essential function(s).
- You have developed and continue to improve a set of cyber security and resilience policies, processes and procedures that manage and mitigate the risk of adverse impact on your essential function(s).
- Your policies, processes and procedures are absent or incomplete.
- Policies, processes and procedures are not applied universally or consistently.
- People often or routinely circumvent policies, processes and procedures to achieve business objectives.
- Your organisation’s security governance and risk management approach has no bearing on your policies, processes and procedures.
- System security is totally reliant on users' careful and consistent application of manual security processes.
- Policies, processes and procedures have not been reviewed in response to major changes (e.g. technology or regulatory framework), or within a suitable period.
- Policies, processes and procedures are not readily available to staff, too detailed to remember, or too hard to understand.
- Your policies, processes and procedures document your overarching security governance and risk management approach, technical security practice and specific regulatory compliance.
- You review and update policies, processes and procedures in response to major cyber security incidents.
- You fully document your overarching security governance and risk management approach, technical security practice and specific regulatory compliance.
- Cyber security is integrated and embedded throughout policies, processes and procedures and key performance indicators are reported to your executive management.
- Your organisation’s policies, processes and procedures are developed to be practical, usable and appropriate to mitigate the risk of adverse impact to network and information systems supporting your essential function(s).
- Policies, processes and procedures that rely on user behaviour are practical, appropriate and achievable.
- You review and update policies, processes and procedures at suitably regular intervals to ensure they remain relevant. This is in addition to reviews following a major cyber security incident.
- Any changes to the essential function(s) or the threat it faces triggers a review of policies, processes and procedures.
- Your systems are designed so that they remain secure even when user security policies, processes and procedures are not always followed.
Not achieved - At least one of the following statements is true:
- Your policies, processes and procedures are absent or incomplete.
- Policies, processes and procedures are not applied universally or consistently.
- People often or routinely circumvent policies, processes and procedures to achieve business objectives.
- Your organisation’s security governance and risk management approach has no bearing on your policies, processes and procedures.
- System security is totally reliant on users' careful and consistent application of manual security processes.
- Policies, processes and procedures have not been reviewed in response to major changes (e.g. technology or regulatory framework), or within a suitable period.
- Policies, processes and procedures are not readily available to staff, too detailed to remember, or too hard to understand.
Partially achieved - All the following statements are true:
- Your policies, processes and procedures document your overarching security governance and risk management approach, technical security practice and specific regulatory compliance.
- You review and update policies, processes and procedures in response to major cyber security incidents.
Achieved - All the following statements are true:
- You fully document your overarching security governance and risk management approach, technical security practice and specific regulatory compliance.
- Cyber security is integrated and embedded throughout policies, processes and procedures and key performance indicators are reported to your executive management.
- Your organisation’s policies, processes and procedures are developed to be practical, usable and appropriate to mitigate the risk of adverse impact to network and information systems supporting your essential function(s).
- Policies, processes and procedures that rely on user behaviour are practical, appropriate and achievable.
- You review and update policies, processes and procedures at suitably regular intervals to ensure they remain relevant. This is in addition to reviews following a major cyber security incident.
- Any changes to the essential function(s) or the threat it faces triggers a review of policies, processes and procedures.
- Your systems are designed so that they remain secure even when user security policies, processes and procedures are not always followed.
B1.b Policy, Process and Procedure Implementation
- You have successfully implemented your security policies, processes and procedures and can demonstrate the security benefits achieved.
- You have successfully implemented your security policies, processes and procedures and can demonstrate the security benefits achieved.
- Policies, processes and procedures are ignored or only partially followed.
- How your policies support the resilience of your essential function(s) is not well understood.
- Staff are unaware of their responsibilities under your policies, processes and procedures.
- You do not attempt to detect breaches of policies, processes and procedures.
- Policies, processes and procedures lack integration with other organisational policies, processes and procedures.
- Your policies, processes and procedures are not well communicated across your organisation.
- Most of your policies, processes and procedures are followed and their application is monitored.
- Your policies, processes and procedures are integrated with other organisational policies, processes and procedures, including HR assessments of individuals' trustworthiness.
- All staff are aware of their responsibilities under your policies, processes and procedures.
- All breaches of policies, processes and procedures with the potential to adversely impact the essential function(s) are fully investigated. Other breaches are tracked, assessed for trends and action is taken to understand and address.
- All your policies, processes and procedures are followed, their correct application and security effectiveness is evaluated.
- Your policies, processes and procedures are integrated with other organisational policies, processes and procedures, including HR assessments of individuals' trustworthiness.
- Your policies, processes and procedures are effectively and appropriately communicated across all levels of the organisation resulting in good staff awareness of their responsibilities.
- Appropriate action is taken to address all breaches of policies, processes and procedures with potential to adversely impact the essential function(s) including aggregated breaches.
Not achieved - At least one of the following statements is true:
- Policies, processes and procedures are ignored or only partially followed.
- How your policies support the resilience of your essential function(s) is not well understood.
- Staff are unaware of their responsibilities under your policies, processes and procedures.
- You do not attempt to detect breaches of policies, processes and procedures.
- Policies, processes and procedures lack integration with other organisational policies, processes and procedures.
- Your policies, processes and procedures are not well communicated across your organisation.
Partially achieved - All the following statements are true:
- Most of your policies, processes and procedures are followed and their application is monitored.
- Your policies, processes and procedures are integrated with other organisational policies, processes and procedures, including HR assessments of individuals' trustworthiness.
- All staff are aware of their responsibilities under your policies, processes and procedures.
- All breaches of policies, processes and procedures with the potential to adversely impact the essential function(s) are fully investigated. Other breaches are tracked, assessed for trends and action is taken to understand and address.
Achieved - All the following statements are true:
- All your policies, processes and procedures are followed, their correct application and security effectiveness is evaluated.
- Your policies, processes and procedures are integrated with other organisational policies, processes and procedures, including HR assessments of individuals' trustworthiness.
- Your policies, processes and procedures are effectively and appropriately communicated across all levels of the organisation resulting in good staff awareness of their responsibilities.
- Appropriate action is taken to address all breaches of policies, processes and procedures with potential to adversely impact the essential function(s) including aggregated breaches.
The organisation understands, documents and manages access to networks and information systems and supporting the operation of essential functions. Users (or automated functions) that can access data or services are appropriately verified, authenticated and authorised.
Description
It is important that the organisation is clear about who (or what in the case of automated functions) has authorisation to interact with the network and information systems supporting an essential function in any way or access associated sensitive data. Access rights granted should be carefully controlled, especially where those rights provide an ability to materially affect the operation of the essential function. Access rights granted should be periodically reviewed and technically removed when no longer required such as when an individual changes role or leaves the organisation.
Users, devices and systems should be appropriately verified, authenticated and authorised before access to data or services is granted. Verification of a user’s identity (they are who they say they are) is a prerequisite for issuing credentials, authentication and access management. For highly privileged access it might be appropriate to include approaches such as multi-factor or hardware authentication.
Unauthorised individuals should be prevented from accessing data or services at all points within the system. This includes system users without the appropriate permissions, unauthorised individuals attempting to interact with any online service or individuals with unauthorised access to user devices (for example if a user device were lost or stolen).
Guidance
The
Introduction to identity and access management
sets out security fundamentals that operators should consider in designing and managing identity and access management systems. Identity and access control should be robust enough that essential functions are not adversely affected by unauthorised access.
In addition to technical security, organisations should protect physical access to networks and information systems supporting the essential function, to prevent unauthorised access, tampering or data deletion. Some organisations may already have physical security measures in place to comply with non-cyber regulatory frameworks. See
NPSA guidance on Control Access
for further information.
Contributing Outcomes
B2.a Identity Verification, Authentication and Authorisation
- You robustly verify, authenticate and authorise access to the network and information systems supporting your essential function(s).
- You robustly verify, authenticate and authorise access to the network and information systems supporting your essential function(s).
- Initial identity verification is not robust enough to provide an acceptable level of confidence of a user’s identity profile.
- Authorised users and systems with access to networks or information systems on which your essential function(s) depends cannot be individually identified.
- Unauthorised individuals or devices can access your network or information systems on which your essential function(s) depends.
- The number of authorised users and systems that have access to your network and information systems are not limited to the minimum necessary.
- Your approach to authenticating users, devices and systems does not follow up to date best practice.
- Your process of initial identity verification is robust enough to provide a reasonable level of confidence of a user’s identity profile before allowing an authorised user access to network and information systems that support your essential function(s).
- All authorised users and systems with access to network or information systems on which your essential function(s) depends are individually identified and authenticated.
- The number of authorised users and systems that have access to essential function(s) network and information systems is limited to the minimum necessary.
- You use additional authentication mechanisms, such as multi-factor (MFA), for privileged access to all network and information systems that operate or support your essential function(s).
- You individually authenticate and authorise all remote access to all your network and information systems that support your essential function(s).
- The list of users and systems with access to network and information systems supporting and delivering the essential function(s) is reviewed on a regular basis, at least annually.
- Your approach to authenticating users, devices and systems follows up to date best practice.
- Your process of initial identity verification is robust enough to provide a high level of confidence of a user’s identity profile before allowing an authorised user access to network and information systems that support your essential function(s).
- Only authorised and individually authenticated users can physically access and logically connect to your network or information systems on which your essential function(s) depends.
- The number of authorised users and systems that have access to all your network and information systems supporting the essential function(s) is limited to the minimum necessary.
- You use additional authentication mechanisms, such as multi-factor (MFA), for all user access, including remote access, to all network and information systems that operate or support your essential function(s).
- The list of users and systems with access to network and information systems supporting and delivering the essential function(s) is reviewed on a regular basis, at least every six months.
- Your approach to authenticating users, devices and systems follows up to date best practice.
Not achieved - At least one of the following statements is true:
- Initial identity verification is not robust enough to provide an acceptable level of confidence of a user’s identity profile.
- Authorised users and systems with access to networks or information systems on which your essential function(s) depends cannot be individually identified.
- Unauthorised individuals or devices can access your network or information systems on which your essential function(s) depends.
- The number of authorised users and systems that have access to your network and information systems are not limited to the minimum necessary.
- Your approach to authenticating users, devices and systems does not follow up to date best practice.
Partially achieved - All the following statements are true:
- Your process of initial identity verification is robust enough to provide a reasonable level of confidence of a user’s identity profile before allowing an authorised user access to network and information systems that support your essential function(s).
- All authorised users and systems with access to network or information systems on which your essential function(s) depends are individually identified and authenticated.
- The number of authorised users and systems that have access to essential function(s) network and information systems is limited to the minimum necessary.
- You use additional authentication mechanisms, such as multi-factor (MFA), for privileged access to all network and information systems that operate or support your essential function(s).
- You individually authenticate and authorise all remote access to all your network and information systems that support your essential function(s).
- The list of users and systems with access to network and information systems supporting and delivering the essential function(s) is reviewed on a regular basis, at least annually.
- Your approach to authenticating users, devices and systems follows up to date best practice.
Achieved - All the following statements are true:
- Your process of initial identity verification is robust enough to provide a high level of confidence of a user’s identity profile before allowing an authorised user access to network and information systems that support your essential function(s).
- Only authorised and individually authenticated users can physically access and logically connect to your network or information systems on which your essential function(s) depends.
- The number of authorised users and systems that have access to all your network and information systems supporting the essential function(s) is limited to the minimum necessary.
- You use additional authentication mechanisms, such as multi-factor (MFA), for all user access, including remote access, to all network and information systems that operate or support your essential function(s).
- The list of users and systems with access to network and information systems supporting and delivering the essential function(s) is reviewed on a regular basis, at least every six months.
- Your approach to authenticating users, devices and systems follows up to date best practice.
B2.b Device Management
- You fully know and have trust in the devices that are used to access your networks, information systems and data that support your essential function(s).
- You fully know and have trust in the devices that are used to access your networks, information systems and data that support your essential function(s).
- Users can connect to your essential function(s)'s network and information systems using devices that are not corporately owned and managed.
- Privileged users can perform privileged operations from devices that are not corporately owned and managed.
- You have not gained assurance in the security of any third-party devices or networks connected to your systems.
- Physically connecting a device to your network and information systems gives that device access without device or user authentication.
- Only corporately owned and managed devices can access your essential function(s)'s network and information systems.
- All privileged operations are performed from corporately owned and managed devices. These devices provide sufficient separation, using a risk-based approach, from the activities of standard users.
- You have sought to understand the security properties of third-party devices and networks before they can be connected to your systems. You have taken appropriate steps to mitigate any risks identified.
- The act of connecting to a network port or cable does not grant access to any systems.
- You are able to detect unknown devices being connected to your network and information systems and investigate such incidents.
- All privileged operations performed on your network and information systems supporting your essential function(s) are conducted from highly trusted devices, such as Privileged Access Workstations, dedicated solely to those operations.
- You either obtain independent and professional assurance of the security of third-party devices or networks before they connect to your network and information systems, or you only allow third-party devices or networks that are dedicated to supporting your network and information systems to connect.
- You perform certificate-based device identity management and only allow known devices to access systems necessary for the operation of your essential function(s).
- You perform regular scans to detect unknown devices and investigate any findings.
Not achieved - At least one of the following statements is true:
- Users can connect to your essential function(s)'s network and information systems using devices that are not corporately owned and managed.
- Privileged users can perform privileged operations from devices that are not corporately owned and managed.
- You have not gained assurance in the security of any third-party devices or networks connected to your systems.
- Physically connecting a device to your network and information systems gives that device access without device or user authentication.
Partially achieved - All the following statements are true:
- Only corporately owned and managed devices can access your essential function(s)'s network and information systems.
- All privileged operations are performed from corporately owned and managed devices. These devices provide sufficient separation, using a risk-based approach, from the activities of standard users.
- You have sought to understand the security properties of third-party devices and networks before they can be connected to your systems. You have taken appropriate steps to mitigate any risks identified.
- The act of connecting to a network port or cable does not grant access to any systems.
- You are able to detect unknown devices being connected to your network and information systems and investigate such incidents.
Achieved - All the following statements are true:
- All privileged operations performed on your network and information systems supporting your essential function(s) are conducted from highly trusted devices, such as Privileged Access Workstations, dedicated solely to those operations.
- You either obtain independent and professional assurance of the security of third-party devices or networks before they connect to your network and information systems, or you only allow third-party devices or networks that are dedicated to supporting your network and information systems to connect.
- You perform certificate-based device identity management and only allow known devices to access systems necessary for the operation of your essential function(s).
- You perform regular scans to detect unknown devices and investigate any findings.
B2.c Privileged User Management
- You closely manage privileged user access to network and information systems supporting the essential function(s).
- You closely manage privileged user access to network and information systems supporting the essential function(s).
- The identities of the individuals with privileged access to your essential function(s) network and information systems (infrastructure, platforms, software, configuration, etc) are not known or not managed.
- Privileged user access to your essential function(s) network and information systems is via weak authentication mechanisms (e.g. only simple passwords).
- The list of privileged users has not been reviewed recently (e.g. within the last 12 months).
- Privileged user access is granted on a system-wide basis rather than by role or function(s).
- Privileged user access to your essential function(s) is via generic, shared or default name accounts.
- Where there are “always on” terminals which can perform privileged actions (such as in a control room), there are no additional controls (e.g. physical controls) to ensure access is appropriately restricted.
- There is no logical separation between roles that an individual may have and hence the actions they perform. (e.g. access to corporate email and privilege user actions).
- All privileged user access to your network and information systems requires strong authentication, such as multi-factor (MFA).
- The identities of the individuals with privileged access to your essential function(s) network and information systems (infrastructure, platforms, software, configuration, etc) are known and managed. This includes third parties.
- Activity by privileged users is routinely reviewed and validated. (e.g. at least annually).
- Privileged users are only granted specific privileged user access rights which are essential to their business role or function.
- Privileged user access to your essential function(s) systems is carried out from dedicated separate accounts that are closely monitored and managed.
- The issuing of temporary, time-bound rights for privileged user access and / or external third-party support access is in place.
- Privileged user access rights are regularly reviewed and always updated as part of your joiners, movers and leavers process.
- All privileged user activity is routinely reviewed, validated and recorded for offline analysis and investigation.
Not achieved - At least one of the following statements is true:
- The identities of the individuals with privileged access to your essential function(s) network and information systems (infrastructure, platforms, software, configuration, etc) are not known or not managed.
- Privileged user access to your essential function(s) network and information systems is via weak authentication mechanisms (e.g. only simple passwords).
- The list of privileged users has not been reviewed recently (e.g. within the last 12 months).
- Privileged user access is granted on a system-wide basis rather than by role or function(s).
- Privileged user access to your essential function(s) is via generic, shared or default name accounts.
- Where there are “always on” terminals which can perform privileged actions (such as in a control room), there are no additional controls (e.g. physical controls) to ensure access is appropriately restricted.
- There is no logical separation between roles that an individual may have and hence the actions they perform. (e.g. access to corporate email and privilege user actions).
Partially achieved - All of the following statements are true:
- All privileged user access to your network and information systems requires strong authentication, such as multi-factor (MFA).
- The identities of the individuals with privileged access to your essential function(s) network and information systems (infrastructure, platforms, software, configuration, etc) are known and managed. This includes third parties.
- Activity by privileged users is routinely reviewed and validated. (e.g. at least annually).
- Privileged users are only granted specific privileged user access rights which are essential to their business role or function.
Achieved - All of the following statements are true:
- Privileged user access to your essential function(s) systems is carried out from dedicated separate accounts that are closely monitored and managed.
- The issuing of temporary, time-bound rights for privileged user access and / or external third-party support access is in place.
- Privileged user access rights are regularly reviewed and always updated as part of your joiners, movers and leavers process.
- All privileged user activity is routinely reviewed, validated and recorded for offline analysis and investigation.
B2.d Identity and Access Management (IdAM)
- You closely manage and maintain identity and access control for users, devices and systems accessing the network and information systems supporting the essential function(s).
- You closely manage and maintain identity and access control for users, devices and systems accessing the network and information systems supporting the essential function(s).
- Greater access rights are granted than necessary.
- Identity validation and requirement for access of a user, device or systems is not carried out.
- User access rights are not reviewed when users change roles.
- User access rights remain active when users leave your organisation.
- Access rights granted to devices or systems to access other devices and systems are not reviewed on a regular basis (at least annually).
- You follow a robust procedure to verify each user and issue the minimum required access rights.
- You regularly review access rights and those no longer needed are revoked.
- User access rights are reviewed when users change roles via your joiners, leavers and movers process.
- All user, device and system access to the systems supporting the essential function(s) is logged and monitored, but it is not compared to other log data or access records.
- You follow a robust procedure to verify each user and issue the minimum required access rights, and the application of the procedure is regularly audited.
- User access rights are reviewed both when people change roles via your joiners, leavers and movers process and at regular intervals - at least annually.
- All user, device and systems access to the systems supporting the essential function(s) is logged and monitored.
- You regularly review access logs and correlate this data with other access records and expected activity.
- Attempts by unauthorised users, devices or systems to connect to the systems supporting the essential function(s) are alerted, promptly assessed and investigated.
Not achieved - At least one of the following statements is true:
- Greater access rights are granted than necessary.
- Identity validation and requirement for access of a user, device or systems is not carried out.
- User access rights are not reviewed when users change roles.
- User access rights remain active when users leave your organisation.
- Access rights granted to devices or systems to access other devices and systems are not reviewed on a regular basis (at least annually).
Partially achieved - All of the following statements are true:
- You follow a robust procedure to verify each user and issue the minimum required access rights.
- You regularly review access rights and those no longer needed are revoked.
- User access rights are reviewed when users change roles via your joiners, leavers and movers process.
- All user, device and system access to the systems supporting the essential function(s) is logged and monitored, but it is not compared to other log data or access records.
Achieved - All of the following statements are true:
- You follow a robust procedure to verify each user and issue the minimum required access rights, and the application of the procedure is regularly audited.
- User access rights are reviewed both when people change roles via your joiners, leavers and movers process and at regular intervals - at least annually.
- All user, device and systems access to the systems supporting the essential function(s) is logged and monitored.
- You regularly review access logs and correlate this data with other access records and expected activity.
- Attempts by unauthorised users, devices or systems to connect to the systems supporting the essential function(s) are alerted, promptly assessed and investigated.
Data stored or transmitted electronically is protected from actions such as unauthorised access, modification, or deletion that may cause an adverse impact on essential functions. Such protection extends to the means by which authorised users, devices and systems access critical data necessary for the operation of essential functions. It also covers information that would assist an attacker, such as design details of networks and information systems.
Description
error determining description
Guidance
Networks and information systems should be designed to protect important data, for example:
protecting the confidentiality of sensitive data by minimising the number of copies of data, the detail these include and by retaining operationally sensitive data on segregated systems (this includes design documentation)
removing functionality that could allow greater access than has been authorised
protecting the integrity of data essential to the operation of the function by providing a read-only copy for non-essential business system consumption
only deploying well-tested cryptographic suites in common use by your chosen software stack
protecting availability through
resilience
measures such as multiple network paths and tested automatic backup systems
consider suitable means to retain access to essential information in the event of an incident. For example, network diagrams needed for restoration, safety-critical information or essential forecasting data
protecting the confidentiality of sensitive data by minimising the number of copies of data, the detail these include and by retaining operationally sensitive data on segregated systems (this includes design documentation)
Contributing Outcomes
B3.a Understanding Data
- You have a good understanding of data important to the operation of network and information systems supporting your essential function(s), where it is stored, where it travels and how unavailability or unauthorised access, uncontrolled release, modification or deletion would adversely impact the essential function(s). This also applies to third parties storing or accessing data important to the operation of essential function(s).
- You have a good understanding of data important to the operation of network and information systems supporting your essential function(s), where it is stored, where it travels and how unavailability or unauthorised access, uncontrolled release, modification or deletion would adversely impact the essential function(s). This also applies to third parties storing or accessing data important to the operation of essential function(s).
- You have incomplete knowledge of what data is used by and produced in the operation of network and information systems supporting your essential function(s).
- You have not identified the important data on which network and information systems supporting your essential function(s) relies.
- You have not identified who has access to data important to the operation of network and information systems supporting your essential function(s).
- You have not clearly articulated the impact of data compromise or lack of availability.
- You have identified and catalogued all the data important to the operation of network and information systems supporting your essential function(s), or that would assist a threat actor.
- You have identified and catalogued who has access to the data important to the operation of network and information systems supporting your essential function(s).
- You regularly review location, transmission, quantity and quality of data important to the operation of network and information systems supporting your essential function(s).
- You have identified all mobile devices and media that hold data important to the operation of network and information systems supporting your essential function(s).
- You understand and document the impact on your essential function(s) of all relevant scenarios, including unauthorised data access, uncontrolled release, modification or deletion, or when authorised users are unable to appropriately access this data.
- You occasionally validate these documented impact statements.
- You have identified and catalogued all the data important to the operation of network and information systems supporting your essential function(s), or that would assist a threat actor.
- You have identified and catalogued who has access to the data important to the operation of network and information systems supporting your essential function(s).
- You maintain a current understanding of the location, quantity and quality of data important to the operation of network and information systems supporting your essential function(s).
- You take steps to remove or minimise unnecessary copies or unneeded historic data.
- You have identified all mobile devices and media that may hold data important to the operation of network and information systems supporting your essential function(s).
- You maintain a current understanding of the data links used to transmit data that is important to network and information systems supporting your essential function(s).
- You understand the context, limitations and dependencies of your important data.
- You understand and document the impact on your essential function(s) of all relevant scenarios, including unauthorised data access, uncontrolled release, modification or deletion, or when authorised users are unable to appropriately access this data.
- You validate these documented impact statements regularly, at least annually.
Not achieved - At least one of the following statements is true:
- You have incomplete knowledge of what data is used by and produced in the operation of network and information systems supporting your essential function(s).
- You have not identified the important data on which network and information systems supporting your essential function(s) relies.
- You have not identified who has access to data important to the operation of network and information systems supporting your essential function(s).
- You have not clearly articulated the impact of data compromise or lack of availability.
Partially achieved - All of the following statements are true:
- You have identified and catalogued all the data important to the operation of network and information systems supporting your essential function(s), or that would assist a threat actor.
- You have identified and catalogued who has access to the data important to the operation of network and information systems supporting your essential function(s).
- You regularly review location, transmission, quantity and quality of data important to the operation of network and information systems supporting your essential function(s).
- You have identified all mobile devices and media that hold data important to the operation of network and information systems supporting your essential function(s).
- You understand and document the impact on your essential function(s) of all relevant scenarios, including unauthorised data access, uncontrolled release, modification or deletion, or when authorised users are unable to appropriately access this data.
- You occasionally validate these documented impact statements.
Achieved - All of the following statements are true:
- You have identified and catalogued all the data important to the operation of network and information systems supporting your essential function(s), or that would assist a threat actor.
- You have identified and catalogued who has access to the data important to the operation of network and information systems supporting your essential function(s).
- You maintain a current understanding of the location, quantity and quality of data important to the operation of network and information systems supporting your essential function(s).
- You take steps to remove or minimise unnecessary copies or unneeded historic data.
- You have identified all mobile devices and media that may hold data important to the operation of network and information systems supporting your essential function(s).
- You maintain a current understanding of the data links used to transmit data that is important to network and information systems supporting your essential function(s).
- You understand the context, limitations and dependencies of your important data.
- You understand and document the impact on your essential function(s) of all relevant scenarios, including unauthorised data access, uncontrolled release, modification or deletion, or when authorised users are unable to appropriately access this data.
- You validate these documented impact statements regularly, at least annually.
B3.b Data in Transit
- You have protected the transit of data important to the operation of network and information systems supporting your essential function(s). This includes the transfer of data to third parties.
- You have protected the transit of data important to the operation of network and information systems supporting your essential function(s). This includes the transfer of data to third parties.
- You do not know what all your data links are, or which carry data important to the operation of the essential function(s).
- Data important to the operation of the essential function(s) travels without technical protection over non-trusted or openly accessible carriers.
- Critical data paths that could fail, be jammed, be overloaded, etc. have no alternative path.
- You have identified and protected (effectively and proportionately) all the data links that carry data important to the operation of your essential function(s).
- You apply appropriate technical means (e.g. cryptography) to protect data that travels over non-trusted or openly accessible carriers, but you have limited or no confidence in the robustness of the protection applied.
- You have identified and protected (effectively and proportionately) all the data links that carry data important to the operation of your essential function(s).
- You apply appropriate physical and/or technical means to protect data that travels over non-trusted or openly accessible carriers, with justified confidence in the robustness of the protection applied.
- Suitable alternative transmission paths are available where there is a significant risk of impact on the operation of the essential function(s) due to resource limitation (e.g. transmission equipment or function failure, or important data being blocked or jammed).
Not achieved - At least one of the following statements is true:
- You do not know what all your data links are, or which carry data important to the operation of the essential function(s).
- Data important to the operation of the essential function(s) travels without technical protection over non-trusted or openly accessible carriers.
- Critical data paths that could fail, be jammed, be overloaded, etc. have no alternative path.
Partially achieved - All the following statements are true:
- You have identified and protected (effectively and proportionately) all the data links that carry data important to the operation of your essential function(s).
- You apply appropriate technical means (e.g. cryptography) to protect data that travels over non-trusted or openly accessible carriers, but you have limited or no confidence in the robustness of the protection applied.
Achieved - All the following statements are true:
- You have identified and protected (effectively and proportionately) all the data links that carry data important to the operation of your essential function(s).
- You apply appropriate physical and/or technical means to protect data that travels over non-trusted or openly accessible carriers, with justified confidence in the robustness of the protection applied.
- Suitable alternative transmission paths are available where there is a significant risk of impact on the operation of the essential function(s) due to resource limitation (e.g. transmission equipment or function failure, or important data being blocked or jammed).
B3.c Stored Data
- You have protected stored soft and hard copy data important to the operation of network and information systems supporting your essential function(s).
- You have protected stored soft and hard copy data important to the operation of network and information systems supporting your essential function(s).
- You have no, or limited, knowledge of where data important to the operation of the essential function(s) is stored.
- You have not protected vulnerable stored data important to the operation of the essential function(s) in a suitable way.
- Backups are incomplete, untested, not adequately secured or could be inaccessible in a disaster recovery or business continuity situation.
- All copies of data important to the operation of your essential function(s) are necessary. Where this important data is transferred to less secure systems, the data is provided with limited detail and / or as a read-only copy.
- You have applied suitable physical and / or technical means to protect this important stored data from unauthorised access, modification or deletion.
- If cryptographic protections are used, you apply suitable technical and procedural means, but you have limited or no confidence in the robustness of the protection applied.
- You have suitable, secured backups of data to allow the operation of the essential function(s) to continue should the original data not be available. This may include off-line or segregated backups, or appropriate alternative forms such as paper copies.
- All copies of data important to the operation of your essential function(s) are necessary. Where this important data is transferred to less secure systems, the data is provided with limited detail and / or as a read-only copy.
- You have applied suitable physical and / or technical means to protect this important stored data from unauthorised access, modification or deletion.
- If cryptographic protections are used you apply suitable technical and procedural means, and you have justified confidence in the robustness of the protection applied.
- You have suitable, secured backups of data to allow the operation of the essential function(s) to continue should the original data not be available. This may include off-line or segregated backups, or appropriate alternative forms such as paper copies.
- Necessary historic or archive data is suitably secured in storage.
Not achieved - At least one of the following statements is true:
- You have no, or limited, knowledge of where data important to the operation of the essential function(s) is stored.
- You have not protected vulnerable stored data important to the operation of the essential function(s) in a suitable way.
- Backups are incomplete, untested, not adequately secured or could be inaccessible in a disaster recovery or business continuity situation.
Partially achieved - All of the following statements are true:
- All copies of data important to the operation of your essential function(s) are necessary. Where this important data is transferred to less secure systems, the data is provided with limited detail and / or as a read-only copy.
- You have applied suitable physical and / or technical means to protect this important stored data from unauthorised access, modification or deletion.
- If cryptographic protections are used, you apply suitable technical and procedural means, but you have limited or no confidence in the robustness of the protection applied.
- You have suitable, secured backups of data to allow the operation of the essential function(s) to continue should the original data not be available. This may include off-line or segregated backups, or appropriate alternative forms such as paper copies.
Achieved - All of the following statements are true:
- All copies of data important to the operation of your essential function(s) are necessary. Where this important data is transferred to less secure systems, the data is provided with limited detail and / or as a read-only copy.
- You have applied suitable physical and / or technical means to protect this important stored data from unauthorised access, modification or deletion.
- If cryptographic protections are used you apply suitable technical and procedural means, and you have justified confidence in the robustness of the protection applied.
- You have suitable, secured backups of data to allow the operation of the essential function(s) to continue should the original data not be available. This may include off-line or segregated backups, or appropriate alternative forms such as paper copies.
- Necessary historic or archive data is suitably secured in storage.
B3.d Mobile Data
- You have protected data important to the operation of network and information systems supporting your essential function(s) on mobile devices (e.g. smartphones, tablets and laptops).
- You have protected data important to the operation of network and information systems supporting your essential function(s) on mobile devices (e.g. smartphones, tablets and laptops).
- You don’t know which mobile devices may hold data important to the operation of the essential function(s).
- You allow data important to the operation of the essential function(s) to be stored on devices not managed by your organisation, or to at least equivalent standard.
- Data on mobile devices is not technically secured, or only some is secured.
- You know which mobile devices hold data important to the operation of the essential function(s).
- Data important to the operation of the essential function(s) is stored on mobile devices only when they have at least the security standard aligned to your overarching security policies.
- Data on mobile devices is technically secured.
- Mobile devices that hold data that is important to the operation of the essential function(s) are catalogued, are under your organisation's control and configured according to best practice for the platform, with appropriate technical and procedural policies in place.
- Your organisation can remotely wipe all mobile devices holding data important to the operation of the essential function(s).
- You have minimised this data on these mobile devices. Some data may be automatically deleted off mobile devices after a certain period.
Not achieved - At least one of the following statements is true:
- You don’t know which mobile devices may hold data important to the operation of the essential function(s).
- You allow data important to the operation of the essential function(s) to be stored on devices not managed by your organisation, or to at least equivalent standard.
- Data on mobile devices is not technically secured, or only some is secured.
Partially achieved - All of the following statements are true:
- You know which mobile devices hold data important to the operation of the essential function(s).
- Data important to the operation of the essential function(s) is stored on mobile devices only when they have at least the security standard aligned to your overarching security policies.
- Data on mobile devices is technically secured.
Achieved - All of the following statements are true:
- Mobile devices that hold data that is important to the operation of the essential function(s) are catalogued, are under your organisation's control and configured according to best practice for the platform, with appropriate technical and procedural policies in place.
- Your organisation can remotely wipe all mobile devices holding data important to the operation of the essential function(s).
- You have minimised this data on these mobile devices. Some data may be automatically deleted off mobile devices after a certain period.
B3.e Media/Equipment Sanitisation
- Before reuse and / or disposal you appropriately sanitise devices, equipment and removable media holding data important to the operation of network and information systems supporting your essential function(s).
- Before reuse and / or disposal you appropriately sanitise devices, equipment and removable media holding data important to the operation of network and information systems supporting your essential function(s).
- You catalogue and track all devices that contain data important to the operation of the essential function(s) (whether a specific storage device or one with integral storage).
- Data important to the operation of the essential function(s) is removed from all devices, equipment and removable media before reuse and / or disposal using an assured product or service.
Not achieved - At least one of the following statements is true:
Partially achieved - All of the following statements are true:
Achieved - All of the following statements are true:
- You catalogue and track all devices that contain data important to the operation of the essential function(s) (whether a specific storage device or one with integral storage).
- Data important to the operation of the essential function(s) is removed from all devices, equipment and removable media before reuse and / or disposal using an assured product or service.
Network and information systems and technology critical for the operation of essential functions are protected from cyber attack. An organisational understanding of risk to essential functions informs the use of robust and reliable protective security measures to effectively limit opportunities for threat actors to compromise networks and systems.
Description
error determining description
Guidance
The majority of cyber security incidents can be traced to
common cyber attack
vectors. The opportunity for successful attack can be minimised by managing the known vulnerabilities which these attacks exploit. Many opportunities for user error can be reduced by technical means.
Attempts to circumvent the measures described below should be detected by
security monitoring
. Together with
data security
and
resilience measures
, the impact of any attempts to circumvent security on the operation of the essential function should be limited.
Contributing Outcomes
B4.a Secure by Design
- You design security into the network and information systems that support the operation of the essential function(s). You minimise their attack surface and ensure that the operation of the essential function(s) should not be impacted by the exploitation of any single vulnerability.
- You design security into the network and information systems that support the operation of the essential function(s). You minimise their attack surface and ensure that the operation of the essential function(s) should not be impacted by the exploitation of any single vulnerability.
- Network and information systems supporting the operation of the essential function(s) are not appropriately segregated from other systems.
- Internet services, such as browsing and email are accessible from network and information systems supporting your essential function(s).
- Data flows between network and information systems supporting your essential function(s) and other systems are complex, making it hard to discriminate between legitimate and illegitimate / malicious traffic.
- Remote or third-party accesses circumvent some network controls to gain more direct access to network and information systems supporting the essential function(s).
- You employ appropriate expertise to design network and information systems supporting your essential function(s).
- You design strong boundary defences where your network and information systems interface with other organisations or the world at large.
- You design simple data flows between your network and information systems and any external interface to enable effective monitoring.
- You design to make network and information system recovery simple.
- All inputs to network and information systems are checked and validated at the network boundary where possible, or additional monitoring is in place for content-based attacks.
- You employ appropriate expertise to design network and information systems supporting your essential function(s).
- Network and information systems are segregated into appropriate security zones (e.g. systems supporting the essential function(s) are segregated in a highly trusted, more secure zone).
- The network and information systems supporting your essential function(s) are designed to have simple data flows between components to support effective security monitoring.
- The network and information systems supporting your essential function(s) are designed to be easy to recover.
- Content-based attacks are mitigated for all inputs to network and information systems that affect the essential function(s) (e.g. via transformation and inspection / sanitisation and validation).
- If automated decision-making technologies are in use, you design and apply appropriate restrictions to prevent actions that could have an adverse impact on network and information systems supporting your essential function(s).
Not achieved - At least one of the following statements is true:
- Network and information systems supporting the operation of the essential function(s) are not appropriately segregated from other systems.
- Internet services, such as browsing and email are accessible from network and information systems supporting your essential function(s).
- Data flows between network and information systems supporting your essential function(s) and other systems are complex, making it hard to discriminate between legitimate and illegitimate / malicious traffic.
- Remote or third-party accesses circumvent some network controls to gain more direct access to network and information systems supporting the essential function(s).
Partially achieved - All the following statements are true:
- You employ appropriate expertise to design network and information systems supporting your essential function(s).
- You design strong boundary defences where your network and information systems interface with other organisations or the world at large.
- You design simple data flows between your network and information systems and any external interface to enable effective monitoring.
- You design to make network and information system recovery simple.
- All inputs to network and information systems are checked and validated at the network boundary where possible, or additional monitoring is in place for content-based attacks.
Achieved - All the following statements are true:
- You employ appropriate expertise to design network and information systems supporting your essential function(s).
- Network and information systems are segregated into appropriate security zones (e.g. systems supporting the essential function(s) are segregated in a highly trusted, more secure zone).
- The network and information systems supporting your essential function(s) are designed to have simple data flows between components to support effective security monitoring.
- The network and information systems supporting your essential function(s) are designed to be easy to recover.
- Content-based attacks are mitigated for all inputs to network and information systems that affect the essential function(s) (e.g. via transformation and inspection / sanitisation and validation).
- If automated decision-making technologies are in use, you design and apply appropriate restrictions to prevent actions that could have an adverse impact on network and information systems supporting your essential function(s).
B4.b Secure Configuration
- You securely configure network and information systems that support the operation of your essential function(s).
- You securely configure network and information systems that support the operation of your essential function(s).
- You haven't identified the assets that need to be carefully configured to maintain the security of the essential function(s).
- Policies relating to the security of operating system builds or configuration are not applied consistently across your network and information systems relating to your essential function(s).
- Configuration details are not recorded or lack enough information to be able to rebuild the system or device.
- The recording of security changes or adjustments that affect your essential function(s) is lacking or inconsistent.
- Generic, shared, default name and built-in accounts have not been removed or disabled.
- Standard users are able to change settings that would adversely impact the security of network and information systems supporting your essential function(s).
- You have identified and documented the assets that need to be carefully configured to maintain the security of the essential function(s).
- Secure platform and device builds are used across the estate.
- Consistent, secure and minimal system and device configurations are applied across the same types of environment.
- Changes and adjustments to security configuration at security boundaries with the network and information systems supporting your essential function(s) are approved and documented.
- You verify software before installation is permitted.
- Generic, shared, default name and built-in accounts have been removed or disabled. Where this is not possible, credentials to these accounts have been changed. Service accounts are appropriately protected.
- Standard users are not able to change settings that would adversely impact the security of network and information systems supporting your essential function(s).
- You have identified, documented and actively manage (e.g. maintain security configurations, patching, updating according to good practice) the assets that need to be carefully configured to maintain the security of the essential function(s).
- All platforms conform to your secure, defined baseline build, or the latest known good configuration version for that environment.
- You closely and effectively manage changes in your environment, ensuring that network and system configurations are secure and documented.
- You regularly review and validate that your network and information systems have the expected, secure settings and configuration.
- Only permitted software can be installed.
- If automated decision-making technologies are in use, their operation is well understood, and decisions can be replicated.
- Generic, shared, default name and built-in accounts have been removed or disabled. Where this is not possible, credentials to these accounts have been changed. Service accounts are appropriately protected.
Not achieved - At least one of the following statements is true:
- You haven't identified the assets that need to be carefully configured to maintain the security of the essential function(s).
- Policies relating to the security of operating system builds or configuration are not applied consistently across your network and information systems relating to your essential function(s).
- Configuration details are not recorded or lack enough information to be able to rebuild the system or device.
- The recording of security changes or adjustments that affect your essential function(s) is lacking or inconsistent.
- Generic, shared, default name and built-in accounts have not been removed or disabled.
- Standard users are able to change settings that would adversely impact the security of network and information systems supporting your essential function(s).
Partially achieved - All of the following statements are true:
- You have identified and documented the assets that need to be carefully configured to maintain the security of the essential function(s).
- Secure platform and device builds are used across the estate.
- Consistent, secure and minimal system and device configurations are applied across the same types of environment.
- Changes and adjustments to security configuration at security boundaries with the network and information systems supporting your essential function(s) are approved and documented.
- You verify software before installation is permitted.
- Generic, shared, default name and built-in accounts have been removed or disabled. Where this is not possible, credentials to these accounts have been changed. Service accounts are appropriately protected.
- Standard users are not able to change settings that would adversely impact the security of network and information systems supporting your essential function(s).
Achieved - All of the following statements are true:
- You have identified, documented and actively manage (e.g. maintain security configurations, patching, updating according to good practice) the assets that need to be carefully configured to maintain the security of the essential function(s).
- All platforms conform to your secure, defined baseline build, or the latest known good configuration version for that environment.
- You closely and effectively manage changes in your environment, ensuring that network and system configurations are secure and documented.
- You regularly review and validate that your network and information systems have the expected, secure settings and configuration.
- Only permitted software can be installed.
- If automated decision-making technologies are in use, their operation is well understood, and decisions can be replicated.
- Generic, shared, default name and built-in accounts have been removed or disabled. Where this is not possible, credentials to these accounts have been changed. Service accounts are appropriately protected.
B4.c Secure Management
- You manage your organisation's network and information systems that support the operation of your essential function(s) to enable and maintain security.
- You manage your organisation's network and information systems that support the operation of your essential function(s) to enable and maintain security.
- Your systems and devices supporting the operation of the essential function(s) are administered or maintained from devices that are not corporately owned and managed.
- You do not have good or current technical documentation of your network and information systems.
- Your systems and devices supporting the operation of the essential function(s) are only administered or maintained by authorised privileged users from devices sufficiently separated, using a risk-based approach, from the activities of standard users.
- Technical knowledge about network and information systems, such as documentation and network diagrams, is regularly reviewed and updated.
- You prevent, detect and remove malware or unauthorised software. You use technical, procedural and physical measures as necessary.
- Your systems and devices supporting the operation of the essential function(s) are only administered or maintained by authorised privileged users from highly trusted devices, such as Privileged Access Workstations, dedicated solely to those operations.
- You regularly review and update technical knowledge about network and information systems, such as documentation and network diagrams, and ensure they are securely stored.
- You prevent, detect and remove malware or unauthorised software. You use technical, procedural and physical measures as necessary.
Not achieved - At least one of the following statements is true:
- Your systems and devices supporting the operation of the essential function(s) are administered or maintained from devices that are not corporately owned and managed.
- You do not have good or current technical documentation of your network and information systems.
Partially achieved - All of the following statements are true:
- Your systems and devices supporting the operation of the essential function(s) are only administered or maintained by authorised privileged users from devices sufficiently separated, using a risk-based approach, from the activities of standard users.
- Technical knowledge about network and information systems, such as documentation and network diagrams, is regularly reviewed and updated.
- You prevent, detect and remove malware or unauthorised software. You use technical, procedural and physical measures as necessary.
Achieved - All of the following statements are true:
- Your systems and devices supporting the operation of the essential function(s) are only administered or maintained by authorised privileged users from highly trusted devices, such as Privileged Access Workstations, dedicated solely to those operations.
- You regularly review and update technical knowledge about network and information systems, such as documentation and network diagrams, and ensure they are securely stored.
- You prevent, detect and remove malware or unauthorised software. You use technical, procedural and physical measures as necessary.
B4.d Vulnerability Management
- You manage known vulnerabilities in network and information systems to prevent adverse impact on your essential function(s).
- You manage known vulnerabilities in network and information systems to prevent adverse impact on your essential function(s).
- You do not understand the exposure of your essential function(s) to publicly-known vulnerabilities.
- You do not mitigate externally exposed vulnerabilities promptly.
- You have not recently tested to verify your understanding of the vulnerabilities of the network and information systems that support your essential function(s).
- You have not suitably mitigated systems or software that is no longer supported.
- You are not pursuing replacement for unsupported systems or software.
- You maintain a current understanding of the exposure of your essential function(s) to publicly-known vulnerabilities.
- Announced vulnerabilities for all software packages, network and information systems used to support your essential function(s) are tracked, prioritised and externally exposed vulnerabilities are mitigated (e.g. by patching) promptly.
- Some vulnerabilities that are not externally exposed have temporary mitigations for an extended period.
- You have temporary mitigations for unsupported systems and software while pursuing migration to supported technology.
- You regularly test to fully understand the vulnerabilities of the network and information systems that support the operation of your essential function(s).
- You maintain a current understanding of the exposure of your essential function(s) to publicly-known vulnerabilities.
- Announced vulnerabilities for all software packages, network and information systems used to support your essential function(s) are tracked, prioritised and mitigated (e.g. by patching) promptly.
- You regularly test to fully understand the vulnerabilities of the network and information systems that support the operation of your essential function(s) and verify this understanding with third-party testing.
- You actively maximise the use of supported software, firmware and hardware in your network and information systems supporting your essential function(s).
Not achieved - At least one of the following statements is true:
- You do not understand the exposure of your essential function(s) to publicly-known vulnerabilities.
- You do not mitigate externally exposed vulnerabilities promptly.
- You have not recently tested to verify your understanding of the vulnerabilities of the network and information systems that support your essential function(s).
- You have not suitably mitigated systems or software that is no longer supported.
- You are not pursuing replacement for unsupported systems or software.
Partially achieved - All of the following statements are true:
- You maintain a current understanding of the exposure of your essential function(s) to publicly-known vulnerabilities.
- Announced vulnerabilities for all software packages, network and information systems used to support your essential function(s) are tracked, prioritised and externally exposed vulnerabilities are mitigated (e.g. by patching) promptly.
- Some vulnerabilities that are not externally exposed have temporary mitigations for an extended period.
- You have temporary mitigations for unsupported systems and software while pursuing migration to supported technology.
- You regularly test to fully understand the vulnerabilities of the network and information systems that support the operation of your essential function(s).
Achieved - All of the following statements are true:
- You maintain a current understanding of the exposure of your essential function(s) to publicly-known vulnerabilities.
- Announced vulnerabilities for all software packages, network and information systems used to support your essential function(s) are tracked, prioritised and mitigated (e.g. by patching) promptly.
- You regularly test to fully understand the vulnerabilities of the network and information systems that support the operation of your essential function(s) and verify this understanding with third-party testing.
- You actively maximise the use of supported software, firmware and hardware in your network and information systems supporting your essential function(s).
The organisation builds resilience against cyber attack and system failure into the design, implementation, operation and management of systems that support the operation of your essential function(s).
Description
error determining description
Guidance
It's important to be prepared to respond to significant disruption by having business continuity and disaster recovery planning in place. This should include a definition of your most critical resources and an understanding of the order of actions needed to restore service(s). Test that these plans work, for example through manually triggering failover testing, carrying out table-top scenario walk-throughs, red-teaming or Cyber adversary simulation testing. You should be ready to adjust the security measures in place in response to changes in risk. For example, if threat intelligence indicates an increased likelihood of your organisation or sector being targeted you may decide to isolate operational networks until the threat has decreased. Alternatively, in the event of public disclosure of an unpatched vulnerability in equipment that you use, with reported use of exploits targeting the vulnerability, you may respond by elevating your protective monitoring, changing your configuration to avoid being susceptible, or taking other mitigating action in the period until a patch is made available and can be deployed.
You should reduce the likelihood of failure or attack by taking all reasonable measures to maintain networks, information systems and necessary technologies in good working order. Exceptions should be appropriately managed.
In the event of an incident, it is more likely that an essential function will be able to continue where the networks and information systems that support it are segregated from other business and external systems. Separation of system architecture, remote access and privileged access are some key principles that can protect more critical systems from external compromise.
Some sectors responsible for the operation of essential functions may apply the industrial automation and control system security standard IEC 62443, which applies a reference model that separates systems into different logical layers. The standard's architecture model segregates equipment into security zones.
Limitations of networks and information systems, or external services or resources, such as network bandwidth, processing capability, or data storage capacity, should be understood and managed with suitable mitigations to avoid disruption through resource overload.
Make appropriate use of diverse technologies, geographic locations and so on, to provide resilience. You should understand and manage external or lower-priority dependencies to ensure that alternative means are suitable for continuation of the essential function.
In the event of an adverse event, you should be able to revert to backups of hardware and data that are known to be functioning and accessible. Organisations should maintain secured offline, potentially off-site, backups of the operational data, equipment configurations, gold builds, etc. needed to recover from an extreme event.
Suitable alternative backups may include paper-based information and manual processes. Other essential backups may include personnel with appropriate knowledge and access to up-to-date documentation. Consider how to make it easy to recover following an incident or compromise.
You should have adequate policies and measures to ensure the physical and environmental security of your network and information systems. This can be achieved through measures such as physical access controls, alarm systems, environmental controls and automated fire systems etc.
When planning physical upgrades or changes to network and information systems (such as moving to new hardware installations, installing new equipment or power supplies), you should take steps to avoid unnecessary or unplanned interruptions to the services that your network and information systems support.
You should also ensure that you have adequate policies to protect supporting utilities such as electricity, fuel, heating, ventilation, and air conditioning. This can be achieved by having alternative sources, such as back-up generators or uninterruptible power supplies, active temperature monitoring, redundant cooling systems etc.
Contributing Outcomes
B5.a Resilience Preparation
- You are prepared to restore the operation of your essential function(s) following adverse impact to network and information systems.
- You are prepared to restore the operation of your essential function(s) following adverse impact to network and information systems.
- You have limited understanding of all the elements that are required to restore operation of the essential function(s).
- You have not completed business continuity and disaster recovery plans for network and information systems, including their dependencies, supporting the operation of the essential function(s).
- You have not fully assessed the practical implementation of your business continuity and disaster recovery plans.
- You know all network and information systems, and underlying technologies that are necessary to restore the operation of the essential function(s) and understand their interdependence.
- You know the order in which systems need to be recovered to efficiently and effectively restore the operation of the essential function(s).
- You have business continuity and disaster recovery plans that have been tested for practicality, effectiveness and completeness. Appropriate use is made of different test methods (e.g. manual fail-over, table-top exercises, or red-teaming).
- You use your security awareness and threat intelligence sources to identify new or heightened levels of risk, which result in immediate and potentially temporary security measures to enhance the security of your network and information systems (e.g. in response to a widespread outbreak of very damaging malware).
Not achieved - Any of the following statements are true:
- You have limited understanding of all the elements that are required to restore operation of the essential function(s).
- You have not completed business continuity and disaster recovery plans for network and information systems, including their dependencies, supporting the operation of the essential function(s).
- You have not fully assessed the practical implementation of your business continuity and disaster recovery plans.
Partially achieved - All of the following statements are true:
- You know all network and information systems, and underlying technologies that are necessary to restore the operation of the essential function(s) and understand their interdependence.
- You know the order in which systems need to be recovered to efficiently and effectively restore the operation of the essential function(s).
Achieved - All of the following statements are true:
- You have business continuity and disaster recovery plans that have been tested for practicality, effectiveness and completeness. Appropriate use is made of different test methods (e.g. manual fail-over, table-top exercises, or red-teaming).
- You use your security awareness and threat intelligence sources to identify new or heightened levels of risk, which result in immediate and potentially temporary security measures to enhance the security of your network and information systems (e.g. in response to a widespread outbreak of very damaging malware).
B5.b Design for Resilience
- You design the network and information systems supporting your essential function(s) to be resilient to cyber security incidents. Systems are appropriately segregated and resource limitations are mitigated.
- You design the network and information systems supporting your essential function(s) to be resilient to cyber security incidents. Systems are appropriately segregated and resource limitations are mitigated.
- Network and information systems supporting the operation of your essential function(s) are not appropriately segregated.
- Internet services, such as browsing and email, are accessible from network and information systems supporting the essential function(s).
- You do not understand or lack plans to mitigate all resource limitations that could adversely affect your essential function(s).
- Network and information systems supporting the operation of your essential function(s) are logically separated from your business systems (e.g. they reside on the same network as the rest of the organisation but within a DMZ).
- Internet services, such as browsing and email, are not accessible from network and information systems supporting the essential function(s).
- Resource limitations (e.g. network bandwidth, single network paths) have been identified but not fully mitigated.
- Network and information systems supporting the operation of your essential function(s) are segregated from other business and external systems by appropriate technical and physical means (e.g. separate network and system infrastructure with independent user administration).
- Internet services, such as browsing and email, are not accessible from network and information systems supporting the essential function(s).
- You have identified and mitigated all resource limitations (e.g. bandwidth limitations and single network paths).
- You have identified and mitigated any geographical constraints or weaknesses. (e.g. systems that your essential function(s) depends upon are replicated in another location, important network connectivity has alternative physical paths and service providers).
- You review and update assessments of dependencies, resource and geographical limitations and mitigations when necessary.
Not achieved - At least one of the following statements is true:
- Network and information systems supporting the operation of your essential function(s) are not appropriately segregated.
- Internet services, such as browsing and email, are accessible from network and information systems supporting the essential function(s).
- You do not understand or lack plans to mitigate all resource limitations that could adversely affect your essential function(s).
Partially achieved - All of the following statements are true:
- Network and information systems supporting the operation of your essential function(s) are logically separated from your business systems (e.g. they reside on the same network as the rest of the organisation but within a DMZ).
- Internet services, such as browsing and email, are not accessible from network and information systems supporting the essential function(s).
- Resource limitations (e.g. network bandwidth, single network paths) have been identified but not fully mitigated.
Achieved - All of the following statements are true:
- Network and information systems supporting the operation of your essential function(s) are segregated from other business and external systems by appropriate technical and physical means (e.g. separate network and system infrastructure with independent user administration).
- Internet services, such as browsing and email, are not accessible from network and information systems supporting the essential function(s).
- You have identified and mitigated all resource limitations (e.g. bandwidth limitations and single network paths).
- You have identified and mitigated any geographical constraints or weaknesses. (e.g. systems that your essential function(s) depends upon are replicated in another location, important network connectivity has alternative physical paths and service providers).
- You review and update assessments of dependencies, resource and geographical limitations and mitigations when necessary.
B5.c Backups
- You hold accessible and secured current backups of data and information needed to recover operation of your essential function(s) following an adverse impact to network and information systems.
- You hold accessible and secured current backups of data and information needed to recover operation of your essential function(s) following an adverse impact to network and information systems.
- Backup coverage is incomplete and does not include all relevant data and information needed to restore the operation of your essential function(s).
- Backups are not frequent enough for the operation of your essential function(s) to be restored effectively.
- Your restoration process does not restore your essential function(s) in a suitable time frame.
- You have appropriately secured backups (including data, configuration information, software, equipment, processes and knowledge). These backups will be accessible to recover from an extreme event.
- You routinely test backups to ensure that the backup process function(s) correctly and the backups are usable.
- Your comprehensive, automatic and tested technical and procedural backups are secured at centrally accessible or secondary sites to recover from an extreme event.
- Backups of all important data and information needed to recover the essential function(s) are made, tested, documented and routinely reviewed
Not achieved - At least one of the following statements is true:
- Backup coverage is incomplete and does not include all relevant data and information needed to restore the operation of your essential function(s).
- Backups are not frequent enough for the operation of your essential function(s) to be restored effectively.
- Your restoration process does not restore your essential function(s) in a suitable time frame.
Partially achieved - All of the following statements are true:
- You have appropriately secured backups (including data, configuration information, software, equipment, processes and knowledge). These backups will be accessible to recover from an extreme event.
- You routinely test backups to ensure that the backup process function(s) correctly and the backups are usable.
Achieved - All of the following statements are true:
- Your comprehensive, automatic and tested technical and procedural backups are secured at centrally accessible or secondary sites to recover from an extreme event.
- Backups of all important data and information needed to recover the essential function(s) are made, tested, documented and routinely reviewed
Staff have appropriate awareness, knowledge and skills to carry out their organisational roles effectively in relation to the security of network and information systems supporting the operation of your essential function(s).
Description
error determining description
Guidance
The people who operate and support essential functions should be provided with all they need to carry out their job while supporting the organisation's cyber security. In line with the design of
service protection policies and processes
, you should apply the same people-focussed approach to staff awareness and training.
Training and awareness activities should provide appropriate cyber security skills for the job role based on an understanding of how people
really
work with the systems, with ongoing reminders and top-up training to maintain skills.
Using a range of approaches to training and awareness can improve understanding and information retention, from briefings, online courses and blogs to simulated cyber attack. You may achieve the widest uptake of training and awareness by accommodating different learning preferences and using various delivery methods. Organisations may find the
GCHQ certified training scheme
useful when considering commercial offerings.
Organisations responsible for essential functions should aim to create a positive security culture, where people are aware of their role in maintaining security and actively take part and contribute to improving security. This is particularly important where a technical solution is not possible, so security relies on people making the right cyber security decisions. Developing a positive security culture is likely to take some time, with some changes possibly taking years to become established and is unlikely to be achieved simply through written guidance or training events.
These outcomes are best achieved when organisations actively engage with staff and communicate effectively with them about network and information system security and how it relates to their jobs. This should be more easily achieved where organisations create and promote a long-term security culture vision that is endorsed and supported by senior management, then make incremental, focused changes to address specific business issues. In some cases, particularly where an essential function is safety-related, an organisation may be able to draw on activities supporting positive safety culture to build up the organisation's cyber security culture.
Contributing Outcomes
B6.a Cyber Security Culture
- You develop and maintain a positive cyber security culture and a shared sense of responsibility.
- You develop and maintain a positive cyber security culture and a shared sense of responsibility.
- People in your organisation do not understand what they contribute to the cyber security of network and information systems supporting your essential function(s).
- People in your organisation do not know how to raise a concern about cyber security.
- People believe that reporting issues may get them into trouble.
- Your organisation's approach to cyber security is perceived by staff as hindering the business of the organisation and may encourage poor security behaviours.
- Formal or informal incentives and rewards conflict with the promotion of positive security outcomes.
- Your executive management understand and widely communicate the importance of a positive cyber security culture. Positive attitudes, behaviours and expectations are described for your organisation.
- All people in your organisation understand the contribution they make to the cyber security of network and information systems supporting your essential function(s).
- All individuals in your organisation know who to contact and where to access more information about cyber security. They know how to raise a cyber security issue.
- You identify and address issues that inhibit people from behaving in a manner that supports your intended cyber security outcomes.
- Your executive management clearly and effectively communicates the organisation's cyber security priorities and objectives to all staff. Your organisation displays positive cyber security attitudes, behaviours, expectations.
- People in your organisation raising potential cyber security incidents and issues are treated positively.
- Individuals at all levels in your organisation routinely report concerns or issues about cyber security and are recognised for their contribution to keeping the organisation secure.
- Your management is seen to be committed to and actively involved in cyber security.
- Your organisation communicates openly about cyber security, with any concern being taken seriously.
- People across your organisation participate in cyber security activities and improvements, building joint ownership and bringing knowledge of their area of expertise.
Not achieved - At least one of the following statements is true:
- People in your organisation do not understand what they contribute to the cyber security of network and information systems supporting your essential function(s).
- People in your organisation do not know how to raise a concern about cyber security.
- People believe that reporting issues may get them into trouble.
- Your organisation's approach to cyber security is perceived by staff as hindering the business of the organisation and may encourage poor security behaviours.
- Formal or informal incentives and rewards conflict with the promotion of positive security outcomes.
Partially achieved - All the following statements are true:
- Your executive management understand and widely communicate the importance of a positive cyber security culture. Positive attitudes, behaviours and expectations are described for your organisation.
- All people in your organisation understand the contribution they make to the cyber security of network and information systems supporting your essential function(s).
- All individuals in your organisation know who to contact and where to access more information about cyber security. They know how to raise a cyber security issue.
- You identify and address issues that inhibit people from behaving in a manner that supports your intended cyber security outcomes.
Achieved - All the following statements are true:
- Your executive management clearly and effectively communicates the organisation's cyber security priorities and objectives to all staff. Your organisation displays positive cyber security attitudes, behaviours, expectations.
- People in your organisation raising potential cyber security incidents and issues are treated positively.
- Individuals at all levels in your organisation routinely report concerns or issues about cyber security and are recognised for their contribution to keeping the organisation secure.
- Your management is seen to be committed to and actively involved in cyber security.
- Your organisation communicates openly about cyber security, with any concern being taken seriously.
- People across your organisation participate in cyber security activities and improvements, building joint ownership and bringing knowledge of their area of expertise.
B6.b Cyber Security Training
- The people who support the operation of network and information systems supporting your essential function(s) are appropriately trained in cyber security.
- The people who support the operation of network and information systems supporting your essential function(s) are appropriately trained in cyber security.
- There are teams who operate and support your essential function(s) that lack any cyber security training.
- Cyber security training is restricted to specific roles in your organisation.
- Cyber security training records for your organisation are lacking or incomplete.
- Training is used as a “silver bullet” for all user security behaviours.
- The success of training is only measured by the number of people reached, rather than assessing whether it has a positive impact on security behaviours.
- Training materials contain out of date or contradictory information, or information that conflicts with other policies, processes or procedures.
- You have defined appropriate cyber security training and awareness activities for all roles in your organisation, from executives to the most junior roles.
- You use a range of teaching and communication techniques for cyber security training and awareness to reach the widest audience effectively.
- Cyber security information is easily available.
- All people in your organisation, from the most senior to the most junior, follow appropriate cyber security training paths.
- Each individuals cyber security training is tracked and refreshed at suitable intervals.
- You routinely evaluate your cyber security training and awareness activities to ensure they reach the widest audience and are effective.
- You make cyber security information and good practice guidance easily accessible, widely available and you know it is referenced and used within your organisation.
Not achieved - At least one of the following statements is true:
- There are teams who operate and support your essential function(s) that lack any cyber security training.
- Cyber security training is restricted to specific roles in your organisation.
- Cyber security training records for your organisation are lacking or incomplete.
- Training is used as a “silver bullet” for all user security behaviours.
- The success of training is only measured by the number of people reached, rather than assessing whether it has a positive impact on security behaviours.
- Training materials contain out of date or contradictory information, or information that conflicts with other policies, processes or procedures.
Partially achieved - All the following statements are true:
- You have defined appropriate cyber security training and awareness activities for all roles in your organisation, from executives to the most junior roles.
- You use a range of teaching and communication techniques for cyber security training and awareness to reach the widest audience effectively.
- Cyber security information is easily available.
Achieved - All the following statements are true:
- All people in your organisation, from the most senior to the most junior, follow appropriate cyber security training paths.
- Each individuals cyber security training is tracked and refreshed at suitable intervals.
- You routinely evaluate your cyber security training and awareness activities to ensure they reach the widest audience and are effective.
- You make cyber security information and good practice guidance easily accessible, widely available and you know it is referenced and used within your organisation.
Staff have appropriate awareness, knowledge and skills to carry out their organisational roles effectively in relation to the security of network and information systems supporting the operation of your essential function(s).
Description
error determining description
Guidance
The people who operate and support essential functions should be provided with all they need to carry out their job while supporting the organisation's cyber security. In line with the design of
service protection policies and processes
, you should apply the same people-focussed approach to staff awareness and training.
Training and awareness activities should provide appropriate cyber security skills for the job role based on an understanding of how people
really
work with the systems, with ongoing reminders and top-up training to maintain skills.
Using a range of approaches to training and awareness can improve understanding and information retention, from briefings, online courses and blogs to simulated cyber attack. You may achieve the widest uptake of training and awareness by accommodating different learning preferences and using various delivery methods. Organisations may find the
GCHQ certified training scheme
useful when considering commercial offerings.
Organisations responsible for essential functions should aim to create a positive security culture, where people are aware of their role in maintaining security and actively take part and contribute to improving security. This is particularly important where a technical solution is not possible, so security relies on people making the right cyber security decisions. Developing a positive security culture is likely to take some time, with some changes possibly taking years to become established and is unlikely to be achieved simply through written guidance or training events.
These outcomes are best achieved when organisations actively engage with staff and communicate effectively with them about network and information system security and how it relates to their jobs. This should be more easily achieved where organisations create and promote a long-term security culture vision that is endorsed and supported by senior management, then make incremental, focused changes to address specific business issues. In some cases, particularly where an essential function is safety-related, an organisation may be able to draw on activities supporting positive safety culture to build up the organisation's cyber security culture.
Contributing Outcomes
B6.a Cyber Security Culture
- You develop and maintain a positive cyber security culture and a shared sense of responsibility.
- You develop and maintain a positive cyber security culture and a shared sense of responsibility.
- People in your organisation do not understand what they contribute to the cyber security of network and information systems supporting your essential function(s).
- People in your organisation do not know how to raise a concern about cyber security.
- People believe that reporting issues may get them into trouble.
- Your organisation's approach to cyber security is perceived by staff as hindering the business of the organisation and may encourage poor security behaviours.
- Formal or informal incentives and rewards conflict with the promotion of positive security outcomes.
- Your executive management understand and widely communicate the importance of a positive cyber security culture. Positive attitudes, behaviours and expectations are described for your organisation.
- All people in your organisation understand the contribution they make to the cyber security of network and information systems supporting your essential function(s).
- All individuals in your organisation know who to contact and where to access more information about cyber security. They know how to raise a cyber security issue.
- You identify and address issues that inhibit people from behaving in a manner that supports your intended cyber security outcomes.
- Your executive management clearly and effectively communicates the organisation's cyber security priorities and objectives to all staff. Your organisation displays positive cyber security attitudes, behaviours, expectations.
- People in your organisation raising potential cyber security incidents and issues are treated positively.
- Individuals at all levels in your organisation routinely report concerns or issues about cyber security and are recognised for their contribution to keeping the organisation secure.
- Your management is seen to be committed to and actively involved in cyber security.
- Your organisation communicates openly about cyber security, with any concern being taken seriously.
- People across your organisation participate in cyber security activities and improvements, building joint ownership and bringing knowledge of their area of expertise.
Not achieved - At least one of the following statements is true:
- People in your organisation do not understand what they contribute to the cyber security of network and information systems supporting your essential function(s).
- People in your organisation do not know how to raise a concern about cyber security.
- People believe that reporting issues may get them into trouble.
- Your organisation's approach to cyber security is perceived by staff as hindering the business of the organisation and may encourage poor security behaviours.
- Formal or informal incentives and rewards conflict with the promotion of positive security outcomes.
Partially achieved - All the following statements are true:
- Your executive management understand and widely communicate the importance of a positive cyber security culture. Positive attitudes, behaviours and expectations are described for your organisation.
- All people in your organisation understand the contribution they make to the cyber security of network and information systems supporting your essential function(s).
- All individuals in your organisation know who to contact and where to access more information about cyber security. They know how to raise a cyber security issue.
- You identify and address issues that inhibit people from behaving in a manner that supports your intended cyber security outcomes.
Achieved - All the following statements are true:
- Your executive management clearly and effectively communicates the organisation's cyber security priorities and objectives to all staff. Your organisation displays positive cyber security attitudes, behaviours, expectations.
- People in your organisation raising potential cyber security incidents and issues are treated positively.
- Individuals at all levels in your organisation routinely report concerns or issues about cyber security and are recognised for their contribution to keeping the organisation secure.
- Your management is seen to be committed to and actively involved in cyber security.
- Your organisation communicates openly about cyber security, with any concern being taken seriously.
- People across your organisation participate in cyber security activities and improvements, building joint ownership and bringing knowledge of their area of expertise.
B6.b Cyber Security Training
- The people who support the operation of network and information systems supporting your essential function(s) are appropriately trained in cyber security.
- The people who support the operation of network and information systems supporting your essential function(s) are appropriately trained in cyber security.
- There are teams who operate and support your essential function(s) that lack any cyber security training.
- Cyber security training is restricted to specific roles in your organisation.
- Cyber security training records for your organisation are lacking or incomplete.
- Training is used as a “silver bullet” for all user security behaviours.
- The success of training is only measured by the number of people reached, rather than assessing whether it has a positive impact on security behaviours.
- Training materials contain out of date or contradictory information, or information that conflicts with other policies, processes or procedures.
- You have defined appropriate cyber security training and awareness activities for all roles in your organisation, from executives to the most junior roles.
- You use a range of teaching and communication techniques for cyber security training and awareness to reach the widest audience effectively.
- Cyber security information is easily available.
- All people in your organisation, from the most senior to the most junior, follow appropriate cyber security training paths.
- Each individuals cyber security training is tracked and refreshed at suitable intervals.
- You routinely evaluate your cyber security training and awareness activities to ensure they reach the widest audience and are effective.
- You make cyber security information and good practice guidance easily accessible, widely available and you know it is referenced and used within your organisation.
Not achieved - At least one of the following statements is true:
- There are teams who operate and support your essential function(s) that lack any cyber security training.
- Cyber security training is restricted to specific roles in your organisation.
- Cyber security training records for your organisation are lacking or incomplete.
- Training is used as a “silver bullet” for all user security behaviours.
- The success of training is only measured by the number of people reached, rather than assessing whether it has a positive impact on security behaviours.
- Training materials contain out of date or contradictory information, or information that conflicts with other policies, processes or procedures.
Partially achieved - All the following statements are true:
- You have defined appropriate cyber security training and awareness activities for all roles in your organisation, from executives to the most junior roles.
- You use a range of teaching and communication techniques for cyber security training and awareness to reach the widest audience effectively.
- Cyber security information is easily available.
Achieved - All the following statements are true:
- All people in your organisation, from the most senior to the most junior, follow appropriate cyber security training paths.
- Each individuals cyber security training is tracked and refreshed at suitable intervals.
- You routinely evaluate your cyber security training and awareness activities to ensure they reach the widest audience and are effective.
- You make cyber security information and good practice guidance easily accessible, widely available and you know it is referenced and used within your organisation.
The organisation monitors the security status of network and information systems supporting the operation of essential function(s) in order to detect security events indicative of a security incident.
Description
error determining description
Guidance
One clear focus of your security monitoring should be the detection of incidents or activity that is likely to have an adverse impact on the network and information systems that support the operation of essential functions. Log data collection, secure storage, analysis tools, understanding your network and information systems that support your essential function(s), threat intelligence and personnel skills should all be used to build an effective security monitoring capability.
An organisation's automated monitoring capability should be able to find threats within their network and information systems by using both signature-based detections and, behavioural and anomaly-based detections.
Examples of signature-based detections are detecting when known command and control traffic is communicating to the internet, or an AV signature is present in a file. Organisations should endeavour to understand what automated detections and alerting do and how best to use them, to ensure they are making the most of the monitoring solution / as well as being as effective as possible.
Organisations should also have the capability to find threats by using behavioural and anomaly-based detections, for example by detecting an abnormally large amount of data being exfiltrated or AV detecting unusual changes to start up registry keys.
Both signature and, anomaly and behaviour-based detections rely on an understanding of indicators of compromise, your network and information systems, user behaviour and threats.
Contributing Outcomes
C1.a Sources and Tools for Logging and Monitoring
- The data sources that you include in your logging and monitoring allow for timely identification of events which might adversely affect the resiliency of network and information system(s) supporting the operation of your essential function(s).
- The data sources that you include in your logging and monitoring allow for timely identification of events which might adversely affect the resiliency of network and information system(s) supporting the operation of your essential function(s).
- Data relating to the security and operation of network and information systems supporting your essential function(s) is not collected.
- You are not able to audit the activities of users and systems in relation to network and information systems supporting your essential function(s).
- You do not monitor traffic crossing your network boundary.
- Log data cannot be synchronised using an accurate common time source.
- Logs are stored in locations where they are not readily available to authorised users and systems.
- Your monitoring tools cannot be configured to make use of new log streams as they come online.
- Your monitoring tools are only able to make use of a fraction of the log data being collected.
- You do not understand where log data is stored or how long it should be stored for.
- You have no way of ensuring log data is being captured as expected and available when needed.
- Data relating to the security and operation of some areas of network and information systems supporting your essential function(s) is collected but coverage is not comprehensive.
- Some user and system monitoring is done, but not covering a fully agreed list of suspicious or undesirable behaviour.
- You monitor traffic crossing your network boundary (including IP address connections as a minimum).
- Some but not all log datasets can be easily queried with search tools to aid in investigations.
- Your monitoring tools work with most log data, with some configuration.
- Your monitoring tools can make use of log data that would capture all common threats.
- You ensure log data is available for analysis when needed.
- Monitoring is based on a thorough understanding of network and information systems supporting your essential function(s), techniques used by threat actors, and awareness of what logging and monitoring is required to detect events and incidents that could affect the operation of your essential function(s).
- Your monitoring data provides enough detail to promptly and reliably detect security events, incidents and support investigations. This is reviewed regularly and after a significant security event.
- Extensive monitoring of user and system activity in relation to network and information systems that support your essential function(s) enables you to promptly detect policy violations, suspicious or undesirable user and system behaviour, deviations from normal / routine behaviour or abnormalities indicative of adverse activity.
- Your logging and monitoring capability includes host-based and network monitoring.
- All new network and information systems supporting your essential function(s) are considered as potential logging and monitoring data sources to maintain a comprehensive monitoring capability.
- Log datasets are synchronised including using an accurate common time source so that separate datasets can be correlated in appropriate ways.
- You enrich log data with other network and information systems data to provide a more comprehensive picture of actions and behaviours.
- Your monitoring tools make use of log data to pinpoint activity.
- You regularly review the data sources and tools included in your logging and monitoring strategy to ensure it remains effective.
Not achieved - At least one of the following statements is true:
- Data relating to the security and operation of network and information systems supporting your essential function(s) is not collected.
- You are not able to audit the activities of users and systems in relation to network and information systems supporting your essential function(s).
- You do not monitor traffic crossing your network boundary.
- Log data cannot be synchronised using an accurate common time source.
- Logs are stored in locations where they are not readily available to authorised users and systems.
- Your monitoring tools cannot be configured to make use of new log streams as they come online.
- Your monitoring tools are only able to make use of a fraction of the log data being collected.
- You do not understand where log data is stored or how long it should be stored for.
- You have no way of ensuring log data is being captured as expected and available when needed.
Partially achieved - All the following statements are true:
- Data relating to the security and operation of some areas of network and information systems supporting your essential function(s) is collected but coverage is not comprehensive.
- Some user and system monitoring is done, but not covering a fully agreed list of suspicious or undesirable behaviour.
- You monitor traffic crossing your network boundary (including IP address connections as a minimum).
- Some but not all log datasets can be easily queried with search tools to aid in investigations.
- Your monitoring tools work with most log data, with some configuration.
- Your monitoring tools can make use of log data that would capture all common threats.
- You ensure log data is available for analysis when needed.
Achieved - All the following statements are true:
- Monitoring is based on a thorough understanding of network and information systems supporting your essential function(s), techniques used by threat actors, and awareness of what logging and monitoring is required to detect events and incidents that could affect the operation of your essential function(s).
- Your monitoring data provides enough detail to promptly and reliably detect security events, incidents and support investigations. This is reviewed regularly and after a significant security event.
- Extensive monitoring of user and system activity in relation to network and information systems that support your essential function(s) enables you to promptly detect policy violations, suspicious or undesirable user and system behaviour, deviations from normal / routine behaviour or abnormalities indicative of adverse activity.
- Your logging and monitoring capability includes host-based and network monitoring.
- All new network and information systems supporting your essential function(s) are considered as potential logging and monitoring data sources to maintain a comprehensive monitoring capability.
- Log datasets are synchronised including using an accurate common time source so that separate datasets can be correlated in appropriate ways.
- You enrich log data with other network and information systems data to provide a more comprehensive picture of actions and behaviours.
- Your monitoring tools make use of log data to pinpoint activity.
- You regularly review the data sources and tools included in your logging and monitoring strategy to ensure it remains effective.
C1.b Securing Logs
- You hold log data securely and grant appropriate user and system access only to accounts with a business need. Log data is held for a suitable retention period, after which it is deleted.
- You hold log data securely and grant appropriate user and system access only to accounts with a business need. Log data is held for a suitable retention period, after which it is deleted.
- It is possible for log data to be easily edited or deleted by unauthorised users or malicious attackers.
- There is no controlled list of the users and systems that can view and query log data.
- There is no monitoring of the access to log data.
- There are no policies for accessing to log data.
- Only authorised users and systems can access log data.
- There is some monitoring of access to log data (e.g. copying, deleting or modification, or even viewing).
- You have defined and implemented retention periods for log data.
- You have given legitimate reasons for accessing log data in your policies.
- Appropriate access to log data is limited to those users and systems with a business need.
- The logging architecture has mechanisms, policies, processes and procedures to ensure that it can protect itself from threats comparable to those that it is trying to identify. This includes protecting the function itself and the data within it.
- Log data analysis and normalisation is only performed on copies of the log data keeping the master copy unaltered.
- All actions involving log data (e.g. copying, deleting, modification, or even viewing) can be traced back to a unique user or system.
- The integrity of log data is protected, verified and any modification, including deletion, is detected and attributed.
Not achieved - At least one of the following is true:
- It is possible for log data to be easily edited or deleted by unauthorised users or malicious attackers.
- There is no controlled list of the users and systems that can view and query log data.
- There is no monitoring of the access to log data.
- There are no policies for accessing to log data.
Partially achieved - All the following statements are true:
- Only authorised users and systems can access log data.
- There is some monitoring of access to log data (e.g. copying, deleting or modification, or even viewing).
- You have defined and implemented retention periods for log data.
- You have given legitimate reasons for accessing log data in your policies.
Achieved - All the following statements are true:
- Appropriate access to log data is limited to those users and systems with a business need.
- The logging architecture has mechanisms, policies, processes and procedures to ensure that it can protect itself from threats comparable to those that it is trying to identify. This includes protecting the function itself and the data within it.
- Log data analysis and normalisation is only performed on copies of the log data keeping the master copy unaltered.
- All actions involving log data (e.g. copying, deleting, modification, or even viewing) can be traced back to a unique user or system.
- The integrity of log data is protected, verified and any modification, including deletion, is detected and attributed.
C1.c Generating Alerts
- Evidence of potential security incidents contained in your monitoring data is reliably identified and where appropriate triggers alerts.
- Evidence of potential security incidents contained in your monitoring data is reliably identified and where appropriate triggers alerts.
- You do not apply updates to your detection security technologies in a timely way, after receiving them (e.g. AV signature updates, other threat signatures or Indicators of Compromise (IoCs)).
- Security alerts relating to network and information systems supporting your essential function(s) are not prioritised.
- The enrichment of security alerts within network and information systems supporting your essential function(s) cannot be performed.
- You do not confidently detect the presence of IoCs on network and information systems supporting your essential function(s), such as known malicious command and control signatures (e.g. because applying the indicator is difficult or your log data is not sufficiently detailed).
- You do not monitor for user or system abnormalities indicative of adverse activity.
- Logs are monitored infrequently.
- You easily detect the presence of Indicators of Compromise (IoCs) on network and information systems supporting your essential function(s), such as known malicious command and control signatures.
- You apply some updates, new signatures and IoCs in a timely way.
- Security alerts relating to network and information systems that support your essential function(s) are prioritised.
- The enrichment of alerts within network and information systems supporting your essential function(s) is performed but not as part of the original alert.
- Detections and alerting rely on off the shelf tooling without customisation or users reporting events and potential incidents.
- There is a documented and shared process for all users who support the operation of the essential function to report events and potential security incidents.
- Where appropriate, detections and alerting result in automated actions being taken. (e.g. malware identified by AV is quarantined).
- You monitor on an irregular basis for user or system abnormalities indicative of adverse activity.
- Logs are monitored at regular intervals.
- You easily detect the presence of Indicators of Compromise (IoCs) on network and information systems supporting your essential function(s), such as known malicious command and control signatures, as well as abnormalities or behaviours indicative of adverse activity.
- You apply all updates, new signatures and IoCs promptly.
- Security alerts relating to all network and information systems supporting your essential function(s) are prioritised and this information is used to support incident management.
- Alerts are routinely enriched within network and information systems supporting your essential function(s). The enrichment of these alerts is performed in almost real time and as part of the original alert.
- Alerts and the underlying detections are regularly reviewed and tested to ensure they are generated promptly and reliably, and it is possible to distinguish genuine security incidents from false alarms.
- Alerts and the underlying detection rules are customisable and tuned to reduce false positives as well as optimising responses.
- Detections and alerting may use off the shelf tooling and rules as well as custom tooling and / or rules.
- You continuously monitor for user and system abnormalities indicative of adverse activity generating alerts based on the results of such monitoring.
- Logs are monitored continuously in near real time.
Not achieved - At least one of the following is true:
- You do not apply updates to your detection security technologies in a timely way, after receiving them (e.g. AV signature updates, other threat signatures or Indicators of Compromise (IoCs)).
- Security alerts relating to network and information systems supporting your essential function(s) are not prioritised.
- The enrichment of security alerts within network and information systems supporting your essential function(s) cannot be performed.
- You do not confidently detect the presence of IoCs on network and information systems supporting your essential function(s), such as known malicious command and control signatures (e.g. because applying the indicator is difficult or your log data is not sufficiently detailed).
- You do not monitor for user or system abnormalities indicative of adverse activity.
- Logs are monitored infrequently.
Partially achieved - All the following statements are true:
- You easily detect the presence of Indicators of Compromise (IoCs) on network and information systems supporting your essential function(s), such as known malicious command and control signatures.
- You apply some updates, new signatures and IoCs in a timely way.
- Security alerts relating to network and information systems that support your essential function(s) are prioritised.
- The enrichment of alerts within network and information systems supporting your essential function(s) is performed but not as part of the original alert.
- Detections and alerting rely on off the shelf tooling without customisation or users reporting events and potential incidents.
- There is a documented and shared process for all users who support the operation of the essential function to report events and potential security incidents.
- Where appropriate, detections and alerting result in automated actions being taken. (e.g. malware identified by AV is quarantined).
- You monitor on an irregular basis for user or system abnormalities indicative of adverse activity.
- Logs are monitored at regular intervals.
Achieved - All the following statements are true:
- You easily detect the presence of Indicators of Compromise (IoCs) on network and information systems supporting your essential function(s), such as known malicious command and control signatures, as well as abnormalities or behaviours indicative of adverse activity.
- You apply all updates, new signatures and IoCs promptly.
- Security alerts relating to all network and information systems supporting your essential function(s) are prioritised and this information is used to support incident management.
- Alerts are routinely enriched within network and information systems supporting your essential function(s). The enrichment of these alerts is performed in almost real time and as part of the original alert.
- Alerts and the underlying detections are regularly reviewed and tested to ensure they are generated promptly and reliably, and it is possible to distinguish genuine security incidents from false alarms.
- Alerts and the underlying detection rules are customisable and tuned to reduce false positives as well as optimising responses.
- Detections and alerting may use off the shelf tooling and rules as well as custom tooling and / or rules.
- You continuously monitor for user and system abnormalities indicative of adverse activity generating alerts based on the results of such monitoring.
- Logs are monitored continuously in near real time.
C1.d Triage of Security Alerts
- You contextualise alerts with knowledge of the threat and your systems, to identify those security incidents as well as responding to all alerts appropriately.
- You contextualise alerts with knowledge of the threat and your systems, to identify those security incidents as well as responding to all alerts appropriately.
- You do not triage alerts from your detection security technologies (e.g. AV, IDS).
- You do not categorise alerts and incidents by type and priority / severity level.
- You do not have Standard Operating Procedures (SOPs) / Playbooks / Runbooks available for use during triage.
- You do not keep records of triage performed.
- You do not have a sufficient understanding of normal user or system behaviour to make effective decisions within triage.
- You investigate and triage alerts from some security tools and take action.
- You have created, made available and use when appropriate, Standard Operating Procedures (SOPs) / Playbooks / Runbooks covering the most common use cases. These are regularly reviewed to ensure they remain effective.
- You perform some triage and actions taken by monitoring and detection personnel are recorded.
- You categorise alerts and incidents by type and priority / severity level.
- Your understanding of normal user or system behaviour informs your decision making within triage.
- You investigate and triage alerts from all security tools and take action.
- You have created, made available and use when appropriate, Standard Operating Procedures (SOPs) / Playbooks / Runbooks covering all plausible use cases. These are regularly reviewed to ensure they remain effective.
- You categorise alerts and incidents by type and priority / severity level.
- You document all triage related activities performed by monitoring and detection personnel and these are used to drive improvements
- Triage provides enough information for subsequent activities to be prioritised (e.g. the containment of damaging malware).
- Your understanding of normal user and system behaviour, and threats, is sufficient for effective decision making within triage.
Not achieved - At least one of the following is true:
- You do not triage alerts from your detection security technologies (e.g. AV, IDS).
- You do not categorise alerts and incidents by type and priority / severity level.
- You do not have Standard Operating Procedures (SOPs) / Playbooks / Runbooks available for use during triage.
- You do not keep records of triage performed.
- You do not have a sufficient understanding of normal user or system behaviour to make effective decisions within triage.
Partially achieved - All the following statements are true:
- You investigate and triage alerts from some security tools and take action.
- You have created, made available and use when appropriate, Standard Operating Procedures (SOPs) / Playbooks / Runbooks covering the most common use cases. These are regularly reviewed to ensure they remain effective.
- You perform some triage and actions taken by monitoring and detection personnel are recorded.
- You categorise alerts and incidents by type and priority / severity level.
- Your understanding of normal user or system behaviour informs your decision making within triage.
Achieved - All the following statements are true:
- You investigate and triage alerts from all security tools and take action.
- You have created, made available and use when appropriate, Standard Operating Procedures (SOPs) / Playbooks / Runbooks covering all plausible use cases. These are regularly reviewed to ensure they remain effective.
- You categorise alerts and incidents by type and priority / severity level.
- You document all triage related activities performed by monitoring and detection personnel and these are used to drive improvements
- Triage provides enough information for subsequent activities to be prioritised (e.g. the containment of damaging malware).
- Your understanding of normal user and system behaviour, and threats, is sufficient for effective decision making within triage.
C1.e Personnel Skills for Monitoring Tools and Detection
- Monitoring and detection personnel skills and roles, including those outsourced, reflect governance and reporting requirements, expected threats and the complexities of the network or system data they need to use. Monitoring and detection personnel have sufficient knowledge of network and information systems and the essential function(s) they need to protect.
- Monitoring and detection personnel skills and roles, including those outsourced, reflect governance and reporting requirements, expected threats and the complexities of the network or system data they need to use. Monitoring and detection personnel have sufficient knowledge of network and information systems and the essential function(s) they need to protect.
- There are no personnel who perform a monitoring and detection function.
- Monitoring and detection personnel do not have the correct specialist skills.
- Monitoring and detection personnel are not capable of reporting against governance requirements.
- Monitoring and detection personnel have a lack of awareness of the essential function(s) the organisation provides, what assets relate to those functions and hence the importance of the log data and security events.
- Monitoring and detection personnel have no awareness of other roles or tasks outside of security monitoring and detection that are relevant to the operation of your essential function(s).
- Monitoring and detection personnel are overwhelmed with the amount of data and alerts they have to work with. Alert / triage fatigue is present.
- Monitoring and detection personnel have some investigative skills and a basic understanding of the data they need to work with.
- Monitoring and detection personnel can report to other parts of the organisation (e.g. security directors, resilience managers).
- Monitoring and detection personnel are capable of following most of the required workflow(s).
- Monitoring and detection personnel are aware of some of the network and information systems and your essential function(s), and can manage alerts relating to them.
- Monitoring and detection personnel have some understanding of the operational context (e.g. people, processes, network and information systems that support your essential function(s)) to enhance the security monitoring function.
- Monitoring and detection personnel deal with their workload and cases effectively.
- You have monitoring and detection personnel who are responsible for the proactive and reactive analysis, investigation and reporting of monitoring alerts including both security and performance.
- Monitoring and detection personnel have defined roles and skills that cover all parts of the monitoring and investigation process.
- Monitoring and detection personnel follow policies, processes and procedures that address all governance reporting requirements, internal and external.
- Monitoring and detection personnel are empowered to look beyond the fixed process to investigate and understand non-standard threats.
- Monitoring and detection personnel are aware of the network and information systems and your essential function(s), related assets and can identify and prioritise alerts and investigations that relate to them.
- Monitoring and detection personnel drive and shape new log data collection and can make effective use of it.
- Monitoring and detection personnel are capable of following all of the required workflow(s).
- Monitoring and detection personnel have a sufficient understanding of the operational context (e.g. people, processes, network and information systems that support your essential function) to enhance the security monitoring function.
- Monitoring and detection personnel deal with their workload and cases effectively as well as identifying areas for improvement.
Not achieved - At least one of the following is true:
- There are no personnel who perform a monitoring and detection function.
- Monitoring and detection personnel do not have the correct specialist skills.
- Monitoring and detection personnel are not capable of reporting against governance requirements.
- Monitoring and detection personnel have a lack of awareness of the essential function(s) the organisation provides, what assets relate to those functions and hence the importance of the log data and security events.
- Monitoring and detection personnel have no awareness of other roles or tasks outside of security monitoring and detection that are relevant to the operation of your essential function(s).
- Monitoring and detection personnel are overwhelmed with the amount of data and alerts they have to work with. Alert / triage fatigue is present.
Partially achieved - All the following statements are true:
- Monitoring and detection personnel have some investigative skills and a basic understanding of the data they need to work with.
- Monitoring and detection personnel can report to other parts of the organisation (e.g. security directors, resilience managers).
- Monitoring and detection personnel are capable of following most of the required workflow(s).
- Monitoring and detection personnel are aware of some of the network and information systems and your essential function(s), and can manage alerts relating to them.
- Monitoring and detection personnel have some understanding of the operational context (e.g. people, processes, network and information systems that support your essential function(s)) to enhance the security monitoring function.
- Monitoring and detection personnel deal with their workload and cases effectively.
Achieved - All the following statements are true:
- You have monitoring and detection personnel who are responsible for the proactive and reactive analysis, investigation and reporting of monitoring alerts including both security and performance.
- Monitoring and detection personnel have defined roles and skills that cover all parts of the monitoring and investigation process.
- Monitoring and detection personnel follow policies, processes and procedures that address all governance reporting requirements, internal and external.
- Monitoring and detection personnel are empowered to look beyond the fixed process to investigate and understand non-standard threats.
- Monitoring and detection personnel are aware of the network and information systems and your essential function(s), related assets and can identify and prioritise alerts and investigations that relate to them.
- Monitoring and detection personnel drive and shape new log data collection and can make effective use of it.
- Monitoring and detection personnel are capable of following all of the required workflow(s).
- Monitoring and detection personnel have a sufficient understanding of the operational context (e.g. people, processes, network and information systems that support your essential function) to enhance the security monitoring function.
- Monitoring and detection personnel deal with their workload and cases effectively as well as identifying areas for improvement.
C1.f Understanding User's and System's Behaviour, and Threat Intelligence (within Security Monitoring)
- Threats to the operation of network and information systems, and corresponding user and system behaviour, are sufficiently understood. These are used to detect cyber security incidents.
- Threats to the operation of network and information systems, and corresponding user and system behaviour, are sufficiently understood. These are used to detect cyber security incidents.
- Your organisation has no sources of threat intelligence.
- You do not evaluate the usefulness of your threat intelligence or share feedback with providers or other users.
- You have no awareness of the steps necessary to make best use of threat intelligence for security monitoring.
- Threat intelligence is unreliable and / or is not actioned by the appropriate users or systems in a timely manner.
- You have no established understanding of what abnormalities to look for that might signify adverse activities.
- You do not receive updates for all your detection security technologies (e.g. AV, IDS).
- You do not understand normal user and system behaviour sufficiently to be able to use abnormalities to detect adverse activity.
- You know how effective your threat intelligence is (e.g. by tracking how threat intelligence helps you identify security incidents).
- Your organisation may use threat intelligence services, but you do not necessarily choose sources or providers specifically because of your business needs, or specific threats in your sector (e.g. sector-based infoshare, software vendors, anti-virus providers, specialist threat intel firms, special interest groups).
- The user and system abnormalities from past attacks and threat intelligence, on your
- and other network and information systems, are used to signify adverse activity.
- You receive regular updates for all of your detection security technologies (e.g. AV, IDS).
- You track the effectiveness of your threat intelligence and actively share feedback on the usefulness of Indicators of Compromise (IoCs) and other intelligence with the threat community (e.g. sector partners, threat intelligence providers, government agencies).
- When using threat intelligence feeds, these have been selected using risk-based and threat-informed decisions based on your business needs and sector.
- You make relevant, reliable and actionable threat intelligence available to the necessary users and systems promptly.
- You contextualise threat intelligence and link it to the why and / or how attacks take place for security monitoring.
- You understand normal user and system abnormalities fully, to such an extent that searching for system abnormalities is an effective way of detecting adverse activity (e.g. you fully understand which systems should and should not communicate and when).
- The user and system abnormalities you monitor for are based on the nature of adverse activities likely to impact network and information systems supporting the operation of your essential function(s).
- The user and system abnormalities indicative of adverse activity you use are regularly updated to reflect changes in network and information systems supporting your essential function(s) and current threat intelligence.
- You possess the capability to share threat intelligence (e.g. ways to effectively detect adversaries) with the threat community / defender community (sector partners, threat intelligence providers, government agencies) when required.
Not achieved - At least one of the following is true:
- Your organisation has no sources of threat intelligence.
- You do not evaluate the usefulness of your threat intelligence or share feedback with providers or other users.
- You have no awareness of the steps necessary to make best use of threat intelligence for security monitoring.
- Threat intelligence is unreliable and / or is not actioned by the appropriate users or systems in a timely manner.
- You have no established understanding of what abnormalities to look for that might signify adverse activities.
- You do not receive updates for all your detection security technologies (e.g. AV, IDS).
- You do not understand normal user and system behaviour sufficiently to be able to use abnormalities to detect adverse activity.
Partially achieved - All the following statements are true:
- You know how effective your threat intelligence is (e.g. by tracking how threat intelligence helps you identify security incidents).
- Your organisation may use threat intelligence services, but you do not necessarily choose sources or providers specifically because of your business needs, or specific threats in your sector (e.g. sector-based infoshare, software vendors, anti-virus providers, specialist threat intel firms, special interest groups).
- The user and system abnormalities from past attacks and threat intelligence, on your
- and other network and information systems, are used to signify adverse activity.
- You receive regular updates for all of your detection security technologies (e.g. AV, IDS).
Achieved - All the following statements are true:
- You track the effectiveness of your threat intelligence and actively share feedback on the usefulness of Indicators of Compromise (IoCs) and other intelligence with the threat community (e.g. sector partners, threat intelligence providers, government agencies).
- When using threat intelligence feeds, these have been selected using risk-based and threat-informed decisions based on your business needs and sector.
- You make relevant, reliable and actionable threat intelligence available to the necessary users and systems promptly.
- You contextualise threat intelligence and link it to the why and / or how attacks take place for security monitoring.
- You understand normal user and system abnormalities fully, to such an extent that searching for system abnormalities is an effective way of detecting adverse activity (e.g. you fully understand which systems should and should not communicate and when).
- The user and system abnormalities you monitor for are based on the nature of adverse activities likely to impact network and information systems supporting the operation of your essential function(s).
- The user and system abnormalities indicative of adverse activity you use are regularly updated to reflect changes in network and information systems supporting your essential function(s) and current threat intelligence.
- You possess the capability to share threat intelligence (e.g. ways to effectively detect adversaries) with the threat community / defender community (sector partners, threat intelligence providers, government agencies) when required.
The organisation monitors the security status of network and information systems supporting the operation of essential function(s) in order to detect security events indicative of a security incident.
Description
error determining description
Guidance
One clear focus of your security monitoring should be the detection of incidents or activity that is likely to have an adverse impact on the network and information systems that support the operation of essential functions. Log data collection, secure storage, analysis tools, understanding your network and information systems that support your essential function(s), threat intelligence and personnel skills should all be used to build an effective security monitoring capability.
An organisation's automated monitoring capability should be able to find threats within their network and information systems by using both signature-based detections and, behavioural and anomaly-based detections.
Examples of signature-based detections are detecting when known command and control traffic is communicating to the internet, or an AV signature is present in a file. Organisations should endeavour to understand what automated detections and alerting do and how best to use them, to ensure they are making the most of the monitoring solution / as well as being as effective as possible.
Organisations should also have the capability to find threats by using behavioural and anomaly-based detections, for example by detecting an abnormally large amount of data being exfiltrated or AV detecting unusual changes to start up registry keys.
Both signature and, anomaly and behaviour-based detections rely on an understanding of indicators of compromise, your network and information systems, user behaviour and threats.
Contributing Outcomes
C1.a Sources and Tools for Logging and Monitoring
- The data sources that you include in your logging and monitoring allow for timely identification of events which might adversely affect the resiliency of network and information system(s) supporting the operation of your essential function(s).
- The data sources that you include in your logging and monitoring allow for timely identification of events which might adversely affect the resiliency of network and information system(s) supporting the operation of your essential function(s).
- Data relating to the security and operation of network and information systems supporting your essential function(s) is not collected.
- You are not able to audit the activities of users and systems in relation to network and information systems supporting your essential function(s).
- You do not monitor traffic crossing your network boundary.
- Log data cannot be synchronised using an accurate common time source.
- Logs are stored in locations where they are not readily available to authorised users and systems.
- Your monitoring tools cannot be configured to make use of new log streams as they come online.
- Your monitoring tools are only able to make use of a fraction of the log data being collected.
- You do not understand where log data is stored or how long it should be stored for.
- You have no way of ensuring log data is being captured as expected and available when needed.
- Data relating to the security and operation of some areas of network and information systems supporting your essential function(s) is collected but coverage is not comprehensive.
- Some user and system monitoring is done, but not covering a fully agreed list of suspicious or undesirable behaviour.
- You monitor traffic crossing your network boundary (including IP address connections as a minimum).
- Some but not all log datasets can be easily queried with search tools to aid in investigations.
- Your monitoring tools work with most log data, with some configuration.
- Your monitoring tools can make use of log data that would capture all common threats.
- You ensure log data is available for analysis when needed.
- Monitoring is based on a thorough understanding of network and information systems supporting your essential function(s), techniques used by threat actors, and awareness of what logging and monitoring is required to detect events and incidents that could affect the operation of your essential function(s).
- Your monitoring data provides enough detail to promptly and reliably detect security events, incidents and support investigations. This is reviewed regularly and after a significant security event.
- Extensive monitoring of user and system activity in relation to network and information systems that support your essential function(s) enables you to promptly detect policy violations, suspicious or undesirable user and system behaviour, deviations from normal / routine behaviour or abnormalities indicative of adverse activity.
- Your logging and monitoring capability includes host-based and network monitoring.
- All new network and information systems supporting your essential function(s) are considered as potential logging and monitoring data sources to maintain a comprehensive monitoring capability.
- Log datasets are synchronised including using an accurate common time source so that separate datasets can be correlated in appropriate ways.
- You enrich log data with other network and information systems data to provide a more comprehensive picture of actions and behaviours.
- Your monitoring tools make use of log data to pinpoint activity.
- You regularly review the data sources and tools included in your logging and monitoring strategy to ensure it remains effective.
Not achieved - At least one of the following statements is true:
- Data relating to the security and operation of network and information systems supporting your essential function(s) is not collected.
- You are not able to audit the activities of users and systems in relation to network and information systems supporting your essential function(s).
- You do not monitor traffic crossing your network boundary.
- Log data cannot be synchronised using an accurate common time source.
- Logs are stored in locations where they are not readily available to authorised users and systems.
- Your monitoring tools cannot be configured to make use of new log streams as they come online.
- Your monitoring tools are only able to make use of a fraction of the log data being collected.
- You do not understand where log data is stored or how long it should be stored for.
- You have no way of ensuring log data is being captured as expected and available when needed.
Partially achieved - All the following statements are true:
- Data relating to the security and operation of some areas of network and information systems supporting your essential function(s) is collected but coverage is not comprehensive.
- Some user and system monitoring is done, but not covering a fully agreed list of suspicious or undesirable behaviour.
- You monitor traffic crossing your network boundary (including IP address connections as a minimum).
- Some but not all log datasets can be easily queried with search tools to aid in investigations.
- Your monitoring tools work with most log data, with some configuration.
- Your monitoring tools can make use of log data that would capture all common threats.
- You ensure log data is available for analysis when needed.
Achieved - All the following statements are true:
- Monitoring is based on a thorough understanding of network and information systems supporting your essential function(s), techniques used by threat actors, and awareness of what logging and monitoring is required to detect events and incidents that could affect the operation of your essential function(s).
- Your monitoring data provides enough detail to promptly and reliably detect security events, incidents and support investigations. This is reviewed regularly and after a significant security event.
- Extensive monitoring of user and system activity in relation to network and information systems that support your essential function(s) enables you to promptly detect policy violations, suspicious or undesirable user and system behaviour, deviations from normal / routine behaviour or abnormalities indicative of adverse activity.
- Your logging and monitoring capability includes host-based and network monitoring.
- All new network and information systems supporting your essential function(s) are considered as potential logging and monitoring data sources to maintain a comprehensive monitoring capability.
- Log datasets are synchronised including using an accurate common time source so that separate datasets can be correlated in appropriate ways.
- You enrich log data with other network and information systems data to provide a more comprehensive picture of actions and behaviours.
- Your monitoring tools make use of log data to pinpoint activity.
- You regularly review the data sources and tools included in your logging and monitoring strategy to ensure it remains effective.
C1.b Securing Logs
- You hold log data securely and grant appropriate user and system access only to accounts with a business need. Log data is held for a suitable retention period, after which it is deleted.
- You hold log data securely and grant appropriate user and system access only to accounts with a business need. Log data is held for a suitable retention period, after which it is deleted.
- It is possible for log data to be easily edited or deleted by unauthorised users or malicious attackers.
- There is no controlled list of the users and systems that can view and query log data.
- There is no monitoring of the access to log data.
- There are no policies for accessing to log data.
- Only authorised users and systems can access log data.
- There is some monitoring of access to log data (e.g. copying, deleting or modification, or even viewing).
- You have defined and implemented retention periods for log data.
- You have given legitimate reasons for accessing log data in your policies.
- Appropriate access to log data is limited to those users and systems with a business need.
- The logging architecture has mechanisms, policies, processes and procedures to ensure that it can protect itself from threats comparable to those that it is trying to identify. This includes protecting the function itself and the data within it.
- Log data analysis and normalisation is only performed on copies of the log data keeping the master copy unaltered.
- All actions involving log data (e.g. copying, deleting, modification, or even viewing) can be traced back to a unique user or system.
- The integrity of log data is protected, verified and any modification, including deletion, is detected and attributed.
Not achieved - At least one of the following is true:
- It is possible for log data to be easily edited or deleted by unauthorised users or malicious attackers.
- There is no controlled list of the users and systems that can view and query log data.
- There is no monitoring of the access to log data.
- There are no policies for accessing to log data.
Partially achieved - All the following statements are true:
- Only authorised users and systems can access log data.
- There is some monitoring of access to log data (e.g. copying, deleting or modification, or even viewing).
- You have defined and implemented retention periods for log data.
- You have given legitimate reasons for accessing log data in your policies.
Achieved - All the following statements are true:
- Appropriate access to log data is limited to those users and systems with a business need.
- The logging architecture has mechanisms, policies, processes and procedures to ensure that it can protect itself from threats comparable to those that it is trying to identify. This includes protecting the function itself and the data within it.
- Log data analysis and normalisation is only performed on copies of the log data keeping the master copy unaltered.
- All actions involving log data (e.g. copying, deleting, modification, or even viewing) can be traced back to a unique user or system.
- The integrity of log data is protected, verified and any modification, including deletion, is detected and attributed.
C1.c Generating Alerts
- Evidence of potential security incidents contained in your monitoring data is reliably identified and where appropriate triggers alerts.
- Evidence of potential security incidents contained in your monitoring data is reliably identified and where appropriate triggers alerts.
- You do not apply updates to your detection security technologies in a timely way, after receiving them (e.g. AV signature updates, other threat signatures or Indicators of Compromise (IoCs)).
- Security alerts relating to network and information systems supporting your essential function(s) are not prioritised.
- The enrichment of security alerts within network and information systems supporting your essential function(s) cannot be performed.
- You do not confidently detect the presence of IoCs on network and information systems supporting your essential function(s), such as known malicious command and control signatures (e.g. because applying the indicator is difficult or your log data is not sufficiently detailed).
- You do not monitor for user or system abnormalities indicative of adverse activity.
- Logs are monitored infrequently.
- You easily detect the presence of Indicators of Compromise (IoCs) on network and information systems supporting your essential function(s), such as known malicious command and control signatures.
- You apply some updates, new signatures and IoCs in a timely way.
- Security alerts relating to network and information systems that support your essential function(s) are prioritised.
- The enrichment of alerts within network and information systems supporting your essential function(s) is performed but not as part of the original alert.
- Detections and alerting rely on off the shelf tooling without customisation or users reporting events and potential incidents.
- There is a documented and shared process for all users who support the operation of the essential function to report events and potential security incidents.
- Where appropriate, detections and alerting result in automated actions being taken. (e.g. malware identified by AV is quarantined).
- You monitor on an irregular basis for user or system abnormalities indicative of adverse activity.
- Logs are monitored at regular intervals.
- You easily detect the presence of Indicators of Compromise (IoCs) on network and information systems supporting your essential function(s), such as known malicious command and control signatures, as well as abnormalities or behaviours indicative of adverse activity.
- You apply all updates, new signatures and IoCs promptly.
- Security alerts relating to all network and information systems supporting your essential function(s) are prioritised and this information is used to support incident management.
- Alerts are routinely enriched within network and information systems supporting your essential function(s). The enrichment of these alerts is performed in almost real time and as part of the original alert.
- Alerts and the underlying detections are regularly reviewed and tested to ensure they are generated promptly and reliably, and it is possible to distinguish genuine security incidents from false alarms.
- Alerts and the underlying detection rules are customisable and tuned to reduce false positives as well as optimising responses.
- Detections and alerting may use off the shelf tooling and rules as well as custom tooling and / or rules.
- You continuously monitor for user and system abnormalities indicative of adverse activity generating alerts based on the results of such monitoring.
- Logs are monitored continuously in near real time.
Not achieved - At least one of the following is true:
- You do not apply updates to your detection security technologies in a timely way, after receiving them (e.g. AV signature updates, other threat signatures or Indicators of Compromise (IoCs)).
- Security alerts relating to network and information systems supporting your essential function(s) are not prioritised.
- The enrichment of security alerts within network and information systems supporting your essential function(s) cannot be performed.
- You do not confidently detect the presence of IoCs on network and information systems supporting your essential function(s), such as known malicious command and control signatures (e.g. because applying the indicator is difficult or your log data is not sufficiently detailed).
- You do not monitor for user or system abnormalities indicative of adverse activity.
- Logs are monitored infrequently.
Partially achieved - All the following statements are true:
- You easily detect the presence of Indicators of Compromise (IoCs) on network and information systems supporting your essential function(s), such as known malicious command and control signatures.
- You apply some updates, new signatures and IoCs in a timely way.
- Security alerts relating to network and information systems that support your essential function(s) are prioritised.
- The enrichment of alerts within network and information systems supporting your essential function(s) is performed but not as part of the original alert.
- Detections and alerting rely on off the shelf tooling without customisation or users reporting events and potential incidents.
- There is a documented and shared process for all users who support the operation of the essential function to report events and potential security incidents.
- Where appropriate, detections and alerting result in automated actions being taken. (e.g. malware identified by AV is quarantined).
- You monitor on an irregular basis for user or system abnormalities indicative of adverse activity.
- Logs are monitored at regular intervals.
Achieved - All the following statements are true:
- You easily detect the presence of Indicators of Compromise (IoCs) on network and information systems supporting your essential function(s), such as known malicious command and control signatures, as well as abnormalities or behaviours indicative of adverse activity.
- You apply all updates, new signatures and IoCs promptly.
- Security alerts relating to all network and information systems supporting your essential function(s) are prioritised and this information is used to support incident management.
- Alerts are routinely enriched within network and information systems supporting your essential function(s). The enrichment of these alerts is performed in almost real time and as part of the original alert.
- Alerts and the underlying detections are regularly reviewed and tested to ensure they are generated promptly and reliably, and it is possible to distinguish genuine security incidents from false alarms.
- Alerts and the underlying detection rules are customisable and tuned to reduce false positives as well as optimising responses.
- Detections and alerting may use off the shelf tooling and rules as well as custom tooling and / or rules.
- You continuously monitor for user and system abnormalities indicative of adverse activity generating alerts based on the results of such monitoring.
- Logs are monitored continuously in near real time.
C1.d Triage of Security Alerts
- You contextualise alerts with knowledge of the threat and your systems, to identify those security incidents as well as responding to all alerts appropriately.
- You contextualise alerts with knowledge of the threat and your systems, to identify those security incidents as well as responding to all alerts appropriately.
- You do not triage alerts from your detection security technologies (e.g. AV, IDS).
- You do not categorise alerts and incidents by type and priority / severity level.
- You do not have Standard Operating Procedures (SOPs) / Playbooks / Runbooks available for use during triage.
- You do not keep records of triage performed.
- You do not have a sufficient understanding of normal user or system behaviour to make effective decisions within triage.
- You investigate and triage alerts from some security tools and take action.
- You have created, made available and use when appropriate, Standard Operating Procedures (SOPs) / Playbooks / Runbooks covering the most common use cases. These are regularly reviewed to ensure they remain effective.
- You perform some triage and actions taken by monitoring and detection personnel are recorded.
- You categorise alerts and incidents by type and priority / severity level.
- Your understanding of normal user or system behaviour informs your decision making within triage.
- You investigate and triage alerts from all security tools and take action.
- You have created, made available and use when appropriate, Standard Operating Procedures (SOPs) / Playbooks / Runbooks covering all plausible use cases. These are regularly reviewed to ensure they remain effective.
- You categorise alerts and incidents by type and priority / severity level.
- You document all triage related activities performed by monitoring and detection personnel and these are used to drive improvements
- Triage provides enough information for subsequent activities to be prioritised (e.g. the containment of damaging malware).
- Your understanding of normal user and system behaviour, and threats, is sufficient for effective decision making within triage.
Not achieved - At least one of the following is true:
- You do not triage alerts from your detection security technologies (e.g. AV, IDS).
- You do not categorise alerts and incidents by type and priority / severity level.
- You do not have Standard Operating Procedures (SOPs) / Playbooks / Runbooks available for use during triage.
- You do not keep records of triage performed.
- You do not have a sufficient understanding of normal user or system behaviour to make effective decisions within triage.
Partially achieved - All the following statements are true:
- You investigate and triage alerts from some security tools and take action.
- You have created, made available and use when appropriate, Standard Operating Procedures (SOPs) / Playbooks / Runbooks covering the most common use cases. These are regularly reviewed to ensure they remain effective.
- You perform some triage and actions taken by monitoring and detection personnel are recorded.
- You categorise alerts and incidents by type and priority / severity level.
- Your understanding of normal user or system behaviour informs your decision making within triage.
Achieved - All the following statements are true:
- You investigate and triage alerts from all security tools and take action.
- You have created, made available and use when appropriate, Standard Operating Procedures (SOPs) / Playbooks / Runbooks covering all plausible use cases. These are regularly reviewed to ensure they remain effective.
- You categorise alerts and incidents by type and priority / severity level.
- You document all triage related activities performed by monitoring and detection personnel and these are used to drive improvements
- Triage provides enough information for subsequent activities to be prioritised (e.g. the containment of damaging malware).
- Your understanding of normal user and system behaviour, and threats, is sufficient for effective decision making within triage.
C1.e Personnel Skills for Monitoring Tools and Detection
- Monitoring and detection personnel skills and roles, including those outsourced, reflect governance and reporting requirements, expected threats and the complexities of the network or system data they need to use. Monitoring and detection personnel have sufficient knowledge of network and information systems and the essential function(s) they need to protect.
- Monitoring and detection personnel skills and roles, including those outsourced, reflect governance and reporting requirements, expected threats and the complexities of the network or system data they need to use. Monitoring and detection personnel have sufficient knowledge of network and information systems and the essential function(s) they need to protect.
- There are no personnel who perform a monitoring and detection function.
- Monitoring and detection personnel do not have the correct specialist skills.
- Monitoring and detection personnel are not capable of reporting against governance requirements.
- Monitoring and detection personnel have a lack of awareness of the essential function(s) the organisation provides, what assets relate to those functions and hence the importance of the log data and security events.
- Monitoring and detection personnel have no awareness of other roles or tasks outside of security monitoring and detection that are relevant to the operation of your essential function(s).
- Monitoring and detection personnel are overwhelmed with the amount of data and alerts they have to work with. Alert / triage fatigue is present.
- Monitoring and detection personnel have some investigative skills and a basic understanding of the data they need to work with.
- Monitoring and detection personnel can report to other parts of the organisation (e.g. security directors, resilience managers).
- Monitoring and detection personnel are capable of following most of the required workflow(s).
- Monitoring and detection personnel are aware of some of the network and information systems and your essential function(s), and can manage alerts relating to them.
- Monitoring and detection personnel have some understanding of the operational context (e.g. people, processes, network and information systems that support your essential function(s)) to enhance the security monitoring function.
- Monitoring and detection personnel deal with their workload and cases effectively.
- You have monitoring and detection personnel who are responsible for the proactive and reactive analysis, investigation and reporting of monitoring alerts including both security and performance.
- Monitoring and detection personnel have defined roles and skills that cover all parts of the monitoring and investigation process.
- Monitoring and detection personnel follow policies, processes and procedures that address all governance reporting requirements, internal and external.
- Monitoring and detection personnel are empowered to look beyond the fixed process to investigate and understand non-standard threats.
- Monitoring and detection personnel are aware of the network and information systems and your essential function(s), related assets and can identify and prioritise alerts and investigations that relate to them.
- Monitoring and detection personnel drive and shape new log data collection and can make effective use of it.
- Monitoring and detection personnel are capable of following all of the required workflow(s).
- Monitoring and detection personnel have a sufficient understanding of the operational context (e.g. people, processes, network and information systems that support your essential function) to enhance the security monitoring function.
- Monitoring and detection personnel deal with their workload and cases effectively as well as identifying areas for improvement.
Not achieved - At least one of the following is true:
- There are no personnel who perform a monitoring and detection function.
- Monitoring and detection personnel do not have the correct specialist skills.
- Monitoring and detection personnel are not capable of reporting against governance requirements.
- Monitoring and detection personnel have a lack of awareness of the essential function(s) the organisation provides, what assets relate to those functions and hence the importance of the log data and security events.
- Monitoring and detection personnel have no awareness of other roles or tasks outside of security monitoring and detection that are relevant to the operation of your essential function(s).
- Monitoring and detection personnel are overwhelmed with the amount of data and alerts they have to work with. Alert / triage fatigue is present.
Partially achieved - All the following statements are true:
- Monitoring and detection personnel have some investigative skills and a basic understanding of the data they need to work with.
- Monitoring and detection personnel can report to other parts of the organisation (e.g. security directors, resilience managers).
- Monitoring and detection personnel are capable of following most of the required workflow(s).
- Monitoring and detection personnel are aware of some of the network and information systems and your essential function(s), and can manage alerts relating to them.
- Monitoring and detection personnel have some understanding of the operational context (e.g. people, processes, network and information systems that support your essential function(s)) to enhance the security monitoring function.
- Monitoring and detection personnel deal with their workload and cases effectively.
Achieved - All the following statements are true:
- You have monitoring and detection personnel who are responsible for the proactive and reactive analysis, investigation and reporting of monitoring alerts including both security and performance.
- Monitoring and detection personnel have defined roles and skills that cover all parts of the monitoring and investigation process.
- Monitoring and detection personnel follow policies, processes and procedures that address all governance reporting requirements, internal and external.
- Monitoring and detection personnel are empowered to look beyond the fixed process to investigate and understand non-standard threats.
- Monitoring and detection personnel are aware of the network and information systems and your essential function(s), related assets and can identify and prioritise alerts and investigations that relate to them.
- Monitoring and detection personnel drive and shape new log data collection and can make effective use of it.
- Monitoring and detection personnel are capable of following all of the required workflow(s).
- Monitoring and detection personnel have a sufficient understanding of the operational context (e.g. people, processes, network and information systems that support your essential function) to enhance the security monitoring function.
- Monitoring and detection personnel deal with their workload and cases effectively as well as identifying areas for improvement.
C1.f Understanding User's and System's Behaviour, and Threat Intelligence (within Security Monitoring)
- Threats to the operation of network and information systems, and corresponding user and system behaviour, are sufficiently understood. These are used to detect cyber security incidents.
- Threats to the operation of network and information systems, and corresponding user and system behaviour, are sufficiently understood. These are used to detect cyber security incidents.
- Your organisation has no sources of threat intelligence.
- You do not evaluate the usefulness of your threat intelligence or share feedback with providers or other users.
- You have no awareness of the steps necessary to make best use of threat intelligence for security monitoring.
- Threat intelligence is unreliable and / or is not actioned by the appropriate users or systems in a timely manner.
- You have no established understanding of what abnormalities to look for that might signify adverse activities.
- You do not receive updates for all your detection security technologies (e.g. AV, IDS).
- You do not understand normal user and system behaviour sufficiently to be able to use abnormalities to detect adverse activity.
- You know how effective your threat intelligence is (e.g. by tracking how threat intelligence helps you identify security incidents).
- Your organisation may use threat intelligence services, but you do not necessarily choose sources or providers specifically because of your business needs, or specific threats in your sector (e.g. sector-based infoshare, software vendors, anti-virus providers, specialist threat intel firms, special interest groups).
- The user and system abnormalities from past attacks and threat intelligence, on your
- and other network and information systems, are used to signify adverse activity.
- You receive regular updates for all of your detection security technologies (e.g. AV, IDS).
- You track the effectiveness of your threat intelligence and actively share feedback on the usefulness of Indicators of Compromise (IoCs) and other intelligence with the threat community (e.g. sector partners, threat intelligence providers, government agencies).
- When using threat intelligence feeds, these have been selected using risk-based and threat-informed decisions based on your business needs and sector.
- You make relevant, reliable and actionable threat intelligence available to the necessary users and systems promptly.
- You contextualise threat intelligence and link it to the why and / or how attacks take place for security monitoring.
- You understand normal user and system abnormalities fully, to such an extent that searching for system abnormalities is an effective way of detecting adverse activity (e.g. you fully understand which systems should and should not communicate and when).
- The user and system abnormalities you monitor for are based on the nature of adverse activities likely to impact network and information systems supporting the operation of your essential function(s).
- The user and system abnormalities indicative of adverse activity you use are regularly updated to reflect changes in network and information systems supporting your essential function(s) and current threat intelligence.
- You possess the capability to share threat intelligence (e.g. ways to effectively detect adversaries) with the threat community / defender community (sector partners, threat intelligence providers, government agencies) when required.
Not achieved - At least one of the following is true:
- Your organisation has no sources of threat intelligence.
- You do not evaluate the usefulness of your threat intelligence or share feedback with providers or other users.
- You have no awareness of the steps necessary to make best use of threat intelligence for security monitoring.
- Threat intelligence is unreliable and / or is not actioned by the appropriate users or systems in a timely manner.
- You have no established understanding of what abnormalities to look for that might signify adverse activities.
- You do not receive updates for all your detection security technologies (e.g. AV, IDS).
- You do not understand normal user and system behaviour sufficiently to be able to use abnormalities to detect adverse activity.
Partially achieved - All the following statements are true:
- You know how effective your threat intelligence is (e.g. by tracking how threat intelligence helps you identify security incidents).
- Your organisation may use threat intelligence services, but you do not necessarily choose sources or providers specifically because of your business needs, or specific threats in your sector (e.g. sector-based infoshare, software vendors, anti-virus providers, specialist threat intel firms, special interest groups).
- The user and system abnormalities from past attacks and threat intelligence, on your
- and other network and information systems, are used to signify adverse activity.
- You receive regular updates for all of your detection security technologies (e.g. AV, IDS).
Achieved - All the following statements are true:
- You track the effectiveness of your threat intelligence and actively share feedback on the usefulness of Indicators of Compromise (IoCs) and other intelligence with the threat community (e.g. sector partners, threat intelligence providers, government agencies).
- When using threat intelligence feeds, these have been selected using risk-based and threat-informed decisions based on your business needs and sector.
- You make relevant, reliable and actionable threat intelligence available to the necessary users and systems promptly.
- You contextualise threat intelligence and link it to the why and / or how attacks take place for security monitoring.
- You understand normal user and system abnormalities fully, to such an extent that searching for system abnormalities is an effective way of detecting adverse activity (e.g. you fully understand which systems should and should not communicate and when).
- The user and system abnormalities you monitor for are based on the nature of adverse activities likely to impact network and information systems supporting the operation of your essential function(s).
- The user and system abnormalities indicative of adverse activity you use are regularly updated to reflect changes in network and information systems supporting your essential function(s) and current threat intelligence.
- You possess the capability to share threat intelligence (e.g. ways to effectively detect adversaries) with the threat community / defender community (sector partners, threat intelligence providers, government agencies) when required.
The organisation monitors the security status of network and information systems supporting the operation of essential function(s) in order to detect security events indicative of a security incident.
Description
error determining description
Guidance
One clear focus of your security monitoring should be the detection of incidents or activity that is likely to have an adverse impact on the network and information systems that support the operation of essential functions. Log data collection, secure storage, analysis tools, understanding your network and information systems that support your essential function(s), threat intelligence and personnel skills should all be used to build an effective security monitoring capability.
An organisation's automated monitoring capability should be able to find threats within their network and information systems by using both signature-based detections and, behavioural and anomaly-based detections.
Examples of signature-based detections are detecting when known command and control traffic is communicating to the internet, or an AV signature is present in a file. Organisations should endeavour to understand what automated detections and alerting do and how best to use them, to ensure they are making the most of the monitoring solution / as well as being as effective as possible.
Organisations should also have the capability to find threats by using behavioural and anomaly-based detections, for example by detecting an abnormally large amount of data being exfiltrated or AV detecting unusual changes to start up registry keys.
Both signature and, anomaly and behaviour-based detections rely on an understanding of indicators of compromise, your network and information systems, user behaviour and threats.
Contributing Outcomes
C1.a Sources and Tools for Logging and Monitoring
- The data sources that you include in your logging and monitoring allow for timely identification of events which might adversely affect the resiliency of network and information system(s) supporting the operation of your essential function(s).
- The data sources that you include in your logging and monitoring allow for timely identification of events which might adversely affect the resiliency of network and information system(s) supporting the operation of your essential function(s).
- Data relating to the security and operation of network and information systems supporting your essential function(s) is not collected.
- You are not able to audit the activities of users and systems in relation to network and information systems supporting your essential function(s).
- You do not monitor traffic crossing your network boundary.
- Log data cannot be synchronised using an accurate common time source.
- Logs are stored in locations where they are not readily available to authorised users and systems.
- Your monitoring tools cannot be configured to make use of new log streams as they come online.
- Your monitoring tools are only able to make use of a fraction of the log data being collected.
- You do not understand where log data is stored or how long it should be stored for.
- You have no way of ensuring log data is being captured as expected and available when needed.
- Data relating to the security and operation of some areas of network and information systems supporting your essential function(s) is collected but coverage is not comprehensive.
- Some user and system monitoring is done, but not covering a fully agreed list of suspicious or undesirable behaviour.
- You monitor traffic crossing your network boundary (including IP address connections as a minimum).
- Some but not all log datasets can be easily queried with search tools to aid in investigations.
- Your monitoring tools work with most log data, with some configuration.
- Your monitoring tools can make use of log data that would capture all common threats.
- You ensure log data is available for analysis when needed.
- Monitoring is based on a thorough understanding of network and information systems supporting your essential function(s), techniques used by threat actors, and awareness of what logging and monitoring is required to detect events and incidents that could affect the operation of your essential function(s).
- Your monitoring data provides enough detail to promptly and reliably detect security events, incidents and support investigations. This is reviewed regularly and after a significant security event.
- Extensive monitoring of user and system activity in relation to network and information systems that support your essential function(s) enables you to promptly detect policy violations, suspicious or undesirable user and system behaviour, deviations from normal / routine behaviour or abnormalities indicative of adverse activity.
- Your logging and monitoring capability includes host-based and network monitoring.
- All new network and information systems supporting your essential function(s) are considered as potential logging and monitoring data sources to maintain a comprehensive monitoring capability.
- Log datasets are synchronised including using an accurate common time source so that separate datasets can be correlated in appropriate ways.
- You enrich log data with other network and information systems data to provide a more comprehensive picture of actions and behaviours.
- Your monitoring tools make use of log data to pinpoint activity.
- You regularly review the data sources and tools included in your logging and monitoring strategy to ensure it remains effective.
Not achieved - At least one of the following statements is true:
- Data relating to the security and operation of network and information systems supporting your essential function(s) is not collected.
- You are not able to audit the activities of users and systems in relation to network and information systems supporting your essential function(s).
- You do not monitor traffic crossing your network boundary.
- Log data cannot be synchronised using an accurate common time source.
- Logs are stored in locations where they are not readily available to authorised users and systems.
- Your monitoring tools cannot be configured to make use of new log streams as they come online.
- Your monitoring tools are only able to make use of a fraction of the log data being collected.
- You do not understand where log data is stored or how long it should be stored for.
- You have no way of ensuring log data is being captured as expected and available when needed.
Partially achieved - All the following statements are true:
- Data relating to the security and operation of some areas of network and information systems supporting your essential function(s) is collected but coverage is not comprehensive.
- Some user and system monitoring is done, but not covering a fully agreed list of suspicious or undesirable behaviour.
- You monitor traffic crossing your network boundary (including IP address connections as a minimum).
- Some but not all log datasets can be easily queried with search tools to aid in investigations.
- Your monitoring tools work with most log data, with some configuration.
- Your monitoring tools can make use of log data that would capture all common threats.
- You ensure log data is available for analysis when needed.
Achieved - All the following statements are true:
- Monitoring is based on a thorough understanding of network and information systems supporting your essential function(s), techniques used by threat actors, and awareness of what logging and monitoring is required to detect events and incidents that could affect the operation of your essential function(s).
- Your monitoring data provides enough detail to promptly and reliably detect security events, incidents and support investigations. This is reviewed regularly and after a significant security event.
- Extensive monitoring of user and system activity in relation to network and information systems that support your essential function(s) enables you to promptly detect policy violations, suspicious or undesirable user and system behaviour, deviations from normal / routine behaviour or abnormalities indicative of adverse activity.
- Your logging and monitoring capability includes host-based and network monitoring.
- All new network and information systems supporting your essential function(s) are considered as potential logging and monitoring data sources to maintain a comprehensive monitoring capability.
- Log datasets are synchronised including using an accurate common time source so that separate datasets can be correlated in appropriate ways.
- You enrich log data with other network and information systems data to provide a more comprehensive picture of actions and behaviours.
- Your monitoring tools make use of log data to pinpoint activity.
- You regularly review the data sources and tools included in your logging and monitoring strategy to ensure it remains effective.
C1.b Securing Logs
- You hold log data securely and grant appropriate user and system access only to accounts with a business need. Log data is held for a suitable retention period, after which it is deleted.
- You hold log data securely and grant appropriate user and system access only to accounts with a business need. Log data is held for a suitable retention period, after which it is deleted.
- It is possible for log data to be easily edited or deleted by unauthorised users or malicious attackers.
- There is no controlled list of the users and systems that can view and query log data.
- There is no monitoring of the access to log data.
- There are no policies for accessing to log data.
- Only authorised users and systems can access log data.
- There is some monitoring of access to log data (e.g. copying, deleting or modification, or even viewing).
- You have defined and implemented retention periods for log data.
- You have given legitimate reasons for accessing log data in your policies.
- Appropriate access to log data is limited to those users and systems with a business need.
- The logging architecture has mechanisms, policies, processes and procedures to ensure that it can protect itself from threats comparable to those that it is trying to identify. This includes protecting the function itself and the data within it.
- Log data analysis and normalisation is only performed on copies of the log data keeping the master copy unaltered.
- All actions involving log data (e.g. copying, deleting, modification, or even viewing) can be traced back to a unique user or system.
- The integrity of log data is protected, verified and any modification, including deletion, is detected and attributed.
Not achieved - At least one of the following is true:
- It is possible for log data to be easily edited or deleted by unauthorised users or malicious attackers.
- There is no controlled list of the users and systems that can view and query log data.
- There is no monitoring of the access to log data.
- There are no policies for accessing to log data.
Partially achieved - All the following statements are true:
- Only authorised users and systems can access log data.
- There is some monitoring of access to log data (e.g. copying, deleting or modification, or even viewing).
- You have defined and implemented retention periods for log data.
- You have given legitimate reasons for accessing log data in your policies.
Achieved - All the following statements are true:
- Appropriate access to log data is limited to those users and systems with a business need.
- The logging architecture has mechanisms, policies, processes and procedures to ensure that it can protect itself from threats comparable to those that it is trying to identify. This includes protecting the function itself and the data within it.
- Log data analysis and normalisation is only performed on copies of the log data keeping the master copy unaltered.
- All actions involving log data (e.g. copying, deleting, modification, or even viewing) can be traced back to a unique user or system.
- The integrity of log data is protected, verified and any modification, including deletion, is detected and attributed.
C1.c Generating Alerts
- Evidence of potential security incidents contained in your monitoring data is reliably identified and where appropriate triggers alerts.
- Evidence of potential security incidents contained in your monitoring data is reliably identified and where appropriate triggers alerts.
- You do not apply updates to your detection security technologies in a timely way, after receiving them (e.g. AV signature updates, other threat signatures or Indicators of Compromise (IoCs)).
- Security alerts relating to network and information systems supporting your essential function(s) are not prioritised.
- The enrichment of security alerts within network and information systems supporting your essential function(s) cannot be performed.
- You do not confidently detect the presence of IoCs on network and information systems supporting your essential function(s), such as known malicious command and control signatures (e.g. because applying the indicator is difficult or your log data is not sufficiently detailed).
- You do not monitor for user or system abnormalities indicative of adverse activity.
- Logs are monitored infrequently.
- You easily detect the presence of Indicators of Compromise (IoCs) on network and information systems supporting your essential function(s), such as known malicious command and control signatures.
- You apply some updates, new signatures and IoCs in a timely way.
- Security alerts relating to network and information systems that support your essential function(s) are prioritised.
- The enrichment of alerts within network and information systems supporting your essential function(s) is performed but not as part of the original alert.
- Detections and alerting rely on off the shelf tooling without customisation or users reporting events and potential incidents.
- There is a documented and shared process for all users who support the operation of the essential function to report events and potential security incidents.
- Where appropriate, detections and alerting result in automated actions being taken. (e.g. malware identified by AV is quarantined).
- You monitor on an irregular basis for user or system abnormalities indicative of adverse activity.
- Logs are monitored at regular intervals.
- You easily detect the presence of Indicators of Compromise (IoCs) on network and information systems supporting your essential function(s), such as known malicious command and control signatures, as well as abnormalities or behaviours indicative of adverse activity.
- You apply all updates, new signatures and IoCs promptly.
- Security alerts relating to all network and information systems supporting your essential function(s) are prioritised and this information is used to support incident management.
- Alerts are routinely enriched within network and information systems supporting your essential function(s). The enrichment of these alerts is performed in almost real time and as part of the original alert.
- Alerts and the underlying detections are regularly reviewed and tested to ensure they are generated promptly and reliably, and it is possible to distinguish genuine security incidents from false alarms.
- Alerts and the underlying detection rules are customisable and tuned to reduce false positives as well as optimising responses.
- Detections and alerting may use off the shelf tooling and rules as well as custom tooling and / or rules.
- You continuously monitor for user and system abnormalities indicative of adverse activity generating alerts based on the results of such monitoring.
- Logs are monitored continuously in near real time.
Not achieved - At least one of the following is true:
- You do not apply updates to your detection security technologies in a timely way, after receiving them (e.g. AV signature updates, other threat signatures or Indicators of Compromise (IoCs)).
- Security alerts relating to network and information systems supporting your essential function(s) are not prioritised.
- The enrichment of security alerts within network and information systems supporting your essential function(s) cannot be performed.
- You do not confidently detect the presence of IoCs on network and information systems supporting your essential function(s), such as known malicious command and control signatures (e.g. because applying the indicator is difficult or your log data is not sufficiently detailed).
- You do not monitor for user or system abnormalities indicative of adverse activity.
- Logs are monitored infrequently.
Partially achieved - All the following statements are true:
- You easily detect the presence of Indicators of Compromise (IoCs) on network and information systems supporting your essential function(s), such as known malicious command and control signatures.
- You apply some updates, new signatures and IoCs in a timely way.
- Security alerts relating to network and information systems that support your essential function(s) are prioritised.
- The enrichment of alerts within network and information systems supporting your essential function(s) is performed but not as part of the original alert.
- Detections and alerting rely on off the shelf tooling without customisation or users reporting events and potential incidents.
- There is a documented and shared process for all users who support the operation of the essential function to report events and potential security incidents.
- Where appropriate, detections and alerting result in automated actions being taken. (e.g. malware identified by AV is quarantined).
- You monitor on an irregular basis for user or system abnormalities indicative of adverse activity.
- Logs are monitored at regular intervals.
Achieved - All the following statements are true:
- You easily detect the presence of Indicators of Compromise (IoCs) on network and information systems supporting your essential function(s), such as known malicious command and control signatures, as well as abnormalities or behaviours indicative of adverse activity.
- You apply all updates, new signatures and IoCs promptly.
- Security alerts relating to all network and information systems supporting your essential function(s) are prioritised and this information is used to support incident management.
- Alerts are routinely enriched within network and information systems supporting your essential function(s). The enrichment of these alerts is performed in almost real time and as part of the original alert.
- Alerts and the underlying detections are regularly reviewed and tested to ensure they are generated promptly and reliably, and it is possible to distinguish genuine security incidents from false alarms.
- Alerts and the underlying detection rules are customisable and tuned to reduce false positives as well as optimising responses.
- Detections and alerting may use off the shelf tooling and rules as well as custom tooling and / or rules.
- You continuously monitor for user and system abnormalities indicative of adverse activity generating alerts based on the results of such monitoring.
- Logs are monitored continuously in near real time.
C1.d Triage of Security Alerts
- You contextualise alerts with knowledge of the threat and your systems, to identify those security incidents as well as responding to all alerts appropriately.
- You contextualise alerts with knowledge of the threat and your systems, to identify those security incidents as well as responding to all alerts appropriately.
- You do not triage alerts from your detection security technologies (e.g. AV, IDS).
- You do not categorise alerts and incidents by type and priority / severity level.
- You do not have Standard Operating Procedures (SOPs) / Playbooks / Runbooks available for use during triage.
- You do not keep records of triage performed.
- You do not have a sufficient understanding of normal user or system behaviour to make effective decisions within triage.
- You investigate and triage alerts from some security tools and take action.
- You have created, made available and use when appropriate, Standard Operating Procedures (SOPs) / Playbooks / Runbooks covering the most common use cases. These are regularly reviewed to ensure they remain effective.
- You perform some triage and actions taken by monitoring and detection personnel are recorded.
- You categorise alerts and incidents by type and priority / severity level.
- Your understanding of normal user or system behaviour informs your decision making within triage.
- You investigate and triage alerts from all security tools and take action.
- You have created, made available and use when appropriate, Standard Operating Procedures (SOPs) / Playbooks / Runbooks covering all plausible use cases. These are regularly reviewed to ensure they remain effective.
- You categorise alerts and incidents by type and priority / severity level.
- You document all triage related activities performed by monitoring and detection personnel and these are used to drive improvements
- Triage provides enough information for subsequent activities to be prioritised (e.g. the containment of damaging malware).
- Your understanding of normal user and system behaviour, and threats, is sufficient for effective decision making within triage.
Not achieved - At least one of the following is true:
- You do not triage alerts from your detection security technologies (e.g. AV, IDS).
- You do not categorise alerts and incidents by type and priority / severity level.
- You do not have Standard Operating Procedures (SOPs) / Playbooks / Runbooks available for use during triage.
- You do not keep records of triage performed.
- You do not have a sufficient understanding of normal user or system behaviour to make effective decisions within triage.
Partially achieved - All the following statements are true:
- You investigate and triage alerts from some security tools and take action.
- You have created, made available and use when appropriate, Standard Operating Procedures (SOPs) / Playbooks / Runbooks covering the most common use cases. These are regularly reviewed to ensure they remain effective.
- You perform some triage and actions taken by monitoring and detection personnel are recorded.
- You categorise alerts and incidents by type and priority / severity level.
- Your understanding of normal user or system behaviour informs your decision making within triage.
Achieved - All the following statements are true:
- You investigate and triage alerts from all security tools and take action.
- You have created, made available and use when appropriate, Standard Operating Procedures (SOPs) / Playbooks / Runbooks covering all plausible use cases. These are regularly reviewed to ensure they remain effective.
- You categorise alerts and incidents by type and priority / severity level.
- You document all triage related activities performed by monitoring and detection personnel and these are used to drive improvements
- Triage provides enough information for subsequent activities to be prioritised (e.g. the containment of damaging malware).
- Your understanding of normal user and system behaviour, and threats, is sufficient for effective decision making within triage.
C1.e Personnel Skills for Monitoring Tools and Detection
- Monitoring and detection personnel skills and roles, including those outsourced, reflect governance and reporting requirements, expected threats and the complexities of the network or system data they need to use. Monitoring and detection personnel have sufficient knowledge of network and information systems and the essential function(s) they need to protect.
- Monitoring and detection personnel skills and roles, including those outsourced, reflect governance and reporting requirements, expected threats and the complexities of the network or system data they need to use. Monitoring and detection personnel have sufficient knowledge of network and information systems and the essential function(s) they need to protect.
- There are no personnel who perform a monitoring and detection function.
- Monitoring and detection personnel do not have the correct specialist skills.
- Monitoring and detection personnel are not capable of reporting against governance requirements.
- Monitoring and detection personnel have a lack of awareness of the essential function(s) the organisation provides, what assets relate to those functions and hence the importance of the log data and security events.
- Monitoring and detection personnel have no awareness of other roles or tasks outside of security monitoring and detection that are relevant to the operation of your essential function(s).
- Monitoring and detection personnel are overwhelmed with the amount of data and alerts they have to work with. Alert / triage fatigue is present.
- Monitoring and detection personnel have some investigative skills and a basic understanding of the data they need to work with.
- Monitoring and detection personnel can report to other parts of the organisation (e.g. security directors, resilience managers).
- Monitoring and detection personnel are capable of following most of the required workflow(s).
- Monitoring and detection personnel are aware of some of the network and information systems and your essential function(s), and can manage alerts relating to them.
- Monitoring and detection personnel have some understanding of the operational context (e.g. people, processes, network and information systems that support your essential function(s)) to enhance the security monitoring function.
- Monitoring and detection personnel deal with their workload and cases effectively.
- You have monitoring and detection personnel who are responsible for the proactive and reactive analysis, investigation and reporting of monitoring alerts including both security and performance.
- Monitoring and detection personnel have defined roles and skills that cover all parts of the monitoring and investigation process.
- Monitoring and detection personnel follow policies, processes and procedures that address all governance reporting requirements, internal and external.
- Monitoring and detection personnel are empowered to look beyond the fixed process to investigate and understand non-standard threats.
- Monitoring and detection personnel are aware of the network and information systems and your essential function(s), related assets and can identify and prioritise alerts and investigations that relate to them.
- Monitoring and detection personnel drive and shape new log data collection and can make effective use of it.
- Monitoring and detection personnel are capable of following all of the required workflow(s).
- Monitoring and detection personnel have a sufficient understanding of the operational context (e.g. people, processes, network and information systems that support your essential function) to enhance the security monitoring function.
- Monitoring and detection personnel deal with their workload and cases effectively as well as identifying areas for improvement.
Not achieved - At least one of the following is true:
- There are no personnel who perform a monitoring and detection function.
- Monitoring and detection personnel do not have the correct specialist skills.
- Monitoring and detection personnel are not capable of reporting against governance requirements.
- Monitoring and detection personnel have a lack of awareness of the essential function(s) the organisation provides, what assets relate to those functions and hence the importance of the log data and security events.
- Monitoring and detection personnel have no awareness of other roles or tasks outside of security monitoring and detection that are relevant to the operation of your essential function(s).
- Monitoring and detection personnel are overwhelmed with the amount of data and alerts they have to work with. Alert / triage fatigue is present.
Partially achieved - All the following statements are true:
- Monitoring and detection personnel have some investigative skills and a basic understanding of the data they need to work with.
- Monitoring and detection personnel can report to other parts of the organisation (e.g. security directors, resilience managers).
- Monitoring and detection personnel are capable of following most of the required workflow(s).
- Monitoring and detection personnel are aware of some of the network and information systems and your essential function(s), and can manage alerts relating to them.
- Monitoring and detection personnel have some understanding of the operational context (e.g. people, processes, network and information systems that support your essential function(s)) to enhance the security monitoring function.
- Monitoring and detection personnel deal with their workload and cases effectively.
Achieved - All the following statements are true:
- You have monitoring and detection personnel who are responsible for the proactive and reactive analysis, investigation and reporting of monitoring alerts including both security and performance.
- Monitoring and detection personnel have defined roles and skills that cover all parts of the monitoring and investigation process.
- Monitoring and detection personnel follow policies, processes and procedures that address all governance reporting requirements, internal and external.
- Monitoring and detection personnel are empowered to look beyond the fixed process to investigate and understand non-standard threats.
- Monitoring and detection personnel are aware of the network and information systems and your essential function(s), related assets and can identify and prioritise alerts and investigations that relate to them.
- Monitoring and detection personnel drive and shape new log data collection and can make effective use of it.
- Monitoring and detection personnel are capable of following all of the required workflow(s).
- Monitoring and detection personnel have a sufficient understanding of the operational context (e.g. people, processes, network and information systems that support your essential function) to enhance the security monitoring function.
- Monitoring and detection personnel deal with their workload and cases effectively as well as identifying areas for improvement.
C1.f Understanding User's and System's Behaviour, and Threat Intelligence (within Security Monitoring)
- Threats to the operation of network and information systems, and corresponding user and system behaviour, are sufficiently understood. These are used to detect cyber security incidents.
- Threats to the operation of network and information systems, and corresponding user and system behaviour, are sufficiently understood. These are used to detect cyber security incidents.
- Your organisation has no sources of threat intelligence.
- You do not evaluate the usefulness of your threat intelligence or share feedback with providers or other users.
- You have no awareness of the steps necessary to make best use of threat intelligence for security monitoring.
- Threat intelligence is unreliable and / or is not actioned by the appropriate users or systems in a timely manner.
- You have no established understanding of what abnormalities to look for that might signify adverse activities.
- You do not receive updates for all your detection security technologies (e.g. AV, IDS).
- You do not understand normal user and system behaviour sufficiently to be able to use abnormalities to detect adverse activity.
- You know how effective your threat intelligence is (e.g. by tracking how threat intelligence helps you identify security incidents).
- Your organisation may use threat intelligence services, but you do not necessarily choose sources or providers specifically because of your business needs, or specific threats in your sector (e.g. sector-based infoshare, software vendors, anti-virus providers, specialist threat intel firms, special interest groups).
- The user and system abnormalities from past attacks and threat intelligence, on your
- and other network and information systems, are used to signify adverse activity.
- You receive regular updates for all of your detection security technologies (e.g. AV, IDS).
- You track the effectiveness of your threat intelligence and actively share feedback on the usefulness of Indicators of Compromise (IoCs) and other intelligence with the threat community (e.g. sector partners, threat intelligence providers, government agencies).
- When using threat intelligence feeds, these have been selected using risk-based and threat-informed decisions based on your business needs and sector.
- You make relevant, reliable and actionable threat intelligence available to the necessary users and systems promptly.
- You contextualise threat intelligence and link it to the why and / or how attacks take place for security monitoring.
- You understand normal user and system abnormalities fully, to such an extent that searching for system abnormalities is an effective way of detecting adverse activity (e.g. you fully understand which systems should and should not communicate and when).
- The user and system abnormalities you monitor for are based on the nature of adverse activities likely to impact network and information systems supporting the operation of your essential function(s).
- The user and system abnormalities indicative of adverse activity you use are regularly updated to reflect changes in network and information systems supporting your essential function(s) and current threat intelligence.
- You possess the capability to share threat intelligence (e.g. ways to effectively detect adversaries) with the threat community / defender community (sector partners, threat intelligence providers, government agencies) when required.
Not achieved - At least one of the following is true:
- Your organisation has no sources of threat intelligence.
- You do not evaluate the usefulness of your threat intelligence or share feedback with providers or other users.
- You have no awareness of the steps necessary to make best use of threat intelligence for security monitoring.
- Threat intelligence is unreliable and / or is not actioned by the appropriate users or systems in a timely manner.
- You have no established understanding of what abnormalities to look for that might signify adverse activities.
- You do not receive updates for all your detection security technologies (e.g. AV, IDS).
- You do not understand normal user and system behaviour sufficiently to be able to use abnormalities to detect adverse activity.
Partially achieved - All the following statements are true:
- You know how effective your threat intelligence is (e.g. by tracking how threat intelligence helps you identify security incidents).
- Your organisation may use threat intelligence services, but you do not necessarily choose sources or providers specifically because of your business needs, or specific threats in your sector (e.g. sector-based infoshare, software vendors, anti-virus providers, specialist threat intel firms, special interest groups).
- The user and system abnormalities from past attacks and threat intelligence, on your
- and other network and information systems, are used to signify adverse activity.
- You receive regular updates for all of your detection security technologies (e.g. AV, IDS).
Achieved - All the following statements are true:
- You track the effectiveness of your threat intelligence and actively share feedback on the usefulness of Indicators of Compromise (IoCs) and other intelligence with the threat community (e.g. sector partners, threat intelligence providers, government agencies).
- When using threat intelligence feeds, these have been selected using risk-based and threat-informed decisions based on your business needs and sector.
- You make relevant, reliable and actionable threat intelligence available to the necessary users and systems promptly.
- You contextualise threat intelligence and link it to the why and / or how attacks take place for security monitoring.
- You understand normal user and system abnormalities fully, to such an extent that searching for system abnormalities is an effective way of detecting adverse activity (e.g. you fully understand which systems should and should not communicate and when).
- The user and system abnormalities you monitor for are based on the nature of adverse activities likely to impact network and information systems supporting the operation of your essential function(s).
- The user and system abnormalities indicative of adverse activity you use are regularly updated to reflect changes in network and information systems supporting your essential function(s) and current threat intelligence.
- You possess the capability to share threat intelligence (e.g. ways to effectively detect adversaries) with the threat community / defender community (sector partners, threat intelligence providers, government agencies) when required.
The organisation proactively seeks to detect, within networks and information systems, adverse activity affecting, or with the potential to affect, the operation of essential functions even when the activity evades standard security prevent/detect solutions (or when standard solutions are not deployable).
Description
error determining description
Guidance
Threat hunting is more difficult than standard security monitoring because it looks beyond the known Indicators of Compromise (IOCs) that can be leveraged by automated detections and alerting covered in
C1 Security Monitoring
.
The aim is to build on what is known of both past and plausible attacks to hypothesise what intrusions might look like in. Threat hunting requires more experienced knowledge of network and system behaviour and of the general characteristics that an intrusion might exhibit. This sort of proactive monitoring or threat discovery would normally involve:
A good understanding of normal system behaviour (e.g. what software is authorised and how it would normally behave, how user accounts normally access network resources or how network components connect to each other and transfer data).
A good understanding of the ways that different types of threats maybe realised within your environment(s) based on a comprehensive and advanced understanding of threat intelligence.
A good understanding of normal system behaviour (e.g. what software is authorised and how it would normally behave, how user accounts normally access network resources or how network components connect to each other and transfer data).
Contributing Outcomes
C2.a Threat Hunting
- You do not know the resources required for threat hunting.
- You do not have access to an effective threat hunting capability.
- Your threat hunts do not follow any structure and few if any records are created.
- You have identified the resources required to perform threat hunting and are able to deploy these, in a timely manner, on an occasional basis.
- You deploy an effective threat hunting capability but not frequent enough to match the risks posed to network and information systems supporting your essential function(s) (e.g. you perform threat hunts in response to a tip off from a reputable source).
- Your threat hunts follow pre-determined and documented methods (e.g. hypothesis driven, data driven, entity driven) designed to identify adverse activity not detected by automated detections.
- You document details of threat hunts and post hunt analysis.
- You understand the resources required to perform threat hunting and these are deployed as part of business as usual.
- You deploy threat hunting resources at a frequency that matches the risks posed to network and information systems supporting your essential function(s).
- Your threat hunts follow pre-determined and documented methods (e.g. hypothesis driven, data driven, entity driven) designed to identify adverse activity not detected by automated detections.
- You turn threat hunts into automated detections and alerting where appropriate.
- You routinely record details of previous threat hunts and post hunt activities. You use these to drive improvements in your threat hunting and security posture.
- You have justified confidence in the effectiveness of your threat hunts and the threat hunting process is reviewed and updated to match the risks posed to network and information systems supporting your essential function(s).
- You leverage automation to improve threat hunts where appropriate (e.g. some stages of the threat hunting process are automated).
- Your threat hunts focus on the tactics, techniques and procedures (TTPs) of threats over atomic IoCs (e.g. hashes, IP addresses, domain names etc).
Not achieved - At least one of the following statements is true:
- You do not know the resources required for threat hunting.
- You do not have access to an effective threat hunting capability.
- Your threat hunts do not follow any structure and few if any records are created.
Partially achieved - All the following statements are true:
- You have identified the resources required to perform threat hunting and are able to deploy these, in a timely manner, on an occasional basis.
- You deploy an effective threat hunting capability but not frequent enough to match the risks posed to network and information systems supporting your essential function(s) (e.g. you perform threat hunts in response to a tip off from a reputable source).
- Your threat hunts follow pre-determined and documented methods (e.g. hypothesis driven, data driven, entity driven) designed to identify adverse activity not detected by automated detections.
- You document details of threat hunts and post hunt analysis.
Achieved - All the following statements are true:
- You understand the resources required to perform threat hunting and these are deployed as part of business as usual.
- You deploy threat hunting resources at a frequency that matches the risks posed to network and information systems supporting your essential function(s).
- Your threat hunts follow pre-determined and documented methods (e.g. hypothesis driven, data driven, entity driven) designed to identify adverse activity not detected by automated detections.
- You turn threat hunts into automated detections and alerting where appropriate.
- You routinely record details of previous threat hunts and post hunt activities. You use these to drive improvements in your threat hunting and security posture.
- You have justified confidence in the effectiveness of your threat hunts and the threat hunting process is reviewed and updated to match the risks posed to network and information systems supporting your essential function(s).
- You leverage automation to improve threat hunts where appropriate (e.g. some stages of the threat hunting process are automated).
- Your threat hunts focus on the tactics, techniques and procedures (TTPs) of threats over atomic IoCs (e.g. hashes, IP addresses, domain names etc).
The organisation proactively seeks to detect, within networks and information systems, adverse activity affecting, or with the potential to affect, the operation of essential functions even when the activity evades standard security prevent/detect solutions (or when standard solutions are not deployable).
Description
error determining description
Guidance
Threat hunting is more difficult than standard security monitoring because it looks beyond the known Indicators of Compromise (IOCs) that can be leveraged by automated detections and alerting covered in
C1 Security Monitoring
.
The aim is to build on what is known of both past and plausible attacks to hypothesise what intrusions might look like in. Threat hunting requires more experienced knowledge of network and system behaviour and of the general characteristics that an intrusion might exhibit. This sort of proactive monitoring or threat discovery would normally involve:
A good understanding of normal system behaviour (e.g. what software is authorised and how it would normally behave, how user accounts normally access network resources or how network components connect to each other and transfer data).
A good understanding of the ways that different types of threats maybe realised within your environment(s) based on a comprehensive and advanced understanding of threat intelligence.
A good understanding of normal system behaviour (e.g. what software is authorised and how it would normally behave, how user accounts normally access network resources or how network components connect to each other and transfer data).
Contributing Outcomes
C2.a Threat Hunting
- You do not know the resources required for threat hunting.
- You do not have access to an effective threat hunting capability.
- Your threat hunts do not follow any structure and few if any records are created.
- You have identified the resources required to perform threat hunting and are able to deploy these, in a timely manner, on an occasional basis.
- You deploy an effective threat hunting capability but not frequent enough to match the risks posed to network and information systems supporting your essential function(s) (e.g. you perform threat hunts in response to a tip off from a reputable source).
- Your threat hunts follow pre-determined and documented methods (e.g. hypothesis driven, data driven, entity driven) designed to identify adverse activity not detected by automated detections.
- You document details of threat hunts and post hunt analysis.
- You understand the resources required to perform threat hunting and these are deployed as part of business as usual.
- You deploy threat hunting resources at a frequency that matches the risks posed to network and information systems supporting your essential function(s).
- Your threat hunts follow pre-determined and documented methods (e.g. hypothesis driven, data driven, entity driven) designed to identify adverse activity not detected by automated detections.
- You turn threat hunts into automated detections and alerting where appropriate.
- You routinely record details of previous threat hunts and post hunt activities. You use these to drive improvements in your threat hunting and security posture.
- You have justified confidence in the effectiveness of your threat hunts and the threat hunting process is reviewed and updated to match the risks posed to network and information systems supporting your essential function(s).
- You leverage automation to improve threat hunts where appropriate (e.g. some stages of the threat hunting process are automated).
- Your threat hunts focus on the tactics, techniques and procedures (TTPs) of threats over atomic IoCs (e.g. hashes, IP addresses, domain names etc).
Not achieved - At least one of the following statements is true:
- You do not know the resources required for threat hunting.
- You do not have access to an effective threat hunting capability.
- Your threat hunts do not follow any structure and few if any records are created.
Partially achieved - All the following statements are true:
- You have identified the resources required to perform threat hunting and are able to deploy these, in a timely manner, on an occasional basis.
- You deploy an effective threat hunting capability but not frequent enough to match the risks posed to network and information systems supporting your essential function(s) (e.g. you perform threat hunts in response to a tip off from a reputable source).
- Your threat hunts follow pre-determined and documented methods (e.g. hypothesis driven, data driven, entity driven) designed to identify adverse activity not detected by automated detections.
- You document details of threat hunts and post hunt analysis.
Achieved - All the following statements are true:
- You understand the resources required to perform threat hunting and these are deployed as part of business as usual.
- You deploy threat hunting resources at a frequency that matches the risks posed to network and information systems supporting your essential function(s).
- Your threat hunts follow pre-determined and documented methods (e.g. hypothesis driven, data driven, entity driven) designed to identify adverse activity not detected by automated detections.
- You turn threat hunts into automated detections and alerting where appropriate.
- You routinely record details of previous threat hunts and post hunt activities. You use these to drive improvements in your threat hunting and security posture.
- You have justified confidence in the effectiveness of your threat hunts and the threat hunting process is reviewed and updated to match the risks posed to network and information systems supporting your essential function(s).
- You leverage automation to improve threat hunts where appropriate (e.g. some stages of the threat hunting process are automated).
- Your threat hunts focus on the tactics, techniques and procedures (TTPs) of threats over atomic IoCs (e.g. hashes, IP addresses, domain names etc).
There are well-defined and tested incident management processes in place, that aim to ensure continuity of essential function(s) in the event of system or service failure. Mitigation activities designed to contain or limit the impact of compromise are also in place.
Description
error determining description
Guidance
The 10 Steps to Cyber Security: Incident Management has concise guidance, but organisations should use other more detailed guidance as and when appropriate. Other authoritative guidance pieces are referenced below.
In addition to meeting the expectations of 10 Steps to Cyber Security, you should ensure that your organisation's incident response plans are grounded in thorough and comprehensive risk assessments. Response plans should prioritise essential functions along with the assets and systems that are required to ensure their continued effective operation, such as operational technologies, or key datasets.
The business continuity implications of any compromise should also be taken into account and your cyber incident response plans should link to other business response functions. You should form a cyber response team that is capable of implementing the plan, with the appropriate skills, tools and reach into other parts of your organisation, such as security monitoring and business continuity.
In practice, the Incident Response function should interoperate with the security monitoring function. The Incident Response function needn't be a dedicated team and some members may have non-response related roles. Collectively, the team should have knowledge of IT security, IT infrastructure and Business Management, any specialist technologies (e.g. Operational Technologies or datacentres), incident reporting requirements, and communications plans.
Your plan should cover all relevant potential incidents. It should be auditable and testable (
via exercises
) across a range of incident scenarios and should encompass all realistic descriptions of what might constitute an incident and its severity. Your test scenarios should draw on threat intelligence, past incidents, exercises and the ways in which security capabilities (e.g. security monitoring and alerting) would feature in your response options. Your scenarios should also consider incidents that involve suppliers and your wider supply chain e.g. incidents arising through supplier relations or relying on suppliers as part of your response.
These scenarios could include, but is not limited to:
The scenarios should be incorporated into exercises, which should be run to test your ability to respond to incidents that could affect the operation of essential functions. These exercises should reflect past experience, red-teaming/scenario planning, or threat intelligence and should draw heavily on your risk assessment, considering all relevant assets and vulnerabilities, especially where they relate to essential functions.
Exercises should record lessons learned, covering governance, roles and internal communication, quality of network and security monitoring data, containment and recovery strategies, or any other factors relevant to their effectiveness. This should integrate with lessons learned activities (see
Principle D2 Lessons Learned
).
Your plans should work seamlessly with other system management and security functions. Changes and improvements to response plans should reflect changes to these functions and vice versa, where appropriate.
Plans should articulate clear governance frameworks and roles with procedures for reporting to relevant internal or external stakeholders, such as regulators and competent authorities.
Your plan should also set out a comprehensive range of containment, eradication and recovery strategies, specifying how and when they should be used.
Your organisation should be able to describe its own state of readiness, using any criteria or expected standards from regulators or competent authorities, or from your internal governance arrangements, where appropriate.
In order to report coherently on incidents when required, your plan should set out reporting thresholds (i.e. what does and does not need to be reported) and standards (i.e. the level of detail that should be reported) and which authorities to report to.
More detailed guidance on developing an incident response plan, and the underlying capability to implement it, can be found in the
NIST Computer Security Incident Handling Guide
, CREST publications (see references) or
ISO/IEC 27035-1
.
Contributing Outcomes
D1.a Response Plan
- You have an up-to-date incident response plan that is grounded in a thorough risk assessment that takes account of network and information systems supporting the operation of your essential function(s) and covers a range of incident scenarios.
- You have an up-to-date incident response plan that is grounded in a thorough risk assessment that takes account of network and information systems supporting the operation of your essential function(s) and covers a range of incident scenarios.
- Your incident response plan is not documented.
- Your incident response plan does not include your organisations identified essential function(s).
- Your incident response plan is not well understood by relevant staff.
- Your incident response plan covers network and information systems supporting your essential function(s).
- Your incident response plan comprehensively covers scenarios that are focused on likely impacts of known and well understood attacks only.
- Your incident response plan is understood by all staff who are involved with your organisation's response function.
- Your incident response plan is documented and shared with all relevant stakeholders.
- Your incident response plan is readily accessible, even when your organisations IT systems have been adversely affected by an incident.
- Your incident response plan is regularly reviewed to ensure it remains effective.
- Your incident response plan is based on a clear understanding of the security risks to the network and information systems supporting your essential function(s).
- Your incident response plan is comprehensive (i.e. covers the complete lifecycle of an incident, roles and responsibilities, and reporting) and covers likely impacts of both known attack patterns and of possible attacks, previously unseen.
- Your incident response plan is documented and integrated with wider organisational business plans and supply chain response plans as well as dependencies on supporting infrastructure (e.g. power, cooling etc).
- Your incident response plan is communicated and understood by the business areas involved with the operation of your essential function(s).
Not achieved - At least one of the following is true:
- Your incident response plan is not documented.
- Your incident response plan does not include your organisations identified essential function(s).
- Your incident response plan is not well understood by relevant staff.
Partially Achieved - All the following statements are true:
- Your incident response plan covers network and information systems supporting your essential function(s).
- Your incident response plan comprehensively covers scenarios that are focused on likely impacts of known and well understood attacks only.
- Your incident response plan is understood by all staff who are involved with your organisation's response function.
- Your incident response plan is documented and shared with all relevant stakeholders.
- Your incident response plan is readily accessible, even when your organisations IT systems have been adversely affected by an incident.
- Your incident response plan is regularly reviewed to ensure it remains effective.
Achieved - All the following statements are true:
- Your incident response plan is based on a clear understanding of the security risks to the network and information systems supporting your essential function(s).
- Your incident response plan is comprehensive (i.e. covers the complete lifecycle of an incident, roles and responsibilities, and reporting) and covers likely impacts of both known attack patterns and of possible attacks, previously unseen.
- Your incident response plan is documented and integrated with wider organisational business plans and supply chain response plans as well as dependencies on supporting infrastructure (e.g. power, cooling etc).
- Your incident response plan is communicated and understood by the business areas involved with the operation of your essential function(s).
D1.b Response and Recovery Capability
- You have the capability to enact your incident response plan, including effective limitation of impact on the operation of your essential function(s). During an incident, you have access to timely information on which to base your response decisions.
- You have the capability to enact your incident response plan, including effective limitation of impact on the operation of your essential function(s). During an incident, you have access to timely information on which to base your response decisions.
- Inadequate arrangements have been made to make the right resources available to implement your response plan.
- Your response team members are not equipped to make good response decisions and put them into effect.
- Inadequate back-up mechanisms exist to allow the continued operation of your essential function(s) during an incident.
- You understand the resources that will likely be needed to carry out any required response activities, and arrangements are in place to make these resources available.
- You understand the types of information that will likely be needed to inform response decisions and arrangements are in place to make this information available.
- Your response team members have the skills and knowledge required to decide on the response actions necessary to limit harm, and the authority to carry them out.
- Key roles are duplicated, and operational delivery knowledge is shared with all individuals involved in the operations and recovery of the essential function(s).
- Back-up mechanisms are available that can be readily activated to allow continued operation of your essential function(s), although possibly at a reduced level, if primary network and information systems fail or are unavailable.
- Arrangements exist to augment your organisation’s incident response capabilities with external support if necessary (e.g. specialist cyber incident responders).
Not Achieved - At least one of the following is true:
- Inadequate arrangements have been made to make the right resources available to implement your response plan.
- Your response team members are not equipped to make good response decisions and put them into effect.
- Inadequate back-up mechanisms exist to allow the continued operation of your essential function(s) during an incident.
Achieved - All the following statements are true:
- You understand the resources that will likely be needed to carry out any required response activities, and arrangements are in place to make these resources available.
- You understand the types of information that will likely be needed to inform response decisions and arrangements are in place to make this information available.
- Your response team members have the skills and knowledge required to decide on the response actions necessary to limit harm, and the authority to carry them out.
- Key roles are duplicated, and operational delivery knowledge is shared with all individuals involved in the operations and recovery of the essential function(s).
- Back-up mechanisms are available that can be readily activated to allow continued operation of your essential function(s), although possibly at a reduced level, if primary network and information systems fail or are unavailable.
- Arrangements exist to augment your organisation’s incident response capabilities with external support if necessary (e.g. specialist cyber incident responders).
D1.c Testing and Exercising
- Your organisation carries out exercises to test response plans, using past incidents that affected your (and other) organisation, and scenarios that draw on threat intelligence and your risk assessment.
- Your organisation carries out exercises to test response plans, using past incidents that affected your (and other) organisation, and scenarios that draw on threat intelligence and your risk assessment.
- Exercises test only a discrete part of the process (e.g. that backups are working), but do not consider all areas.
- Incident response exercises are not routinely carried out or are carried out in an ad-hoc way.
- Outputs from exercises are not fed into the organisation's lessons learned process.
- Exercises do not test all parts of the response cycle.
- Exercise scenarios are based on incidents experienced by your and other organisations or are composed using experience or threat intelligence.
- Exercise scenarios are documented, regularly reviewed, and validated.
- Exercises are routinely run, with the findings documented and used to refine incident response plans and protective security, in line with the lessons learned.
- Exercises test all parts of your response cycle relating to your essential function(s) (e.g. restoration of normal function(s) levels).
Not Achieved - At least one of the following is true:
- Exercises test only a discrete part of the process (e.g. that backups are working), but do not consider all areas.
- Incident response exercises are not routinely carried out or are carried out in an ad-hoc way.
- Outputs from exercises are not fed into the organisation's lessons learned process.
- Exercises do not test all parts of the response cycle.
Achieved - All the following statements are true:
- Exercise scenarios are based on incidents experienced by your and other organisations or are composed using experience or threat intelligence.
- Exercise scenarios are documented, regularly reviewed, and validated.
- Exercises are routinely run, with the findings documented and used to refine incident response plans and protective security, in line with the lessons learned.
- Exercises test all parts of your response cycle relating to your essential function(s) (e.g. restoration of normal function(s) levels).
When an incident occurs, steps are taken to understand its causes and to ensure remediating action is taken to protect against future incidents.
Description
error determining description
Guidance
You should use the guidance points below to learn lessons and address shortfalls in:
your overall protective security (see
Objectives A - C
) and
your incident response plan (see
Response and Recovery Planning
)
your overall protective security (see
Objectives A - C
) and
Contributing Outcomes
D2.a Post Incident Analysis
- When an incident occurs, your organisation takes steps to understand its causes, informing appropriate remediating action.
- When an incident occurs, your organisation takes steps to understand its causes, informing appropriate remediating action.
- You are not usually able to resolve incidents to a root cause or identify the contributing factors within a broader systems context.
- You do not have a formal process for investigating causes.
- Investigators form theories early in the process and only seek evidence that affirms their belief.
- Investigations are solely focused on identifying the person(s) who can be held responsible for the incident.
- Post incident analysis is conducted routinely as a key part of your lessons learned activities following an incident.
- Your post incident analysis is comprehensive, considering organisational factors (e.g. policies, processes and procedures), technical factors (e.g. system design, vulnerabilities), human factors (e.g. training, security culture) and any changes to threat.
- All relevant incident data is made available to the analysis team to perform post incident analysis.
- Your analysis considers what could have happened under plausible, alternative circumstances (e.g. ‘what if’ / ’if only’ scenarios).
Not Achieved - At least one of the following statements is true:
- You are not usually able to resolve incidents to a root cause or identify the contributing factors within a broader systems context.
- You do not have a formal process for investigating causes.
- Investigators form theories early in the process and only seek evidence that affirms their belief.
- Investigations are solely focused on identifying the person(s) who can be held responsible for the incident.
Achieved - All the following statements are true:
- Post incident analysis is conducted routinely as a key part of your lessons learned activities following an incident.
- Your post incident analysis is comprehensive, considering organisational factors (e.g. policies, processes and procedures), technical factors (e.g. system design, vulnerabilities), human factors (e.g. training, security culture) and any changes to threat.
- All relevant incident data is made available to the analysis team to perform post incident analysis.
- Your analysis considers what could have happened under plausible, alternative circumstances (e.g. ‘what if’ / ’if only’ scenarios).
D2.b Using Incidents to Drive Improvements
- Your organisation uses lessons learned from incidents to improve your security measures.
- Your organisation uses lessons learned from incidents to improve your security measures.
- Improvements arising from lessons learned following an incident are not implemented or not given sufficient organisational priority.
- Changes are made as a ‘knee jerk’ reaction to an incident without proper analysis and testing to ensure the change is appropriate.
- You wait until a severe or high-profile incident has occurred before you take steps to improve.
- You have a documented incident review process / policy which ensures that lessons learned from each incident, including near misses, are identified, captured, and acted upon.
- Lessons learned cover issues with reporting, roles, governance, skills and organisational policies, processes and procedures as well as technical aspects of network and information systems.
- You use lessons learned to improve security measures, including updating and retesting response plans when necessary.
- Security improvements identified as a result of lessons learned are prioritised, with the highest priority improvements completed promptly.
- Analysis is fed to senior management and incorporated into risk management and continuous improvement.
- Your organisation maximises the lessons learned by using the analysis into ‘what if’ / ’if only’ scenarios.
- Your organisation learns from reported incidents in your sector and the wider national infrastructure.
Not Achieved - At least one of the following is true:
- Improvements arising from lessons learned following an incident are not implemented or not given sufficient organisational priority.
- Changes are made as a ‘knee jerk’ reaction to an incident without proper analysis and testing to ensure the change is appropriate.
- You wait until a severe or high-profile incident has occurred before you take steps to improve.
Achieved - All the following statements are true:
- You have a documented incident review process / policy which ensures that lessons learned from each incident, including near misses, are identified, captured, and acted upon.
- Lessons learned cover issues with reporting, roles, governance, skills and organisational policies, processes and procedures as well as technical aspects of network and information systems.
- You use lessons learned to improve security measures, including updating and retesting response plans when necessary.
- Security improvements identified as a result of lessons learned are prioritised, with the highest priority improvements completed promptly.
- Analysis is fed to senior management and incorporated into risk management and continuous improvement.
- Your organisation maximises the lessons learned by using the analysis into ‘what if’ / ’if only’ scenarios.
- Your organisation learns from reported incidents in your sector and the wider national infrastructure.
Principles
The organisation has appropriate management policies, processes and procedures in place to govern its approach to the security of network and information systems.
Description
error determining description
Guidance
Your organisation's approach to security governance needs to be an appropriate fit for your organisation. Good security governance is integrated with your business's usual decision making structures and processes.
Decisions about risk can be made at all levels of your organisation when delegated effectively to people with the right security, business and technical knowledge, skills and experience. Clear lines of communication are also necessary.
Contributing Outcomes
A1.a Board Direction
- You have effective organisational security management led at board level and articulated clearly in corresponding policies.
- You have effective organisational security management led at board level and articulated clearly in corresponding policies.
- The security of network and information systems related to the operation of essential function(s) is not discussed or reported on regularly at board-level.
- Board-level discussions on the security of network and information systems are based on partial or out-of-date information, without the benefit of expert guidance.
- The security of network and information systems supporting your essential function(s) are not driven effectively by the direction set at board-level.
- Senior management or other pockets of the organisation consider themselves exempt from some policies or expect special accommodations to be made.
- Your organisation's approach and policy relating to the security of network and information systems supporting the operation of essential function(s) are owned and managed at board-level. These are communicated, in a meaningful way, to risk management decision-makers across the organisation.
- Regular board-level discussions on the security of network and information systems supporting the operation of your essential function(s) take place, based on timely and accurate information and informed by expert guidance.
- There is a board-level individual who has overall accountability for the security of network and information systems and drives regular discussion at board-level.
- Direction set at board-level is translated into effective organisational practices that direct and control the security of the network and information systems supporting your essential functions(s).
- The board has the information and understanding needed in order to effectively discuss how the security and resilience of network and information systems contributes to the delivery of essential function(s) and what the potential impact from compromise of those systems would be.
- Security is recognised as an important enabler for the resilience of your essential function(s) and considered in all relevant discussions.
Not achieved - At least one of the following statements is true:
- The security of network and information systems related to the operation of essential function(s) is not discussed or reported on regularly at board-level.
- Board-level discussions on the security of network and information systems are based on partial or out-of-date information, without the benefit of expert guidance.
- The security of network and information systems supporting your essential function(s) are not driven effectively by the direction set at board-level.
- Senior management or other pockets of the organisation consider themselves exempt from some policies or expect special accommodations to be made.
Achieved - All the following statements are true:
- Your organisation's approach and policy relating to the security of network and information systems supporting the operation of essential function(s) are owned and managed at board-level. These are communicated, in a meaningful way, to risk management decision-makers across the organisation.
- Regular board-level discussions on the security of network and information systems supporting the operation of your essential function(s) take place, based on timely and accurate information and informed by expert guidance.
- There is a board-level individual who has overall accountability for the security of network and information systems and drives regular discussion at board-level.
- Direction set at board-level is translated into effective organisational practices that direct and control the security of the network and information systems supporting your essential functions(s).
- The board has the information and understanding needed in order to effectively discuss how the security and resilience of network and information systems contributes to the delivery of essential function(s) and what the potential impact from compromise of those systems would be.
- Security is recognised as an important enabler for the resilience of your essential function(s) and considered in all relevant discussions.
A1.b Roles and Responsibilities
- Your organisation has established roles and responsibilities for the security of network and information systems at all levels, with clear and well-understood channels for communicating and escalating risks.
- Your organisation has established roles and responsibilities for the security of network and information systems at all levels, with clear and well-understood channels for communicating and escalating risks.
- Key roles are missing, left vacant, or fulfilled on an ad-hoc or informal basis.
- Staff are assigned security responsibilities but without adequate authority or resources to fulfil them.
- Staff are unsure what their responsibilities are for the security of the essential function(s).
- Key roles and responsibilities for the security of network and information systems supporting your essential function(s) have been identified. These are reviewed regularly to ensure they remain fit for purpose.
- Appropriately capable and knowledgeable staff fill those roles and are given the time, authority, and resources to carry out their duties.
- There is clarity on who in your organisation has overall accountability for the security of the network and information systems supporting your essential function(s).
Not achieved - At least one of the following statements is true:
- Key roles are missing, left vacant, or fulfilled on an ad-hoc or informal basis.
- Staff are assigned security responsibilities but without adequate authority or resources to fulfil them.
- Staff are unsure what their responsibilities are for the security of the essential function(s).
Achieved - All the following statements are true:
- Key roles and responsibilities for the security of network and information systems supporting your essential function(s) have been identified. These are reviewed regularly to ensure they remain fit for purpose.
- Appropriately capable and knowledgeable staff fill those roles and are given the time, authority, and resources to carry out their duties.
- There is clarity on who in your organisation has overall accountability for the security of the network and information systems supporting your essential function(s).
A1.c Decision-making
- You have senior-level accountability for the security of network and information systems, and delegate decision-making authority appropriately and effectively. Risks to network and information systems related to the operation of the essential function(s) are considered in the context of other organisational risks
.
- You have senior-level accountability for the security of network and information systems, and delegate decision-making authority appropriately and effectively. Risks to network and information systems related to the operation of the essential function(s) are considered in the context of other organisational risks
- What should be relatively straightforward risk decisions are constantly referred up the chain, or not made.
- Risks are resolved informally (or ignored) at a local level when the use of a more formal risk reporting mechanism would be more appropriate.
- Decision-makers are unsure of what senior management's risk appetite is, or only understand it in vague terms such as "averse" or "cautious".
- Decision-makers are unable to justify their risk management decisions.
- Organisational structure causes risk decisions to be made in isolation. (e.g. engineering and IT don't talk to each other about risk).
- Risk priorities are too vague to make meaningful distinctions between them. (e.g. almost all risks are rated 'medium' or 'amber').
- Senior management have visibility of key risk decisions made throughout the organisation.
- Risk management decision-makers understand their responsibilities for making effective and timely decisions in the context of the risk appetite regarding the essential function(s), as set by senior management.
- Risk management decision-making is delegated and escalated where necessary, across the organisation, to people who have the skills, knowledge, tools and authority they need.
- Risk management decisions are regularly reviewed to ensure their continued relevance and validity.
Not achieved - At least one of the following statements is true:
- What should be relatively straightforward risk decisions are constantly referred up the chain, or not made.
- Risks are resolved informally (or ignored) at a local level when the use of a more formal risk reporting mechanism would be more appropriate.
- Decision-makers are unsure of what senior management's risk appetite is, or only understand it in vague terms such as "averse" or "cautious".
- Decision-makers are unable to justify their risk management decisions.
- Organisational structure causes risk decisions to be made in isolation. (e.g. engineering and IT don't talk to each other about risk).
- Risk priorities are too vague to make meaningful distinctions between them. (e.g. almost all risks are rated 'medium' or 'amber').
Achieved - All the following statements are true:
- Senior management have visibility of key risk decisions made throughout the organisation.
- Risk management decision-makers understand their responsibilities for making effective and timely decisions in the context of the risk appetite regarding the essential function(s), as set by senior management.
- Risk management decision-making is delegated and escalated where necessary, across the organisation, to people who have the skills, knowledge, tools and authority they need.
- Risk management decisions are regularly reviewed to ensure their continued relevance and validity.
The organisation takes appropriate steps to identify, assess and understand security risks to network and information systems supporting the operation of essential functions. This includes an overall organisational approach to risk management.
Description
error determining description
Guidance
Our
Risk Management guidance
aims to help you to choose an approach that's right for your organisation. Organisations responsible for essential functions are likely to benefit from a combination of a
system-based approach
, which looks at the interactions between components of the function, and a
component-driven analysis
, which considers the threats, vulnerabilities, and impacts relevant to particular critical components.
Your organisation should choose a method or framework for managing risk that fits with the organisation's business and technology needs.
Whichever approach you choose, the scope of your programme must include all systems relevant to the operation of essential functions. Simply following the minimum requirements of a standard or applying blanket controls across the organisation is unlikely to adequately manage risks to critical systems.
Where industrial control and automation systems are in scope of the essential function, you should keep in mind that controls suitable for managing risks on the corporate IT network may be inappropriate or damaging in an operational technology environment. These systems will likely require a more tailored approach, and some frameworks and standards address specific concerns relating to such systems.
Cyber threats continue to evolve and develop, putting each organisation’s operational continuity and services at significant risk. By identifying and understanding cyber threats, and the steps a threat actor may take to compromise systems supporting essential functions, an organisation can implement effective security measures to counter malicious attacks and breaches. Various methods can be used to better understand threat which are discussed in our
Risk Management guidance
.
Ultimately, a detailed understanding of current cyber threats helps organisations to mitigate risks, ensuring the security and resilience of network and information systems in an increasingly hostile world.
Various means are available to gain confidence in the effectiveness of the security of technologies, processes and people. The NCSC Risk Management guidance discusses
how to gain and maintain assurance
in your risk treatments.
The NCSC assurance guidance provides some examples that may be useful to understand cyber security confidence in your organisation and there are some specific technical NCSC guides:
The
NCSC Penetration guidance
will help you understand the proper use and commissioning of penetration tests to gain assurance in the security of an IT system.
Our
Cloud Security collection
provides guidance on managing the risks involved with using cloud services, and some of the principles and guidance are more broadly applicable. The cloud guidance for having confidence in cyber security provides principles that are useful for assuring cyber security of essential functions. The collection will be of particular interest if your organisation hosts any part of your essential function infrastructure on a cloud service.
The
NCSC Penetration guidance
will help you understand the proper use and commissioning of penetration tests to gain assurance in the security of an IT system.
Contributing Outcomes
A2.a Risk Management Process
- Your organisation has effective internal processes for managing risks to the security and resilience of network and information systems related to the operation of your essential function(s) and communicating associated activities.
- Your organisation has effective internal processes for managing risks to the security and resilience of network and information systems related to the operation of your essential function(s) and communicating associated activities.
- Risk assessments are not based on a clearly defined set of threat assumptions.
- Risk assessment outputs are too complex or unwieldy to be consumed by decision-makers and are not effectively communicated in a clear and timely manner.
- Risk assessments for network and information systems that support your essential function(s) are a "one-off" activity or not done at all.
- The security elements of projects or programmes are solely dependent on the completion of a risk management assessment without any regard to the outcomes.
- There is no systematic process in place to ensure that identified security risks are managed effectively.
- Systems are assessed in isolation, without consideration of dependencies and interactions with other systems. (e.g. interactions between IT and OT environments).
- Security requirements and mitigations are arbitrary or are applied from a control catalogue without consideration of how they contribute to the security of the essential function(s).
- Risks remain unresolved on a register for prolonged periods of time awaiting senior decision-making or resource allocation to resolve.
- Your organisational process ensures that security risks to network and information systems relevant to essential function(s) are identified, analysed, prioritised, and managed.
- Your risk assessments are informed by an understanding of the vulnerabilities in the network and information systems supporting your essential function(s).
- The output from your risk management process is a clear set of security requirements that will address the risks in line with your organisational approach to security.
- Significant conclusions reached in the course of your risk management process are communicated to key security decision-makers and accountable individuals.
- You conduct risk assessments when significant events potentially affect the essential function(s), such as replacing a system, introducing new or emergent technologies or a change in the cyber security threat.
- Your organisational process ensures that security risks to network and information systems relevant to essential function(s) are identified, analysed, prioritised, and managed.
- Your approach to risk is focused on the possibility of adverse impact to your essential function(s), leading to a detailed understanding of how such impact might arise as a consequence of possible attacker actions and the security properties of your network and information systems.
- Your risk assessments are based on a clearly understood set of threat assumptions, informed by an up-to-date understanding of security threats to your essential function(s) and your sector.
- Your risk assessments are informed by an understanding of the vulnerabilities in the network and information systems supporting your essential function(s).
- The output from your risk management process is a clear set of security requirements that will address the risks in line with your organisational approach to security.
- Significant conclusions reached in the course of your risk management process are communicated to key security decision-makers and accountable individuals.
- Your risk assessments are dynamic and updated in the light of relevant changes which may include technical changes to network and information systems, change of use and new threat information.
- The effectiveness of your risk management process is reviewed regularly, and improvements made as required.
- You anticipate technological developments that could be used to adversely impact network and information systems supporting your essential function(s).
Not achieved - At least one of the following statements is true:
- Risk assessments are not based on a clearly defined set of threat assumptions.
- Risk assessment outputs are too complex or unwieldy to be consumed by decision-makers and are not effectively communicated in a clear and timely manner.
- Risk assessments for network and information systems that support your essential function(s) are a "one-off" activity or not done at all.
- The security elements of projects or programmes are solely dependent on the completion of a risk management assessment without any regard to the outcomes.
- There is no systematic process in place to ensure that identified security risks are managed effectively.
- Systems are assessed in isolation, without consideration of dependencies and interactions with other systems. (e.g. interactions between IT and OT environments).
- Security requirements and mitigations are arbitrary or are applied from a control catalogue without consideration of how they contribute to the security of the essential function(s).
- Risks remain unresolved on a register for prolonged periods of time awaiting senior decision-making or resource allocation to resolve.
Partially achieved - All the following statements are true:
- Your organisational process ensures that security risks to network and information systems relevant to essential function(s) are identified, analysed, prioritised, and managed.
- Your risk assessments are informed by an understanding of the vulnerabilities in the network and information systems supporting your essential function(s).
- The output from your risk management process is a clear set of security requirements that will address the risks in line with your organisational approach to security.
- Significant conclusions reached in the course of your risk management process are communicated to key security decision-makers and accountable individuals.
- You conduct risk assessments when significant events potentially affect the essential function(s), such as replacing a system, introducing new or emergent technologies or a change in the cyber security threat.
Achieved - All the following statements are true:
- Your organisational process ensures that security risks to network and information systems relevant to essential function(s) are identified, analysed, prioritised, and managed.
- Your approach to risk is focused on the possibility of adverse impact to your essential function(s), leading to a detailed understanding of how such impact might arise as a consequence of possible attacker actions and the security properties of your network and information systems.
- Your risk assessments are based on a clearly understood set of threat assumptions, informed by an up-to-date understanding of security threats to your essential function(s) and your sector.
- Your risk assessments are informed by an understanding of the vulnerabilities in the network and information systems supporting your essential function(s).
- The output from your risk management process is a clear set of security requirements that will address the risks in line with your organisational approach to security.
- Significant conclusions reached in the course of your risk management process are communicated to key security decision-makers and accountable individuals.
- Your risk assessments are dynamic and updated in the light of relevant changes which may include technical changes to network and information systems, change of use and new threat information.
- The effectiveness of your risk management process is reviewed regularly, and improvements made as required.
- You anticipate technological developments that could be used to adversely impact network and information systems supporting your essential function(s).
A2.b Understanding Threat
- You understand the capabilities, methods and techniques of threat actors and what network and information systems they may compromise to adversely impact your essential function(s). This information is used to inform security and resilience risk management decisions, adjusting, enhancing or adding security measures to better defend against threats.
- You understand the capabilities, methods and techniques of threat actors and what network and information systems they may compromise to adversely impact your essential function(s). This information is used to inform security and resilience risk management decisions, adjusting, enhancing or adding security measures to better defend against threats.
- You are unable to perform threat analysis.
- You do not understand the threats to network and information systems supporting your essential function(s).
- You do not have a clearly defined set of threat assumptions.
- You do not use your understanding of threat to inform your risk management decisions.
- You perform threat analysis and understand how common threats apply to network and information systems supporting your essential function(s).
- You understand common types of cyber attacks, including the methods and techniques, and how these might apply to network and information systems supporting your essential function(s). This understanding is kept up to date.
- You anticipate what threat actors might target in network and information systems to cause an adverse impact to your essential function(s).
- Your understanding of threat is informed by common incidents.
- You apply your understanding of threat to inform your risk management decision-making.
- You perform detailed threat analysis and understand how this applies to network and information systems supporting your essential function(s), in the context of your sector and wider national infrastructure.
- Your detailed understanding of threat includes the methods and techniques available to capable and well-resourced threat actors and how they could be used systematically against network and information systems supporting your essential function(s).
- You use appropriate techniques to develop an understanding of network and information systems supporting your essential function(s) from a threat actor’s perspective. You anticipate probable attack methods and techniques, targets and objectives, and develop plausible scenarios.
- You understand the different steps a capable and well-resourced threat actor would need to take to reach the probable target(s).
- You identify and justify what measures can be used at each step to reduce the likelihood of the threat actor reaching the probable target(s) or achieving their objective(s).
- You maintain a detailed understanding of current threats (e.g. by threat intelligence and proactive research).
- You apply your detailed understanding of threat to inform your risk management decision-making.
- You have documented the steps required to undertake detailed threat analysis.
Not achieved - At least one of the following statements is true:
- You are unable to perform threat analysis.
- You do not understand the threats to network and information systems supporting your essential function(s).
- You do not have a clearly defined set of threat assumptions.
- You do not use your understanding of threat to inform your risk management decisions.
Partially achieved - All the following statements are true:
- You perform threat analysis and understand how common threats apply to network and information systems supporting your essential function(s).
- You understand common types of cyber attacks, including the methods and techniques, and how these might apply to network and information systems supporting your essential function(s). This understanding is kept up to date.
- You anticipate what threat actors might target in network and information systems to cause an adverse impact to your essential function(s).
- Your understanding of threat is informed by common incidents.
- You apply your understanding of threat to inform your risk management decision-making.
Achieved - All the following statements are true:
- You perform detailed threat analysis and understand how this applies to network and information systems supporting your essential function(s), in the context of your sector and wider national infrastructure.
- Your detailed understanding of threat includes the methods and techniques available to capable and well-resourced threat actors and how they could be used systematically against network and information systems supporting your essential function(s).
- You use appropriate techniques to develop an understanding of network and information systems supporting your essential function(s) from a threat actor’s perspective. You anticipate probable attack methods and techniques, targets and objectives, and develop plausible scenarios.
- You understand the different steps a capable and well-resourced threat actor would need to take to reach the probable target(s).
- You identify and justify what measures can be used at each step to reduce the likelihood of the threat actor reaching the probable target(s) or achieving their objective(s).
- You maintain a detailed understanding of current threats (e.g. by threat intelligence and proactive research).
- You apply your detailed understanding of threat to inform your risk management decision-making.
- You have documented the steps required to undertake detailed threat analysis.
A2.c Assurance
- You have gained confidence in the effectiveness of the security of your technology, people, and processes relevant to the operation of network and information systems supporting your essential function(s).
- You have gained confidence in the effectiveness of the security of your technology, people, and processes relevant to the operation of network and information systems supporting your essential function(s).
- A particular product or service is seen as a "silver bullet" and vendor claims are taken at face value.
- Assurance methods are applied without appreciation of their strengths and limitations, such as the risks of penetration testing in operational environments.
- Assurance is assumed because there have been no known problems to date.
- You validate that the security measures in place to protect the network and information systems are effective and remain effective for the lifetime over which they are needed.
- You understand the assurance methods available to you and choose appropriate methods to gain confidence in the security of essential function(s).
- Your confidence in the security as it relates to your technology, people, and processes can be justified to, and verified by, a third party.
- Security deficiencies uncovered by assurance activities are assessed, prioritised and remedied when necessary in a timely and effective way.
- The methods used for assurance are reviewed to ensure they are working as intended and remain the most appropriate method to use.
Not achieved - At least one of the following statements is true:
- A particular product or service is seen as a "silver bullet" and vendor claims are taken at face value.
- Assurance methods are applied without appreciation of their strengths and limitations, such as the risks of penetration testing in operational environments.
- Assurance is assumed because there have been no known problems to date.
Achieved - All the following statements are true:
- You validate that the security measures in place to protect the network and information systems are effective and remain effective for the lifetime over which they are needed.
- You understand the assurance methods available to you and choose appropriate methods to gain confidence in the security of essential function(s).
- Your confidence in the security as it relates to your technology, people, and processes can be justified to, and verified by, a third party.
- Security deficiencies uncovered by assurance activities are assessed, prioritised and remedied when necessary in a timely and effective way.
- The methods used for assurance are reviewed to ensure they are working as intended and remain the most appropriate method to use.
Everything required to deliver, maintain or support networks and information systems necessary for the operation of essential functions is determined and understood. This includes data, people and systems, as well as any supporting infrastructure (such as power or cooling).
Description
error determining description
Guidance
Whichever risk management method your organisation uses, asset management will play a key role as you cannot effectively manage risks without understanding what assets are part of the essential function. Your asset management regime should consider all relevant assets, and dependencies between them. Dependencies may be identified between assets under your organisation's control (including IT and OT domains), elements of the supply chain (including power), and key staff who are critical to operations. Assets in an operational technology environment may need a more tailored approach than the corporate IT assets.
For asset management to be effective, up to date knowledge of your assets must be maintained throughout their lifecycle.
Asset management is part of an ISO 27001 Information Security Management System (ISMS), but management of critical assets may require a tailored approach.
If your organisation is using an ISMS as a tool for compliance with cyber regulation, you must ensure the scope includes all systems relevant to the operation of the essential function covered by the regulation. Asset management is a key part of an ISMS, although critical services may need more attention than the minimum requirements of the standard.
This standard aligns with ISO 27001 and can be used in conjunction with it or independent of it. It outlines requirements for a generic asset management system. An organisation following this standard as a tool for compliance with cyber regulation must ensure the scope encompasses all the relevant systems. The standard covers needs and expectations of stakeholders, which must include any requirements from regulators.
ITIL is an IT service management framework that outlines best practices for delivering IT services. It recommends a staged approach to IT Asset Management (ITAM). You may find this useful for improving management of your IT assets, but must keep in mind that there may be assets and dependencies beyond the corporate IT domain as outlined above.
Asset management is part of an ISO 27001 Information Security Management System (ISMS), but management of critical assets may require a tailored approach.
If your organisation is using an ISMS as a tool for compliance with cyber regulation, you must ensure the scope includes all systems relevant to the operation of the essential function covered by the regulation. Asset management is a key part of an ISMS, although critical services may need more attention than the minimum requirements of the standard.
Contributing Outcomes
A3.a Asset Management
- Inventories of assets relevant to the essential function(s) are incomplete, non-existent, or inadequately detailed.
- Only certain domains or types of asset are documented and understood. Dependencies between assets are not understood (such as the dependencies between IT and OT).
- Information assets, which could include personally identifiable information and / or important / critical data, are stored for long periods of time with no clear business need or retention policy.
- Knowledge critical to the management, operation, or recovery of the essential function(s) is held by one or two key individuals with no succession plan.
- Asset inventories are neglected and out of date.
- All assets relevant to the secure operation of essential function(s) are identified and inventoried (at a suitable level of detail). The inventory is kept up-to-date.
- Dependencies on supporting infrastructure (e.g. power, cooling etc) are recognised and recorded.
- You have prioritised your assets according to their importance to the operation of the essential function(s).
- You have assigned responsibility for managing all assets, including physical assets, relevant to the operation of the essential function(s).
- Assets relevant to the essential function(s) are managed with cyber security in mind throughout their lifecycle, from creation through to eventual decommissioning or disposal.
Not achieved - At least one of the following statements is true:
- Inventories of assets relevant to the essential function(s) are incomplete, non-existent, or inadequately detailed.
- Only certain domains or types of asset are documented and understood. Dependencies between assets are not understood (such as the dependencies between IT and OT).
- Information assets, which could include personally identifiable information and / or important / critical data, are stored for long periods of time with no clear business need or retention policy.
- Knowledge critical to the management, operation, or recovery of the essential function(s) is held by one or two key individuals with no succession plan.
- Asset inventories are neglected and out of date.
Achieved - All the following statements are true:
- All assets relevant to the secure operation of essential function(s) are identified and inventoried (at a suitable level of detail). The inventory is kept up-to-date.
- Dependencies on supporting infrastructure (e.g. power, cooling etc) are recognised and recorded.
- You have prioritised your assets according to their importance to the operation of the essential function(s).
- You have assigned responsibility for managing all assets, including physical assets, relevant to the operation of the essential function(s).
- Assets relevant to the essential function(s) are managed with cyber security in mind throughout their lifecycle, from creation through to eventual decommissioning or disposal.
The organisation understands and manages security risks to networks and information systems supporting the operation of essential functions that arise as a result of dependencies on suppliers. This includes ensuring that appropriate measures are employed where third party services are used.
Description
error determining description
Guidance
Organisations responsible for essential functions need to ensure that when third party suppliers are used, all relevant security requirements are met. This means that a number of specific supply chain related security considerations should be addressed where relevant to the provision of the essential function. This might include:
Ensuring the protection of data shared with a third party. This includes protecting data from actions such as unauthorised access, modification, or deletion that may cause an adverse impact on any essential functions (see
Principle B3
).
Effective specification of the security properties of products or services procured from an external third party, or sourced internally from another part of the organisation, that are important for the protection of the essential function. This should include the security requirements derived from the rest of these Principles.
Ensure that any network connections or data sharing with third parties do not introduce unmanaged vulnerabilities that have the potential to affect the security of the essential function.
Confidence that third party suppliers are trustworthy such that malicious attempts to subvert the security of products or systems that could affect the essential function are managed.
Ensuring the protection of data shared with a third party. This includes protecting data from actions such as unauthorised access, modification, or deletion that may cause an adverse impact on any essential functions (see
Principle B3
).
Contributing Outcomes
A4.a Supply Chain
- You understand and effectively manage the risks associated with suppliers to the security of network and information systems supporting the operation of your essential function(s).
- You understand and effectively manage the risks associated with suppliers to the security of network and information systems supporting the operation of your essential function(s).
- You do not know what data belonging to you is held by suppliers, or how it is managed.
- Elements of the supply chain for essential function(s) are subcontracted and you have little or no visibility of the sub-contractors.
- You have no understanding of which contracts are relevant and / or relevant contracts do not specify appropriate security obligations.
- Suppliers have access to systems that provide your essential function(s) that is unrestricted, not monitored or bypasses your own security controls.
- You understand the general risks suppliers may pose to your essential function(s).
- You know the extent of your supply chain that supports your essential function(s), including sub-contractors.
- Suppliers to network and information systems that support your essential function(s) can demonstrate appropriate and proportionate levels of cyber security within the context of common threats.
- You understand which contracts are relevant and you include appropriate security obligations in relevant contracts.
- You are aware of all third-party connections and have assurance that they meet your organisation’s security requirements.
- Your approach to security incident management considers incidents that might arise in your supply chain.
- You have confidence that information shared with suppliers that is necessary for the operation of your essential function(s) is appropriately protected from common threats.
- You have a deep understanding of your supply chain, including sub-contractors and the wider risks it faces.
- You consider factors such as your supplier’s ownership, nationality, partnerships, competitors, other organisations with which they sub-contract and their approach to cyber security. These factors inform your risk assessment and are fully considered in your procurement lifecycle processes and purchasing decisions.
- Your approach to supply chain risk management considers the risks to network and information systems supporting your essential function(s) arising from supply chain subversion by capable and well-resourced threat actors.
- Critical suppliers to network and information systems supporting your essential functions(s) can demonstrate appropriate and proportionate levels of cyber security within the context of capable and well-resourced threat actors.
- You have confidence that information held by suppliers that is essential to the operation of network and information systems supporting your essential function(s) is appropriately protected from capable and well-resourced threat actors.
- You understand which contracts are relevant and you include appropriate security obligations, in relevant contracts.
- You have a proactive approach to contract management which may include a contract management plan for relevant contracts.
- Customer / supplier ownership of responsibilities is defined in contracts.
- All network connections and data sharing with third parties are managed effectively and proportionately.
- When appropriate, your incident management process and that of your suppliers provide mutual support in the resolution of incidents.
Not achieved - At least one of the following statements is true:
- You do not know what data belonging to you is held by suppliers, or how it is managed.
- Elements of the supply chain for essential function(s) are subcontracted and you have little or no visibility of the sub-contractors.
- You have no understanding of which contracts are relevant and / or relevant contracts do not specify appropriate security obligations.
- Suppliers have access to systems that provide your essential function(s) that is unrestricted, not monitored or bypasses your own security controls.
Partially achieved - All the following statements are true:
- You understand the general risks suppliers may pose to your essential function(s).
- You know the extent of your supply chain that supports your essential function(s), including sub-contractors.
- Suppliers to network and information systems that support your essential function(s) can demonstrate appropriate and proportionate levels of cyber security within the context of common threats.
- You understand which contracts are relevant and you include appropriate security obligations in relevant contracts.
- You are aware of all third-party connections and have assurance that they meet your organisation’s security requirements.
- Your approach to security incident management considers incidents that might arise in your supply chain.
- You have confidence that information shared with suppliers that is necessary for the operation of your essential function(s) is appropriately protected from common threats.
Achieved - All the following statements are true:
- You have a deep understanding of your supply chain, including sub-contractors and the wider risks it faces.
- You consider factors such as your supplier’s ownership, nationality, partnerships, competitors, other organisations with which they sub-contract and their approach to cyber security. These factors inform your risk assessment and are fully considered in your procurement lifecycle processes and purchasing decisions.
- Your approach to supply chain risk management considers the risks to network and information systems supporting your essential function(s) arising from supply chain subversion by capable and well-resourced threat actors.
- Critical suppliers to network and information systems supporting your essential functions(s) can demonstrate appropriate and proportionate levels of cyber security within the context of capable and well-resourced threat actors.
- You have confidence that information held by suppliers that is essential to the operation of network and information systems supporting your essential function(s) is appropriately protected from capable and well-resourced threat actors.
- You understand which contracts are relevant and you include appropriate security obligations, in relevant contracts.
- You have a proactive approach to contract management which may include a contract management plan for relevant contracts.
- Customer / supplier ownership of responsibilities is defined in contracts.
- All network connections and data sharing with third parties are managed effectively and proportionately.
- When appropriate, your incident management process and that of your suppliers provide mutual support in the resolution of incidents.
A4.b Secure Software Development and Support
- You actively maximise the use of secure and supported software, whether developed internally or sourced externally, within network and information systems supporting the operation of your essential function(s).
- You actively maximise the use of secure and supported software, whether developed internally or sourced externally, within network and information systems supporting the operation of your essential function(s).
- Your software supplier(s) is unaware of the composition and provenance of software provided to you.
- Software, including updates and patches, undergoes little to no testing.
- Updates and patches often introduce new problems or fail to address existing issues.
- Vulnerabilities are discovered in software despite the negligible difficulty of implementing mitigations.
- Your software supplier leverages secure development principles and practices.
- Your software supplier(s) can demonstrate a limited understanding of the composition and provenance of software provided to you.
- You consider the security of environments (e.g. development, test and production), including source code and repositories, used in the production of software to be appropriate and proportionate within the context of common threats.
- The testing regime uses a range of different approaches (e.g. static and dynamic analysis, unit and integration testing and point in time assessments) that verify all aspects of the development lifecycle covering both functional and non-functional testing.
- You have arrangements in place with your software supplier to receive timely security updates, patches and notifications.
- Software, including updates and patches, is obtained from your supplier(s) via secure channels.
- Your software supplier(s) has processes in place to identify, report and mitigate security vulnerabilities.
- You have arrangements in place with your software supplier to be notified of any significant events that may adversely impact network and information systems supporting your essential function(s).
- If open-source software is used, you have taken appropriate and proportionate steps to establish and maintain sufficient confidence in its security for its use.
- You have appropriate support and maintenance arrangements in place.
- Your software supplier(s) leverages an established secure software development framework (e.g. NIST Secure Software Development Framework (SSDF), Microsoft Secure Development Lifecycle (SDL)).
- Your software supplier can demonstrate a thorough understanding of the composition and provenance of software provided to you, including any third-party components used in the development of that software, and those components are being monitored for new vulnerabilities throughout the lifespan of the product.
- You consider the security of environments (e.g. development, test, and production), including source code and repositories, used in the production of software to be appropriate and proportionate within the context of capable and well-resourced threat actors.
- The software development lifecycle is informed by a detailed and up to date understanding of threat and applies appropriate techniques, such as threat modelling, to identify and assess potential vulnerabilities and attack vectors.
- You can attest to the authenticity and integrity of software, including updates and patches.
Not achieved - At least one of the following statements is true:
- Your software supplier(s) is unaware of the composition and provenance of software provided to you.
- Software, including updates and patches, undergoes little to no testing.
- Updates and patches often introduce new problems or fail to address existing issues.
- Vulnerabilities are discovered in software despite the negligible difficulty of implementing mitigations.
Partially achieved - All the following statements are true:
- Your software supplier leverages secure development principles and practices.
- Your software supplier(s) can demonstrate a limited understanding of the composition and provenance of software provided to you.
- You consider the security of environments (e.g. development, test and production), including source code and repositories, used in the production of software to be appropriate and proportionate within the context of common threats.
- The testing regime uses a range of different approaches (e.g. static and dynamic analysis, unit and integration testing and point in time assessments) that verify all aspects of the development lifecycle covering both functional and non-functional testing.
- You have arrangements in place with your software supplier to receive timely security updates, patches and notifications.
- Software, including updates and patches, is obtained from your supplier(s) via secure channels.
- Your software supplier(s) has processes in place to identify, report and mitigate security vulnerabilities.
- You have arrangements in place with your software supplier to be notified of any significant events that may adversely impact network and information systems supporting your essential function(s).
- If open-source software is used, you have taken appropriate and proportionate steps to establish and maintain sufficient confidence in its security for its use.
- You have appropriate support and maintenance arrangements in place.
Achieved - All the following statements are true:
- Your software supplier(s) leverages an established secure software development framework (e.g. NIST Secure Software Development Framework (SSDF), Microsoft Secure Development Lifecycle (SDL)).
- Your software supplier can demonstrate a thorough understanding of the composition and provenance of software provided to you, including any third-party components used in the development of that software, and those components are being monitored for new vulnerabilities throughout the lifespan of the product.
- You consider the security of environments (e.g. development, test, and production), including source code and repositories, used in the production of software to be appropriate and proportionate within the context of capable and well-resourced threat actors.
- The software development lifecycle is informed by a detailed and up to date understanding of threat and applies appropriate techniques, such as threat modelling, to identify and assess potential vulnerabilities and attack vectors.
- You can attest to the authenticity and integrity of software, including updates and patches.
The organisation defines, implements, communicates and enforces appropriate policies, processes and procedures that direct its overall approach to securing systems and data that support the operation of essential functions.
Description
error determining description
Guidance
The policies, processes and procedures needed by an organisation depend upon its function and should integrate with the organisation’s approach to governance and risk management. Organisations responsible for essential functions should have a range of policies, processes and procedures, including:
An organisational security or service protection policy: endorsed by senior management, this high-level policy should include the organisation’s overarching approach to governing security and managing risks, the organisation’s aims and intents for security and what is of key concern.
Supporting policies, processes and procedures: contextual lower-level definitions controlling, directing and communicating organisational security practice.
Compliance policies and processes for sector regulations, standards, etc.: specific policies and processes appropriate to the compliance regime; these may be defined by the regulation, standard, etc. For example, to comply with ISO/IEC 27001, organisations should have in place certain security policies and procedures relevant to what the organisation does, how it does it, and what their ISO/IEC 27001 information security management system covers (see ISO/IEC 27002 for detail).
An organisational security or service protection policy: endorsed by senior management, this high-level policy should include the organisation’s overarching approach to governing security and managing risks, the organisation’s aims and intents for security and what is of key concern.
Contributing Outcomes
B1.a Policy, Process and Procedure Development
- You have developed and continue to improve a set of cyber security and resilience policies, processes and procedures that manage and mitigate the risk of adverse impact on your essential function(s).
- You have developed and continue to improve a set of cyber security and resilience policies, processes and procedures that manage and mitigate the risk of adverse impact on your essential function(s).
- Your policies, processes and procedures are absent or incomplete.
- Policies, processes and procedures are not applied universally or consistently.
- People often or routinely circumvent policies, processes and procedures to achieve business objectives.
- Your organisation’s security governance and risk management approach has no bearing on your policies, processes and procedures.
- System security is totally reliant on users' careful and consistent application of manual security processes.
- Policies, processes and procedures have not been reviewed in response to major changes (e.g. technology or regulatory framework), or within a suitable period.
- Policies, processes and procedures are not readily available to staff, too detailed to remember, or too hard to understand.
- Your policies, processes and procedures document your overarching security governance and risk management approach, technical security practice and specific regulatory compliance.
- You review and update policies, processes and procedures in response to major cyber security incidents.
- You fully document your overarching security governance and risk management approach, technical security practice and specific regulatory compliance.
- Cyber security is integrated and embedded throughout policies, processes and procedures and key performance indicators are reported to your executive management.
- Your organisation’s policies, processes and procedures are developed to be practical, usable and appropriate to mitigate the risk of adverse impact to network and information systems supporting your essential function(s).
- Policies, processes and procedures that rely on user behaviour are practical, appropriate and achievable.
- You review and update policies, processes and procedures at suitably regular intervals to ensure they remain relevant. This is in addition to reviews following a major cyber security incident.
- Any changes to the essential function(s) or the threat it faces triggers a review of policies, processes and procedures.
- Your systems are designed so that they remain secure even when user security policies, processes and procedures are not always followed.
Not achieved - At least one of the following statements is true:
- Your policies, processes and procedures are absent or incomplete.
- Policies, processes and procedures are not applied universally or consistently.
- People often or routinely circumvent policies, processes and procedures to achieve business objectives.
- Your organisation’s security governance and risk management approach has no bearing on your policies, processes and procedures.
- System security is totally reliant on users' careful and consistent application of manual security processes.
- Policies, processes and procedures have not been reviewed in response to major changes (e.g. technology or regulatory framework), or within a suitable period.
- Policies, processes and procedures are not readily available to staff, too detailed to remember, or too hard to understand.
Partially achieved - All the following statements are true:
- Your policies, processes and procedures document your overarching security governance and risk management approach, technical security practice and specific regulatory compliance.
- You review and update policies, processes and procedures in response to major cyber security incidents.
Achieved - All the following statements are true:
- You fully document your overarching security governance and risk management approach, technical security practice and specific regulatory compliance.
- Cyber security is integrated and embedded throughout policies, processes and procedures and key performance indicators are reported to your executive management.
- Your organisation’s policies, processes and procedures are developed to be practical, usable and appropriate to mitigate the risk of adverse impact to network and information systems supporting your essential function(s).
- Policies, processes and procedures that rely on user behaviour are practical, appropriate and achievable.
- You review and update policies, processes and procedures at suitably regular intervals to ensure they remain relevant. This is in addition to reviews following a major cyber security incident.
- Any changes to the essential function(s) or the threat it faces triggers a review of policies, processes and procedures.
- Your systems are designed so that they remain secure even when user security policies, processes and procedures are not always followed.
B1.b Policy, Process and Procedure Implementation
- You have successfully implemented your security policies, processes and procedures and can demonstrate the security benefits achieved.
- You have successfully implemented your security policies, processes and procedures and can demonstrate the security benefits achieved.
- Policies, processes and procedures are ignored or only partially followed.
- How your policies support the resilience of your essential function(s) is not well understood.
- Staff are unaware of their responsibilities under your policies, processes and procedures.
- You do not attempt to detect breaches of policies, processes and procedures.
- Policies, processes and procedures lack integration with other organisational policies, processes and procedures.
- Your policies, processes and procedures are not well communicated across your organisation.
- Most of your policies, processes and procedures are followed and their application is monitored.
- Your policies, processes and procedures are integrated with other organisational policies, processes and procedures, including HR assessments of individuals' trustworthiness.
- All staff are aware of their responsibilities under your policies, processes and procedures.
- All breaches of policies, processes and procedures with the potential to adversely impact the essential function(s) are fully investigated. Other breaches are tracked, assessed for trends and action is taken to understand and address.
- All your policies, processes and procedures are followed, their correct application and security effectiveness is evaluated.
- Your policies, processes and procedures are integrated with other organisational policies, processes and procedures, including HR assessments of individuals' trustworthiness.
- Your policies, processes and procedures are effectively and appropriately communicated across all levels of the organisation resulting in good staff awareness of their responsibilities.
- Appropriate action is taken to address all breaches of policies, processes and procedures with potential to adversely impact the essential function(s) including aggregated breaches.
Not achieved - At least one of the following statements is true:
- Policies, processes and procedures are ignored or only partially followed.
- How your policies support the resilience of your essential function(s) is not well understood.
- Staff are unaware of their responsibilities under your policies, processes and procedures.
- You do not attempt to detect breaches of policies, processes and procedures.
- Policies, processes and procedures lack integration with other organisational policies, processes and procedures.
- Your policies, processes and procedures are not well communicated across your organisation.
Partially achieved - All the following statements are true:
- Most of your policies, processes and procedures are followed and their application is monitored.
- Your policies, processes and procedures are integrated with other organisational policies, processes and procedures, including HR assessments of individuals' trustworthiness.
- All staff are aware of their responsibilities under your policies, processes and procedures.
- All breaches of policies, processes and procedures with the potential to adversely impact the essential function(s) are fully investigated. Other breaches are tracked, assessed for trends and action is taken to understand and address.
Achieved - All the following statements are true:
- All your policies, processes and procedures are followed, their correct application and security effectiveness is evaluated.
- Your policies, processes and procedures are integrated with other organisational policies, processes and procedures, including HR assessments of individuals' trustworthiness.
- Your policies, processes and procedures are effectively and appropriately communicated across all levels of the organisation resulting in good staff awareness of their responsibilities.
- Appropriate action is taken to address all breaches of policies, processes and procedures with potential to adversely impact the essential function(s) including aggregated breaches.
The organisation understands, documents and manages access to networks and information systems and supporting the operation of essential functions. Users (or automated functions) that can access data or services are appropriately verified, authenticated and authorised.
Description
It is important that the organisation is clear about who (or what in the case of automated functions) has authorisation to interact with the network and information systems supporting an essential function in any way or access associated sensitive data. Access rights granted should be carefully controlled, especially where those rights provide an ability to materially affect the operation of the essential function. Access rights granted should be periodically reviewed and technically removed when no longer required such as when an individual changes role or leaves the organisation.
Users, devices and systems should be appropriately verified, authenticated and authorised before access to data or services is granted. Verification of a user’s identity (they are who they say they are) is a prerequisite for issuing credentials, authentication and access management. For highly privileged access it might be appropriate to include approaches such as multi-factor or hardware authentication.
Unauthorised individuals should be prevented from accessing data or services at all points within the system. This includes system users without the appropriate permissions, unauthorised individuals attempting to interact with any online service or individuals with unauthorised access to user devices (for example if a user device were lost or stolen).
Guidance
The
Introduction to identity and access management
sets out security fundamentals that operators should consider in designing and managing identity and access management systems. Identity and access control should be robust enough that essential functions are not adversely affected by unauthorised access.
In addition to technical security, organisations should protect physical access to networks and information systems supporting the essential function, to prevent unauthorised access, tampering or data deletion. Some organisations may already have physical security measures in place to comply with non-cyber regulatory frameworks. See
NPSA guidance on Control Access
for further information.
Contributing Outcomes
B2.a Identity Verification, Authentication and Authorisation
- You robustly verify, authenticate and authorise access to the network and information systems supporting your essential function(s).
- You robustly verify, authenticate and authorise access to the network and information systems supporting your essential function(s).
- Initial identity verification is not robust enough to provide an acceptable level of confidence of a user’s identity profile.
- Authorised users and systems with access to networks or information systems on which your essential function(s) depends cannot be individually identified.
- Unauthorised individuals or devices can access your network or information systems on which your essential function(s) depends.
- The number of authorised users and systems that have access to your network and information systems are not limited to the minimum necessary.
- Your approach to authenticating users, devices and systems does not follow up to date best practice.
- Your process of initial identity verification is robust enough to provide a reasonable level of confidence of a user’s identity profile before allowing an authorised user access to network and information systems that support your essential function(s).
- All authorised users and systems with access to network or information systems on which your essential function(s) depends are individually identified and authenticated.
- The number of authorised users and systems that have access to essential function(s) network and information systems is limited to the minimum necessary.
- You use additional authentication mechanisms, such as multi-factor (MFA), for privileged access to all network and information systems that operate or support your essential function(s).
- You individually authenticate and authorise all remote access to all your network and information systems that support your essential function(s).
- The list of users and systems with access to network and information systems supporting and delivering the essential function(s) is reviewed on a regular basis, at least annually.
- Your approach to authenticating users, devices and systems follows up to date best practice.
- Your process of initial identity verification is robust enough to provide a high level of confidence of a user’s identity profile before allowing an authorised user access to network and information systems that support your essential function(s).
- Only authorised and individually authenticated users can physically access and logically connect to your network or information systems on which your essential function(s) depends.
- The number of authorised users and systems that have access to all your network and information systems supporting the essential function(s) is limited to the minimum necessary.
- You use additional authentication mechanisms, such as multi-factor (MFA), for all user access, including remote access, to all network and information systems that operate or support your essential function(s).
- The list of users and systems with access to network and information systems supporting and delivering the essential function(s) is reviewed on a regular basis, at least every six months.
- Your approach to authenticating users, devices and systems follows up to date best practice.
Not achieved - At least one of the following statements is true:
- Initial identity verification is not robust enough to provide an acceptable level of confidence of a user’s identity profile.
- Authorised users and systems with access to networks or information systems on which your essential function(s) depends cannot be individually identified.
- Unauthorised individuals or devices can access your network or information systems on which your essential function(s) depends.
- The number of authorised users and systems that have access to your network and information systems are not limited to the minimum necessary.
- Your approach to authenticating users, devices and systems does not follow up to date best practice.
Partially achieved - All the following statements are true:
- Your process of initial identity verification is robust enough to provide a reasonable level of confidence of a user’s identity profile before allowing an authorised user access to network and information systems that support your essential function(s).
- All authorised users and systems with access to network or information systems on which your essential function(s) depends are individually identified and authenticated.
- The number of authorised users and systems that have access to essential function(s) network and information systems is limited to the minimum necessary.
- You use additional authentication mechanisms, such as multi-factor (MFA), for privileged access to all network and information systems that operate or support your essential function(s).
- You individually authenticate and authorise all remote access to all your network and information systems that support your essential function(s).
- The list of users and systems with access to network and information systems supporting and delivering the essential function(s) is reviewed on a regular basis, at least annually.
- Your approach to authenticating users, devices and systems follows up to date best practice.
Achieved - All the following statements are true:
- Your process of initial identity verification is robust enough to provide a high level of confidence of a user’s identity profile before allowing an authorised user access to network and information systems that support your essential function(s).
- Only authorised and individually authenticated users can physically access and logically connect to your network or information systems on which your essential function(s) depends.
- The number of authorised users and systems that have access to all your network and information systems supporting the essential function(s) is limited to the minimum necessary.
- You use additional authentication mechanisms, such as multi-factor (MFA), for all user access, including remote access, to all network and information systems that operate or support your essential function(s).
- The list of users and systems with access to network and information systems supporting and delivering the essential function(s) is reviewed on a regular basis, at least every six months.
- Your approach to authenticating users, devices and systems follows up to date best practice.
B2.b Device Management
- You fully know and have trust in the devices that are used to access your networks, information systems and data that support your essential function(s).
- You fully know and have trust in the devices that are used to access your networks, information systems and data that support your essential function(s).
- Users can connect to your essential function(s)'s network and information systems using devices that are not corporately owned and managed.
- Privileged users can perform privileged operations from devices that are not corporately owned and managed.
- You have not gained assurance in the security of any third-party devices or networks connected to your systems.
- Physically connecting a device to your network and information systems gives that device access without device or user authentication.
- Only corporately owned and managed devices can access your essential function(s)'s network and information systems.
- All privileged operations are performed from corporately owned and managed devices. These devices provide sufficient separation, using a risk-based approach, from the activities of standard users.
- You have sought to understand the security properties of third-party devices and networks before they can be connected to your systems. You have taken appropriate steps to mitigate any risks identified.
- The act of connecting to a network port or cable does not grant access to any systems.
- You are able to detect unknown devices being connected to your network and information systems and investigate such incidents.
- All privileged operations performed on your network and information systems supporting your essential function(s) are conducted from highly trusted devices, such as Privileged Access Workstations, dedicated solely to those operations.
- You either obtain independent and professional assurance of the security of third-party devices or networks before they connect to your network and information systems, or you only allow third-party devices or networks that are dedicated to supporting your network and information systems to connect.
- You perform certificate-based device identity management and only allow known devices to access systems necessary for the operation of your essential function(s).
- You perform regular scans to detect unknown devices and investigate any findings.
Not achieved - At least one of the following statements is true:
- Users can connect to your essential function(s)'s network and information systems using devices that are not corporately owned and managed.
- Privileged users can perform privileged operations from devices that are not corporately owned and managed.
- You have not gained assurance in the security of any third-party devices or networks connected to your systems.
- Physically connecting a device to your network and information systems gives that device access without device or user authentication.
Partially achieved - All the following statements are true:
- Only corporately owned and managed devices can access your essential function(s)'s network and information systems.
- All privileged operations are performed from corporately owned and managed devices. These devices provide sufficient separation, using a risk-based approach, from the activities of standard users.
- You have sought to understand the security properties of third-party devices and networks before they can be connected to your systems. You have taken appropriate steps to mitigate any risks identified.
- The act of connecting to a network port or cable does not grant access to any systems.
- You are able to detect unknown devices being connected to your network and information systems and investigate such incidents.
Achieved - All the following statements are true:
- All privileged operations performed on your network and information systems supporting your essential function(s) are conducted from highly trusted devices, such as Privileged Access Workstations, dedicated solely to those operations.
- You either obtain independent and professional assurance of the security of third-party devices or networks before they connect to your network and information systems, or you only allow third-party devices or networks that are dedicated to supporting your network and information systems to connect.
- You perform certificate-based device identity management and only allow known devices to access systems necessary for the operation of your essential function(s).
- You perform regular scans to detect unknown devices and investigate any findings.
B2.c Privileged User Management
- You closely manage privileged user access to network and information systems supporting the essential function(s).
- You closely manage privileged user access to network and information systems supporting the essential function(s).
- The identities of the individuals with privileged access to your essential function(s) network and information systems (infrastructure, platforms, software, configuration, etc) are not known or not managed.
- Privileged user access to your essential function(s) network and information systems is via weak authentication mechanisms (e.g. only simple passwords).
- The list of privileged users has not been reviewed recently (e.g. within the last 12 months).
- Privileged user access is granted on a system-wide basis rather than by role or function(s).
- Privileged user access to your essential function(s) is via generic, shared or default name accounts.
- Where there are “always on” terminals which can perform privileged actions (such as in a control room), there are no additional controls (e.g. physical controls) to ensure access is appropriately restricted.
- There is no logical separation between roles that an individual may have and hence the actions they perform. (e.g. access to corporate email and privilege user actions).
- All privileged user access to your network and information systems requires strong authentication, such as multi-factor (MFA).
- The identities of the individuals with privileged access to your essential function(s) network and information systems (infrastructure, platforms, software, configuration, etc) are known and managed. This includes third parties.
- Activity by privileged users is routinely reviewed and validated. (e.g. at least annually).
- Privileged users are only granted specific privileged user access rights which are essential to their business role or function.
- Privileged user access to your essential function(s) systems is carried out from dedicated separate accounts that are closely monitored and managed.
- The issuing of temporary, time-bound rights for privileged user access and / or external third-party support access is in place.
- Privileged user access rights are regularly reviewed and always updated as part of your joiners, movers and leavers process.
- All privileged user activity is routinely reviewed, validated and recorded for offline analysis and investigation.
Not achieved - At least one of the following statements is true:
- The identities of the individuals with privileged access to your essential function(s) network and information systems (infrastructure, platforms, software, configuration, etc) are not known or not managed.
- Privileged user access to your essential function(s) network and information systems is via weak authentication mechanisms (e.g. only simple passwords).
- The list of privileged users has not been reviewed recently (e.g. within the last 12 months).
- Privileged user access is granted on a system-wide basis rather than by role or function(s).
- Privileged user access to your essential function(s) is via generic, shared or default name accounts.
- Where there are “always on” terminals which can perform privileged actions (such as in a control room), there are no additional controls (e.g. physical controls) to ensure access is appropriately restricted.
- There is no logical separation between roles that an individual may have and hence the actions they perform. (e.g. access to corporate email and privilege user actions).
Partially achieved - All of the following statements are true:
- All privileged user access to your network and information systems requires strong authentication, such as multi-factor (MFA).
- The identities of the individuals with privileged access to your essential function(s) network and information systems (infrastructure, platforms, software, configuration, etc) are known and managed. This includes third parties.
- Activity by privileged users is routinely reviewed and validated. (e.g. at least annually).
- Privileged users are only granted specific privileged user access rights which are essential to their business role or function.
Achieved - All of the following statements are true:
- Privileged user access to your essential function(s) systems is carried out from dedicated separate accounts that are closely monitored and managed.
- The issuing of temporary, time-bound rights for privileged user access and / or external third-party support access is in place.
- Privileged user access rights are regularly reviewed and always updated as part of your joiners, movers and leavers process.
- All privileged user activity is routinely reviewed, validated and recorded for offline analysis and investigation.
B2.d Identity and Access Management (IdAM)
- You closely manage and maintain identity and access control for users, devices and systems accessing the network and information systems supporting the essential function(s).
- You closely manage and maintain identity and access control for users, devices and systems accessing the network and information systems supporting the essential function(s).
- Greater access rights are granted than necessary.
- Identity validation and requirement for access of a user, device or systems is not carried out.
- User access rights are not reviewed when users change roles.
- User access rights remain active when users leave your organisation.
- Access rights granted to devices or systems to access other devices and systems are not reviewed on a regular basis (at least annually).
- You follow a robust procedure to verify each user and issue the minimum required access rights.
- You regularly review access rights and those no longer needed are revoked.
- User access rights are reviewed when users change roles via your joiners, leavers and movers process.
- All user, device and system access to the systems supporting the essential function(s) is logged and monitored, but it is not compared to other log data or access records.
- You follow a robust procedure to verify each user and issue the minimum required access rights, and the application of the procedure is regularly audited.
- User access rights are reviewed both when people change roles via your joiners, leavers and movers process and at regular intervals - at least annually.
- All user, device and systems access to the systems supporting the essential function(s) is logged and monitored.
- You regularly review access logs and correlate this data with other access records and expected activity.
- Attempts by unauthorised users, devices or systems to connect to the systems supporting the essential function(s) are alerted, promptly assessed and investigated.
Not achieved - At least one of the following statements is true:
- Greater access rights are granted than necessary.
- Identity validation and requirement for access of a user, device or systems is not carried out.
- User access rights are not reviewed when users change roles.
- User access rights remain active when users leave your organisation.
- Access rights granted to devices or systems to access other devices and systems are not reviewed on a regular basis (at least annually).
Partially achieved - All of the following statements are true:
- You follow a robust procedure to verify each user and issue the minimum required access rights.
- You regularly review access rights and those no longer needed are revoked.
- User access rights are reviewed when users change roles via your joiners, leavers and movers process.
- All user, device and system access to the systems supporting the essential function(s) is logged and monitored, but it is not compared to other log data or access records.
Achieved - All of the following statements are true:
- You follow a robust procedure to verify each user and issue the minimum required access rights, and the application of the procedure is regularly audited.
- User access rights are reviewed both when people change roles via your joiners, leavers and movers process and at regular intervals - at least annually.
- All user, device and systems access to the systems supporting the essential function(s) is logged and monitored.
- You regularly review access logs and correlate this data with other access records and expected activity.
- Attempts by unauthorised users, devices or systems to connect to the systems supporting the essential function(s) are alerted, promptly assessed and investigated.
Data stored or transmitted electronically is protected from actions such as unauthorised access, modification, or deletion that may cause an adverse impact on essential functions. Such protection extends to the means by which authorised users, devices and systems access critical data necessary for the operation of essential functions. It also covers information that would assist an attacker, such as design details of networks and information systems.
Description
error determining description
Guidance
Networks and information systems should be designed to protect important data, for example:
protecting the confidentiality of sensitive data by minimising the number of copies of data, the detail these include and by retaining operationally sensitive data on segregated systems (this includes design documentation)
removing functionality that could allow greater access than has been authorised
protecting the integrity of data essential to the operation of the function by providing a read-only copy for non-essential business system consumption
only deploying well-tested cryptographic suites in common use by your chosen software stack
protecting availability through
resilience
measures such as multiple network paths and tested automatic backup systems
consider suitable means to retain access to essential information in the event of an incident. For example, network diagrams needed for restoration, safety-critical information or essential forecasting data
protecting the confidentiality of sensitive data by minimising the number of copies of data, the detail these include and by retaining operationally sensitive data on segregated systems (this includes design documentation)
Contributing Outcomes
B3.a Understanding Data
- You have a good understanding of data important to the operation of network and information systems supporting your essential function(s), where it is stored, where it travels and how unavailability or unauthorised access, uncontrolled release, modification or deletion would adversely impact the essential function(s). This also applies to third parties storing or accessing data important to the operation of essential function(s).
- You have a good understanding of data important to the operation of network and information systems supporting your essential function(s), where it is stored, where it travels and how unavailability or unauthorised access, uncontrolled release, modification or deletion would adversely impact the essential function(s). This also applies to third parties storing or accessing data important to the operation of essential function(s).
- You have incomplete knowledge of what data is used by and produced in the operation of network and information systems supporting your essential function(s).
- You have not identified the important data on which network and information systems supporting your essential function(s) relies.
- You have not identified who has access to data important to the operation of network and information systems supporting your essential function(s).
- You have not clearly articulated the impact of data compromise or lack of availability.
- You have identified and catalogued all the data important to the operation of network and information systems supporting your essential function(s), or that would assist a threat actor.
- You have identified and catalogued who has access to the data important to the operation of network and information systems supporting your essential function(s).
- You regularly review location, transmission, quantity and quality of data important to the operation of network and information systems supporting your essential function(s).
- You have identified all mobile devices and media that hold data important to the operation of network and information systems supporting your essential function(s).
- You understand and document the impact on your essential function(s) of all relevant scenarios, including unauthorised data access, uncontrolled release, modification or deletion, or when authorised users are unable to appropriately access this data.
- You occasionally validate these documented impact statements.
- You have identified and catalogued all the data important to the operation of network and information systems supporting your essential function(s), or that would assist a threat actor.
- You have identified and catalogued who has access to the data important to the operation of network and information systems supporting your essential function(s).
- You maintain a current understanding of the location, quantity and quality of data important to the operation of network and information systems supporting your essential function(s).
- You take steps to remove or minimise unnecessary copies or unneeded historic data.
- You have identified all mobile devices and media that may hold data important to the operation of network and information systems supporting your essential function(s).
- You maintain a current understanding of the data links used to transmit data that is important to network and information systems supporting your essential function(s).
- You understand the context, limitations and dependencies of your important data.
- You understand and document the impact on your essential function(s) of all relevant scenarios, including unauthorised data access, uncontrolled release, modification or deletion, or when authorised users are unable to appropriately access this data.
- You validate these documented impact statements regularly, at least annually.
Not achieved - At least one of the following statements is true:
- You have incomplete knowledge of what data is used by and produced in the operation of network and information systems supporting your essential function(s).
- You have not identified the important data on which network and information systems supporting your essential function(s) relies.
- You have not identified who has access to data important to the operation of network and information systems supporting your essential function(s).
- You have not clearly articulated the impact of data compromise or lack of availability.
Partially achieved - All of the following statements are true:
- You have identified and catalogued all the data important to the operation of network and information systems supporting your essential function(s), or that would assist a threat actor.
- You have identified and catalogued who has access to the data important to the operation of network and information systems supporting your essential function(s).
- You regularly review location, transmission, quantity and quality of data important to the operation of network and information systems supporting your essential function(s).
- You have identified all mobile devices and media that hold data important to the operation of network and information systems supporting your essential function(s).
- You understand and document the impact on your essential function(s) of all relevant scenarios, including unauthorised data access, uncontrolled release, modification or deletion, or when authorised users are unable to appropriately access this data.
- You occasionally validate these documented impact statements.
Achieved - All of the following statements are true:
- You have identified and catalogued all the data important to the operation of network and information systems supporting your essential function(s), or that would assist a threat actor.
- You have identified and catalogued who has access to the data important to the operation of network and information systems supporting your essential function(s).
- You maintain a current understanding of the location, quantity and quality of data important to the operation of network and information systems supporting your essential function(s).
- You take steps to remove or minimise unnecessary copies or unneeded historic data.
- You have identified all mobile devices and media that may hold data important to the operation of network and information systems supporting your essential function(s).
- You maintain a current understanding of the data links used to transmit data that is important to network and information systems supporting your essential function(s).
- You understand the context, limitations and dependencies of your important data.
- You understand and document the impact on your essential function(s) of all relevant scenarios, including unauthorised data access, uncontrolled release, modification or deletion, or when authorised users are unable to appropriately access this data.
- You validate these documented impact statements regularly, at least annually.
B3.b Data in Transit
- You have protected the transit of data important to the operation of network and information systems supporting your essential function(s). This includes the transfer of data to third parties.
- You have protected the transit of data important to the operation of network and information systems supporting your essential function(s). This includes the transfer of data to third parties.
- You do not know what all your data links are, or which carry data important to the operation of the essential function(s).
- Data important to the operation of the essential function(s) travels without technical protection over non-trusted or openly accessible carriers.
- Critical data paths that could fail, be jammed, be overloaded, etc. have no alternative path.
- You have identified and protected (effectively and proportionately) all the data links that carry data important to the operation of your essential function(s).
- You apply appropriate technical means (e.g. cryptography) to protect data that travels over non-trusted or openly accessible carriers, but you have limited or no confidence in the robustness of the protection applied.
- You have identified and protected (effectively and proportionately) all the data links that carry data important to the operation of your essential function(s).
- You apply appropriate physical and/or technical means to protect data that travels over non-trusted or openly accessible carriers, with justified confidence in the robustness of the protection applied.
- Suitable alternative transmission paths are available where there is a significant risk of impact on the operation of the essential function(s) due to resource limitation (e.g. transmission equipment or function failure, or important data being blocked or jammed).
Not achieved - At least one of the following statements is true:
- You do not know what all your data links are, or which carry data important to the operation of the essential function(s).
- Data important to the operation of the essential function(s) travels without technical protection over non-trusted or openly accessible carriers.
- Critical data paths that could fail, be jammed, be overloaded, etc. have no alternative path.
Partially achieved - All the following statements are true:
- You have identified and protected (effectively and proportionately) all the data links that carry data important to the operation of your essential function(s).
- You apply appropriate technical means (e.g. cryptography) to protect data that travels over non-trusted or openly accessible carriers, but you have limited or no confidence in the robustness of the protection applied.
Achieved - All the following statements are true:
- You have identified and protected (effectively and proportionately) all the data links that carry data important to the operation of your essential function(s).
- You apply appropriate physical and/or technical means to protect data that travels over non-trusted or openly accessible carriers, with justified confidence in the robustness of the protection applied.
- Suitable alternative transmission paths are available where there is a significant risk of impact on the operation of the essential function(s) due to resource limitation (e.g. transmission equipment or function failure, or important data being blocked or jammed).
B3.c Stored Data
- You have protected stored soft and hard copy data important to the operation of network and information systems supporting your essential function(s).
- You have protected stored soft and hard copy data important to the operation of network and information systems supporting your essential function(s).
- You have no, or limited, knowledge of where data important to the operation of the essential function(s) is stored.
- You have not protected vulnerable stored data important to the operation of the essential function(s) in a suitable way.
- Backups are incomplete, untested, not adequately secured or could be inaccessible in a disaster recovery or business continuity situation.
- All copies of data important to the operation of your essential function(s) are necessary. Where this important data is transferred to less secure systems, the data is provided with limited detail and / or as a read-only copy.
- You have applied suitable physical and / or technical means to protect this important stored data from unauthorised access, modification or deletion.
- If cryptographic protections are used, you apply suitable technical and procedural means, but you have limited or no confidence in the robustness of the protection applied.
- You have suitable, secured backups of data to allow the operation of the essential function(s) to continue should the original data not be available. This may include off-line or segregated backups, or appropriate alternative forms such as paper copies.
- All copies of data important to the operation of your essential function(s) are necessary. Where this important data is transferred to less secure systems, the data is provided with limited detail and / or as a read-only copy.
- You have applied suitable physical and / or technical means to protect this important stored data from unauthorised access, modification or deletion.
- If cryptographic protections are used you apply suitable technical and procedural means, and you have justified confidence in the robustness of the protection applied.
- You have suitable, secured backups of data to allow the operation of the essential function(s) to continue should the original data not be available. This may include off-line or segregated backups, or appropriate alternative forms such as paper copies.
- Necessary historic or archive data is suitably secured in storage.
Not achieved - At least one of the following statements is true:
- You have no, or limited, knowledge of where data important to the operation of the essential function(s) is stored.
- You have not protected vulnerable stored data important to the operation of the essential function(s) in a suitable way.
- Backups are incomplete, untested, not adequately secured or could be inaccessible in a disaster recovery or business continuity situation.
Partially achieved - All of the following statements are true:
- All copies of data important to the operation of your essential function(s) are necessary. Where this important data is transferred to less secure systems, the data is provided with limited detail and / or as a read-only copy.
- You have applied suitable physical and / or technical means to protect this important stored data from unauthorised access, modification or deletion.
- If cryptographic protections are used, you apply suitable technical and procedural means, but you have limited or no confidence in the robustness of the protection applied.
- You have suitable, secured backups of data to allow the operation of the essential function(s) to continue should the original data not be available. This may include off-line or segregated backups, or appropriate alternative forms such as paper copies.
Achieved - All of the following statements are true:
- All copies of data important to the operation of your essential function(s) are necessary. Where this important data is transferred to less secure systems, the data is provided with limited detail and / or as a read-only copy.
- You have applied suitable physical and / or technical means to protect this important stored data from unauthorised access, modification or deletion.
- If cryptographic protections are used you apply suitable technical and procedural means, and you have justified confidence in the robustness of the protection applied.
- You have suitable, secured backups of data to allow the operation of the essential function(s) to continue should the original data not be available. This may include off-line or segregated backups, or appropriate alternative forms such as paper copies.
- Necessary historic or archive data is suitably secured in storage.
B3.d Mobile Data
- You have protected data important to the operation of network and information systems supporting your essential function(s) on mobile devices (e.g. smartphones, tablets and laptops).
- You have protected data important to the operation of network and information systems supporting your essential function(s) on mobile devices (e.g. smartphones, tablets and laptops).
- You don’t know which mobile devices may hold data important to the operation of the essential function(s).
- You allow data important to the operation of the essential function(s) to be stored on devices not managed by your organisation, or to at least equivalent standard.
- Data on mobile devices is not technically secured, or only some is secured.
- You know which mobile devices hold data important to the operation of the essential function(s).
- Data important to the operation of the essential function(s) is stored on mobile devices only when they have at least the security standard aligned to your overarching security policies.
- Data on mobile devices is technically secured.
- Mobile devices that hold data that is important to the operation of the essential function(s) are catalogued, are under your organisation's control and configured according to best practice for the platform, with appropriate technical and procedural policies in place.
- Your organisation can remotely wipe all mobile devices holding data important to the operation of the essential function(s).
- You have minimised this data on these mobile devices. Some data may be automatically deleted off mobile devices after a certain period.
Not achieved - At least one of the following statements is true:
- You don’t know which mobile devices may hold data important to the operation of the essential function(s).
- You allow data important to the operation of the essential function(s) to be stored on devices not managed by your organisation, or to at least equivalent standard.
- Data on mobile devices is not technically secured, or only some is secured.
Partially achieved - All of the following statements are true:
- You know which mobile devices hold data important to the operation of the essential function(s).
- Data important to the operation of the essential function(s) is stored on mobile devices only when they have at least the security standard aligned to your overarching security policies.
- Data on mobile devices is technically secured.
Achieved - All of the following statements are true:
- Mobile devices that hold data that is important to the operation of the essential function(s) are catalogued, are under your organisation's control and configured according to best practice for the platform, with appropriate technical and procedural policies in place.
- Your organisation can remotely wipe all mobile devices holding data important to the operation of the essential function(s).
- You have minimised this data on these mobile devices. Some data may be automatically deleted off mobile devices after a certain period.
B3.e Media/Equipment Sanitisation
- Before reuse and / or disposal you appropriately sanitise devices, equipment and removable media holding data important to the operation of network and information systems supporting your essential function(s).
- Before reuse and / or disposal you appropriately sanitise devices, equipment and removable media holding data important to the operation of network and information systems supporting your essential function(s).
- You catalogue and track all devices that contain data important to the operation of the essential function(s) (whether a specific storage device or one with integral storage).
- Data important to the operation of the essential function(s) is removed from all devices, equipment and removable media before reuse and / or disposal using an assured product or service.
Not achieved - At least one of the following statements is true:
Partially achieved - All of the following statements are true:
Achieved - All of the following statements are true:
- You catalogue and track all devices that contain data important to the operation of the essential function(s) (whether a specific storage device or one with integral storage).
- Data important to the operation of the essential function(s) is removed from all devices, equipment and removable media before reuse and / or disposal using an assured product or service.
Network and information systems and technology critical for the operation of essential functions are protected from cyber attack. An organisational understanding of risk to essential functions informs the use of robust and reliable protective security measures to effectively limit opportunities for threat actors to compromise networks and systems.
Description
error determining description
Guidance
The majority of cyber security incidents can be traced to
common cyber attack
vectors. The opportunity for successful attack can be minimised by managing the known vulnerabilities which these attacks exploit. Many opportunities for user error can be reduced by technical means.
Attempts to circumvent the measures described below should be detected by
security monitoring
. Together with
data security
and
resilience measures
, the impact of any attempts to circumvent security on the operation of the essential function should be limited.
Contributing Outcomes
B4.a Secure by Design
- You design security into the network and information systems that support the operation of the essential function(s). You minimise their attack surface and ensure that the operation of the essential function(s) should not be impacted by the exploitation of any single vulnerability.
- You design security into the network and information systems that support the operation of the essential function(s). You minimise their attack surface and ensure that the operation of the essential function(s) should not be impacted by the exploitation of any single vulnerability.
- Network and information systems supporting the operation of the essential function(s) are not appropriately segregated from other systems.
- Internet services, such as browsing and email are accessible from network and information systems supporting your essential function(s).
- Data flows between network and information systems supporting your essential function(s) and other systems are complex, making it hard to discriminate between legitimate and illegitimate / malicious traffic.
- Remote or third-party accesses circumvent some network controls to gain more direct access to network and information systems supporting the essential function(s).
- You employ appropriate expertise to design network and information systems supporting your essential function(s).
- You design strong boundary defences where your network and information systems interface with other organisations or the world at large.
- You design simple data flows between your network and information systems and any external interface to enable effective monitoring.
- You design to make network and information system recovery simple.
- All inputs to network and information systems are checked and validated at the network boundary where possible, or additional monitoring is in place for content-based attacks.
- You employ appropriate expertise to design network and information systems supporting your essential function(s).
- Network and information systems are segregated into appropriate security zones (e.g. systems supporting the essential function(s) are segregated in a highly trusted, more secure zone).
- The network and information systems supporting your essential function(s) are designed to have simple data flows between components to support effective security monitoring.
- The network and information systems supporting your essential function(s) are designed to be easy to recover.
- Content-based attacks are mitigated for all inputs to network and information systems that affect the essential function(s) (e.g. via transformation and inspection / sanitisation and validation).
- If automated decision-making technologies are in use, you design and apply appropriate restrictions to prevent actions that could have an adverse impact on network and information systems supporting your essential function(s).
Not achieved - At least one of the following statements is true:
- Network and information systems supporting the operation of the essential function(s) are not appropriately segregated from other systems.
- Internet services, such as browsing and email are accessible from network and information systems supporting your essential function(s).
- Data flows between network and information systems supporting your essential function(s) and other systems are complex, making it hard to discriminate between legitimate and illegitimate / malicious traffic.
- Remote or third-party accesses circumvent some network controls to gain more direct access to network and information systems supporting the essential function(s).
Partially achieved - All the following statements are true:
- You employ appropriate expertise to design network and information systems supporting your essential function(s).
- You design strong boundary defences where your network and information systems interface with other organisations or the world at large.
- You design simple data flows between your network and information systems and any external interface to enable effective monitoring.
- You design to make network and information system recovery simple.
- All inputs to network and information systems are checked and validated at the network boundary where possible, or additional monitoring is in place for content-based attacks.
Achieved - All the following statements are true:
- You employ appropriate expertise to design network and information systems supporting your essential function(s).
- Network and information systems are segregated into appropriate security zones (e.g. systems supporting the essential function(s) are segregated in a highly trusted, more secure zone).
- The network and information systems supporting your essential function(s) are designed to have simple data flows between components to support effective security monitoring.
- The network and information systems supporting your essential function(s) are designed to be easy to recover.
- Content-based attacks are mitigated for all inputs to network and information systems that affect the essential function(s) (e.g. via transformation and inspection / sanitisation and validation).
- If automated decision-making technologies are in use, you design and apply appropriate restrictions to prevent actions that could have an adverse impact on network and information systems supporting your essential function(s).
B4.b Secure Configuration
- You securely configure network and information systems that support the operation of your essential function(s).
- You securely configure network and information systems that support the operation of your essential function(s).
- You haven't identified the assets that need to be carefully configured to maintain the security of the essential function(s).
- Policies relating to the security of operating system builds or configuration are not applied consistently across your network and information systems relating to your essential function(s).
- Configuration details are not recorded or lack enough information to be able to rebuild the system or device.
- The recording of security changes or adjustments that affect your essential function(s) is lacking or inconsistent.
- Generic, shared, default name and built-in accounts have not been removed or disabled.
- Standard users are able to change settings that would adversely impact the security of network and information systems supporting your essential function(s).
- You have identified and documented the assets that need to be carefully configured to maintain the security of the essential function(s).
- Secure platform and device builds are used across the estate.
- Consistent, secure and minimal system and device configurations are applied across the same types of environment.
- Changes and adjustments to security configuration at security boundaries with the network and information systems supporting your essential function(s) are approved and documented.
- You verify software before installation is permitted.
- Generic, shared, default name and built-in accounts have been removed or disabled. Where this is not possible, credentials to these accounts have been changed. Service accounts are appropriately protected.
- Standard users are not able to change settings that would adversely impact the security of network and information systems supporting your essential function(s).
- You have identified, documented and actively manage (e.g. maintain security configurations, patching, updating according to good practice) the assets that need to be carefully configured to maintain the security of the essential function(s).
- All platforms conform to your secure, defined baseline build, or the latest known good configuration version for that environment.
- You closely and effectively manage changes in your environment, ensuring that network and system configurations are secure and documented.
- You regularly review and validate that your network and information systems have the expected, secure settings and configuration.
- Only permitted software can be installed.
- If automated decision-making technologies are in use, their operation is well understood, and decisions can be replicated.
- Generic, shared, default name and built-in accounts have been removed or disabled. Where this is not possible, credentials to these accounts have been changed. Service accounts are appropriately protected.
Not achieved - At least one of the following statements is true:
- You haven't identified the assets that need to be carefully configured to maintain the security of the essential function(s).
- Policies relating to the security of operating system builds or configuration are not applied consistently across your network and information systems relating to your essential function(s).
- Configuration details are not recorded or lack enough information to be able to rebuild the system or device.
- The recording of security changes or adjustments that affect your essential function(s) is lacking or inconsistent.
- Generic, shared, default name and built-in accounts have not been removed or disabled.
- Standard users are able to change settings that would adversely impact the security of network and information systems supporting your essential function(s).
Partially achieved - All of the following statements are true:
- You have identified and documented the assets that need to be carefully configured to maintain the security of the essential function(s).
- Secure platform and device builds are used across the estate.
- Consistent, secure and minimal system and device configurations are applied across the same types of environment.
- Changes and adjustments to security configuration at security boundaries with the network and information systems supporting your essential function(s) are approved and documented.
- You verify software before installation is permitted.
- Generic, shared, default name and built-in accounts have been removed or disabled. Where this is not possible, credentials to these accounts have been changed. Service accounts are appropriately protected.
- Standard users are not able to change settings that would adversely impact the security of network and information systems supporting your essential function(s).
Achieved - All of the following statements are true:
- You have identified, documented and actively manage (e.g. maintain security configurations, patching, updating according to good practice) the assets that need to be carefully configured to maintain the security of the essential function(s).
- All platforms conform to your secure, defined baseline build, or the latest known good configuration version for that environment.
- You closely and effectively manage changes in your environment, ensuring that network and system configurations are secure and documented.
- You regularly review and validate that your network and information systems have the expected, secure settings and configuration.
- Only permitted software can be installed.
- If automated decision-making technologies are in use, their operation is well understood, and decisions can be replicated.
- Generic, shared, default name and built-in accounts have been removed or disabled. Where this is not possible, credentials to these accounts have been changed. Service accounts are appropriately protected.
B4.c Secure Management
- You manage your organisation's network and information systems that support the operation of your essential function(s) to enable and maintain security.
- You manage your organisation's network and information systems that support the operation of your essential function(s) to enable and maintain security.
- Your systems and devices supporting the operation of the essential function(s) are administered or maintained from devices that are not corporately owned and managed.
- You do not have good or current technical documentation of your network and information systems.
- Your systems and devices supporting the operation of the essential function(s) are only administered or maintained by authorised privileged users from devices sufficiently separated, using a risk-based approach, from the activities of standard users.
- Technical knowledge about network and information systems, such as documentation and network diagrams, is regularly reviewed and updated.
- You prevent, detect and remove malware or unauthorised software. You use technical, procedural and physical measures as necessary.
- Your systems and devices supporting the operation of the essential function(s) are only administered or maintained by authorised privileged users from highly trusted devices, such as Privileged Access Workstations, dedicated solely to those operations.
- You regularly review and update technical knowledge about network and information systems, such as documentation and network diagrams, and ensure they are securely stored.
- You prevent, detect and remove malware or unauthorised software. You use technical, procedural and physical measures as necessary.
Not achieved - At least one of the following statements is true:
- Your systems and devices supporting the operation of the essential function(s) are administered or maintained from devices that are not corporately owned and managed.
- You do not have good or current technical documentation of your network and information systems.
Partially achieved - All of the following statements are true:
- Your systems and devices supporting the operation of the essential function(s) are only administered or maintained by authorised privileged users from devices sufficiently separated, using a risk-based approach, from the activities of standard users.
- Technical knowledge about network and information systems, such as documentation and network diagrams, is regularly reviewed and updated.
- You prevent, detect and remove malware or unauthorised software. You use technical, procedural and physical measures as necessary.
Achieved - All of the following statements are true:
- Your systems and devices supporting the operation of the essential function(s) are only administered or maintained by authorised privileged users from highly trusted devices, such as Privileged Access Workstations, dedicated solely to those operations.
- You regularly review and update technical knowledge about network and information systems, such as documentation and network diagrams, and ensure they are securely stored.
- You prevent, detect and remove malware or unauthorised software. You use technical, procedural and physical measures as necessary.
B4.d Vulnerability Management
- You manage known vulnerabilities in network and information systems to prevent adverse impact on your essential function(s).
- You manage known vulnerabilities in network and information systems to prevent adverse impact on your essential function(s).
- You do not understand the exposure of your essential function(s) to publicly-known vulnerabilities.
- You do not mitigate externally exposed vulnerabilities promptly.
- You have not recently tested to verify your understanding of the vulnerabilities of the network and information systems that support your essential function(s).
- You have not suitably mitigated systems or software that is no longer supported.
- You are not pursuing replacement for unsupported systems or software.
- You maintain a current understanding of the exposure of your essential function(s) to publicly-known vulnerabilities.
- Announced vulnerabilities for all software packages, network and information systems used to support your essential function(s) are tracked, prioritised and externally exposed vulnerabilities are mitigated (e.g. by patching) promptly.
- Some vulnerabilities that are not externally exposed have temporary mitigations for an extended period.
- You have temporary mitigations for unsupported systems and software while pursuing migration to supported technology.
- You regularly test to fully understand the vulnerabilities of the network and information systems that support the operation of your essential function(s).
- You maintain a current understanding of the exposure of your essential function(s) to publicly-known vulnerabilities.
- Announced vulnerabilities for all software packages, network and information systems used to support your essential function(s) are tracked, prioritised and mitigated (e.g. by patching) promptly.
- You regularly test to fully understand the vulnerabilities of the network and information systems that support the operation of your essential function(s) and verify this understanding with third-party testing.
- You actively maximise the use of supported software, firmware and hardware in your network and information systems supporting your essential function(s).
Not achieved - At least one of the following statements is true:
- You do not understand the exposure of your essential function(s) to publicly-known vulnerabilities.
- You do not mitigate externally exposed vulnerabilities promptly.
- You have not recently tested to verify your understanding of the vulnerabilities of the network and information systems that support your essential function(s).
- You have not suitably mitigated systems or software that is no longer supported.
- You are not pursuing replacement for unsupported systems or software.
Partially achieved - All of the following statements are true:
- You maintain a current understanding of the exposure of your essential function(s) to publicly-known vulnerabilities.
- Announced vulnerabilities for all software packages, network and information systems used to support your essential function(s) are tracked, prioritised and externally exposed vulnerabilities are mitigated (e.g. by patching) promptly.
- Some vulnerabilities that are not externally exposed have temporary mitigations for an extended period.
- You have temporary mitigations for unsupported systems and software while pursuing migration to supported technology.
- You regularly test to fully understand the vulnerabilities of the network and information systems that support the operation of your essential function(s).
Achieved - All of the following statements are true:
- You maintain a current understanding of the exposure of your essential function(s) to publicly-known vulnerabilities.
- Announced vulnerabilities for all software packages, network and information systems used to support your essential function(s) are tracked, prioritised and mitigated (e.g. by patching) promptly.
- You regularly test to fully understand the vulnerabilities of the network and information systems that support the operation of your essential function(s) and verify this understanding with third-party testing.
- You actively maximise the use of supported software, firmware and hardware in your network and information systems supporting your essential function(s).
The organisation builds resilience against cyber attack and system failure into the design, implementation, operation and management of systems that support the operation of your essential function(s).
Description
error determining description
Guidance
It's important to be prepared to respond to significant disruption by having business continuity and disaster recovery planning in place. This should include a definition of your most critical resources and an understanding of the order of actions needed to restore service(s). Test that these plans work, for example through manually triggering failover testing, carrying out table-top scenario walk-throughs, red-teaming or Cyber adversary simulation testing. You should be ready to adjust the security measures in place in response to changes in risk. For example, if threat intelligence indicates an increased likelihood of your organisation or sector being targeted you may decide to isolate operational networks until the threat has decreased. Alternatively, in the event of public disclosure of an unpatched vulnerability in equipment that you use, with reported use of exploits targeting the vulnerability, you may respond by elevating your protective monitoring, changing your configuration to avoid being susceptible, or taking other mitigating action in the period until a patch is made available and can be deployed.
You should reduce the likelihood of failure or attack by taking all reasonable measures to maintain networks, information systems and necessary technologies in good working order. Exceptions should be appropriately managed.
In the event of an incident, it is more likely that an essential function will be able to continue where the networks and information systems that support it are segregated from other business and external systems. Separation of system architecture, remote access and privileged access are some key principles that can protect more critical systems from external compromise.
Some sectors responsible for the operation of essential functions may apply the industrial automation and control system security standard IEC 62443, which applies a reference model that separates systems into different logical layers. The standard's architecture model segregates equipment into security zones.
Limitations of networks and information systems, or external services or resources, such as network bandwidth, processing capability, or data storage capacity, should be understood and managed with suitable mitigations to avoid disruption through resource overload.
Make appropriate use of diverse technologies, geographic locations and so on, to provide resilience. You should understand and manage external or lower-priority dependencies to ensure that alternative means are suitable for continuation of the essential function.
In the event of an adverse event, you should be able to revert to backups of hardware and data that are known to be functioning and accessible. Organisations should maintain secured offline, potentially off-site, backups of the operational data, equipment configurations, gold builds, etc. needed to recover from an extreme event.
Suitable alternative backups may include paper-based information and manual processes. Other essential backups may include personnel with appropriate knowledge and access to up-to-date documentation. Consider how to make it easy to recover following an incident or compromise.
You should have adequate policies and measures to ensure the physical and environmental security of your network and information systems. This can be achieved through measures such as physical access controls, alarm systems, environmental controls and automated fire systems etc.
When planning physical upgrades or changes to network and information systems (such as moving to new hardware installations, installing new equipment or power supplies), you should take steps to avoid unnecessary or unplanned interruptions to the services that your network and information systems support.
You should also ensure that you have adequate policies to protect supporting utilities such as electricity, fuel, heating, ventilation, and air conditioning. This can be achieved by having alternative sources, such as back-up generators or uninterruptible power supplies, active temperature monitoring, redundant cooling systems etc.
Contributing Outcomes
B5.a Resilience Preparation
- You are prepared to restore the operation of your essential function(s) following adverse impact to network and information systems.
- You are prepared to restore the operation of your essential function(s) following adverse impact to network and information systems.
- You have limited understanding of all the elements that are required to restore operation of the essential function(s).
- You have not completed business continuity and disaster recovery plans for network and information systems, including their dependencies, supporting the operation of the essential function(s).
- You have not fully assessed the practical implementation of your business continuity and disaster recovery plans.
- You know all network and information systems, and underlying technologies that are necessary to restore the operation of the essential function(s) and understand their interdependence.
- You know the order in which systems need to be recovered to efficiently and effectively restore the operation of the essential function(s).
- You have business continuity and disaster recovery plans that have been tested for practicality, effectiveness and completeness. Appropriate use is made of different test methods (e.g. manual fail-over, table-top exercises, or red-teaming).
- You use your security awareness and threat intelligence sources to identify new or heightened levels of risk, which result in immediate and potentially temporary security measures to enhance the security of your network and information systems (e.g. in response to a widespread outbreak of very damaging malware).
Not achieved - Any of the following statements are true:
- You have limited understanding of all the elements that are required to restore operation of the essential function(s).
- You have not completed business continuity and disaster recovery plans for network and information systems, including their dependencies, supporting the operation of the essential function(s).
- You have not fully assessed the practical implementation of your business continuity and disaster recovery plans.
Partially achieved - All of the following statements are true:
- You know all network and information systems, and underlying technologies that are necessary to restore the operation of the essential function(s) and understand their interdependence.
- You know the order in which systems need to be recovered to efficiently and effectively restore the operation of the essential function(s).
Achieved - All of the following statements are true:
- You have business continuity and disaster recovery plans that have been tested for practicality, effectiveness and completeness. Appropriate use is made of different test methods (e.g. manual fail-over, table-top exercises, or red-teaming).
- You use your security awareness and threat intelligence sources to identify new or heightened levels of risk, which result in immediate and potentially temporary security measures to enhance the security of your network and information systems (e.g. in response to a widespread outbreak of very damaging malware).
B5.b Design for Resilience
- You design the network and information systems supporting your essential function(s) to be resilient to cyber security incidents. Systems are appropriately segregated and resource limitations are mitigated.
- You design the network and information systems supporting your essential function(s) to be resilient to cyber security incidents. Systems are appropriately segregated and resource limitations are mitigated.
- Network and information systems supporting the operation of your essential function(s) are not appropriately segregated.
- Internet services, such as browsing and email, are accessible from network and information systems supporting the essential function(s).
- You do not understand or lack plans to mitigate all resource limitations that could adversely affect your essential function(s).
- Network and information systems supporting the operation of your essential function(s) are logically separated from your business systems (e.g. they reside on the same network as the rest of the organisation but within a DMZ).
- Internet services, such as browsing and email, are not accessible from network and information systems supporting the essential function(s).
- Resource limitations (e.g. network bandwidth, single network paths) have been identified but not fully mitigated.
- Network and information systems supporting the operation of your essential function(s) are segregated from other business and external systems by appropriate technical and physical means (e.g. separate network and system infrastructure with independent user administration).
- Internet services, such as browsing and email, are not accessible from network and information systems supporting the essential function(s).
- You have identified and mitigated all resource limitations (e.g. bandwidth limitations and single network paths).
- You have identified and mitigated any geographical constraints or weaknesses. (e.g. systems that your essential function(s) depends upon are replicated in another location, important network connectivity has alternative physical paths and service providers).
- You review and update assessments of dependencies, resource and geographical limitations and mitigations when necessary.
Not achieved - At least one of the following statements is true:
- Network and information systems supporting the operation of your essential function(s) are not appropriately segregated.
- Internet services, such as browsing and email, are accessible from network and information systems supporting the essential function(s).
- You do not understand or lack plans to mitigate all resource limitations that could adversely affect your essential function(s).
Partially achieved - All of the following statements are true:
- Network and information systems supporting the operation of your essential function(s) are logically separated from your business systems (e.g. they reside on the same network as the rest of the organisation but within a DMZ).
- Internet services, such as browsing and email, are not accessible from network and information systems supporting the essential function(s).
- Resource limitations (e.g. network bandwidth, single network paths) have been identified but not fully mitigated.
Achieved - All of the following statements are true:
- Network and information systems supporting the operation of your essential function(s) are segregated from other business and external systems by appropriate technical and physical means (e.g. separate network and system infrastructure with independent user administration).
- Internet services, such as browsing and email, are not accessible from network and information systems supporting the essential function(s).
- You have identified and mitigated all resource limitations (e.g. bandwidth limitations and single network paths).
- You have identified and mitigated any geographical constraints or weaknesses. (e.g. systems that your essential function(s) depends upon are replicated in another location, important network connectivity has alternative physical paths and service providers).
- You review and update assessments of dependencies, resource and geographical limitations and mitigations when necessary.
B5.c Backups
- You hold accessible and secured current backups of data and information needed to recover operation of your essential function(s) following an adverse impact to network and information systems.
- You hold accessible and secured current backups of data and information needed to recover operation of your essential function(s) following an adverse impact to network and information systems.
- Backup coverage is incomplete and does not include all relevant data and information needed to restore the operation of your essential function(s).
- Backups are not frequent enough for the operation of your essential function(s) to be restored effectively.
- Your restoration process does not restore your essential function(s) in a suitable time frame.
- You have appropriately secured backups (including data, configuration information, software, equipment, processes and knowledge). These backups will be accessible to recover from an extreme event.
- You routinely test backups to ensure that the backup process function(s) correctly and the backups are usable.
- Your comprehensive, automatic and tested technical and procedural backups are secured at centrally accessible or secondary sites to recover from an extreme event.
- Backups of all important data and information needed to recover the essential function(s) are made, tested, documented and routinely reviewed
Not achieved - At least one of the following statements is true:
- Backup coverage is incomplete and does not include all relevant data and information needed to restore the operation of your essential function(s).
- Backups are not frequent enough for the operation of your essential function(s) to be restored effectively.
- Your restoration process does not restore your essential function(s) in a suitable time frame.
Partially achieved - All of the following statements are true:
- You have appropriately secured backups (including data, configuration information, software, equipment, processes and knowledge). These backups will be accessible to recover from an extreme event.
- You routinely test backups to ensure that the backup process function(s) correctly and the backups are usable.
Achieved - All of the following statements are true:
- Your comprehensive, automatic and tested technical and procedural backups are secured at centrally accessible or secondary sites to recover from an extreme event.
- Backups of all important data and information needed to recover the essential function(s) are made, tested, documented and routinely reviewed
Staff have appropriate awareness, knowledge and skills to carry out their organisational roles effectively in relation to the security of network and information systems supporting the operation of your essential function(s).
Description
error determining description
Guidance
The people who operate and support essential functions should be provided with all they need to carry out their job while supporting the organisation's cyber security. In line with the design of
service protection policies and processes
, you should apply the same people-focussed approach to staff awareness and training.
Training and awareness activities should provide appropriate cyber security skills for the job role based on an understanding of how people
really
work with the systems, with ongoing reminders and top-up training to maintain skills.
Using a range of approaches to training and awareness can improve understanding and information retention, from briefings, online courses and blogs to simulated cyber attack. You may achieve the widest uptake of training and awareness by accommodating different learning preferences and using various delivery methods. Organisations may find the
GCHQ certified training scheme
useful when considering commercial offerings.
Organisations responsible for essential functions should aim to create a positive security culture, where people are aware of their role in maintaining security and actively take part and contribute to improving security. This is particularly important where a technical solution is not possible, so security relies on people making the right cyber security decisions. Developing a positive security culture is likely to take some time, with some changes possibly taking years to become established and is unlikely to be achieved simply through written guidance or training events.
These outcomes are best achieved when organisations actively engage with staff and communicate effectively with them about network and information system security and how it relates to their jobs. This should be more easily achieved where organisations create and promote a long-term security culture vision that is endorsed and supported by senior management, then make incremental, focused changes to address specific business issues. In some cases, particularly where an essential function is safety-related, an organisation may be able to draw on activities supporting positive safety culture to build up the organisation's cyber security culture.
Contributing Outcomes
B6.a Cyber Security Culture
- You develop and maintain a positive cyber security culture and a shared sense of responsibility.
- You develop and maintain a positive cyber security culture and a shared sense of responsibility.
- People in your organisation do not understand what they contribute to the cyber security of network and information systems supporting your essential function(s).
- People in your organisation do not know how to raise a concern about cyber security.
- People believe that reporting issues may get them into trouble.
- Your organisation's approach to cyber security is perceived by staff as hindering the business of the organisation and may encourage poor security behaviours.
- Formal or informal incentives and rewards conflict with the promotion of positive security outcomes.
- Your executive management understand and widely communicate the importance of a positive cyber security culture. Positive attitudes, behaviours and expectations are described for your organisation.
- All people in your organisation understand the contribution they make to the cyber security of network and information systems supporting your essential function(s).
- All individuals in your organisation know who to contact and where to access more information about cyber security. They know how to raise a cyber security issue.
- You identify and address issues that inhibit people from behaving in a manner that supports your intended cyber security outcomes.
- Your executive management clearly and effectively communicates the organisation's cyber security priorities and objectives to all staff. Your organisation displays positive cyber security attitudes, behaviours, expectations.
- People in your organisation raising potential cyber security incidents and issues are treated positively.
- Individuals at all levels in your organisation routinely report concerns or issues about cyber security and are recognised for their contribution to keeping the organisation secure.
- Your management is seen to be committed to and actively involved in cyber security.
- Your organisation communicates openly about cyber security, with any concern being taken seriously.
- People across your organisation participate in cyber security activities and improvements, building joint ownership and bringing knowledge of their area of expertise.
Not achieved - At least one of the following statements is true:
- People in your organisation do not understand what they contribute to the cyber security of network and information systems supporting your essential function(s).
- People in your organisation do not know how to raise a concern about cyber security.
- People believe that reporting issues may get them into trouble.
- Your organisation's approach to cyber security is perceived by staff as hindering the business of the organisation and may encourage poor security behaviours.
- Formal or informal incentives and rewards conflict with the promotion of positive security outcomes.
Partially achieved - All the following statements are true:
- Your executive management understand and widely communicate the importance of a positive cyber security culture. Positive attitudes, behaviours and expectations are described for your organisation.
- All people in your organisation understand the contribution they make to the cyber security of network and information systems supporting your essential function(s).
- All individuals in your organisation know who to contact and where to access more information about cyber security. They know how to raise a cyber security issue.
- You identify and address issues that inhibit people from behaving in a manner that supports your intended cyber security outcomes.
Achieved - All the following statements are true:
- Your executive management clearly and effectively communicates the organisation's cyber security priorities and objectives to all staff. Your organisation displays positive cyber security attitudes, behaviours, expectations.
- People in your organisation raising potential cyber security incidents and issues are treated positively.
- Individuals at all levels in your organisation routinely report concerns or issues about cyber security and are recognised for their contribution to keeping the organisation secure.
- Your management is seen to be committed to and actively involved in cyber security.
- Your organisation communicates openly about cyber security, with any concern being taken seriously.
- People across your organisation participate in cyber security activities and improvements, building joint ownership and bringing knowledge of their area of expertise.
B6.b Cyber Security Training
- The people who support the operation of network and information systems supporting your essential function(s) are appropriately trained in cyber security.
- The people who support the operation of network and information systems supporting your essential function(s) are appropriately trained in cyber security.
- There are teams who operate and support your essential function(s) that lack any cyber security training.
- Cyber security training is restricted to specific roles in your organisation.
- Cyber security training records for your organisation are lacking or incomplete.
- Training is used as a “silver bullet” for all user security behaviours.
- The success of training is only measured by the number of people reached, rather than assessing whether it has a positive impact on security behaviours.
- Training materials contain out of date or contradictory information, or information that conflicts with other policies, processes or procedures.
- You have defined appropriate cyber security training and awareness activities for all roles in your organisation, from executives to the most junior roles.
- You use a range of teaching and communication techniques for cyber security training and awareness to reach the widest audience effectively.
- Cyber security information is easily available.
- All people in your organisation, from the most senior to the most junior, follow appropriate cyber security training paths.
- Each individuals cyber security training is tracked and refreshed at suitable intervals.
- You routinely evaluate your cyber security training and awareness activities to ensure they reach the widest audience and are effective.
- You make cyber security information and good practice guidance easily accessible, widely available and you know it is referenced and used within your organisation.
Not achieved - At least one of the following statements is true:
- There are teams who operate and support your essential function(s) that lack any cyber security training.
- Cyber security training is restricted to specific roles in your organisation.
- Cyber security training records for your organisation are lacking or incomplete.
- Training is used as a “silver bullet” for all user security behaviours.
- The success of training is only measured by the number of people reached, rather than assessing whether it has a positive impact on security behaviours.
- Training materials contain out of date or contradictory information, or information that conflicts with other policies, processes or procedures.
Partially achieved - All the following statements are true:
- You have defined appropriate cyber security training and awareness activities for all roles in your organisation, from executives to the most junior roles.
- You use a range of teaching and communication techniques for cyber security training and awareness to reach the widest audience effectively.
- Cyber security information is easily available.
Achieved - All the following statements are true:
- All people in your organisation, from the most senior to the most junior, follow appropriate cyber security training paths.
- Each individuals cyber security training is tracked and refreshed at suitable intervals.
- You routinely evaluate your cyber security training and awareness activities to ensure they reach the widest audience and are effective.
- You make cyber security information and good practice guidance easily accessible, widely available and you know it is referenced and used within your organisation.
The organisation monitors the security status of network and information systems supporting the operation of essential function(s) in order to detect security events indicative of a security incident.
Description
error determining description
Guidance
One clear focus of your security monitoring should be the detection of incidents or activity that is likely to have an adverse impact on the network and information systems that support the operation of essential functions. Log data collection, secure storage, analysis tools, understanding your network and information systems that support your essential function(s), threat intelligence and personnel skills should all be used to build an effective security monitoring capability.
An organisation's automated monitoring capability should be able to find threats within their network and information systems by using both signature-based detections and, behavioural and anomaly-based detections.
Examples of signature-based detections are detecting when known command and control traffic is communicating to the internet, or an AV signature is present in a file. Organisations should endeavour to understand what automated detections and alerting do and how best to use them, to ensure they are making the most of the monitoring solution / as well as being as effective as possible.
Organisations should also have the capability to find threats by using behavioural and anomaly-based detections, for example by detecting an abnormally large amount of data being exfiltrated or AV detecting unusual changes to start up registry keys.
Both signature and, anomaly and behaviour-based detections rely on an understanding of indicators of compromise, your network and information systems, user behaviour and threats.
Contributing Outcomes
C1.a Sources and Tools for Logging and Monitoring
- The data sources that you include in your logging and monitoring allow for timely identification of events which might adversely affect the resiliency of network and information system(s) supporting the operation of your essential function(s).
- The data sources that you include in your logging and monitoring allow for timely identification of events which might adversely affect the resiliency of network and information system(s) supporting the operation of your essential function(s).
- Data relating to the security and operation of network and information systems supporting your essential function(s) is not collected.
- You are not able to audit the activities of users and systems in relation to network and information systems supporting your essential function(s).
- You do not monitor traffic crossing your network boundary.
- Log data cannot be synchronised using an accurate common time source.
- Logs are stored in locations where they are not readily available to authorised users and systems.
- Your monitoring tools cannot be configured to make use of new log streams as they come online.
- Your monitoring tools are only able to make use of a fraction of the log data being collected.
- You do not understand where log data is stored or how long it should be stored for.
- You have no way of ensuring log data is being captured as expected and available when needed.
- Data relating to the security and operation of some areas of network and information systems supporting your essential function(s) is collected but coverage is not comprehensive.
- Some user and system monitoring is done, but not covering a fully agreed list of suspicious or undesirable behaviour.
- You monitor traffic crossing your network boundary (including IP address connections as a minimum).
- Some but not all log datasets can be easily queried with search tools to aid in investigations.
- Your monitoring tools work with most log data, with some configuration.
- Your monitoring tools can make use of log data that would capture all common threats.
- You ensure log data is available for analysis when needed.
- Monitoring is based on a thorough understanding of network and information systems supporting your essential function(s), techniques used by threat actors, and awareness of what logging and monitoring is required to detect events and incidents that could affect the operation of your essential function(s).
- Your monitoring data provides enough detail to promptly and reliably detect security events, incidents and support investigations. This is reviewed regularly and after a significant security event.
- Extensive monitoring of user and system activity in relation to network and information systems that support your essential function(s) enables you to promptly detect policy violations, suspicious or undesirable user and system behaviour, deviations from normal / routine behaviour or abnormalities indicative of adverse activity.
- Your logging and monitoring capability includes host-based and network monitoring.
- All new network and information systems supporting your essential function(s) are considered as potential logging and monitoring data sources to maintain a comprehensive monitoring capability.
- Log datasets are synchronised including using an accurate common time source so that separate datasets can be correlated in appropriate ways.
- You enrich log data with other network and information systems data to provide a more comprehensive picture of actions and behaviours.
- Your monitoring tools make use of log data to pinpoint activity.
- You regularly review the data sources and tools included in your logging and monitoring strategy to ensure it remains effective.
Not achieved - At least one of the following statements is true:
- Data relating to the security and operation of network and information systems supporting your essential function(s) is not collected.
- You are not able to audit the activities of users and systems in relation to network and information systems supporting your essential function(s).
- You do not monitor traffic crossing your network boundary.
- Log data cannot be synchronised using an accurate common time source.
- Logs are stored in locations where they are not readily available to authorised users and systems.
- Your monitoring tools cannot be configured to make use of new log streams as they come online.
- Your monitoring tools are only able to make use of a fraction of the log data being collected.
- You do not understand where log data is stored or how long it should be stored for.
- You have no way of ensuring log data is being captured as expected and available when needed.
Partially achieved - All the following statements are true:
- Data relating to the security and operation of some areas of network and information systems supporting your essential function(s) is collected but coverage is not comprehensive.
- Some user and system monitoring is done, but not covering a fully agreed list of suspicious or undesirable behaviour.
- You monitor traffic crossing your network boundary (including IP address connections as a minimum).
- Some but not all log datasets can be easily queried with search tools to aid in investigations.
- Your monitoring tools work with most log data, with some configuration.
- Your monitoring tools can make use of log data that would capture all common threats.
- You ensure log data is available for analysis when needed.
Achieved - All the following statements are true:
- Monitoring is based on a thorough understanding of network and information systems supporting your essential function(s), techniques used by threat actors, and awareness of what logging and monitoring is required to detect events and incidents that could affect the operation of your essential function(s).
- Your monitoring data provides enough detail to promptly and reliably detect security events, incidents and support investigations. This is reviewed regularly and after a significant security event.
- Extensive monitoring of user and system activity in relation to network and information systems that support your essential function(s) enables you to promptly detect policy violations, suspicious or undesirable user and system behaviour, deviations from normal / routine behaviour or abnormalities indicative of adverse activity.
- Your logging and monitoring capability includes host-based and network monitoring.
- All new network and information systems supporting your essential function(s) are considered as potential logging and monitoring data sources to maintain a comprehensive monitoring capability.
- Log datasets are synchronised including using an accurate common time source so that separate datasets can be correlated in appropriate ways.
- You enrich log data with other network and information systems data to provide a more comprehensive picture of actions and behaviours.
- Your monitoring tools make use of log data to pinpoint activity.
- You regularly review the data sources and tools included in your logging and monitoring strategy to ensure it remains effective.
C1.b Securing Logs
- You hold log data securely and grant appropriate user and system access only to accounts with a business need. Log data is held for a suitable retention period, after which it is deleted.
- You hold log data securely and grant appropriate user and system access only to accounts with a business need. Log data is held for a suitable retention period, after which it is deleted.
- It is possible for log data to be easily edited or deleted by unauthorised users or malicious attackers.
- There is no controlled list of the users and systems that can view and query log data.
- There is no monitoring of the access to log data.
- There are no policies for accessing to log data.
- Only authorised users and systems can access log data.
- There is some monitoring of access to log data (e.g. copying, deleting or modification, or even viewing).
- You have defined and implemented retention periods for log data.
- You have given legitimate reasons for accessing log data in your policies.
- Appropriate access to log data is limited to those users and systems with a business need.
- The logging architecture has mechanisms, policies, processes and procedures to ensure that it can protect itself from threats comparable to those that it is trying to identify. This includes protecting the function itself and the data within it.
- Log data analysis and normalisation is only performed on copies of the log data keeping the master copy unaltered.
- All actions involving log data (e.g. copying, deleting, modification, or even viewing) can be traced back to a unique user or system.
- The integrity of log data is protected, verified and any modification, including deletion, is detected and attributed.
Not achieved - At least one of the following is true:
- It is possible for log data to be easily edited or deleted by unauthorised users or malicious attackers.
- There is no controlled list of the users and systems that can view and query log data.
- There is no monitoring of the access to log data.
- There are no policies for accessing to log data.
Partially achieved - All the following statements are true:
- Only authorised users and systems can access log data.
- There is some monitoring of access to log data (e.g. copying, deleting or modification, or even viewing).
- You have defined and implemented retention periods for log data.
- You have given legitimate reasons for accessing log data in your policies.
Achieved - All the following statements are true:
- Appropriate access to log data is limited to those users and systems with a business need.
- The logging architecture has mechanisms, policies, processes and procedures to ensure that it can protect itself from threats comparable to those that it is trying to identify. This includes protecting the function itself and the data within it.
- Log data analysis and normalisation is only performed on copies of the log data keeping the master copy unaltered.
- All actions involving log data (e.g. copying, deleting, modification, or even viewing) can be traced back to a unique user or system.
- The integrity of log data is protected, verified and any modification, including deletion, is detected and attributed.
C1.c Generating Alerts
- Evidence of potential security incidents contained in your monitoring data is reliably identified and where appropriate triggers alerts.
- Evidence of potential security incidents contained in your monitoring data is reliably identified and where appropriate triggers alerts.
- You do not apply updates to your detection security technologies in a timely way, after receiving them (e.g. AV signature updates, other threat signatures or Indicators of Compromise (IoCs)).
- Security alerts relating to network and information systems supporting your essential function(s) are not prioritised.
- The enrichment of security alerts within network and information systems supporting your essential function(s) cannot be performed.
- You do not confidently detect the presence of IoCs on network and information systems supporting your essential function(s), such as known malicious command and control signatures (e.g. because applying the indicator is difficult or your log data is not sufficiently detailed).
- You do not monitor for user or system abnormalities indicative of adverse activity.
- Logs are monitored infrequently.
- You easily detect the presence of Indicators of Compromise (IoCs) on network and information systems supporting your essential function(s), such as known malicious command and control signatures.
- You apply some updates, new signatures and IoCs in a timely way.
- Security alerts relating to network and information systems that support your essential function(s) are prioritised.
- The enrichment of alerts within network and information systems supporting your essential function(s) is performed but not as part of the original alert.
- Detections and alerting rely on off the shelf tooling without customisation or users reporting events and potential incidents.
- There is a documented and shared process for all users who support the operation of the essential function to report events and potential security incidents.
- Where appropriate, detections and alerting result in automated actions being taken. (e.g. malware identified by AV is quarantined).
- You monitor on an irregular basis for user or system abnormalities indicative of adverse activity.
- Logs are monitored at regular intervals.
- You easily detect the presence of Indicators of Compromise (IoCs) on network and information systems supporting your essential function(s), such as known malicious command and control signatures, as well as abnormalities or behaviours indicative of adverse activity.
- You apply all updates, new signatures and IoCs promptly.
- Security alerts relating to all network and information systems supporting your essential function(s) are prioritised and this information is used to support incident management.
- Alerts are routinely enriched within network and information systems supporting your essential function(s). The enrichment of these alerts is performed in almost real time and as part of the original alert.
- Alerts and the underlying detections are regularly reviewed and tested to ensure they are generated promptly and reliably, and it is possible to distinguish genuine security incidents from false alarms.
- Alerts and the underlying detection rules are customisable and tuned to reduce false positives as well as optimising responses.
- Detections and alerting may use off the shelf tooling and rules as well as custom tooling and / or rules.
- You continuously monitor for user and system abnormalities indicative of adverse activity generating alerts based on the results of such monitoring.
- Logs are monitored continuously in near real time.
Not achieved - At least one of the following is true:
- You do not apply updates to your detection security technologies in a timely way, after receiving them (e.g. AV signature updates, other threat signatures or Indicators of Compromise (IoCs)).
- Security alerts relating to network and information systems supporting your essential function(s) are not prioritised.
- The enrichment of security alerts within network and information systems supporting your essential function(s) cannot be performed.
- You do not confidently detect the presence of IoCs on network and information systems supporting your essential function(s), such as known malicious command and control signatures (e.g. because applying the indicator is difficult or your log data is not sufficiently detailed).
- You do not monitor for user or system abnormalities indicative of adverse activity.
- Logs are monitored infrequently.
Partially achieved - All the following statements are true:
- You easily detect the presence of Indicators of Compromise (IoCs) on network and information systems supporting your essential function(s), such as known malicious command and control signatures.
- You apply some updates, new signatures and IoCs in a timely way.
- Security alerts relating to network and information systems that support your essential function(s) are prioritised.
- The enrichment of alerts within network and information systems supporting your essential function(s) is performed but not as part of the original alert.
- Detections and alerting rely on off the shelf tooling without customisation or users reporting events and potential incidents.
- There is a documented and shared process for all users who support the operation of the essential function to report events and potential security incidents.
- Where appropriate, detections and alerting result in automated actions being taken. (e.g. malware identified by AV is quarantined).
- You monitor on an irregular basis for user or system abnormalities indicative of adverse activity.
- Logs are monitored at regular intervals.
Achieved - All the following statements are true:
- You easily detect the presence of Indicators of Compromise (IoCs) on network and information systems supporting your essential function(s), such as known malicious command and control signatures, as well as abnormalities or behaviours indicative of adverse activity.
- You apply all updates, new signatures and IoCs promptly.
- Security alerts relating to all network and information systems supporting your essential function(s) are prioritised and this information is used to support incident management.
- Alerts are routinely enriched within network and information systems supporting your essential function(s). The enrichment of these alerts is performed in almost real time and as part of the original alert.
- Alerts and the underlying detections are regularly reviewed and tested to ensure they are generated promptly and reliably, and it is possible to distinguish genuine security incidents from false alarms.
- Alerts and the underlying detection rules are customisable and tuned to reduce false positives as well as optimising responses.
- Detections and alerting may use off the shelf tooling and rules as well as custom tooling and / or rules.
- You continuously monitor for user and system abnormalities indicative of adverse activity generating alerts based on the results of such monitoring.
- Logs are monitored continuously in near real time.
C1.d Triage of Security Alerts
- You contextualise alerts with knowledge of the threat and your systems, to identify those security incidents as well as responding to all alerts appropriately.
- You contextualise alerts with knowledge of the threat and your systems, to identify those security incidents as well as responding to all alerts appropriately.
- You do not triage alerts from your detection security technologies (e.g. AV, IDS).
- You do not categorise alerts and incidents by type and priority / severity level.
- You do not have Standard Operating Procedures (SOPs) / Playbooks / Runbooks available for use during triage.
- You do not keep records of triage performed.
- You do not have a sufficient understanding of normal user or system behaviour to make effective decisions within triage.
- You investigate and triage alerts from some security tools and take action.
- You have created, made available and use when appropriate, Standard Operating Procedures (SOPs) / Playbooks / Runbooks covering the most common use cases. These are regularly reviewed to ensure they remain effective.
- You perform some triage and actions taken by monitoring and detection personnel are recorded.
- You categorise alerts and incidents by type and priority / severity level.
- Your understanding of normal user or system behaviour informs your decision making within triage.
- You investigate and triage alerts from all security tools and take action.
- You have created, made available and use when appropriate, Standard Operating Procedures (SOPs) / Playbooks / Runbooks covering all plausible use cases. These are regularly reviewed to ensure they remain effective.
- You categorise alerts and incidents by type and priority / severity level.
- You document all triage related activities performed by monitoring and detection personnel and these are used to drive improvements
- Triage provides enough information for subsequent activities to be prioritised (e.g. the containment of damaging malware).
- Your understanding of normal user and system behaviour, and threats, is sufficient for effective decision making within triage.
Not achieved - At least one of the following is true:
- You do not triage alerts from your detection security technologies (e.g. AV, IDS).
- You do not categorise alerts and incidents by type and priority / severity level.
- You do not have Standard Operating Procedures (SOPs) / Playbooks / Runbooks available for use during triage.
- You do not keep records of triage performed.
- You do not have a sufficient understanding of normal user or system behaviour to make effective decisions within triage.
Partially achieved - All the following statements are true:
- You investigate and triage alerts from some security tools and take action.
- You have created, made available and use when appropriate, Standard Operating Procedures (SOPs) / Playbooks / Runbooks covering the most common use cases. These are regularly reviewed to ensure they remain effective.
- You perform some triage and actions taken by monitoring and detection personnel are recorded.
- You categorise alerts and incidents by type and priority / severity level.
- Your understanding of normal user or system behaviour informs your decision making within triage.
Achieved - All the following statements are true:
- You investigate and triage alerts from all security tools and take action.
- You have created, made available and use when appropriate, Standard Operating Procedures (SOPs) / Playbooks / Runbooks covering all plausible use cases. These are regularly reviewed to ensure they remain effective.
- You categorise alerts and incidents by type and priority / severity level.
- You document all triage related activities performed by monitoring and detection personnel and these are used to drive improvements
- Triage provides enough information for subsequent activities to be prioritised (e.g. the containment of damaging malware).
- Your understanding of normal user and system behaviour, and threats, is sufficient for effective decision making within triage.
C1.e Personnel Skills for Monitoring Tools and Detection
- Monitoring and detection personnel skills and roles, including those outsourced, reflect governance and reporting requirements, expected threats and the complexities of the network or system data they need to use. Monitoring and detection personnel have sufficient knowledge of network and information systems and the essential function(s) they need to protect.
- Monitoring and detection personnel skills and roles, including those outsourced, reflect governance and reporting requirements, expected threats and the complexities of the network or system data they need to use. Monitoring and detection personnel have sufficient knowledge of network and information systems and the essential function(s) they need to protect.
- There are no personnel who perform a monitoring and detection function.
- Monitoring and detection personnel do not have the correct specialist skills.
- Monitoring and detection personnel are not capable of reporting against governance requirements.
- Monitoring and detection personnel have a lack of awareness of the essential function(s) the organisation provides, what assets relate to those functions and hence the importance of the log data and security events.
- Monitoring and detection personnel have no awareness of other roles or tasks outside of security monitoring and detection that are relevant to the operation of your essential function(s).
- Monitoring and detection personnel are overwhelmed with the amount of data and alerts they have to work with. Alert / triage fatigue is present.
- Monitoring and detection personnel have some investigative skills and a basic understanding of the data they need to work with.
- Monitoring and detection personnel can report to other parts of the organisation (e.g. security directors, resilience managers).
- Monitoring and detection personnel are capable of following most of the required workflow(s).
- Monitoring and detection personnel are aware of some of the network and information systems and your essential function(s), and can manage alerts relating to them.
- Monitoring and detection personnel have some understanding of the operational context (e.g. people, processes, network and information systems that support your essential function(s)) to enhance the security monitoring function.
- Monitoring and detection personnel deal with their workload and cases effectively.
- You have monitoring and detection personnel who are responsible for the proactive and reactive analysis, investigation and reporting of monitoring alerts including both security and performance.
- Monitoring and detection personnel have defined roles and skills that cover all parts of the monitoring and investigation process.
- Monitoring and detection personnel follow policies, processes and procedures that address all governance reporting requirements, internal and external.
- Monitoring and detection personnel are empowered to look beyond the fixed process to investigate and understand non-standard threats.
- Monitoring and detection personnel are aware of the network and information systems and your essential function(s), related assets and can identify and prioritise alerts and investigations that relate to them.
- Monitoring and detection personnel drive and shape new log data collection and can make effective use of it.
- Monitoring and detection personnel are capable of following all of the required workflow(s).
- Monitoring and detection personnel have a sufficient understanding of the operational context (e.g. people, processes, network and information systems that support your essential function) to enhance the security monitoring function.
- Monitoring and detection personnel deal with their workload and cases effectively as well as identifying areas for improvement.
Not achieved - At least one of the following is true:
- There are no personnel who perform a monitoring and detection function.
- Monitoring and detection personnel do not have the correct specialist skills.
- Monitoring and detection personnel are not capable of reporting against governance requirements.
- Monitoring and detection personnel have a lack of awareness of the essential function(s) the organisation provides, what assets relate to those functions and hence the importance of the log data and security events.
- Monitoring and detection personnel have no awareness of other roles or tasks outside of security monitoring and detection that are relevant to the operation of your essential function(s).
- Monitoring and detection personnel are overwhelmed with the amount of data and alerts they have to work with. Alert / triage fatigue is present.
Partially achieved - All the following statements are true:
- Monitoring and detection personnel have some investigative skills and a basic understanding of the data they need to work with.
- Monitoring and detection personnel can report to other parts of the organisation (e.g. security directors, resilience managers).
- Monitoring and detection personnel are capable of following most of the required workflow(s).
- Monitoring and detection personnel are aware of some of the network and information systems and your essential function(s), and can manage alerts relating to them.
- Monitoring and detection personnel have some understanding of the operational context (e.g. people, processes, network and information systems that support your essential function(s)) to enhance the security monitoring function.
- Monitoring and detection personnel deal with their workload and cases effectively.
Achieved - All the following statements are true:
- You have monitoring and detection personnel who are responsible for the proactive and reactive analysis, investigation and reporting of monitoring alerts including both security and performance.
- Monitoring and detection personnel have defined roles and skills that cover all parts of the monitoring and investigation process.
- Monitoring and detection personnel follow policies, processes and procedures that address all governance reporting requirements, internal and external.
- Monitoring and detection personnel are empowered to look beyond the fixed process to investigate and understand non-standard threats.
- Monitoring and detection personnel are aware of the network and information systems and your essential function(s), related assets and can identify and prioritise alerts and investigations that relate to them.
- Monitoring and detection personnel drive and shape new log data collection and can make effective use of it.
- Monitoring and detection personnel are capable of following all of the required workflow(s).
- Monitoring and detection personnel have a sufficient understanding of the operational context (e.g. people, processes, network and information systems that support your essential function) to enhance the security monitoring function.
- Monitoring and detection personnel deal with their workload and cases effectively as well as identifying areas for improvement.
C1.f Understanding User's and System's Behaviour, and Threat Intelligence (within Security Monitoring)
- Threats to the operation of network and information systems, and corresponding user and system behaviour, are sufficiently understood. These are used to detect cyber security incidents.
- Threats to the operation of network and information systems, and corresponding user and system behaviour, are sufficiently understood. These are used to detect cyber security incidents.
- Your organisation has no sources of threat intelligence.
- You do not evaluate the usefulness of your threat intelligence or share feedback with providers or other users.
- You have no awareness of the steps necessary to make best use of threat intelligence for security monitoring.
- Threat intelligence is unreliable and / or is not actioned by the appropriate users or systems in a timely manner.
- You have no established understanding of what abnormalities to look for that might signify adverse activities.
- You do not receive updates for all your detection security technologies (e.g. AV, IDS).
- You do not understand normal user and system behaviour sufficiently to be able to use abnormalities to detect adverse activity.
- You know how effective your threat intelligence is (e.g. by tracking how threat intelligence helps you identify security incidents).
- Your organisation may use threat intelligence services, but you do not necessarily choose sources or providers specifically because of your business needs, or specific threats in your sector (e.g. sector-based infoshare, software vendors, anti-virus providers, specialist threat intel firms, special interest groups).
- The user and system abnormalities from past attacks and threat intelligence, on your
- and other network and information systems, are used to signify adverse activity.
- You receive regular updates for all of your detection security technologies (e.g. AV, IDS).
- You track the effectiveness of your threat intelligence and actively share feedback on the usefulness of Indicators of Compromise (IoCs) and other intelligence with the threat community (e.g. sector partners, threat intelligence providers, government agencies).
- When using threat intelligence feeds, these have been selected using risk-based and threat-informed decisions based on your business needs and sector.
- You make relevant, reliable and actionable threat intelligence available to the necessary users and systems promptly.
- You contextualise threat intelligence and link it to the why and / or how attacks take place for security monitoring.
- You understand normal user and system abnormalities fully, to such an extent that searching for system abnormalities is an effective way of detecting adverse activity (e.g. you fully understand which systems should and should not communicate and when).
- The user and system abnormalities you monitor for are based on the nature of adverse activities likely to impact network and information systems supporting the operation of your essential function(s).
- The user and system abnormalities indicative of adverse activity you use are regularly updated to reflect changes in network and information systems supporting your essential function(s) and current threat intelligence.
- You possess the capability to share threat intelligence (e.g. ways to effectively detect adversaries) with the threat community / defender community (sector partners, threat intelligence providers, government agencies) when required.
Not achieved - At least one of the following is true:
- Your organisation has no sources of threat intelligence.
- You do not evaluate the usefulness of your threat intelligence or share feedback with providers or other users.
- You have no awareness of the steps necessary to make best use of threat intelligence for security monitoring.
- Threat intelligence is unreliable and / or is not actioned by the appropriate users or systems in a timely manner.
- You have no established understanding of what abnormalities to look for that might signify adverse activities.
- You do not receive updates for all your detection security technologies (e.g. AV, IDS).
- You do not understand normal user and system behaviour sufficiently to be able to use abnormalities to detect adverse activity.
Partially achieved - All the following statements are true:
- You know how effective your threat intelligence is (e.g. by tracking how threat intelligence helps you identify security incidents).
- Your organisation may use threat intelligence services, but you do not necessarily choose sources or providers specifically because of your business needs, or specific threats in your sector (e.g. sector-based infoshare, software vendors, anti-virus providers, specialist threat intel firms, special interest groups).
- The user and system abnormalities from past attacks and threat intelligence, on your
- and other network and information systems, are used to signify adverse activity.
- You receive regular updates for all of your detection security technologies (e.g. AV, IDS).
Achieved - All the following statements are true:
- You track the effectiveness of your threat intelligence and actively share feedback on the usefulness of Indicators of Compromise (IoCs) and other intelligence with the threat community (e.g. sector partners, threat intelligence providers, government agencies).
- When using threat intelligence feeds, these have been selected using risk-based and threat-informed decisions based on your business needs and sector.
- You make relevant, reliable and actionable threat intelligence available to the necessary users and systems promptly.
- You contextualise threat intelligence and link it to the why and / or how attacks take place for security monitoring.
- You understand normal user and system abnormalities fully, to such an extent that searching for system abnormalities is an effective way of detecting adverse activity (e.g. you fully understand which systems should and should not communicate and when).
- The user and system abnormalities you monitor for are based on the nature of adverse activities likely to impact network and information systems supporting the operation of your essential function(s).
- The user and system abnormalities indicative of adverse activity you use are regularly updated to reflect changes in network and information systems supporting your essential function(s) and current threat intelligence.
- You possess the capability to share threat intelligence (e.g. ways to effectively detect adversaries) with the threat community / defender community (sector partners, threat intelligence providers, government agencies) when required.
The organisation proactively seeks to detect, within networks and information systems, adverse activity affecting, or with the potential to affect, the operation of essential functions even when the activity evades standard security prevent/detect solutions (or when standard solutions are not deployable).
Description
error determining description
Guidance
Threat hunting is more difficult than standard security monitoring because it looks beyond the known Indicators of Compromise (IOCs) that can be leveraged by automated detections and alerting covered in
C1 Security Monitoring
.
The aim is to build on what is known of both past and plausible attacks to hypothesise what intrusions might look like in. Threat hunting requires more experienced knowledge of network and system behaviour and of the general characteristics that an intrusion might exhibit. This sort of proactive monitoring or threat discovery would normally involve:
A good understanding of normal system behaviour (e.g. what software is authorised and how it would normally behave, how user accounts normally access network resources or how network components connect to each other and transfer data).
A good understanding of the ways that different types of threats maybe realised within your environment(s) based on a comprehensive and advanced understanding of threat intelligence.
A good understanding of normal system behaviour (e.g. what software is authorised and how it would normally behave, how user accounts normally access network resources or how network components connect to each other and transfer data).
Contributing Outcomes
C2.a Threat Hunting
- You do not know the resources required for threat hunting.
- You do not have access to an effective threat hunting capability.
- Your threat hunts do not follow any structure and few if any records are created.
- You have identified the resources required to perform threat hunting and are able to deploy these, in a timely manner, on an occasional basis.
- You deploy an effective threat hunting capability but not frequent enough to match the risks posed to network and information systems supporting your essential function(s) (e.g. you perform threat hunts in response to a tip off from a reputable source).
- Your threat hunts follow pre-determined and documented methods (e.g. hypothesis driven, data driven, entity driven) designed to identify adverse activity not detected by automated detections.
- You document details of threat hunts and post hunt analysis.
- You understand the resources required to perform threat hunting and these are deployed as part of business as usual.
- You deploy threat hunting resources at a frequency that matches the risks posed to network and information systems supporting your essential function(s).
- Your threat hunts follow pre-determined and documented methods (e.g. hypothesis driven, data driven, entity driven) designed to identify adverse activity not detected by automated detections.
- You turn threat hunts into automated detections and alerting where appropriate.
- You routinely record details of previous threat hunts and post hunt activities. You use these to drive improvements in your threat hunting and security posture.
- You have justified confidence in the effectiveness of your threat hunts and the threat hunting process is reviewed and updated to match the risks posed to network and information systems supporting your essential function(s).
- You leverage automation to improve threat hunts where appropriate (e.g. some stages of the threat hunting process are automated).
- Your threat hunts focus on the tactics, techniques and procedures (TTPs) of threats over atomic IoCs (e.g. hashes, IP addresses, domain names etc).
Not achieved - At least one of the following statements is true:
- You do not know the resources required for threat hunting.
- You do not have access to an effective threat hunting capability.
- Your threat hunts do not follow any structure and few if any records are created.
Partially achieved - All the following statements are true:
- You have identified the resources required to perform threat hunting and are able to deploy these, in a timely manner, on an occasional basis.
- You deploy an effective threat hunting capability but not frequent enough to match the risks posed to network and information systems supporting your essential function(s) (e.g. you perform threat hunts in response to a tip off from a reputable source).
- Your threat hunts follow pre-determined and documented methods (e.g. hypothesis driven, data driven, entity driven) designed to identify adverse activity not detected by automated detections.
- You document details of threat hunts and post hunt analysis.
Achieved - All the following statements are true:
- You understand the resources required to perform threat hunting and these are deployed as part of business as usual.
- You deploy threat hunting resources at a frequency that matches the risks posed to network and information systems supporting your essential function(s).
- Your threat hunts follow pre-determined and documented methods (e.g. hypothesis driven, data driven, entity driven) designed to identify adverse activity not detected by automated detections.
- You turn threat hunts into automated detections and alerting where appropriate.
- You routinely record details of previous threat hunts and post hunt activities. You use these to drive improvements in your threat hunting and security posture.
- You have justified confidence in the effectiveness of your threat hunts and the threat hunting process is reviewed and updated to match the risks posed to network and information systems supporting your essential function(s).
- You leverage automation to improve threat hunts where appropriate (e.g. some stages of the threat hunting process are automated).
- Your threat hunts focus on the tactics, techniques and procedures (TTPs) of threats over atomic IoCs (e.g. hashes, IP addresses, domain names etc).
The organisation proactively seeks to detect, within networks and information systems, adverse activity affecting, or with the potential to affect, the operation of essential functions even when the activity evades standard security prevent/detect solutions (or when standard solutions are not deployable).
Description
error determining description
Guidance
Threat hunting is more difficult than standard security monitoring because it looks beyond the known Indicators of Compromise (IOCs) that can be leveraged by automated detections and alerting covered in
C1 Security Monitoring
.
The aim is to build on what is known of both past and plausible attacks to hypothesise what intrusions might look like in. Threat hunting requires more experienced knowledge of network and system behaviour and of the general characteristics that an intrusion might exhibit. This sort of proactive monitoring or threat discovery would normally involve:
A good understanding of normal system behaviour (e.g. what software is authorised and how it would normally behave, how user accounts normally access network resources or how network components connect to each other and transfer data).
A good understanding of the ways that different types of threats maybe realised within your environment(s) based on a comprehensive and advanced understanding of threat intelligence.
A good understanding of normal system behaviour (e.g. what software is authorised and how it would normally behave, how user accounts normally access network resources or how network components connect to each other and transfer data).
Contributing Outcomes
C2.a Threat Hunting
- You do not know the resources required for threat hunting.
- You do not have access to an effective threat hunting capability.
- Your threat hunts do not follow any structure and few if any records are created.
- You have identified the resources required to perform threat hunting and are able to deploy these, in a timely manner, on an occasional basis.
- You deploy an effective threat hunting capability but not frequent enough to match the risks posed to network and information systems supporting your essential function(s) (e.g. you perform threat hunts in response to a tip off from a reputable source).
- Your threat hunts follow pre-determined and documented methods (e.g. hypothesis driven, data driven, entity driven) designed to identify adverse activity not detected by automated detections.
- You document details of threat hunts and post hunt analysis.
- You understand the resources required to perform threat hunting and these are deployed as part of business as usual.
- You deploy threat hunting resources at a frequency that matches the risks posed to network and information systems supporting your essential function(s).
- Your threat hunts follow pre-determined and documented methods (e.g. hypothesis driven, data driven, entity driven) designed to identify adverse activity not detected by automated detections.
- You turn threat hunts into automated detections and alerting where appropriate.
- You routinely record details of previous threat hunts and post hunt activities. You use these to drive improvements in your threat hunting and security posture.
- You have justified confidence in the effectiveness of your threat hunts and the threat hunting process is reviewed and updated to match the risks posed to network and information systems supporting your essential function(s).
- You leverage automation to improve threat hunts where appropriate (e.g. some stages of the threat hunting process are automated).
- Your threat hunts focus on the tactics, techniques and procedures (TTPs) of threats over atomic IoCs (e.g. hashes, IP addresses, domain names etc).
Not achieved - At least one of the following statements is true:
- You do not know the resources required for threat hunting.
- You do not have access to an effective threat hunting capability.
- Your threat hunts do not follow any structure and few if any records are created.
Partially achieved - All the following statements are true:
- You have identified the resources required to perform threat hunting and are able to deploy these, in a timely manner, on an occasional basis.
- You deploy an effective threat hunting capability but not frequent enough to match the risks posed to network and information systems supporting your essential function(s) (e.g. you perform threat hunts in response to a tip off from a reputable source).
- Your threat hunts follow pre-determined and documented methods (e.g. hypothesis driven, data driven, entity driven) designed to identify adverse activity not detected by automated detections.
- You document details of threat hunts and post hunt analysis.
Achieved - All the following statements are true:
- You understand the resources required to perform threat hunting and these are deployed as part of business as usual.
- You deploy threat hunting resources at a frequency that matches the risks posed to network and information systems supporting your essential function(s).
- Your threat hunts follow pre-determined and documented methods (e.g. hypothesis driven, data driven, entity driven) designed to identify adverse activity not detected by automated detections.
- You turn threat hunts into automated detections and alerting where appropriate.
- You routinely record details of previous threat hunts and post hunt activities. You use these to drive improvements in your threat hunting and security posture.
- You have justified confidence in the effectiveness of your threat hunts and the threat hunting process is reviewed and updated to match the risks posed to network and information systems supporting your essential function(s).
- You leverage automation to improve threat hunts where appropriate (e.g. some stages of the threat hunting process are automated).
- Your threat hunts focus on the tactics, techniques and procedures (TTPs) of threats over atomic IoCs (e.g. hashes, IP addresses, domain names etc).
There are well-defined and tested incident management processes in place, that aim to ensure continuity of essential function(s) in the event of system or service failure. Mitigation activities designed to contain or limit the impact of compromise are also in place.
Description
error determining description
Guidance
The 10 Steps to Cyber Security: Incident Management has concise guidance, but organisations should use other more detailed guidance as and when appropriate. Other authoritative guidance pieces are referenced below.
In addition to meeting the expectations of 10 Steps to Cyber Security, you should ensure that your organisation's incident response plans are grounded in thorough and comprehensive risk assessments. Response plans should prioritise essential functions along with the assets and systems that are required to ensure their continued effective operation, such as operational technologies, or key datasets.
The business continuity implications of any compromise should also be taken into account and your cyber incident response plans should link to other business response functions. You should form a cyber response team that is capable of implementing the plan, with the appropriate skills, tools and reach into other parts of your organisation, such as security monitoring and business continuity.
In practice, the Incident Response function should interoperate with the security monitoring function. The Incident Response function needn't be a dedicated team and some members may have non-response related roles. Collectively, the team should have knowledge of IT security, IT infrastructure and Business Management, any specialist technologies (e.g. Operational Technologies or datacentres), incident reporting requirements, and communications plans.
Your plan should cover all relevant potential incidents. It should be auditable and testable (
via exercises
) across a range of incident scenarios and should encompass all realistic descriptions of what might constitute an incident and its severity. Your test scenarios should draw on threat intelligence, past incidents, exercises and the ways in which security capabilities (e.g. security monitoring and alerting) would feature in your response options. Your scenarios should also consider incidents that involve suppliers and your wider supply chain e.g. incidents arising through supplier relations or relying on suppliers as part of your response.
These scenarios could include, but is not limited to:
The scenarios should be incorporated into exercises, which should be run to test your ability to respond to incidents that could affect the operation of essential functions. These exercises should reflect past experience, red-teaming/scenario planning, or threat intelligence and should draw heavily on your risk assessment, considering all relevant assets and vulnerabilities, especially where they relate to essential functions.
Exercises should record lessons learned, covering governance, roles and internal communication, quality of network and security monitoring data, containment and recovery strategies, or any other factors relevant to their effectiveness. This should integrate with lessons learned activities (see
Principle D2 Lessons Learned
).
Your plans should work seamlessly with other system management and security functions. Changes and improvements to response plans should reflect changes to these functions and vice versa, where appropriate.
Plans should articulate clear governance frameworks and roles with procedures for reporting to relevant internal or external stakeholders, such as regulators and competent authorities.
Your plan should also set out a comprehensive range of containment, eradication and recovery strategies, specifying how and when they should be used.
Your organisation should be able to describe its own state of readiness, using any criteria or expected standards from regulators or competent authorities, or from your internal governance arrangements, where appropriate.
In order to report coherently on incidents when required, your plan should set out reporting thresholds (i.e. what does and does not need to be reported) and standards (i.e. the level of detail that should be reported) and which authorities to report to.
More detailed guidance on developing an incident response plan, and the underlying capability to implement it, can be found in the
NIST Computer Security Incident Handling Guide
, CREST publications (see references) or
ISO/IEC 27035-1
.
Contributing Outcomes
D1.a Response Plan
- You have an up-to-date incident response plan that is grounded in a thorough risk assessment that takes account of network and information systems supporting the operation of your essential function(s) and covers a range of incident scenarios.
- You have an up-to-date incident response plan that is grounded in a thorough risk assessment that takes account of network and information systems supporting the operation of your essential function(s) and covers a range of incident scenarios.
- Your incident response plan is not documented.
- Your incident response plan does not include your organisations identified essential function(s).
- Your incident response plan is not well understood by relevant staff.
- Your incident response plan covers network and information systems supporting your essential function(s).
- Your incident response plan comprehensively covers scenarios that are focused on likely impacts of known and well understood attacks only.
- Your incident response plan is understood by all staff who are involved with your organisation's response function.
- Your incident response plan is documented and shared with all relevant stakeholders.
- Your incident response plan is readily accessible, even when your organisations IT systems have been adversely affected by an incident.
- Your incident response plan is regularly reviewed to ensure it remains effective.
- Your incident response plan is based on a clear understanding of the security risks to the network and information systems supporting your essential function(s).
- Your incident response plan is comprehensive (i.e. covers the complete lifecycle of an incident, roles and responsibilities, and reporting) and covers likely impacts of both known attack patterns and of possible attacks, previously unseen.
- Your incident response plan is documented and integrated with wider organisational business plans and supply chain response plans as well as dependencies on supporting infrastructure (e.g. power, cooling etc).
- Your incident response plan is communicated and understood by the business areas involved with the operation of your essential function(s).
Not achieved - At least one of the following is true:
- Your incident response plan is not documented.
- Your incident response plan does not include your organisations identified essential function(s).
- Your incident response plan is not well understood by relevant staff.
Partially Achieved - All the following statements are true:
- Your incident response plan covers network and information systems supporting your essential function(s).
- Your incident response plan comprehensively covers scenarios that are focused on likely impacts of known and well understood attacks only.
- Your incident response plan is understood by all staff who are involved with your organisation's response function.
- Your incident response plan is documented and shared with all relevant stakeholders.
- Your incident response plan is readily accessible, even when your organisations IT systems have been adversely affected by an incident.
- Your incident response plan is regularly reviewed to ensure it remains effective.
Achieved - All the following statements are true:
- Your incident response plan is based on a clear understanding of the security risks to the network and information systems supporting your essential function(s).
- Your incident response plan is comprehensive (i.e. covers the complete lifecycle of an incident, roles and responsibilities, and reporting) and covers likely impacts of both known attack patterns and of possible attacks, previously unseen.
- Your incident response plan is documented and integrated with wider organisational business plans and supply chain response plans as well as dependencies on supporting infrastructure (e.g. power, cooling etc).
- Your incident response plan is communicated and understood by the business areas involved with the operation of your essential function(s).
D1.b Response and Recovery Capability
- You have the capability to enact your incident response plan, including effective limitation of impact on the operation of your essential function(s). During an incident, you have access to timely information on which to base your response decisions.
- You have the capability to enact your incident response plan, including effective limitation of impact on the operation of your essential function(s). During an incident, you have access to timely information on which to base your response decisions.
- Inadequate arrangements have been made to make the right resources available to implement your response plan.
- Your response team members are not equipped to make good response decisions and put them into effect.
- Inadequate back-up mechanisms exist to allow the continued operation of your essential function(s) during an incident.
- You understand the resources that will likely be needed to carry out any required response activities, and arrangements are in place to make these resources available.
- You understand the types of information that will likely be needed to inform response decisions and arrangements are in place to make this information available.
- Your response team members have the skills and knowledge required to decide on the response actions necessary to limit harm, and the authority to carry them out.
- Key roles are duplicated, and operational delivery knowledge is shared with all individuals involved in the operations and recovery of the essential function(s).
- Back-up mechanisms are available that can be readily activated to allow continued operation of your essential function(s), although possibly at a reduced level, if primary network and information systems fail or are unavailable.
- Arrangements exist to augment your organisation’s incident response capabilities with external support if necessary (e.g. specialist cyber incident responders).
Not Achieved - At least one of the following is true:
- Inadequate arrangements have been made to make the right resources available to implement your response plan.
- Your response team members are not equipped to make good response decisions and put them into effect.
- Inadequate back-up mechanisms exist to allow the continued operation of your essential function(s) during an incident.
Achieved - All the following statements are true:
- You understand the resources that will likely be needed to carry out any required response activities, and arrangements are in place to make these resources available.
- You understand the types of information that will likely be needed to inform response decisions and arrangements are in place to make this information available.
- Your response team members have the skills and knowledge required to decide on the response actions necessary to limit harm, and the authority to carry them out.
- Key roles are duplicated, and operational delivery knowledge is shared with all individuals involved in the operations and recovery of the essential function(s).
- Back-up mechanisms are available that can be readily activated to allow continued operation of your essential function(s), although possibly at a reduced level, if primary network and information systems fail or are unavailable.
- Arrangements exist to augment your organisation’s incident response capabilities with external support if necessary (e.g. specialist cyber incident responders).
D1.c Testing and Exercising
- Your organisation carries out exercises to test response plans, using past incidents that affected your (and other) organisation, and scenarios that draw on threat intelligence and your risk assessment.
- Your organisation carries out exercises to test response plans, using past incidents that affected your (and other) organisation, and scenarios that draw on threat intelligence and your risk assessment.
- Exercises test only a discrete part of the process (e.g. that backups are working), but do not consider all areas.
- Incident response exercises are not routinely carried out or are carried out in an ad-hoc way.
- Outputs from exercises are not fed into the organisation's lessons learned process.
- Exercises do not test all parts of the response cycle.
- Exercise scenarios are based on incidents experienced by your and other organisations or are composed using experience or threat intelligence.
- Exercise scenarios are documented, regularly reviewed, and validated.
- Exercises are routinely run, with the findings documented and used to refine incident response plans and protective security, in line with the lessons learned.
- Exercises test all parts of your response cycle relating to your essential function(s) (e.g. restoration of normal function(s) levels).
Not Achieved - At least one of the following is true:
- Exercises test only a discrete part of the process (e.g. that backups are working), but do not consider all areas.
- Incident response exercises are not routinely carried out or are carried out in an ad-hoc way.
- Outputs from exercises are not fed into the organisation's lessons learned process.
- Exercises do not test all parts of the response cycle.
Achieved - All the following statements are true:
- Exercise scenarios are based on incidents experienced by your and other organisations or are composed using experience or threat intelligence.
- Exercise scenarios are documented, regularly reviewed, and validated.
- Exercises are routinely run, with the findings documented and used to refine incident response plans and protective security, in line with the lessons learned.
- Exercises test all parts of your response cycle relating to your essential function(s) (e.g. restoration of normal function(s) levels).
There are well-defined and tested incident management processes in place, that aim to ensure continuity of essential function(s) in the event of system or service failure. Mitigation activities designed to contain or limit the impact of compromise are also in place.
Description
error determining description
Guidance
The 10 Steps to Cyber Security: Incident Management has concise guidance, but organisations should use other more detailed guidance as and when appropriate. Other authoritative guidance pieces are referenced below.
In addition to meeting the expectations of 10 Steps to Cyber Security, you should ensure that your organisation's incident response plans are grounded in thorough and comprehensive risk assessments. Response plans should prioritise essential functions along with the assets and systems that are required to ensure their continued effective operation, such as operational technologies, or key datasets.
The business continuity implications of any compromise should also be taken into account and your cyber incident response plans should link to other business response functions. You should form a cyber response team that is capable of implementing the plan, with the appropriate skills, tools and reach into other parts of your organisation, such as security monitoring and business continuity.
In practice, the Incident Response function should interoperate with the security monitoring function. The Incident Response function needn't be a dedicated team and some members may have non-response related roles. Collectively, the team should have knowledge of IT security, IT infrastructure and Business Management, any specialist technologies (e.g. Operational Technologies or datacentres), incident reporting requirements, and communications plans.
Your plan should cover all relevant potential incidents. It should be auditable and testable (
via exercises
) across a range of incident scenarios and should encompass all realistic descriptions of what might constitute an incident and its severity. Your test scenarios should draw on threat intelligence, past incidents, exercises and the ways in which security capabilities (e.g. security monitoring and alerting) would feature in your response options. Your scenarios should also consider incidents that involve suppliers and your wider supply chain e.g. incidents arising through supplier relations or relying on suppliers as part of your response.
These scenarios could include, but is not limited to:
The scenarios should be incorporated into exercises, which should be run to test your ability to respond to incidents that could affect the operation of essential functions. These exercises should reflect past experience, red-teaming/scenario planning, or threat intelligence and should draw heavily on your risk assessment, considering all relevant assets and vulnerabilities, especially where they relate to essential functions.
Exercises should record lessons learned, covering governance, roles and internal communication, quality of network and security monitoring data, containment and recovery strategies, or any other factors relevant to their effectiveness. This should integrate with lessons learned activities (see
Principle D2 Lessons Learned
).
Your plans should work seamlessly with other system management and security functions. Changes and improvements to response plans should reflect changes to these functions and vice versa, where appropriate.
Plans should articulate clear governance frameworks and roles with procedures for reporting to relevant internal or external stakeholders, such as regulators and competent authorities.
Your plan should also set out a comprehensive range of containment, eradication and recovery strategies, specifying how and when they should be used.
Your organisation should be able to describe its own state of readiness, using any criteria or expected standards from regulators or competent authorities, or from your internal governance arrangements, where appropriate.
In order to report coherently on incidents when required, your plan should set out reporting thresholds (i.e. what does and does not need to be reported) and standards (i.e. the level of detail that should be reported) and which authorities to report to.
More detailed guidance on developing an incident response plan, and the underlying capability to implement it, can be found in the
NIST Computer Security Incident Handling Guide
, CREST publications (see references) or
ISO/IEC 27035-1
.
Contributing Outcomes
D1.a Response Plan
- You have an up-to-date incident response plan that is grounded in a thorough risk assessment that takes account of network and information systems supporting the operation of your essential function(s) and covers a range of incident scenarios.
- You have an up-to-date incident response plan that is grounded in a thorough risk assessment that takes account of network and information systems supporting the operation of your essential function(s) and covers a range of incident scenarios.
- Your incident response plan is not documented.
- Your incident response plan does not include your organisations identified essential function(s).
- Your incident response plan is not well understood by relevant staff.
- Your incident response plan covers network and information systems supporting your essential function(s).
- Your incident response plan comprehensively covers scenarios that are focused on likely impacts of known and well understood attacks only.
- Your incident response plan is understood by all staff who are involved with your organisation's response function.
- Your incident response plan is documented and shared with all relevant stakeholders.
- Your incident response plan is readily accessible, even when your organisations IT systems have been adversely affected by an incident.
- Your incident response plan is regularly reviewed to ensure it remains effective.
- Your incident response plan is based on a clear understanding of the security risks to the network and information systems supporting your essential function(s).
- Your incident response plan is comprehensive (i.e. covers the complete lifecycle of an incident, roles and responsibilities, and reporting) and covers likely impacts of both known attack patterns and of possible attacks, previously unseen.
- Your incident response plan is documented and integrated with wider organisational business plans and supply chain response plans as well as dependencies on supporting infrastructure (e.g. power, cooling etc).
- Your incident response plan is communicated and understood by the business areas involved with the operation of your essential function(s).
Not achieved - At least one of the following is true:
- Your incident response plan is not documented.
- Your incident response plan does not include your organisations identified essential function(s).
- Your incident response plan is not well understood by relevant staff.
Partially Achieved - All the following statements are true:
- Your incident response plan covers network and information systems supporting your essential function(s).
- Your incident response plan comprehensively covers scenarios that are focused on likely impacts of known and well understood attacks only.
- Your incident response plan is understood by all staff who are involved with your organisation's response function.
- Your incident response plan is documented and shared with all relevant stakeholders.
- Your incident response plan is readily accessible, even when your organisations IT systems have been adversely affected by an incident.
- Your incident response plan is regularly reviewed to ensure it remains effective.
Achieved - All the following statements are true:
- Your incident response plan is based on a clear understanding of the security risks to the network and information systems supporting your essential function(s).
- Your incident response plan is comprehensive (i.e. covers the complete lifecycle of an incident, roles and responsibilities, and reporting) and covers likely impacts of both known attack patterns and of possible attacks, previously unseen.
- Your incident response plan is documented and integrated with wider organisational business plans and supply chain response plans as well as dependencies on supporting infrastructure (e.g. power, cooling etc).
- Your incident response plan is communicated and understood by the business areas involved with the operation of your essential function(s).
D1.b Response and Recovery Capability
- You have the capability to enact your incident response plan, including effective limitation of impact on the operation of your essential function(s). During an incident, you have access to timely information on which to base your response decisions.
- You have the capability to enact your incident response plan, including effective limitation of impact on the operation of your essential function(s). During an incident, you have access to timely information on which to base your response decisions.
- Inadequate arrangements have been made to make the right resources available to implement your response plan.
- Your response team members are not equipped to make good response decisions and put them into effect.
- Inadequate back-up mechanisms exist to allow the continued operation of your essential function(s) during an incident.
- You understand the resources that will likely be needed to carry out any required response activities, and arrangements are in place to make these resources available.
- You understand the types of information that will likely be needed to inform response decisions and arrangements are in place to make this information available.
- Your response team members have the skills and knowledge required to decide on the response actions necessary to limit harm, and the authority to carry them out.
- Key roles are duplicated, and operational delivery knowledge is shared with all individuals involved in the operations and recovery of the essential function(s).
- Back-up mechanisms are available that can be readily activated to allow continued operation of your essential function(s), although possibly at a reduced level, if primary network and information systems fail or are unavailable.
- Arrangements exist to augment your organisation’s incident response capabilities with external support if necessary (e.g. specialist cyber incident responders).
Not Achieved - At least one of the following is true:
- Inadequate arrangements have been made to make the right resources available to implement your response plan.
- Your response team members are not equipped to make good response decisions and put them into effect.
- Inadequate back-up mechanisms exist to allow the continued operation of your essential function(s) during an incident.
Achieved - All the following statements are true:
- You understand the resources that will likely be needed to carry out any required response activities, and arrangements are in place to make these resources available.
- You understand the types of information that will likely be needed to inform response decisions and arrangements are in place to make this information available.
- Your response team members have the skills and knowledge required to decide on the response actions necessary to limit harm, and the authority to carry them out.
- Key roles are duplicated, and operational delivery knowledge is shared with all individuals involved in the operations and recovery of the essential function(s).
- Back-up mechanisms are available that can be readily activated to allow continued operation of your essential function(s), although possibly at a reduced level, if primary network and information systems fail or are unavailable.
- Arrangements exist to augment your organisation’s incident response capabilities with external support if necessary (e.g. specialist cyber incident responders).
D1.c Testing and Exercising
- Your organisation carries out exercises to test response plans, using past incidents that affected your (and other) organisation, and scenarios that draw on threat intelligence and your risk assessment.
- Your organisation carries out exercises to test response plans, using past incidents that affected your (and other) organisation, and scenarios that draw on threat intelligence and your risk assessment.
- Exercises test only a discrete part of the process (e.g. that backups are working), but do not consider all areas.
- Incident response exercises are not routinely carried out or are carried out in an ad-hoc way.
- Outputs from exercises are not fed into the organisation's lessons learned process.
- Exercises do not test all parts of the response cycle.
- Exercise scenarios are based on incidents experienced by your and other organisations or are composed using experience or threat intelligence.
- Exercise scenarios are documented, regularly reviewed, and validated.
- Exercises are routinely run, with the findings documented and used to refine incident response plans and protective security, in line with the lessons learned.
- Exercises test all parts of your response cycle relating to your essential function(s) (e.g. restoration of normal function(s) levels).
Not Achieved - At least one of the following is true:
- Exercises test only a discrete part of the process (e.g. that backups are working), but do not consider all areas.
- Incident response exercises are not routinely carried out or are carried out in an ad-hoc way.
- Outputs from exercises are not fed into the organisation's lessons learned process.
- Exercises do not test all parts of the response cycle.
Achieved - All the following statements are true:
- Exercise scenarios are based on incidents experienced by your and other organisations or are composed using experience or threat intelligence.
- Exercise scenarios are documented, regularly reviewed, and validated.
- Exercises are routinely run, with the findings documented and used to refine incident response plans and protective security, in line with the lessons learned.
- Exercises test all parts of your response cycle relating to your essential function(s) (e.g. restoration of normal function(s) levels).
There are well-defined and tested incident management processes in place, that aim to ensure continuity of essential function(s) in the event of system or service failure. Mitigation activities designed to contain or limit the impact of compromise are also in place.
Description
error determining description
Guidance
The 10 Steps to Cyber Security: Incident Management has concise guidance, but organisations should use other more detailed guidance as and when appropriate. Other authoritative guidance pieces are referenced below.
In addition to meeting the expectations of 10 Steps to Cyber Security, you should ensure that your organisation's incident response plans are grounded in thorough and comprehensive risk assessments. Response plans should prioritise essential functions along with the assets and systems that are required to ensure their continued effective operation, such as operational technologies, or key datasets.
The business continuity implications of any compromise should also be taken into account and your cyber incident response plans should link to other business response functions. You should form a cyber response team that is capable of implementing the plan, with the appropriate skills, tools and reach into other parts of your organisation, such as security monitoring and business continuity.
In practice, the Incident Response function should interoperate with the security monitoring function. The Incident Response function needn't be a dedicated team and some members may have non-response related roles. Collectively, the team should have knowledge of IT security, IT infrastructure and Business Management, any specialist technologies (e.g. Operational Technologies or datacentres), incident reporting requirements, and communications plans.
Your plan should cover all relevant potential incidents. It should be auditable and testable (
via exercises
) across a range of incident scenarios and should encompass all realistic descriptions of what might constitute an incident and its severity. Your test scenarios should draw on threat intelligence, past incidents, exercises and the ways in which security capabilities (e.g. security monitoring and alerting) would feature in your response options. Your scenarios should also consider incidents that involve suppliers and your wider supply chain e.g. incidents arising through supplier relations or relying on suppliers as part of your response.
These scenarios could include, but is not limited to:
The scenarios should be incorporated into exercises, which should be run to test your ability to respond to incidents that could affect the operation of essential functions. These exercises should reflect past experience, red-teaming/scenario planning, or threat intelligence and should draw heavily on your risk assessment, considering all relevant assets and vulnerabilities, especially where they relate to essential functions.
Exercises should record lessons learned, covering governance, roles and internal communication, quality of network and security monitoring data, containment and recovery strategies, or any other factors relevant to their effectiveness. This should integrate with lessons learned activities (see
Principle D2 Lessons Learned
).
Your plans should work seamlessly with other system management and security functions. Changes and improvements to response plans should reflect changes to these functions and vice versa, where appropriate.
Plans should articulate clear governance frameworks and roles with procedures for reporting to relevant internal or external stakeholders, such as regulators and competent authorities.
Your plan should also set out a comprehensive range of containment, eradication and recovery strategies, specifying how and when they should be used.
Your organisation should be able to describe its own state of readiness, using any criteria or expected standards from regulators or competent authorities, or from your internal governance arrangements, where appropriate.
In order to report coherently on incidents when required, your plan should set out reporting thresholds (i.e. what does and does not need to be reported) and standards (i.e. the level of detail that should be reported) and which authorities to report to.
More detailed guidance on developing an incident response plan, and the underlying capability to implement it, can be found in the
NIST Computer Security Incident Handling Guide
, CREST publications (see references) or
ISO/IEC 27035-1
.
Contributing Outcomes
D1.a Response Plan
- You have an up-to-date incident response plan that is grounded in a thorough risk assessment that takes account of network and information systems supporting the operation of your essential function(s) and covers a range of incident scenarios.
- You have an up-to-date incident response plan that is grounded in a thorough risk assessment that takes account of network and information systems supporting the operation of your essential function(s) and covers a range of incident scenarios.
- Your incident response plan is not documented.
- Your incident response plan does not include your organisations identified essential function(s).
- Your incident response plan is not well understood by relevant staff.
- Your incident response plan covers network and information systems supporting your essential function(s).
- Your incident response plan comprehensively covers scenarios that are focused on likely impacts of known and well understood attacks only.
- Your incident response plan is understood by all staff who are involved with your organisation's response function.
- Your incident response plan is documented and shared with all relevant stakeholders.
- Your incident response plan is readily accessible, even when your organisations IT systems have been adversely affected by an incident.
- Your incident response plan is regularly reviewed to ensure it remains effective.
- Your incident response plan is based on a clear understanding of the security risks to the network and information systems supporting your essential function(s).
- Your incident response plan is comprehensive (i.e. covers the complete lifecycle of an incident, roles and responsibilities, and reporting) and covers likely impacts of both known attack patterns and of possible attacks, previously unseen.
- Your incident response plan is documented and integrated with wider organisational business plans and supply chain response plans as well as dependencies on supporting infrastructure (e.g. power, cooling etc).
- Your incident response plan is communicated and understood by the business areas involved with the operation of your essential function(s).
Not achieved - At least one of the following is true:
- Your incident response plan is not documented.
- Your incident response plan does not include your organisations identified essential function(s).
- Your incident response plan is not well understood by relevant staff.
Partially Achieved - All the following statements are true:
- Your incident response plan covers network and information systems supporting your essential function(s).
- Your incident response plan comprehensively covers scenarios that are focused on likely impacts of known and well understood attacks only.
- Your incident response plan is understood by all staff who are involved with your organisation's response function.
- Your incident response plan is documented and shared with all relevant stakeholders.
- Your incident response plan is readily accessible, even when your organisations IT systems have been adversely affected by an incident.
- Your incident response plan is regularly reviewed to ensure it remains effective.
Achieved - All the following statements are true:
- Your incident response plan is based on a clear understanding of the security risks to the network and information systems supporting your essential function(s).
- Your incident response plan is comprehensive (i.e. covers the complete lifecycle of an incident, roles and responsibilities, and reporting) and covers likely impacts of both known attack patterns and of possible attacks, previously unseen.
- Your incident response plan is documented and integrated with wider organisational business plans and supply chain response plans as well as dependencies on supporting infrastructure (e.g. power, cooling etc).
- Your incident response plan is communicated and understood by the business areas involved with the operation of your essential function(s).
D1.b Response and Recovery Capability
- You have the capability to enact your incident response plan, including effective limitation of impact on the operation of your essential function(s). During an incident, you have access to timely information on which to base your response decisions.
- You have the capability to enact your incident response plan, including effective limitation of impact on the operation of your essential function(s). During an incident, you have access to timely information on which to base your response decisions.
- Inadequate arrangements have been made to make the right resources available to implement your response plan.
- Your response team members are not equipped to make good response decisions and put them into effect.
- Inadequate back-up mechanisms exist to allow the continued operation of your essential function(s) during an incident.
- You understand the resources that will likely be needed to carry out any required response activities, and arrangements are in place to make these resources available.
- You understand the types of information that will likely be needed to inform response decisions and arrangements are in place to make this information available.
- Your response team members have the skills and knowledge required to decide on the response actions necessary to limit harm, and the authority to carry them out.
- Key roles are duplicated, and operational delivery knowledge is shared with all individuals involved in the operations and recovery of the essential function(s).
- Back-up mechanisms are available that can be readily activated to allow continued operation of your essential function(s), although possibly at a reduced level, if primary network and information systems fail or are unavailable.
- Arrangements exist to augment your organisation’s incident response capabilities with external support if necessary (e.g. specialist cyber incident responders).
Not Achieved - At least one of the following is true:
- Inadequate arrangements have been made to make the right resources available to implement your response plan.
- Your response team members are not equipped to make good response decisions and put them into effect.
- Inadequate back-up mechanisms exist to allow the continued operation of your essential function(s) during an incident.
Achieved - All the following statements are true:
- You understand the resources that will likely be needed to carry out any required response activities, and arrangements are in place to make these resources available.
- You understand the types of information that will likely be needed to inform response decisions and arrangements are in place to make this information available.
- Your response team members have the skills and knowledge required to decide on the response actions necessary to limit harm, and the authority to carry them out.
- Key roles are duplicated, and operational delivery knowledge is shared with all individuals involved in the operations and recovery of the essential function(s).
- Back-up mechanisms are available that can be readily activated to allow continued operation of your essential function(s), although possibly at a reduced level, if primary network and information systems fail or are unavailable.
- Arrangements exist to augment your organisation’s incident response capabilities with external support if necessary (e.g. specialist cyber incident responders).
D1.c Testing and Exercising
- Your organisation carries out exercises to test response plans, using past incidents that affected your (and other) organisation, and scenarios that draw on threat intelligence and your risk assessment.
- Your organisation carries out exercises to test response plans, using past incidents that affected your (and other) organisation, and scenarios that draw on threat intelligence and your risk assessment.
- Exercises test only a discrete part of the process (e.g. that backups are working), but do not consider all areas.
- Incident response exercises are not routinely carried out or are carried out in an ad-hoc way.
- Outputs from exercises are not fed into the organisation's lessons learned process.
- Exercises do not test all parts of the response cycle.
- Exercise scenarios are based on incidents experienced by your and other organisations or are composed using experience or threat intelligence.
- Exercise scenarios are documented, regularly reviewed, and validated.
- Exercises are routinely run, with the findings documented and used to refine incident response plans and protective security, in line with the lessons learned.
- Exercises test all parts of your response cycle relating to your essential function(s) (e.g. restoration of normal function(s) levels).
Not Achieved - At least one of the following is true:
- Exercises test only a discrete part of the process (e.g. that backups are working), but do not consider all areas.
- Incident response exercises are not routinely carried out or are carried out in an ad-hoc way.
- Outputs from exercises are not fed into the organisation's lessons learned process.
- Exercises do not test all parts of the response cycle.
Achieved - All the following statements are true:
- Exercise scenarios are based on incidents experienced by your and other organisations or are composed using experience or threat intelligence.
- Exercise scenarios are documented, regularly reviewed, and validated.
- Exercises are routinely run, with the findings documented and used to refine incident response plans and protective security, in line with the lessons learned.
- Exercises test all parts of your response cycle relating to your essential function(s) (e.g. restoration of normal function(s) levels).
When an incident occurs, steps are taken to understand its causes and to ensure remediating action is taken to protect against future incidents.
Description
error determining description
Guidance
You should use the guidance points below to learn lessons and address shortfalls in:
your overall protective security (see
Objectives A - C
) and
your incident response plan (see
Response and Recovery Planning
)
your overall protective security (see
Objectives A - C
) and
Contributing Outcomes
D2.a Post Incident Analysis
- When an incident occurs, your organisation takes steps to understand its causes, informing appropriate remediating action.
- When an incident occurs, your organisation takes steps to understand its causes, informing appropriate remediating action.
- You are not usually able to resolve incidents to a root cause or identify the contributing factors within a broader systems context.
- You do not have a formal process for investigating causes.
- Investigators form theories early in the process and only seek evidence that affirms their belief.
- Investigations are solely focused on identifying the person(s) who can be held responsible for the incident.
- Post incident analysis is conducted routinely as a key part of your lessons learned activities following an incident.
- Your post incident analysis is comprehensive, considering organisational factors (e.g. policies, processes and procedures), technical factors (e.g. system design, vulnerabilities), human factors (e.g. training, security culture) and any changes to threat.
- All relevant incident data is made available to the analysis team to perform post incident analysis.
- Your analysis considers what could have happened under plausible, alternative circumstances (e.g. ‘what if’ / ’if only’ scenarios).
Not Achieved - At least one of the following statements is true:
- You are not usually able to resolve incidents to a root cause or identify the contributing factors within a broader systems context.
- You do not have a formal process for investigating causes.
- Investigators form theories early in the process and only seek evidence that affirms their belief.
- Investigations are solely focused on identifying the person(s) who can be held responsible for the incident.
Achieved - All the following statements are true:
- Post incident analysis is conducted routinely as a key part of your lessons learned activities following an incident.
- Your post incident analysis is comprehensive, considering organisational factors (e.g. policies, processes and procedures), technical factors (e.g. system design, vulnerabilities), human factors (e.g. training, security culture) and any changes to threat.
- All relevant incident data is made available to the analysis team to perform post incident analysis.
- Your analysis considers what could have happened under plausible, alternative circumstances (e.g. ‘what if’ / ’if only’ scenarios).
D2.b Using Incidents to Drive Improvements
- Your organisation uses lessons learned from incidents to improve your security measures.
- Your organisation uses lessons learned from incidents to improve your security measures.
- Improvements arising from lessons learned following an incident are not implemented or not given sufficient organisational priority.
- Changes are made as a ‘knee jerk’ reaction to an incident without proper analysis and testing to ensure the change is appropriate.
- You wait until a severe or high-profile incident has occurred before you take steps to improve.
- You have a documented incident review process / policy which ensures that lessons learned from each incident, including near misses, are identified, captured, and acted upon.
- Lessons learned cover issues with reporting, roles, governance, skills and organisational policies, processes and procedures as well as technical aspects of network and information systems.
- You use lessons learned to improve security measures, including updating and retesting response plans when necessary.
- Security improvements identified as a result of lessons learned are prioritised, with the highest priority improvements completed promptly.
- Analysis is fed to senior management and incorporated into risk management and continuous improvement.
- Your organisation maximises the lessons learned by using the analysis into ‘what if’ / ’if only’ scenarios.
- Your organisation learns from reported incidents in your sector and the wider national infrastructure.
Not Achieved - At least one of the following is true:
- Improvements arising from lessons learned following an incident are not implemented or not given sufficient organisational priority.
- Changes are made as a ‘knee jerk’ reaction to an incident without proper analysis and testing to ensure the change is appropriate.
- You wait until a severe or high-profile incident has occurred before you take steps to improve.
Achieved - All the following statements are true:
- You have a documented incident review process / policy which ensures that lessons learned from each incident, including near misses, are identified, captured, and acted upon.
- Lessons learned cover issues with reporting, roles, governance, skills and organisational policies, processes and procedures as well as technical aspects of network and information systems.
- You use lessons learned to improve security measures, including updating and retesting response plans when necessary.
- Security improvements identified as a result of lessons learned are prioritised, with the highest priority improvements completed promptly.
- Analysis is fed to senior management and incorporated into risk management and continuous improvement.
- Your organisation maximises the lessons learned by using the analysis into ‘what if’ / ’if only’ scenarios.
- Your organisation learns from reported incidents in your sector and the wider national infrastructure.
When an incident occurs, steps are taken to understand its causes and to ensure remediating action is taken to protect against future incidents.
Description
error determining description
Guidance
You should use the guidance points below to learn lessons and address shortfalls in:
your overall protective security (see
Objectives A - C
) and
your incident response plan (see
Response and Recovery Planning
)
your overall protective security (see
Objectives A - C
) and
Contributing Outcomes
D2.a Post Incident Analysis
- When an incident occurs, your organisation takes steps to understand its causes, informing appropriate remediating action.
- When an incident occurs, your organisation takes steps to understand its causes, informing appropriate remediating action.
- You are not usually able to resolve incidents to a root cause or identify the contributing factors within a broader systems context.
- You do not have a formal process for investigating causes.
- Investigators form theories early in the process and only seek evidence that affirms their belief.
- Investigations are solely focused on identifying the person(s) who can be held responsible for the incident.
- Post incident analysis is conducted routinely as a key part of your lessons learned activities following an incident.
- Your post incident analysis is comprehensive, considering organisational factors (e.g. policies, processes and procedures), technical factors (e.g. system design, vulnerabilities), human factors (e.g. training, security culture) and any changes to threat.
- All relevant incident data is made available to the analysis team to perform post incident analysis.
- Your analysis considers what could have happened under plausible, alternative circumstances (e.g. ‘what if’ / ’if only’ scenarios).
Not Achieved - At least one of the following statements is true:
- You are not usually able to resolve incidents to a root cause or identify the contributing factors within a broader systems context.
- You do not have a formal process for investigating causes.
- Investigators form theories early in the process and only seek evidence that affirms their belief.
- Investigations are solely focused on identifying the person(s) who can be held responsible for the incident.
Achieved - All the following statements are true:
- Post incident analysis is conducted routinely as a key part of your lessons learned activities following an incident.
- Your post incident analysis is comprehensive, considering organisational factors (e.g. policies, processes and procedures), technical factors (e.g. system design, vulnerabilities), human factors (e.g. training, security culture) and any changes to threat.
- All relevant incident data is made available to the analysis team to perform post incident analysis.
- Your analysis considers what could have happened under plausible, alternative circumstances (e.g. ‘what if’ / ’if only’ scenarios).
D2.b Using Incidents to Drive Improvements
- Your organisation uses lessons learned from incidents to improve your security measures.
- Your organisation uses lessons learned from incidents to improve your security measures.
- Improvements arising from lessons learned following an incident are not implemented or not given sufficient organisational priority.
- Changes are made as a ‘knee jerk’ reaction to an incident without proper analysis and testing to ensure the change is appropriate.
- You wait until a severe or high-profile incident has occurred before you take steps to improve.
- You have a documented incident review process / policy which ensures that lessons learned from each incident, including near misses, are identified, captured, and acted upon.
- Lessons learned cover issues with reporting, roles, governance, skills and organisational policies, processes and procedures as well as technical aspects of network and information systems.
- You use lessons learned to improve security measures, including updating and retesting response plans when necessary.
- Security improvements identified as a result of lessons learned are prioritised, with the highest priority improvements completed promptly.
- Analysis is fed to senior management and incorporated into risk management and continuous improvement.
- Your organisation maximises the lessons learned by using the analysis into ‘what if’ / ’if only’ scenarios.
- Your organisation learns from reported incidents in your sector and the wider national infrastructure.
Not Achieved - At least one of the following is true:
- Improvements arising from lessons learned following an incident are not implemented or not given sufficient organisational priority.
- Changes are made as a ‘knee jerk’ reaction to an incident without proper analysis and testing to ensure the change is appropriate.
- You wait until a severe or high-profile incident has occurred before you take steps to improve.
Achieved - All the following statements are true:
- You have a documented incident review process / policy which ensures that lessons learned from each incident, including near misses, are identified, captured, and acted upon.
- Lessons learned cover issues with reporting, roles, governance, skills and organisational policies, processes and procedures as well as technical aspects of network and information systems.
- You use lessons learned to improve security measures, including updating and retesting response plans when necessary.
- Security improvements identified as a result of lessons learned are prioritised, with the highest priority improvements completed promptly.
- Analysis is fed to senior management and incorporated into risk management and continuous improvement.
- Your organisation maximises the lessons learned by using the analysis into ‘what if’ / ’if only’ scenarios.
- Your organisation learns from reported incidents in your sector and the wider national infrastructure.