NCSC CAF

Version: 4.0

Published: 18 April 2024

Reviewed: 6 August 2025

Objectives

CAF Objective A - Managing Security Risk

Principles

Principle A1 Governance

The organisation has appropriate management policies, processes and procedures in place to govern its approach to the security of network and information systems.

Description

error determining description

Guidance

Your organisation's approach to security governance needs to be an appropriate fit for your organisation. Good security governance is integrated with your business's usual decision making structures and processes.

Decisions about risk can be made at all levels of your organisation when delegated effectively to people with the right security, business and technical knowledge, skills and experience. Clear lines of communication are also necessary.

Contributing Outcomes

A1.a Board Direction

Not achieved - At least one of the following statements is true:

Achieved - All the following statements are true:

A1.b Roles and Responsibilities

Not achieved - At least one of the following statements is true:

Achieved - All the following statements are true:

A1.c Decision-making

Not achieved - At least one of the following statements is true:

Achieved - All the following statements are true:

Principle A1 Governance

The organisation has appropriate management policies, processes and procedures in place to govern its approach to the security of network and information systems.

Description

error determining description

Guidance

Your organisation's approach to security governance needs to be an appropriate fit for your organisation. Good security governance is integrated with your business's usual decision making structures and processes.

Decisions about risk can be made at all levels of your organisation when delegated effectively to people with the right security, business and technical knowledge, skills and experience. Clear lines of communication are also necessary.

Contributing Outcomes

A1.a Board Direction

Not achieved - At least one of the following statements is true:

Achieved - All the following statements are true:

A1.b Roles and Responsibilities

Not achieved - At least one of the following statements is true:

Achieved - All the following statements are true:

A1.c Decision-making

Not achieved - At least one of the following statements is true:

Achieved - All the following statements are true:

Principle A1 Governance

The organisation has appropriate management policies, processes and procedures in place to govern its approach to the security of network and information systems.

Description

error determining description

Guidance

Your organisation's approach to security governance needs to be an appropriate fit for your organisation. Good security governance is integrated with your business's usual decision making structures and processes.

Decisions about risk can be made at all levels of your organisation when delegated effectively to people with the right security, business and technical knowledge, skills and experience. Clear lines of communication are also necessary.

Contributing Outcomes

A1.a Board Direction

Not achieved - At least one of the following statements is true:

Achieved - All the following statements are true:

A1.b Roles and Responsibilities

Not achieved - At least one of the following statements is true:

Achieved - All the following statements are true:

A1.c Decision-making

Not achieved - At least one of the following statements is true:

Achieved - All the following statements are true:

Principle A2 Risk Management

The organisation takes appropriate steps to identify, assess and understand security risks to network and information systems supporting the operation of essential functions. This includes an overall organisational approach to risk management.

Description

error determining description

Guidance

Our Risk Management guidance aims to help you to choose an approach that's right for your organisation. Organisations responsible for essential functions are likely to benefit from a combination of a system-based approach , which looks at the interactions between components of the function, and a component-driven analysis , which considers the threats, vulnerabilities, and impacts relevant to particular critical components.

Your organisation should choose a method or framework for managing risk that fits with the organisation's business and technology needs.

Whichever approach you choose, the scope of your programme must include all systems relevant to the operation of essential functions. Simply following the minimum requirements of a standard or applying blanket controls across the organisation is unlikely to adequately manage risks to critical systems.

Where industrial control and automation systems are in scope of the essential function, you should keep in mind that controls suitable for managing risks on the corporate IT network may be inappropriate or damaging in an operational technology environment. These systems will likely require a more tailored approach, and some frameworks and standards address specific concerns relating to such systems.

Cyber threats continue to evolve and develop, putting each organisation’s operational continuity and services at significant risk. By identifying and understanding cyber threats, and the steps a threat actor may take to compromise systems supporting essential functions, an organisation can implement effective security measures to counter malicious attacks and breaches. Various methods can be used to better understand threat which are discussed in our Risk Management guidance .

Ultimately, a detailed understanding of current cyber threats helps organisations to mitigate risks, ensuring the security and resilience of network and information systems in an increasingly hostile world.

Various means are available to gain confidence in the effectiveness of the security of technologies, processes and people. The NCSC Risk Management guidance discusses how to gain and maintain assurance in your risk treatments.

The NCSC assurance guidance provides some examples that may be useful to understand cyber security confidence in your organisation and there are some specific technical NCSC guides:

The NCSC Penetration guidance will help you understand the proper use and commissioning of penetration tests to gain assurance in the security of an IT system.

Our Cloud Security collection provides guidance on managing the risks involved with using cloud services, and some of the principles and guidance are more broadly applicable. The cloud guidance for having confidence in cyber security provides principles that are useful for assuring cyber security of essential functions. The collection will be of particular interest if your organisation hosts any part of your essential function infrastructure on a cloud service.

The NCSC Penetration guidance will help you understand the proper use and commissioning of penetration tests to gain assurance in the security of an IT system.

Contributing Outcomes

A2.a Risk Management Process

Not achieved - At least one of the following statements is true:

Partially achieved - All the following statements are true:

Achieved - All the following statements are true:

A2.b Understanding Threat

Not achieved - At least one of the following statements is true:

Partially achieved - All the following statements are true:

Achieved - All the following statements are true:

A2.c Assurance

Not achieved - At least one of the following statements is true:

Achieved - All the following statements are true:

Principle A2 Risk Management

The organisation takes appropriate steps to identify, assess and understand security risks to network and information systems supporting the operation of essential functions. This includes an overall organisational approach to risk management.

Description

error determining description

Guidance

Our Risk Management guidance aims to help you to choose an approach that's right for your organisation. Organisations responsible for essential functions are likely to benefit from a combination of a system-based approach , which looks at the interactions between components of the function, and a component-driven analysis , which considers the threats, vulnerabilities, and impacts relevant to particular critical components.

Your organisation should choose a method or framework for managing risk that fits with the organisation's business and technology needs.

Whichever approach you choose, the scope of your programme must include all systems relevant to the operation of essential functions. Simply following the minimum requirements of a standard or applying blanket controls across the organisation is unlikely to adequately manage risks to critical systems.

Where industrial control and automation systems are in scope of the essential function, you should keep in mind that controls suitable for managing risks on the corporate IT network may be inappropriate or damaging in an operational technology environment. These systems will likely require a more tailored approach, and some frameworks and standards address specific concerns relating to such systems.

Cyber threats continue to evolve and develop, putting each organisation’s operational continuity and services at significant risk. By identifying and understanding cyber threats, and the steps a threat actor may take to compromise systems supporting essential functions, an organisation can implement effective security measures to counter malicious attacks and breaches. Various methods can be used to better understand threat which are discussed in our Risk Management guidance .

Ultimately, a detailed understanding of current cyber threats helps organisations to mitigate risks, ensuring the security and resilience of network and information systems in an increasingly hostile world.

Various means are available to gain confidence in the effectiveness of the security of technologies, processes and people. The NCSC Risk Management guidance discusses how to gain and maintain assurance in your risk treatments.

The NCSC assurance guidance provides some examples that may be useful to understand cyber security confidence in your organisation and there are some specific technical NCSC guides:

The NCSC Penetration guidance will help you understand the proper use and commissioning of penetration tests to gain assurance in the security of an IT system.

Our Cloud Security collection provides guidance on managing the risks involved with using cloud services, and some of the principles and guidance are more broadly applicable. The cloud guidance for having confidence in cyber security provides principles that are useful for assuring cyber security of essential functions. The collection will be of particular interest if your organisation hosts any part of your essential function infrastructure on a cloud service.

The NCSC Penetration guidance will help you understand the proper use and commissioning of penetration tests to gain assurance in the security of an IT system.

Contributing Outcomes

A2.a Risk Management Process

Not achieved - At least one of the following statements is true:

Partially achieved - All the following statements are true:

Achieved - All the following statements are true:

A2.b Understanding Threat

Not achieved - At least one of the following statements is true:

Partially achieved - All the following statements are true:

Achieved - All the following statements are true:

A2.c Assurance

Not achieved - At least one of the following statements is true:

Achieved - All the following statements are true:

Principle A3 Asset Management

Everything required to deliver, maintain or support networks and information systems necessary for the operation of essential functions is determined and understood. This includes data, people and systems, as well as any supporting infrastructure (such as power or cooling).

Description

error determining description

Guidance

Whichever risk management method your organisation uses, asset management will play a key role as you cannot effectively manage risks without understanding what assets are part of the essential function. Your asset management regime should consider all relevant assets, and dependencies between them. Dependencies may be identified between assets under your organisation's control (including IT and OT domains), elements of the supply chain (including power), and key staff who are critical to operations. Assets in an operational technology environment may need a more tailored approach than the corporate IT assets.

For asset management to be effective, up to date knowledge of your assets must be maintained throughout their lifecycle.

Asset management is part of an ISO 27001 Information Security Management System (ISMS), but management of critical assets may require a tailored approach.

If your organisation is using an ISMS as a tool for compliance with cyber regulation, you must ensure the scope includes all systems relevant to the operation of the essential function covered by the regulation. Asset management is a key part of an ISMS, although critical services may need more attention than the minimum requirements of the standard.

This standard aligns with ISO 27001 and can be used in conjunction with it or independent of it. It outlines requirements for a generic asset management system. An organisation following this standard as a tool for compliance with cyber regulation must ensure the scope encompasses all the relevant systems. The standard covers needs and expectations of stakeholders, which must include any requirements from regulators.

ITIL is an IT service management framework that outlines best practices for delivering IT services. It  recommends a staged approach to IT Asset Management (ITAM). You may find this useful for improving management of your IT assets, but must keep in mind that there may be assets and dependencies beyond the corporate IT domain as outlined above.

Asset management is part of an ISO 27001 Information Security Management System (ISMS), but management of critical assets may require a tailored approach.

If your organisation is using an ISMS as a tool for compliance with cyber regulation, you must ensure the scope includes all systems relevant to the operation of the essential function covered by the regulation. Asset management is a key part of an ISMS, although critical services may need more attention than the minimum requirements of the standard.

Contributing Outcomes

A3.a Asset Management

Not achieved - At least one of the following statements is true:

Achieved - All the following statements are true:

Principle A3 Asset Management

Everything required to deliver, maintain or support networks and information systems necessary for the operation of essential functions is determined and understood. This includes data, people and systems, as well as any supporting infrastructure (such as power or cooling).

Description

error determining description

Guidance

Whichever risk management method your organisation uses, asset management will play a key role as you cannot effectively manage risks without understanding what assets are part of the essential function. Your asset management regime should consider all relevant assets, and dependencies between them. Dependencies may be identified between assets under your organisation's control (including IT and OT domains), elements of the supply chain (including power), and key staff who are critical to operations. Assets in an operational technology environment may need a more tailored approach than the corporate IT assets.

For asset management to be effective, up to date knowledge of your assets must be maintained throughout their lifecycle.

Asset management is part of an ISO 27001 Information Security Management System (ISMS), but management of critical assets may require a tailored approach.

If your organisation is using an ISMS as a tool for compliance with cyber regulation, you must ensure the scope includes all systems relevant to the operation of the essential function covered by the regulation. Asset management is a key part of an ISMS, although critical services may need more attention than the minimum requirements of the standard.

This standard aligns with ISO 27001 and can be used in conjunction with it or independent of it. It outlines requirements for a generic asset management system. An organisation following this standard as a tool for compliance with cyber regulation must ensure the scope encompasses all the relevant systems. The standard covers needs and expectations of stakeholders, which must include any requirements from regulators.

ITIL is an IT service management framework that outlines best practices for delivering IT services. It  recommends a staged approach to IT Asset Management (ITAM). You may find this useful for improving management of your IT assets, but must keep in mind that there may be assets and dependencies beyond the corporate IT domain as outlined above.

Asset management is part of an ISO 27001 Information Security Management System (ISMS), but management of critical assets may require a tailored approach.

If your organisation is using an ISMS as a tool for compliance with cyber regulation, you must ensure the scope includes all systems relevant to the operation of the essential function covered by the regulation. Asset management is a key part of an ISMS, although critical services may need more attention than the minimum requirements of the standard.

Contributing Outcomes

A3.a Asset Management

Not achieved - At least one of the following statements is true:

Achieved - All the following statements are true:

Principle A4 Supply Chain

The organisation understands and manages security risks to networks and information systems supporting the operation of essential functions that arise as a result of dependencies on suppliers. This includes ensuring that appropriate measures are employed where third party services are used.

Description

error determining description

Guidance

Organisations responsible for essential functions need to ensure that when third party suppliers are used, all relevant security requirements are met. This means that a number of specific supply chain related security considerations should be addressed where relevant to the provision of the essential function. This might include:

Ensuring the protection of data shared with a third party. This includes protecting data from actions such as unauthorised access, modification, or deletion that may cause an adverse impact on any essential functions (see Principle B3 ).

Effective specification of the security properties of products or services procured from an external third party, or sourced internally from another part of the organisation, that are important for the protection of the essential function. This should include the security requirements derived from the rest of these Principles.

Ensure that any network connections or data sharing with third parties do not introduce unmanaged vulnerabilities that have the potential to affect the security of the essential function.

Confidence that third party suppliers are trustworthy such that malicious attempts to subvert the security of products or systems that could affect the essential function are managed.

Ensuring the protection of data shared with a third party. This includes protecting data from actions such as unauthorised access, modification, or deletion that may cause an adverse impact on any essential functions (see Principle B3 ).

Contributing Outcomes

A4.a Supply Chain

Not achieved - At least one of the following statements is true:

Partially achieved - All the following statements are true:

Achieved - All the following statements are true:

A4.b Secure Software Development and Support

Not achieved - At least one of the following statements is true:

Partially achieved - All the following statements are true:

Achieved - All the following statements are true:

Principle A4 Supply Chain

The organisation understands and manages security risks to networks and information systems supporting the operation of essential functions that arise as a result of dependencies on suppliers. This includes ensuring that appropriate measures are employed where third party services are used.

Description

error determining description

Guidance

Organisations responsible for essential functions need to ensure that when third party suppliers are used, all relevant security requirements are met. This means that a number of specific supply chain related security considerations should be addressed where relevant to the provision of the essential function. This might include:

Ensuring the protection of data shared with a third party. This includes protecting data from actions such as unauthorised access, modification, or deletion that may cause an adverse impact on any essential functions (see Principle B3 ).

Effective specification of the security properties of products or services procured from an external third party, or sourced internally from another part of the organisation, that are important for the protection of the essential function. This should include the security requirements derived from the rest of these Principles.

Ensure that any network connections or data sharing with third parties do not introduce unmanaged vulnerabilities that have the potential to affect the security of the essential function.

Confidence that third party suppliers are trustworthy such that malicious attempts to subvert the security of products or systems that could affect the essential function are managed.

Ensuring the protection of data shared with a third party. This includes protecting data from actions such as unauthorised access, modification, or deletion that may cause an adverse impact on any essential functions (see Principle B3 ).

Contributing Outcomes

A4.a Supply Chain

Not achieved - At least one of the following statements is true:

Partially achieved - All the following statements are true:

Achieved - All the following statements are true:

A4.b Secure Software Development and Support

Not achieved - At least one of the following statements is true:

Partially achieved - All the following statements are true:

Achieved - All the following statements are true:

Principle B1 Service protection policies, processes and procedures

The organisation defines, implements, communicates and enforces appropriate policies, processes and procedures that direct its overall approach to securing systems and data that support the operation of essential functions.

Description

error determining description

Guidance

The policies, processes and procedures needed by an organisation depend upon its function and should integrate with the organisation’s approach to governance and risk management. Organisations responsible for essential functions should have a range of policies, processes and procedures, including:

An organisational security or service protection policy: endorsed by senior management, this high-level policy should include the organisation’s overarching approach to governing security and managing risks, the organisation’s aims and intents for security and what is of key concern.

Supporting policies, processes and procedures: contextual lower-level definitions controlling, directing and communicating organisational security practice.

Compliance policies and processes for sector regulations, standards, etc.: specific policies and processes appropriate to the compliance regime; these may be defined by the regulation, standard, etc. For example, to comply with ISO/IEC 27001, organisations should have in place certain security policies and procedures relevant to what the organisation does, how it does it, and what their ISO/IEC 27001 information security management system covers (see ISO/IEC 27002 for detail).

An organisational security or service protection policy: endorsed by senior management, this high-level policy should include the organisation’s overarching approach to governing security and managing risks, the organisation’s aims and intents for security and what is of key concern.

Contributing Outcomes

B1.a Policy, Process and Procedure Development

Not achieved - At least one of the following statements is true:

Partially achieved - All the following statements are true:

Achieved - All the following statements are true:

B1.b Policy, Process and Procedure Implementation

Not achieved - At least one of the following statements is true:

Partially achieved - All the following statements are true:

Achieved - All the following statements are true:

Principle B2 Identity and Access Control

The organisation understands, documents and manages access to networks and information systems and supporting the operation of essential functions. Users (or automated functions) that can access data or services are appropriately verified, authenticated and authorised.

Description

It is important that the organisation is clear about who (or what in the case of automated functions) has authorisation to interact with the network and information systems supporting an essential function in any way or access associated sensitive data. Access rights granted should be carefully controlled, especially where those rights provide an ability to materially affect the operation of the essential function. Access rights granted should be periodically reviewed and technically removed when no longer required such as when an individual changes role or leaves the organisation.

Users, devices and systems should be appropriately verified, authenticated and authorised before access to data or services is granted. Verification of a user’s identity (they are who they say they are) is a prerequisite for issuing credentials, authentication and access management. For highly privileged access it might be appropriate to include approaches such as multi-factor or hardware authentication.

Unauthorised individuals should be prevented from accessing data or services at all points within the system. This includes system users without the appropriate permissions, unauthorised individuals attempting to interact with any online service or individuals with unauthorised access to user devices (for example if a user device were lost or stolen).

Guidance

The Introduction to identity and access management sets out security fundamentals that operators should consider in designing and managing identity and access management systems. Identity and access control should be robust enough that essential functions are not adversely affected by unauthorised access.

In addition to technical security, organisations should protect physical access to networks and information systems supporting the essential function, to prevent unauthorised access, tampering or data deletion. Some organisations may already have physical security measures in place to comply with non-cyber regulatory frameworks. See NPSA guidance on Control Access for further information.

Contributing Outcomes

B2.a Identity Verification, Authentication and Authorisation

Not achieved - At least one of the following statements is true:

Partially achieved - All the following statements are true:

Achieved - All the following statements are true:

B2.b Device Management

Not achieved - At least one of the following statements is true:

Partially achieved - All the following statements are true:

Achieved - All the following statements are true:

B2.c Privileged User Management

Not achieved - At least one of the following statements is true:

Partially achieved - All of the following statements are true:

Achieved - All of the following statements are true:

B2.d Identity and Access Management (IdAM)

Not achieved - At least one of the following statements is true:

Partially achieved - All of the following statements are true:

Achieved - All of the following statements are true:

Principle B3 Data security

Data stored or transmitted electronically is protected from actions such as unauthorised access, modification, or deletion that may cause an adverse impact on essential functions. Such protection extends to the means by which authorised users, devices and systems access critical data necessary for the operation of essential functions. It also covers information that would assist an attacker, such as design details of networks and information systems.

Description

error determining description

Guidance

Networks and information systems should be designed to protect important data, for example:

protecting the confidentiality of sensitive data by minimising the number of copies of data, the detail these include and by retaining operationally sensitive data on segregated systems (this includes design documentation)

removing functionality that could allow greater access than has been authorised

protecting the integrity of data essential to the operation of the function by providing a read-only copy for non-essential business system consumption

only deploying well-tested cryptographic suites in common use by your chosen software stack

protecting availability through resilience measures such as multiple network paths and tested automatic backup systems

consider suitable means to retain access to essential information in the event of an incident. For example, network diagrams needed for restoration, safety-critical information or essential forecasting data

protecting the confidentiality of sensitive data by minimising the number of copies of data, the detail these include and by retaining operationally sensitive data on segregated systems (this includes design documentation)

Contributing Outcomes

B3.a Understanding Data

Not achieved - At least one of the following statements is true:

Partially achieved - All of the following statements are true:

Achieved - All of the following statements are true:

B3.b Data in Transit

Not achieved - At least one of the following statements is true:

Partially achieved - All the following statements are true:

Achieved - All the following statements are true:

B3.c Stored Data

Not achieved - At least one of the following statements is true:

Partially achieved - All of the following statements are true:

Achieved - All of the following statements are true:

B3.d Mobile Data

Not achieved - At least one of the following statements is true:

Partially achieved - All of the following statements are true:

Achieved - All of the following statements are true:

B3.e Media/Equipment Sanitisation

Not achieved - At least one of the following statements is true:

Partially achieved - All of the following statements are true:

Achieved - All of the following statements are true:

Principle B4 System security

Network and information systems and technology critical for the operation of essential functions are protected from cyber attack. An organisational understanding of risk to essential functions informs the use of robust and reliable protective security measures to effectively limit opportunities for threat actors to compromise networks and systems.

Description

error determining description

Guidance

The majority of cyber security incidents can be traced to common cyber attack vectors. The opportunity for successful attack can be minimised by managing the known vulnerabilities which these attacks exploit. Many opportunities for user error can be reduced by technical means.

Attempts to circumvent the measures described below should be detected by security monitoring . Together with data security and resilience measures , the impact of any attempts to circumvent security on the operation of the essential function should be limited.

Contributing Outcomes

B4.a Secure by Design

Not achieved - At least one of the following statements is true:

Partially achieved - All the following statements are true:

Achieved - All the following statements are true:

B4.b Secure Configuration

Not achieved - At least one of the following statements is true:

Partially achieved - All of the following statements are true:

Achieved - All of the following statements are true:

B4.c Secure Management

Not achieved - At least one of the following statements is true:

Partially achieved - All of the following statements are true:

Achieved - All of the following statements are true:

B4.d Vulnerability Management

Not achieved - At least one of the following statements is true:

Partially achieved - All of the following statements are true:

Achieved - All of the following statements are true:

Principle B5 Resilient networks and systems

The organisation builds resilience against cyber attack and system failure into the design, implementation, operation and management of systems that support the operation of your essential function(s).

Description

error determining description

Guidance

It's important to be prepared to respond to significant disruption by having business continuity and disaster recovery planning in place. This should include a definition of your most critical resources and an understanding of the order of actions needed to restore service(s). Test that these plans work, for example through manually triggering failover testing, carrying out table-top scenario walk-throughs, red-teaming or Cyber adversary simulation testing. You should be ready to adjust the security measures in place in response to changes in risk. For example, if threat intelligence indicates an increased likelihood of your organisation or sector being targeted you may decide to isolate operational networks until the threat has decreased. Alternatively, in the event of public disclosure of an unpatched vulnerability in equipment that you use, with reported use of exploits targeting the vulnerability, you may respond by elevating your protective monitoring, changing your configuration to avoid being susceptible, or taking other mitigating action in the period until a patch is made available and can be deployed.

You should reduce the likelihood of failure or attack by taking all reasonable measures to maintain networks, information systems and necessary technologies in good working order. Exceptions should be appropriately managed.

In the event of an incident, it is more likely that an essential function will be able to continue where the networks and information systems that support it are segregated from other business and external systems. Separation of system architecture, remote access and privileged access are some key principles that can protect more critical systems from external compromise.

Some sectors responsible for the operation of essential functions may apply the industrial automation and control system security standard IEC 62443, which applies a reference model that separates systems into different logical layers. The standard's architecture model segregates equipment into security zones.

Limitations of networks and information systems, or external services or resources, such as network bandwidth, processing capability, or data storage capacity, should be understood and managed with suitable mitigations to avoid disruption through resource overload.

Make appropriate use of diverse technologies, geographic locations and so on, to provide resilience. You should understand and manage external or lower-priority dependencies to ensure that alternative means are suitable for continuation of the essential function.

In the event of an adverse event, you should be able to revert to backups of hardware and data that are known to be functioning and accessible. Organisations should maintain secured offline, potentially off-site, backups of the operational data, equipment configurations, gold builds, etc. needed to recover from an extreme event.

Suitable alternative backups may include paper-based information and manual processes. Other essential backups may include personnel with appropriate knowledge and access to up-to-date documentation. Consider how to make it easy to recover following an incident or compromise.

You should have adequate policies and measures to ensure the physical and environmental security of your network and information systems. This can be achieved through measures such as physical access controls, alarm systems, environmental controls and automated fire systems etc.

When planning physical upgrades or changes to network and information systems (such as moving to new hardware installations, installing new equipment or power supplies), you should take steps to avoid unnecessary or unplanned interruptions to the services that your network and information systems support.

You should also ensure that you have adequate policies to protect supporting utilities such as electricity, fuel, heating, ventilation, and air conditioning. This can be achieved by having alternative sources, such as back-up generators or uninterruptible power supplies, active temperature monitoring, redundant cooling systems etc.

Contributing Outcomes

B5.a Resilience Preparation

Not achieved - Any of the following statements are true:

Partially achieved - All of the following statements are true:

Achieved - All of the following statements are true:

B5.b Design for Resilience

Not achieved - At least one of the following statements is true:

Partially achieved - All of the following statements are true:

Achieved - All of the following statements are true:

B5.c Backups

Not achieved - At least one of the following statements is true:

Partially achieved - All of the following statements are true:

Achieved - All of the following statements are true:

Principle B6 Staff awareness and training

Staff have appropriate awareness, knowledge and skills to carry out their organisational roles effectively in relation to the security of network and information systems supporting the operation of your essential function(s).

Description

error determining description

Guidance

The people who operate and support essential functions should be provided with all they need to carry out their job while supporting the organisation's cyber security. In line with the design of service protection policies and processes , you should apply the same people-focussed approach to staff awareness and training.

Training and awareness activities should provide appropriate cyber security skills for the job role based on an understanding of how people really work with the systems, with ongoing reminders and top-up training to maintain skills.

Using a range of approaches to training and awareness can improve understanding and information retention, from briefings, online courses and blogs to simulated cyber attack. You may achieve the widest uptake of training and awareness by accommodating different learning preferences and using various delivery methods. Organisations may find the GCHQ certified training scheme useful when considering commercial offerings.

Organisations responsible for essential functions should aim to create a positive security culture, where people are aware of their role in maintaining security and actively take part and contribute to improving security. This is particularly important where a technical solution is not possible, so security relies on people making the right cyber security decisions. Developing a positive security culture is likely to take some time, with some changes possibly taking years to become established and is unlikely to be achieved simply through written guidance or training events.

These outcomes are best achieved when organisations actively engage with staff and communicate effectively with them about network and information system security and how it relates to their jobs. This should be more easily achieved where organisations create and promote a long-term security culture vision that is endorsed and supported by senior management, then make incremental, focused changes to address specific business issues. In some cases, particularly where an essential function is safety-related, an organisation may be able to draw on activities supporting positive safety culture to build up the organisation's cyber security culture.

Contributing Outcomes

B6.a Cyber Security Culture

Not achieved - At least one of the following statements is true:

Partially achieved - All the following statements are true:

Achieved - All the following statements are true:

B6.b Cyber Security Training

Not achieved - At least one of the following statements is true:

Partially achieved - All the following statements are true:

Achieved - All the following statements are true:

Principle C1 Security monitoring

The organisation monitors the security status of network and information systems supporting the operation of essential function(s) in order to detect  security events indicative of a security incident.

Description

error determining description

Guidance

One clear focus of your security monitoring should be the detection of incidents or activity that is likely to have an adverse impact on the network and information systems that support the operation of essential functions. Log data collection, secure storage, analysis tools, understanding your network and information systems that support your essential function(s), threat intelligence and personnel skills should all be used to build an effective security monitoring capability.

An organisation's automated monitoring capability should be able to find threats within their network and information systems by using both signature-based detections and, behavioural and anomaly-based detections.

Examples of signature-based detections are detecting when known command and control traffic is communicating to the internet, or an AV signature is present in a file. Organisations should endeavour to understand what automated detections and alerting do and how best to use them, to ensure they are making the most of the monitoring solution / as well as being as effective as possible.

Organisations should also have the capability to find threats by using behavioural and anomaly-based detections, for example by detecting an abnormally large amount of data being exfiltrated or AV detecting unusual changes to start up registry keys.

Both signature and, anomaly and behaviour-based detections rely on an understanding of indicators of compromise, your network and information systems, user behaviour and threats.

Contributing Outcomes

C1.a Sources and Tools for Logging and Monitoring

Not achieved - At least one of the following statements is true:

Partially achieved - All the following statements are true:

Achieved - All the following statements are true:

C1.b Securing Logs

Not achieved - At least one of the following is true:

Partially achieved - All the following statements are true:

Achieved - All the following statements are true:

C1.c Generating Alerts

Not achieved - At least one of the following is true:

Partially achieved - All the following statements are true:

Achieved - All the following statements are true:

C1.d Triage of Security Alerts

Not achieved - At least one of the following is true:

Partially achieved - All the following statements are true:

Achieved - All the following statements are true:

C1.e Personnel Skills for Monitoring Tools and Detection

Not achieved - At least one of the following is true:

Partially achieved - All the following statements are true:

Achieved - All the following statements are true:

C1.f Understanding User's and System's Behaviour, and Threat Intelligence (within Security Monitoring)

Not achieved - At least one of the following is true:

Partially achieved - All the following statements are true:

Achieved - All the following statements are true:

Principle C2 Threat Hunting

The organisation proactively seeks to detect, within networks and information systems, adverse activity affecting, or with the potential to affect, the operation of essential functions even when the activity evades standard security prevent/detect solutions (or when standard solutions are not deployable).

Description

error determining description

Guidance

Threat hunting is more difficult than standard security monitoring because it looks beyond the known Indicators of Compromise (IOCs) that can be leveraged by automated detections and alerting covered in C1 Security Monitoring .

The aim is to build on what is known of both past and plausible attacks to hypothesise what intrusions might look like in. Threat hunting requires more experienced knowledge of network and system behaviour and of the general characteristics that an intrusion might exhibit. This sort of proactive monitoring or threat discovery would normally involve:

A good understanding of normal system behaviour (e.g. what software is authorised and how it would normally behave, how user accounts normally access network resources or how network components connect to each other and transfer data).

A good understanding of the ways that different types of threats maybe realised within your environment(s) based on a comprehensive and advanced understanding of threat intelligence.

A good understanding of normal system behaviour (e.g. what software is authorised and how it would normally behave, how user accounts normally access network resources or how network components connect to each other and transfer data).

Contributing Outcomes

C2.a Threat Hunting

Not achieved - At least one of the following statements is true:

Partially achieved - All the following statements are true:

Achieved - All the following statements are true:

Principle D1 Response and recovery planning

There are well-defined and tested incident management processes in place, that aim to ensure continuity of essential function(s) in the event of system or service failure. Mitigation activities designed to contain or limit the impact of compromise are also in place.

Description

error determining description

Guidance

The 10 Steps to Cyber Security: Incident Management has concise guidance, but organisations should use other more detailed guidance as and when appropriate. Other authoritative guidance pieces are referenced below.

In addition to meeting the expectations of 10 Steps to Cyber Security, you should ensure that your organisation's incident response plans are grounded in thorough and comprehensive risk assessments. Response plans should prioritise essential functions along with the assets and systems that are required to ensure their continued effective operation, such as operational technologies, or key datasets.

The business continuity implications of any compromise should also be taken into account and your cyber incident response plans should link to other business response functions. You should form a cyber response team that is capable of implementing the plan, with the appropriate skills, tools and reach into other parts of your organisation, such as security monitoring and business continuity.

In practice, the Incident Response function should interoperate with the security monitoring function. The Incident Response function needn't be a dedicated team and some members may have non-response related roles. Collectively, the team should have knowledge of IT security, IT infrastructure and Business Management, any specialist technologies (e.g. Operational Technologies or datacentres), incident reporting requirements, and communications plans.

Your plan should cover all relevant potential incidents. It should be auditable and testable ( via exercises ) across a range of incident scenarios and should encompass all realistic descriptions of what might constitute an incident and its severity. Your test scenarios should draw on threat intelligence, past incidents, exercises and the ways in which security capabilities (e.g. security monitoring and alerting) would feature in your response options. Your scenarios should also consider incidents that involve suppliers and your wider supply chain e.g. incidents arising through supplier relations or relying on suppliers as part of your response.

These scenarios could include, but is not limited to:

The scenarios should be incorporated into exercises, which should be run to test your ability to respond to incidents that could affect the operation of essential functions. These exercises should reflect past experience, red-teaming/scenario planning, or threat intelligence and should draw heavily on your risk assessment, considering all relevant assets and vulnerabilities, especially where they relate to essential functions.

Exercises should record lessons learned, covering governance, roles and internal communication, quality of network and security monitoring data, containment and recovery strategies, or any other factors relevant to their effectiveness. This should integrate with lessons learned activities (see Principle D2 Lessons Learned ).

Your plans should work seamlessly with other system management and security functions. Changes and improvements to response plans should reflect changes to these functions and vice versa, where appropriate.

Plans should articulate clear governance frameworks and roles with procedures for reporting to relevant internal or external stakeholders, such as regulators and competent authorities.

Your plan should also set out a comprehensive range of containment, eradication and recovery strategies, specifying how and when they should be used.

Your organisation should be able to describe its own state of readiness, using any criteria or expected standards from regulators or competent authorities, or from your internal governance arrangements, where appropriate.

In order to report coherently on incidents when required, your plan should set out reporting thresholds (i.e. what does and does not need to be reported) and standards (i.e. the level of detail that should be reported) and which authorities to report to.

More detailed guidance on developing an incident response plan, and the underlying capability to implement it, can be found in the NIST Computer Security Incident Handling Guide , CREST publications (see references) or ISO/IEC 27035-1 .

Contributing Outcomes

D1.a Response Plan

Not achieved - At least one of the following is true:

Partially Achieved - All the following statements are true:

Achieved - All the following statements are true:

D1.b Response and Recovery Capability

Not Achieved - At least one of the following is true:

Achieved - All the following statements are true:

D1.c Testing and Exercising

Not Achieved - At least one of the following is true:

Achieved - All the following statements are true:

Principle D2 Lessons Learned

When an incident occurs, steps are taken to understand its causes and to ensure remediating action is taken to protect against future incidents.

Description

error determining description

Guidance

You should use the guidance points below to learn lessons and address shortfalls in:

your overall protective security (see Objectives A - C ) and

your incident response plan (see Response and Recovery Planning )

your overall protective security (see Objectives A - C ) and

Contributing Outcomes

D2.a Post Incident Analysis

Not Achieved - At least one of the following statements is true:

Achieved - All the following statements are true:

D2.b Using Incidents to Drive Improvements

Not Achieved - At least one of the following is true:

Achieved - All the following statements are true:

CAF Objective B - Protecting against cyber attacks

Principles

Principle A1 Governance

The organisation has appropriate management policies, processes and procedures in place to govern its approach to the security of network and information systems.

Description

error determining description

Guidance

Your organisation's approach to security governance needs to be an appropriate fit for your organisation. Good security governance is integrated with your business's usual decision making structures and processes.

Decisions about risk can be made at all levels of your organisation when delegated effectively to people with the right security, business and technical knowledge, skills and experience. Clear lines of communication are also necessary.

Contributing Outcomes

A1.a Board Direction

Not achieved - At least one of the following statements is true:

Achieved - All the following statements are true:

A1.b Roles and Responsibilities

Not achieved - At least one of the following statements is true:

Achieved - All the following statements are true:

A1.c Decision-making

Not achieved - At least one of the following statements is true:

Achieved - All the following statements are true:

Principle A2 Risk Management

The organisation takes appropriate steps to identify, assess and understand security risks to network and information systems supporting the operation of essential functions. This includes an overall organisational approach to risk management.

Description

error determining description

Guidance

Our Risk Management guidance aims to help you to choose an approach that's right for your organisation. Organisations responsible for essential functions are likely to benefit from a combination of a system-based approach , which looks at the interactions between components of the function, and a component-driven analysis , which considers the threats, vulnerabilities, and impacts relevant to particular critical components.

Your organisation should choose a method or framework for managing risk that fits with the organisation's business and technology needs.

Whichever approach you choose, the scope of your programme must include all systems relevant to the operation of essential functions. Simply following the minimum requirements of a standard or applying blanket controls across the organisation is unlikely to adequately manage risks to critical systems.

Where industrial control and automation systems are in scope of the essential function, you should keep in mind that controls suitable for managing risks on the corporate IT network may be inappropriate or damaging in an operational technology environment. These systems will likely require a more tailored approach, and some frameworks and standards address specific concerns relating to such systems.

Cyber threats continue to evolve and develop, putting each organisation’s operational continuity and services at significant risk. By identifying and understanding cyber threats, and the steps a threat actor may take to compromise systems supporting essential functions, an organisation can implement effective security measures to counter malicious attacks and breaches. Various methods can be used to better understand threat which are discussed in our Risk Management guidance .

Ultimately, a detailed understanding of current cyber threats helps organisations to mitigate risks, ensuring the security and resilience of network and information systems in an increasingly hostile world.

Various means are available to gain confidence in the effectiveness of the security of technologies, processes and people. The NCSC Risk Management guidance discusses how to gain and maintain assurance in your risk treatments.

The NCSC assurance guidance provides some examples that may be useful to understand cyber security confidence in your organisation and there are some specific technical NCSC guides:

The NCSC Penetration guidance will help you understand the proper use and commissioning of penetration tests to gain assurance in the security of an IT system.

Our Cloud Security collection provides guidance on managing the risks involved with using cloud services, and some of the principles and guidance are more broadly applicable. The cloud guidance for having confidence in cyber security provides principles that are useful for assuring cyber security of essential functions. The collection will be of particular interest if your organisation hosts any part of your essential function infrastructure on a cloud service.

The NCSC Penetration guidance will help you understand the proper use and commissioning of penetration tests to gain assurance in the security of an IT system.

Contributing Outcomes

A2.a Risk Management Process

Not achieved - At least one of the following statements is true:

Partially achieved - All the following statements are true:

Achieved - All the following statements are true:

A2.b Understanding Threat

Not achieved - At least one of the following statements is true:

Partially achieved - All the following statements are true:

Achieved - All the following statements are true:

A2.c Assurance

Not achieved - At least one of the following statements is true:

Achieved - All the following statements are true:

Principle A3 Asset Management

Everything required to deliver, maintain or support networks and information systems necessary for the operation of essential functions is determined and understood. This includes data, people and systems, as well as any supporting infrastructure (such as power or cooling).

Description

error determining description

Guidance

Whichever risk management method your organisation uses, asset management will play a key role as you cannot effectively manage risks without understanding what assets are part of the essential function. Your asset management regime should consider all relevant assets, and dependencies between them. Dependencies may be identified between assets under your organisation's control (including IT and OT domains), elements of the supply chain (including power), and key staff who are critical to operations. Assets in an operational technology environment may need a more tailored approach than the corporate IT assets.

For asset management to be effective, up to date knowledge of your assets must be maintained throughout their lifecycle.

Asset management is part of an ISO 27001 Information Security Management System (ISMS), but management of critical assets may require a tailored approach.

If your organisation is using an ISMS as a tool for compliance with cyber regulation, you must ensure the scope includes all systems relevant to the operation of the essential function covered by the regulation. Asset management is a key part of an ISMS, although critical services may need more attention than the minimum requirements of the standard.

This standard aligns with ISO 27001 and can be used in conjunction with it or independent of it. It outlines requirements for a generic asset management system. An organisation following this standard as a tool for compliance with cyber regulation must ensure the scope encompasses all the relevant systems. The standard covers needs and expectations of stakeholders, which must include any requirements from regulators.

ITIL is an IT service management framework that outlines best practices for delivering IT services. It  recommends a staged approach to IT Asset Management (ITAM). You may find this useful for improving management of your IT assets, but must keep in mind that there may be assets and dependencies beyond the corporate IT domain as outlined above.

Asset management is part of an ISO 27001 Information Security Management System (ISMS), but management of critical assets may require a tailored approach.

If your organisation is using an ISMS as a tool for compliance with cyber regulation, you must ensure the scope includes all systems relevant to the operation of the essential function covered by the regulation. Asset management is a key part of an ISMS, although critical services may need more attention than the minimum requirements of the standard.

Contributing Outcomes

A3.a Asset Management

Not achieved - At least one of the following statements is true:

Achieved - All the following statements are true:

Principle A4 Supply Chain

The organisation understands and manages security risks to networks and information systems supporting the operation of essential functions that arise as a result of dependencies on suppliers. This includes ensuring that appropriate measures are employed where third party services are used.

Description

error determining description

Guidance

Organisations responsible for essential functions need to ensure that when third party suppliers are used, all relevant security requirements are met. This means that a number of specific supply chain related security considerations should be addressed where relevant to the provision of the essential function. This might include:

Ensuring the protection of data shared with a third party. This includes protecting data from actions such as unauthorised access, modification, or deletion that may cause an adverse impact on any essential functions (see Principle B3 ).

Effective specification of the security properties of products or services procured from an external third party, or sourced internally from another part of the organisation, that are important for the protection of the essential function. This should include the security requirements derived from the rest of these Principles.

Ensure that any network connections or data sharing with third parties do not introduce unmanaged vulnerabilities that have the potential to affect the security of the essential function.

Confidence that third party suppliers are trustworthy such that malicious attempts to subvert the security of products or systems that could affect the essential function are managed.

Ensuring the protection of data shared with a third party. This includes protecting data from actions such as unauthorised access, modification, or deletion that may cause an adverse impact on any essential functions (see Principle B3 ).

Contributing Outcomes

A4.a Supply Chain

Not achieved - At least one of the following statements is true:

Partially achieved - All the following statements are true:

Achieved - All the following statements are true:

A4.b Secure Software Development and Support

Not achieved - At least one of the following statements is true:

Partially achieved - All the following statements are true:

Achieved - All the following statements are true:

Principle A4 Supply Chain

The organisation understands and manages security risks to networks and information systems supporting the operation of essential functions that arise as a result of dependencies on suppliers. This includes ensuring that appropriate measures are employed where third party services are used.

Description

error determining description

Guidance

Organisations responsible for essential functions need to ensure that when third party suppliers are used, all relevant security requirements are met. This means that a number of specific supply chain related security considerations should be addressed where relevant to the provision of the essential function. This might include:

Ensuring the protection of data shared with a third party. This includes protecting data from actions such as unauthorised access, modification, or deletion that may cause an adverse impact on any essential functions (see Principle B3 ).

Effective specification of the security properties of products or services procured from an external third party, or sourced internally from another part of the organisation, that are important for the protection of the essential function. This should include the security requirements derived from the rest of these Principles.

Ensure that any network connections or data sharing with third parties do not introduce unmanaged vulnerabilities that have the potential to affect the security of the essential function.

Confidence that third party suppliers are trustworthy such that malicious attempts to subvert the security of products or systems that could affect the essential function are managed.

Ensuring the protection of data shared with a third party. This includes protecting data from actions such as unauthorised access, modification, or deletion that may cause an adverse impact on any essential functions (see Principle B3 ).

Contributing Outcomes

A4.a Supply Chain

Not achieved - At least one of the following statements is true:

Partially achieved - All the following statements are true:

Achieved - All the following statements are true:

A4.b Secure Software Development and Support

Not achieved - At least one of the following statements is true:

Partially achieved - All the following statements are true:

Achieved - All the following statements are true:

Principle B1 Service protection policies, processes and procedures

The organisation defines, implements, communicates and enforces appropriate policies, processes and procedures that direct its overall approach to securing systems and data that support the operation of essential functions.

Description

error determining description

Guidance

The policies, processes and procedures needed by an organisation depend upon its function and should integrate with the organisation’s approach to governance and risk management. Organisations responsible for essential functions should have a range of policies, processes and procedures, including:

An organisational security or service protection policy: endorsed by senior management, this high-level policy should include the organisation’s overarching approach to governing security and managing risks, the organisation’s aims and intents for security and what is of key concern.

Supporting policies, processes and procedures: contextual lower-level definitions controlling, directing and communicating organisational security practice.

Compliance policies and processes for sector regulations, standards, etc.: specific policies and processes appropriate to the compliance regime; these may be defined by the regulation, standard, etc. For example, to comply with ISO/IEC 27001, organisations should have in place certain security policies and procedures relevant to what the organisation does, how it does it, and what their ISO/IEC 27001 information security management system covers (see ISO/IEC 27002 for detail).

An organisational security or service protection policy: endorsed by senior management, this high-level policy should include the organisation’s overarching approach to governing security and managing risks, the organisation’s aims and intents for security and what is of key concern.

Contributing Outcomes

B1.a Policy, Process and Procedure Development

Not achieved - At least one of the following statements is true:

Partially achieved - All the following statements are true:

Achieved - All the following statements are true:

B1.b Policy, Process and Procedure Implementation

Not achieved - At least one of the following statements is true:

Partially achieved - All the following statements are true:

Achieved - All the following statements are true:

Principle B1 Service protection policies, processes and procedures

The organisation defines, implements, communicates and enforces appropriate policies, processes and procedures that direct its overall approach to securing systems and data that support the operation of essential functions.

Description

error determining description

Guidance

The policies, processes and procedures needed by an organisation depend upon its function and should integrate with the organisation’s approach to governance and risk management. Organisations responsible for essential functions should have a range of policies, processes and procedures, including:

An organisational security or service protection policy: endorsed by senior management, this high-level policy should include the organisation’s overarching approach to governing security and managing risks, the organisation’s aims and intents for security and what is of key concern.

Supporting policies, processes and procedures: contextual lower-level definitions controlling, directing and communicating organisational security practice.

Compliance policies and processes for sector regulations, standards, etc.: specific policies and processes appropriate to the compliance regime; these may be defined by the regulation, standard, etc. For example, to comply with ISO/IEC 27001, organisations should have in place certain security policies and procedures relevant to what the organisation does, how it does it, and what their ISO/IEC 27001 information security management system covers (see ISO/IEC 27002 for detail).

An organisational security or service protection policy: endorsed by senior management, this high-level policy should include the organisation’s overarching approach to governing security and managing risks, the organisation’s aims and intents for security and what is of key concern.

Contributing Outcomes

B1.a Policy, Process and Procedure Development

Not achieved - At least one of the following statements is true:

Partially achieved - All the following statements are true:

Achieved - All the following statements are true:

B1.b Policy, Process and Procedure Implementation

Not achieved - At least one of the following statements is true:

Partially achieved - All the following statements are true:

Achieved - All the following statements are true:

Principle B1 Service protection policies, processes and procedures

The organisation defines, implements, communicates and enforces appropriate policies, processes and procedures that direct its overall approach to securing systems and data that support the operation of essential functions.

Description

error determining description

Guidance

The policies, processes and procedures needed by an organisation depend upon its function and should integrate with the organisation’s approach to governance and risk management. Organisations responsible for essential functions should have a range of policies, processes and procedures, including:

An organisational security or service protection policy: endorsed by senior management, this high-level policy should include the organisation’s overarching approach to governing security and managing risks, the organisation’s aims and intents for security and what is of key concern.

Supporting policies, processes and procedures: contextual lower-level definitions controlling, directing and communicating organisational security practice.

Compliance policies and processes for sector regulations, standards, etc.: specific policies and processes appropriate to the compliance regime; these may be defined by the regulation, standard, etc. For example, to comply with ISO/IEC 27001, organisations should have in place certain security policies and procedures relevant to what the organisation does, how it does it, and what their ISO/IEC 27001 information security management system covers (see ISO/IEC 27002 for detail).

An organisational security or service protection policy: endorsed by senior management, this high-level policy should include the organisation’s overarching approach to governing security and managing risks, the organisation’s aims and intents for security and what is of key concern.

Contributing Outcomes

B1.a Policy, Process and Procedure Development

Not achieved - At least one of the following statements is true:

Partially achieved - All the following statements are true:

Achieved - All the following statements are true:

B1.b Policy, Process and Procedure Implementation

Not achieved - At least one of the following statements is true:

Partially achieved - All the following statements are true:

Achieved - All the following statements are true:

Principle B2 Identity and Access Control

The organisation understands, documents and manages access to networks and information systems and supporting the operation of essential functions. Users (or automated functions) that can access data or services are appropriately verified, authenticated and authorised.

Description

It is important that the organisation is clear about who (or what in the case of automated functions) has authorisation to interact with the network and information systems supporting an essential function in any way or access associated sensitive data. Access rights granted should be carefully controlled, especially where those rights provide an ability to materially affect the operation of the essential function. Access rights granted should be periodically reviewed and technically removed when no longer required such as when an individual changes role or leaves the organisation.

Users, devices and systems should be appropriately verified, authenticated and authorised before access to data or services is granted. Verification of a user’s identity (they are who they say they are) is a prerequisite for issuing credentials, authentication and access management. For highly privileged access it might be appropriate to include approaches such as multi-factor or hardware authentication.

Unauthorised individuals should be prevented from accessing data or services at all points within the system. This includes system users without the appropriate permissions, unauthorised individuals attempting to interact with any online service or individuals with unauthorised access to user devices (for example if a user device were lost or stolen).

Guidance

The Introduction to identity and access management sets out security fundamentals that operators should consider in designing and managing identity and access management systems. Identity and access control should be robust enough that essential functions are not adversely affected by unauthorised access.

In addition to technical security, organisations should protect physical access to networks and information systems supporting the essential function, to prevent unauthorised access, tampering or data deletion. Some organisations may already have physical security measures in place to comply with non-cyber regulatory frameworks. See NPSA guidance on Control Access for further information.

Contributing Outcomes

B2.a Identity Verification, Authentication and Authorisation

Not achieved - At least one of the following statements is true:

Partially achieved - All the following statements are true:

Achieved - All the following statements are true:

B2.b Device Management

Not achieved - At least one of the following statements is true:

Partially achieved - All the following statements are true:

Achieved - All the following statements are true:

B2.c Privileged User Management

Not achieved - At least one of the following statements is true:

Partially achieved - All of the following statements are true:

Achieved - All of the following statements are true:

B2.d Identity and Access Management (IdAM)

Not achieved - At least one of the following statements is true:

Partially achieved - All of the following statements are true:

Achieved - All of the following statements are true:

Principle B2 Identity and Access Control

The organisation understands, documents and manages access to networks and information systems and supporting the operation of essential functions. Users (or automated functions) that can access data or services are appropriately verified, authenticated and authorised.

Description

It is important that the organisation is clear about who (or what in the case of automated functions) has authorisation to interact with the network and information systems supporting an essential function in any way or access associated sensitive data. Access rights granted should be carefully controlled, especially where those rights provide an ability to materially affect the operation of the essential function. Access rights granted should be periodically reviewed and technically removed when no longer required such as when an individual changes role or leaves the organisation.

Users, devices and systems should be appropriately verified, authenticated and authorised before access to data or services is granted. Verification of a user’s identity (they are who they say they are) is a prerequisite for issuing credentials, authentication and access management. For highly privileged access it might be appropriate to include approaches such as multi-factor or hardware authentication.

Unauthorised individuals should be prevented from accessing data or services at all points within the system. This includes system users without the appropriate permissions, unauthorised individuals attempting to interact with any online service or individuals with unauthorised access to user devices (for example if a user device were lost or stolen).

Guidance

The Introduction to identity and access management sets out security fundamentals that operators should consider in designing and managing identity and access management systems. Identity and access control should be robust enough that essential functions are not adversely affected by unauthorised access.

In addition to technical security, organisations should protect physical access to networks and information systems supporting the essential function, to prevent unauthorised access, tampering or data deletion. Some organisations may already have physical security measures in place to comply with non-cyber regulatory frameworks. See NPSA guidance on Control Access for further information.

Contributing Outcomes

B2.a Identity Verification, Authentication and Authorisation

Not achieved - At least one of the following statements is true:

Partially achieved - All the following statements are true:

Achieved - All the following statements are true:

B2.b Device Management

Not achieved - At least one of the following statements is true:

Partially achieved - All the following statements are true:

Achieved - All the following statements are true:

B2.c Privileged User Management

Not achieved - At least one of the following statements is true:

Partially achieved - All of the following statements are true:

Achieved - All of the following statements are true:

B2.d Identity and Access Management (IdAM)

Not achieved - At least one of the following statements is true:

Partially achieved - All of the following statements are true:

Achieved - All of the following statements are true:

Principle B3 Data security

Data stored or transmitted electronically is protected from actions such as unauthorised access, modification, or deletion that may cause an adverse impact on essential functions. Such protection extends to the means by which authorised users, devices and systems access critical data necessary for the operation of essential functions. It also covers information that would assist an attacker, such as design details of networks and information systems.

Description

error determining description

Guidance

Networks and information systems should be designed to protect important data, for example:

protecting the confidentiality of sensitive data by minimising the number of copies of data, the detail these include and by retaining operationally sensitive data on segregated systems (this includes design documentation)

removing functionality that could allow greater access than has been authorised

protecting the integrity of data essential to the operation of the function by providing a read-only copy for non-essential business system consumption

only deploying well-tested cryptographic suites in common use by your chosen software stack

protecting availability through resilience measures such as multiple network paths and tested automatic backup systems

consider suitable means to retain access to essential information in the event of an incident. For example, network diagrams needed for restoration, safety-critical information or essential forecasting data

protecting the confidentiality of sensitive data by minimising the number of copies of data, the detail these include and by retaining operationally sensitive data on segregated systems (this includes design documentation)

Contributing Outcomes

B3.a Understanding Data

Not achieved - At least one of the following statements is true:

Partially achieved - All of the following statements are true:

Achieved - All of the following statements are true:

B3.b Data in Transit

Not achieved - At least one of the following statements is true:

Partially achieved - All the following statements are true:

Achieved - All the following statements are true:

B3.c Stored Data

Not achieved - At least one of the following statements is true:

Partially achieved - All of the following statements are true:

Achieved - All of the following statements are true:

B3.d Mobile Data

Not achieved - At least one of the following statements is true:

Partially achieved - All of the following statements are true:

Achieved - All of the following statements are true:

B3.e Media/Equipment Sanitisation

Not achieved - At least one of the following statements is true:

Partially achieved - All of the following statements are true:

Achieved - All of the following statements are true:

Principle B3 Data security

Data stored or transmitted electronically is protected from actions such as unauthorised access, modification, or deletion that may cause an adverse impact on essential functions. Such protection extends to the means by which authorised users, devices and systems access critical data necessary for the operation of essential functions. It also covers information that would assist an attacker, such as design details of networks and information systems.

Description

error determining description

Guidance

Networks and information systems should be designed to protect important data, for example:

protecting the confidentiality of sensitive data by minimising the number of copies of data, the detail these include and by retaining operationally sensitive data on segregated systems (this includes design documentation)

removing functionality that could allow greater access than has been authorised

protecting the integrity of data essential to the operation of the function by providing a read-only copy for non-essential business system consumption

only deploying well-tested cryptographic suites in common use by your chosen software stack

protecting availability through resilience measures such as multiple network paths and tested automatic backup systems

consider suitable means to retain access to essential information in the event of an incident. For example, network diagrams needed for restoration, safety-critical information or essential forecasting data

protecting the confidentiality of sensitive data by minimising the number of copies of data, the detail these include and by retaining operationally sensitive data on segregated systems (this includes design documentation)

Contributing Outcomes

B3.a Understanding Data

Not achieved - At least one of the following statements is true:

Partially achieved - All of the following statements are true:

Achieved - All of the following statements are true:

B3.b Data in Transit

Not achieved - At least one of the following statements is true:

Partially achieved - All the following statements are true:

Achieved - All the following statements are true:

B3.c Stored Data

Not achieved - At least one of the following statements is true:

Partially achieved - All of the following statements are true:

Achieved - All of the following statements are true:

B3.d Mobile Data

Not achieved - At least one of the following statements is true:

Partially achieved - All of the following statements are true:

Achieved - All of the following statements are true:

B3.e Media/Equipment Sanitisation

Not achieved - At least one of the following statements is true:

Partially achieved - All of the following statements are true:

Achieved - All of the following statements are true:

Principle B4 System security

Network and information systems and technology critical for the operation of essential functions are protected from cyber attack. An organisational understanding of risk to essential functions informs the use of robust and reliable protective security measures to effectively limit opportunities for threat actors to compromise networks and systems.

Description

error determining description

Guidance

The majority of cyber security incidents can be traced to common cyber attack vectors. The opportunity for successful attack can be minimised by managing the known vulnerabilities which these attacks exploit. Many opportunities for user error can be reduced by technical means.

Attempts to circumvent the measures described below should be detected by security monitoring . Together with data security and resilience measures , the impact of any attempts to circumvent security on the operation of the essential function should be limited.

Contributing Outcomes

B4.a Secure by Design

Not achieved - At least one of the following statements is true:

Partially achieved - All the following statements are true:

Achieved - All the following statements are true:

B4.b Secure Configuration

Not achieved - At least one of the following statements is true:

Partially achieved - All of the following statements are true:

Achieved - All of the following statements are true:

B4.c Secure Management

Not achieved - At least one of the following statements is true:

Partially achieved - All of the following statements are true:

Achieved - All of the following statements are true:

B4.d Vulnerability Management

Not achieved - At least one of the following statements is true:

Partially achieved - All of the following statements are true:

Achieved - All of the following statements are true:

Principle B4 System security

Network and information systems and technology critical for the operation of essential functions are protected from cyber attack. An organisational understanding of risk to essential functions informs the use of robust and reliable protective security measures to effectively limit opportunities for threat actors to compromise networks and systems.

Description

error determining description

Guidance

The majority of cyber security incidents can be traced to common cyber attack vectors. The opportunity for successful attack can be minimised by managing the known vulnerabilities which these attacks exploit. Many opportunities for user error can be reduced by technical means.

Attempts to circumvent the measures described below should be detected by security monitoring . Together with data security and resilience measures , the impact of any attempts to circumvent security on the operation of the essential function should be limited.

Contributing Outcomes

B4.a Secure by Design

Not achieved - At least one of the following statements is true:

Partially achieved - All the following statements are true:

Achieved - All the following statements are true:

B4.b Secure Configuration

Not achieved - At least one of the following statements is true:

Partially achieved - All of the following statements are true:

Achieved - All of the following statements are true:

B4.c Secure Management

Not achieved - At least one of the following statements is true:

Partially achieved - All of the following statements are true:

Achieved - All of the following statements are true:

B4.d Vulnerability Management

Not achieved - At least one of the following statements is true:

Partially achieved - All of the following statements are true:

Achieved - All of the following statements are true:

Principle B5 Resilient networks and systems

The organisation builds resilience against cyber attack and system failure into the design, implementation, operation and management of systems that support the operation of your essential function(s).

Description

error determining description

Guidance

It's important to be prepared to respond to significant disruption by having business continuity and disaster recovery planning in place. This should include a definition of your most critical resources and an understanding of the order of actions needed to restore service(s). Test that these plans work, for example through manually triggering failover testing, carrying out table-top scenario walk-throughs, red-teaming or Cyber adversary simulation testing. You should be ready to adjust the security measures in place in response to changes in risk. For example, if threat intelligence indicates an increased likelihood of your organisation or sector being targeted you may decide to isolate operational networks until the threat has decreased. Alternatively, in the event of public disclosure of an unpatched vulnerability in equipment that you use, with reported use of exploits targeting the vulnerability, you may respond by elevating your protective monitoring, changing your configuration to avoid being susceptible, or taking other mitigating action in the period until a patch is made available and can be deployed.

You should reduce the likelihood of failure or attack by taking all reasonable measures to maintain networks, information systems and necessary technologies in good working order. Exceptions should be appropriately managed.

In the event of an incident, it is more likely that an essential function will be able to continue where the networks and information systems that support it are segregated from other business and external systems. Separation of system architecture, remote access and privileged access are some key principles that can protect more critical systems from external compromise.

Some sectors responsible for the operation of essential functions may apply the industrial automation and control system security standard IEC 62443, which applies a reference model that separates systems into different logical layers. The standard's architecture model segregates equipment into security zones.

Limitations of networks and information systems, or external services or resources, such as network bandwidth, processing capability, or data storage capacity, should be understood and managed with suitable mitigations to avoid disruption through resource overload.

Make appropriate use of diverse technologies, geographic locations and so on, to provide resilience. You should understand and manage external or lower-priority dependencies to ensure that alternative means are suitable for continuation of the essential function.

In the event of an adverse event, you should be able to revert to backups of hardware and data that are known to be functioning and accessible. Organisations should maintain secured offline, potentially off-site, backups of the operational data, equipment configurations, gold builds, etc. needed to recover from an extreme event.

Suitable alternative backups may include paper-based information and manual processes. Other essential backups may include personnel with appropriate knowledge and access to up-to-date documentation. Consider how to make it easy to recover following an incident or compromise.

You should have adequate policies and measures to ensure the physical and environmental security of your network and information systems. This can be achieved through measures such as physical access controls, alarm systems, environmental controls and automated fire systems etc.

When planning physical upgrades or changes to network and information systems (such as moving to new hardware installations, installing new equipment or power supplies), you should take steps to avoid unnecessary or unplanned interruptions to the services that your network and information systems support.

You should also ensure that you have adequate policies to protect supporting utilities such as electricity, fuel, heating, ventilation, and air conditioning. This can be achieved by having alternative sources, such as back-up generators or uninterruptible power supplies, active temperature monitoring, redundant cooling systems etc.

Contributing Outcomes

B5.a Resilience Preparation

Not achieved - Any of the following statements are true:

Partially achieved - All of the following statements are true:

Achieved - All of the following statements are true:

B5.b Design for Resilience

Not achieved - At least one of the following statements is true:

Partially achieved - All of the following statements are true:

Achieved - All of the following statements are true:

B5.c Backups

Not achieved - At least one of the following statements is true:

Partially achieved - All of the following statements are true:

Achieved - All of the following statements are true:

Principle B5 Resilient networks and systems

The organisation builds resilience against cyber attack and system failure into the design, implementation, operation and management of systems that support the operation of your essential function(s).

Description

error determining description

Guidance

It's important to be prepared to respond to significant disruption by having business continuity and disaster recovery planning in place. This should include a definition of your most critical resources and an understanding of the order of actions needed to restore service(s). Test that these plans work, for example through manually triggering failover testing, carrying out table-top scenario walk-throughs, red-teaming or Cyber adversary simulation testing. You should be ready to adjust the security measures in place in response to changes in risk. For example, if threat intelligence indicates an increased likelihood of your organisation or sector being targeted you may decide to isolate operational networks until the threat has decreased. Alternatively, in the event of public disclosure of an unpatched vulnerability in equipment that you use, with reported use of exploits targeting the vulnerability, you may respond by elevating your protective monitoring, changing your configuration to avoid being susceptible, or taking other mitigating action in the period until a patch is made available and can be deployed.

You should reduce the likelihood of failure or attack by taking all reasonable measures to maintain networks, information systems and necessary technologies in good working order. Exceptions should be appropriately managed.

In the event of an incident, it is more likely that an essential function will be able to continue where the networks and information systems that support it are segregated from other business and external systems. Separation of system architecture, remote access and privileged access are some key principles that can protect more critical systems from external compromise.

Some sectors responsible for the operation of essential functions may apply the industrial automation and control system security standard IEC 62443, which applies a reference model that separates systems into different logical layers. The standard's architecture model segregates equipment into security zones.

Limitations of networks and information systems, or external services or resources, such as network bandwidth, processing capability, or data storage capacity, should be understood and managed with suitable mitigations to avoid disruption through resource overload.

Make appropriate use of diverse technologies, geographic locations and so on, to provide resilience. You should understand and manage external or lower-priority dependencies to ensure that alternative means are suitable for continuation of the essential function.

In the event of an adverse event, you should be able to revert to backups of hardware and data that are known to be functioning and accessible. Organisations should maintain secured offline, potentially off-site, backups of the operational data, equipment configurations, gold builds, etc. needed to recover from an extreme event.

Suitable alternative backups may include paper-based information and manual processes. Other essential backups may include personnel with appropriate knowledge and access to up-to-date documentation. Consider how to make it easy to recover following an incident or compromise.

You should have adequate policies and measures to ensure the physical and environmental security of your network and information systems. This can be achieved through measures such as physical access controls, alarm systems, environmental controls and automated fire systems etc.

When planning physical upgrades or changes to network and information systems (such as moving to new hardware installations, installing new equipment or power supplies), you should take steps to avoid unnecessary or unplanned interruptions to the services that your network and information systems support.

You should also ensure that you have adequate policies to protect supporting utilities such as electricity, fuel, heating, ventilation, and air conditioning. This can be achieved by having alternative sources, such as back-up generators or uninterruptible power supplies, active temperature monitoring, redundant cooling systems etc.

Contributing Outcomes

B5.a Resilience Preparation

Not achieved - Any of the following statements are true:

Partially achieved - All of the following statements are true:

Achieved - All of the following statements are true:

B5.b Design for Resilience

Not achieved - At least one of the following statements is true:

Partially achieved - All of the following statements are true:

Achieved - All of the following statements are true:

B5.c Backups

Not achieved - At least one of the following statements is true:

Partially achieved - All of the following statements are true:

Achieved - All of the following statements are true:

Principle B6 Staff awareness and training

Staff have appropriate awareness, knowledge and skills to carry out their organisational roles effectively in relation to the security of network and information systems supporting the operation of your essential function(s).

Description

error determining description

Guidance

The people who operate and support essential functions should be provided with all they need to carry out their job while supporting the organisation's cyber security. In line with the design of service protection policies and processes , you should apply the same people-focussed approach to staff awareness and training.

Training and awareness activities should provide appropriate cyber security skills for the job role based on an understanding of how people really work with the systems, with ongoing reminders and top-up training to maintain skills.

Using a range of approaches to training and awareness can improve understanding and information retention, from briefings, online courses and blogs to simulated cyber attack. You may achieve the widest uptake of training and awareness by accommodating different learning preferences and using various delivery methods. Organisations may find the GCHQ certified training scheme useful when considering commercial offerings.

Organisations responsible for essential functions should aim to create a positive security culture, where people are aware of their role in maintaining security and actively take part and contribute to improving security. This is particularly important where a technical solution is not possible, so security relies on people making the right cyber security decisions. Developing a positive security culture is likely to take some time, with some changes possibly taking years to become established and is unlikely to be achieved simply through written guidance or training events.

These outcomes are best achieved when organisations actively engage with staff and communicate effectively with them about network and information system security and how it relates to their jobs. This should be more easily achieved where organisations create and promote a long-term security culture vision that is endorsed and supported by senior management, then make incremental, focused changes to address specific business issues. In some cases, particularly where an essential function is safety-related, an organisation may be able to draw on activities supporting positive safety culture to build up the organisation's cyber security culture.

Contributing Outcomes

B6.a Cyber Security Culture

Not achieved - At least one of the following statements is true:

Partially achieved - All the following statements are true:

Achieved - All the following statements are true:

B6.b Cyber Security Training

Not achieved - At least one of the following statements is true:

Partially achieved - All the following statements are true:

Achieved - All the following statements are true:

Principle B6 Staff awareness and training

Staff have appropriate awareness, knowledge and skills to carry out their organisational roles effectively in relation to the security of network and information systems supporting the operation of your essential function(s).

Description

error determining description

Guidance

The people who operate and support essential functions should be provided with all they need to carry out their job while supporting the organisation's cyber security. In line with the design of service protection policies and processes , you should apply the same people-focussed approach to staff awareness and training.

Training and awareness activities should provide appropriate cyber security skills for the job role based on an understanding of how people really work with the systems, with ongoing reminders and top-up training to maintain skills.

Using a range of approaches to training and awareness can improve understanding and information retention, from briefings, online courses and blogs to simulated cyber attack. You may achieve the widest uptake of training and awareness by accommodating different learning preferences and using various delivery methods. Organisations may find the GCHQ certified training scheme useful when considering commercial offerings.

Organisations responsible for essential functions should aim to create a positive security culture, where people are aware of their role in maintaining security and actively take part and contribute to improving security. This is particularly important where a technical solution is not possible, so security relies on people making the right cyber security decisions. Developing a positive security culture is likely to take some time, with some changes possibly taking years to become established and is unlikely to be achieved simply through written guidance or training events.

These outcomes are best achieved when organisations actively engage with staff and communicate effectively with them about network and information system security and how it relates to their jobs. This should be more easily achieved where organisations create and promote a long-term security culture vision that is endorsed and supported by senior management, then make incremental, focused changes to address specific business issues. In some cases, particularly where an essential function is safety-related, an organisation may be able to draw on activities supporting positive safety culture to build up the organisation's cyber security culture.

Contributing Outcomes

B6.a Cyber Security Culture

Not achieved - At least one of the following statements is true:

Partially achieved - All the following statements are true:

Achieved - All the following statements are true:

B6.b Cyber Security Training

Not achieved - At least one of the following statements is true:

Partially achieved - All the following statements are true:

Achieved - All the following statements are true:

Principle C1 Security monitoring

The organisation monitors the security status of network and information systems supporting the operation of essential function(s) in order to detect  security events indicative of a security incident.

Description

error determining description

Guidance

One clear focus of your security monitoring should be the detection of incidents or activity that is likely to have an adverse impact on the network and information systems that support the operation of essential functions. Log data collection, secure storage, analysis tools, understanding your network and information systems that support your essential function(s), threat intelligence and personnel skills should all be used to build an effective security monitoring capability.

An organisation's automated monitoring capability should be able to find threats within their network and information systems by using both signature-based detections and, behavioural and anomaly-based detections.

Examples of signature-based detections are detecting when known command and control traffic is communicating to the internet, or an AV signature is present in a file. Organisations should endeavour to understand what automated detections and alerting do and how best to use them, to ensure they are making the most of the monitoring solution / as well as being as effective as possible.

Organisations should also have the capability to find threats by using behavioural and anomaly-based detections, for example by detecting an abnormally large amount of data being exfiltrated or AV detecting unusual changes to start up registry keys.

Both signature and, anomaly and behaviour-based detections rely on an understanding of indicators of compromise, your network and information systems, user behaviour and threats.

Contributing Outcomes

C1.a Sources and Tools for Logging and Monitoring

Not achieved - At least one of the following statements is true:

Partially achieved - All the following statements are true:

Achieved - All the following statements are true:

C1.b Securing Logs

Not achieved - At least one of the following is true:

Partially achieved - All the following statements are true:

Achieved - All the following statements are true:

C1.c Generating Alerts

Not achieved - At least one of the following is true:

Partially achieved - All the following statements are true:

Achieved - All the following statements are true:

C1.d Triage of Security Alerts

Not achieved - At least one of the following is true:

Partially achieved - All the following statements are true:

Achieved - All the following statements are true:

C1.e Personnel Skills for Monitoring Tools and Detection

Not achieved - At least one of the following is true:

Partially achieved - All the following statements are true:

Achieved - All the following statements are true:

C1.f Understanding User's and System's Behaviour, and Threat Intelligence (within Security Monitoring)

Not achieved - At least one of the following is true:

Partially achieved - All the following statements are true:

Achieved - All the following statements are true:

Principle C2 Threat Hunting

The organisation proactively seeks to detect, within networks and information systems, adverse activity affecting, or with the potential to affect, the operation of essential functions even when the activity evades standard security prevent/detect solutions (or when standard solutions are not deployable).

Description

error determining description

Guidance

Threat hunting is more difficult than standard security monitoring because it looks beyond the known Indicators of Compromise (IOCs) that can be leveraged by automated detections and alerting covered in C1 Security Monitoring .

The aim is to build on what is known of both past and plausible attacks to hypothesise what intrusions might look like in. Threat hunting requires more experienced knowledge of network and system behaviour and of the general characteristics that an intrusion might exhibit. This sort of proactive monitoring or threat discovery would normally involve:

A good understanding of normal system behaviour (e.g. what software is authorised and how it would normally behave, how user accounts normally access network resources or how network components connect to each other and transfer data).

A good understanding of the ways that different types of threats maybe realised within your environment(s) based on a comprehensive and advanced understanding of threat intelligence.

A good understanding of normal system behaviour (e.g. what software is authorised and how it would normally behave, how user accounts normally access network resources or how network components connect to each other and transfer data).

Contributing Outcomes

C2.a Threat Hunting

Not achieved - At least one of the following statements is true:

Partially achieved - All the following statements are true:

Achieved - All the following statements are true:

Principle D1 Response and recovery planning

There are well-defined and tested incident management processes in place, that aim to ensure continuity of essential function(s) in the event of system or service failure. Mitigation activities designed to contain or limit the impact of compromise are also in place.

Description

error determining description

Guidance

The 10 Steps to Cyber Security: Incident Management has concise guidance, but organisations should use other more detailed guidance as and when appropriate. Other authoritative guidance pieces are referenced below.

In addition to meeting the expectations of 10 Steps to Cyber Security, you should ensure that your organisation's incident response plans are grounded in thorough and comprehensive risk assessments. Response plans should prioritise essential functions along with the assets and systems that are required to ensure their continued effective operation, such as operational technologies, or key datasets.

The business continuity implications of any compromise should also be taken into account and your cyber incident response plans should link to other business response functions. You should form a cyber response team that is capable of implementing the plan, with the appropriate skills, tools and reach into other parts of your organisation, such as security monitoring and business continuity.

In practice, the Incident Response function should interoperate with the security monitoring function. The Incident Response function needn't be a dedicated team and some members may have non-response related roles. Collectively, the team should have knowledge of IT security, IT infrastructure and Business Management, any specialist technologies (e.g. Operational Technologies or datacentres), incident reporting requirements, and communications plans.

Your plan should cover all relevant potential incidents. It should be auditable and testable ( via exercises ) across a range of incident scenarios and should encompass all realistic descriptions of what might constitute an incident and its severity. Your test scenarios should draw on threat intelligence, past incidents, exercises and the ways in which security capabilities (e.g. security monitoring and alerting) would feature in your response options. Your scenarios should also consider incidents that involve suppliers and your wider supply chain e.g. incidents arising through supplier relations or relying on suppliers as part of your response.

These scenarios could include, but is not limited to:

The scenarios should be incorporated into exercises, which should be run to test your ability to respond to incidents that could affect the operation of essential functions. These exercises should reflect past experience, red-teaming/scenario planning, or threat intelligence and should draw heavily on your risk assessment, considering all relevant assets and vulnerabilities, especially where they relate to essential functions.

Exercises should record lessons learned, covering governance, roles and internal communication, quality of network and security monitoring data, containment and recovery strategies, or any other factors relevant to their effectiveness. This should integrate with lessons learned activities (see Principle D2 Lessons Learned ).

Your plans should work seamlessly with other system management and security functions. Changes and improvements to response plans should reflect changes to these functions and vice versa, where appropriate.

Plans should articulate clear governance frameworks and roles with procedures for reporting to relevant internal or external stakeholders, such as regulators and competent authorities.

Your plan should also set out a comprehensive range of containment, eradication and recovery strategies, specifying how and when they should be used.

Your organisation should be able to describe its own state of readiness, using any criteria or expected standards from regulators or competent authorities, or from your internal governance arrangements, where appropriate.

In order to report coherently on incidents when required, your plan should set out reporting thresholds (i.e. what does and does not need to be reported) and standards (i.e. the level of detail that should be reported) and which authorities to report to.

More detailed guidance on developing an incident response plan, and the underlying capability to implement it, can be found in the NIST Computer Security Incident Handling Guide , CREST publications (see references) or ISO/IEC 27035-1 .

Contributing Outcomes

D1.a Response Plan

Not achieved - At least one of the following is true:

Partially Achieved - All the following statements are true:

Achieved - All the following statements are true:

D1.b Response and Recovery Capability

Not Achieved - At least one of the following is true:

Achieved - All the following statements are true:

D1.c Testing and Exercising

Not Achieved - At least one of the following is true:

Achieved - All the following statements are true:

Principle D2 Lessons Learned

When an incident occurs, steps are taken to understand its causes and to ensure remediating action is taken to protect against future incidents.

Description

error determining description

Guidance

You should use the guidance points below to learn lessons and address shortfalls in:

your overall protective security (see Objectives A - C ) and

your incident response plan (see Response and Recovery Planning )

your overall protective security (see Objectives A - C ) and

Contributing Outcomes

D2.a Post Incident Analysis

Not Achieved - At least one of the following statements is true:

Achieved - All the following statements are true:

D2.b Using Incidents to Drive Improvements

Not Achieved - At least one of the following is true:

Achieved - All the following statements are true:

CAF Objective C - Detecting cyber security events

Principles

Principle A1 Governance

The organisation has appropriate management policies, processes and procedures in place to govern its approach to the security of network and information systems.

Description

error determining description

Guidance

Your organisation's approach to security governance needs to be an appropriate fit for your organisation. Good security governance is integrated with your business's usual decision making structures and processes.

Decisions about risk can be made at all levels of your organisation when delegated effectively to people with the right security, business and technical knowledge, skills and experience. Clear lines of communication are also necessary.

Contributing Outcomes

A1.a Board Direction

Not achieved - At least one of the following statements is true:

Achieved - All the following statements are true:

A1.b Roles and Responsibilities

Not achieved - At least one of the following statements is true:

Achieved - All the following statements are true:

A1.c Decision-making

Not achieved - At least one of the following statements is true:

Achieved - All the following statements are true:

Principle A2 Risk Management

The organisation takes appropriate steps to identify, assess and understand security risks to network and information systems supporting the operation of essential functions. This includes an overall organisational approach to risk management.

Description

error determining description

Guidance

Our Risk Management guidance aims to help you to choose an approach that's right for your organisation. Organisations responsible for essential functions are likely to benefit from a combination of a system-based approach , which looks at the interactions between components of the function, and a component-driven analysis , which considers the threats, vulnerabilities, and impacts relevant to particular critical components.

Your organisation should choose a method or framework for managing risk that fits with the organisation's business and technology needs.

Whichever approach you choose, the scope of your programme must include all systems relevant to the operation of essential functions. Simply following the minimum requirements of a standard or applying blanket controls across the organisation is unlikely to adequately manage risks to critical systems.

Where industrial control and automation systems are in scope of the essential function, you should keep in mind that controls suitable for managing risks on the corporate IT network may be inappropriate or damaging in an operational technology environment. These systems will likely require a more tailored approach, and some frameworks and standards address specific concerns relating to such systems.

Cyber threats continue to evolve and develop, putting each organisation’s operational continuity and services at significant risk. By identifying and understanding cyber threats, and the steps a threat actor may take to compromise systems supporting essential functions, an organisation can implement effective security measures to counter malicious attacks and breaches. Various methods can be used to better understand threat which are discussed in our Risk Management guidance .

Ultimately, a detailed understanding of current cyber threats helps organisations to mitigate risks, ensuring the security and resilience of network and information systems in an increasingly hostile world.

Various means are available to gain confidence in the effectiveness of the security of technologies, processes and people. The NCSC Risk Management guidance discusses how to gain and maintain assurance in your risk treatments.

The NCSC assurance guidance provides some examples that may be useful to understand cyber security confidence in your organisation and there are some specific technical NCSC guides:

The NCSC Penetration guidance will help you understand the proper use and commissioning of penetration tests to gain assurance in the security of an IT system.

Our Cloud Security collection provides guidance on managing the risks involved with using cloud services, and some of the principles and guidance are more broadly applicable. The cloud guidance for having confidence in cyber security provides principles that are useful for assuring cyber security of essential functions. The collection will be of particular interest if your organisation hosts any part of your essential function infrastructure on a cloud service.

The NCSC Penetration guidance will help you understand the proper use and commissioning of penetration tests to gain assurance in the security of an IT system.

Contributing Outcomes

A2.a Risk Management Process

Not achieved - At least one of the following statements is true:

Partially achieved - All the following statements are true:

Achieved - All the following statements are true:

A2.b Understanding Threat

Not achieved - At least one of the following statements is true:

Partially achieved - All the following statements are true:

Achieved - All the following statements are true:

A2.c Assurance

Not achieved - At least one of the following statements is true:

Achieved - All the following statements are true:

Principle A3 Asset Management

Everything required to deliver, maintain or support networks and information systems necessary for the operation of essential functions is determined and understood. This includes data, people and systems, as well as any supporting infrastructure (such as power or cooling).

Description

error determining description

Guidance

Whichever risk management method your organisation uses, asset management will play a key role as you cannot effectively manage risks without understanding what assets are part of the essential function. Your asset management regime should consider all relevant assets, and dependencies between them. Dependencies may be identified between assets under your organisation's control (including IT and OT domains), elements of the supply chain (including power), and key staff who are critical to operations. Assets in an operational technology environment may need a more tailored approach than the corporate IT assets.

For asset management to be effective, up to date knowledge of your assets must be maintained throughout their lifecycle.

Asset management is part of an ISO 27001 Information Security Management System (ISMS), but management of critical assets may require a tailored approach.

If your organisation is using an ISMS as a tool for compliance with cyber regulation, you must ensure the scope includes all systems relevant to the operation of the essential function covered by the regulation. Asset management is a key part of an ISMS, although critical services may need more attention than the minimum requirements of the standard.

This standard aligns with ISO 27001 and can be used in conjunction with it or independent of it. It outlines requirements for a generic asset management system. An organisation following this standard as a tool for compliance with cyber regulation must ensure the scope encompasses all the relevant systems. The standard covers needs and expectations of stakeholders, which must include any requirements from regulators.

ITIL is an IT service management framework that outlines best practices for delivering IT services. It  recommends a staged approach to IT Asset Management (ITAM). You may find this useful for improving management of your IT assets, but must keep in mind that there may be assets and dependencies beyond the corporate IT domain as outlined above.

Asset management is part of an ISO 27001 Information Security Management System (ISMS), but management of critical assets may require a tailored approach.

If your organisation is using an ISMS as a tool for compliance with cyber regulation, you must ensure the scope includes all systems relevant to the operation of the essential function covered by the regulation. Asset management is a key part of an ISMS, although critical services may need more attention than the minimum requirements of the standard.

Contributing Outcomes

A3.a Asset Management

Not achieved - At least one of the following statements is true:

Achieved - All the following statements are true:

Principle A4 Supply Chain

The organisation understands and manages security risks to networks and information systems supporting the operation of essential functions that arise as a result of dependencies on suppliers. This includes ensuring that appropriate measures are employed where third party services are used.

Description

error determining description

Guidance

Organisations responsible for essential functions need to ensure that when third party suppliers are used, all relevant security requirements are met. This means that a number of specific supply chain related security considerations should be addressed where relevant to the provision of the essential function. This might include:

Ensuring the protection of data shared with a third party. This includes protecting data from actions such as unauthorised access, modification, or deletion that may cause an adverse impact on any essential functions (see Principle B3 ).

Effective specification of the security properties of products or services procured from an external third party, or sourced internally from another part of the organisation, that are important for the protection of the essential function. This should include the security requirements derived from the rest of these Principles.

Ensure that any network connections or data sharing with third parties do not introduce unmanaged vulnerabilities that have the potential to affect the security of the essential function.

Confidence that third party suppliers are trustworthy such that malicious attempts to subvert the security of products or systems that could affect the essential function are managed.

Ensuring the protection of data shared with a third party. This includes protecting data from actions such as unauthorised access, modification, or deletion that may cause an adverse impact on any essential functions (see Principle B3 ).

Contributing Outcomes

A4.a Supply Chain

Not achieved - At least one of the following statements is true:

Partially achieved - All the following statements are true:

Achieved - All the following statements are true:

A4.b Secure Software Development and Support

Not achieved - At least one of the following statements is true:

Partially achieved - All the following statements are true:

Achieved - All the following statements are true:

Principle B1 Service protection policies, processes and procedures

The organisation defines, implements, communicates and enforces appropriate policies, processes and procedures that direct its overall approach to securing systems and data that support the operation of essential functions.

Description

error determining description

Guidance

The policies, processes and procedures needed by an organisation depend upon its function and should integrate with the organisation’s approach to governance and risk management. Organisations responsible for essential functions should have a range of policies, processes and procedures, including:

An organisational security or service protection policy: endorsed by senior management, this high-level policy should include the organisation’s overarching approach to governing security and managing risks, the organisation’s aims and intents for security and what is of key concern.

Supporting policies, processes and procedures: contextual lower-level definitions controlling, directing and communicating organisational security practice.

Compliance policies and processes for sector regulations, standards, etc.: specific policies and processes appropriate to the compliance regime; these may be defined by the regulation, standard, etc. For example, to comply with ISO/IEC 27001, organisations should have in place certain security policies and procedures relevant to what the organisation does, how it does it, and what their ISO/IEC 27001 information security management system covers (see ISO/IEC 27002 for detail).

An organisational security or service protection policy: endorsed by senior management, this high-level policy should include the organisation’s overarching approach to governing security and managing risks, the organisation’s aims and intents for security and what is of key concern.

Contributing Outcomes

B1.a Policy, Process and Procedure Development

Not achieved - At least one of the following statements is true:

Partially achieved - All the following statements are true:

Achieved - All the following statements are true:

B1.b Policy, Process and Procedure Implementation

Not achieved - At least one of the following statements is true:

Partially achieved - All the following statements are true:

Achieved - All the following statements are true:

Principle B2 Identity and Access Control

The organisation understands, documents and manages access to networks and information systems and supporting the operation of essential functions. Users (or automated functions) that can access data or services are appropriately verified, authenticated and authorised.

Description

It is important that the organisation is clear about who (or what in the case of automated functions) has authorisation to interact with the network and information systems supporting an essential function in any way or access associated sensitive data. Access rights granted should be carefully controlled, especially where those rights provide an ability to materially affect the operation of the essential function. Access rights granted should be periodically reviewed and technically removed when no longer required such as when an individual changes role or leaves the organisation.

Users, devices and systems should be appropriately verified, authenticated and authorised before access to data or services is granted. Verification of a user’s identity (they are who they say they are) is a prerequisite for issuing credentials, authentication and access management. For highly privileged access it might be appropriate to include approaches such as multi-factor or hardware authentication.

Unauthorised individuals should be prevented from accessing data or services at all points within the system. This includes system users without the appropriate permissions, unauthorised individuals attempting to interact with any online service or individuals with unauthorised access to user devices (for example if a user device were lost or stolen).

Guidance

The Introduction to identity and access management sets out security fundamentals that operators should consider in designing and managing identity and access management systems. Identity and access control should be robust enough that essential functions are not adversely affected by unauthorised access.

In addition to technical security, organisations should protect physical access to networks and information systems supporting the essential function, to prevent unauthorised access, tampering or data deletion. Some organisations may already have physical security measures in place to comply with non-cyber regulatory frameworks. See NPSA guidance on Control Access for further information.

Contributing Outcomes

B2.a Identity Verification, Authentication and Authorisation

Not achieved - At least one of the following statements is true:

Partially achieved - All the following statements are true:

Achieved - All the following statements are true:

B2.b Device Management

Not achieved - At least one of the following statements is true:

Partially achieved - All the following statements are true:

Achieved - All the following statements are true:

B2.c Privileged User Management

Not achieved - At least one of the following statements is true:

Partially achieved - All of the following statements are true:

Achieved - All of the following statements are true:

B2.d Identity and Access Management (IdAM)

Not achieved - At least one of the following statements is true:

Partially achieved - All of the following statements are true:

Achieved - All of the following statements are true:

Principle B3 Data security

Data stored or transmitted electronically is protected from actions such as unauthorised access, modification, or deletion that may cause an adverse impact on essential functions. Such protection extends to the means by which authorised users, devices and systems access critical data necessary for the operation of essential functions. It also covers information that would assist an attacker, such as design details of networks and information systems.

Description

error determining description

Guidance

Networks and information systems should be designed to protect important data, for example:

protecting the confidentiality of sensitive data by minimising the number of copies of data, the detail these include and by retaining operationally sensitive data on segregated systems (this includes design documentation)

removing functionality that could allow greater access than has been authorised

protecting the integrity of data essential to the operation of the function by providing a read-only copy for non-essential business system consumption

only deploying well-tested cryptographic suites in common use by your chosen software stack

protecting availability through resilience measures such as multiple network paths and tested automatic backup systems

consider suitable means to retain access to essential information in the event of an incident. For example, network diagrams needed for restoration, safety-critical information or essential forecasting data

protecting the confidentiality of sensitive data by minimising the number of copies of data, the detail these include and by retaining operationally sensitive data on segregated systems (this includes design documentation)

Contributing Outcomes

B3.a Understanding Data

Not achieved - At least one of the following statements is true:

Partially achieved - All of the following statements are true:

Achieved - All of the following statements are true:

B3.b Data in Transit

Not achieved - At least one of the following statements is true:

Partially achieved - All the following statements are true:

Achieved - All the following statements are true:

B3.c Stored Data

Not achieved - At least one of the following statements is true:

Partially achieved - All of the following statements are true:

Achieved - All of the following statements are true:

B3.d Mobile Data

Not achieved - At least one of the following statements is true:

Partially achieved - All of the following statements are true:

Achieved - All of the following statements are true:

B3.e Media/Equipment Sanitisation

Not achieved - At least one of the following statements is true:

Partially achieved - All of the following statements are true:

Achieved - All of the following statements are true:

Principle B4 System security

Network and information systems and technology critical for the operation of essential functions are protected from cyber attack. An organisational understanding of risk to essential functions informs the use of robust and reliable protective security measures to effectively limit opportunities for threat actors to compromise networks and systems.

Description

error determining description

Guidance

The majority of cyber security incidents can be traced to common cyber attack vectors. The opportunity for successful attack can be minimised by managing the known vulnerabilities which these attacks exploit. Many opportunities for user error can be reduced by technical means.

Attempts to circumvent the measures described below should be detected by security monitoring . Together with data security and resilience measures , the impact of any attempts to circumvent security on the operation of the essential function should be limited.

Contributing Outcomes

B4.a Secure by Design

Not achieved - At least one of the following statements is true:

Partially achieved - All the following statements are true:

Achieved - All the following statements are true:

B4.b Secure Configuration

Not achieved - At least one of the following statements is true:

Partially achieved - All of the following statements are true:

Achieved - All of the following statements are true:

B4.c Secure Management

Not achieved - At least one of the following statements is true:

Partially achieved - All of the following statements are true:

Achieved - All of the following statements are true:

B4.d Vulnerability Management

Not achieved - At least one of the following statements is true:

Partially achieved - All of the following statements are true:

Achieved - All of the following statements are true:

Principle B5 Resilient networks and systems

The organisation builds resilience against cyber attack and system failure into the design, implementation, operation and management of systems that support the operation of your essential function(s).

Description

error determining description

Guidance

It's important to be prepared to respond to significant disruption by having business continuity and disaster recovery planning in place. This should include a definition of your most critical resources and an understanding of the order of actions needed to restore service(s). Test that these plans work, for example through manually triggering failover testing, carrying out table-top scenario walk-throughs, red-teaming or Cyber adversary simulation testing. You should be ready to adjust the security measures in place in response to changes in risk. For example, if threat intelligence indicates an increased likelihood of your organisation or sector being targeted you may decide to isolate operational networks until the threat has decreased. Alternatively, in the event of public disclosure of an unpatched vulnerability in equipment that you use, with reported use of exploits targeting the vulnerability, you may respond by elevating your protective monitoring, changing your configuration to avoid being susceptible, or taking other mitigating action in the period until a patch is made available and can be deployed.

You should reduce the likelihood of failure or attack by taking all reasonable measures to maintain networks, information systems and necessary technologies in good working order. Exceptions should be appropriately managed.

In the event of an incident, it is more likely that an essential function will be able to continue where the networks and information systems that support it are segregated from other business and external systems. Separation of system architecture, remote access and privileged access are some key principles that can protect more critical systems from external compromise.

Some sectors responsible for the operation of essential functions may apply the industrial automation and control system security standard IEC 62443, which applies a reference model that separates systems into different logical layers. The standard's architecture model segregates equipment into security zones.

Limitations of networks and information systems, or external services or resources, such as network bandwidth, processing capability, or data storage capacity, should be understood and managed with suitable mitigations to avoid disruption through resource overload.

Make appropriate use of diverse technologies, geographic locations and so on, to provide resilience. You should understand and manage external or lower-priority dependencies to ensure that alternative means are suitable for continuation of the essential function.

In the event of an adverse event, you should be able to revert to backups of hardware and data that are known to be functioning and accessible. Organisations should maintain secured offline, potentially off-site, backups of the operational data, equipment configurations, gold builds, etc. needed to recover from an extreme event.

Suitable alternative backups may include paper-based information and manual processes. Other essential backups may include personnel with appropriate knowledge and access to up-to-date documentation. Consider how to make it easy to recover following an incident or compromise.

You should have adequate policies and measures to ensure the physical and environmental security of your network and information systems. This can be achieved through measures such as physical access controls, alarm systems, environmental controls and automated fire systems etc.

When planning physical upgrades or changes to network and information systems (such as moving to new hardware installations, installing new equipment or power supplies), you should take steps to avoid unnecessary or unplanned interruptions to the services that your network and information systems support.

You should also ensure that you have adequate policies to protect supporting utilities such as electricity, fuel, heating, ventilation, and air conditioning. This can be achieved by having alternative sources, such as back-up generators or uninterruptible power supplies, active temperature monitoring, redundant cooling systems etc.

Contributing Outcomes

B5.a Resilience Preparation

Not achieved - Any of the following statements are true:

Partially achieved - All of the following statements are true:

Achieved - All of the following statements are true:

B5.b Design for Resilience

Not achieved - At least one of the following statements is true:

Partially achieved - All of the following statements are true:

Achieved - All of the following statements are true:

B5.c Backups

Not achieved - At least one of the following statements is true:

Partially achieved - All of the following statements are true:

Achieved - All of the following statements are true:

Principle B6 Staff awareness and training

Staff have appropriate awareness, knowledge and skills to carry out their organisational roles effectively in relation to the security of network and information systems supporting the operation of your essential function(s).

Description

error determining description

Guidance

The people who operate and support essential functions should be provided with all they need to carry out their job while supporting the organisation's cyber security. In line with the design of service protection policies and processes , you should apply the same people-focussed approach to staff awareness and training.

Training and awareness activities should provide appropriate cyber security skills for the job role based on an understanding of how people really work with the systems, with ongoing reminders and top-up training to maintain skills.

Using a range of approaches to training and awareness can improve understanding and information retention, from briefings, online courses and blogs to simulated cyber attack. You may achieve the widest uptake of training and awareness by accommodating different learning preferences and using various delivery methods. Organisations may find the GCHQ certified training scheme useful when considering commercial offerings.

Organisations responsible for essential functions should aim to create a positive security culture, where people are aware of their role in maintaining security and actively take part and contribute to improving security. This is particularly important where a technical solution is not possible, so security relies on people making the right cyber security decisions. Developing a positive security culture is likely to take some time, with some changes possibly taking years to become established and is unlikely to be achieved simply through written guidance or training events.

These outcomes are best achieved when organisations actively engage with staff and communicate effectively with them about network and information system security and how it relates to their jobs. This should be more easily achieved where organisations create and promote a long-term security culture vision that is endorsed and supported by senior management, then make incremental, focused changes to address specific business issues. In some cases, particularly where an essential function is safety-related, an organisation may be able to draw on activities supporting positive safety culture to build up the organisation's cyber security culture.

Contributing Outcomes

B6.a Cyber Security Culture

Not achieved - At least one of the following statements is true:

Partially achieved - All the following statements are true:

Achieved - All the following statements are true:

B6.b Cyber Security Training

Not achieved - At least one of the following statements is true:

Partially achieved - All the following statements are true:

Achieved - All the following statements are true:

Principle B6 Staff awareness and training

Staff have appropriate awareness, knowledge and skills to carry out their organisational roles effectively in relation to the security of network and information systems supporting the operation of your essential function(s).

Description

error determining description

Guidance

The people who operate and support essential functions should be provided with all they need to carry out their job while supporting the organisation's cyber security. In line with the design of service protection policies and processes , you should apply the same people-focussed approach to staff awareness and training.

Training and awareness activities should provide appropriate cyber security skills for the job role based on an understanding of how people really work with the systems, with ongoing reminders and top-up training to maintain skills.

Using a range of approaches to training and awareness can improve understanding and information retention, from briefings, online courses and blogs to simulated cyber attack. You may achieve the widest uptake of training and awareness by accommodating different learning preferences and using various delivery methods. Organisations may find the GCHQ certified training scheme useful when considering commercial offerings.

Organisations responsible for essential functions should aim to create a positive security culture, where people are aware of their role in maintaining security and actively take part and contribute to improving security. This is particularly important where a technical solution is not possible, so security relies on people making the right cyber security decisions. Developing a positive security culture is likely to take some time, with some changes possibly taking years to become established and is unlikely to be achieved simply through written guidance or training events.

These outcomes are best achieved when organisations actively engage with staff and communicate effectively with them about network and information system security and how it relates to their jobs. This should be more easily achieved where organisations create and promote a long-term security culture vision that is endorsed and supported by senior management, then make incremental, focused changes to address specific business issues. In some cases, particularly where an essential function is safety-related, an organisation may be able to draw on activities supporting positive safety culture to build up the organisation's cyber security culture.

Contributing Outcomes

B6.a Cyber Security Culture

Not achieved - At least one of the following statements is true:

Partially achieved - All the following statements are true:

Achieved - All the following statements are true:

B6.b Cyber Security Training

Not achieved - At least one of the following statements is true:

Partially achieved - All the following statements are true:

Achieved - All the following statements are true:

Principle C1 Security monitoring

The organisation monitors the security status of network and information systems supporting the operation of essential function(s) in order to detect  security events indicative of a security incident.

Description

error determining description

Guidance

One clear focus of your security monitoring should be the detection of incidents or activity that is likely to have an adverse impact on the network and information systems that support the operation of essential functions. Log data collection, secure storage, analysis tools, understanding your network and information systems that support your essential function(s), threat intelligence and personnel skills should all be used to build an effective security monitoring capability.

An organisation's automated monitoring capability should be able to find threats within their network and information systems by using both signature-based detections and, behavioural and anomaly-based detections.

Examples of signature-based detections are detecting when known command and control traffic is communicating to the internet, or an AV signature is present in a file. Organisations should endeavour to understand what automated detections and alerting do and how best to use them, to ensure they are making the most of the monitoring solution / as well as being as effective as possible.

Organisations should also have the capability to find threats by using behavioural and anomaly-based detections, for example by detecting an abnormally large amount of data being exfiltrated or AV detecting unusual changes to start up registry keys.

Both signature and, anomaly and behaviour-based detections rely on an understanding of indicators of compromise, your network and information systems, user behaviour and threats.

Contributing Outcomes

C1.a Sources and Tools for Logging and Monitoring

Not achieved - At least one of the following statements is true:

Partially achieved - All the following statements are true:

Achieved - All the following statements are true:

C1.b Securing Logs

Not achieved - At least one of the following is true:

Partially achieved - All the following statements are true:

Achieved - All the following statements are true:

C1.c Generating Alerts

Not achieved - At least one of the following is true:

Partially achieved - All the following statements are true:

Achieved - All the following statements are true:

C1.d Triage of Security Alerts

Not achieved - At least one of the following is true:

Partially achieved - All the following statements are true:

Achieved - All the following statements are true:

C1.e Personnel Skills for Monitoring Tools and Detection

Not achieved - At least one of the following is true:

Partially achieved - All the following statements are true:

Achieved - All the following statements are true:

C1.f Understanding User's and System's Behaviour, and Threat Intelligence (within Security Monitoring)

Not achieved - At least one of the following is true:

Partially achieved - All the following statements are true:

Achieved - All the following statements are true:

Principle C1 Security monitoring

The organisation monitors the security status of network and information systems supporting the operation of essential function(s) in order to detect  security events indicative of a security incident.

Description

error determining description

Guidance

One clear focus of your security monitoring should be the detection of incidents or activity that is likely to have an adverse impact on the network and information systems that support the operation of essential functions. Log data collection, secure storage, analysis tools, understanding your network and information systems that support your essential function(s), threat intelligence and personnel skills should all be used to build an effective security monitoring capability.

An organisation's automated monitoring capability should be able to find threats within their network and information systems by using both signature-based detections and, behavioural and anomaly-based detections.

Examples of signature-based detections are detecting when known command and control traffic is communicating to the internet, or an AV signature is present in a file. Organisations should endeavour to understand what automated detections and alerting do and how best to use them, to ensure they are making the most of the monitoring solution / as well as being as effective as possible.

Organisations should also have the capability to find threats by using behavioural and anomaly-based detections, for example by detecting an abnormally large amount of data being exfiltrated or AV detecting unusual changes to start up registry keys.

Both signature and, anomaly and behaviour-based detections rely on an understanding of indicators of compromise, your network and information systems, user behaviour and threats.

Contributing Outcomes

C1.a Sources and Tools for Logging and Monitoring

Not achieved - At least one of the following statements is true:

Partially achieved - All the following statements are true:

Achieved - All the following statements are true:

C1.b Securing Logs

Not achieved - At least one of the following is true:

Partially achieved - All the following statements are true:

Achieved - All the following statements are true:

C1.c Generating Alerts

Not achieved - At least one of the following is true:

Partially achieved - All the following statements are true:

Achieved - All the following statements are true:

C1.d Triage of Security Alerts

Not achieved - At least one of the following is true:

Partially achieved - All the following statements are true:

Achieved - All the following statements are true:

C1.e Personnel Skills for Monitoring Tools and Detection

Not achieved - At least one of the following is true:

Partially achieved - All the following statements are true:

Achieved - All the following statements are true:

C1.f Understanding User's and System's Behaviour, and Threat Intelligence (within Security Monitoring)

Not achieved - At least one of the following is true:

Partially achieved - All the following statements are true:

Achieved - All the following statements are true:

Principle C1 Security monitoring

The organisation monitors the security status of network and information systems supporting the operation of essential function(s) in order to detect  security events indicative of a security incident.

Description

error determining description

Guidance

One clear focus of your security monitoring should be the detection of incidents or activity that is likely to have an adverse impact on the network and information systems that support the operation of essential functions. Log data collection, secure storage, analysis tools, understanding your network and information systems that support your essential function(s), threat intelligence and personnel skills should all be used to build an effective security monitoring capability.

An organisation's automated monitoring capability should be able to find threats within their network and information systems by using both signature-based detections and, behavioural and anomaly-based detections.

Examples of signature-based detections are detecting when known command and control traffic is communicating to the internet, or an AV signature is present in a file. Organisations should endeavour to understand what automated detections and alerting do and how best to use them, to ensure they are making the most of the monitoring solution / as well as being as effective as possible.

Organisations should also have the capability to find threats by using behavioural and anomaly-based detections, for example by detecting an abnormally large amount of data being exfiltrated or AV detecting unusual changes to start up registry keys.

Both signature and, anomaly and behaviour-based detections rely on an understanding of indicators of compromise, your network and information systems, user behaviour and threats.

Contributing Outcomes

C1.a Sources and Tools for Logging and Monitoring

Not achieved - At least one of the following statements is true:

Partially achieved - All the following statements are true:

Achieved - All the following statements are true:

C1.b Securing Logs

Not achieved - At least one of the following is true:

Partially achieved - All the following statements are true:

Achieved - All the following statements are true:

C1.c Generating Alerts

Not achieved - At least one of the following is true:

Partially achieved - All the following statements are true:

Achieved - All the following statements are true:

C1.d Triage of Security Alerts

Not achieved - At least one of the following is true:

Partially achieved - All the following statements are true:

Achieved - All the following statements are true:

C1.e Personnel Skills for Monitoring Tools and Detection

Not achieved - At least one of the following is true:

Partially achieved - All the following statements are true:

Achieved - All the following statements are true:

C1.f Understanding User's and System's Behaviour, and Threat Intelligence (within Security Monitoring)

Not achieved - At least one of the following is true:

Partially achieved - All the following statements are true:

Achieved - All the following statements are true:

Principle C2 Threat Hunting

The organisation proactively seeks to detect, within networks and information systems, adverse activity affecting, or with the potential to affect, the operation of essential functions even when the activity evades standard security prevent/detect solutions (or when standard solutions are not deployable).

Description

error determining description

Guidance

Threat hunting is more difficult than standard security monitoring because it looks beyond the known Indicators of Compromise (IOCs) that can be leveraged by automated detections and alerting covered in C1 Security Monitoring .

The aim is to build on what is known of both past and plausible attacks to hypothesise what intrusions might look like in. Threat hunting requires more experienced knowledge of network and system behaviour and of the general characteristics that an intrusion might exhibit. This sort of proactive monitoring or threat discovery would normally involve:

A good understanding of normal system behaviour (e.g. what software is authorised and how it would normally behave, how user accounts normally access network resources or how network components connect to each other and transfer data).

A good understanding of the ways that different types of threats maybe realised within your environment(s) based on a comprehensive and advanced understanding of threat intelligence.

A good understanding of normal system behaviour (e.g. what software is authorised and how it would normally behave, how user accounts normally access network resources or how network components connect to each other and transfer data).

Contributing Outcomes

C2.a Threat Hunting

Not achieved - At least one of the following statements is true:

Partially achieved - All the following statements are true:

Achieved - All the following statements are true:

Principle C2 Threat Hunting

The organisation proactively seeks to detect, within networks and information systems, adverse activity affecting, or with the potential to affect, the operation of essential functions even when the activity evades standard security prevent/detect solutions (or when standard solutions are not deployable).

Description

error determining description

Guidance

Threat hunting is more difficult than standard security monitoring because it looks beyond the known Indicators of Compromise (IOCs) that can be leveraged by automated detections and alerting covered in C1 Security Monitoring .

The aim is to build on what is known of both past and plausible attacks to hypothesise what intrusions might look like in. Threat hunting requires more experienced knowledge of network and system behaviour and of the general characteristics that an intrusion might exhibit. This sort of proactive monitoring or threat discovery would normally involve:

A good understanding of normal system behaviour (e.g. what software is authorised and how it would normally behave, how user accounts normally access network resources or how network components connect to each other and transfer data).

A good understanding of the ways that different types of threats maybe realised within your environment(s) based on a comprehensive and advanced understanding of threat intelligence.

A good understanding of normal system behaviour (e.g. what software is authorised and how it would normally behave, how user accounts normally access network resources or how network components connect to each other and transfer data).

Contributing Outcomes

C2.a Threat Hunting

Not achieved - At least one of the following statements is true:

Partially achieved - All the following statements are true:

Achieved - All the following statements are true:

Principle D1 Response and recovery planning

There are well-defined and tested incident management processes in place, that aim to ensure continuity of essential function(s) in the event of system or service failure. Mitigation activities designed to contain or limit the impact of compromise are also in place.

Description

error determining description

Guidance

The 10 Steps to Cyber Security: Incident Management has concise guidance, but organisations should use other more detailed guidance as and when appropriate. Other authoritative guidance pieces are referenced below.

In addition to meeting the expectations of 10 Steps to Cyber Security, you should ensure that your organisation's incident response plans are grounded in thorough and comprehensive risk assessments. Response plans should prioritise essential functions along with the assets and systems that are required to ensure their continued effective operation, such as operational technologies, or key datasets.

The business continuity implications of any compromise should also be taken into account and your cyber incident response plans should link to other business response functions. You should form a cyber response team that is capable of implementing the plan, with the appropriate skills, tools and reach into other parts of your organisation, such as security monitoring and business continuity.

In practice, the Incident Response function should interoperate with the security monitoring function. The Incident Response function needn't be a dedicated team and some members may have non-response related roles. Collectively, the team should have knowledge of IT security, IT infrastructure and Business Management, any specialist technologies (e.g. Operational Technologies or datacentres), incident reporting requirements, and communications plans.

Your plan should cover all relevant potential incidents. It should be auditable and testable ( via exercises ) across a range of incident scenarios and should encompass all realistic descriptions of what might constitute an incident and its severity. Your test scenarios should draw on threat intelligence, past incidents, exercises and the ways in which security capabilities (e.g. security monitoring and alerting) would feature in your response options. Your scenarios should also consider incidents that involve suppliers and your wider supply chain e.g. incidents arising through supplier relations or relying on suppliers as part of your response.

These scenarios could include, but is not limited to:

The scenarios should be incorporated into exercises, which should be run to test your ability to respond to incidents that could affect the operation of essential functions. These exercises should reflect past experience, red-teaming/scenario planning, or threat intelligence and should draw heavily on your risk assessment, considering all relevant assets and vulnerabilities, especially where they relate to essential functions.

Exercises should record lessons learned, covering governance, roles and internal communication, quality of network and security monitoring data, containment and recovery strategies, or any other factors relevant to their effectiveness. This should integrate with lessons learned activities (see Principle D2 Lessons Learned ).

Your plans should work seamlessly with other system management and security functions. Changes and improvements to response plans should reflect changes to these functions and vice versa, where appropriate.

Plans should articulate clear governance frameworks and roles with procedures for reporting to relevant internal or external stakeholders, such as regulators and competent authorities.

Your plan should also set out a comprehensive range of containment, eradication and recovery strategies, specifying how and when they should be used.

Your organisation should be able to describe its own state of readiness, using any criteria or expected standards from regulators or competent authorities, or from your internal governance arrangements, where appropriate.

In order to report coherently on incidents when required, your plan should set out reporting thresholds (i.e. what does and does not need to be reported) and standards (i.e. the level of detail that should be reported) and which authorities to report to.

More detailed guidance on developing an incident response plan, and the underlying capability to implement it, can be found in the NIST Computer Security Incident Handling Guide , CREST publications (see references) or ISO/IEC 27035-1 .

Contributing Outcomes

D1.a Response Plan

Not achieved - At least one of the following is true:

Partially Achieved - All the following statements are true:

Achieved - All the following statements are true:

D1.b Response and Recovery Capability

Not Achieved - At least one of the following is true:

Achieved - All the following statements are true:

D1.c Testing and Exercising

Not Achieved - At least one of the following is true:

Achieved - All the following statements are true:

Principle D2 Lessons Learned

When an incident occurs, steps are taken to understand its causes and to ensure remediating action is taken to protect against future incidents.

Description

error determining description

Guidance

You should use the guidance points below to learn lessons and address shortfalls in:

your overall protective security (see Objectives A - C ) and

your incident response plan (see Response and Recovery Planning )

your overall protective security (see Objectives A - C ) and

Contributing Outcomes

D2.a Post Incident Analysis

Not Achieved - At least one of the following statements is true:

Achieved - All the following statements are true:

D2.b Using Incidents to Drive Improvements

Not Achieved - At least one of the following is true:

Achieved - All the following statements are true:

CAF Objective D - Minimising the impact of cyber security incidents

Principles

Principle A1 Governance

The organisation has appropriate management policies, processes and procedures in place to govern its approach to the security of network and information systems.

Description

error determining description

Guidance

Your organisation's approach to security governance needs to be an appropriate fit for your organisation. Good security governance is integrated with your business's usual decision making structures and processes.

Decisions about risk can be made at all levels of your organisation when delegated effectively to people with the right security, business and technical knowledge, skills and experience. Clear lines of communication are also necessary.

Contributing Outcomes

A1.a Board Direction

Not achieved - At least one of the following statements is true:

Achieved - All the following statements are true:

A1.b Roles and Responsibilities

Not achieved - At least one of the following statements is true:

Achieved - All the following statements are true:

A1.c Decision-making

Not achieved - At least one of the following statements is true:

Achieved - All the following statements are true:

Principle A2 Risk Management

The organisation takes appropriate steps to identify, assess and understand security risks to network and information systems supporting the operation of essential functions. This includes an overall organisational approach to risk management.

Description

error determining description

Guidance

Our Risk Management guidance aims to help you to choose an approach that's right for your organisation. Organisations responsible for essential functions are likely to benefit from a combination of a system-based approach , which looks at the interactions between components of the function, and a component-driven analysis , which considers the threats, vulnerabilities, and impacts relevant to particular critical components.

Your organisation should choose a method or framework for managing risk that fits with the organisation's business and technology needs.

Whichever approach you choose, the scope of your programme must include all systems relevant to the operation of essential functions. Simply following the minimum requirements of a standard or applying blanket controls across the organisation is unlikely to adequately manage risks to critical systems.

Where industrial control and automation systems are in scope of the essential function, you should keep in mind that controls suitable for managing risks on the corporate IT network may be inappropriate or damaging in an operational technology environment. These systems will likely require a more tailored approach, and some frameworks and standards address specific concerns relating to such systems.

Cyber threats continue to evolve and develop, putting each organisation’s operational continuity and services at significant risk. By identifying and understanding cyber threats, and the steps a threat actor may take to compromise systems supporting essential functions, an organisation can implement effective security measures to counter malicious attacks and breaches. Various methods can be used to better understand threat which are discussed in our Risk Management guidance .

Ultimately, a detailed understanding of current cyber threats helps organisations to mitigate risks, ensuring the security and resilience of network and information systems in an increasingly hostile world.

Various means are available to gain confidence in the effectiveness of the security of technologies, processes and people. The NCSC Risk Management guidance discusses how to gain and maintain assurance in your risk treatments.

The NCSC assurance guidance provides some examples that may be useful to understand cyber security confidence in your organisation and there are some specific technical NCSC guides:

The NCSC Penetration guidance will help you understand the proper use and commissioning of penetration tests to gain assurance in the security of an IT system.

Our Cloud Security collection provides guidance on managing the risks involved with using cloud services, and some of the principles and guidance are more broadly applicable. The cloud guidance for having confidence in cyber security provides principles that are useful for assuring cyber security of essential functions. The collection will be of particular interest if your organisation hosts any part of your essential function infrastructure on a cloud service.

The NCSC Penetration guidance will help you understand the proper use and commissioning of penetration tests to gain assurance in the security of an IT system.

Contributing Outcomes

A2.a Risk Management Process

Not achieved - At least one of the following statements is true:

Partially achieved - All the following statements are true:

Achieved - All the following statements are true:

A2.b Understanding Threat

Not achieved - At least one of the following statements is true:

Partially achieved - All the following statements are true:

Achieved - All the following statements are true:

A2.c Assurance

Not achieved - At least one of the following statements is true:

Achieved - All the following statements are true:

Principle A3 Asset Management

Everything required to deliver, maintain or support networks and information systems necessary for the operation of essential functions is determined and understood. This includes data, people and systems, as well as any supporting infrastructure (such as power or cooling).

Description

error determining description

Guidance

Whichever risk management method your organisation uses, asset management will play a key role as you cannot effectively manage risks without understanding what assets are part of the essential function. Your asset management regime should consider all relevant assets, and dependencies between them. Dependencies may be identified between assets under your organisation's control (including IT and OT domains), elements of the supply chain (including power), and key staff who are critical to operations. Assets in an operational technology environment may need a more tailored approach than the corporate IT assets.

For asset management to be effective, up to date knowledge of your assets must be maintained throughout their lifecycle.

Asset management is part of an ISO 27001 Information Security Management System (ISMS), but management of critical assets may require a tailored approach.

If your organisation is using an ISMS as a tool for compliance with cyber regulation, you must ensure the scope includes all systems relevant to the operation of the essential function covered by the regulation. Asset management is a key part of an ISMS, although critical services may need more attention than the minimum requirements of the standard.

This standard aligns with ISO 27001 and can be used in conjunction with it or independent of it. It outlines requirements for a generic asset management system. An organisation following this standard as a tool for compliance with cyber regulation must ensure the scope encompasses all the relevant systems. The standard covers needs and expectations of stakeholders, which must include any requirements from regulators.

ITIL is an IT service management framework that outlines best practices for delivering IT services. It  recommends a staged approach to IT Asset Management (ITAM). You may find this useful for improving management of your IT assets, but must keep in mind that there may be assets and dependencies beyond the corporate IT domain as outlined above.

Asset management is part of an ISO 27001 Information Security Management System (ISMS), but management of critical assets may require a tailored approach.

If your organisation is using an ISMS as a tool for compliance with cyber regulation, you must ensure the scope includes all systems relevant to the operation of the essential function covered by the regulation. Asset management is a key part of an ISMS, although critical services may need more attention than the minimum requirements of the standard.

Contributing Outcomes

A3.a Asset Management

Not achieved - At least one of the following statements is true:

Achieved - All the following statements are true:

Principle A4 Supply Chain

The organisation understands and manages security risks to networks and information systems supporting the operation of essential functions that arise as a result of dependencies on suppliers. This includes ensuring that appropriate measures are employed where third party services are used.

Description

error determining description

Guidance

Organisations responsible for essential functions need to ensure that when third party suppliers are used, all relevant security requirements are met. This means that a number of specific supply chain related security considerations should be addressed where relevant to the provision of the essential function. This might include:

Ensuring the protection of data shared with a third party. This includes protecting data from actions such as unauthorised access, modification, or deletion that may cause an adverse impact on any essential functions (see Principle B3 ).

Effective specification of the security properties of products or services procured from an external third party, or sourced internally from another part of the organisation, that are important for the protection of the essential function. This should include the security requirements derived from the rest of these Principles.

Ensure that any network connections or data sharing with third parties do not introduce unmanaged vulnerabilities that have the potential to affect the security of the essential function.

Confidence that third party suppliers are trustworthy such that malicious attempts to subvert the security of products or systems that could affect the essential function are managed.

Ensuring the protection of data shared with a third party. This includes protecting data from actions such as unauthorised access, modification, or deletion that may cause an adverse impact on any essential functions (see Principle B3 ).

Contributing Outcomes

A4.a Supply Chain

Not achieved - At least one of the following statements is true:

Partially achieved - All the following statements are true:

Achieved - All the following statements are true:

A4.b Secure Software Development and Support

Not achieved - At least one of the following statements is true:

Partially achieved - All the following statements are true:

Achieved - All the following statements are true:

Principle B1 Service protection policies, processes and procedures

The organisation defines, implements, communicates and enforces appropriate policies, processes and procedures that direct its overall approach to securing systems and data that support the operation of essential functions.

Description

error determining description

Guidance

The policies, processes and procedures needed by an organisation depend upon its function and should integrate with the organisation’s approach to governance and risk management. Organisations responsible for essential functions should have a range of policies, processes and procedures, including:

An organisational security or service protection policy: endorsed by senior management, this high-level policy should include the organisation’s overarching approach to governing security and managing risks, the organisation’s aims and intents for security and what is of key concern.

Supporting policies, processes and procedures: contextual lower-level definitions controlling, directing and communicating organisational security practice.

Compliance policies and processes for sector regulations, standards, etc.: specific policies and processes appropriate to the compliance regime; these may be defined by the regulation, standard, etc. For example, to comply with ISO/IEC 27001, organisations should have in place certain security policies and procedures relevant to what the organisation does, how it does it, and what their ISO/IEC 27001 information security management system covers (see ISO/IEC 27002 for detail).

An organisational security or service protection policy: endorsed by senior management, this high-level policy should include the organisation’s overarching approach to governing security and managing risks, the organisation’s aims and intents for security and what is of key concern.

Contributing Outcomes

B1.a Policy, Process and Procedure Development

Not achieved - At least one of the following statements is true:

Partially achieved - All the following statements are true:

Achieved - All the following statements are true:

B1.b Policy, Process and Procedure Implementation

Not achieved - At least one of the following statements is true:

Partially achieved - All the following statements are true:

Achieved - All the following statements are true:

Principle B2 Identity and Access Control

The organisation understands, documents and manages access to networks and information systems and supporting the operation of essential functions. Users (or automated functions) that can access data or services are appropriately verified, authenticated and authorised.

Description

It is important that the organisation is clear about who (or what in the case of automated functions) has authorisation to interact with the network and information systems supporting an essential function in any way or access associated sensitive data. Access rights granted should be carefully controlled, especially where those rights provide an ability to materially affect the operation of the essential function. Access rights granted should be periodically reviewed and technically removed when no longer required such as when an individual changes role or leaves the organisation.

Users, devices and systems should be appropriately verified, authenticated and authorised before access to data or services is granted. Verification of a user’s identity (they are who they say they are) is a prerequisite for issuing credentials, authentication and access management. For highly privileged access it might be appropriate to include approaches such as multi-factor or hardware authentication.

Unauthorised individuals should be prevented from accessing data or services at all points within the system. This includes system users without the appropriate permissions, unauthorised individuals attempting to interact with any online service or individuals with unauthorised access to user devices (for example if a user device were lost or stolen).

Guidance

The Introduction to identity and access management sets out security fundamentals that operators should consider in designing and managing identity and access management systems. Identity and access control should be robust enough that essential functions are not adversely affected by unauthorised access.

In addition to technical security, organisations should protect physical access to networks and information systems supporting the essential function, to prevent unauthorised access, tampering or data deletion. Some organisations may already have physical security measures in place to comply with non-cyber regulatory frameworks. See NPSA guidance on Control Access for further information.

Contributing Outcomes

B2.a Identity Verification, Authentication and Authorisation

Not achieved - At least one of the following statements is true:

Partially achieved - All the following statements are true:

Achieved - All the following statements are true:

B2.b Device Management

Not achieved - At least one of the following statements is true:

Partially achieved - All the following statements are true:

Achieved - All the following statements are true:

B2.c Privileged User Management

Not achieved - At least one of the following statements is true:

Partially achieved - All of the following statements are true:

Achieved - All of the following statements are true:

B2.d Identity and Access Management (IdAM)

Not achieved - At least one of the following statements is true:

Partially achieved - All of the following statements are true:

Achieved - All of the following statements are true:

Principle B3 Data security

Data stored or transmitted electronically is protected from actions such as unauthorised access, modification, or deletion that may cause an adverse impact on essential functions. Such protection extends to the means by which authorised users, devices and systems access critical data necessary for the operation of essential functions. It also covers information that would assist an attacker, such as design details of networks and information systems.

Description

error determining description

Guidance

Networks and information systems should be designed to protect important data, for example:

protecting the confidentiality of sensitive data by minimising the number of copies of data, the detail these include and by retaining operationally sensitive data on segregated systems (this includes design documentation)

removing functionality that could allow greater access than has been authorised

protecting the integrity of data essential to the operation of the function by providing a read-only copy for non-essential business system consumption

only deploying well-tested cryptographic suites in common use by your chosen software stack

protecting availability through resilience measures such as multiple network paths and tested automatic backup systems

consider suitable means to retain access to essential information in the event of an incident. For example, network diagrams needed for restoration, safety-critical information or essential forecasting data

protecting the confidentiality of sensitive data by minimising the number of copies of data, the detail these include and by retaining operationally sensitive data on segregated systems (this includes design documentation)

Contributing Outcomes

B3.a Understanding Data

Not achieved - At least one of the following statements is true:

Partially achieved - All of the following statements are true:

Achieved - All of the following statements are true:

B3.b Data in Transit

Not achieved - At least one of the following statements is true:

Partially achieved - All the following statements are true:

Achieved - All the following statements are true:

B3.c Stored Data

Not achieved - At least one of the following statements is true:

Partially achieved - All of the following statements are true:

Achieved - All of the following statements are true:

B3.d Mobile Data

Not achieved - At least one of the following statements is true:

Partially achieved - All of the following statements are true:

Achieved - All of the following statements are true:

B3.e Media/Equipment Sanitisation

Not achieved - At least one of the following statements is true:

Partially achieved - All of the following statements are true:

Achieved - All of the following statements are true:

Principle B4 System security

Network and information systems and technology critical for the operation of essential functions are protected from cyber attack. An organisational understanding of risk to essential functions informs the use of robust and reliable protective security measures to effectively limit opportunities for threat actors to compromise networks and systems.

Description

error determining description

Guidance

The majority of cyber security incidents can be traced to common cyber attack vectors. The opportunity for successful attack can be minimised by managing the known vulnerabilities which these attacks exploit. Many opportunities for user error can be reduced by technical means.

Attempts to circumvent the measures described below should be detected by security monitoring . Together with data security and resilience measures , the impact of any attempts to circumvent security on the operation of the essential function should be limited.

Contributing Outcomes

B4.a Secure by Design

Not achieved - At least one of the following statements is true:

Partially achieved - All the following statements are true:

Achieved - All the following statements are true:

B4.b Secure Configuration

Not achieved - At least one of the following statements is true:

Partially achieved - All of the following statements are true:

Achieved - All of the following statements are true:

B4.c Secure Management

Not achieved - At least one of the following statements is true:

Partially achieved - All of the following statements are true:

Achieved - All of the following statements are true:

B4.d Vulnerability Management

Not achieved - At least one of the following statements is true:

Partially achieved - All of the following statements are true:

Achieved - All of the following statements are true:

Principle B5 Resilient networks and systems

The organisation builds resilience against cyber attack and system failure into the design, implementation, operation and management of systems that support the operation of your essential function(s).

Description

error determining description

Guidance

It's important to be prepared to respond to significant disruption by having business continuity and disaster recovery planning in place. This should include a definition of your most critical resources and an understanding of the order of actions needed to restore service(s). Test that these plans work, for example through manually triggering failover testing, carrying out table-top scenario walk-throughs, red-teaming or Cyber adversary simulation testing. You should be ready to adjust the security measures in place in response to changes in risk. For example, if threat intelligence indicates an increased likelihood of your organisation or sector being targeted you may decide to isolate operational networks until the threat has decreased. Alternatively, in the event of public disclosure of an unpatched vulnerability in equipment that you use, with reported use of exploits targeting the vulnerability, you may respond by elevating your protective monitoring, changing your configuration to avoid being susceptible, or taking other mitigating action in the period until a patch is made available and can be deployed.

You should reduce the likelihood of failure or attack by taking all reasonable measures to maintain networks, information systems and necessary technologies in good working order. Exceptions should be appropriately managed.

In the event of an incident, it is more likely that an essential function will be able to continue where the networks and information systems that support it are segregated from other business and external systems. Separation of system architecture, remote access and privileged access are some key principles that can protect more critical systems from external compromise.

Some sectors responsible for the operation of essential functions may apply the industrial automation and control system security standard IEC 62443, which applies a reference model that separates systems into different logical layers. The standard's architecture model segregates equipment into security zones.

Limitations of networks and information systems, or external services or resources, such as network bandwidth, processing capability, or data storage capacity, should be understood and managed with suitable mitigations to avoid disruption through resource overload.

Make appropriate use of diverse technologies, geographic locations and so on, to provide resilience. You should understand and manage external or lower-priority dependencies to ensure that alternative means are suitable for continuation of the essential function.

In the event of an adverse event, you should be able to revert to backups of hardware and data that are known to be functioning and accessible. Organisations should maintain secured offline, potentially off-site, backups of the operational data, equipment configurations, gold builds, etc. needed to recover from an extreme event.

Suitable alternative backups may include paper-based information and manual processes. Other essential backups may include personnel with appropriate knowledge and access to up-to-date documentation. Consider how to make it easy to recover following an incident or compromise.

You should have adequate policies and measures to ensure the physical and environmental security of your network and information systems. This can be achieved through measures such as physical access controls, alarm systems, environmental controls and automated fire systems etc.

When planning physical upgrades or changes to network and information systems (such as moving to new hardware installations, installing new equipment or power supplies), you should take steps to avoid unnecessary or unplanned interruptions to the services that your network and information systems support.

You should also ensure that you have adequate policies to protect supporting utilities such as electricity, fuel, heating, ventilation, and air conditioning. This can be achieved by having alternative sources, such as back-up generators or uninterruptible power supplies, active temperature monitoring, redundant cooling systems etc.

Contributing Outcomes

B5.a Resilience Preparation

Not achieved - Any of the following statements are true:

Partially achieved - All of the following statements are true:

Achieved - All of the following statements are true:

B5.b Design for Resilience

Not achieved - At least one of the following statements is true:

Partially achieved - All of the following statements are true:

Achieved - All of the following statements are true:

B5.c Backups

Not achieved - At least one of the following statements is true:

Partially achieved - All of the following statements are true:

Achieved - All of the following statements are true:

Principle B6 Staff awareness and training

Staff have appropriate awareness, knowledge and skills to carry out their organisational roles effectively in relation to the security of network and information systems supporting the operation of your essential function(s).

Description

error determining description

Guidance

The people who operate and support essential functions should be provided with all they need to carry out their job while supporting the organisation's cyber security. In line with the design of service protection policies and processes , you should apply the same people-focussed approach to staff awareness and training.

Training and awareness activities should provide appropriate cyber security skills for the job role based on an understanding of how people really work with the systems, with ongoing reminders and top-up training to maintain skills.

Using a range of approaches to training and awareness can improve understanding and information retention, from briefings, online courses and blogs to simulated cyber attack. You may achieve the widest uptake of training and awareness by accommodating different learning preferences and using various delivery methods. Organisations may find the GCHQ certified training scheme useful when considering commercial offerings.

Organisations responsible for essential functions should aim to create a positive security culture, where people are aware of their role in maintaining security and actively take part and contribute to improving security. This is particularly important where a technical solution is not possible, so security relies on people making the right cyber security decisions. Developing a positive security culture is likely to take some time, with some changes possibly taking years to become established and is unlikely to be achieved simply through written guidance or training events.

These outcomes are best achieved when organisations actively engage with staff and communicate effectively with them about network and information system security and how it relates to their jobs. This should be more easily achieved where organisations create and promote a long-term security culture vision that is endorsed and supported by senior management, then make incremental, focused changes to address specific business issues. In some cases, particularly where an essential function is safety-related, an organisation may be able to draw on activities supporting positive safety culture to build up the organisation's cyber security culture.

Contributing Outcomes

B6.a Cyber Security Culture

Not achieved - At least one of the following statements is true:

Partially achieved - All the following statements are true:

Achieved - All the following statements are true:

B6.b Cyber Security Training

Not achieved - At least one of the following statements is true:

Partially achieved - All the following statements are true:

Achieved - All the following statements are true:

Principle C1 Security monitoring

The organisation monitors the security status of network and information systems supporting the operation of essential function(s) in order to detect  security events indicative of a security incident.

Description

error determining description

Guidance

One clear focus of your security monitoring should be the detection of incidents or activity that is likely to have an adverse impact on the network and information systems that support the operation of essential functions. Log data collection, secure storage, analysis tools, understanding your network and information systems that support your essential function(s), threat intelligence and personnel skills should all be used to build an effective security monitoring capability.

An organisation's automated monitoring capability should be able to find threats within their network and information systems by using both signature-based detections and, behavioural and anomaly-based detections.

Examples of signature-based detections are detecting when known command and control traffic is communicating to the internet, or an AV signature is present in a file. Organisations should endeavour to understand what automated detections and alerting do and how best to use them, to ensure they are making the most of the monitoring solution / as well as being as effective as possible.

Organisations should also have the capability to find threats by using behavioural and anomaly-based detections, for example by detecting an abnormally large amount of data being exfiltrated or AV detecting unusual changes to start up registry keys.

Both signature and, anomaly and behaviour-based detections rely on an understanding of indicators of compromise, your network and information systems, user behaviour and threats.

Contributing Outcomes

C1.a Sources and Tools for Logging and Monitoring

Not achieved - At least one of the following statements is true:

Partially achieved - All the following statements are true:

Achieved - All the following statements are true:

C1.b Securing Logs

Not achieved - At least one of the following is true:

Partially achieved - All the following statements are true:

Achieved - All the following statements are true:

C1.c Generating Alerts

Not achieved - At least one of the following is true:

Partially achieved - All the following statements are true:

Achieved - All the following statements are true:

C1.d Triage of Security Alerts

Not achieved - At least one of the following is true:

Partially achieved - All the following statements are true:

Achieved - All the following statements are true:

C1.e Personnel Skills for Monitoring Tools and Detection

Not achieved - At least one of the following is true:

Partially achieved - All the following statements are true:

Achieved - All the following statements are true:

C1.f Understanding User's and System's Behaviour, and Threat Intelligence (within Security Monitoring)

Not achieved - At least one of the following is true:

Partially achieved - All the following statements are true:

Achieved - All the following statements are true:

Principle C2 Threat Hunting

The organisation proactively seeks to detect, within networks and information systems, adverse activity affecting, or with the potential to affect, the operation of essential functions even when the activity evades standard security prevent/detect solutions (or when standard solutions are not deployable).

Description

error determining description

Guidance

Threat hunting is more difficult than standard security monitoring because it looks beyond the known Indicators of Compromise (IOCs) that can be leveraged by automated detections and alerting covered in C1 Security Monitoring .

The aim is to build on what is known of both past and plausible attacks to hypothesise what intrusions might look like in. Threat hunting requires more experienced knowledge of network and system behaviour and of the general characteristics that an intrusion might exhibit. This sort of proactive monitoring or threat discovery would normally involve:

A good understanding of normal system behaviour (e.g. what software is authorised and how it would normally behave, how user accounts normally access network resources or how network components connect to each other and transfer data).

A good understanding of the ways that different types of threats maybe realised within your environment(s) based on a comprehensive and advanced understanding of threat intelligence.

A good understanding of normal system behaviour (e.g. what software is authorised and how it would normally behave, how user accounts normally access network resources or how network components connect to each other and transfer data).

Contributing Outcomes

C2.a Threat Hunting

Not achieved - At least one of the following statements is true:

Partially achieved - All the following statements are true:

Achieved - All the following statements are true:

Principle C2 Threat Hunting

The organisation proactively seeks to detect, within networks and information systems, adverse activity affecting, or with the potential to affect, the operation of essential functions even when the activity evades standard security prevent/detect solutions (or when standard solutions are not deployable).

Description

error determining description

Guidance

Threat hunting is more difficult than standard security monitoring because it looks beyond the known Indicators of Compromise (IOCs) that can be leveraged by automated detections and alerting covered in C1 Security Monitoring .

The aim is to build on what is known of both past and plausible attacks to hypothesise what intrusions might look like in. Threat hunting requires more experienced knowledge of network and system behaviour and of the general characteristics that an intrusion might exhibit. This sort of proactive monitoring or threat discovery would normally involve:

A good understanding of normal system behaviour (e.g. what software is authorised and how it would normally behave, how user accounts normally access network resources or how network components connect to each other and transfer data).

A good understanding of the ways that different types of threats maybe realised within your environment(s) based on a comprehensive and advanced understanding of threat intelligence.

A good understanding of normal system behaviour (e.g. what software is authorised and how it would normally behave, how user accounts normally access network resources or how network components connect to each other and transfer data).

Contributing Outcomes

C2.a Threat Hunting

Not achieved - At least one of the following statements is true:

Partially achieved - All the following statements are true:

Achieved - All the following statements are true:

Principle D1 Response and recovery planning

There are well-defined and tested incident management processes in place, that aim to ensure continuity of essential function(s) in the event of system or service failure. Mitigation activities designed to contain or limit the impact of compromise are also in place.

Description

error determining description

Guidance

The 10 Steps to Cyber Security: Incident Management has concise guidance, but organisations should use other more detailed guidance as and when appropriate. Other authoritative guidance pieces are referenced below.

In addition to meeting the expectations of 10 Steps to Cyber Security, you should ensure that your organisation's incident response plans are grounded in thorough and comprehensive risk assessments. Response plans should prioritise essential functions along with the assets and systems that are required to ensure their continued effective operation, such as operational technologies, or key datasets.

The business continuity implications of any compromise should also be taken into account and your cyber incident response plans should link to other business response functions. You should form a cyber response team that is capable of implementing the plan, with the appropriate skills, tools and reach into other parts of your organisation, such as security monitoring and business continuity.

In practice, the Incident Response function should interoperate with the security monitoring function. The Incident Response function needn't be a dedicated team and some members may have non-response related roles. Collectively, the team should have knowledge of IT security, IT infrastructure and Business Management, any specialist technologies (e.g. Operational Technologies or datacentres), incident reporting requirements, and communications plans.

Your plan should cover all relevant potential incidents. It should be auditable and testable ( via exercises ) across a range of incident scenarios and should encompass all realistic descriptions of what might constitute an incident and its severity. Your test scenarios should draw on threat intelligence, past incidents, exercises and the ways in which security capabilities (e.g. security monitoring and alerting) would feature in your response options. Your scenarios should also consider incidents that involve suppliers and your wider supply chain e.g. incidents arising through supplier relations or relying on suppliers as part of your response.

These scenarios could include, but is not limited to:

The scenarios should be incorporated into exercises, which should be run to test your ability to respond to incidents that could affect the operation of essential functions. These exercises should reflect past experience, red-teaming/scenario planning, or threat intelligence and should draw heavily on your risk assessment, considering all relevant assets and vulnerabilities, especially where they relate to essential functions.

Exercises should record lessons learned, covering governance, roles and internal communication, quality of network and security monitoring data, containment and recovery strategies, or any other factors relevant to their effectiveness. This should integrate with lessons learned activities (see Principle D2 Lessons Learned ).

Your plans should work seamlessly with other system management and security functions. Changes and improvements to response plans should reflect changes to these functions and vice versa, where appropriate.

Plans should articulate clear governance frameworks and roles with procedures for reporting to relevant internal or external stakeholders, such as regulators and competent authorities.

Your plan should also set out a comprehensive range of containment, eradication and recovery strategies, specifying how and when they should be used.

Your organisation should be able to describe its own state of readiness, using any criteria or expected standards from regulators or competent authorities, or from your internal governance arrangements, where appropriate.

In order to report coherently on incidents when required, your plan should set out reporting thresholds (i.e. what does and does not need to be reported) and standards (i.e. the level of detail that should be reported) and which authorities to report to.

More detailed guidance on developing an incident response plan, and the underlying capability to implement it, can be found in the NIST Computer Security Incident Handling Guide , CREST publications (see references) or ISO/IEC 27035-1 .

Contributing Outcomes

D1.a Response Plan

Not achieved - At least one of the following is true:

Partially Achieved - All the following statements are true:

Achieved - All the following statements are true:

D1.b Response and Recovery Capability

Not Achieved - At least one of the following is true:

Achieved - All the following statements are true:

D1.c Testing and Exercising

Not Achieved - At least one of the following is true:

Achieved - All the following statements are true:

Principle D1 Response and recovery planning

There are well-defined and tested incident management processes in place, that aim to ensure continuity of essential function(s) in the event of system or service failure. Mitigation activities designed to contain or limit the impact of compromise are also in place.

Description

error determining description

Guidance

The 10 Steps to Cyber Security: Incident Management has concise guidance, but organisations should use other more detailed guidance as and when appropriate. Other authoritative guidance pieces are referenced below.

In addition to meeting the expectations of 10 Steps to Cyber Security, you should ensure that your organisation's incident response plans are grounded in thorough and comprehensive risk assessments. Response plans should prioritise essential functions along with the assets and systems that are required to ensure their continued effective operation, such as operational technologies, or key datasets.

The business continuity implications of any compromise should also be taken into account and your cyber incident response plans should link to other business response functions. You should form a cyber response team that is capable of implementing the plan, with the appropriate skills, tools and reach into other parts of your organisation, such as security monitoring and business continuity.

In practice, the Incident Response function should interoperate with the security monitoring function. The Incident Response function needn't be a dedicated team and some members may have non-response related roles. Collectively, the team should have knowledge of IT security, IT infrastructure and Business Management, any specialist technologies (e.g. Operational Technologies or datacentres), incident reporting requirements, and communications plans.

Your plan should cover all relevant potential incidents. It should be auditable and testable ( via exercises ) across a range of incident scenarios and should encompass all realistic descriptions of what might constitute an incident and its severity. Your test scenarios should draw on threat intelligence, past incidents, exercises and the ways in which security capabilities (e.g. security monitoring and alerting) would feature in your response options. Your scenarios should also consider incidents that involve suppliers and your wider supply chain e.g. incidents arising through supplier relations or relying on suppliers as part of your response.

These scenarios could include, but is not limited to:

The scenarios should be incorporated into exercises, which should be run to test your ability to respond to incidents that could affect the operation of essential functions. These exercises should reflect past experience, red-teaming/scenario planning, or threat intelligence and should draw heavily on your risk assessment, considering all relevant assets and vulnerabilities, especially where they relate to essential functions.

Exercises should record lessons learned, covering governance, roles and internal communication, quality of network and security monitoring data, containment and recovery strategies, or any other factors relevant to their effectiveness. This should integrate with lessons learned activities (see Principle D2 Lessons Learned ).

Your plans should work seamlessly with other system management and security functions. Changes and improvements to response plans should reflect changes to these functions and vice versa, where appropriate.

Plans should articulate clear governance frameworks and roles with procedures for reporting to relevant internal or external stakeholders, such as regulators and competent authorities.

Your plan should also set out a comprehensive range of containment, eradication and recovery strategies, specifying how and when they should be used.

Your organisation should be able to describe its own state of readiness, using any criteria or expected standards from regulators or competent authorities, or from your internal governance arrangements, where appropriate.

In order to report coherently on incidents when required, your plan should set out reporting thresholds (i.e. what does and does not need to be reported) and standards (i.e. the level of detail that should be reported) and which authorities to report to.

More detailed guidance on developing an incident response plan, and the underlying capability to implement it, can be found in the NIST Computer Security Incident Handling Guide , CREST publications (see references) or ISO/IEC 27035-1 .

Contributing Outcomes

D1.a Response Plan

Not achieved - At least one of the following is true:

Partially Achieved - All the following statements are true:

Achieved - All the following statements are true:

D1.b Response and Recovery Capability

Not Achieved - At least one of the following is true:

Achieved - All the following statements are true:

D1.c Testing and Exercising

Not Achieved - At least one of the following is true:

Achieved - All the following statements are true:

Principle D1 Response and recovery planning

There are well-defined and tested incident management processes in place, that aim to ensure continuity of essential function(s) in the event of system or service failure. Mitigation activities designed to contain or limit the impact of compromise are also in place.

Description

error determining description

Guidance

The 10 Steps to Cyber Security: Incident Management has concise guidance, but organisations should use other more detailed guidance as and when appropriate. Other authoritative guidance pieces are referenced below.

In addition to meeting the expectations of 10 Steps to Cyber Security, you should ensure that your organisation's incident response plans are grounded in thorough and comprehensive risk assessments. Response plans should prioritise essential functions along with the assets and systems that are required to ensure their continued effective operation, such as operational technologies, or key datasets.

The business continuity implications of any compromise should also be taken into account and your cyber incident response plans should link to other business response functions. You should form a cyber response team that is capable of implementing the plan, with the appropriate skills, tools and reach into other parts of your organisation, such as security monitoring and business continuity.

In practice, the Incident Response function should interoperate with the security monitoring function. The Incident Response function needn't be a dedicated team and some members may have non-response related roles. Collectively, the team should have knowledge of IT security, IT infrastructure and Business Management, any specialist technologies (e.g. Operational Technologies or datacentres), incident reporting requirements, and communications plans.

Your plan should cover all relevant potential incidents. It should be auditable and testable ( via exercises ) across a range of incident scenarios and should encompass all realistic descriptions of what might constitute an incident and its severity. Your test scenarios should draw on threat intelligence, past incidents, exercises and the ways in which security capabilities (e.g. security monitoring and alerting) would feature in your response options. Your scenarios should also consider incidents that involve suppliers and your wider supply chain e.g. incidents arising through supplier relations or relying on suppliers as part of your response.

These scenarios could include, but is not limited to:

The scenarios should be incorporated into exercises, which should be run to test your ability to respond to incidents that could affect the operation of essential functions. These exercises should reflect past experience, red-teaming/scenario planning, or threat intelligence and should draw heavily on your risk assessment, considering all relevant assets and vulnerabilities, especially where they relate to essential functions.

Exercises should record lessons learned, covering governance, roles and internal communication, quality of network and security monitoring data, containment and recovery strategies, or any other factors relevant to their effectiveness. This should integrate with lessons learned activities (see Principle D2 Lessons Learned ).

Your plans should work seamlessly with other system management and security functions. Changes and improvements to response plans should reflect changes to these functions and vice versa, where appropriate.

Plans should articulate clear governance frameworks and roles with procedures for reporting to relevant internal or external stakeholders, such as regulators and competent authorities.

Your plan should also set out a comprehensive range of containment, eradication and recovery strategies, specifying how and when they should be used.

Your organisation should be able to describe its own state of readiness, using any criteria or expected standards from regulators or competent authorities, or from your internal governance arrangements, where appropriate.

In order to report coherently on incidents when required, your plan should set out reporting thresholds (i.e. what does and does not need to be reported) and standards (i.e. the level of detail that should be reported) and which authorities to report to.

More detailed guidance on developing an incident response plan, and the underlying capability to implement it, can be found in the NIST Computer Security Incident Handling Guide , CREST publications (see references) or ISO/IEC 27035-1 .

Contributing Outcomes

D1.a Response Plan

Not achieved - At least one of the following is true:

Partially Achieved - All the following statements are true:

Achieved - All the following statements are true:

D1.b Response and Recovery Capability

Not Achieved - At least one of the following is true:

Achieved - All the following statements are true:

D1.c Testing and Exercising

Not Achieved - At least one of the following is true:

Achieved - All the following statements are true:

Principle D2 Lessons Learned

When an incident occurs, steps are taken to understand its causes and to ensure remediating action is taken to protect against future incidents.

Description

error determining description

Guidance

You should use the guidance points below to learn lessons and address shortfalls in:

your overall protective security (see Objectives A - C ) and

your incident response plan (see Response and Recovery Planning )

your overall protective security (see Objectives A - C ) and

Contributing Outcomes

D2.a Post Incident Analysis

Not Achieved - At least one of the following statements is true:

Achieved - All the following statements are true:

D2.b Using Incidents to Drive Improvements

Not Achieved - At least one of the following is true:

Achieved - All the following statements are true:

Principle D2 Lessons Learned

When an incident occurs, steps are taken to understand its causes and to ensure remediating action is taken to protect against future incidents.

Description

error determining description

Guidance

You should use the guidance points below to learn lessons and address shortfalls in:

your overall protective security (see Objectives A - C ) and

your incident response plan (see Response and Recovery Planning )

your overall protective security (see Objectives A - C ) and

Contributing Outcomes

D2.a Post Incident Analysis

Not Achieved - At least one of the following statements is true:

Achieved - All the following statements are true:

D2.b Using Incidents to Drive Improvements

Not Achieved - At least one of the following is true:

Achieved - All the following statements are true: