The NCSC has published version 3.2 of the Cyber Assessment Framework (CAF).
The update refines several indicators of good practice to reflect current threats and technology, with particular attention to:
- Remote access and the use of multi-factor authentication.
- Privileged operations and administrative access.
- User access management.
- Security monitoring and logging.
The CAF continues to be used by UK regulators to assess organisations under the NIS Regulations and is increasingly used in government (through GovAssure) and the NHS. It is also a useful, outcome-focused self-assessment tool for any organisation.
Source: Cyber Assessment Framework (NCSC)
Need help understanding what this change means for your organisation? Get in touch for a pragmatic, no-obligation conversation.