The NCSC has released version 4.0 of the Cyber Assessment Framework (CAF), in response to the growing and evolving threat to UK essential services.
Key changes
- A stronger focus on understanding threats, including a new contributing outcome on threat understanding.
- New and updated expectations on secure software development and support.
- Improved guidance on security monitoring and threat hunting.
- Recognition of risks from AI and other emerging technologies.
The CAF is expected to underpin the expanded regime under the forthcoming Cyber Security and Resilience Bill. Organisations using the CAF for regulatory or self-assessment purposes should plan a gap analysis against version 4.0.
Source: Cyber Assessment Framework (NCSC)
Need help understanding what this change means for your organisation? Get in touch for a pragmatic, no-obligation conversation.