Don’t do SECURITY. Do business SECURELY.

NCSC publishes the Cyber Assessment Framework (CAF)

The NCSC has published the Cyber Assessment Framework, the basis for assessing operators of essential services under the UK NIS Regulations.

The National Cyber Security Centre (NCSC) has published version 1.0 of the Cyber Assessment Framework (CAF), ahead of the UK NIS Regulations coming into force next month.

Rather than a checklist of prescriptive controls, the CAF is outcome-based. It is structured around four objectives:

  • A: Managing security risk
  • B: Protecting against cyber-attack
  • C: Detecting cyber security events
  • D: Minimising the impact of cyber security incidents

Each objective is broken down into principles and contributing outcomes, with “indicators of good practice” used to judge whether an outcome is achieved, partially achieved or not achieved.

Regulators will use the CAF to assess operators of essential services, but it is also a valuable self-assessment tool for any organisation that wants to understand its cyber resilience.

Source: Cyber Assessment Framework (NCSC)

Need help understanding what this change means for your organisation? Get in touch for a pragmatic, no-obligation conversation.

More insights