NCSC Annual Review 2022
Looking back at the National Cyber Security Centre's sixth year and its key developments and highlights, between 1 September 2021 and 31 August 2022.
Pages
Page 32 of 33
Setting, certifying, assuring and testing standards, products and services
A key feature of the NCSC’s ecosystem development work is its standards-setting, and industry assurance, certification and testing schemes. This year the NCSC relaunched schemes such as Assured Consultancy and Cyber Incident Response, while introducing new initiatives and standards to harness more talent in the ecosystem, broaden the market and allow a wider cross section of industry to work with the NCSC or find support from the 400+ organisations assured by it.
The NCSC broadened its Cyber Incident Response (CIR) scheme to support government, CNI and large corporate organisations in their preparedness for significant targeted cyber attacks. This included rewriting the Technical Standard and a new application process for the Cyber Incident Response scheme.
The scheme supports ‘high threat’ organisations of national significance and was relaunched at the end of March as Cyber Incident Response Level 1. Work has continued on a new Level 2 scheme, which is expected to support the growth in the sector while extending the reach of the NCSC in providing incident-response support to medium and large enterprises, local authorities and other government bodies.
This year, a new Cyber Incident Exercising pilot was successfully completed, with the findings enabling the NCSC to deliver a controlled, scenario-based platform for organisations who want to practice, evaluate and improve their cyber incident response plans in a safe environment. An Expression of Interest was released earlier this year to find a partner to help deliver these new schemes.
Since the formation of the UK Cyber Security Council (UKCSC), the self-regulatory body for the cyber security profession, the NCSC has worked closely with them on a range of shared challenges. In May it was announced that the NCSC was working to pass the stewardship of the Certified Cyber Professional (CCP) scheme to the UKCSC.
In July, the NCSC launched a new Cyber Advisor scheme with 100 fully funded assessments of potential Cyber Advisors to confirm they possessed a good understanding of baseline security controls and the ability to provide practical help to companies who wanted to achieve them.
The scheme is planned to go live next year and will offer assured cyber security consultancy services to a wider market of small and medium sized firms, helping them to meet minimum standards of security.
Cyber Advisor organisations will be able to provide customers with practical help to achieve a basic level of resilience. Advice will initially be focused on Cyber Essentials’ five technical controls – firewalls, secure settings, access controls, malware and software updates – and qualified Cyber Advisors will help customers meet these controls and implement any recommendations.
As well as launching Cyber Advisor, the NCSC refreshed the Assured Cyber Security Consultancy scheme, and developed a new standard, assessment criteria and assessment process. These updates have been implemented by the NCSC alongside input from scheme members. The scheme continued to deliver tailored cyber security consultations on complex issues to government, public sector organisations and the UK’s CNI.