Cyber Assessment Framework
The CAF is a collection of cyber security guidance for organisations that play a vital role in the day-to-day life of the UK, with a focus on essential functions.
Pages
Page 14 of 25
Principle B5 Resilient networks and systems

Proportionate security measures are in place to protect network and information systems supporting essential functions from cyber attack.
Principle
The organisation builds resilience against cyber attack and system failure into the design, implementation, operation and management of systems that support the operation of your essential function(s).
Description of principle
The essential functions performed by an organisation should be resilient to cyber attack. Building upon Principle B4 (the technical protection of systems), organisations should ensure that not only is technology well built and maintained, but consideration is also given to how operation of the essential function can continue in the event of technology failure or compromise. In addition to technical means, this might include additional contingency capability such as manual processes to ensure functions can continue.
Organisations should ensure that systems are well maintained and administered through life. The devices and interfaces that are used for administration are frequently targeted, so should be well protected. Spear phishing remains a common method used to compromise accounts with privileged access. Preventing the use of these accounts for routine activities such as email and web browsing significantly limits the ability for a hacker to compromise them.
Guidance
Preparation
It's important to be prepared to respond to significant disruption by having business continuity and disaster recovery planning in place. This should include a definition of your most critical resources and an understanding of the order of actions needed to restore service(s). Test that these plans work, for example through manually triggering failover testing, carrying out table-top scenario walk-throughs, red-teaming or Cyber adversary simulation testing. You should be ready to adjust the security measures in place in response to changes in risk. For example, if threat intelligence indicates an increased likelihood of your organisation or sector being targeted you may decide to isolate operational networks until the threat has decreased. Alternatively, in the event of public disclosure of an unpatched vulnerability in equipment that you use, with reported use of exploits targeting the vulnerability, you may respond by elevating your protective monitoring, changing your configuration to avoid being susceptible, or taking other mitigating action in the period until a patch is made available and can be deployed.
Maintenance and repair
You should reduce the likelihood of failure or attack by taking all reasonable measures to maintain networks, information systems and necessary technologies in good working order. Exceptions should be appropriately managed.
Segregation
In the event of an incident, it is more likely that an essential function will be able to continue where the networks and information systems that support it are segregated from other business and external systems. Separation of system architecture, remote access and privileged access are some key principles that can protect more critical systems from external compromise.
Some sectors responsible for the operation of essential functions may apply the industrial automation and control system security standard IEC 62443, which applies a reference model that separates systems into different logical layers. The standard's architecture model segregates equipment into security zones.
Capacity
Limitations of networks and information systems, or external services or resources, such as network bandwidth, processing capability, or data storage capacity, should be understood and managed with suitable mitigations to avoid disruption through resource overload.
Diversity and dependencies
Make appropriate use of diverse technologies, geographic locations and so on, to provide resilience. You should understand and manage external or lower-priority dependencies to ensure that alternative means are suitable for continuation of the essential function.
Working backups
In the event of an adverse event, you should be able to revert to backups of hardware and data that are known to be functioning and accessible. Organisations should maintain secured offline, potentially off-site, backups of the operational data, equipment configurations, gold builds, etc. needed to recover from an extreme event.
Suitable alternative backups may include paper-based information and manual processes. Other essential backups may include personnel with appropriate knowledge and access to up-to-date documentation. Consider how to make it easy to recover following an incident or compromise.
Physical Resilience
You should have adequate policies and measures to ensure the physical and environmental security of your network and information systems. This can be achieved through measures such as physical access controls, alarm systems, environmental controls and automated fire systems etc.
When planning physical upgrades or changes to network and information systems (such as moving to new hardware installations, installing new equipment or power supplies), you should take steps to avoid unnecessary or unplanned interruptions to the services that your network and information systems support.
You should also ensure that you have adequate policies to protect supporting utilities such as electricity, fuel, heating, ventilation, and air conditioning. This can be achieved by having alternative sources, such as back-up generators or uninterruptible power supplies, active temperature monitoring, redundant cooling systems etc.
B5.a Resilience Preparation
You are prepared to restore the operation of your essential function(s) following adverse impact to network and information systems.
| Not achieved | Partially achieved | Achieved |
|---|---|---|
| Any of the following statements are true: | All of the following statements are true: | All of the following statements are true: |
You have limited understanding of all the elements that are required to restore operation of the essential function(s). You have not completed business continuity and disaster recovery plans for network and information systems, including their dependencies, supporting the operation of the essential function(s). You have not fully assessed the practical implementation of your business continuity and disaster recovery plans. | You know all network and information systems, and underlying technologies that are necessary to restore the operation of the essential function(s) and understand their interdependence. You know the order in which systems need to be recovered to efficiently and effectively restore the operation of the essential function(s). | You have business continuity and disaster recovery plans that have been tested for practicality, effectiveness and completeness. Appropriate use is made of different test methods (e.g. manual fail-over, table-top exercises, or red-teaming). You use your security awareness and threat intelligence sources to identify new or heightened levels of risk, which result in immediate and potentially temporary security measures to enhance the security of your network and information systems (e.g. in response to a widespread outbreak of very damaging malware). |
B5.b Design for Resilience
You design the network and information systems supporting your essential function(s) to be resilient to cyber security incidents. Systems are appropriately segregated and resource limitations are mitigated.
| Not achieved | Partially achieved | Achieved |
|---|---|---|
| At least one of the following statements is true: | All of the following statements are true: | All of the following statements are true: |
Network and information systems supporting the operation of your essential function(s) are not appropriately segregated. Internet services, such as browsing and email, are accessible from network and information systems supporting the essential function(s). You do not understand or lack plans to mitigate all resource limitations that could adversely affect your essential function(s). | Network and information systems supporting the operation of your essential function(s) are logically separated from your business systems (e.g. they reside on the same network as the rest of the organisation but within a DMZ). Internet services, such as browsing and email, are not accessible from network and information systems supporting the essential function(s). Resource limitations (e.g. network bandwidth, single network paths) have been identified but not fully mitigated. | Network and information systems supporting the operation of your essential function(s) are segregated from other business and external systems by appropriate technical and physical means (e.g. separate network and system infrastructure with independent user administration). Internet services, such as browsing and email, are not accessible from network and information systems supporting the essential function(s). You have identified and mitigated all resource limitations (e.g. bandwidth limitations and single network paths). You have identified and mitigated any geographical constraints or weaknesses. (e.g. systems that your essential function(s) depends upon are replicated in another location, important network connectivity has alternative physical paths and service providers). You review and update assessments of dependencies, resource and geographical limitations and mitigations when necessary. |
B5.c Backups
You hold accessible and secured current backups of data and information needed to recover operation of your essential function(s) following an adverse impact to network and information systems.
| Not achieved | Partially achieved | Achieved |
|---|---|---|
| At least one of the following statements is true: | All of the following statements are true: | All of the following statements are true: |
Backup coverage is incomplete and does not include all relevant data and information needed to restore the operation of your essential function(s). Backups are not frequent enough for the operation of your essential function(s) to be restored effectively. Your restoration process does not restore your essential function(s) in a suitable time frame. | You have appropriately secured backups (including data, configuration information, software, equipment, processes and knowledge). These backups will be accessible to recover from an extreme event. You routinely test backups to ensure that the backup process function(s) correctly and the backups are usable. | Your comprehensive, automatic and tested technical and procedural backups are secured at centrally accessible or secondary sites to recover from an extreme event. Backups of all important data and information needed to recover the essential function(s) are made, tested, documented and routinely reviewed |
Additional information
- Exercising list of guidance
- Principles for ransomware-resistant cloud backups
- Cloud security guidance - Principle 2: Asset protection and resilience
- Secure design principles - 5. Reduce the impact of compromise
- 10 Steps to Cyber Security - Data Security
- Small Business Guide: Cyber Security. Step 1 - Backing up your data
- Using online services safely. Back up your organisation's critical data
- Actions to take when the cyber threat is heightened
- Denial of Service (DoS) guidance
- NCSC Ransomware-resistant backups
- RITICS Resolving anti-patterns in ICS / OT environments
- The Business Continuity Institute has some freely available introductory business continuity guidance and members can access more detailed resources
- Civil Contingencies Secretariat’s 2011 guidance on resilience of critical infrastructure and essential services (pdf)
- NIST SP800-53
- NIST SP800-82
- IEC 62443 / ISA99 2-1
- IEC 62443-1-1
- IEC 62443-3-3
- ISO/IEC 27001


