Skip to main content
Guidance

Cyber Assessment Framework

The CAF is a collection of cyber security guidance for organisations that play a vital role in the day-to-day life of the UK, with a focus on essential functions.

Page 14 of 25

Principle B5 Resilient networks and systems

iStock.com/ArtemisDiana

Proportionate security measures are in place to protect network and information systems supporting essential functions from cyber attack.




B5.a Resilience Preparation

You are prepared to restore the operation of your essential function(s) following adverse impact to network and information systems.

Not achievedPartially achievedAchieved
Any of the following statements are true:All of the following statements are true:All of the following statements are true:

You have limited understanding of all the elements that are required to restore operation of the essential function(s). 

You have not completed business continuity and disaster recovery plans for network and information systems, including their dependencies, supporting the operation of the essential function(s).

You have not fully assessed the practical implementation of your business continuity and disaster recovery plans.

You know all network and information systems, and underlying technologies that are necessary to restore the operation of the essential function(s) and understand their interdependence.

You know the order in which systems need to be recovered to efficiently and effectively restore the operation of the essential function(s).

You have business continuity and disaster recovery plans that have been tested for practicality, effectiveness and completeness. Appropriate use is made of different test methods (e.g. manual fail-over, table-top exercises, or red-teaming).

You use your security awareness and threat intelligence sources to identify new or heightened levels of risk, which result in immediate and potentially temporary security measures to enhance the security of your network and information systems (e.g. in response to a widespread outbreak of very damaging malware).

B5.b Design for Resilience

You design the network and information systems supporting your essential function(s) to be resilient to cyber security incidents. Systems are appropriately segregated and resource limitations are mitigated.

Not achievedPartially achievedAchieved
At least one of the following statements is true:All of the following statements are true:All of the following statements are true:

Network and information systems supporting the operation of your essential function(s) are not appropriately segregated.

Internet services, such as browsing and email, are accessible from network and information systems supporting the essential function(s).

You do not understand or lack plans to mitigate all resource limitations that could adversely affect your essential function(s).

Network and information systems supporting the operation of your essential function(s) are logically separated from your business systems (e.g. they reside on the same network as the rest of the organisation but within a DMZ).

Internet services, such as browsing and email, are not accessible from network and information systems supporting the essential function(s).

Resource limitations (e.g. network bandwidth, single network paths) have been identified but not fully mitigated.

Network and information systems supporting the operation of your essential function(s) are segregated from other business and external systems by appropriate technical and physical means (e.g. separate network and system infrastructure with independent user administration).

Internet services, such as browsing and email, are not accessible from network and information systems supporting the essential function(s).

You have identified and mitigated all resource limitations (e.g. bandwidth limitations and single network paths).

You have identified and mitigated any geographical constraints or weaknesses. (e.g. systems that your essential function(s) depends upon are replicated in another location, important network connectivity has alternative physical paths and service providers).

You review and update assessments of dependencies, resource and geographical limitations and mitigations when necessary.

B5.c Backups

You hold accessible and secured current backups of data and information needed to recover operation of your essential function(s) following an adverse impact to network and information systems.

Not achievedPartially achievedAchieved
At least one of the following statements is true:All of the following statements are true:All of the following statements are true:

Backup coverage is incomplete and does not include all relevant data and information needed to restore the operation of your essential function(s).

Backups are not frequent enough for the operation of your essential function(s) to be restored effectively.

Your restoration process does not restore your essential function(s) in a suitable time frame.

You have appropriately secured backups (including data, configuration information, software, equipment, processes and knowledge). These backups will be accessible to recover from an extreme event.

You routinely test backups to ensure that the backup process function(s) correctly and the backups are usable.

Your comprehensive, automatic and tested technical and procedural backups are secured at centrally accessible or secondary sites to recover from an extreme event.

Backups of all important data and information needed to recover the essential function(s) are made, tested, documented and routinely reviewed


Published

Reviewed

Version

4.0