Skip to main content
Guidance

Cyber Assessment Framework

The CAF is a collection of cyber security guidance for organisations that play a vital role in the day-to-day life of the UK, with a focus on essential functions.

Page 6 of 25

Principle A2 Risk Management

iStock.com/Alyona Zueva

Appropriate organisational structures, policies, processes and procedures in place to understand, assess and systematically manage security risks to network and information systems supporting essential functions.




Physical Risks

You should have adequate policies and measures in place to identify and address risks to the physical infrastructure that supports your network and information systems. This can be achieved through measures such as identifying single points of failure, assessing the impact of physical failures on your ability to provide your essential service, maintaining a list of risks and assets.  Physical risks include, but are not limited to, hardware failure, power failure, environmental hazards such as fire and flood, physical damage etc. 

A2.a Risk Management Process

Your organisation has effective internal processes for managing risks to the security and resilience of network and information systems related to the operation of your essential function(s) and communicating associated activities.

Not achievedPartially achievedAchieved
At least one of the following statements is true:All the following statements are true:All the following statements are true:

Risk assessments are not based on a clearly defined set of threat assumptions.

Risk assessment outputs are too complex or unwieldy to be consumed by decision-makers and are not effectively communicated in a clear and timely manner. 

Risk assessments for network and information systems that support your essential function(s) are a "one-off" activity or not done at all.  

The security elements of projects or programmes are solely dependent on the completion of a risk management assessment without any regard to the outcomes.  

There is no systematic process in place to ensure that identified security risks are managed effectively.  

Systems are assessed in isolation, without consideration of dependencies and interactions with other systems. (e.g. interactions between IT and OT environments).  

Security requirements and mitigations are arbitrary or are applied from a control catalogue without consideration of how they contribute to the security of the essential function(s).  

Risks remain unresolved on a register for prolonged periods of time awaiting senior decision-making or resource allocation to resolve.

Your organisational process ensures that security risks to network and information systems relevant to essential function(s) are identified, analysed, prioritised, and managed.  

Your risk assessments are informed by an understanding of the vulnerabilities in the network and information systems supporting your essential function(s).  

The output from your risk management process is a clear set of security requirements that will address the risks in line with your organisational approach to security.  

Significant conclusions reached in the course of your risk management process are communicated to key security decision-makers and accountable individuals.  

You conduct risk assessments when significant events potentially affect the essential function(s), such as replacing a system, introducing new or emergent technologies or a change in the cyber security threat.

Your organisational process ensures that security risks to network and information systems relevant to essential function(s) are identified, analysed, prioritised, and managed. 

Your approach to risk is focused on the possibility of adverse impact to your essential function(s), leading to a detailed understanding of how such impact might arise as a consequence of possible attacker actions and the security properties of your network and information systems. 

Your risk assessments are based on a clearly understood set of threat assumptions, informed by an up-to-date understanding of security threats to your essential function(s) and your sector.

Your risk assessments are informed by an understanding of the vulnerabilities in the network and information systems supporting your essential function(s).  

The output from your risk management process is a clear set of security requirements that will address the risks in line with your organisational approach to security.  

Significant conclusions reached in the course of your risk management process are communicated to key security decision-makers and accountable individuals.  

Your risk assessments are dynamic and updated in the light of relevant changes which may include technical changes to network and information systems, change of use and new threat information.  

The effectiveness of your risk management process is reviewed regularly, and improvements made as required.  

You anticipate technological developments that could be used to adversely impact network and information systems supporting your essential function(s).

A2.b Understanding Threat

You understand the capabilities, methods and techniques of threat actors and what network and information systems they may compromise to adversely impact your essential function(s). This information is used to inform security and resilience risk management decisions, adjusting, enhancing or adding security measures to better defend against threats.

Not achievedPartially achievedAchieved
At least one of the following statements is true:All the following statements are true:All the following statements are true:

You are unable to perform threat analysis.

You do not understand the threats to network and information systems supporting your essential function(s).

You do not have a clearly defined set of threat assumptions.

You do not use your understanding of threat to inform your risk management decisions.

You perform threat analysis and understand how common threats apply to network and information systems supporting your essential function(s).

You understand common types of cyber attacks, including the methods and techniques, and how these might apply to network and information systems supporting your essential function(s). This understanding is kept up to date.

You anticipate what threat actors might target in network and information systems to cause an adverse impact to your essential function(s).

Your understanding of threat is informed by common incidents.

You apply your understanding of threat to inform your risk management decision-making.

You perform detailed threat analysis and understand how this applies to network and information systems supporting your essential function(s), in the context of your sector and wider national infrastructure.

Your detailed understanding of threat includes the methods and techniques available to capable and well-resourced threat actors and how they could be used systematically against network and information systems supporting your essential function(s).

You use appropriate techniques to develop an understanding of network and information systems supporting your essential function(s) from a threat actor’s perspective. You anticipate probable attack methods and techniques, targets and objectives, and develop plausible scenarios.

You understand the different steps a capable and well-resourced threat actor would need to take to reach the probable target(s).

You identify and justify what measures can be used at each step to reduce the likelihood of the threat actor reaching the probable target(s) or achieving their objective(s).

You maintain a detailed understanding of current threats (e.g. by threat intelligence and proactive research).

You apply your detailed understanding of threat to inform your risk management decision-making.

You have documented the steps required to undertake detailed threat analysis.

A2.c Assurance

You have gained confidence in the effectiveness of the security of your technology, people, and processes relevant to the operation of network and information systems supporting your essential function(s).

Not achievedAchieved
At least one of the following statements is true:All the following statements are true:

A particular product or service is seen as a "silver bullet" and vendor claims are taken at face value.  

Assurance methods are applied without appreciation of their strengths and limitations, such as the risks of penetration testing in operational environments.  

Assurance is assumed because there have been no known problems to date.

You validate that the security measures in place to protect the network and information systems are effective and remain effective for the lifetime over which they are needed.  

You understand the assurance methods available to you and choose appropriate methods to gain confidence in the security of essential function(s).  

Your confidence in the security as it relates to your technology, people, and processes can be justified to, and verified by, a third party.  

Security deficiencies uncovered by assurance activities are assessed, prioritised and remedied when necessary in a timely and effective way.  

The methods used for assurance are reviewed to ensure they are working as intended and remain the most appropriate method to use.  


Published

Reviewed

Version

4.0