Cyber Assessment Framework
The CAF is a collection of cyber security guidance for organisations that play a vital role in the day-to-day life of the UK, with a focus on essential functions.
Pages
Page 6 of 25
Principle A2 Risk Management
Appropriate organisational structures, policies, processes and procedures in place to understand, assess and systematically manage security risks to network and information systems supporting essential functions.
Principle
The organisation takes appropriate steps to identify, assess and understand security risks to network and information systems supporting the operation of essential functions. This includes an overall organisational approach to risk management.
Description of principle
There is no single blueprint for cyber security and therefore organisations need to take steps to determine security risks that could affect the operation of essential functions and take measures to appropriately manage those risks.
Threats can come from many sources, both from within and external to an organisation. A good understanding of the threat landscape and the vulnerabilities that may be exploited is essential to effectively identify and manage risks. Such information may come from sources including NCSC, information exchanges relevant to the organisation's sector, and reputable government, commercial, and open sources, all of which can inform the organisation's own risk assessment process. Organisations may contribute to the understanding of threats and vulnerabilities in their sector by participating in relevant information exchanges and liaising with authorities as appropriate.
There should be a systematic process in place to ensure that identified risks are managed and the organisation has confidence mitigations are working effectively. Confidence can be gained through, for example, product assurance, monitoring, vulnerability testing, auditing and supply chain security.
Guidance
NCSC Risk Management guidance
Our Risk Management guidance aims to help you to choose an approach that's right for your organisation. Organisations responsible for essential functions are likely to benefit from a combination of a system-based approach, which looks at the interactions between components of the function, and a component-driven analysis, which considers the threats, vulnerabilities, and impacts relevant to particular critical components.
Risk methods and frameworks
Your organisation should choose a method or framework for managing risk that fits with the organisation's business and technology needs.
Whichever approach you choose, the scope of your programme must include all systems relevant to the operation of essential functions. Simply following the minimum requirements of a standard or applying blanket controls across the organisation is unlikely to adequately manage risks to critical systems.
Where industrial control and automation systems are in scope of the essential function, you should keep in mind that controls suitable for managing risks on the corporate IT network may be inappropriate or damaging in an operational technology environment. These systems will likely require a more tailored approach, and some frameworks and standards address specific concerns relating to such systems.
Understanding Threat
Cyber threats continue to evolve and develop, putting each organisation’s operational continuity and services at significant risk. By identifying and understanding cyber threats, and the steps a threat actor may take to compromise systems supporting essential functions, an organisation can implement effective security measures to counter malicious attacks and breaches. Various methods can be used to better understand threat which are discussed in our Risk Management guidance.
Ultimately, a detailed understanding of current cyber threats helps organisations to mitigate risks, ensuring the security and resilience of network and information systems in an increasingly hostile world.
Cyber security assurance
Various means are available to gain confidence in the effectiveness of the security of technologies, processes and people. The NCSC Risk Management guidance discusses how to gain and maintain assurance in your risk treatments.
The NCSC assurance guidance provides some examples that may be useful to understand cyber security confidence in your organisation and there are some specific technical NCSC guides:
-
NCSC Penetration Testing
The NCSC Penetration guidance will help you understand the proper use and commissioning of penetration tests to gain assurance in the security of an IT system.
-
NCSC Cloud Security collection
Our Cloud Security collection provides guidance on managing the risks involved with using cloud services, and some of the principles and guidance are more broadly applicable. The cloud guidance for having confidence in cyber security provides principles that are useful for assuring cyber security of essential functions. The collection will be of particular interest if your organisation hosts any part of your essential function infrastructure on a cloud service.
Physical Risks
You should have adequate policies and measures in place to identify and address risks to the physical infrastructure that supports your network and information systems. This can be achieved through measures such as identifying single points of failure, assessing the impact of physical failures on your ability to provide your essential service, maintaining a list of risks and assets. Physical risks include, but are not limited to, hardware failure, power failure, environmental hazards such as fire and flood, physical damage etc.
A2.a Risk Management Process
Your organisation has effective internal processes for managing risks to the security and resilience of network and information systems related to the operation of your essential function(s) and communicating associated activities.
| Not achieved | Partially achieved | Achieved |
|---|---|---|
| At least one of the following statements is true: | All the following statements are true: | All the following statements are true: |
Risk assessments are not based on a clearly defined set of threat assumptions. Risk assessment outputs are too complex or unwieldy to be consumed by decision-makers and are not effectively communicated in a clear and timely manner. Risk assessments for network and information systems that support your essential function(s) are a "one-off" activity or not done at all. The security elements of projects or programmes are solely dependent on the completion of a risk management assessment without any regard to the outcomes. There is no systematic process in place to ensure that identified security risks are managed effectively. Systems are assessed in isolation, without consideration of dependencies and interactions with other systems. (e.g. interactions between IT and OT environments). Security requirements and mitigations are arbitrary or are applied from a control catalogue without consideration of how they contribute to the security of the essential function(s). Risks remain unresolved on a register for prolonged periods of time awaiting senior decision-making or resource allocation to resolve. | Your organisational process ensures that security risks to network and information systems relevant to essential function(s) are identified, analysed, prioritised, and managed. Your risk assessments are informed by an understanding of the vulnerabilities in the network and information systems supporting your essential function(s). The output from your risk management process is a clear set of security requirements that will address the risks in line with your organisational approach to security. Significant conclusions reached in the course of your risk management process are communicated to key security decision-makers and accountable individuals. You conduct risk assessments when significant events potentially affect the essential function(s), such as replacing a system, introducing new or emergent technologies or a change in the cyber security threat. | Your organisational process ensures that security risks to network and information systems relevant to essential function(s) are identified, analysed, prioritised, and managed. Your approach to risk is focused on the possibility of adverse impact to your essential function(s), leading to a detailed understanding of how such impact might arise as a consequence of possible attacker actions and the security properties of your network and information systems. Your risk assessments are based on a clearly understood set of threat assumptions, informed by an up-to-date understanding of security threats to your essential function(s) and your sector. Your risk assessments are informed by an understanding of the vulnerabilities in the network and information systems supporting your essential function(s). The output from your risk management process is a clear set of security requirements that will address the risks in line with your organisational approach to security. Significant conclusions reached in the course of your risk management process are communicated to key security decision-makers and accountable individuals. Your risk assessments are dynamic and updated in the light of relevant changes which may include technical changes to network and information systems, change of use and new threat information. The effectiveness of your risk management process is reviewed regularly, and improvements made as required. You anticipate technological developments that could be used to adversely impact network and information systems supporting your essential function(s). |
A2.b Understanding Threat
You understand the capabilities, methods and techniques of threat actors and what network and information systems they may compromise to adversely impact your essential function(s). This information is used to inform security and resilience risk management decisions, adjusting, enhancing or adding security measures to better defend against threats.
| Not achieved | Partially achieved | Achieved |
|---|---|---|
| At least one of the following statements is true: | All the following statements are true: | All the following statements are true: |
You are unable to perform threat analysis. You do not understand the threats to network and information systems supporting your essential function(s). You do not have a clearly defined set of threat assumptions. You do not use your understanding of threat to inform your risk management decisions. | You perform threat analysis and understand how common threats apply to network and information systems supporting your essential function(s). You understand common types of cyber attacks, including the methods and techniques, and how these might apply to network and information systems supporting your essential function(s). This understanding is kept up to date. You anticipate what threat actors might target in network and information systems to cause an adverse impact to your essential function(s). Your understanding of threat is informed by common incidents. You apply your understanding of threat to inform your risk management decision-making. | You perform detailed threat analysis and understand how this applies to network and information systems supporting your essential function(s), in the context of your sector and wider national infrastructure. Your detailed understanding of threat includes the methods and techniques available to capable and well-resourced threat actors and how they could be used systematically against network and information systems supporting your essential function(s). You use appropriate techniques to develop an understanding of network and information systems supporting your essential function(s) from a threat actor’s perspective. You anticipate probable attack methods and techniques, targets and objectives, and develop plausible scenarios. You understand the different steps a capable and well-resourced threat actor would need to take to reach the probable target(s). You identify and justify what measures can be used at each step to reduce the likelihood of the threat actor reaching the probable target(s) or achieving their objective(s). You maintain a detailed understanding of current threats (e.g. by threat intelligence and proactive research). You apply your detailed understanding of threat to inform your risk management decision-making. You have documented the steps required to undertake detailed threat analysis. |
A2.c Assurance
You have gained confidence in the effectiveness of the security of your technology, people, and processes relevant to the operation of network and information systems supporting your essential function(s).
| Not achieved | Achieved |
|---|---|
| At least one of the following statements is true: | All the following statements are true: |
A particular product or service is seen as a "silver bullet" and vendor claims are taken at face value. Assurance methods are applied without appreciation of their strengths and limitations, such as the risks of penetration testing in operational environments. Assurance is assumed because there have been no known problems to date. | You validate that the security measures in place to protect the network and information systems are effective and remain effective for the lifetime over which they are needed. You understand the assurance methods available to you and choose appropriate methods to gain confidence in the security of essential function(s). Your confidence in the security as it relates to your technology, people, and processes can be justified to, and verified by, a third party. Security deficiencies uncovered by assurance activities are assessed, prioritised and remedied when necessary in a timely and effective way. The methods used for assurance are reviewed to ensure they are working as intended and remain the most appropriate method to use. |
Additional information
- NPSA Protective Security Risk Management
- ISO/IEC 27005
- Civil Contingencies Secretariat’s 2011 guidance on resilience of critical infrastructure and essential services (.pdf)
- NIST SP800-53
- NIST SP800-82
- IEC 62443-2-1
- IEC 62443-3-3
- ISO 31000
- UK Government Performing threat modelling
- CISA Identifying and Mitigating Living Off the Land Techniques
- NIST AI 100-1
- NIST Adversarial Machine Learning a Taxonomy and Terminology of Attacks and Mitigations


