Cyber Assessment Framework
The CAF is a collection of cyber security guidance for organisations that play a vital role in the day-to-day life of the UK, with a focus on essential functions.
Pages
Page 15 of 25
Principle B6 Staff awareness and training

Proportionate security measures are in place to protect network and information systems supporting essential functions from cyber attack.
Principle
Staff have appropriate awareness, knowledge and skills to carry out their organisational roles effectively in relation to the security of network and information systems supporting the operation of your essential function(s).
Description of principle
Staff are central to any organisation’s ability to operate securely. Therefore, organisations responsible for essential functions should ensure that their employees have the information, knowledge, and skills they need to support the security of networks and information systems.
To be effective any security awareness and training programme needs to recognise and be tailored to reflect the way people really work with security in an organisation, as part of creating a positive security culture.
Guidance
The people who operate and support essential functions should be provided with all they need to carry out their job while supporting the organisation's cyber security. In line with the design of service protection policies and processes, you should apply the same people-focussed approach to staff awareness and training.
Training and awareness activities should provide appropriate cyber security skills for the job role based on an understanding of how people really work with the systems, with ongoing reminders and top-up training to maintain skills.
Using a range of approaches to training and awareness can improve understanding and information retention, from briefings, online courses and blogs to simulated cyber attack. You may achieve the widest uptake of training and awareness by accommodating different learning preferences and using various delivery methods. Organisations may find the GCHQ certified training scheme useful when considering commercial offerings.
Security culture
Organisations responsible for essential functions should aim to create a positive security culture, where people are aware of their role in maintaining security and actively take part and contribute to improving security. This is particularly important where a technical solution is not possible, so security relies on people making the right cyber security decisions. Developing a positive security culture is likely to take some time, with some changes possibly taking years to become established and is unlikely to be achieved simply through written guidance or training events.
Communications
These outcomes are best achieved when organisations actively engage with staff and communicate effectively with them about network and information system security and how it relates to their jobs. This should be more easily achieved where organisations create and promote a long-term security culture vision that is endorsed and supported by senior management, then make incremental, focused changes to address specific business issues. In some cases, particularly where an essential function is safety-related, an organisation may be able to draw on activities supporting positive safety culture to build up the organisation's cyber security culture.
B6.a Cyber Security Culture
You develop and maintain a positive cyber security culture and a shared sense of responsibility.
| Not achieved | Partially achieved | Achieved |
|---|---|---|
| At least one of the following statements is true: | All the following statements are true: | All the following statements are true: |
People in your organisation do not understand what they contribute to the cyber security of network and information systems supporting your essential function(s). People in your organisation do not know how to raise a concern about cyber security. People believe that reporting issues may get them into trouble. Your organisation's approach to cyber security is perceived by staff as hindering the business of the organisation and may encourage poor security behaviours. Formal or informal incentives and rewards conflict with the promotion of positive security outcomes. | Your executive management understand and widely communicate the importance of a positive cyber security culture. Positive attitudes, behaviours and expectations are described for your organisation. All people in your organisation understand the contribution they make to the cyber security of network and information systems supporting your essential function(s). All individuals in your organisation know who to contact and where to access more information about cyber security. They know how to raise a cyber security issue. You identify and address issues that inhibit people from behaving in a manner that supports your intended cyber security outcomes.
| Your executive management clearly and effectively communicates the organisation's cyber security priorities and objectives to all staff. Your organisation displays positive cyber security attitudes, behaviours, expectations. People in your organisation raising potential cyber security incidents and issues are treated positively. Individuals at all levels in your organisation routinely report concerns or issues about cyber security and are recognised for their contribution to keeping the organisation secure. Your management is seen to be committed to and actively involved in cyber security. Your organisation communicates openly about cyber security, with any concern being taken seriously. People across your organisation participate in cyber security activities and improvements, building joint ownership and bringing knowledge of their area of expertise. |
B6.b Cyber Security Training
The people who support the operation of network and information systems supporting your essential function(s) are appropriately trained in cyber security.
| Not achieved | Partially achieved | Achieved |
|---|---|---|
| At least one of the following statements is true: | All the following statements are true: | All the following statements are true: |
There are teams who operate and support your essential function(s) that lack any cyber security training. Cyber security training is restricted to specific roles in your organisation. Cyber security training records for your organisation are lacking or incomplete. Training is used as a “silver bullet” for all user security behaviours. The success of training is only measured by the number of people reached, rather than assessing whether it has a positive impact on security behaviours. Training materials contain out of date or contradictory information, or information that conflicts with other policies, processes or procedures. | You have defined appropriate cyber security training and awareness activities for all roles in your organisation, from executives to the most junior roles. You use a range of teaching and communication techniques for cyber security training and awareness to reach the widest audience effectively. Cyber security information is easily available. | All people in your organisation, from the most senior to the most junior, follow appropriate cyber security training paths. Each individuals cyber security training is tracked and refreshed at suitable intervals. You routinely evaluate your cyber security training and awareness activities to ensure they reach the widest audience and are effective. You make cyber security information and good practice guidance easily accessible, widely available and you know it is referenced and used within your organisation. |


