Skip to main content
Guidance

Cyber Assessment Framework

The CAF is a collection of cyber security guidance for organisations that play a vital role in the day-to-day life of the UK, with a focus on essential functions.

Page 15 of 25

Principle B6 Staff awareness and training

iStock.com/flash vector

Proportionate security measures are in place to protect network and information systems supporting essential functions from cyber attack.




B6.a Cyber Security Culture

You develop and maintain a positive cyber security culture and a shared sense of responsibility.

Not achievedPartially achievedAchieved
At least one of the following statements is true:All the following statements are true:All the following statements are true:

People in your organisation do not understand what they contribute to the cyber security of network and information systems supporting your essential function(s).

People in your organisation do not know how to raise a concern about cyber security.

People believe that reporting issues may get them into trouble.

Your organisation's approach to cyber security is perceived by staff as hindering the business of the organisation and may encourage poor security behaviours.

Formal or informal incentives and rewards conflict with the promotion of positive security outcomes.

Your executive management understand and widely communicate the importance of a positive cyber security culture. Positive attitudes, behaviours and expectations are described for your organisation.

All people in your organisation understand the contribution they make to the cyber security of network and information systems supporting your essential function(s).

All individuals in your organisation know who to contact and where to access more information about cyber security. They know how to raise a cyber security issue.

You identify and address issues that inhibit people from behaving in a manner that supports your intended cyber security outcomes.

 

Your executive management clearly and effectively communicates the organisation's cyber security priorities and objectives to all staff.  Your organisation displays positive cyber security attitudes, behaviours, expectations. 

People in your organisation raising potential cyber security incidents and issues are treated positively.

Individuals at all levels in your organisation routinely report concerns or issues about cyber security and are recognised for their contribution to keeping the organisation secure. 

Your management is seen to be committed to and actively involved in cyber security.

Your organisation communicates openly about cyber security, with any concern being taken seriously.

People across your organisation participate in cyber security activities and improvements, building joint ownership and bringing knowledge of their area of expertise.

B6.b Cyber Security Training

The people who support the operation of network and information systems supporting your essential function(s) are appropriately trained in cyber security.

Not achievedPartially achievedAchieved
At least one of the following statements is true:All the following statements are true:All the following statements are true:

There are teams who operate and support your essential function(s) that lack any cyber security training.

Cyber security training is restricted to specific roles in your organisation.

Cyber security training records for your organisation are lacking or incomplete.

Training is used as a “silver bullet” for all user security behaviours.

The success of training is only measured by the number of people reached, rather than assessing whether it has a positive impact on security behaviours.

Training materials contain out of date or contradictory information, or information that conflicts with other policies, processes or procedures.

You have defined appropriate cyber security training and awareness activities for all roles in your organisation, from executives to the most junior roles.

You use a range of teaching and communication techniques for cyber security training and awareness to reach the widest audience effectively.

Cyber security information is easily available.
 

All people in your organisation, from the most senior to the most junior, follow appropriate cyber security training paths.

Each individuals cyber security training is tracked and refreshed at suitable intervals.

You routinely evaluate your cyber security training and awareness activities to ensure they reach the widest audience and are effective.

You make cyber security information and good practice guidance easily accessible, widely available and you know it is referenced and used within your organisation.


Published

Reviewed

Version

4.0