Cyber Assessment Framework
The CAF is a collection of cyber security guidance for organisations that play a vital role in the day-to-day life of the UK, with a focus on essential functions.
Pages
Page 2 of 25
Introduction to the CAF Collection
Why has the NCSC produced the CAF collection?
Network and information systems and the essential functions they support play a vital role in society, from ensuring the supply of electricity, water, oil and gas, to the provision of healthcare and the safety of passenger and freight transport. Their reliability and security are essential to everyday activities.
As we have seen from numerous cyber security incidents, these systems can be an attractive target for malicious actors, and they can also be susceptible to disruption through systems failure. The magnitude, frequency and impact of network and information system security incidents is increasing. Historical events such as the 2015 attack on Ukraine’s electricity network and the 2017 WannaCry ransomware attack, together with more recent events such as the US Colonial Pipeline and Redcar & Cleveland and Hackney councils ransomware attacks and the Synnovis pathology laboratory ransomware attack clearly highlight the impact that incidents can have.
There is therefore a need to continually improve the security of network and information systems across the UK, with a particular focus on essential functions which if compromised could potentially cause significant damage to the economy, society, the environment, and individuals’ welfare, including loss of life.
The resources within the CAF collection are intended for the use of organisations that play a vital role in the day-to-day life of the UK, organisations such as those designated as forming part of the Critical National Infrastructure (CNI), or subject to certain types of cyber regulation, including The Network & Information Systems (NIS) regulations 2018, and cyber aspects of safety regulation such as Control Of Major Accident Hazards (COMAH).
Note
Organisations that are subject to cyber regulation should talk to their regulator before using the NCSC CAF in relation to meeting regulatory requirements.
What is the CAF collection for?
The CAF collection is aimed at helping an organisation achieve and demonstrate an appropriate level of cyber resilience in relation to certain specified essential functions performed by that organisation.
Why ‘achieve and demonstrate’?
The CAF is intended to be used by an organisation to manage the risk that pre-determined unacceptable consequences occur as a result of cyber attack. This is very frequently the type of context in which there is an external entity, or cyber oversight body, (such as a cyber regulator or a government policy organisation) responsible for understanding the extent to which all the organisations in a sector are successfully managing that kind of cyber risk. The CAF collection provides a framework specifically designed to assist relevant cyber oversight bodies in generating such a sector-level understanding.
The CAF collection is written primarily in terms of outcomes to be achieved rather than a compliance checklist. There will often be a number of different ways of achieving the specified CAF outcomes, which could give rise to uncertainty about the extent to which an organisation has successfully put in place an appropriate level of cyber resilience. However, the inclusion of Indicators of Good Practice (IGPs) in the CAF provides a guide to the type of measures that would normally be present in an organisation that was achieving CAF outcomes, allowing that organisation to demonstrate the appropriate level of cyber resilience.
Why ‘cyber resilience’?
The term ‘cyber resilience’ refers to an organisation’s ability to maintain the correct operation of its essential functions even in the presence of adverse cyber events. This term is chosen to emphasise that the CAF collection is intended for use where there are some pre-determined unacceptable consequences, and the purpose of following CAF requirements is to manage the risk of those unacceptable consequences occurring as a result of a cyber attack.
Why ‘specified essential functions’?
The focus on cyber resilience of ‘specified essential functions’ is used to distinguish the CAF from a set of generic good cyber security practices. Users of the CAF will typically be responsible for the correct operation of one or more important organisational functions, the compromise or failure of which would lead to unacceptable consequences.
For example, the organisation might be an electricity Distribution Network Operator / Distribution System Operator in which case the essential function would be ‘provision of a reliable electricity supply to consumer premises’. This example would fall into the category of both CNI, and NIS Operator of Essential Service.
The specified essential functions drive considerations such as which network and information systems are in scope of CAF cyber resilience requirements. In recognition of this the CAF collection has been designed to be equally applicable to both Information Technology (IT) and Operational Technology (OT). This is in contrast to generic good cyber security practices which are usually assumed to be generally applicable across the entirety of an organisation’s IT estate and are not usually designed to encompass OT.
Please note that the use of CAF Collection extends beyond organisations that own and operate elements of the UK CNI. For that reason, the terminology of the CAF Collection is intended to generalise and extend CNI terminology. Specifically, in the CAF Collection:
-
‘essential function’
may refer to something recognised as a CNI essential service or to another important activity carried out by an organisation (e.g. an essential service as defined by the NIS Regulations, or preservation of public safety in the context of transportation services, operation of industrial sites etc).
-
‘organisation responsible for an essential function’
may refer to an organisation that owns and operates an element of the CNI, or to another type of organisation (e.g. an organisation designated as an Operator of Essential Services under the NIS Regulations, or an organisation subject to cyber safety regulation).
Additionally note that, as used in the CAF collection, the term ‘essential function’ may or may not refer to an activity subject to cyber regulation.


