Cyber Assessment Framework
The CAF is a collection of cyber security guidance for organisations that play a vital role in the day-to-day life of the UK, with a focus on essential functions.
Pages
Page 4 of 25
CAF Objective A - Managing Security Risk
Principle: A1 Governance
-
The organisation has appropriate management policies, processes and procedures in place to govern its approach to the security of network and information systems.
Principle: A2 Risk Management
-
The organisation takes appropriate steps to identify, assess and understand security risks to network and information systems supporting the operation of essential functions. This includes an overall organisational approach to risk management.
Principle: A3 Asset Management
-
Everything required to deliver, maintain or support network and information systems necessary for the operation of essential functions is determined and understood. This includes data, people and systems, as well as any supporting infrastructure (such as power or cooling).
Principle: A4 Supply Chain
-
The organisation understands and manages security risks to network and information systems supporting the operation of essential functions that arise as a result of dependencies on suppliers. This includes ensuring that appropriate measures are employed where third party services are used.