Skip to main content
Guidance

Cyber Assessment Framework

The CAF is a collection of cyber security guidance for organisations that play a vital role in the day-to-day life of the UK, with a focus on essential functions.

Page 5 of 25

Principle A1 Governance

iStock.com/BroVector

Appropriate organisational structures, policies, processes and procedures in place to understand, assess and systematically manage security risks to network and information systems supporting essential functions.




Governance through risk management standards

Following a standardised risk management approach can help in achieving good cyber security governance. There are many such standards to choose from. Some of the most well-known are: 

  • ISO 27001

    An Information Security Management System can aid governance of cyber security risk.

     

    An Information Security Management System (ISMS) is a set of policies, procedures, and roles designed to ensure cyber security risks are identified and managed. Traditionally an ISMS is considered to be an information risk management system, however it can be used to manage cyber security risks to essential functions. 

     

    A properly scoped and implemented ISMS can help your organisation to meet requirements your organisation might have to protect essential functions by putting in place policies, procedures, and roles which govern the organisational approach to managing cyber security risks to those functions. 

     

    ISO 27001 is one of many standards you can use to implement an ISMS. If your organisation is intending to use ISO 27001, you should consider which elements will help achieve your organisational objectives - full compliance and certification may be unnecessary.  

     

    Your organisation must incorporate into the ISMS any relevant external requirements, for example direction from a regulator. You should also set appropriate cyber security requirements for your supply chain to ensure their support in achieving your cyber security and resilience objectives (see A4 Supply Chain Security).

  • IEC 62443-2-1:2010

    An industrial automation and control system (IACS) cyber security management system (CSMS) that is relevant to organisations responsible for essential functions in some particular sectors. 

     

    The CSMS defined in IEC 62443-2-1 is designed to build on ISO 27001 & ISO 27002 for IACS environments, with the aim of aligning cyber security risk management with existing safety risk management practices. A management system framework is provided as a baseline, which organisations are encouraged to tailor for their own context.

A1.a Board Direction

You have effective organisational security management led at board level and articulated clearly in corresponding policies.

Not achievedAchieved
At least one of the following statements is true:All the following statements are true:

The security of network and information systems related to the operation of essential function(s) is not discussed or reported on regularly at board-level.

Board-level discussions on the security of network and information systems are based on partial or out-of-date information, without the benefit of expert guidance.

The security of network and information systems supporting your essential function(s) are not driven effectively by the direction set at board-level. 

Senior management or other pockets of the organisation consider themselves exempt from some policies or expect special accommodations to be made.

Your organisation's approach and policy relating to the security of network and information systems supporting the operation of essential function(s) are owned and managed at board-level. These are communicated, in a meaningful way, to risk management decision-makers across the organisation.

Regular board-level discussions on the security of network and information systems supporting the operation of your essential function(s) take place, based on timely and accurate information and informed by expert guidance.

There is a board-level individual who has overall accountability for the security of network and information systems and drives regular discussion at board-level.

Direction set at board-level is translated into effective organisational practices that direct and control the security of the network and information systems supporting your essential functions(s).

The board has the information and understanding needed in order to effectively discuss how the security and resilience of network and information systems contributes to the delivery of essential function(s) and what the potential impact from compromise of those systems would be.

Security is recognised as an important enabler for the resilience of your essential function(s) and considered in all relevant discussions.

A1.b Roles and Responsibilities

Your organisation has established roles and responsibilities for the security of network and information systems at all levels, with clear and well-understood channels for communicating and escalating risks.

Not achievedAchieved
At least one of the following statements is true:All the following statements are true: 

Key roles are missing, left vacant, or fulfilled on an ad-hoc or informal basis.  

Staff are assigned security responsibilities but without adequate authority or resources to fulfil them.  

Staff are unsure what their responsibilities are for the security of the essential function(s).

Key roles and responsibilities for the security of network and information systems supporting your essential function(s) have been identified. These are reviewed regularly to ensure they remain fit for purpose.  

Appropriately capable and knowledgeable staff fill those roles and are given the time, authority, and resources to carry out their duties.  

There is clarity on who in your organisation has overall accountability for the security of the network and information systems supporting your essential function(s).

A1.c Decision-making  

You have senior-level accountability for the security of network and information systems, and delegate decision-making authority appropriately and effectively. Risks to network and information systems related to the operation of the essential function(s) are considered in the context of other organisational risks.

Not achievedAchieved
At least one of the following statements is true:All the following statements are true:

What should be relatively straightforward risk decisions are constantly referred up the chain, or not made.  

Risks are resolved informally (or ignored) at a local level when the use of a more formal risk reporting mechanism would be more appropriate.  

Decision-makers are unsure of what senior management's risk appetite is, or only understand it in vague terms such as "averse" or "cautious". 

Decision-makers are unable to justify their risk management decisions.

Organisational structure causes risk decisions to be made in isolation. (e.g. engineering and IT don't talk to each other about risk).  

Risk priorities are too vague to make meaningful distinctions between them. (e.g. almost all risks are rated 'medium' or 'amber'). 

Senior management have visibility of key risk decisions made throughout the organisation.  

Risk management decision-makers understand their responsibilities for making effective and timely decisions in the context of the risk appetite regarding the essential function(s), as set by senior management.  

Risk management decision-making is delegated and escalated where necessary, across the organisation, to people who have the skills, knowledge, tools and authority they need.  

Risk management decisions are regularly reviewed to ensure their continued relevance and validity.


Published

Reviewed

Version

4.0