Cyber Assessment Framework
The CAF is a collection of cyber security guidance for organisations that play a vital role in the day-to-day life of the UK, with a focus on essential functions.
Pages
Page 5 of 25
Principle A1 Governance
Appropriate organisational structures, policies, processes and procedures in place to understand, assess and systematically manage security risks to network and information systems supporting essential functions.
Principle
The organisation has appropriate management policies, processes and procedures in place to govern its approach to the security of network and information systems.
Description of principle
Effective security of network and information systems should be driven by organisational management and corresponding policies and practices. There should be clear governance structures in place with well-defined lines of responsibility and accountability for the security of network and information systems.
Senior management should clearly articulate unacceptable impacts to the business (often called risk appetite), which should take into account the organisation’s role in the operation of essential functions, so decision makers at all levels can make informed decisions about risk without constantly referring decisions up the governance chain.
There should be an individual who holds overall responsibility and is accountable for security. This individual is empowered and accountable for decisions regarding how essential functions are protected. For small organisations, the governance structure can be very simple.
Guidance
Your organisation's approach to security governance needs to be an appropriate fit for your organisation. Good security governance is integrated with your business's usual decision making structures and processes.
Decisions about risk can be made at all levels of your organisation when delegated effectively to people with the right security, business and technical knowledge, skills and experience. Clear lines of communication are also necessary.
Governance through risk management standards
Following a standardised risk management approach can help in achieving good cyber security governance. There are many such standards to choose from. Some of the most well-known are:
-
ISO 27001
An Information Security Management System can aid governance of cyber security risk.
An Information Security Management System (ISMS) is a set of policies, procedures, and roles designed to ensure cyber security risks are identified and managed. Traditionally an ISMS is considered to be an information risk management system, however it can be used to manage cyber security risks to essential functions.
A properly scoped and implemented ISMS can help your organisation to meet requirements your organisation might have to protect essential functions by putting in place policies, procedures, and roles which govern the organisational approach to managing cyber security risks to those functions.
ISO 27001 is one of many standards you can use to implement an ISMS. If your organisation is intending to use ISO 27001, you should consider which elements will help achieve your organisational objectives - full compliance and certification may be unnecessary.
Your organisation must incorporate into the ISMS any relevant external requirements, for example direction from a regulator. You should also set appropriate cyber security requirements for your supply chain to ensure their support in achieving your cyber security and resilience objectives (see A4 Supply Chain Security).
-
IEC 62443-2-1:2010
An industrial automation and control system (IACS) cyber security management system (CSMS) that is relevant to organisations responsible for essential functions in some particular sectors.
The CSMS defined in IEC 62443-2-1 is designed to build on ISO 27001 & ISO 27002 for IACS environments, with the aim of aligning cyber security risk management with existing safety risk management practices. A management system framework is provided as a baseline, which organisations are encouraged to tailor for their own context.
A1.a Board Direction
You have effective organisational security management led at board level and articulated clearly in corresponding policies.
| Not achieved | Achieved |
|---|---|
| At least one of the following statements is true: | All the following statements are true: |
The security of network and information systems related to the operation of essential function(s) is not discussed or reported on regularly at board-level. Board-level discussions on the security of network and information systems are based on partial or out-of-date information, without the benefit of expert guidance. The security of network and information systems supporting your essential function(s) are not driven effectively by the direction set at board-level. Senior management or other pockets of the organisation consider themselves exempt from some policies or expect special accommodations to be made. | Your organisation's approach and policy relating to the security of network and information systems supporting the operation of essential function(s) are owned and managed at board-level. These are communicated, in a meaningful way, to risk management decision-makers across the organisation. Regular board-level discussions on the security of network and information systems supporting the operation of your essential function(s) take place, based on timely and accurate information and informed by expert guidance. There is a board-level individual who has overall accountability for the security of network and information systems and drives regular discussion at board-level. Direction set at board-level is translated into effective organisational practices that direct and control the security of the network and information systems supporting your essential functions(s). The board has the information and understanding needed in order to effectively discuss how the security and resilience of network and information systems contributes to the delivery of essential function(s) and what the potential impact from compromise of those systems would be. Security is recognised as an important enabler for the resilience of your essential function(s) and considered in all relevant discussions. |
A1.b Roles and Responsibilities
Your organisation has established roles and responsibilities for the security of network and information systems at all levels, with clear and well-understood channels for communicating and escalating risks.
| Not achieved | Achieved |
|---|---|
| At least one of the following statements is true: | All the following statements are true: |
Key roles are missing, left vacant, or fulfilled on an ad-hoc or informal basis. Staff are assigned security responsibilities but without adequate authority or resources to fulfil them. Staff are unsure what their responsibilities are for the security of the essential function(s). | Key roles and responsibilities for the security of network and information systems supporting your essential function(s) have been identified. These are reviewed regularly to ensure they remain fit for purpose. Appropriately capable and knowledgeable staff fill those roles and are given the time, authority, and resources to carry out their duties. There is clarity on who in your organisation has overall accountability for the security of the network and information systems supporting your essential function(s). |
A1.c Decision-making
You have senior-level accountability for the security of network and information systems, and delegate decision-making authority appropriately and effectively. Risks to network and information systems related to the operation of the essential function(s) are considered in the context of other organisational risks.
| Not achieved | Achieved |
|---|---|
| At least one of the following statements is true: | All the following statements are true: |
What should be relatively straightforward risk decisions are constantly referred up the chain, or not made. Risks are resolved informally (or ignored) at a local level when the use of a more formal risk reporting mechanism would be more appropriate. Decision-makers are unsure of what senior management's risk appetite is, or only understand it in vague terms such as "averse" or "cautious". Decision-makers are unable to justify their risk management decisions. Organisational structure causes risk decisions to be made in isolation. (e.g. engineering and IT don't talk to each other about risk). Risk priorities are too vague to make meaningful distinctions between them. (e.g. almost all risks are rated 'medium' or 'amber'). | Senior management have visibility of key risk decisions made throughout the organisation. Risk management decision-makers understand their responsibilities for making effective and timely decisions in the context of the risk appetite regarding the essential function(s), as set by senior management. Risk management decision-making is delegated and escalated where necessary, across the organisation, to people who have the skills, knowledge, tools and authority they need. Risk management decisions are regularly reviewed to ensure their continued relevance and validity. |
Additional information
- NPSA secure business
- NPSA Good Governance
- ISO/IEC 27001
- ISO/IEC 27002
- ISO/IEC 27019
- IEC 62443-2-1:2010
- NIST SP800-53
- NIST SP800-82


