Skip to main content
Guidance

Cyber Assessment Framework

The CAF is a collection of cyber security guidance for organisations that play a vital role in the day-to-day life of the UK, with a focus on essential functions.

Page 10 of 25

Principle B1 Service protection policies, processes and procedures

iStock.com/shendart

Proportionate security measures are in place to protect network and information systems supporting essential functions from cyber attack.




People and security 

People can contribute to effective security within their organisation. This NCSC guidance suggests ways in which meaningful discussions can begin and organisations can start developing collaborative polices, drawing out and understanding the workarounds people have developed to help them navigate difficult policies, process or unusable IT. Use your understanding of how people work to develop practical security policies and processes and, wherever possible, reduce the human effort required to comply. 

There are many resources available intended to help organisations decide what their cyber security and resilience protection policies should look like; for example, SANS provide various information security policy templates.

Personnel security 

You should ensure that individuals authorised to access networks and information systems supporting the operation of essential functions are trustworthy. To be fully effective, link personnel security with identity and access control. Further information can be found in NPSA's Personnel and People Security and ISO/IEC 27002. 

Implementing and communicating policies and processes

Implementation of a new or improved cyber security and resilience policy or process requires communication to those under its scope and evaluation of its effectiveness. NPSA has produced some useful guidance on how to embed security behaviour change. 

Effectively communicate the policies and information on how processes and procedures work to everyone who can affect the security of the system, so that they can readily understand the contribution they make and their responsibilities to essential function security and resilience. 

Communication can be achieved through continued security conversations and staff awareness and training programmes. However, it should be noted that having a staff awareness and training programme alone, without an understanding of how people work with security, is unlikely to result in improved compliance with cyber security and resilience policies and processes. Refer to B6. Staff Awareness & Training for further information on effective staff awareness and training programmes. 

Suitable data and metrics should be defined prior to implementation to evaluate the previous condition and assess the impact of the new or updated policy or process. Information may be drawn from security incidents, technical measurements, surveys, customer feedback, etc. 

Improving policies and processes

Cyber security and resilience policies and processes should be designed to be adaptable, to fit the needs of the changing environment. Organisations should regularly review their policies and processes in light of any recorded security breaches so that these documents and the organisation’s security can be continually improved.

B1.a Policy, Process and Procedure Development 

You have developed and continue to improve a set of cyber security and resilience policies, processes and procedures that manage and mitigate the risk of adverse impact on your essential function(s).

Not achievedPartially achievedAchieved
At least one of the following statements is true:All the following statements are true:All the following statements are true:

Your policies, processes and procedures are absent or incomplete.

Policies, processes and procedures are not applied universally or consistently.

People often or routinely circumvent policies, processes and procedures to achieve business objectives.

Your organisation’s security governance and risk management approach has no bearing on your policies, processes and procedures.

System security is totally reliant on users' careful and consistent application of manual security processes.

Policies, processes and procedures have not been reviewed in response to major changes (e.g. technology or regulatory framework), or within a suitable period.

Policies, processes and procedures are not readily available to staff, too detailed to remember, or too hard to understand.

Your policies, processes and procedures document your overarching security governance and risk management approach, technical security practice and specific regulatory compliance.

You review and update policies, processes and procedures in response to major cyber security incidents.

You fully document your overarching security governance and risk management approach, technical security practice and specific regulatory compliance.

Cyber security is integrated and embedded throughout policies, processes and procedures and key performance indicators are reported to your executive management.

Your organisation’s policies, processes and procedures are developed to be practical, usable and appropriate to mitigate the risk of adverse impact to network and information systems supporting your essential function(s).

Policies, processes and procedures that rely on user behaviour are practical, appropriate and achievable.

You review and update policies, processes and procedures at suitably regular intervals to ensure they remain relevant. This is in addition to reviews following a major cyber security incident.

Any changes to the essential function(s) or the threat it faces triggers a review of policies, processes and procedures. 

Your systems are designed so that they remain secure even when user security policies, processes and procedures are not always followed.

B1.b Policy, Process and Procedure Implementation

You have successfully implemented your security policies, processes and procedures and can demonstrate the security benefits achieved.

Not achievedPartially achievedAchieved
At least one of the following statements is true:All the following statements are true:All the following statements are true:

Policies, processes and procedures are ignored or only partially followed.

How your policies support the resilience of your essential function(s) is not well understood.

Staff are unaware of their responsibilities under your policies, processes and procedures.

You do not attempt to detect breaches of policies, processes and procedures.

Policies, processes and procedures lack integration with other organisational policies, processes and procedures.

Your policies, processes and procedures are not well communicated across your organisation.

Most of your policies, processes and procedures are followed and their application is monitored.

Your policies, processes and procedures are integrated with other organisational policies, processes and procedures, including HR assessments of individuals' trustworthiness.

All staff are aware of their responsibilities under your policies, processes and procedures.

All breaches of policies, processes and procedures with the potential to adversely impact the essential function(s) are fully investigated. Other breaches are tracked, assessed for trends and action is taken to understand and address.

All your policies, processes and procedures are followed, their correct application and security effectiveness is evaluated. 

Your policies, processes and procedures are integrated with other organisational policies, processes and procedures, including HR assessments of individuals' trustworthiness. 

Your policies, processes and procedures are effectively and appropriately communicated across all levels of the organisation resulting in good staff awareness of their responsibilities. 

Appropriate action is taken to address all breaches of policies, processes and procedures with potential to adversely impact the essential function(s) including aggregated breaches. 


Published

Reviewed

Version

4.0