Cyber Assessment Framework
The CAF is a collection of cyber security guidance for organisations that play a vital role in the day-to-day life of the UK, with a focus on essential functions.
Pages
Page 10 of 25
Principle B1 Service protection policies, processes and procedures
Proportionate security measures are in place to protect network and information systems supporting essential functions from cyber attack.
Principle
The organisation defines, implements, communicates and enforces appropriate policies, processes and procedures that direct its overall approach to securing systems and data that support the operation of essential functions.
Description of principle
The organisation’s approach to securing network and information systems that support essential functions should be defined in a set of comprehensive security policies with associated processes and procedures. It is essential that these policies, processes and procedures are more than just a paper exercise and steps must be taken to ensure that they are well described, communicated and effectively implemented.
Policies, processes and procedures should be written with the intended recipient community in mind. For example, the message or direction communicated to IT staff will be different from that communicated to senior managers. There should be mechanisms in place to validate the implementation and effectiveness of the policies, processes and procedures where these are relied upon for the security of the essential function. Such mechanisms should also support an organisational ability to enforce compliance when necessary.
To be effective, cyber security and resilience policies, processes and procedures need to be realistic, i.e. based on a clear understanding of the way people act and make decisions in the workplace, particularly in relation to security. If they are developed without this understanding there is a significant risk that service protection policies, processes and procedures will be routinely circumvented as people use work-arounds and shortcuts to achieve their work objectives.
Guidance
Developing policies, processes and procedures
The policies, processes and procedures needed by an organisation depend upon its function and should integrate with the organisation’s approach to governance and risk management. Organisations responsible for essential functions should have a range of policies, processes and procedures, including:
-
An organisational security or service protection policy: endorsed by senior management, this high-level policy should include the organisation’s overarching approach to governing security and managing risks, the organisation’s aims and intents for security and what is of key concern.
-
Supporting policies, processes and procedures: contextual lower-level definitions controlling, directing and communicating organisational security practice.
-
Compliance policies and processes for sector regulations, standards, etc.: specific policies and processes appropriate to the compliance regime; these may be defined by the regulation, standard, etc. For example, to comply with ISO/IEC 27001, organisations should have in place certain security policies and procedures relevant to what the organisation does, how it does it, and what their ISO/IEC 27001 information security management system covers (see ISO/IEC 27002 for detail).
People and security
People can contribute to effective security within their organisation. This NCSC guidance suggests ways in which meaningful discussions can begin and organisations can start developing collaborative polices, drawing out and understanding the workarounds people have developed to help them navigate difficult policies, process or unusable IT. Use your understanding of how people work to develop practical security policies and processes and, wherever possible, reduce the human effort required to comply.
There are many resources available intended to help organisations decide what their cyber security and resilience protection policies should look like; for example, SANS provide various information security policy templates.
Personnel security
You should ensure that individuals authorised to access networks and information systems supporting the operation of essential functions are trustworthy. To be fully effective, link personnel security with identity and access control. Further information can be found in NPSA's Personnel and People Security and ISO/IEC 27002.
Implementing and communicating policies and processes
Implementation of a new or improved cyber security and resilience policy or process requires communication to those under its scope and evaluation of its effectiveness. NPSA has produced some useful guidance on how to embed security behaviour change.
Effectively communicate the policies and information on how processes and procedures work to everyone who can affect the security of the system, so that they can readily understand the contribution they make and their responsibilities to essential function security and resilience.
Communication can be achieved through continued security conversations and staff awareness and training programmes. However, it should be noted that having a staff awareness and training programme alone, without an understanding of how people work with security, is unlikely to result in improved compliance with cyber security and resilience policies and processes. Refer to B6. Staff Awareness & Training for further information on effective staff awareness and training programmes.
Suitable data and metrics should be defined prior to implementation to evaluate the previous condition and assess the impact of the new or updated policy or process. Information may be drawn from security incidents, technical measurements, surveys, customer feedback, etc.
Improving policies and processes
Cyber security and resilience policies and processes should be designed to be adaptable, to fit the needs of the changing environment. Organisations should regularly review their policies and processes in light of any recorded security breaches so that these documents and the organisation’s security can be continually improved.
B1.a Policy, Process and Procedure Development
You have developed and continue to improve a set of cyber security and resilience policies, processes and procedures that manage and mitigate the risk of adverse impact on your essential function(s).
| Not achieved | Partially achieved | Achieved |
|---|---|---|
| At least one of the following statements is true: | All the following statements are true: | All the following statements are true: |
Your policies, processes and procedures are absent or incomplete. Policies, processes and procedures are not applied universally or consistently. People often or routinely circumvent policies, processes and procedures to achieve business objectives. Your organisation’s security governance and risk management approach has no bearing on your policies, processes and procedures. System security is totally reliant on users' careful and consistent application of manual security processes. Policies, processes and procedures have not been reviewed in response to major changes (e.g. technology or regulatory framework), or within a suitable period. Policies, processes and procedures are not readily available to staff, too detailed to remember, or too hard to understand. | Your policies, processes and procedures document your overarching security governance and risk management approach, technical security practice and specific regulatory compliance. You review and update policies, processes and procedures in response to major cyber security incidents. | You fully document your overarching security governance and risk management approach, technical security practice and specific regulatory compliance. Cyber security is integrated and embedded throughout policies, processes and procedures and key performance indicators are reported to your executive management. Your organisation’s policies, processes and procedures are developed to be practical, usable and appropriate to mitigate the risk of adverse impact to network and information systems supporting your essential function(s). Policies, processes and procedures that rely on user behaviour are practical, appropriate and achievable. You review and update policies, processes and procedures at suitably regular intervals to ensure they remain relevant. This is in addition to reviews following a major cyber security incident. Any changes to the essential function(s) or the threat it faces triggers a review of policies, processes and procedures. Your systems are designed so that they remain secure even when user security policies, processes and procedures are not always followed. |
B1.b Policy, Process and Procedure Implementation
You have successfully implemented your security policies, processes and procedures and can demonstrate the security benefits achieved.
| Not achieved | Partially achieved | Achieved |
|---|---|---|
| At least one of the following statements is true: | All the following statements are true: | All the following statements are true: |
Policies, processes and procedures are ignored or only partially followed. How your policies support the resilience of your essential function(s) is not well understood. Staff are unaware of their responsibilities under your policies, processes and procedures. You do not attempt to detect breaches of policies, processes and procedures. Policies, processes and procedures lack integration with other organisational policies, processes and procedures. Your policies, processes and procedures are not well communicated across your organisation. | Most of your policies, processes and procedures are followed and their application is monitored. Your policies, processes and procedures are integrated with other organisational policies, processes and procedures, including HR assessments of individuals' trustworthiness. All staff are aware of their responsibilities under your policies, processes and procedures. All breaches of policies, processes and procedures with the potential to adversely impact the essential function(s) are fully investigated. Other breaches are tracked, assessed for trends and action is taken to understand and address. | All your policies, processes and procedures are followed, their correct application and security effectiveness is evaluated. Your policies, processes and procedures are integrated with other organisational policies, processes and procedures, including HR assessments of individuals' trustworthiness. Your policies, processes and procedures are effectively and appropriately communicated across all levels of the organisation resulting in good staff awareness of their responsibilities. Appropriate action is taken to address all breaches of policies, processes and procedures with potential to adversely impact the essential function(s) including aggregated breaches. |
Additional information
- NPSA Embedding Security Behaviour Change
- NPSA's Personnel and People Security
- SANS Security Policy Templates
- NIST SP800-82
- IEC 62443 / ISA99 2-1
- ISO/IEC 27001/27002


