Cyber Assessment Framework
The CAF is a collection of cyber security guidance for organisations that play a vital role in the day-to-day life of the UK, with a focus on essential functions.
Pages
Page 11 of 25
Principle B2 Identity and Access Control

Proportionate security measures are in place to protect network and information systems supporting essential functions from cyber attack.
Principle
The organisation understands, documents and manages access to networks and information systems and supporting the operation of essential functions. Users (or automated functions) that can access data or services are appropriately verified, authenticated and authorised.
Description of principle
It is important that the organisation is clear about who (or what in the case of automated functions) has authorisation to interact with the network and information systems supporting an essential function in any way or access associated sensitive data. Access rights granted should be carefully controlled, especially where those rights provide an ability to materially affect the operation of the essential function. Access rights granted should be periodically reviewed and technically removed when no longer required such as when an individual changes role or leaves the organisation.
Users, devices and systems should be appropriately verified, authenticated and authorised before access to data or services is granted. Verification of a user’s identity (they are who they say they are) is a prerequisite for issuing credentials, authentication and access management. For highly privileged access it might be appropriate to include approaches such as multi-factor or hardware authentication.
Unauthorised individuals should be prevented from accessing data or services at all points within the system. This includes system users without the appropriate permissions, unauthorised individuals attempting to interact with any online service or individuals with unauthorised access to user devices (for example if a user device were lost or stolen).
Guidance
Identity and access management
The Introduction to identity and access management sets out security fundamentals that operators should consider in designing and managing identity and access management systems. Identity and access control should be robust enough that essential functions are not adversely affected by unauthorised access.
Physical security
In addition to technical security, organisations should protect physical access to networks and information systems supporting the essential function, to prevent unauthorised access, tampering or data deletion. Some organisations may already have physical security measures in place to comply with non-cyber regulatory frameworks. See NPSA guidance on Control Access for further information.
B2.a Identity Verification, Authentication and Authorisation
You robustly verify, authenticate and authorise access to the network and information systems supporting your essential function(s).
| Not achieved | Partially achieved | Achieved |
|---|---|---|
| At least one of the following statements is true: | All the following statements are true: | All the following statements are true: |
Initial identity verification is not robust enough to provide an acceptable level of confidence of a user’s identity profile. Authorised users and systems with access to networks or information systems on which your essential function(s) depends cannot be individually identified. Unauthorised individuals or devices can access your network or information systems on which your essential function(s) depends. The number of authorised users and systems that have access to your network and information systems are not limited to the minimum necessary. Your approach to authenticating users, devices and systems does not follow up to date best practice. | Your process of initial identity verification is robust enough to provide a reasonable level of confidence of a user’s identity profile before allowing an authorised user access to network and information systems that support your essential function(s). All authorised users and systems with access to network or information systems on which your essential function(s) depends are individually identified and authenticated. The number of authorised users and systems that have access to essential function(s) network and information systems is limited to the minimum necessary. You use additional authentication mechanisms, such as multi-factor (MFA), for privileged access to all network and information systems that operate or support your essential function(s). You individually authenticate and authorise all remote access to all your network and information systems that support your essential function(s). The list of users and systems with access to network and information systems supporting and delivering the essential function(s) is reviewed on a regular basis, at least annually. Your approach to authenticating users, devices and systems follows up to date best practice. | Your process of initial identity verification is robust enough to provide a high level of confidence of a user’s identity profile before allowing an authorised user access to network and information systems that support your essential function(s). Only authorised and individually authenticated users can physically access and logically connect to your network or information systems on which your essential function(s) depends. The number of authorised users and systems that have access to all your network and information systems supporting the essential function(s) is limited to the minimum necessary. You use additional authentication mechanisms, such as multi-factor (MFA), for all user access, including remote access, to all network and information systems that operate or support your essential function(s). The list of users and systems with access to network and information systems supporting and delivering the essential function(s) is reviewed on a regular basis, at least every six months. Your approach to authenticating users, devices and systems follows up to date best practice. |
B2.b Device Management
You fully know and have trust in the devices that are used to access your networks, information systems and data that support your essential function(s).
| Not achieved | Partially achieved | Achieved |
|---|---|---|
| At least one of the following statements is true: | All the following statements are true: | All the following statements are true: |
Users can connect to your essential function(s)'s network and information systems using devices that are not corporately owned and managed. Privileged users can perform privileged operations from devices that are not corporately owned and managed. You have not gained assurance in the security of any third-party devices or networks connected to your systems. Physically connecting a device to your network and information systems gives that device access without device or user authentication. | Only corporately owned and managed devices can access your essential function(s)'s network and information systems. All privileged operations are performed from corporately owned and managed devices. These devices provide sufficient separation, using a risk-based approach, from the activities of standard users. You have sought to understand the security properties of third-party devices and networks before they can be connected to your systems. You have taken appropriate steps to mitigate any risks identified. The act of connecting to a network port or cable does not grant access to any systems. You are able to detect unknown devices being connected to your network and information systems and investigate such incidents. | All privileged operations performed on your network and information systems supporting your essential function(s) are conducted from highly trusted devices, such as Privileged Access Workstations, dedicated solely to those operations. You either obtain independent and professional assurance of the security of third-party devices or networks before they connect to your network and information systems, or you only allow third-party devices or networks that are dedicated to supporting your network and information systems to connect. You perform certificate-based device identity management and only allow known devices to access systems necessary for the operation of your essential function(s). You perform regular scans to detect unknown devices and investigate any findings. |
B2.c Privileged User Management
You closely manage privileged user access to network and information systems supporting the essential function(s).
| Not achieved | Partially achieved | Achieved |
|---|---|---|
| At least one of the following statements is true: | All of the following statements are true: | All of the following statements are true: |
The identities of the individuals with privileged access to your essential function(s) network and information systems (infrastructure, platforms, software, configuration, etc) are not known or not managed. Privileged user access to your essential function(s) network and information systems is via weak authentication mechanisms (e.g. only simple passwords). The list of privileged users has not been reviewed recently (e.g. within the last 12 months). Privileged user access is granted on a system-wide basis rather than by role or function(s). Privileged user access to your essential function(s) is via generic, shared or default name accounts. Where there are “always on” terminals which can perform privileged actions (such as in a control room), there are no additional controls (e.g. physical controls) to ensure access is appropriately restricted. There is no logical separation between roles that an individual may have and hence the actions they perform. (e.g. access to corporate email and privilege user actions). | All privileged user access to your network and information systems requires strong authentication, such as multi-factor (MFA). The identities of the individuals with privileged access to your essential function(s) network and information systems (infrastructure, platforms, software, configuration, etc) are known and managed. This includes third parties. Activity by privileged users is routinely reviewed and validated. (e.g. at least annually). Privileged users are only granted specific privileged user access rights which are essential to their business role or function. | Privileged user access to your essential function(s) systems is carried out from dedicated separate accounts that are closely monitored and managed. The issuing of temporary, time-bound rights for privileged user access and / or external third-party support access is in place. Privileged user access rights are regularly reviewed and always updated as part of your joiners, movers and leavers process. All privileged user activity is routinely reviewed, validated and recorded for offline analysis and investigation. |
B2.d Identity and Access Management (IdAM)
You closely manage and maintain identity and access control for users, devices and systems accessing the network and information systems supporting the essential function(s).
| Not achieved | Partially achieved | Achieved |
|---|---|---|
| At least one of the following statements is true: | All of the following statements are true: | All of the following statements are true: |
Greater access rights are granted than necessary. Identity validation and requirement for access of a user, device or systems is not carried out. User access rights are not reviewed when users change roles. User access rights remain active when users leave your organisation. Access rights granted to devices or systems to access other devices and systems are not reviewed on a regular basis (at least annually). | You follow a robust procedure to verify each user and issue the minimum required access rights. You regularly review access rights and those no longer needed are revoked. User access rights are reviewed when users change roles via your joiners, leavers and movers process. All user, device and system access to the systems supporting the essential function(s) is logged and monitored, but it is not compared to other log data or access records. | You follow a robust procedure to verify each user and issue the minimum required access rights, and the application of the procedure is regularly audited. User access rights are reviewed both when people change roles via your joiners, leavers and movers process and at regular intervals - at least annually. All user, device and systems access to the systems supporting the essential function(s) is logged and monitored. You regularly review access logs and correlate this data with other access records and expected activity. Attempts by unauthorised users, devices or systems to connect to the systems supporting the essential function(s) are alerted, promptly assessed and investigated. |
Additional information
- NPSA Control Access
- RITICS Management of ICS / OT field devices
- NIST SP800-82
- IEC 62443 / ISA 99 3-3
- ISA 62443-2-1
- ISA 99 (Part 4)
- ISO/IEC 27001 / 27002
- CISA Identifying and Mitigating Living Off the Land Techniques
- CISA Implementing Phishing-Resistant MFA


