Skip to main content
Guidance

Cyber Assessment Framework

The CAF is a collection of cyber security guidance for organisations that play a vital role in the day-to-day life of the UK, with a focus on essential functions.

Page 12 of 25

Principle B3 Data security

iStock.com/Dilen_ua

Proportionate security measures are in place to protect network and information systems supporting essential functions from cyber attack.



Note

Data supporting the operation of essential functions must be identified in accordance with Principle A3 Asset Management. Important data to protect may include operational data, network traffic, configurations, as well as data that could provide an insight or advantage to an attacker, such as network and information system designs.


Consider applying the NCSC good practice measure for protecting bulk personal data to data supporting the operation of essential functions.

Protecting data in transit

Data in transit may be at risk of attacks such as interception, traffic replay, manipulation or jamming.

Transport Layer Security (TLS) is often used to protect external data connections such as web browser traffic and IPSec is a well-known encryption technology for individual communication links. Where cryptography is deployed to protect communication links, you should protect cryptographic material such as certificates and keys from external or unauthorised access.

Alternative communications links or network paths are recommended for critical data paths.

For cloud services, see our guidance on protecting data in transit.

Protecting data at rest

Wherever data is stored, even temporarily, it may be vulnerable to unauthorised access, tampering or deletion.

You should identify where data supporting the operation of essential functions is stored, including:

  • exports from core operational systems to other business systems

  • on mobile devices

  • removable media

  • in temporary caches

  • in systems used for remote access

You should reduce the unauthorised access, tampering and deletion risks to stored data by limiting the quantity and detail of data held to the minimum necessary for business purposes, especially on devices and media that are more vulnerable to unauthorised access or that could be stolen.

Where dedicated systems and removable media are used, the storage devices can be hardware or software encrypted. You should take suitable measures to physically protect devices and media containing data supporting the operation of essential functions.

Backups remain an essential part of resilience measures and should be appropriately secured.

For cloud services, refer to NCSC cloud security principle 2 on asset protection and resilience.

Protecting data on mobile devices

Mobile devices may be used by an organisation responsible for essential functions, a partner or third-party supplier. Whether owned and managed by the responsible organisation or not, these devices are likely to contain business data. Potentially, data important to the operation of the essential function could be on these devices.

Well-configured and managed, business-owned, devices are preferred to personal or external organisation equipment: refer to the NCSC Device Security Collection for security principles and platform-specific guidance.

It may be possible to gain sufficient assurance that a partner or supplier applies security controls to the same rigour (or better).

In addition to good mobile device management, ensure that mobile devices accessing data supporting service delivery are well monitored.

Secure disposal

Data important to the operation of the essential function is likely to be found on network and information system media and operational equipment, including IT and operational technology (OT) assets. Service management systems, along with network and mobile devices should be considered for secure sanitisation. Some organisations responsible for essential functions may also need to consider the data stored on defunct OT and safety systems.

B3.a Understanding Data

You have a good understanding of data important to the operation of network and information systems supporting your essential function(s), where it is stored, where it travels and how unavailability or unauthorised access, uncontrolled release, modification or deletion would adversely impact the essential function(s). This also applies to third parties storing or accessing data important to the operation of essential function(s).

Not achievedPartially achievedAchieved
At least one of the following statements is true:All of the following statements are true:All of the following statements are true:

You have incomplete knowledge of what data is used by and produced in the operation of network and information systems supporting your essential function(s).

You have not identified the important data on which network and information systems supporting your essential function(s) relies.

You have not identified who has access to data important to the operation of network and information systems supporting your essential function(s).

You have not clearly articulated the impact of data compromise or lack of availability.

You have identified and catalogued all the data important to the operation of network and information systems supporting your essential function(s), or that would assist a threat actor.

You have identified and catalogued who has access to the data important to the operation of network and information systems supporting your essential function(s).

You regularly review location, transmission, quantity and quality of data important to the operation of network and information systems supporting your essential function(s).

You have identified all mobile devices and media that hold data important to the operation of network and information systems supporting your essential function(s).

You understand and document the impact on your essential function(s) of all relevant scenarios, including unauthorised data access, uncontrolled release, modification or deletion, or when authorised users are unable to appropriately access this data.

You occasionally validate these documented impact statements.

 

You have identified and catalogued all the data important to the operation of network and information systems supporting your essential function(s), or that would assist a threat actor.

You have identified and catalogued who has access to the data important to the operation of network and information systems supporting your essential function(s).

You maintain a current understanding of the location, quantity and quality of data important to the operation of network and information systems supporting your essential function(s).

You take steps to remove or minimise unnecessary copies or unneeded historic data.

You have identified all mobile devices and media that may hold data important to the operation of network and information systems supporting your essential function(s).

You maintain a current understanding of the data links used to transmit data that is important to network and information systems supporting your essential function(s).

You understand the context, limitations and dependencies of your important data.

You understand and document the impact on your essential function(s) of all relevant scenarios, including unauthorised data access, uncontrolled release, modification or deletion, or when authorised users are unable to appropriately access this data.

You validate these documented impact statements regularly, at least annually.

B3.b Data in Transit

You have protected the transit of data important to the operation of network and information systems supporting your essential function(s). This includes the transfer of data to third parties.

Not achievedPartially achievedAchieved
At least one of the following statements is true:All the following statements are true:All the following statements are true:

You do not know what all your data links are, or which carry data important to the operation of the essential function(s).

Data important to the operation of the essential function(s) travels without technical protection over non-trusted or openly accessible carriers.

Critical data paths that could fail, be jammed, be overloaded, etc. have no alternative path.

You have identified and protected (effectively and proportionately) all the data links that carry data important to the operation of your essential function(s).

You apply appropriate technical means (e.g. cryptography) to protect data that travels over non-trusted or openly accessible carriers, but you have limited or no confidence in the robustness of the protection applied.

You have identified and protected (effectively and proportionately) all the data links that carry data important to the operation of your essential function(s).

You apply appropriate physical and/or technical means to protect data that travels over non-trusted or openly accessible carriers, with justified confidence in the robustness of the protection applied.

Suitable alternative transmission paths are available where there is a significant risk of impact on the operation of the essential function(s) due to resource limitation (e.g. transmission equipment or function failure, or important data being blocked or jammed).

B3.c Stored Data

You have protected stored soft and hard copy data important to the operation of network and information systems supporting your essential function(s).

Not achievedPartially achievedAchieved
At least one of the following statements is true:All of the following statements are true:All of the following statements are true:

You have no, or limited, knowledge of where data important to the operation of the essential function(s) is stored.

You have not protected vulnerable stored data important to the operation of the essential function(s) in a suitable way.

Backups are incomplete, untested, not adequately secured or could be inaccessible in a disaster recovery or business continuity situation.

All copies of data important to the operation of your essential function(s) are necessary. Where this important data is transferred to less secure systems, the data is provided with limited detail and / or as a read-only copy.

You have applied suitable physical and / or technical means to protect this important stored data from unauthorised access, modification or deletion.

If cryptographic protections are used, you apply suitable technical and procedural means, but you have limited or no confidence in the robustness of the protection applied.

You have suitable, secured backups of data to allow the operation of the essential function(s) to continue should the original data not be available. This may include off-line or segregated backups, or appropriate alternative forms such as paper copies.

All copies of data important to the operation of your essential function(s) are necessary. Where this important data is transferred to less secure systems, the data is provided with limited detail and / or as a read-only copy.

You have applied suitable physical and / or technical means to protect this important stored data from unauthorised access, modification or deletion.

If cryptographic protections are used you apply suitable technical and procedural means, and you have justified confidence in the robustness of the protection applied.

You have suitable, secured backups of data to allow the operation of the essential function(s) to continue should the original data not be available. This may include off-line or segregated backups, or appropriate alternative forms such as paper copies.

Necessary historic or archive data is suitably secured in storage.

B3.d Mobile Data 

You have protected data important to the operation of network and information systems supporting your essential function(s) on mobile devices (e.g. smartphones, tablets and laptops).

Not achievedPartially achievedAchieved
At least one of the following statements is true:All of the following statements are true:All of the following statements are true:

You don’t know which mobile devices may hold data important to the operation of the essential function(s).

You allow data important to the operation of the essential function(s) to be stored on devices not managed by your organisation, or to at least equivalent standard.

Data on mobile devices is not technically secured, or only some is secured.

You know which mobile devices hold data important to the operation of the essential function(s).

Data important to the operation of the essential function(s) is stored on mobile devices only when they have at least the security standard aligned to your overarching security policies.

Data on mobile devices is technically secured.

 

Mobile devices that hold data that is important to the operation of the essential function(s) are catalogued, are under your organisation's control and configured according to best practice for the platform, with appropriate technical and procedural policies in place.

Your organisation can remotely wipe all mobile devices holding data important to the operation of the essential function(s).

You have minimised this data on these mobile devices. Some data may be automatically deleted off mobile devices after a certain period. 

B3.e Media/Equipment Sanitisation 

Before reuse and / or disposal you appropriately sanitise devices, equipment and removable media holding data important to the operation of network and information systems supporting your essential function(s).

Not achievedPartially achievedAchieved
At least one of the following statements is true:All of the following statements are true:All of the following statements are true:
Some or all devices, equipment or removable media that hold data important to the operation of the essential function(s) are reused or disposed of without sanitisation of that data.Data important to the operations of the essential function(s) is removed from all devices, equipment and removable media before reuse and / or disposal.

You catalogue and track all devices that contain data important to the operation of the essential function(s) (whether a specific storage device or one with integral storage).

Data important to the operation of the essential function(s) is removed from all devices, equipment and removable media before reuse and / or disposal using an assured product or service.


Published

Reviewed

Version

4.0