Guidance
Cyber Assessment Framework
The CAF is a collection of cyber security guidance for organisations that play a vital role in the day-to-day life of the UK, with a focus on essential functions.
Pages
Page 19 of 25
CAF Objective D - Minimising the impact of cyber security incidents
iStock.com/vectorot
Capabilities exist to minimise the adverse impact of a cyber security incident on the operation of essential function(s), including the restoration of those function(s) where necessary.
Principle: D1 Response and Recovery Planning
-
There are well-defined and tested incident management processes in place, that aim to ensure continuity of essential function(s) in the event of system or service failure. Mitigation activities designed to contain or limit the impact of compromise are also in place.
Principle: D2 Lessons Learned
-
When an incident occurs, steps are taken to understand its causes and to ensure remediating action is taken to protect against future incidents.