Skip to main content
Guidance

Cyber Assessment Framework

The CAF is a collection of cyber security guidance for organisations that play a vital role in the day-to-day life of the UK, with a focus on essential functions.

Page 20 of 25

Principle D1 Response and recovery planning

iStock.com/Mykyta Dolmatov

Capabilities exist to minimise the adverse impact of a cyber security incident on the operation of essential functions, including the restoration of those function(s) where necessary.




Response and Containment 

Your organisation's security monitoring function should be capable of alerting with enough detail for a response team to triage and determine the most appropriate response, which might be to investigate further, to take predetermined action, or to take no action. Eventualities not covered in the plan should be dealt with by making risk-based decisions, taking account of factors like potential disruption, cost-effectiveness of response and the need for evidence preservation. 

The resilience measures your organisation has in place should support incident response (see Principle B5 Resilient Networks and Systems). 

Incidents should be reported to the appropriate internal and external authorities, in line with the relevant reporting thresholds and standards. The response team should be capable of prioritising incidents, according to the potential consequences and  possible adverse impact on essential functions, using risk-based methods. These events should be documented, including alerts provided, information passed and decisions taken. 

In addition to adhering to mandatory reporting requirements, organisations should seriously consider voluntarily reporting cyber security incidents to the NCSC, who may be able to provide situational awareness, drawing on incident reporting from other victims, as well as response and protective security advice. Assistance may also be sought from Cyber Incident Response (CIR) companies - see CIR scheme. 

Further guidance is found in the NIST Computer Security Incident Handling Guide, Part 5 of CREST Computer Security Incident Response Guide or ISO/IEC 27035-1.

Physical resilience 

You should have and maintain a strategy for ensuring the continuity of your essential service in the event of a physical failure in the network and information systems. This can be achieved through measures such as contingency plans for critical systems, including clear steps and procedures for common threats, triggers for activation, and recovery time objectives. 

You should also consider having documented policies or procedures for coping with major disasters and recovery of capabilities. This could include plans for alternative solutions such as mobile equipment, mobile sites, fail-over sites, etc.

D1.a Response Plan

You have an up-to-date incident response plan that is grounded in a thorough risk assessment that takes account of network and information systems supporting the operation of your essential function(s) and covers a range of incident scenarios.

Not achievedPartially AchievedAchieved
At least one of the following is true:All the following statements are true:All the following statements are true:

Your incident response plan is not documented. 

Your incident response plan does not include your organisations identified essential function(s). 

Your incident response plan is not well understood by relevant staff. 

Your incident response plan covers network and information systems supporting your essential function(s). 

Your incident response plan comprehensively covers scenarios that are focused on likely impacts of known and well understood attacks only. 

Your incident response plan is understood by all staff who are involved with your organisation's response function. 

Your incident response plan is documented and shared with all relevant stakeholders.

Your incident response plan is readily accessible, even when your organisations IT systems have been adversely affected by an incident.

Your incident response plan is regularly reviewed to ensure it remains effective.

Your incident response plan is based on a clear understanding of the security risks to the network and information systems supporting your essential function(s). 

Your incident response plan is comprehensive (i.e. covers the complete lifecycle of an incident, roles and responsibilities, and reporting) and covers likely impacts of both known attack patterns and of possible attacks, previously unseen. 

Your incident response plan is documented and integrated with wider organisational business plans and supply chain response plans as well as dependencies on supporting infrastructure (e.g. power, cooling etc). 

Your incident response plan is communicated and understood by the business areas involved with the operation of your essential function(s).

D1.b Response and Recovery Capability

You have the capability to enact your incident response plan, including effective limitation of impact on the operation of your essential function(s). During an incident, you have access to timely information on which to base your response decisions.

Not AchievedAchieved
At least one of the following is true:All the following statements are true:

Inadequate arrangements have been made to make the right resources available to implement your response plan. 

Your response team members are not equipped to make good response decisions and put them into effect. 

Inadequate back-up mechanisms exist to allow the continued operation of your essential function(s) during an incident.

You understand the resources that will likely be needed to carry out any required response activities, and arrangements are in place to make these resources available. 

You understand the types of information that will likely be needed to inform response decisions and arrangements are in place to make this information available. 

Your response team members have the skills and knowledge required to decide on the response actions necessary to limit harm, and the authority to carry them out. 

Key roles are duplicated, and operational delivery knowledge is shared with all individuals involved in the operations and recovery of the essential function(s). 

Back-up mechanisms are available that can be readily activated to allow continued operation of your essential function(s), although possibly at a reduced level, if primary network and information systems fail or are unavailable. 

Arrangements exist to augment your organisation’s incident response capabilities with external support if necessary (e.g. specialist cyber incident responders).

D1.c Testing and Exercising

Your organisation carries out exercises to test response plans, using past incidents that affected your (and other) organisation, and scenarios that draw on threat intelligence and your risk assessment.

Not AchievedAchieved
At least one of the following is true:All the following statements are true: 

Exercises test only a discrete part of the process (e.g. that backups are working), but do not consider all areas. 

Incident response exercises are not routinely carried out or are carried out in an ad-hoc way. 

Outputs from exercises are not fed into the organisation's lessons learned process. 

Exercises do not test all parts of the response cycle.

Exercise scenarios are based on incidents experienced by your and other organisations or are composed using experience or threat intelligence. 

Exercise scenarios are documented, regularly reviewed, and validated. 

Exercises are routinely run, with the findings documented and used to refine incident response plans and protective security, in line with the lessons learned.  

Exercises test all parts of your response cycle relating to your essential function(s) (e.g. restoration of normal function(s) levels).


Published

Reviewed

Version

4.0