Cyber Assessment Framework
The CAF is a collection of cyber security guidance for organisations that play a vital role in the day-to-day life of the UK, with a focus on essential functions.
Pages
Page 20 of 25
Principle D1 Response and recovery planning
Capabilities exist to minimise the adverse impact of a cyber security incident on the operation of essential functions, including the restoration of those function(s) where necessary.
Principle
There are well-defined and tested incident management processes in place, that aim to ensure continuity of essential function(s) in the event of system or service failure. Mitigation activities designed to contain or limit the impact of compromise are also in place.
Description of principle
Incidents will invariably happen. When they do organisations should be prepared to deal with them, and as far as possible, have mechanisms in place that minimise the impact on the essential function.
The particular mechanisms required should be determined as part of the organisation's overall risk management approach. Examples might include things such as DDoS protection, protected power supply, critical system redundancy, rate-limiting access to data or service commands, critical data backup or manual fail-over processes.
Note: Some cyber-related regulation (e.g. the NIS Directive) has mandatory reporting requirements around cyber security incidents that have the potential to affect essential functions. Organisations should make sure that they understand any mandatory incident reporting requirements that apply to them and include such requirements in their incident management planning.
Guidance
The 10 Steps to Cyber Security: Incident Management has concise guidance, but organisations should use other more detailed guidance as and when appropriate. Other authoritative guidance pieces are referenced below.
Preparation - An Incident Response Plan
In addition to meeting the expectations of 10 Steps to Cyber Security, you should ensure that your organisation's incident response plans are grounded in thorough and comprehensive risk assessments. Response plans should prioritise essential functions along with the assets and systems that are required to ensure their continued effective operation, such as operational technologies, or key datasets.
The business continuity implications of any compromise should also be taken into account and your cyber incident response plans should link to other business response functions. You should form a cyber response team that is capable of implementing the plan, with the appropriate skills, tools and reach into other parts of your organisation, such as security monitoring and business continuity.
In practice, the Incident Response function should interoperate with the security monitoring function. The Incident Response function needn't be a dedicated team and some members may have non-response related roles. Collectively, the team should have knowledge of IT security, IT infrastructure and Business Management, any specialist technologies (e.g. Operational Technologies or datacentres), incident reporting requirements, and communications plans.
Your plan should cover all relevant potential incidents. It should be auditable and testable (via exercises) across a range of incident scenarios and should encompass all realistic descriptions of what might constitute an incident and its severity. Your test scenarios should draw on threat intelligence, past incidents, exercises and the ways in which security capabilities (e.g. security monitoring and alerting) would feature in your response options. Your scenarios should also consider incidents that involve suppliers and your wider supply chain e.g. incidents arising through supplier relations or relying on suppliers as part of your response.
These scenarios could include, but is not limited to:
- malware infection
- denial of service
- hacker infiltration
- an insider incident
- an inability to view status of the network or operational system
- emergency patching or antivirus signature roll-out
- system backup and restore
- confirmation of normal operations
The scenarios should be incorporated into exercises, which should be run to test your ability to respond to incidents that could affect the operation of essential functions. These exercises should reflect past experience, red-teaming/scenario planning, or threat intelligence and should draw heavily on your risk assessment, considering all relevant assets and vulnerabilities, especially where they relate to essential functions.
Exercises should record lessons learned, covering governance, roles and internal communication, quality of network and security monitoring data, containment and recovery strategies, or any other factors relevant to their effectiveness. This should integrate with lessons learned activities (see Principle D2 Lessons Learned).
Your plans should work seamlessly with other system management and security functions. Changes and improvements to response plans should reflect changes to these functions and vice versa, where appropriate.
Plans should articulate clear governance frameworks and roles with procedures for reporting to relevant internal or external stakeholders, such as regulators and competent authorities.
Your plan should also set out a comprehensive range of containment, eradication and recovery strategies, specifying how and when they should be used.
Your organisation should be able to describe its own state of readiness, using any criteria or expected standards from regulators or competent authorities, or from your internal governance arrangements, where appropriate.
In order to report coherently on incidents when required, your plan should set out reporting thresholds (i.e. what does and does not need to be reported) and standards (i.e. the level of detail that should be reported) and which authorities to report to.
More detailed guidance on developing an incident response plan, and the underlying capability to implement it, can be found in the NIST Computer Security Incident Handling Guide, CREST publications (see references) or ISO/IEC 27035-1.
Response and Containment
Your organisation's security monitoring function should be capable of alerting with enough detail for a response team to triage and determine the most appropriate response, which might be to investigate further, to take predetermined action, or to take no action. Eventualities not covered in the plan should be dealt with by making risk-based decisions, taking account of factors like potential disruption, cost-effectiveness of response and the need for evidence preservation.
The resilience measures your organisation has in place should support incident response (see Principle B5 Resilient Networks and Systems).
Incidents should be reported to the appropriate internal and external authorities, in line with the relevant reporting thresholds and standards. The response team should be capable of prioritising incidents, according to the potential consequences and possible adverse impact on essential functions, using risk-based methods. These events should be documented, including alerts provided, information passed and decisions taken.
In addition to adhering to mandatory reporting requirements, organisations should seriously consider voluntarily reporting cyber security incidents to the NCSC, who may be able to provide situational awareness, drawing on incident reporting from other victims, as well as response and protective security advice. Assistance may also be sought from Cyber Incident Response (CIR) companies - see CIR scheme.
Further guidance is found in the NIST Computer Security Incident Handling Guide, Part 5 of CREST Computer Security Incident Response Guide or ISO/IEC 27035-1.
Physical resilience
You should have and maintain a strategy for ensuring the continuity of your essential service in the event of a physical failure in the network and information systems. This can be achieved through measures such as contingency plans for critical systems, including clear steps and procedures for common threats, triggers for activation, and recovery time objectives.
You should also consider having documented policies or procedures for coping with major disasters and recovery of capabilities. This could include plans for alternative solutions such as mobile equipment, mobile sites, fail-over sites, etc.
D1.a Response Plan
You have an up-to-date incident response plan that is grounded in a thorough risk assessment that takes account of network and information systems supporting the operation of your essential function(s) and covers a range of incident scenarios.
| Not achieved | Partially Achieved | Achieved |
|---|---|---|
| At least one of the following is true: | All the following statements are true: | All the following statements are true: |
Your incident response plan is not documented. Your incident response plan does not include your organisations identified essential function(s). Your incident response plan is not well understood by relevant staff. | Your incident response plan covers network and information systems supporting your essential function(s). Your incident response plan comprehensively covers scenarios that are focused on likely impacts of known and well understood attacks only. Your incident response plan is understood by all staff who are involved with your organisation's response function. Your incident response plan is documented and shared with all relevant stakeholders. Your incident response plan is readily accessible, even when your organisations IT systems have been adversely affected by an incident. Your incident response plan is regularly reviewed to ensure it remains effective. | Your incident response plan is based on a clear understanding of the security risks to the network and information systems supporting your essential function(s). Your incident response plan is comprehensive (i.e. covers the complete lifecycle of an incident, roles and responsibilities, and reporting) and covers likely impacts of both known attack patterns and of possible attacks, previously unseen. Your incident response plan is documented and integrated with wider organisational business plans and supply chain response plans as well as dependencies on supporting infrastructure (e.g. power, cooling etc). Your incident response plan is communicated and understood by the business areas involved with the operation of your essential function(s). |
D1.b Response and Recovery Capability
You have the capability to enact your incident response plan, including effective limitation of impact on the operation of your essential function(s). During an incident, you have access to timely information on which to base your response decisions.
| Not Achieved | Achieved |
|---|---|
| At least one of the following is true: | All the following statements are true: |
Inadequate arrangements have been made to make the right resources available to implement your response plan. Your response team members are not equipped to make good response decisions and put them into effect. Inadequate back-up mechanisms exist to allow the continued operation of your essential function(s) during an incident. | You understand the resources that will likely be needed to carry out any required response activities, and arrangements are in place to make these resources available. You understand the types of information that will likely be needed to inform response decisions and arrangements are in place to make this information available. Your response team members have the skills and knowledge required to decide on the response actions necessary to limit harm, and the authority to carry them out. Key roles are duplicated, and operational delivery knowledge is shared with all individuals involved in the operations and recovery of the essential function(s). Back-up mechanisms are available that can be readily activated to allow continued operation of your essential function(s), although possibly at a reduced level, if primary network and information systems fail or are unavailable. Arrangements exist to augment your organisation’s incident response capabilities with external support if necessary (e.g. specialist cyber incident responders). |
D1.c Testing and Exercising
Your organisation carries out exercises to test response plans, using past incidents that affected your (and other) organisation, and scenarios that draw on threat intelligence and your risk assessment.
| Not Achieved | Achieved |
|---|---|
| At least one of the following is true: | All the following statements are true: |
Exercises test only a discrete part of the process (e.g. that backups are working), but do not consider all areas. Incident response exercises are not routinely carried out or are carried out in an ad-hoc way. Outputs from exercises are not fed into the organisation's lessons learned process. Exercises do not test all parts of the response cycle. | Exercise scenarios are based on incidents experienced by your and other organisations or are composed using experience or threat intelligence. Exercise scenarios are documented, regularly reviewed, and validated. Exercises are routinely run, with the findings documented and used to refine incident response plans and protective security, in line with the lessons learned. Exercises test all parts of your response cycle relating to your essential function(s) (e.g. restoration of normal function(s) levels). |


