Cyber Assessment Framework
The CAF is a collection of cyber security guidance for organisations that play a vital role in the day-to-day life of the UK, with a focus on essential functions.
Pages
Page 22 of 25
Supplementary information
The Network and Information Systems (NIS) Regulations
The Network and Information Systems (NIS) Regulations, aimed at raising levels of cyber security and resilience of key systems across the UK, came into force in May 2018. The Department for Science, Innovation and Technology (DSIT) is the government department responsible for NIS in the UK. The NCSC has supported the introduction of the NIS regulations in a number of different ways, including the production of the CAF Collection which provides a set of resources for organisations affected by the regulations.
Who is affected by the NIS regulations?
Companies and organisations identified as either Operators of Essential Services (OES), Relevant Digital Service Providers (RDSPs) or Competent Authorities (CAs) are primarily involved. The criteria for identifying OES, RDSPs and the list of CAs in the UK can be found within the NIS Regulations at the link above.
NCSC support to the operation of the UK NIS regulations
The NCSC has the following three roles in support of the operations of the NIS regulations in the UK:
- Single Point of Contact (SPOC) - we are the contact point for engagement with EU partners on NIS, coordinating requests for action or information and collating annual incident statistics.
- CSIRT (Computer Security Incident Response Team) – we are responsible for responding to cyber incidents that have been reported to NIS CAs by OES and RDSPs under the NIS Regulations. Note: any OES or RDSP affected by a cyber incident is strongly encouraged to contact the NCSC directly for advice and support.
- Technical Authority on Cyber Security - the NCSC supports NIS OES, RDSPs and CAs with cyber security advice and guidance and acts as a source of technical expertise.
Most of the NIS CAs have adopted the CAF for use in their sectors.
The NCSC has no regulatory role in NIS. Information about how the NCSC works with cyber regulators, including NIS Competent Authorities is provided below.
Critical National Infrastructure
As recognised in the National Cyber Strategy 2022, cyber threats to UK Critical National Infrastructure (CNI) represent an area of particular concern for HMG, and consequently the cyber security and resilience of the thirteen CNI sectors is a high priority for the NCSC. More information on what constitutes the CNI, including a list of the thirteen CNI sectors, can be found on the website of the NCSC’s partner organisation, the National Protective Security Authority (NPSA).
The robust level of cyber resilience represented by the CAF was designed to be appropriate for managing cyber risks to CNI essential services by organisations designated as CNI operators. The extent to which the use of the CAF by CNI operators may be required is a matter for sector regulators and CNI Lead Government Departments (LGDs).
Cyber and safety
Increasingly, computerised systems are performing vital safety-related functions designed to protect human lives. For example, such systems are controlling the safe operation of industrial sites processing and storing dangerous chemicals, and play a key role in the safety of aviation, rail transportation etc.
Computerised safety systems could, potentially, be adversely affected by a cyber incident – either as a side-effect of a compromise not intended by the perpetrators to affect safety, or as a result of highly targeted cyber-attack, specifically aimed at reducing the effectiveness of safety mechanisms. This is not just a theoretical possibility. There has been at least one well-documented example of a safety-related targeted cyber incident (see the NCSC advisory “TRITON Malware Targeting Safety Controllers”).
Where the possible impact of a safety-related incident is sufficiently serious, certain industrial sites are designated Critical National Infrastructure (CNI). In some cases, where organisations are subject to specific regulation aimed at protecting public safety such as the Control Of Major Accidents & Hazards regulation (COMAH), there may be a regulatory requirement to manage cyber-related risks to safety. Consequently, maintenance of public safety is an essential function for some organisations, and this includes managing the cyber-related risks to safety.
The NCSC CAF has been incorporated in the Health and Safety Executive (HSE) OG86 – Cyber Security for Industrial Automation and Control Systems (IACS). The guidance describes the required cyber security countermeasures to address levels of cyber security risk for OES that fall under the regulatory responsibilities of HSE. The NCSC continues to work with HSE to address higher levels of risk which will be incorporated in future iterations of OG 86.
The UK Civil Aviation Authority (CAA) has produced the Cyber Assessment Framework (CAF) for Aviation, based on the NCSC CAF, and has been designed with scalability and consistency in mind. This allows it to be applied to aviation organisations of varying size and complexity whilst maintaining a consistent approach across different scopes including; safety, security and resilience (see The Cyber Security Oversight Process for Aviation CAP 1753).
Managing cyber-related risks to safety
The successful management of cyber-related risks to safety is based on the same fundamental principles that underpin effective cyber risk management more generally. However, an integrated approach is needed which combines the established good practices of both the security and safety communities. There are recognised challenges associated with achieving such an integrated approach, and the NCSC continues to work with others to develop additional guidance. For example, the NCSC has supported the Institution of Engineering and Technology (IET) in the production of a Code of Practice written for engineers and engineering management to support their understanding of the issues involved in ensuring that the safety responsibilities of an organisation are addressed, in the presence of a threat of a cyber attack.
CAF wider use
The CAF is now being used more widely, beyond the context of cyber regulated sectors described above. The UK Government Cyber Security Strategy 2022-2030 introduced the use of the NCSC CAF as the assurance framework for government, with specific CAF profiles to articulate the outcomes required by government organisations in order to proportionately respond to the varying threats to their most important functions. Adoption of the CAF provides a common framework for government to more effectively understand and manage cyber risk. This cyber security assurance approach for government has replaced the cyber security element of the Departmental Security Health Check (DSHC) and is called GovAssure.
The CAF has also been adopted for use for the local government sector with the Department for Levelling Up, Housing and Communities (DLUHC) taking on the role of the responsible cyber oversight body. A further example sees Welsh Government working with Local Authorities to pilot the implementation of the CAF.
Adopting the CAF allows a cyber oversight body to assess the cyber resilience posture of its sector in a consistent and comparable way to other organisations that operate the UK’s essential services.
Should a cyber oversight body wish to consider if the CAF is appropriate for use within their sector then they are encouraged to contact the NCSC and request advice.
NCSC and regulators
The NCSC is not a regulator. Within the general UK cyber security regulatory environment, including both NIS and GDPR, the NCSC’s aim is to operate as a trusted, expert and impartial advisor to all interested parties.
To help ensure that cyber regulation delivers the intended improvements in cyber security, the NCSC supports cyber regulators in a number of specific ways. For example, we assist by developing cyber security standards and guidance (such as the CAF collection), and by supporting regulators in the use of NCSC-provided resources.
However, in order to maintain the benefits that result from the open and collaborative relationship the NCSC enjoys with many of the organisations that fall under the scope of cyber regulation, some important constraints govern how the NCSC works with cyber regulators. The NCSC has adopted a deliberately restrictive approach to the type of cyber security information that it shares with cyber regulators. This is to ensure that any commercially sensitive information about individual entities acquired in the course of the NCSC’s cyber advisory and incident management work is appropriately protected from disclosure and use for regulatory purposes. (See, for example, the Reporting To Regulators section of the NCSC Incident Management webpage). And, while the NCSC may advise cyber regulators on how to do cyber security assessments against regulatory standards, we do not undertake regulatory assessments on behalf of regulators or provide any advice or assistance on individual regulatory investigations.


