Cyber Assessment Framework
The CAF is a collection of cyber security guidance for organisations that play a vital role in the day-to-day life of the UK, with a focus on essential functions.
Pages
Page 24 of 25
CAF Terms and Definitions
Guide to the key terms and associated definitions used within the NCSC Cyber Assessment Framework (CAF) Version 4.0
Introduction
This document serves as a comprehensive guide to the key terms and associated definitions used within the NCSC Cyber Assessment Framework (CAF) Version 3.2. It has been created to provide an understanding of what particular terms mean within the CAF.
This document will be periodically updated as new terms and definitions are introduced into the CAF and completely reviewed upon publication of each new version of the CAF.
To facilitate ease of use the terms and associated definitions in this document have been organised alphabetically. Each term is supported with a definition that captures the intended meaning of the term to support the CAF.
It is recommended that before these CAF specific Terms and Definitions are referred to, the NCSC Glossary should be consulted. The NCSC Glossary contains definitions for common cyber security terms and is the primary source of cyber security definitions.
Scope
This document covers a range of terms used within the NCSC’s CAF version 3.2. As new versions of the CAF are created, this document will be updated accordingly to reflect any changes. Where acronyms are used within the CAF and not accompanied by an appropriate definition they will be covered here. This document is not exhaustive and covers what we believe are appropriate terms. If there are any further definitions of terms that you believe should be included or are terms you do not understand please contact NCSC via the Support to Regulation Team.
Purpose
The purpose of this document is to provide readers with an understanding as to what the terms used within the accompanying CAF mean. Outside of the CAF some terms have various meanings depending on the context they are used, so this document has been created to clear up any potential confusion and to define how these terms are to be used with relation to the CAF.
A
Performed as needed but not regularly or periodically.
Refer to Privileged Operation(s)
Storage of data that is no longer needed as normal business as usual activities but still provides or could provide some value in the future.
A product or service that has normally been independently assessed against a set of standards. This provides the organisation with extra confidence that the service or product is effective when compared with a non-assured service or product.
The sum of an organisation’s vulnerabilities, pathways or methods that can be used by threat actors to facilitate an attack.
A way of verifying the identity of a user, process, or device, often as a prerequisite to allowing access to resources in an information system or network.
B
A hardware or software configuration built to a certain specification normally based on a balance of security and usability.
An organisation’s ability to maintain essential functions after an adverse event.
C
Highly skilled individuals or groups with ample resources, capable of executing sophisticated cyber attacks, often targeting specific objectives.
Command and Control are techniques that adversaries may use to communicate with systems under their control within a victim network. Adversaries commonly attempt to mimic normal, expected traffic to avoid detection. There are many ways an adversary can establish command and control with various levels of stealth depending on the victim’s network structure and defences.
When the content of data is used to exploit a vulnerability or adversely affect the victim system or network.
A device managed by an organisation normally through some form of mobile device management solution.
A device owned by the organisation but provided to an employee for use.
Data that the essential function(s) relies upon, with a sense of urgency and immediacy, to operate in a safe and secure manner. Without critical data the essential function(s) will fail quickly. It also includes information that would assist a threat actor to prosecute an attack on the essential function(s).
Systems that the essential function relies upon to operate in a safe and secure manner.
D
Please see data links.
The route data takes when moving form source to destination.
The organisation of data to ensure it appears similar across all fields and records.
Please see data links.
Relationships or interconnections between systems, processes and workflows. Often an asset is reliant or dependent upon another asset or assets for its functionality, performance and security.
A method of maintaining or re-establishing essential functions after a disaster has occurred.
A digital subset of an organisation.
E
Defined in legislation as: “essential service” means a service which is essential for the maintenance of critical societal or economic activities.
Critical activities performed by network and information systems. These functions are vital for the provision of both essential services and digital services.
A connection to a network not controlled by the organisation such as the internet.
H
A system’s physical components.
Data about past events.
I
The identity and attributes a user claims to have or be.
The process of proving an individual’s claimed identity.
A piece of hardware and/or software that detects intrusions within an organisation’s digital networks.
Data that the essential function relies upon to operate in a safe and secure manner. There is a less emphasis on the sense of urgency and immediacy.
Indicators of Compromise (IoCs) are observable artefacts or a collection of artefacts relating to a compromise. Examples of IoCs are tactics, techniques, procedures (TTPs), domain names, IP addresses, hash values and other network and host artefacts such as the creation of registry key values.
A lack of formal requirements or time-based review points.
A property whereby data has not been altered in an unauthorised manner since it was created, transmitted, or stored.
The digital backbone of an organisation. It's necessary for monitoring, managing, and securing core functions such as email, finance, human resources, and other applications in the organisations on-premises infrastructure and cloud. This is separate from OT which can be found later in this document.
K
A quantifiable measure used to evaluate the success of an organization, employee, action etc.
A position or responsibility within an organisation that holds significant importance and influence in achieving goals and objectives.
L
A digital record of an activity or event taking place.
The separation of different networks or hosts into subnets and/or zones whilst allowing these to be present on the same piece of hardware or to physically connect.
M
Refer to Privileged Operation(s)
Authentication using two or more factors. Factors include: Something you know, Something you have, Something you are
N
Refer to Key Role
Limits that define where the network begins or ends. This may often be defined by routers, firewalls etc.
- an electronic communications network within the meaning of section 32(1) of the Communications Act 2003;
- any device or group of interconnected or related devices, one or more of which, pursuant to a program, perform automatic processing of digital data; or
- digital data stored, processed, retrieved or transmitted by elements covered under paragraph (a) or (b) for the purposes of their operation, use, protection and maintenance.
O
Analysis of data outside of a live system. This is normally done in a specifically created environment.
P
The actions an account can take for example read, write or execute.
An account that can perform privileged operations.
Refer to Privileged Operation(s)
An action that could have a significant impact on the system.
A user that is authorised (and therefore, trusted) to perform privileged operations that standard users are not authorised to perform.
R
Access to an asset normally data is limited to viewing only.
A practice of rigorously challenging the cyber security of organisation normally with a specific goal in mind.
The response cycle is the series of procedures executed in the event of a security incident.
The data or information an account can access when access is granted to a system.
The process of discovering the source of a problem or issue in order to identify appropriate solutions.
S
A change in the normal operations of a given entity that involves the security of said entity.
Portion of a network or host that has specific security requirements.
Segregation involves developing and enforcing a ruleset for controlling the communications between specific hosts, services and networks.
Computer programs, applications and associated data that may be dynamically written or modified during execution. For the purposes of the CAF the term software includes firmware and code.
A user/account that is used for day-to-day activities and that does not have elevated permissions (Look to Privileged User/s for more information). The same user may have both a standard account for day-to-day use and a privileged account to perform more sensitive and privileged actions.
The undermining of power and authority of an established system or organisation.
A system normally software or firmware that receives regular updates or patches for vulnerabilities, bugs, defects or performance from the vendor.
T
Discussion based sessions where responses to a hypothetical event or incident are discussed. These are used to simulate the response to a real incident.
Rights provided to an account for a specific, limited period of time.
Any circumstance or event with the potential to adversely impact organisational operations (including mission, functions, image, or reputation), organisational assets, or individuals through an information system via unauthorised access, destruction, disclosure, modification of information, and/or denial of service. Also, the potential for a threat-source to successfully exploit a particular information system vulnerability.
Process of formally evaluating the degree of threat to an information system or enterprise and describing the nature of the threat
U
An individual or (system) process authorised to access a network and information system.
Please refer ‘Introduction to the CAF Appendix E’ for an appropriate description and explanation.
Sources
The below sources have been used to help build the above definitions where appropriate but have not been used exclusively. Where the definition at one of the below sources either isn’t present or isn’t appropriate a definition has been created within the NCSC Support to Regulation Team to best get across the meaning of the term used with relation to the CAF. For example, the definition of Malware at the below sources wasn’t deemed appropriate, so a definition tailored to the CAF was used here.


