Assured Cyber Security Consultancy
This scheme assures providers offering independent consultancy services to organisations with complex, high-risk, or nationally significant cyber security requirements.
In this scheme
Assured Consultancy - Audit and Review Offering
ACSC Audit and Review Companies apply NCSC advice and guidance, alongside other recognised methodologies and frameworks as appropriate to provide expert advice and guidance to Senior Information Risk Owners (SIROs) and business managers. They are responsible for defining and implementing the processes and techniques used to:
- audit compliance with cyber security policies, standards, expert guidance, and relevant legal or regulatory requirements
- review how these policies and standards are applied and implemented within a Customer’s organisation
These audits and reviews are conducted using recognised or standardised methodologies to ensure consistency, reliability, and effectiveness.
Expected Activities
Companies assured under the ACSC Audit and Review Offering are likely to undertake the following (not exhaustive list of) activities:
- Advising Customers on their overall cyber security maturity, identifying areas for improvement based on their sector, business context, risk profile, and applicable regulations, standards, and NCSC guidance.
- Providing guidance on maintaining the relevance and effectiveness of internal and external cyber security standards, policies, and procedures, including the appropriate use of NCSC guidance.
- Advising Customers on meeting and maintaining certification or compliance requirements.
- Reviewing existing cyber security policies and procedures, and recommending updates or improvements where necessary.
- Assessing supporting artefacts such as system designs, risk analyses, security processes, procedures, and security claims provided by Customers or partners, as part of audit activities.
- Conducting audits, checks, and reviews, and producing reports that provide assurance on compliance with internal and / or external cyber security requirements.
- Supporting the development and execution of audit schedules, and liaising with internal auditors, regulatory bodies, lead government departments, and certification authorities.
- Identifying and clearly communicating necessary remediation or corrective actions following audits or reviews. Ensuring that recommendations are appropriately targeted, well-documented, and recorded to support continuous improvement.