Assured Cyber Security Consultancy
This scheme assures providers offering independent consultancy services to organisations with complex, high-risk, or nationally significant cyber security requirements.
In this scheme
Assured Consultancy - Risk Management Offering
ACSC Risk Management Companies apply NCSC cyber security risk management advice and guidance, alongside other recognised methodologies and frameworks as appropriate to meet the Customer’s business needs, objectives and governance structures. The Companies provide unambiguous, well-articulated and tailored advice, guidance, and recommendations that enable Customers to:
- understand and effectively manage their cyber security risks
- make informed, effective and timely risk management decisions
- develop and implement strategies for ongoing risk management and assurance
Expected activities
Companies assured under the ACSC Risk Management Offering are likely to undertake the following (not exhaustive list of) activities:
- Advising Customers on managing cyber security risks using, as a basis, the core concepts and outcomes proposed by the NCSC Risk Management guidance and / or other relevant good practice.
- Helping Customers to develop a realistic view and understanding of the cyber security risks to their business activities and objectives.
- Conducting and documenting risk assessments on behalf of and with Customers, helping them to identify, assess and prioritise cyber security risks in the context of their business, their objectives and priorities.
- Communicating risk assessment outcomes to Customers in ways that support effective decision making.
- Recommending effective risk management approaches and methods for gaining and maintaining assurance.
- Developing and documenting risk management and assurance plans tailored to the Customer’s business and priorities.
- Providing ongoing guidance to support continuous risk management throughout the lifecycle of systems and services.
- Helping Customers adapt their risk management strategies to evolving threats, technologies, and business changes.
- Defining and evaluating governance structures to ensure that they support effective cyber risk management, including roles, responsibilities, and decision-making processes, and the development and effective communication of risk appetite.
- Supporting Customers in developing and maintaining their understanding of cyber threat intelligence, including sourcing and using third-party (e.g. NCSC) assessments and developing internal capabilities such as threat modelling.