The Cyber Assessment Framework (CAF) provides guidance for organisations responsible for vitally important services and activities. Latest version of the CAF focusses on clarification and consistency between areas of the CAF.
Introduction
Understand what the Cyber Assessment Framework (CAF) guidance is, why it has been produced, what it is for, and how the collection should be used.
Why has the NCSC produced the CAF collection?
Network and information systems and the essential functions they support play a vital role in society, from ensuring the supply of electricity, water, oil and gas, to the provision of healthcare and the safety of passenger and freight transport. Their reliability and security are essential to everyday activities.
As we have seen from numerous cyber security incidents, these systems can be an attractive target for malicious actors, and they can also be susceptible to disruption through single points of failure. The magnitude, frequency and impact of network and information system security incidents is increasing. Historical events such as the 2015 attack on Ukraine’s electricity network and the 2017 Wannacry ransomware attack, together with more recent events such as the US Colonial Pipeline and Israeli water infrastructure attacks clearly highlight the impact that incidents can have..
There is therefore a need to improve the security of network and information systems across the UK, with a particular focus on essential functions which if compromised could potentially cause significant damage to the economy, society, the environment, and individuals’ welfare, including loss of life.
The resources within the CAF collection are intended for the use of organisations that play a vital role in the day-to-day life of the UK, organisations such as those designated as forming part of the Critical National Infrastructure (CNI), or subject to certain types of cyber regulation, including the EU Security of Networks & Information Systems (NIS) regulations, and cyber aspects of safety regulation such as Control Of Major Accident Hazards (COMAH).
(Please note: organisations that are subject to cyber regulation should talk to their regulator before using the NCSC CAF Collection in relation to meeting regulatory requirements.)
What is the CAF collection?
The CAF collection consists of a set of 14 cyber security & resilience principles, together with guidance on using and applying the principles, and the Cyber Assessment Framework (CAF) itself.
Views: 2