CYBER ASSESSMENT FRAMEWORK (CAF)
To comply with the requirements of the Civil Contingency Act 2007 (the “Act”), a designated Operator of Essential Services (“OES”) must take appropriate and proportionate technical and organisational measures to manage the risks to the security of network and information systems, which support the delivery of essential services.
The Cyber Assessment Framework (“CAF”) was developed in accordance with section 54 of the Act, to provide guidance to OESs and particularly, to provide the GRA with the capability to assess the extent to which OESs are achieving the required levels of cyber security. The CAF is based on the UK’s framework and is used as a tool whereby the GRA liaises with the different OESs in order to tailor the CAF to each sector profile.
The general CAF is based on the following four main objectives:
A: Managing security risk
B: Protecting against cyber attack
C: Detecting cyber security incidents
D: Minimising the impact of cyber security incidents
The CAF is further broken down into 14 specific principles that are based on sets of indicators of good practice. These are:
|
Principles |
Objectives |
|
1. Governance |
Managing Security Risk |
|
2. Risk Management |
|
|
3. Asset Management |
|
|
4. Supply Chain |
|
|
5. Service Protection Policies, Processes and Procedures |
Protecting against cyber attack |
|
6. Identity and Access Control |
|
|
7. Data Security |
|
|
8. System Security |
|
|
9. Resilient Networks & Systems |
|
|
10. Staff Awareness & Training |
|
|
11. Security Monitoring |
Detecting cyber security events |
|
12. Threat Hunting |
|
|
13. Response and Recovery Planning |
Minimising the impact of cyber security incidents |
|
14. Lessons Learned |
The CAF has been updated to version 4 to make the content of the assessment framework easier to interpret and assess. There is an increased emphasis on proportionate and strategic risk responses. Now, organisations are expected to consider and anticipate potential risks from technological developments that could be used to adversely impact network and information systems. CAF 4.0 can be reviewed and downloaded below.