Objective A: Managing security risk
NCSC guidanceAppropriate organisational structures, policies, processes and practices to understand, assess and systematically manage security risks to the networks and information systems supporting essential functions.
Principles
- A1 Governance - board-level ownership, clear roles and accountability for cyber resilience
- A2 Risk management - a systematic, proportionate process to identify, assess and treat risks to essential functions
- A3 Asset management - a complete, current understanding of the data, systems and people that support essential functions
- A4 Supply chain - understanding and managing the security risks that arise from third parties and dependencies
