NATO Cyber Defence Policy and NATO Computer Incident Response Capability (NCIRC)
Strategic Cyber Defence

NATO Cyber Defence Policy and NATO Computer Incident Response Capability (NCIRC) NATO-NCIRC-8: Cyberspace as Operational Domain + Cyber Defence Pledge + Annual Self-Assessment

Recognise cyberspace as an operational domain per 2016 Warsaw Summit + integrate cyber effects into NATO planning and operations. Submit annual Cyber Defence Pledge progress report to the Cyber Defence Committee covering: national cyber defence strategy progress + cyber budget commitments (target 2% of GDP defence spending with cyber proportion increasing) + cyber expertise gaps + NCIRC capability contributions + Rapid Reaction Team contributions. Achieve and report progress against Cyber Defence Pledge targets adopted at 2016 Warsaw Summit. Participate in Article 5 collective defence in cyberspace where applicable.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 42 controls across 19 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

  • 4.3.2 Legal and Other Requirements
  • 4.4.1 Resources, Roles, Responsibility, and Authority
  • 4.4.2 Competence, Training, and Awareness
  • FFIEC-11 Business continuity planning and testing
  • FFIEC-12 Disaster recovery procedures
  • FFIEC-14 Critical service identification
  • IM8-DAT.2 Data Protection
  • IM8-DSS.2 Service Reliability Standards
  • IM8-RES.4 Resilience Testing

APRA CPS 234 · 2 controls

  • CPS234-14 Definition of Information Security Roles and Responsibilities
  • CPS234-15 Information Security Capability
  • 62351-12 Resilience and security recommendations for DER
  • 62351-13 Cyber-physical generation and storage resilience

ISO/IEC 27031:2011 · 2 controls

  • 27031-8.1 Exercising and Testing
  • 27031-B High availability embedded systems
  • ASD37-20 Multi-factor authentication (Essential)
  • BS65000-RM-03 Leadership and Culture

COBIT 2019 · 1 control

  • COBIT-BAI04 Managed availability and capacity
  • CAT-D5-4 Resilience planning and testing
  • ISO20000-03 Capacity and availability management
  • ISO-25012-4.13 Availability

ISO/IEC 27007:2020 · 1 control

  • 27007-5.4 Establishing the Programme Resources

ITIL 4 · 1 control

  • ITIL4-03 Capacity and availability management
  • NGCB-6 Incident Response, 72-Hour NGCB Notification, and Independent Investigation
  • PSPF24-2 Information Security, Cybersecurity Maturity, Essential Eight
  • KRCSAP-1 CSAP Certification Tiers (IaaS, SaaS, DaaS, AI)
  • CERT-1 RRA Certification to EPA

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Query this from an agent

The graph holds this control, the 42 it maps to, and the evidence behind each claim, over MCP and REST.