UK NCSC Cyber Assessment Framework
Objective A: Managing security risk – UK NCSC Cyber Assessment Framework

UK NCSC Cyber Assessment Framework A1.a: A1.a Board direction

Security of network and information systems is led and owned at board level and set out in policy. Achieved: policy is owned and managed at board level and communicated meaningfully to risk decision-makers; the board discusses security regularly on timely, accurate, expert-informed information; a board-level individual is accountable and drives discussion; board direction becomes effective organisational practice; the board understands how security supports essential functions and the impact of compromise; and security is treated as an enabler of resilience in relevant discussions.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

Other controls in Objective A: Managing security risk – UK NCSC Cyber Assessment Framework

Query this from an agent

The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.