UK NCSC Cyber Assessment Framework
Objective A: Managing security risk – UK NCSC Cyber Assessment Framework

UK NCSC Cyber Assessment Framework A2.b: A2.b Understanding threat

The organisation understands threat actors' capabilities, methods and likely targets and uses this to shape risk decisions and defences (new in v4.0). Partially achieved: threat analysis of common threats and attack types, kept current, anticipating targets, informed by common incidents and applied to risk decisions. Achieved: detailed analysis in the context of the sector and national infrastructure, including capable well-resourced actors; viewing systems from an attacker's perspective, developing plausible scenarios, mapping the steps an attacker must take and justified measures at each step; maintaining current intelligence; and documenting the analysis method.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

Other controls in Objective A: Managing security risk – UK NCSC Cyber Assessment Framework

Query this from an agent

The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.