UK NCSC Cyber Assessment Framework
Objective D: Minimising the impact of cyber security incidents – UK NCSC Cyber Assessment Framework

UK NCSC Cyber Assessment Framework D2.a: D2.a Post incident analysis

After incidents the organisation understands causes to inform remediation. Achieved: post-incident analysis is routine and considers organisational, technical and human factors and threat changes; all relevant incident data is available to analysts; and plausible alternative ('what if') circumstances are considered. Not achieved includes no root cause process, confirmation bias in investigations, and investigations aimed only at blaming individuals.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

Other controls in Objective D: Minimising the impact of cyber security incidents – UK NCSC Cyber Assessment Framework

Query this from an agent

The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.