UK NCSC Cyber Assessment Framework
Objective D: Minimising the impact of cyber security incidents – UK NCSC Cyber Assessment Framework

UK NCSC Cyber Assessment Framework D2.b: D2.b Using incidents to drive improvements

Lessons from incidents improve security measures. Achieved: a documented review process captures and acts on lessons from each incident and near miss; lessons cover reporting, roles, governance, skills and procedures as well as technology; measures and response plans are updated and retested; improvements are prioritised with the most important done promptly; analysis reaches senior management and feeds risk management; 'what if' analysis is exploited; and incidents across the sector and national infrastructure are learned from.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

Other controls in Objective D: Minimising the impact of cyber security incidents – UK NCSC Cyber Assessment Framework

Query this from an agent

The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.