Questions about completing the CAF
How often will councils be expected to do a CAF assessment?
The CAF is a not a one-off exercise, but a tool you can use to continuously assess and improve your council’s cyber resilience.
Assessing your organisation (objectives A and D)
If you are doing the CAF for the first time, we recommend you start by self-assessing your organisation and then work through any remediation actions outlined in your improvement and implementation plan (IIP).
You should aim to do a full reassessment of your organisation every few years to maintain an up-to-date view of your cyber posture and risk.
You may also need to reassess your organisation if there are significant changes to:
- your leadership or council structure (such as reorganisation)
- the threat landscape, such as who could attack your organisation and why
- your mission and priorities
- your cyber risk appetite
- the essential services that allow your council to operate and achieve your mission and objectives
Assessing your critical systems (objectives B and C)
Once you have completed your organisational self-assessment, move on to self-assessing your critical systems. We recommend you assess up to three systems a year. Your longer-term goal should be to assess all your critical systems. This will support you to identify cyber risks that could disrupt your most important services.
We’re interested to learn how you plan to use the CAF as part of your routine risk management and business planning. Email [email protected] to share your feedback.
We’ve completed a self-assessment – what should we do next?
Once you’ve completed a self-assessment you should work with an independent assurer to develop an improvement and implementation plan (IIP). Your IIP outlines how you plan to address the issues you’ve identified and is an important step in building your cyber resilience.
You can then submit your finalised report and IIP to MHCLG. This will help us understand cyber security risks and issues within the sector, so that we can consider how to support the sector in addressing these.
If you’ve got an IIP
Work through the recommended actions. You may be asked to update MHCLG on your progress against your IIP so that we can understand what issues you may be facing and how we might support you to address them.
If you’re already working on your IIP
While working on your recommended actions, you can also get started on your next self-assessment. For example, while you’re working through the actions for your organisation (objectives A and D), you could start assessing one of your prioritised critical systems (objectives B and C).
If you’re waiting for assurance
Complete this form to request assurance from MCHLG and we will contact you once an assurer is available. Thank you for your patience if you have already requested assurance.
What if our council has done the Get CAF Ready programme?
By completing Get CAF Ready, you have gained the skills and knowledge to identify and prioritise critical systems and map system and network architecture. You can use this to start the self-assessment of your critical systems.
If you have not done so already, you should start by preparing your council for the self-assessment, including planning your schedule and identifying key roles and responsibilities.