# NCSC CAF

<span style="background: transparent; margin-top: 0pt; margin-bottom: 0pt;">The [Cyber Assessment Framework](https://www.ncsc.gov.uk/collection/caf/caf-principles-and-guidance) (CAF) is an extensive framework of fourteen principles used to assess the risk of various cyber threats and an organisation's defences against these.</span>

<span style="background: transparent; margin-top: 0pt; margin-bottom: 0pt;">  
</span>

<span style="background: transparent; margin-top: 0pt; margin-bottom: 0pt;">The framework applies to organisations considered to perform "vitally important services and activities" such as critical infrastructure, banking, and the likes. The framework mainly focuses on and assesses the following topics:</span>

- Data security
- System security
- Identity and access control
- Resiliency
- Monitoring
- Response and recovery planning

<table class="table table-bordered" id="bkmrk-advantages-disadvant"><tbody><tr><td style="background: #efefef;">Advantages</td><td style="background: #efefef;">Disadvantages</td></tr><tr><td>This framework is backed by a government cybersecurity agency.<span style="white-space: pre;"> </span>  
</td><td>The framework is still new in the industry, meaning that organisations haven't had much time to make the necessary changes to be suitable for it.  
</td></tr><tr><td>This framework provides accreditation.  
</td><td>The framework is based on principles and ideas and isn't as direct as having rules like some other frameworks.  
</td></tr><tr><td>This framework covers fourteen principles which range from security to response.  
</td><td>Intentionally left blank.</td></tr></tbody></table>