CAF v4 Assessment

Assessment Dashboard

Objective A: Managing Security Risk

Objective B: Protecting Against Cyber Attack

Objective C: Detecting Cyber Security Events

Objective D: Minimising the Impact of Incidents

Instructions

Authored by Jordan M. Schroeder, Arxa Cyber. For any bugs or feature requests, send a note to tools@ArxaCyber.com.

Loading...

This tool allows you to perform an assessment against the NCSC's Cyber Assessment Framework (CAF) v4 using a flat CSV file of the Indicative Good Practice (IGP) statements.

Step 1: Get the Indicative Good Practice (IGP) Statements and Sector Profile

The IGP statements are automatically loaded by selecting the most recent IGP file from: https://github.com/Erreinion/NCSC_CAF_v4/. You can also use the "Load IGP" button to load a CSV file from your computer. Loading a new IGP file will reset the current assessment.

Additionally, you can use the "Load Profile" button to load a Sector Profile CSV file. This is an optional step that adds a new compliance section to the dashboard.

Step 2: Perform the Assessment

Once the file is loaded, navigate through the tabs for Objectives A, B, C, and D. For each section, you can set the attainment level and add notes for each Area:

  • Use the "Attainment Level" dropdown to select a status: "Achieved", "Partially Achieved", "Not Achieved", or "Not Applicable".
  • Use the "Notes" text area to add detailed comments or evidence for your assessment.

Step 3: Review the Dashboard

Click the "Dashboard" tab at any time to see a summary of your progress. The dashboard provides a visual breakdown of your assessment by Objective, and if a Sector Profile is loaded, a breakdown of your compliance against that profile.

Step 4: Save and Load

To save your progress, click the "Download Assessment" button. This will download a JSON file with your current assessment status. To resume your work later, click the "Load Assessment" button and select a previously downloaded assessment JSON file.

Step 5: Print a Report

Click the "Print Dashboard" button to generate a printable report of your assessment summary.