Part of Objective A - Managing risk
Principle: A1 Governance
A1.a Board direction
“You have effective organisational information assurance management led at board level and articulated clearly in corresponding policies.”
Overview
To meet this contributing outcome, you need to assure that your board is appropriately sighted and involved in your organisation’s cyber security and information governance (IG) activities.
Board direction
Your board, or senior management, should take overall accountability for the data protection and security risks your organisation faces. They should provide direction on cyber security and IG, which is then disseminated through your organisation’s policies, projects and procedures.
In health and care, these board level activities are usually driven by the Senior Information Risk Owner (SIRO) (see A1.b Roles and responsibilities).
Linking governance and security to essential services
The board should be able to discuss how IG and cyber security contribute to the delivery of essential functions, and understand the potential impact if important information or systems were compromised. They should also recognise IG and cyber security as important enablers for the resilience of those essential functions. To facilitate this, the board must receive briefings that clearly demonstrate how IG and cyber security activities facilitate the organisation’s delivery of services.
Where seeking the board’s input on topics such as the legal or regulatory landscape, the organisation’s risk profile, or emerging threats, you should make it clear which essential functions are likely to be impacted without adequate mitigations in place. This may be all of them in certain scenarios.
Supporting evidence
To support your response, you can upload (or link to) evidence which best demonstrates your achievement of the contributing outcome. Examples include:
- policies relating to the security and governance of information, systems and networks
- evidence of IG and security group findings and decisions being discussed at board level
- terms of reference and minutes from board meetings
- board level strategy and action plans relating to the security and governance of information, systems and networks
This is not an exhaustive list. You can provide other types of evidence if you feel they are relevant to the contributing outcome.
Your supporting statement should cross reference how each piece of evidence provides justification for your achievement of the contributing outcome, including relevant page numbers where appropriate.
Interpreting indicators of good practice
| Indicator of good practice | Term | Interpretation |
|---|---|---|
|
A#1 Your organisation’s approach and policy relating to the security and governance of information, systems and networks supporting the operation of your essential function(s) are owned and managed at board level. These are communicated, in a meaningful way, to risk management decision makers across the organisation. |
'essential function(s)' |
Your essential functions should be identified in a scoping exercise which you carry out before beginning your DSPT submission. The same exercise should identify all the information, systems and networks which support your essential functions. For more information, see guidance on scoping essential functions. |
|
A#2 Regular board discussions on the security and governance of information, systems and networks supporting the operation of your essential function(s) take place, based on timely and accurate information and informed by expert guidance. |
'regular' | On a scheduled basis, with enough frequency to ensure there are no key strategic decisions made which the board does not have visibility of. |
|
A#3 There are board level individuals who have overall accountability for the security and governance of information, systems and networks (these may be the same person), who drive regular discussion at board level. |
'regular' | On a scheduled basis, with enough frequency to ensure there are no key strategic decisions made which the board does not have visibility of. |
|
A#5 The board has the information and understanding needed in order to effectively discuss how the security, resilience and governance of information, systems and networks contribute to the delivery of essential function(s) and what the potential impact from compromise of the organisation’s information or systems would be. |
‘understanding needed […] to effectively discuss’ | See Linking governance and security to essential services above. |
|
A#6 Information assurance is recognised as an important enabler for the resilience of your essential function(s) and considered in all relevant discussions. |
‘recognised as an important enabler’ | See Linking governance and security to essential services above. |
National services
The following national services may help you meet the requirements of A1.a.Board Direction
- training services - board training
- training services - SIRO training
- training services - simulated phishing exercises
- security services - Cyber Assurance Service (CAS)
Additional guidance
For additional guidance, see:
National Cyber Security Centre CAF guidance A1 Governance
National Cyber Security Centre Risk management Cyber security governance
ICO Leadership and oversight
A1.b Roles and responsibilities
“Your organisation has established roles and responsibilities for the security and governance of information, systems and networks at all levels, with clear and well-understood channels for communicating and escalating risks.”
Overview
This contributing outcome relates to your organisation’s cyber security and information governance (IG) activities being directed, delivered and followed by a team of appropriately knowledgeable and capable staff.
Roles and responsibilities
How you structure your cyber security and IG teams and allocate responsibilities is a local decision.
Roles and responsibilities should be well understood to ensure that cyber and IG activities are effectively delivered, and that any gaps in resources are promptly identified and addressed.
You can define roles and responsibilities in a range of ways, including but not limited to:
- documented ownership of actions
- documented role descriptions
- policies and processes
- training
- contracts
NHS England has created cyber security job profiles and IG role profiles which help provide a practical reference point for defining local role responsibilities and evidencing that key duties are clearly assigned.
Key roles in health and care
The key cyber security and IG roles for health and care organisations are highlighted below, with brief explanations of their purpose, main responsibilities and how they support effective governance, risk management and assurance.
Staff contracts
Your employment contracts for staff should contain data protection and security requirements.
The NHS terms and conditions of service handbook outlines the following under the ‘Governance, confidentiality, data protection’ section:
“35.46 All employees must comply with the General Data Protection Regulation (GDPR) as it applies in the UK, informed by the Data Protection Act 2018.
Policies should set out clear principles and processes. Specifically, home and/or agile/hybrid workers are under a duty to observe security and confidentiality practices in relation to equipment and data in line with GDPR, data protection legislation, and local policies and procedures. Employers need to ensure provisions are in place for the secure storage, use and disposal of confidential information from the home base.”
Your organisation may use wording reflecting this, or signpost to the NHS terms and conditions of service handbook, to ensure your contracts cover the appropriate bases.
Supporting evidence
To support your response, you can upload (or link to) evidence which best demonstrates your achievement of the contributing outcome. Examples include:
- documentation of key roles and responsibilities
- evidence of the review process for roles and responsibilities
- job descriptions
- procedures for reporting resourcing issues
- name of the individual with overall accountability
- staff contract sample
This is not an exhaustive list. You can provide other types of evidence if you feel they are relevant to the contributing outcome.
Your supporting statement should cross reference how each piece of evidence provides justification for your achievement of the contributing outcome, including relevant page numbers where appropriate.
A practical example of a supporting statement for outcome A1.b Roles and responsibilities has been provided. The template is to be used as an example only. The information you provide in your supporting statement must be relevant to your organisation and you are encouraged to choose an approach that best suits you.
Interpreting indicators of good practice
| Indicator(s) of good practice | Term | Interpretation |
|---|---|---|
|
A#1 Key roles and responsibilities for the security and governance of information, systems and networks supporting your essential function(s) have been identified. These are reviewed regularly to ensure they remain fit for purpose. |
'regularly' |
On a scheduled basis, with enough frequency to ensure there are no critical gaps in cyber security or IG activities.
|
|
A#1 Key roles and responsibilities for the security and governance of information, systems and networks supporting your essential function(s) have been identified. These are reviewed regularly to ensure they remain fit for purpose. |
'essential function(s)' |
Your essential functions should be identified in a scoping exercise which you carry out before beginning your DSPT submission. The same exercise should identify all the information, systems and networks which support your essential functions. For more information, see guidance on scoping essential functions. |
National services
The following national services may help you meet the requirements of A1.b Roles and responsibilities:
- Training services | Board training
- Training services | SIRO training
- Training services | Cyber Incident Response Exercise (CIRE)
- Training services | Immersive labs
- Training services | Keep IT Confidential
- Security services | Secure Boundary
- Security services | Vulnerability Monitoring Service (VMS)
- Security services | Technical Remediation
- Security services | Microsoft Defender for Endpoint (MDE)
- NCSC services | Exercise in a box
- NCSC services | Check your cyber security
Additional guidance
For additional guidance, see:
National Cyber Security Centre CAF guidance | A1 Governance
National Cyber Security Centre | Risk management – Cyber security governance
A1.c Decision making
“You have senior level accountability for the security and governance of information, systems and networks, and delegate decision making authority appropriately and effectively. Risks to information, systems and networks related to the operation of your essential function(s) are considered in the context of other organisational risks.”
Overview
This contributing outcome relates to your organisational procedures for making decisions relating to cyber security and information governance (IG).
Decision making
Your procedures for risk decision making should ensure that:
- appropriate staff members are involved
- staff members operate under direction from senior management
- risk decisions are reviewed in response to changing circumstances
The teams who are directly involved in conducting your cyber security and IG activities are best placed to determine what decisions should be taken in each individual case and escalating where appropriate. However, they should operate with an informed understanding of your board’s risk appetite.
Risk appetite
Your organisation should have a board approved risk appetite which:
- determines acceptable and unacceptable risks
- creates a risk culture and sets risk expectations to be shared across your organisation’s teams
- allows staff members to make informed, timely and effective risk management decisions
Your organisation’s risk appetite should be continually assessed against current threats and refreshed at suitable intervals.
Supporting evidence
To support your response, you can upload (or link to) evidence which best demonstrates your achievement of the contributing outcome. Examples include:
- risk appetite statement
- responsibilities for decision making in different risk areas
- procedures for reporting key risk decisions to the board
- procedures for delegating risk decisions
- risk registers
- procedures for risk register review
- procedures for involving other departments in risk decisions
This is not an exhaustive list. You can provide other types of evidence if you feel they are relevant to the contributing outcome.
Your supporting statement should cross reference how each piece of evidence provides justification for your achievement of the contributing outcome, including relevant page numbers where appropriate.
Interpreting indicators of good practice
| Indicator of good practice | Term | Interpretation |
|---|---|---|
|
A#2 Risk management decision makers understand their responsibilities for making effective and timely decisions in the context of the risk appetite regarding the essential function(s), as set by senior management. |
'essential function(s)' |
Your essential functions should be identified in a scoping exercise which you carry out before beginning your DSPT submission. The same exercise should identify all the information, systems and networks which support your essential functions. For more information, see guidance on scoping essential functions. |
|
A#4 Risk management decisions are regularly reviewed to ensure their continued relevance and validity. |
'regularly' |
On a scheduled basis, with enough frequency to ensure that the criteria upon which you have made decisions have not changed due to evolving external factors. |
National services
The following national services may help you meet the requirements of A1.c Decision making:
Additional guidance
For additional guidance, see:
National Cyber Security Centre CAF guidance | A1 Governance
National Cyber Security Centre | Risk management – Cyber security governance
Last edited: 26 August 2026 11:39 am