Skip to main content

Part of Objective A - Managing risk

Principle: A2 Risk management

Current Chapter

Current chapter – Principle: A2 Risk management


A2.a Risk management process

“Your organisation has effective internal processes for managing risks to the security, resilience and governance of information, systems and networks related to the operation of your essential function(s), and communicating associated activities. This includes a process for data protection impact assessments (DPIAs).”

Overview

This contributing outcome is about ensuring your organisation has effective processes for managing risk.

Risk assessments

You should conduct risk assessments on a scheduled basis, at sufficient intervals,to ensure any new risks are identified without undue delay, and whenever significant changes occur to your organisational systems or processes. 

The DSPT does not mandate a specific approach to risk assessment, however, it's important to consider:

  • your organisation’s business priorities and objectives
  • who or what those things should be protected from
  • any legal and regulatory obligations that apply to your organisation
  • the cyber security and information governance (IG) risk red lines your organisation will and won’t cross to complete the things it needs to do

For more information on understanding and managing risk from a cyber security perspective, see National Cyber Security Centre (NCSC) guidance on A basic risk assessment and management method. For information on managing IG risk, see Information Commissioner’s Office (ICO) guidance on risks and data protection impact assessments.

Linking risk assessment to controls

You should link your cyber security and IG controls to your risk assessments. Ways of clearly demonstrating links between controls and risks may include:

  • listing controls against each risk in your risk register
  • creating a controls catalogue which cross references each control against individual risks

This should help you ensure that your controls are sufficient and proportionate, and that time and resources are not being wasted on solutions that do not effectively contribute towards the management of cyber security and IG risk.

Data protection by design and by default

The requirements of data protection by design and by default should be clearly incorporated into your overall approach to cyber security and wider IG risk. Examples of where considerations should be made include when: 

  • developing new IT systems, services and processes that involve processing personal data
  • developing organisational policies, processes and strategies that have IG or cyber security implications 
  • embarking on data sharing initiatives
  • using personal data for new purposes
  • changes to the scope or purpose of current processing activities

See ICO guidance on data protection by design and by default for more information.

Data protection impact assessments (DPIAs)

Data protection impact assessments (DPIAs) are a key way of putting data protection by design and by default into practice.  

You should demonstrate that your organisation conducts DPIAs before beginning any type of processing which is "likely to result in a high risk to the rights and freedoms" of individuals. For a detailed list of situations where this applies, see guidance from the ICO. The DPIA process can also help you assess the level of risk associated with a project where this is not clear from the outset. 

See NHS England’s universal IG templates page for a template DPIA document which you can use, or reference your own processes against, to ensure all appropriate bases are covered.

"Achieved" level

Adverse impacts

Your approach to risk should be focused on the possibility of adverse impact to your essential function(s). You should understand how this could happen through possible threat actor actions, and how the security of the information, systems and networks that support those functions could contribute to the impact.

This means linking each relevant risk to the techniques threat actors are likely to use (see Common types of cyber attacks in A2.b Understanding threat) and the controls you have in place to prevent or limit those techniques. 

For example, if you identify device code phishing as a technique likely to be used against your organisation, you should be able to show that you have considered this risk, implemented appropriate controls such as disabling device code flow, and reassessed the residual risk in light of those controls.

Updating threat assumptions

You need to have a documented threat assessment where your assumptions cover a wide range of attackers and capabilities. 

Your threat assumptions need to be continuously updated in response to changes in the threat landscape. These could include geo-political campaigns, significant data protection and security incidents in health and care, and the discovery of new vulnerabilities. 

Your threat assumptions should also be informed by information sharing resources and initiatives. These might include threat intelligence and services provided by NCSC, forums and engagement with professionals in your industry.

Anticipating technological developments

A practical approach to anticipating technological developments as part of your risk assessment process is to carry out horizon scanning for emerging technologies and developments in attacker capabilities.

The resources you might use for this activity include:

Those developments which could affect your own information, systems and networks should be documented, with the results used to update relevant risk assessments.

Supporting evidence

To support your response, you can upload (or link to) evidence which best demonstrates your achievement of the contributing outcome. Examples include:

  • procedures for identifying, analysing, prioritising and managing information governance (IG) and cyber security risk 
  • risk assessments 
  • data protection impact assessments (DPIAs) 
  • risk registers 
  • evidence of data protection by design and by default being incorporated into risk management processes  
  • evidence of data protection principles and relevant legislation being incorporated into risk management processes 
  • evidence of nature of information being considered as part of risk management processes 
  • evidence of vulnerabilities in systems and networks being considered as part of risk management processes  
  • procedures for communicating significant conclusions from risk management processes to accountable individuals 
  • evidence of threat intelligence being used for cyber risk management processes 
  • evidence of business impact evaluations for multiple scenarios 
  • threat assumptions and review process 
  • evidence of lessons learned from near misses being integrated into risk management processes 
  • evidence of dynamic risk assessments 
  • procedures for evaluation and improvement of risk management processes 
  • evidence of ongoing detailed threat analysis

This is not an exhaustive list. You can provide other types of evidence if you feel they are relevant to the contributing outcome.

Your supporting statement should cross reference how each piece of evidence provides justification for your achievement of the contributing outcome, including relevant page numbers where appropriate.

Interpreting indicators of good practice

Indicator(s) of good practice Term Interpretation

PA#1

Your organisational process ensures that security and wider IG risks to information, systems and networks relevant to essential function(s) are identified, analysed, prioritised, and managed. 

This includes incorporating data protection by design and default into your process.

'essential function(s)'

Your essential functions should be identified in a scoping exercise which you carry out before beginning your DSPT submission. The same exercise should identify all the information, systems and networks which support your essential functions.

For more information, see guidance on scoping essential functions.

PA#2

Your risk assessments are informed by an understanding of known and well understood threats and vulnerabilities in the systems and networks supporting your essential function(s), as well as your other data processing activities.

'known and well understood threats'

For cyber risk assessments, you should incorporate knowledge of threats including:

PA#5

You conduct risk assessments when significant events potentially affect the essential function(s), such as replacing a system, introducing new or emergent technologies or a change in the cyber security threat.

'new or emergent technologies or a change in the cyber security threat’'

New or emergent technologies: You need to appropriately risk assess new technologies adopted by your organisation.

A change in the cyber security threat: New threats can affect previous risk assessments for existing products. For example, the growing ability of generative AI to quickly find and exploit vulnerabilities may impact your assessment of security risks that were previously considered low.

PA#6

Your risk process clearly demonstrates how your organisation’s processing complies with data protection principles and relevant legislation, including the right to a private life.

‘data protection principles and relevant legislation’

Principles and legislation which should be considered include:

A#2

Your approach to risk is focused on the possibility of adverse impact to your essential function(s), leading to a detailed understanding of how such impact might arise as a consequence of possible threat actor actions and the security properties of information, systems and networks supporting your essential function(s).

'adverse impact'

This term describes any effect on your essential functions that prevents you from delivering them effectively.

A#7

Your risk assessments (including DPIAs) are dynamic and readily updated in the light of relevant changes which may include technical changes to systems and networks supporting your essential function(s), change of use, or processing, the introduction of new emergent technologies, or new threat information.

‘[updating risk assessments for] new emergent technologies’ Where new technologies are introduced into your organisation, you should review any existing risk assessments for systems or assets which might be impacted by the way the new technologies function on your network.

National services

The following national services may help you meet the requirements of A2.a Risk management process:

Additional guidance

For additional guidance, see:

National Cyber Security Centre CAF guidance | A2 Risk management
National Cyber Security Centre | Risk management
National Cyber Security Centre | Risk management - Introducing system and component driven risk management approaches
Information Commissioner’s Office | Risk and data protection impact assessments (DPIAs)
Information Commissioner’s Office | Data protection by design and by default


A2.b Understanding threat

"You understand the capabilities, methods and techniques of threat actors and what information, systems and networks they may compromise to adversely impact your essential function(s). This information is used to inform security and resilience risk management decisions, adjusting, enhancing or adding security measures to better defend against threats.”

Overview

This contributing outcome is about understanding likely cyber threats and using that knowledge to strengthen your security controls.

Threat analysis 

For cyber risk assessments, you should incorporate knowledge of threats including:

  • current and emerging threats described in DHSC or NHS England's Cyber Security Strategy for Health and Care to 2030
  • any threats which you have been contacted about directly by DHSC or NHS England
  • threat intelligence and alerts received from NHS England's CSCOC, including via Microsoft Defender for Endpoint 

Common types of cyber attacks

You should maintain an up to date understanding of common types of cyber attacks, including the method and techniques by which they might affect your organisation. You should ensure your understanding of threat is informed by common incidents.

For example, to defend against:

  • phishing – you need to be aware of malicious links, attachments, spoofed emails and credential harvesting
  • ransomware – you need to understand how this could happen downstream of phishing, unpatched systems or stolen credentials
  • malware – you need to know how malicious code could be introduced through downloads, attachments, websites, removable media or compromised software
  • credential attacks – you need to be aware of password spraying, brute force, credential stuffing and reuse of stolen passwords 
  • social engineering – you need to understand that attackers may manipulate staff by email, phone or messaging to bypass normal checks, disclose information or approve unsafe actions
  • Denial of Service (DoS) / Distributed Denial of Service (DDoS) you need to know how public facing services, remote access and supplier-hosted systems could be overwhelmed and made unavailable

Your understanding of attacker methods and techniques should be reflected in your policies, procedures and risk assessments.

Anticipating targets for threat actors

Your organisation should use its understanding of current cyber threats to anticipate which systems, services or access routes are most likely to be targeted by threat actors. This is likely to include:

  • user accounts and identities
  • email and collaboration tools
  • edge devices and other internet facing systems
  • remote access services

You should be able to show that you have considered the likely methods of attack for these target areas and implemented proportionate controls to prevent or reduce the risk of successful compromise.

Applying threat analysis to risk management

You should apply your understanding of threat to inform your risk management decision making.

In practice, this could mean using your understanding of likely threats to:

  • decide whether to mitigate or tolerate risks
  • prioritise risk mitigations 
  • review whether existing mitigations remain proportionate
  • decide where controls need to be strengthened

"Achieved” level 7

Threat analysis

Your threat analysis should be:

  • detailed and comprehensive
  • underpinned by a robust understanding of attacker tactics and techniques
  • continuously updated in response to changes in the threat landscape such as geo-political campaigns, data protection and security incidents in health and care, and the discovery of new vulnerabilities

Capable and well resourced threat actors

A structured way of building a detailed understanding of threat, including the methods and techniques available to capable and well resourced threat actors, would be to sign up to receive briefings from NHS England’s CSOC. 

CSOC briefings provide information on sophisticated techniques and methods used by threat actors, which you can apply to your understanding of your own systems to identify the potential implications for your organisation.

You can learn more about these by contacting [email protected].

Threat modelling

You should apply a specific threat modelling framework such as STRIDE, Attack Trees or MITRE ATT&CK Mapping to analyse and examine threats to your information, systems and networks from a threat actor’s perspective.

You should prioritise threat modelling for systems and assets which you consider to be probable targets for capable and well resourced threat actors.

This should lead to a documented understanding of threat actors’ likely attack methods and techniques, their targets and objectives, and the different steps they would need to take to reach their probable targets on your networks.

Threat intelligence and proactive research

To maintain a detailed understanding of current threats, your threat intelligence and proactive research can involve resources such as: 

The above resources should be used to help you regularly undertake horizon scanning for new vulnerabilities, attack trends, common threat actor techniques, and incidents affecting health and care organisations.  

Documenting detailed threat analysis

You should document the steps your organisation takes to conduct your detailed threat analysis.

This means that your organisation has a structured local process underpinning your threat analysis, threat modelling, and the way your understanding of threats is applied to your management of risks.

Supporting evidence

To support your response, you can upload (or link to) evidence which best demonstrates your achievement of the contributing outcome. Examples include:

  • procedures for identifying, analysing, prioritising and managing IG and cyber security risk
  • risk assessments
  • DPIAs 
  • risk registers
  • evidence of up to date understanding of common types of cyber attacks
  • evidence of information or assets being prioritised by likelihood of being targeted by threat actors
  • evidence of use of a specific threat modelling framework
  • evidence of sources used to maintain a detailed understanding of current threats
  • procedures for doing threat analysis and threat modelling in a structured way and applying them to risk management

This is not an exhaustive list. You can provide other types of evidence if you feel they are relevant to the contributing outcome.

Your supporting statement should cross reference how each piece of evidence provides justification for your achievement of the contributing outcome, including relevant page numbers where appropriate.

Interpreting indicators of good practice

Indicator of good practice Term Interpretation

PA#4

Your understanding of threat is informed by common incidents.

'common incidents'

An approach similar to the one outlined in the Common types of cyber attack section above would lead to an understanding of threat informed by common incidents.

A#7

You apply your detailed understanding of threat to inform your risk management decision making.

'detailed understanding of threat' See Threat intelligence and proactive research section above. When you learn that ways of conducting cyber attacks are evolving, you should have a structured way of updating your internal controls to match your new understanding.

Additional guidance

For additional guidance, see:

National Cyber Security Centre CAF guidance | A2 Risk management
National Cyber Security Centre | Building a Security Operations Centre (SOC) | Threat Intelligence


A2.c Assurance

“You have gained confidence in the effectiveness of your technology, people and processes relevant to the security and governance of information, systems and networks supporting your essential function(s).”


Overview

To meet this contributing outcome, your organisation needs to show that it tests the effectiveness of its cyber security and information governance (IG) controls for assurance.

Assurance

Assurance is about gaining confidence that your cyber security and IG controls are working effectively. To achieve this, you should use a variety of techniques to proactively review how your people, processes and technology are working in practice. Any weak points identified through your assurance activities should be documented and acted upon.

You should undertake your assurance activities at planned intervals that you can justify based on the risks being managed, to confirm that existing controls remain effective as circumstances and threats change.

See NCSC’s guidance on how to gain and maintain assurance for more information.

Understanding and reviewing assurance methods

You should understand the assurance methods that are available and review the ones you use to ensure they remain effective. This might mean, for example, optimising your vulnerability testing process or focussing your spot checks on specific areas or processes identified as weak points.

As part of your review, you may consider whether you are making most effective use of assurance activities such as:

  • penetration testing
  • behavioural testing, for example simulated phishing exercises
  • spot checks of processes, for example joiner / mover / leaver procedures, checking new assets are being appropriately registered, responses to subject access requests
  • spot checks of the premises, for example physical security of the building, locked cabinets, staff and visitor ID badges, paper waste, computer equipment

Supporting evidence

To support your response, you can upload (or link to) evidence which best demonstrates your achievement of the contributing outcome. Examples include:

  • procedures for assurance of cyber security and IG controls 
  • evidence of validation and selection of assurance methods
  • evidence of previous DSPT audits or equivalent independent assurance
  • action plans for remediating deficiencies
  • procedures for reviewing assurance methods

This is not an exhaustive list. You can provide other types of evidence if you feel they are relevant to the contributing outcome.

Your supporting statement should cross reference how each piece of evidence provides justification for your achievement of the contributing outcome, including relevant page numbers where appropriate.

Interpreting indicators of good practice

Indicator(s) of good practice Term Interpretation 

A#2 

You understand the assurance methods available to you and choose appropriate methods to gain confidence in the security and governance of information systems and networks

'essential function(s)'

Your essential functions should be identified in a scoping exercise which you carry out before beginning your DSPT submission. The same exercise should identify all the information, systems and networks which support your essential functions. 

For more information, see guidance on scoping essential functions

National services

The following national services may help you meet the requirements of A2.c Assurance:

Additional guidance

For additional guidance, see:

National Cyber Security Centre CAF guidance | A2 Risk management
National Cyber Security Centre | Risk management - How to gain and maintain assurance
National Cyber Security Centre | Penetration testing


Last edited: 26 August 2026 11:47 am