Eskenzi PR ad banner Eskenzi PR ad banner
  • About Us
Monday, 15 June, 2026
IT Security Guru
Eskenzi PR banner
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us
No Result
View All Result
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us
No Result
View All Result
IT Security Guru
No Result
View All Result

Understanding the UK government’s new cybersecurity regime, GovAssure

Tom Miller, Senior Consultant and Internal Assurance and Cyber Security Manager at AMR Cyber Security describes the UK government’s new approach to ensure cyber resilience

by Guru Writer
November 20, 2023
in Featured, Insight
Understanding the UK government’s new cybersecurity regime, GovAssure
Share on FacebookShare on Twitter

With the ever-growing threat of cyberattacks on the UK government and Critical National Infrastructure cyber safety matters more than ever.

With the rising tide of ever-resent threat in mind, GovAssure was launched by the UK government in April 2023. It’s a cyber security programme that aims to ensure government IT systems are fully protected from cyberattacks.

The new cyber security scheme is run by the Cabinet Office’s Government Security Group (GSG), with input from the National Cyber Security Centre (NCSC). Under this new scheme, all central government departments will have their cyber health reviewed annually through new, more robust criteria.

At the launch of the new, more robust scheme, Government Chief Security Officer, Vincent Devine described GovAssure as a chance to gain far greater visibility of the common cyber security challenges facing government, as well as being “a powerful tool for security advocacy”, and it will empower cyber security professionals to strengthen the case for security change and investment.

GovAssure aims to review government departments (and select arm’s length bodies’), and approaches to cyber security. It is currently only designated for official systems and does not apply to secret systems or higher.

It will help develop a greater understanding of the cyber security posture and capability of government departments and arm’s length bodies. Through robust annual security audits, departments must now attest to their cyber security assurance measures as set out in the NCSC’s Cyber Assessment Framework (CAF).

CAF sets out indicators of good practice for managing security risk and protecting against cyberattacks.

The NCSC’s CAF was designed to be used by operators within Critical National Infrastructure (CNI) in relation to the Network & Information Systems (NIS) regulations, which aimed to raise cyber security levels and resilience of key systems across the EU. NIS came into force in the UK in May 2018.

GovAssure replaces existing ‘Departmental Security Health Checks’ that departments must currently provide to the Cabinet Office for review. This is a key part of the Government’s Cyber Security Strategy to improve cyber resilience and help government organisations protect themselves from growing hostile cyber threats.

GovAssure is a five-stage process:

  1. Organisational contact and services
  2. In-scope systems and assignment to the Government CAF profile
  3. CAF self-assessment
  4. Independent assurance review
  5. Final assessment and targeted improvement plan

 

Stage 1

The first stage of GovAssure is a scoping exercise. Here, organisations must develop a complete understanding of their strategic context and understand the cyber security threat landscape.

The scope will be defined by the essential services that the department provides, either in relation to CNI, or Operators of Essential Services (OES).

Stage 2

Once essential services are identified, critical systems are then identified. These may be a mix of operational and support systems for the identified essential services.

There are two Government Cyber Assessment Framework (CAF) profiles: Baseline and Enhanced. These profiles will be assigned through discussion with GSG, the NCSC and the Cabinet Office. The enhanced profile will be automatically applied to government CNI.

Stage 3

CAF self-assessment has four objectives: managing security risk, protecting against cyberattacks, detecting cyber security events and minimising the impact of cyber security incidents.

Departments should complete the self-assessment with input from relevant key stakeholders within the organisation. The CAF has been mapped to several industry-standard frameworks, including ISO 27001 and NIST SP 800-53.

Stage 4

Next, accredited third parties will perform independent reviews to verify the department’s self-assessment. This review will assess the level of attainment of the relevant CAF profile, validate the results of self-assessed findings, and determine how effective current cyber security controls are.

This assessment will evaluate CAF level attainment, by reviewing the department’s WebCAF submissions, alongside a review of any supporting documents referenced in the submission.

The third-party reviewer will also hold interviews with key stakeholders to review responses on a per objective basis. Reviews will consider the extent to which supporting indicators of good practice have been achieved, partially achieved, or not achieved.

Stage 5

Finally, once an independent review is completed, a final assessment report is generated and provided to the organisation by the independent assurance provider. GSG will then work with the organisation to develop a targeted improvement plan, outlining a prioritised list of areas for improvement.

This process might seem daunting or complex, but many companies can help. AMR CyberSecurity is a GovAssure Independent Assurance Reviewer, for example, which can provide the Stage 4 requirements of GovAssure to relevant organisations. Its highly skilled, qualified assurance consultants can assist organisations in carrying out the Independent Assurance Review, as well as other assurance activities in relation to cyber security.

ShareTweet
Previous Post

Can bcrypt Passwords Be Cracked?

Next Post

Recognising Scam Patterns and Preventing Data Loss: A Unified Approach

Recent News

Check Point Expands MSP Platform with AI Security Capabilities and Unified Bundles

From Playbooks to Adaptive Workflows: How MSSPs Are Evolving Security Operations with Agentic AI

June 15, 2026
Nagomi Control Brings CTEM Into Action

2 in 5 Organisations Experienced Cyber Incidents Tied to Suppliers in Past Year

June 12, 2026
Certes Research Warns Legacy Systems Are Biggest Barrier to Quantum Security Readiness

KnowBe4 Expands Gamified Training Library With Launch of “Spot the Vish” Game

June 12, 2026
Swan Song For Infosec’s Most Gripping Awareness Training Series: The Inside Man Goes Out With A Star-Studded Bang

Swan Song For Infosec’s Most Gripping Awareness Training Series: The Inside Man Goes Out With A Star-Studded Bang

June 12, 2026

The IT Security Guru offers a daily news digest of all the best breaking IT security news stories first thing in the morning! Rather than you having to trawl through all the news feeds to find out what’s cooking, you can quickly get everything you need from this site!

Our Address: 10 London Mews, London, W2 1HY

Follow Us

© 2015 - 2024 IT Security Guru - Website Managed by Dessol

  • About Us
Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}
No Result
View All Result
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us

© 2015 - 2024 IT Security Guru - Website Managed by Dessol