Beenet

|  Secure by Design

< Back

Secure by Design Foundation Assessment

Has the lifecycle for each information type been identified throughout the life of the capability?

No
Yes

Has the capability used information journeys to identify risks?

No
Yes

Has the capability set up the management of cyber risks by using a formal framework?

No
Yes

Has the capability developed a risk appetite tailored for its intended use?

No
Yes

Has the capability used its risk appetite to make informed risk decsions, in line with NCSC guidance?

No
Yes

Has the capability done a comprehensive risk assessment?

No
Yes

Has the capability used its risk assessment to prioritise its most significant risks?

No
Yes

Has the capability evidenced that risks outside of appetite have been escalated?

No
Yes

Has the capability developed overall risks that include cyber security risks?

No
Yes

Has the capability received formal acceptance for any transferred risks?

No
Yes