The 14 Themes of Cyber Assurance: A Practical Deep Dive
Published 25 May 2026
Area 1: Identify and classify
1. Planning information security
Strategy, scope, governance structure. Evidence: information security policy, named SRO, board minute approving the policy.
2. Organisation
Roles, responsibilities, segregation of duties. Evidence: org chart, RACI for key security roles.
3. Assets
Hardware, software, data, cloud services. Evidence: asset register, data classification scheme.
4. Legal and regulatory
UK GDPR, sector regulators, contractual obligations. Evidence: register of legal/regulatory requirements, ICO registration.
5. Risk assessment and management
Live risk register with treatments. Evidence: dated register, scoring methodology, board review minutes.
6. Policy realisation
Policies into practice. Evidence: signed acceptable use policies, training records.
Area 2: Protect
7. People
Recruitment screening, onboarding, training, leavers process. Evidence: induction records, annual training, JML log.
8. Physical and environmental
Premises security, clear desk, visitor controls. Evidence: visitor log, access control records.
9. Operations and management
Day-to-day IT operations, change control, capacity. Evidence: change log, configuration baselines.
10. Technical security
The CE controls, plus encryption, vulnerability management, secure development if applicable. Evidence: CE certificate, scan reports, patching SLAs met.
Area 3: Deter and detect
11. Backup and restore
Frequency, retention, restore-tested. Evidence: backup logs, restore test record.
12. Incident response
Plan, roles, tested. Evidence: IR plan, last tabletop / live exercise record.
Area 4: Respond and recover
13. Business continuity and disaster recovery
BCP/DR with RTO/RPO, tested annually. See our BCP guide.
14. Secure business operations
Monitoring, review, change management, supplier oversight. Evidence: monitoring reports, supplier register, change tickets.
How to evidence efficiently
- Build one master evidence index, mapped to all 14 themes.
- Keep evidence in one location – a SharePoint site or GRC platform works.
- Date-stamp every document.
- Cross-reference: one piece of evidence often covers multiple themes.
See the full pillar: 14 themes of Cyber Assurance.
