Skip to main content
    NixInfinity-AI
    Standard Deep Dive

    The 14 Themes of Cyber Assurance: A Practical Deep Dive

    Published 25 May 2026

    Area 1: Identify and classify

    1. Planning information security

    Strategy, scope, governance structure. Evidence: information security policy, named SRO, board minute approving the policy.

    2. Organisation

    Roles, responsibilities, segregation of duties. Evidence: org chart, RACI for key security roles.

    3. Assets

    Hardware, software, data, cloud services. Evidence: asset register, data classification scheme.

    4. Legal and regulatory

    UK GDPR, sector regulators, contractual obligations. Evidence: register of legal/regulatory requirements, ICO registration.

    5. Risk assessment and management

    Live risk register with treatments. Evidence: dated register, scoring methodology, board review minutes.

    6. Policy realisation

    Policies into practice. Evidence: signed acceptable use policies, training records.

    Area 2: Protect

    7. People

    Recruitment screening, onboarding, training, leavers process. Evidence: induction records, annual training, JML log.

    8. Physical and environmental

    Premises security, clear desk, visitor controls. Evidence: visitor log, access control records.

    9. Operations and management

    Day-to-day IT operations, change control, capacity. Evidence: change log, configuration baselines.

    10. Technical security

    The CE controls, plus encryption, vulnerability management, secure development if applicable. Evidence: CE certificate, scan reports, patching SLAs met.

    Area 3: Deter and detect

    11. Backup and restore

    Frequency, retention, restore-tested. Evidence: backup logs, restore test record.

    12. Incident response

    Plan, roles, tested. Evidence: IR plan, last tabletop / live exercise record.

    Area 4: Respond and recover

    13. Business continuity and disaster recovery

    BCP/DR with RTO/RPO, tested annually. See our BCP guide.

    14. Secure business operations

    Monitoring, review, change management, supplier oversight. Evidence: monitoring reports, supplier register, change tickets.

    How to evidence efficiently

    1. Build one master evidence index, mapped to all 14 themes.
    2. Keep evidence in one location – a SharePoint site or GRC platform works.
    3. Date-stamp every document.
    4. Cross-reference: one piece of evidence often covers multiple themes.

    See the full pillar: 14 themes of Cyber Assurance.

    Need a hand getting certified?

    Speak to an IASME-licensed assessor. Pre-check, plain-English support, certificates issued £320 + VAT.

    Frequently Asked Questions