Skip to main content
    NixInfinity-AI
    Standard

    The 14 Themes of IASME Cyber Assurance Explained

    Published 30 April 2026

    Area 1: Identify & Classify

    Understanding what you have, who's responsible, what regulation applies and what risks need treatment.

    • Identifying and protecting assets – know your information assets so you can protect them.
    • Legal and regulatory landscape – be aware of contractual and legal obligations and meet them.
    • Assessing and treating risks – identify, assess and manage risks at an acceptable level.
    • Organisation – clear ownership and accountability for security.
    • Planning information security – consider security in projects, procurement, contracting and partnerships.

    Area 2: Protect

    Putting the right physical, procedural, technical and people controls in place.

    • Physical and environmental protection – defend assets against theft, loss and environmental harm.
    • People – screening, training and security responsibilities for all staff.
    • Policy realisation – the policies that codify your rules and values.
    • Managing access – least-privilege access to systems and data.
    • Technical intrusion – anti-malware, monitoring, insider-threat measures.
    • Change management – well-documented procedures for operational and technological change.

    Area 3: Deter & Detect

    Spotting threats early and acting on them.

    • Secure business operations: monitoring and review – track and monitor systems to detect and analyse threats.

    Area 4: Respond & Recover

    Being ready when something does go wrong.

    • Backup and restore – regular, tested backups that can actually be restored.
    • Resilience – business continuity, incident management and disaster recovery so you can respond, keep operating and recover.

    Tailored by organisation size

    IASME tailors the depth of the standard depending on whether you are a sole trader, micro business (3–9), small business (10–49) or larger. Smaller organisations are not asked to implement controls disproportionate to their size – it's risk-based, not check-box.

    How it connects to Cyber Essentials

    The five technical controls assessed by Cyber Essentials sit underneath the 14 CA themes. CE proves the technical baseline; CA proves the surrounding governance. That's why CE is a hard prerequisite – see CA prerequisites explained.

    Need help across all 14 themes?

    We provide policy templates, a risk register starter and a BC plan structure with every Cyber Assurance engagement.

    Frequently Asked Questions

    Related Cyber Essentials Guides