The 14 Themes of IASME Cyber Assurance Explained
Published 30 April 2026
Area 1: Identify & Classify
Understanding what you have, who's responsible, what regulation applies and what risks need treatment.
- Identifying and protecting assets – know your information assets so you can protect them.
- Legal and regulatory landscape – be aware of contractual and legal obligations and meet them.
- Assessing and treating risks – identify, assess and manage risks at an acceptable level.
- Organisation – clear ownership and accountability for security.
- Planning information security – consider security in projects, procurement, contracting and partnerships.
Area 2: Protect
Putting the right physical, procedural, technical and people controls in place.
- Physical and environmental protection – defend assets against theft, loss and environmental harm.
- People – screening, training and security responsibilities for all staff.
- Policy realisation – the policies that codify your rules and values.
- Managing access – least-privilege access to systems and data.
- Technical intrusion – anti-malware, monitoring, insider-threat measures.
- Change management – well-documented procedures for operational and technological change.
Area 3: Deter & Detect
Spotting threats early and acting on them.
- Secure business operations: monitoring and review – track and monitor systems to detect and analyse threats.
Area 4: Respond & Recover
Being ready when something does go wrong.
- Backup and restore – regular, tested backups that can actually be restored.
- Resilience – business continuity, incident management and disaster recovery so you can respond, keep operating and recover.
Tailored by organisation size
IASME tailors the depth of the standard depending on whether you are a sole trader, micro business (3–9), small business (10–49) or larger. Smaller organisations are not asked to implement controls disproportionate to their size – it's risk-based, not check-box.
How it connects to Cyber Essentials
The five technical controls assessed by Cyber Essentials sit underneath the 14 CA themes. CE proves the technical baseline; CA proves the surrounding governance. That's why CE is a hard prerequisite – see CA prerequisites explained.
