logo

Impacts on ICS from the updated Cyber Assessment Framework (CAF)

ID: 13630946-a493-585b-baee-0c89a9ea54fd

STIX ID: report--13630946-a493-585b-baee-0c89a9ea54fd

Feed Name: Pen Test Partners Blog

Date Published: 2024-05-17

Date Updated: 2026-03-26

Author: Martin Slack

...
...

UK NCSC’s CAF v3.2 introduces material changes requiring multi-factor authentication for all user access to systems supporting essential functions and mandates removal or disablement of generic/shared/default accounts (or changing their credentials where removal is not possible). While these updates aim to raise baseline security for NIS-regulated organizations, they may pose challenges for legacy ICS/OT environments; organizations should review and update security programs, budget for necessary changes, justify best-practice authentication choices, and implement compensating controls where full compliance is temporarily infeasible.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.