Impacts on ICS from the updated Cyber Assessment Framework (CAF)
ID: 13630946-a493-585b-baee-0c89a9ea54fd
STIX ID: report--13630946-a493-585b-baee-0c89a9ea54fd
Feed Name: Pen Test Partners Blog
UK NCSC’s CAF v3.2 introduces material changes requiring multi-factor authentication for all user access to systems supporting essential functions and mandates removal or disablement of generic/shared/default accounts (or changing their credentials where removal is not possible). While these updates aim to raise baseline security for NIS-regulated organizations, they may pose challenges for legacy ICS/OT environments; organizations should review and update security programs, budget for necessary changes, justify best-practice authentication choices, and implement compensating controls where full compliance is temporarily infeasible.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
