Cyber Security
Case Study

Getting ready for GovAssure

A department facing its first GovAssure cycle, unsure which systems were in scope and whether its evidence would survive independent review.

GovAssureNCSC CAFPublic sector

The challenge

The organisation knew GovAssure was coming but had no agreed view of which systems were critical enough to be in scope, and no consistent evidence base behind the controls it believed were in place.

Previous assurance had been a self-declared annual return. GovAssure introduces independent review, so positions that had never been challenged were about to be — and an over-stated self-assessment is worse than an honest one, because it destroys confidence in everything else.

Our approach

  1. Establish organisational contextWork back from the functions the organisation exists to deliver, so that criticality is argued from business consequence rather than asserted by system owners.
  2. Agree the scopeIdentify the systems that genuinely support those functions, and document why others are out of scope so the boundary can be defended during review.
  3. Assess honestly against the CAFWork through the contributing outcomes with the people who actually operate the systems, recording evidence as it is found and marking outcomes as partially achieved where that is the truth.
  4. Rehearse the independent reviewChallenge the draft position the way an external reviewer will, so weak evidence is found internally rather than in the formal review.
  5. Convert gaps into a planTurn the assessed gaps into a prioritised improvement plan with named owners, rather than a list of observations that nobody is accountable for.

What changed

The department entered its review with a defensible scope, an assessment its own people recognised as accurate, and a plan that showed the centre of government it understood its own gaps.

The more durable result is that the CAF position became something maintained rather than reconstructed from scratch each cycle.

This is an anonymised, representative engagement. We do not publish client names, or figures we cannot substantiate, without explicit permission — in government and critical infrastructure, naming a client can itself be a security concern.

Other case studies

Recognise this situation?

If yours looks similar, the useful first step is usually a conversation about what is actually driving the requirement.