The UK Cyber Assessment Framework (CAF) requires incident response documentation across two principles under Objective D: D1 (Response and Recovery Planning), which needs a documented incident response plan , evidence of the capability to execute it, and records of regular testing; and D2 (Lessons Learned), which needs root cause analysis records and evidence that findings actually change your plans and controls afterward. A plan that exists but has never been tested, or an incident that was never analysed for root cause, will not satisfy an assessor even if your organisation handled the incident well in practice.

What Incident Response Documentation Does UK CAF Require?
aditi@cm-alliance.com (Aditi Uberoi)

