I’ll correct the CAF alignment for the eight risks I identified, using the control-first approach we have now agreed. I’ve also checked these against CAF v4.0: B5.c Backups explicitly addresses incomplete backup coverage, backup frequency, secured backups, restoration timescales, testing and routine review, so it should be prominent where those are the actual control deficiencies. (National Cyber Security Centre)

1. Azure Recovery Services Vault Security Weaknesses

CAF Objectives

  1. Objective B: Protecting Against Cyber Attack

  2. Objective B: Protecting Against Cyber Attack

  3. Objective B: Protecting Against Cyber Attack

  4. Objective A: Managing Security Risk

  5. Objective C: Detecting Cyber Security Events

  6. Objective D: Minimising the Impact of Cyber Security Incidents

  7. Objective D: Minimising the Impact of Cyber Security Incidents

CAF Principles

  1. B5 Resilient Networks and Systems

  2. B2 Identity and Access Control

  3. B3 Data Security

  4. A3 Asset Management

  5. C1 Security Monitoring

  6. D1 Response and Recovery Planning

  7. D2 Lessons Learned

CAF Alignment Summary

The principal focus is Objective B: Protecting Against Cyber Attack, particularly B5 Resilient Networks and Systems and B5.c Backups, because Recovery Services Vaults form part of the organisation's core capability for maintaining secured, accessible and usable recovery copies.

B2 Identity and Access Control supports restriction of privileged access to vault configuration, backup data and destructive operations. B3 Data Security supports protection of the confidentiality and integrity of information held within the vault.

A3 Asset Management provides visibility of the workloads that should be protected, while C1 Security Monitoring supports identification of failed backups, unauthorised changes and deterioration in expected protection.

D1 Response and Recovery Planning becomes important when demonstrating that protected workloads can actually be restored within required recovery timescales, while D2 Lessons Learned ensures restoration testing and incidents improve future vault configuration.


2. Azure Recovery Services Vaults Not Appropriately Protected or Configured

CAF Objectives

  1. Objective B: Protecting Against Cyber Attack

  2. Objective B: Protecting Against Cyber Attack

  3. Objective B: Protecting Against Cyber Attack

  4. Objective C: Detecting Cyber Security Events

  5. Objective D: Minimising the Impact of Cyber Security Incidents

  6. Objective D: Minimising the Impact of Cyber Security Incidents

CAF Principles

  1. B5 Resilient Networks and Systems

  2. B2 Identity and Access Control

  3. B3 Data Security

  4. C1 Security Monitoring

  5. D1 Response and Recovery Planning

  6. D2 Lessons Learned

CAF Alignment Summary

The principal focus is B5 Resilient Networks and Systems, particularly B5.c Backups, because Recovery Services Vault configuration directly affects whether backup copies remain appropriately protected and available following compromise or system failure.

B2 Identity and Access Control is relevant to restricting administrative and destructive actions against vaults, while B3 Data Security supports protection of the backup information itself.

C1 Security Monitoring provides visibility of backup failures and significant changes to vault protection. D1 Response and Recovery Planning applies when the organisation validates that protected workloads can actually be recovered, with D2 Lessons Learned supporting improvement following restoration tests and recovery events.


3. AWS Backup Vaults Not Locked or Protected

CAF Objectives

  1. Objective B: Protecting Against Cyber Attack

  2. Objective B: Protecting Against Cyber Attack

  3. Objective B: Protecting Against Cyber Attack

  4. Objective C: Detecting Cyber Security Events

  5. Objective D: Minimising the Impact of Cyber Security Incidents

  6. Objective D: Minimising the Impact of Cyber Security Incidents

CAF Principles

  1. B5 Resilient Networks and Systems

  2. B2 Identity and Access Control

  3. B3 Data Security

  4. C1 Security Monitoring

  5. D1 Response and Recovery Planning

  6. D2 Lessons Learned

CAF Alignment Summary

The principal focus is Objective B, particularly B5 Resilient Networks and Systems and B5.c Backups, because backup vault protection is intended to ensure recovery copies remain secured and accessible even when production systems or privileged identities are compromised.

B2 Identity and Access Control supports strict control of privileged actions against backup vaults, while B3 Data Security addresses protection of backup information against unauthorised modification or deletion.

C1 Security Monitoring supports detection of suspicious vault activity and protection changes. D1 Response and Recovery Planning applies when proving protected recovery points can be used following a significant incident, while D2 Lessons Learned ensures testing and incidents improve backup-vault protection.


4. AWS Backup Plans Not in Place for All Resources

CAF Objectives

  1. Objective B: Protecting Against Cyber Attack

  2. Objective A: Managing Security Risk

  3. Objective B: Protecting Against Cyber Attack

  4. Objective C: Detecting Cyber Security Events

  5. Objective D: Minimising the Impact of Cyber Security Incidents

  6. Objective D: Minimising the Impact of Cyber Security Incidents

CAF Principles

  1. B5 Resilient Networks and Systems

  2. A3 Asset Management

  3. B4 System Security

  4. C1 Security Monitoring

  5. D1 Response and Recovery Planning

  6. D2 Lessons Learned

CAF Alignment Summary

The principal focus is B5 Resilient Networks and Systems, particularly B5.c Backups, because the immediate deficiency is that resources requiring recovery protection have not been incorporated into appropriate backup plans.

A3 Asset Management is essential for identifying the complete AWS resource estate and determining which resources require protection. B4 System Security supports embedding backup-plan assignment into controlled resource provisioning and management.

C1 Security Monitoring provides visibility of resources falling outside required backup policies. D1 Response and Recovery Planning applies to restoration testing against RTOs and RPOs, while D2 Lessons Learned ensures backup failures and recovery experience improve future arrangements.


5. Azure SQL Database Insufficient Retention Periods

CAF Objectives

  1. Objective B: Protecting Against Cyber Attack

  2. Objective A: Managing Security Risk

  3. Objective B: Protecting Against Cyber Attack

  4. Objective D: Minimising the Impact of Cyber Security Incidents

  5. Objective D: Minimising the Impact of Cyber Security Incidents

CAF Principles

  1. B5 Resilient Networks and Systems

  2. A3 Asset Management

  3. B3 Data Security

  4. D1 Response and Recovery Planning

  5. D2 Lessons Learned

CAF Alignment Summary

The principal focus is B5 Resilient Networks and Systems and B5.c Backups, because insufficient retention directly limits the availability of suitable recovery points following data loss, corruption or compromise.

A3 Asset Management supports identification of database criticality and the business services dependent upon each database, allowing appropriate retention requirements to be established.

B3 Data Security supports appropriate protection of retained database information. D1 Response and Recovery Planning becomes relevant when determining whether available recovery points allow services to be restored within required RTOs and RPOs.

D2 Lessons Learned ensures restoration exercises and actual recovery events are used to refine retention requirements.


6. RDS DB Instance Retention Periods and Backup Data to Be Reviewed

CAF Objectives

  1. Objective B: Protecting Against Cyber Attack

  2. Objective A: Managing Security Risk

  3. Objective B: Protecting Against Cyber Attack

  4. Objective C: Detecting Cyber Security Events

  5. Objective D: Minimising the Impact of Cyber Security Incidents

  6. Objective D: Minimising the Impact of Cyber Security Incidents

CAF Principles

  1. B5 Resilient Networks and Systems

  2. A3 Asset Management

  3. B3 Data Security

  4. C1 Security Monitoring

  5. D1 Response and Recovery Planning

  6. D2 Lessons Learned

CAF Alignment Summary

The principal focus is B5 Resilient Networks and Systems, particularly B5.c Backups, because RDS backup frequency and retention must provide sufficiently current and accessible recovery points for the databases supporting organisational services.

A3 Asset Management supports classification of RDS instances and their recovery requirements, while B3 Data Security supports appropriate protection of retained database information.

C1 Security Monitoring supports identification of failed backups or deviations from required protection. D1 Response and Recovery Planning applies to proving that retained backups can restore dependent services within required timescales.

D2 Lessons Learned ensures restoration testing and recovery incidents inform future RDS backup and retention arrangements.


7. Testing the Organisation's Ability to Recover Archived Data for Operational Use

CAF Objectives

  1. Objective B: Protecting Against Cyber Attack

  2. Objective D: Minimising the Impact of Cyber Security Incidents

  3. Objective A: Managing Security Risk

  4. Objective D: Minimising the Impact of Cyber Security Incidents

CAF Principles

  1. B5 Resilient Networks and Systems

  2. D1 Response and Recovery Planning

  3. A3 Asset Management

  4. D2 Lessons Learned

CAF Alignment Summary

This risk has a strong dual alignment. B5 Resilient Networks and Systems, particularly B5.c Backups, applies because CAF v4.0 expects backups to be usable and routinely tested rather than simply existing. Testing archived data therefore provides assurance that retained information remains accessible and capable of supporting recovery. (National Cyber Security Centre)

D1 Response and Recovery Planning is equally important where testing extends beyond retrieval of the archived information and demonstrates that it can be restored into operational use as part of recovering a service. CAF v4.0 distinguishes broader response and recovery exercises from testing only a discrete component such as whether backups work. (National Cyber Security Centre)

A3 Asset Management supports understanding which archived information is required to recover critical systems and services.

D2 Lessons Learned ensures restoration failures, excessive recovery times and other weaknesses identified during testing result in improvements to archive and recovery arrangements.


8. Limited Response Plans for Total IT Loss

CAF Objectives

  1. Objective D: Minimising the Impact of Cyber Security Incidents

  2. Objective B: Protecting Against Cyber Attack

  3. Objective B: Protecting Against Cyber Attack

  4. Objective A: Managing Security Risk

  5. Objective A: Managing Security Risk

  6. Objective D: Minimising the Impact of Cyber Security Incidents

CAF Principles

  1. D1 Response and Recovery Planning

  2. B5 Resilient Networks and Systems

  3. B5 Resilient Networks and Systems

  4. A3 Asset Management

  5. A4 Supply Chain

  6. D2 Lessons Learned

CAF Alignment Summary

The principal focus remains Objective D: Minimising the Impact of Cyber Security Incidents, particularly D1 Response and Recovery Planning, because the primary deficiency is the absence of sufficiently developed plans for responding to and recovering from a total loss of IT capability.

However, B5 Resilient Networks and Systems is a major supporting principle. B5.a Resilience Preparation applies to understanding the systems, technologies, dependencies and recovery sequence required to restore critical services, while B5.c Backups applies to ensuring the data, configurations, software and other information required for reconstruction remain secured and accessible following an extreme event. CAF v4.0 explicitly places these resilience capabilities within B5. (National Cyber Security Centre)

A3 Asset Management supports identification of the systems and dependencies that must be recovered. A4 Supply Chain is important because total IT recovery may depend heavily upon cloud providers, telecommunications providers, hardware suppliers, managed service providers and specialist recovery support.

Finally, D2 Lessons Learned ensures total-loss exercises and actual major incidents result in improvements to recovery plans, technical resilience and organisational preparedness.

The key distinction across these eight is now much cleaner: B5/B5.c owns the backup capability itself; D1 owns the broader organisational capability to respond and recover. CAF v4.0 deliberately links the two, but they are not interchangeable. (National Cyber Security Centre)

Image Placeholder

Welcome to Cybersolve

 

Cybersolve provide Information Security and Data Protection services to company's looking to comply with National and International regulations and legislation. The services will align organisations to their required standards and prepare them for audit and ongoing cyber security management requirements.

 

We can offer professional services, and assitence with : 

✔ Cyber Security

✔ Information Security

✔ Data Protection

✔ ISO 27001

✔ National Cyber Security Centre compliance

✔ Microsoft 365 Security & Compliance

✔ Cyber Essentials Scheme

 


Get In Touch

We will be happy to answer any questions or queries you have. We aim to reply to all comments/queries as soon as possible and look forward to hearing from you!

 

Email


Please use the contact form opposite and we will get back to you as soon as possible.

Required fields are marked *
Please tick this box to prove that you are human *