I’ll correct the CAF alignment for the eight risks I identified, using the control-first approach we have now agreed. I’ve also checked these against CAF v4.0: B5.c Backups explicitly addresses incomplete backup coverage, backup frequency, secured backups, restoration timescales, testing and routine review, so it should be prominent where those are the actual control deficiencies. (National Cyber Security Centre)
Objective B: Protecting Against Cyber Attack
Objective B: Protecting Against Cyber Attack
Objective B: Protecting Against Cyber Attack
Objective A: Managing Security Risk
Objective C: Detecting Cyber Security Events
Objective D: Minimising the Impact of Cyber Security Incidents
Objective D: Minimising the Impact of Cyber Security Incidents
B5 Resilient Networks and Systems
B2 Identity and Access Control
B3 Data Security
A3 Asset Management
C1 Security Monitoring
D1 Response and Recovery Planning
D2 Lessons Learned
The principal focus is Objective B: Protecting Against Cyber Attack, particularly B5 Resilient Networks and Systems and B5.c Backups, because Recovery Services Vaults form part of the organisation's core capability for maintaining secured, accessible and usable recovery copies.
B2 Identity and Access Control supports restriction of privileged access to vault configuration, backup data and destructive operations. B3 Data Security supports protection of the confidentiality and integrity of information held within the vault.
A3 Asset Management provides visibility of the workloads that should be protected, while C1 Security Monitoring supports identification of failed backups, unauthorised changes and deterioration in expected protection.
D1 Response and Recovery Planning becomes important when demonstrating that protected workloads can actually be restored within required recovery timescales, while D2 Lessons Learned ensures restoration testing and incidents improve future vault configuration.
Objective B: Protecting Against Cyber Attack
Objective B: Protecting Against Cyber Attack
Objective B: Protecting Against Cyber Attack
Objective C: Detecting Cyber Security Events
Objective D: Minimising the Impact of Cyber Security Incidents
Objective D: Minimising the Impact of Cyber Security Incidents
B5 Resilient Networks and Systems
B2 Identity and Access Control
B3 Data Security
C1 Security Monitoring
D1 Response and Recovery Planning
D2 Lessons Learned
The principal focus is B5 Resilient Networks and Systems, particularly B5.c Backups, because Recovery Services Vault configuration directly affects whether backup copies remain appropriately protected and available following compromise or system failure.
B2 Identity and Access Control is relevant to restricting administrative and destructive actions against vaults, while B3 Data Security supports protection of the backup information itself.
C1 Security Monitoring provides visibility of backup failures and significant changes to vault protection. D1 Response and Recovery Planning applies when the organisation validates that protected workloads can actually be recovered, with D2 Lessons Learned supporting improvement following restoration tests and recovery events.
Objective B: Protecting Against Cyber Attack
Objective B: Protecting Against Cyber Attack
Objective B: Protecting Against Cyber Attack
Objective C: Detecting Cyber Security Events
Objective D: Minimising the Impact of Cyber Security Incidents
Objective D: Minimising the Impact of Cyber Security Incidents
B5 Resilient Networks and Systems
B2 Identity and Access Control
B3 Data Security
C1 Security Monitoring
D1 Response and Recovery Planning
D2 Lessons Learned
The principal focus is Objective B, particularly B5 Resilient Networks and Systems and B5.c Backups, because backup vault protection is intended to ensure recovery copies remain secured and accessible even when production systems or privileged identities are compromised.
B2 Identity and Access Control supports strict control of privileged actions against backup vaults, while B3 Data Security addresses protection of backup information against unauthorised modification or deletion.
C1 Security Monitoring supports detection of suspicious vault activity and protection changes. D1 Response and Recovery Planning applies when proving protected recovery points can be used following a significant incident, while D2 Lessons Learned ensures testing and incidents improve backup-vault protection.
Objective B: Protecting Against Cyber Attack
Objective A: Managing Security Risk
Objective B: Protecting Against Cyber Attack
Objective C: Detecting Cyber Security Events
Objective D: Minimising the Impact of Cyber Security Incidents
Objective D: Minimising the Impact of Cyber Security Incidents
B5 Resilient Networks and Systems
A3 Asset Management
B4 System Security
C1 Security Monitoring
D1 Response and Recovery Planning
D2 Lessons Learned
The principal focus is B5 Resilient Networks and Systems, particularly B5.c Backups, because the immediate deficiency is that resources requiring recovery protection have not been incorporated into appropriate backup plans.
A3 Asset Management is essential for identifying the complete AWS resource estate and determining which resources require protection. B4 System Security supports embedding backup-plan assignment into controlled resource provisioning and management.
C1 Security Monitoring provides visibility of resources falling outside required backup policies. D1 Response and Recovery Planning applies to restoration testing against RTOs and RPOs, while D2 Lessons Learned ensures backup failures and recovery experience improve future arrangements.
Objective B: Protecting Against Cyber Attack
Objective A: Managing Security Risk
Objective B: Protecting Against Cyber Attack
Objective D: Minimising the Impact of Cyber Security Incidents
Objective D: Minimising the Impact of Cyber Security Incidents
B5 Resilient Networks and Systems
A3 Asset Management
B3 Data Security
D1 Response and Recovery Planning
D2 Lessons Learned
The principal focus is B5 Resilient Networks and Systems and B5.c Backups, because insufficient retention directly limits the availability of suitable recovery points following data loss, corruption or compromise.
A3 Asset Management supports identification of database criticality and the business services dependent upon each database, allowing appropriate retention requirements to be established.
B3 Data Security supports appropriate protection of retained database information. D1 Response and Recovery Planning becomes relevant when determining whether available recovery points allow services to be restored within required RTOs and RPOs.
D2 Lessons Learned ensures restoration exercises and actual recovery events are used to refine retention requirements.
Objective B: Protecting Against Cyber Attack
Objective A: Managing Security Risk
Objective B: Protecting Against Cyber Attack
Objective C: Detecting Cyber Security Events
Objective D: Minimising the Impact of Cyber Security Incidents
Objective D: Minimising the Impact of Cyber Security Incidents
B5 Resilient Networks and Systems
A3 Asset Management
B3 Data Security
C1 Security Monitoring
D1 Response and Recovery Planning
D2 Lessons Learned
The principal focus is B5 Resilient Networks and Systems, particularly B5.c Backups, because RDS backup frequency and retention must provide sufficiently current and accessible recovery points for the databases supporting organisational services.
A3 Asset Management supports classification of RDS instances and their recovery requirements, while B3 Data Security supports appropriate protection of retained database information.
C1 Security Monitoring supports identification of failed backups or deviations from required protection. D1 Response and Recovery Planning applies to proving that retained backups can restore dependent services within required timescales.
D2 Lessons Learned ensures restoration testing and recovery incidents inform future RDS backup and retention arrangements.
Objective B: Protecting Against Cyber Attack
Objective D: Minimising the Impact of Cyber Security Incidents
Objective A: Managing Security Risk
Objective D: Minimising the Impact of Cyber Security Incidents
B5 Resilient Networks and Systems
D1 Response and Recovery Planning
A3 Asset Management
D2 Lessons Learned
This risk has a strong dual alignment. B5 Resilient Networks and Systems, particularly B5.c Backups, applies because CAF v4.0 expects backups to be usable and routinely tested rather than simply existing. Testing archived data therefore provides assurance that retained information remains accessible and capable of supporting recovery. (National Cyber Security Centre)
D1 Response and Recovery Planning is equally important where testing extends beyond retrieval of the archived information and demonstrates that it can be restored into operational use as part of recovering a service. CAF v4.0 distinguishes broader response and recovery exercises from testing only a discrete component such as whether backups work. (National Cyber Security Centre)
A3 Asset Management supports understanding which archived information is required to recover critical systems and services.
D2 Lessons Learned ensures restoration failures, excessive recovery times and other weaknesses identified during testing result in improvements to archive and recovery arrangements.
Objective D: Minimising the Impact of Cyber Security Incidents
Objective B: Protecting Against Cyber Attack
Objective B: Protecting Against Cyber Attack
Objective A: Managing Security Risk
Objective A: Managing Security Risk
Objective D: Minimising the Impact of Cyber Security Incidents
D1 Response and Recovery Planning
B5 Resilient Networks and Systems
B5 Resilient Networks and Systems
A3 Asset Management
A4 Supply Chain
D2 Lessons Learned
The principal focus remains Objective D: Minimising the Impact of Cyber Security Incidents, particularly D1 Response and Recovery Planning, because the primary deficiency is the absence of sufficiently developed plans for responding to and recovering from a total loss of IT capability.
However, B5 Resilient Networks and Systems is a major supporting principle. B5.a Resilience Preparation applies to understanding the systems, technologies, dependencies and recovery sequence required to restore critical services, while B5.c Backups applies to ensuring the data, configurations, software and other information required for reconstruction remain secured and accessible following an extreme event. CAF v4.0 explicitly places these resilience capabilities within B5. (National Cyber Security Centre)
A3 Asset Management supports identification of the systems and dependencies that must be recovered. A4 Supply Chain is important because total IT recovery may depend heavily upon cloud providers, telecommunications providers, hardware suppliers, managed service providers and specialist recovery support.
Finally, D2 Lessons Learned ensures total-loss exercises and actual major incidents result in improvements to recovery plans, technical resilience and organisational preparedness.
The key distinction across these eight is now much cleaner: B5/B5.c owns the backup capability itself; D1 owns the broader organisational capability to respond and recover. CAF v4.0 deliberately links the two, but they are not interchangeable. (National Cyber Security Centre)
Welcome to Cybersolve
Cybersolve provide Information Security and Data Protection services to company's looking to comply with National and International regulations and legislation. The services will align organisations to their required standards and prepare them for audit and ongoing cyber security management requirements.
We can offer professional services, and assitence with :
✔ Cyber Security
✔ Information Security
✔ Data Protection
✔ ISO 27001
✔ National Cyber Security Centre compliance
✔ Microsoft 365 Security & Compliance
✔ Cyber Essentials Scheme


We will be happy to answer any questions or queries you have. We aim to reply to all comments/queries as soon as possible and look forward to hearing from you!
Please use the contact form opposite and we will get back to you as soon as possible.
ALL RIGHTS RESERVED ©
Cybersolve | cyberserve.uk
Email: admin@cybersolve.uk