Provide authoritative outcomes, requirements, principles or safeguards against which an organisation can structure its programme.
The RACF-CC Framework
Resource-aware cybersecurity for organisations that cannot compromise on care.
RACF-CC helps care charities turn recognised cybersecurity principles into affordable, prioritised and measurable action—without assuming enterprise budgets, specialist teams or a dedicated security operations centre.
Designed for operational reality
Strong controls, proportionate delivery
Care charities hold sensitive information and depend on reliable services, yet commonly work with constrained budgets, small technology teams, legacy systems and limited monitoring. RACF-CC preserves the intent of established security guidance while adapting implementation to those realities.
The framework prioritises controls by likely risk reduction, implementation effort, operational impact and cost. Progress is demonstrated through evidence rather than tool ownership or compliance claims alone.
Risk-led
Start with realistic attack paths and service consequences.
Resource-aware
Make effective use of existing people, platforms and licensing.
Care-conscious
Balance protection with continuity, accessibility and safeguarding.
Evidence-led
Measure whether controls are deployed, sustained and effective.
A different job, not a competing standard
How RACF-CC complements established frameworks
Established frameworks describe recognised cybersecurity outcomes, controls and management practices. RACF-CC focuses on the local implementation question: how can a resource-constrained organisation turn relevant principles into proportionate, prioritised and evidenced action?
Adds a practical method for sequencing work around credible risk, available resources, operational impact and evidence.
| Framework or approach | What it provides | Where RACF-CC helps |
|---|---|---|
| NIST CSF 2.0 and the NIST SP 800 series | High-level cybersecurity outcomes, a risk-management structure and detailed security guidance. | Helps translate relevant outcomes and guidance into a manageable sequence based on local risk, evidence and delivery constraints. |
| ISO/IEC 27001 | Requirements for an information security management system, centred on risk, governance and continual improvement. | Helps connect governance intent to practical technical work that a small team can implement and evidence. It does not replace formal ISO requirements or certification. |
| CIS Controls v8.1 and IG1 | Prioritised, practical safeguards, including an essential cyber-hygiene starting point through Implementation Group 1. | Adds local prioritisation around hybrid infrastructure, legacy dependencies, care-service impact, compensating controls and residual risk. |
| Zero Trust Architecture | Principles and architectural models built around explicit verification, resource protection and the removal of implicit trust. | Provides a staged route towards those principles where legacy systems, incomplete visibility or operational constraints make the target state difficult to implement immediately. |
Where an organisation has a contractual, regulatory, certification or formal assurance requirement, the relevant standard or framework should be used directly. RACF-CC helps organisations decide how to move towards recognised security outcomes when resources and operational constraints make full implementation difficult.
Eight connected domains
A complete path from prevention to assurance
Each domain can be adopted in stages, but the strongest results come from treating them as one connected system.
Identity and Access Management
Strengthen authentication, privileged access, guest governance and hybrid identity assurance.
Read the guide →Endpoint and Device Security
Improve device visibility, supported configurations, endpoint protection and management coverage.
Read the guide →Network Segmentation and Secure Connectivity
Reduce unnecessary trust and contain compromise across sites, wireless networks and remote access.
Read the guide →Configuration and Vulnerability Management
Find, prioritise and remediate exploitable weaknesses while managing unavoidable legacy risk.
Read the guide →Data Protection and Backup
Protect sensitive information and prove that essential data and services can be recovered.
Read the guide →Monitoring and Detection
Turn existing telemetry into a focused, sustainable view of suspicious activity.
Read the guide →Incident Response and Automation
Translate alerts into repeatable containment, communication, recovery and learning.
Read the guide →Governance, Risk and Framework Alignment
Connect controls to ownership, evidence, exceptions, organisational risk and continuous improvement.
Read the guide →Layered defence
How the eight domains reinforce each other
RACF-CC treats cybersecurity as a connected system. Each domain addresses a different part of risk, but the strongest outcomes come when controls reinforce one another across identity, devices, networks, data, monitoring, response and governance.
- 01 Identity & AccessRestrict access
Reduce the chance that compromised credentials become a route in.
- 02 Endpoint & DeviceEstablish device trust
Manage and harden devices before they are trusted.
- 03 Network & ConnectivityContain compromise
Limit lateral movement across systems, sites and services.
- 04 Configuration & VulnerabilityReduce exposure
Remove or contain exploitable weaknesses.
- 05 Data Protection & BackupLimit operational impact
Protect essential information and make recovery possible.
- 06 Monitoring & DetectionSee meaningful signals
Turn focused telemetry into evidence for investigation.
- 07 Incident Response & AutomationAct and recover
Convert evidence into containment, recovery and learning.
Connect ownership, policy, risk decisions, evidence, exceptions and continuous improvement across all seven operational domains.
Layers, not a mandatory sequence. Organisations may work across several domains at the same time according to risk and operational need.
The relationships are not purely linear. A single security outcome often depends on several domains working together, as the examples below show.
Control connections
Security outcomes cross domain boundaries
A control is rarely delivered or assured by one domain alone. These examples show how technical controls, operational processes and governance combine into one outcome.
Protecting authentication with MFA
Authentication becomes more dependable when identity policy is supported by device context, monitoring, response and accountable assurance.
Remediating a vulnerability
A scan finding only becomes risk reduction after it is evaluated, safely changed, validated and reflected in the organisation’s risk position.
Implementation cycle
From evidence to sustainable improvement
Understand
Establish the current state using configuration, telemetry, policy and operational evidence.
Prioritise
Rank controls by risk reduction, effort, service impact and cost.
Implement
Deliver realistic controls in manageable phases with clear ownership.
Evidence
Validate outcomes, record residual risk and feed learning into the next cycle.
