Purpose
Move from policy presence to assurance
Governance sustains every technical domain. RACF-CC does not require a large compliance team or enterprise governance platform. It creates a lightweight evidence trail showing which risks matter, which controls operate, where exceptions remain and who has accepted the residual exposure.
What good looks like
Trustees and leaders can see the principal cyber risks, control status, significant exceptions and improvement priorities in understandable terms; technical evidence supports policy claims; and incidents, scans and changes feed back into decisions.
Use consistent assurance language
The RACF-CC Control Assurance model distinguishes controls that are Implemented, Evidenced and Sustained without creating an organisational compliance badge. Explore the assurance model →
Risk picture
Common assurance failures
Paper compliance
A policy says a control exists, but no current evidence demonstrates enforcement.
Disconnected risk register
Risk ratings do not change when telemetry, incidents or exposure changes.
Unvalidated change
A security change is recorded without proving its intended outcome.
Informal exceptions
Legacy constraints persist without owner, compensating controls or review date.
Aggregate-score confidence
A headline score masks material gaps in individual controls or parts of the estate.
Unclear accountability
Cyber risk is treated as an IT issue rather than an organisational responsibility.
Prioritised action
The RACF-CC governance control set
| Priority | Control direction | Outcome | Evidence |
|---|---|---|---|
| First | Map each RACF-CC domain to organisational risk-register entries. | Connects cyber work to mission and care impact. | Domain-to-risk matrix. |
| First | Maintain a risk-tiered supplier and critical-service dependency register. | Focuses assurance on third parties whose failure or compromise would matter most. | Owned supplier records with access, evidence, incident and review details. |
| First | Map policy statements to controls, owners and current evidence. | Reveals enforcement gaps and unsupported claims. | Policy-control matrix. |
| First | Create an exception and residual-risk register. | Makes infeasible controls visible, owned and time-bound. | Approved exceptions with review dates. |
| Next | Use technical and operational evidence in periodic risk review. | Keeps risk ratings aligned with actual exposure. | Assurance pack and decisions. |
| Next | Require security changes to include risk, rollback and validation. | Proves that changes achieved their intended outcome. | Complete change records. |
| Next | Run a proportionate quarterly cyber assurance review. | Creates leadership visibility and tracked priorities. | Minutes, actions and evidence summary. |
| Develop | Maintain framework mappings and a continuous improvement loop. | Shows alignment without claiming certification or endorsement. | Crosswalk and completed improvements. |
Implementation
A four-phase roadmap
Phase 1
Create traceability
- Map domains to organisational risks
- Map policies to control evidence
- Assign control and risk owners
- Create the exception register
Phase 2
Review assurance
- Build a concise evidence pack
- Update risks from telemetry
- Add security validation to change
- Review overdue actions
Phase 3
Engage leadership
- Run quarterly assurance reviews
- Present risk in operational language
- Agree residual-risk decisions
- Test continuity assumptions
Phase 4
Improve continuously
- Feed incidents and scans into priorities
- Review framework alignment
- Measure control sustainability
- Refine investment decisions
Governance must support decisions, not paperwork
Keep the assurance pack short enough to maintain and clear enough for non-technical leaders. Report control outcomes, evidence quality, uncertainty and residual risk—not only activity counts or vendor scores.
Govern the movement from pilot to enforcement
Audit/report-only → pilot → validate → enforce → monitor → reviewGovernance should define approval, evidence, communications, exception and rollback expectations proportionate to the care impact of each change. Use the Safe Enforcement Pattern →
Make supplier dependency visible
Prioritise suppliers by the consequence of compromise or failure, not by questionnaire completion. Record access, data, responsibilities, assurance, incident arrangements, concentration and exit. Use the Supplier and Third-Party Risk guide →
Evidence
Measure ownership and assurance
Residual risk and escalation
Record governance and assurance gaps that remain
What may remain unresolved?
Incomplete policy-to-control mapping, weak evidence, overdue exceptions, unclear ownership, deferred investment and risks that remain above organisational appetite may persist.
Leadership capacity, missing evidence, competing care priorities, supplier dependencies, funding cycles or unresolved ownership can delay treatment.
Increase review frequency, assign interim owners, restrict exposure, require additional approval, improve monitoring and maintain explicit contingency decisions.
An authorised organisational leader owns the residual business risk; technical teams provide evidence and treatment advice rather than accepting it alone.
Review by the approved date and after incidents, material evidence change, missed actions, control failure or change in organisational risk appetite.
Risk above appetite, expired acceptance, absent owner, failed safeguard, repeated overdue action, regulatory concern or credible threat to care continuity.
Recording does not equal acceptance. Acceptance must be explicit, authorised, time-bound and supported by a decision to treat, tolerate, transfer or avoid the exposure.
References
Standards alignment
- NIST Cybersecurity Framework 2.0 — Govern, Identify, Protect, Detect, Respond and Recover outcomes.
- NIST SP 1305 — CSF 2.0 supply-chain risk management through the GV.SC category and supplier requirements.
- NCSC Supply Chain Security — supplier prioritisation, shared responsibilities, proportionate requirements, incident arrangements and over-reliance.
- NCSC Cyber Governance Code of Practice — critical board ownership and accountability.
- NCSC Cyber Security Toolkit for Boards — practical risk-management questions and indicators.
Framework complete
Use the eight domains as one system
Governance closes the loop: evidence from identity, endpoints, networks, vulnerabilities, data, monitoring and incidents informs the next cycle of prioritisation and improvement.
