Skip to content

Risk & Governance

Security architecture must be grounded in risk management and aligned to governance frameworks. This section covers the foundational governance tools, UK-specific frameworks, and organisational security practices.

In this section

PageWhat it covers
Asset ManagementHardware, software, and data asset inventory and lifecycle
Supply Chain SecurityThird-party risk, software supply chain, SBOM
Cyber Assessment Framework (CAF)NCSC CAF for CNI and public sector organisations
Cyber EssentialsUK government-backed baseline certification scheme
Operational Security (OPSEC)Protecting information about your organisation and operations
People-Centred SecurityHuman factors, security culture, and awareness
Penetration TestingTypes, scoping, methodology, and UK certification schemes

Released under the MIT Licence.