Skip to main content

Cyber Security and Resilience Method (CSRM)

The NCSC has developed a Cybersecurity and Resilience Method (CSRM) to help organisations and businesses improve how they identify risks, protect their systems and respond to cyberthreats.

As digitalisation becomes increasingly prevalent in society and the business world, ensuring cybersecurity and resilience is becoming an ever-greater challenge. Although numerous standards, recommendations and models relating to cyber resilience already exist, organisations and businesses often do not know how to approach the issue or how to strengthen and improve their cybersecurity and resilience in the long term. What is often missing are specific, practical guidelines and points of reference.

The NCSC's Cybersecurity and Resilience Method (CSRM) addresses this need by offering a structured, five-step approach. This enables organisations and businesses, regardless of their size or sector, to strengthen and improve their cybersecurity and resilience sustainably.

Step-by-step approach

The method is based on an enhanced baseline security approach and consists of the following steps:

Step 1

Analyse the organisation’s or business’s key activities and business and production processes.

Step 2

Identify the IT resources that support these activities and processes, and group them into IT objects requiring protection.

Step 3

Determine the protection requirements for each relevant IT object. In the simplest case, this is a binary decision as to whether the IT object has an increased need for protection or not.

Step 4

Create a security plan for each IT object that requires increased protection. This plan should describe how the relevant security threats should be addressed.

Step 5

Implement the technical and organisational measures (TOMs) for baseline protection, as well as the additional TOMs set out in the security plans.

A priority-based and iterative approach

Although the CSRM is structured as a five-step method, in practice it can make sense to start with the most important processes and IT objects, and work through the rest later. This approach is not ideal, as many IT objects are interconnected and the resulting dependencies also need to be taken into account in the security concepts. In practice, however, it may still be a useful way to proceed.

Ongoing development of the CSRM

The CSRM is currently undergoing testing and further development in collaboration with selected partners and interested parties. It will be made available to the public as a recommendation. Where appropriate, industry associations can adopt the method and recommend it to their members. Regulators can adapt and specify the method according to their needs and make it binding within their remit. This can be done in addition to, or instead of, the minimum standard for improving ICT resilience issued by the Federal Office for National Economic Supply (FONES).

Documents

Feedback Form

We would like to know your opinion on the content of the CSRM method, so that we can better adapt such products to your needs in the future. Therefore, we would be grateful if you could reply to the following questions (about 2 minutes). You can then send us the form by clicking on the “Submit” button.