KubitDocs · Legislation

NCSC 10 Steps to Cyber Security (published 11 May 2021)

Provisions the documents cite: the ten steps

What it requires

NCSC guidance aimed at medium to large organisations with someone dedicated to managing cyber security, summarising NCSC advice for security professionals and technical staff. The ten steps are risk management, engagement and training, asset management, architecture and configuration, vulnerability management, identity and access management, data security, logging and monitoring, incident management and supply chain security. For a small contractor the proportionate evidence is usually Cyber Essentials; this guidance frames the wider management approach.

The instrument itself: https://www.ncsc.gov.uk/collection/10-steps. The summary above is our plain-English reading, not the text of the instrument — always work from the source.

How this entry is kept current

  • Citation status: cited from the primary source.
  • Watched by: NCSC page — check the reviewed date at each monthly horizon scan.
  • Source last checked by the automated scan: not yet — first scan pending.

Every source is re-checked monthly and the result is published in the scan log. A change that alters what a document should say raises a revision, and past buyers of that document are told.

The 1 document that cite it

Every KubitDocs document prints its statutory basis on the form itself, so the person signing can verify the citation rather than take our word for it.

Company policies