Security Policy Framework

The Security Policy Framework (or "SPF") is a set of high-level policies on security, mainly affecting the UK government and its suppliers.[1][2]

The SPF has 70 "mandatory requirements", which are grouped into 7 areas:[3]

1: Governance, Risk Management & Compliance
2: Protective Marking & Asset Control
3: Personnel Security
4: Information Security & Assurance
5: Physical Security
6: Counter-Terrorism
7: Business Continuity

These mandatory requirements are a baseline which apply to all UK government departments; higher requirements may apply in some cases.[4] Public-sector bodies are responsible for managing their own technical security risks, but can draw on expertise and guidelines provided by CESG and the Cabinet Office. The Centre for Protection of National Infrastructure also helps protect critical infrastructure.[5] The Ministry of Defence has its own separate policies and systems.

The SPF superseded the Manual of Protective Security. Part of the SPF is produced by CESG, and part by the Cabinet Office's Security Policy Division.[6]

External links

References