National Cybersecurity Authority (NCA)
NCA Essential Cybersecurity Controls
The baseline cyber security controls for government entities and critical national infrastructure.
Who it applies to
Government organisations, entities operating critical national infrastructure and private organisations that the NCA brings into scope.
What internal audit has to show
The controls are organised in domains with a compliance self-assessment that internal audit is expected to verify independently and evidence.
What Oversight does with NCA ECC
- Loads the control list into the audit universe and maps each control to the owning department and the systems in scope.
- Drafts the compliance review program with the evidence expected for each control and the sampling where it applies.
- Issues evidence requests to owners, tracks receipt and records the examination result per control.
- Drafts the compliance findings and keeps the status of remediation visible until closure.
Typical engagements
- ECC compliance review
- Cyber security governance review
- Data and information protection review
See a NCA ECC engagement drafted from your scope
Bring the regulation and your org structure. The walkthrough builds the universe, drafts a program and traces a finding to its source on your documents.
Request a demo