National Cybersecurity Authority (NCA)

    NCA Essential Cybersecurity Controls

    The baseline cyber security controls for government entities and critical national infrastructure.

    Who it applies to

    Government organisations, entities operating critical national infrastructure and private organisations that the NCA brings into scope.

    What internal audit has to show

    The controls are organised in domains with a compliance self-assessment that internal audit is expected to verify independently and evidence.

    What Oversight does with NCA ECC

    • Loads the control list into the audit universe and maps each control to the owning department and the systems in scope.
    • Drafts the compliance review program with the evidence expected for each control and the sampling where it applies.
    • Issues evidence requests to owners, tracks receipt and records the examination result per control.
    • Drafts the compliance findings and keeps the status of remediation visible until closure.

    Typical engagements

    • ECC compliance review
    • Cyber security governance review
    • Data and information protection review

    See a NCA ECC engagement drafted from your scope

    Bring the regulation and your org structure. The walkthrough builds the universe, drafts a program and traces a finding to its source on your documents.

    Request a demo