23
Recommendation
24th Report - Government cyber resilien…
Accepted in Part
We asked the Cabinet Office how it would increase the scale and pace of GovAssure to assess the cyber resilience of all of government’s critical systems. The Cabinet Office explained that it did not plan to assess 100% 43 C&AG’s Report, paras 14, 15 44 C&AG’s Report, para 19 45 …
Read more
We asked the Cabinet Office how it would increase the scale and pace of GovAssure to assess the cyber resilience of all of government’s critical systems. The Cabinet Office explained that it did not plan to assess 100% 43 C&AG’s Report, paras 14, 15 44 C&AG’s Report, para 19 45 Q 39 46 Q 44 47 Q 45 14 of critical systems through GovAssure.48 This was because GovAssure was one part of a wider system of assurance, which included department’s own cyber experts as the “first line of defence”. The Cabinet Office said that it had designed GovAssure to bring consistency and share best practice, but that government must balance its effort between assurance and frontline cyber security.49 We asked if that meant the Cabinet Office was happy with the current scale and pace of GovAssure. The Cabinet Office told us it wanted to increase the number of systems it assessed and it needed to make GovAssure quicker and easier to complete for departments.50
Show less
Government response AI summary
The government agrees to the recommendation, aiming for implementation by Spring 2026, and commits to requiring departments to identify and report critical systems through GovAssure, driving its adoption across government, and determining optimal assessment scale and frequency. However, it does not explicitly detail how GovAssure …
Read full response →
HM Treasury