A 91-document, Excel-ready master register mapping every UK CAF incident response document to its NCSC outcome
The CAF-IR Master Document Register is the single, Excel-ready control sheet behind a complete UK Cyber Assessment Framework (CAF) incident response documentation set. Instead of tracking policies, procedures, playbooks, registers and evidence logs separately across shared drives and inboxes, you manage all 91 documents through one structured spreadsheet — supplied as a free, adaptable CSV template you take as your baseline, populate with your own owners and dates, and run as the live single source of truth for your incident response documentation.
Every row maps a document directly to the specific CAF outcome (or outcomes) it evidences — from Board Direction under A1 through to Lessons Learned under D2 — so when an assessor or internal auditor asks "where's your evidence for this outcome," the answer is a filter, not a search.
|
Column |
Purpose |
|
Document ID |
Unique identifier in the CAF-IR-[TYPE]-[NNN] format — never changed, never reused. |
|
Document name |
The document's working title. |
|
Category |
Which of the 13 categories the document belongs to. |
|
Document type |
Policy, procedure, plan, matrix, register, log, playbook, and 8 other type codes. |
|
Owner |
The role accountable for maintaining the document. |
|
Approver |
The role or body that signs it off — Board / SIRO for the most sensitive artefacts. |
|
CAF outcome reference |
The specific CAF Indicator of Good Practice(s) the document evidences, e.g. A1.a, D2.b. |
|
Evidence weight |
Core evidence or Supporting evidence — see below. |
|
Format |
Word to PDF, Excel, GRC platform, and so on. |
|
Review frequency |
How often the document must be revisited. |
|
Retention period |
How long versions must be kept. |
|
Status |
Current lifecycle state (supplied as "Not started (template)" until you adapt it). |
|
Version |
Current version number. |
|
Last reviewed date |
Populated once you put the register into live use. |
|
Next review date |
Drives your review cadence once populated. |
|
Linked documents |
Cross-references to dependent artefacts. |
|
Evidence location |
Where the live file or record actually lives. |
|
Notes |
Free-text adaptation or context notes. |
The 91 documents are grouped into 13 categories, each aligned to a stage of the incident response lifecycle and mapped back to the CAF objective it evidences:
Every document in the register carries an evidence weight: of the 91 documents, 54 are Core evidence — the artefacts an assessor or internal reviewer expects to see directly against a named CAF outcome — and 37 are Supporting evidence, which strengthen the response capability and provide context without being the primary evidence for any single outcome. This split lets you prioritise build-out: get the 54 core documents in place and reviewed first, then layer in supporting evidence as capacity allows.
The 91 documents span 15 distinct types, led by registers (17), plans (10), templates (8), checklists (7), matrices (6), records (6), logs (6), playbooks (6) and assessments (6), with policies, procedures, maps, guides, standards and reports filling out the remainder. This mix reflects what incident response documentation actually needs to be — not just policy statements, but the live registers, logs and playbooks a response team uses in the moment.
Every document is identified as CAF-IR-[TYPE]-[NNN], where the type code reflects its function (POL for policies, PRO for procedures, MTX for matrices, REG for registers, PLN for plans, PLY for playbooks, and more) and the number is unique within that type. IDs are fixed for the life of the document — they never change and are never reused — so cross-references, audit trails and version history stay coherent as the register evolves.
The register's CAF outcome references span all four CAF objectives relevant to incident response:
Each document's CAF outcome reference column can carry more than one Indicator of Good Practice — for example, the Cyber Incident Management Policy maps to both A1.a and A1.b — so the register reflects the reality that a single well-built document often evidences several related outcomes at once.
** GDPR & Privacy ** We wholeheartedly believe in your and our rights to privacy and in the GDPR. The bottom of the page explains how we use your data.
The register contains 91 documents across 13 categories, spanning governance, risk, asset management, supply chain, monitoring, alerting, response planning, recovery, resilience, testing, lessons learned, training, and evidence registers.
Core evidence documents (54 of the 91) are the artefacts an assessor or reviewer expects to see directly against a named CAF outcome. Supporting evidence documents (37) strengthen the incident response capability and provide useful context, without being the primary evidence for any single outcome on their own.
Every document carries a CAF outcome reference column identifying the specific Indicator(s) of Good Practice it evidences, spanning Objective A (Governance, Risk Management, Asset Management, Supply Chain), Objective B (Resilient Networks and Systems, Staff Awareness and Training), Objective C (Security Monitoring, Proactive Security Event Discovery), and Objective D (Response and Recovery Planning, Lessons Learned).
Every document is identified as CAF-IR-[TYPE]-[NNN], where the type code reflects its function (for example POL for policies, MTX for matrices, REG for registers) and the number is unique within that type. IDs never change and are never reused, keeping cross-references stable as documents are revised.
It's supplied as a free, adaptable CSV template. You take it as your baseline, replace role placeholders with named owners and approvers for your organisation, populate the version, review and retention dates, and record where each document's live evidence actually sits before treating it as your working control sheet.
Ownership sits mostly with the CISO and Head of Incident Response across most categories, while approval for governance-critical documents — such as the incident management policy and escalation procedure — sits explicitly with the Board or Senior Information Risk Owner (SIRO), reflecting CAF's expectation of board-level accountability for security governance.
Review frequency is tracked per document in its own column, with most core governance and response documents set to at least annual review and after any major incident or exercise, so the register drives an ongoing review cadence rather than a one-off setup exercise.
Yes. It's supplied as a CSV with 18 structured columns, ready to import directly into Excel, SharePoint or a GRC platform, so it can sit alongside your existing risk and compliance tooling rather than replacing it.
We offer a host of courses including our NCSC Assured Training in Cyber Incident Planning and Response and our NCSC Assured Training in Building and Optimising Incident Response Playbooks.
Hands On, full-support 'Security As a Service', specifically designed for organisations that require access to experienced cybersecurity, governance, risk and compliance professionals.
A unique, affordable, subscription-based, cybersecurity service for small to medium businesses, offering 280+ services in cybersecurity.
Scenario-based, verbally-simulated tabletop attack exercises that test your organisation's ability to effectively respond to a cyber-attack.