CAF Incident Response Master Document Register

A 91-document, Excel-ready master register mapping every UK CAF incident response document to its NCSC outcome

CAF Master Doc Register UK CAF

What is the CAF-IR Master Document Register? 

The CAF-IR Master Document Register is the single, Excel-ready control sheet behind a complete UK Cyber Assessment Framework (CAF) incident response documentation set. Instead of tracking policies, procedures, playbooks, registers and evidence logs separately across shared drives and inboxes, you manage all 91 documents through one structured spreadsheet — supplied as a free, adaptable CSV template you take as your baseline, populate with your own owners and dates, and run as the live single source of truth for your incident response documentation.

Every row maps a document directly to the specific CAF outcome (or outcomes) it evidences — from Board Direction under A1 through to Lessons Learned under D2 — so when an assessor or internal auditor asks "where's your evidence for this outcome," the answer is a filter, not a search.

What's Inside?

Column

Purpose

Document ID

Unique identifier in the CAF-IR-[TYPE]-[NNN] format — never changed, never reused.

Document name

The document's working title.

Category

Which of the 13 categories the document belongs to.

Document type

Policy, procedure, plan, matrix, register, log, playbook, and 8 other type codes.

Owner

The role accountable for maintaining the document.

Approver

The role or body that signs it off — Board / SIRO for the most sensitive artefacts.

CAF outcome reference

The specific CAF Indicator of Good Practice(s) the document evidences, e.g. A1.a, D2.b.

Evidence weight

Core evidence or Supporting evidence — see below.

Format

Word to PDF, Excel, GRC platform, and so on.

Review frequency

How often the document must be revisited.

Retention period

How long versions must be kept.

Status

Current lifecycle state (supplied as "Not started (template)" until you adapt it).

Version

Current version number.

Last reviewed date

Populated once you put the register into live use.

Next review date

Drives your review cadence once populated.

Linked documents

Cross-references to dependent artefacts.

Evidence location

Where the live file or record actually lives.

Notes

Free-text adaptation or context notes.

 

The 13 Categories

The 91 documents are grouped into 13 categories, each aligned to a stage of the incident response lifecycle and mapped back to the CAF objective it evidences:

  1. Governance and accountability (8 documents) — policy, escalation procedure, and the roles/RACI matrices that evidence CAF's Governance principle (A1).
  2. Risk and threat understanding (8 documents) — the risk assessment and threat intelligence artefacts behind Risk Management (A2).
  3. Essential functions, assets and dependencies (5 documents) — the asset and dependency mapping behind Asset Management (A3).
  4. Supply chain incident support (7 documents) — third-party and supplier incident coordination evidencing Supply Chain (A4).
  5. Security monitoring and logging (8 documents) — the logging and monitoring standards feeding Security Monitoring (C1).
  6. Alerting, triage and threat hunting (8 documents) — alert handling and proactive discovery evidencing Proactive Security Event Discovery (C2).
  7. Incident response planning (8 documents) — the core response plans behind Response and Recovery Planning (D1).
  8. Response and recovery capability (8 documents) — the operational playbooks that execute the plan.
  9. Resilience, backups and restoration (6 documents) — recovery and restoration evidence supporting Resilient Networks and Systems (B5).
  10. Testing and exercising (6 documents) — exercise programmes and reports evidencing tested response capability.
  11. Post-incident analysis and lessons learned (7 documents) — root cause analysis and plan-update records behind Lessons Learned (D2).
  12. Staff awareness and training (5 documents) — training records and programmes evidencing Staff Awareness and Training (B6).
  13. Evidence, registers and CAF outcome mapping (7 documents) — the master incident register and cross-referencing artefacts an assessor reviews directly.

Core Evidence vs. Supporting Evidence

Every document in the register carries an evidence weight: of the 91 documents, 54 are Core evidence — the artefacts an assessor or internal reviewer expects to see directly against a named CAF outcome — and 37 are Supporting evidence, which strengthen the response capability and provide context without being the primary evidence for any single outcome. This split lets you prioritise build-out: get the 54 core documents in place and reviewed first, then layer in supporting evidence as capacity allows.

Document Types at a Glance

The 91 documents span 15 distinct types, led by registers (17), plans (10), templates (8), checklists (7), matrices (6), records (6), logs (6), playbooks (6) and assessments (6), with policies, procedures, maps, guides, standards and reports filling out the remainder. This mix reflects what incident response documentation actually needs to be — not just policy statements, but the live registers, logs and playbooks a response team uses in the moment.

Numbering Convention

Every document is identified as CAF-IR-[TYPE]-[NNN], where the type code reflects its function (POL for policies, PRO for procedures, MTX for matrices, REG for registers, PLN for plans, PLY for playbooks, and more) and the number is unique within that type. IDs are fixed for the life of the document — they never change and are never reused — so cross-references, audit trails and version history stay coherent as the register evolves.

Mapped to CAF Outcomes Across All Four Objectives

The register's CAF outcome references span all four CAF objectives relevant to incident response:

  • Objective A — Managing security risk: A1 (Governance), A2 (Risk Management), A3 (Asset Management), A4 (Supply Chain).
  • Objective B — Protecting against cyber attack: B5 (Resilient Networks and Systems), B6 (Staff Awareness and Training).
  • Objective C — Detecting cyber security events: C1 (Security Monitoring), C2 (Proactive Security Event Discovery).
  • Objective D — Minimising the impact of cyber security incidents: D1 (Response and Recovery Planning), D2 (Lessons Learned).

Each document's CAF outcome reference column can carry more than one Indicator of Good Practice — for example, the Cyber Incident Management Policy maps to both A1.a and A1.b — so the register reflects the reality that a single well-built document often evidences several related outcomes at once.

Key Benefits

  • One controlled source of truth. All 18 columns — ownership, approval, CAF mapping, review dates and evidence location — live in a single maintained sheet instead of scattered across a shared drive.
  • Assessment-ready by design. The Core/Supporting evidence split tells you in advance which documents a CAF assessment will focus on and which strengthen your position without being the headline evidence.
  • Direct CAF outcome traceability. Every document ties back to a named Indicator of Good Practice, so gap analysis against a specific CAF principle is a filter, not a manual cross-check.
  • Board-level accountability built in. The Approver column names Board / SIRO sign-off explicitly wherever CAF's governance expectations require it, keeping accountability visible rather than implied.
  • You save weeks of setup. Rather than building a documentation inventory from scratch, you adapt a professionally structured register with 91 documents and their relationships already mapped.

** GDPR & Privacy ** We wholeheartedly believe in your and our rights to privacy and in the GDPR. The bottom of the page explains how we use your data.

Please Fill the Form Below To Get Your Free Copy of the CAF Incident Response Master Document Register

cyber-essentials-certification
NCSC Certified Training B&W 300px
CSC

Frequently Asked Questions about the CAF Incident Response Master Document Register

  • 1. How many documents are in the CAF-IR Master Document Register?

    The register contains 91 documents across 13 categories, spanning governance, risk, asset management, supply chain, monitoring, alerting, response planning, recovery, resilience, testing, lessons learned, training, and evidence registers.

  • 2. What's the difference between "Core evidence" and "Supporting evidence" in the register?

    Core evidence documents (54 of the 91) are the artefacts an assessor or reviewer expects to see directly against a named CAF outcome. Supporting evidence documents (37) strengthen the incident response capability and provide useful context, without being the primary evidence for any single outcome on their own.

  • 3. How does the register map to the NCSC Cyber Assessment Framework?

    Every document carries a CAF outcome reference column identifying the specific Indicator(s) of Good Practice it evidences, spanning Objective A (Governance, Risk Management, Asset Management, Supply Chain), Objective B (Resilient Networks and Systems, Staff Awareness and Training), Objective C (Security Monitoring, Proactive Security Event Discovery), and Objective D (Response and Recovery Planning, Lessons Learned).

  • 4. What is the CAF-IR numbering convention?

    Every document is identified as CAF-IR-[TYPE]-[NNN], where the type code reflects its function (for example POL for policies, MTX for matrices, REG for registers) and the number is unique within that type. IDs never change and are never reused, keeping cross-references stable as documents are revised.

     

  • 5. Is this register ready to use as-is, or does it need to be adapted?

    It's supplied as a free, adaptable CSV template. You take it as your baseline, replace role placeholders with named owners and approvers for your organisation, populate the version, review and retention dates, and record where each document's live evidence actually sits before treating it as your working control sheet.

  • 6. Who should own and approve the documents in this register?

    Ownership sits mostly with the CISO and Head of Incident Response across most categories, while approval for governance-critical documents — such as the incident management policy and escalation procedure — sits explicitly with the Board or Senior Information Risk Owner (SIRO), reflecting CAF's expectation of board-level accountability for security governance.

  • 7. How often should documents in the register be reviewed?

    Review frequency is tracked per document in its own column, with most core governance and response documents set to at least annual review and after any major incident or exercise, so the register drives an ongoing review cadence rather than a one-off setup exercise.

  • 8. Can this register be imported into an existing GRC platform?

    Yes. It's supplied as a CSV with 18 structured columns, ready to import directly into Excel, SharePoint or a GRC platform, so it can sit alongside your existing risk and compliance tooling rather than replacing it.

     

We are industry experienced practitioners when it comes to cyber security training & cyber security consultancy services

1487652208_graduationcap

Training

We offer a host of courses including our NCSC Assured Training in Cyber Incident Planning and Response and our NCSC Assured Training in Building and Optimising Incident Response Playbooks.

1487652701_like

Virtual CISO Services

Hands On, full-support 'Security As a Service', specifically designed for organisations that require access to experienced cybersecurity, governance, risk and compliance professionals.

1487652784_calendar-3

Virtual Cyber Assistant

A unique, affordable, subscription-based, cybersecurity service for small to medium businesses, offering 280+ services in cybersecurity.

1487652846_microphone

Cyber Crisis Tabletop Exercises

Scenario-based, verbally-simulated tabletop attack exercises that test your organisation's ability to effectively respond to a cyber-attack.

1487652632_search

Ransomware Tabletop Exercise

Measure your organisation’s Ransomware Readiness with a unique blend of verbal and visual simulations and ransomware scenario walkthroughs.

1487652567_line-chart

Executive Cyber Awareness Sessions

Specially designed for executive management, CEOs and boards of directors, engaging them in a business context to help explain the threats and risks from cyber-attacks.

How we use your data:

  • Contact you about our services including, but not limited to, training, trusted advisory and consultancy.
  • Keep you posted on free resources and documents.
  • Update you on upcoming webinars and surveys.
  • Update you when we host our ground-breaking Wisdom of Crowds events.
  • Ask you, every now and then, if you want to take part in crowdsourced initiatives.
  • Our partners (we carefully select our partners) may contact you to arrange or demo or share more information with you about their products or services when you watch one of our sponsored webinars. Remember, you can always tell us or our partners, "No, not interested".
Cyber Incident Response Plan Template