Freedom of information (FOI) disclosure log
23317
Date Sent: May 26, 2026
Conclusion: Released In Full
Description: Has the Council formally adopted the Cyber Assessment Framework (CAF) as its primary cyber security assurance model? If yes, on what date was the framework adopted, and what is the current progress of its implementation (e.g., pilot stage, partial rollout, or fully implemented)? If the Council has not adopted the CAF, is there a formal plan or timeline to do so in the 2026/27 financial year (or beyond)? How many Full-Time Equivalent (FTE) staff members are currently allocated to the implementation, assessment, or ongoing maintenance of the CAF? Has the Council recruited new staff specifically to handle the requirements of the CAF, or has the workload been absorbed by existing IT/security teams?
Attachments: FOI_Response 452.docx