Access and authentication is where CSCRF concentrates, and so does Akku

63 of 244 CSCRF guidelines mapped, from 88 mapping points, with 37 of the 63 in access and authentication alone.

The Cyber Security and Cyber Resilience Framework runs across six functions: governance, identify, protect, detect, respond and evolve. Akku maps to 63 of its 244 guidelines, and 37 of those 63 sit in access and authentication, which is the single largest concentration in the framework. CSCRF also requires that logs of user access to critical systems be uniquely identified and retained for at least two years.

  • Who this applies to
  • Which module carries which guidelines
  • What sits outside
63 / 244
CSCRF guidelines mapped
37 / 63
In access and authentication alone

From 88 overlapping mapping points across the platform.

Who this applies to

Market infrastructure institutions, credit rating agencies, asset management companies, custodians and stock brokers. CSCRF grades obligations by entity category, which changes reporting frequency and audit depth rather than which controls have to be in place.

Which module carries which guidelines

ModuleGuidelinesMapping points
UEMID.AM.S1-S4 (G2, G3, G4), PR.AA.S1-S9 (G2b), PR.AA.S15 (G1c, G4a, G4b, G4d, G4e, G4f), PR.IP.S1 (G2, G3), PR.IP.S2 (G1a, G1b, G1e, G1f), PR.IP.S15 (G1a, G1e), PR.MA.S2 (G2), PR.MA.S3 (G1-2)20
PAMPR.AA.S1-S9 (G1b, G1c, G3a, G3d, G4f), PR.AA.S4-S5 (G1), PR.AA.S10-S12 (G2a, G2b, G2c), PR.AA.S15 (G1c, G4c), PR.IP.S2 (G1a), PR.MA.S2 (G2, G3, G4), RS.AN.S1-S3 (G1-4)18
Workforce IAMID.RA.S4 (G2), PR.AA.S1-S9 (G1e, G1f, G1i, G1j, G3b, G4h), PR.AA.S4-S5 (G1), PR.AA.S6 (G1, G3, G4), PR.AA.S8 (G3), PR.AA.S10-S12 (G2b), PR.IP.S2 (G1a), PR.IP.S16-S17 (G1b), PR.MA.S2 (G2)17
CIAMID.RA.S4 (G2), PR.AA.S1-S9 (G1e, G1i, G1j, G4h), PR.AA.S16-S17 (G1b, G2i), PR.AT.S3 (G2, G3)9
IGAPR.AA.S1-S9 (G1a, G1b, G1c, G1g, G1h, G2a), PR.AA.S4-S5 (G2), PR.AA.S6 (G2), PR.AA.S15 (G4c)9
DLPPR.AA.S1-S9 (G1d, G3c), PR.AA.S8 (G3), PR.AA.S15 (G3a), PR.DS.S1-S3 (G1b, G1c, G1e, G4b), RS.AN.S1-S3 (G1-4)9
MDMID.AM.S1-S4 (G2, G3), PR.AA.S1-S9 (G2b, G4j), PR.AA.S16-S17 (G2o), PR.MA.S2 (G2)6

What sits outside

CSCRF mandates a 24x7 security operations centre. Akku feeds logs into a SOC and does not staff or operate one. The rest of what sits outside is network hardware, offensive testing, business continuity, and the governance the framework requires of the board.

Tell us which framework you're being measured against.

Send us the framework, the audit date and what you already run. We'll come back with the mapping for your environment and the evidence Akku produces for each control.