标准解读

Cyber resilience: what constitutes adequate evidence

标准解读

Explains what constitutes adequate evidence in relation to cyber resilience, with attention to decision authority, material exceptions and continuing assurance.

In 2024, consideration of cyber resilience must take account of the growing dependence on digital education infrastructure and the responsibilities it places before education systems. For the applicable requirement, interpretation should begin with the intended outcome, then identify the controls and evidence needed to show that the outcome is achieved across the declared scope.

A narrow control applied to the relevant process may create false assurance. In the present context, retention beyond an identified need, secondary use without adequate authority and inaccurate data affecting decisions may produce acceptable aggregate reporting while individual learners remain exposed to material disadvantage. For cyber resilience, the test should deliberately include exceptions and cases in which the expected outcome was not achieved.

Applicable scope

In the context of cyber resilience, responsibility should be identifiable at the point where consequential decisions are made. For the matter, a provider should be able to trace the expectation from approved policy through implementation, monitoring, identified exceptions and corrective action. Incomplete evidence, unmanaged conflict, absent learner groups or material learner impact require a higher level of review.

The reference point is the growing dependence on digital education infrastructure. Assurance concerning the matter should state the scope examined, evidence relied upon and any condition preventing a complete conclusion. Unsupported elements should remain open. For decisions concerning cyber resilience, that distinction should remain visible in the decision record, public reporting and later review.

Evidence concerning cyber resilience should be relevant to the stated requirement, sufficiently complete for the affected scope, current for the decision period and attributable to a source with knowledge or control of the matter. Volume does not cure a gap in relevance. A formally complete record is not reliable if its scope or measure does not correspond to the decision being made.

  • Test incident and recovery arrangements.
  • Control third-party processing.
  • Assign accountable data owners, identifying the accountable function and affected scope.
  • Limit and review access.
  • Minimise collection.

Implementation and evidence

Proportionality in relation to cyber resilience does not mean reduced protection for learners exposed to greater risk. Security, privacy and data quality are related but distinct. A secure record may still be inaccurate or used without adequate authority, and a lawful use may still be poorly governed. Within the scope under review, an isolated example cannot establish consistent operation, and an isolated failure should be evaluated for materiality, recurrence and systemic effect. No exception should continue without a documented basis, accountable approval and scheduled review.

Relevant evidence for cyber resilience will normally include lawful authority and consent records where relevant, a register of information assets and purposes, incident response and notification records, retention and secure disposal evidence, and supplier and transfer arrangements. Evidence outside the relevant period or scope should be identified and given no more weight than its limitations permit. An unresolved contradiction is a limitation on the conclusion and should be reported as such.

When examining cyber resilience, decisions concerning the matter should remain traceable to the information available for the stated reference period. Without this distinction, a reporting change may be mistaken for improvement or deterioration in educational practice.

Assessment of conformity

Implementation of cyber resilience can be tested without imposing unnecessary reporting. A competent review of the assurance conclusion should define the proposition to be established, identify the minimum combination of records, test authenticity and reconcile contradictions. Expand the sample where an exception, complaint or material unexplained variation indicates that the initial evidence may not be representative. Reuse of existing information is appropriate only where its purpose, scope and reliability correspond to the decision under review.

As regards cyber resilience, the final record on the control should identify the applicable expectation, the relevant scope, the evidence examined, the sampling basis, material exceptions and the reason for the conclusion. Departure from an illustrative method may be justified where equivalent outcome and evidence are established. A limitation preventing a complete conclusion should remain visible and unresolved until suitable evidence is obtained.

  • Does it cover the material scope?
  • What would require expanded testing?
  • What fact must be established?
  • Is the evidence current and attributable?
  • Do independent sources agree?

Review and corrective action

For cyber resilience, the public interest is not confined to institutional compliance. For the control, education information should be collected for a defined purpose, protected in proportion to its sensitivity and retained only for an authorised period.

Accountability for the assurance conclusion should follow decision-making authority. Within the scope under review, relevant evidence should reach the body authorised to commit resources, amend policy or accept residual risk, and its judgement should be recorded. For cyber resilience, where work is delegated, the record should continue to identify who is accountable for material consequences to learners.

For cyber resilience, a clear objective, proportionate evidential basis and account of affected learners are required. The decision record for cyber resilience should state the unsupported element and the further work required.