UK CYBER RESILIENCE · 2026
EVIDENCE INTELLIGENCE FOR CYBER ASSURANCE
CAF OUTCOME · A2.a — Policy and process
HUMAN REVIEW REQUIRED
EVIDENCE REFERENCES · 02 CONNECTED
Information Security Policy.pdf
PAGE 14 · §4.2
SOURCE DOCUMENT EXTRACT
“The policy is reviewed annually by the Information Security Steering Group.”
POTENTIAL EVIDENCE GAP — No evidence of review effectiveness was identified in the supplied material.
THE EVIDENCE PROBLEM
POLICY
RISK REGISTER
PEN TEST
STANDARD
GOVERNANCE
SUPPLIER
INCIDENT
TECHNICAL CONTROL
EVIDENCE → OUTCOMES → GAPS → ACTIONS
SIFTR creates an initial evidence picture so professionals can spend more time investigating, challenging and making judgements.
CAF A2.a — Policy and process
SUPPORTING EVIDENCE IDENTIFIED · 3 SOURCES
Information Security Policy.pdf
Risk Management Standard.pdf
Security Governance Terms of Reference.pdf
The supplied evidence describes governance responsibilities, but does not clearly demonstrate how effectiveness is periodically reviewed.
HUMAN REVIEW REQUIRED
START SMALL
Controlled scope. No certification claim. Human review remains essential.
CAF EVIDENCE READINESS
Evidence identified — 24
Outcomes explored — 8
Potential gaps — 5
Human review areas — 3
Evidence sources — 12
SIFTR
Find evidence
Organise evidence
Map evidence
Surface supporting extracts
Identify potential gaps
Maintain traceability
ASSURANCE PROFESSIONAL
Challenge
Interpret
Validate
Investigate
Exercise judgement
Sign off
SIFTR assists assurance. It doesn’t certify it.
SIFTR reduces repetitive evidence discovery and mapping so cyber-assurance professionals can spend more time challenging evidence, investigating gaps and exercising judgement.
TRADITIONAL
Collect → Search → Open → Read → Copy → Map → Reference → Review → Judge
SIFTR
Evidence intelligence → Review → Challenge → Judge
Move from point-in-time assessment preparation to continuous evidence readiness.
JAN Evidence baseline → MAR Evidence changed → JUN Action completed → SEP New gap identified → DEC Assessment ready

Start with a controlled evidence sample and see what SIFTR can uncover.
START SMALL
Request a complimentary CAF Evidence Readiness Check using a controlled sample of organisational evidence. No evidence upload is required at this stage.
WHAT YOU’LL RECEIVE
Evidence identified
Relevant CAF outcomes
Source references
Potential evidence gaps
Areas requiring professional review

