Change description : 2025-08-11 17:11:00: Added new details mapping the cyber governance code to the ISACA CMMI, WEF Principles for Board Governance of Cyber Risk, and ISO 27001. [Policy papers and consultations]
ThisThese mapping documentdocuments complementscomplement thethe Cyber Governance Code of Practice and andaim willto help businesses and organisations understand the Code.
The government is working with industry to improve the management of digital risks and improve cyber resilience across the economy. As part of this the government has launched a new Cyber Governance Code of Practice. To support adoption of this Code, the Department for Science, Innovation and Technology (DSIT) has created a Cyber Governance Mapping document for boards, directors and Chief Information Security Officers (or equivalent).
The andmapping internationaldocuments stakeholders.were Itwascreated in response to feedback from industry, received throughthrough a consultation on the Cyber Governance Code of Practice (the (theCode), which stated that greater clarification was needed on how the Code fits into the current cyber standards landscape. TheThis mapping document addresses this by illustrating where there are similarities and differences between the Code and other domestic and international cyber standards and frameworks.
ThisThese mapping documentdocuments can behelp usedbyorganisations tounderstand what actions of the Code they may already be implementing through adherence to other cyber standards and frameworks.
Themappingdocumentisalive document.documents. Additional domestic and international cyber standards and frameworks will be included as they are completed. The document will be periodically reviewed from time to time and updated accordingly, including incorporating any new standards and frameworks that are published.
TheThese mapping documentdocuments isare illustrative and should only be used as a point of reference. ItThey isare not intended to be authoritative or be taken as legal advice on compliance with the standards or frameworks mentioned.