NATO Cyber Defence Policy and NATO Computer Incident Response Capability (NCIRC)
Evidence request list. 8 controls, 8 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 12 September 2026. Published by The Art of Service.
Classified Systems
Maintain strict segregation of NATO classified networks (NATO Restricted / NATO Confidential / NATO Secret / Cosmic Top Secret) from unclassified networks per AC/35-D/2002 + AC/35-D/2004 + AC/35-D/2005 NATO Security Policies. Apply cross-domain solutions (CDS) per AC/322(SC/4)WP(2017) Communication Information System Cryptographic Policy. Handle COMSEC material per ACO Directive 70-1 + NATO Comsec Authority (NCSA). Implement TEMPEST controls + media sanitisation and destruction per NATO Industrial Security TEMPEST programme.
- Network architecture diagram showing classification levels
- Cross-domain solution authorisation
- COMSEC custody records
- NCSA inspection report
- TEMPEST zoning certificate
- Media destruction certificate
- No segregation evidence
- Unauthorised CDS
- Lapsed COMSEC custody
- No TEMPEST zoning
Cyber Defence Policy
Align with the NATO Cyber Defence Policy first established at the 2008 Bucharest Summit + revised at the 2014 Wales Summit (recognising cyberspace as a domain of operations + reaffirmed at 2016 Warsaw Summit as a domain of operations equal to land + sea + air) + further revised at the 2021 Brussels Summit (Comprehensive Cyber Defence Policy with explicit Article 5 application + 2023 Vilnius Summit (counter-hybrid + ransomware framing) + 2024 Washington Summit declaration (75th anniversary + Integrated Cyber Defence Centre activation at SHAPE Mons). Maintain national alignment via Allied Cyber Defence Plan + Comprehensive Approach + NATO Defence Planning Process (NDPP) cyber chapter.
- National Cyber Defence Strategy referencing NATO policy
- Summit declaration acknowledgement
- NDPP cyber chapter compliance
- Allied Cyber Defence Plan participation
- Cyber Defence Pledge progress report
- Article 5 cyber threshold analysis
- No reference to NATO policy
- Missing summit alignment
- No NDPP cyber chapter
- Outdated Pledge report
Incident Response
Operate incident triage and categorisation per NATO incident severity matrix (Cat I to Cat V) aligned with NCIRC reporting taxonomy. Maintain capability to support NATO Rapid Reaction Teams (RRT) per the Cyber Defence Pledge - deployable cyber experts who can be activated within 48 hours to assist NATO nations under significant cyber attack. Coordinate with EU Cyber Diplomacy Toolbox + UN Group of Governmental Experts (GGE) + Open-Ended Working Group (OEWG) responsible state behaviour norms. Maintain incident logs for minimum 7 years.
- Incident response plan with NATO severity categories
- RRT deployment readiness evidence
- Incident log retention (7 years)
- NCIRC notification records
- EU Cyber Diplomacy Toolbox alignment
- NATO-EU joint exercise records
- No NATO severity alignment
- Missing RRT capability
- Short incident retention
- No NATO-EU coordination
NCIRC Operations
Operate or interface with the NATO Computer Incident Response Capability (NCIRC) technical centre run by the NATO Communications and Information (NCI) Agency from SHAPE (Mons Belgium) + NATO HQ (Brussels) covering 24/7 monitoring + intrusion detection + threat hunting + incident response + forensics across all NATO enterprise networks (NS-WAN + NU-WAN + missions and operations). Integrate with the NATO Cyber Defence Committee + NC3 Board (NATO Consultation Command and Control Board) + Cyber Defence Management Authority (CDMA) governance. NCIRC Full Operational Capability achieved 2014 + Cyberspace as a Domain of Operations 2016 + Cyber Operations Centre (CYOC) at SHAPE 2018.
- NCIRC Memorandum of Understanding
- 24/7 SOC roster
- NCI Agency liaison appointment
- Cyber Defence Committee report
- NC3 Board technical report
- CYOC integration evidence
- No NCIRC MoU
- Lack of 24/7 capability
- Missing NCI Agency liaison
- No NC3 Board reporting
Personnel and Exercises
Maintain personnel security clearances per AC/35-D/2000 NATO Personnel Security Policy (CONFIDENTIAL/SECRET/COSMIC TOP SECRET investigations + reinvestigations every 5 years + continuous evaluation). Verify need-to-know and need-to-share controls. Conduct cyber exercises including NATO Cyber Coalition (annual, largest NATO cyber exercise involving 30+ nations) + Locked Shields hosted by CCDCOE in Tallinn (largest live-fire cyber exercise globally with 2000+ participants) + Crossed Swords (red team focused) + national tabletops. Maintain training records aligned to NATO Cyber Range curriculum.
- Personnel clearance register
- 5-year reinvestigation schedule
- Cyber Coalition participation evidence
- Locked Shields participation evidence
- Tabletop exercise reports
- NATO Cyber Range training records
- Need-to-know verification
- Outdated clearances
- No Cyber Coalition
- Skipped Locked Shields
- Missing tabletops
Strategic Cyber Defence
Recognise cyberspace as an operational domain per 2016 Warsaw Summit + integrate cyber effects into NATO planning and operations. Submit annual Cyber Defence Pledge progress report to the Cyber Defence Committee covering: national cyber defence strategy progress + cyber budget commitments (target 2% of GDP defence spending with cyber proportion increasing) + cyber expertise gaps + NCIRC capability contributions + Rapid Reaction Team contributions. Achieve and report progress against Cyber Defence Pledge targets adopted at 2016 Warsaw Summit. Participate in Article 5 collective defence in cyberspace where applicable.
- Cyber Defence Pledge progress report
- Annual self-assessment to NATO
- Cyber-in-operations doctrine
- Budget evidence for cyber proportion
- Cyber expertise inventory
- RRT contribution record
- Article 5 cyber consultations evidence
- No Pledge report
- No cyber budget tracking
- Missing self-assessment
- Cyber not integrated into operations
Technical Controls
Apply NATO-specific configuration baselines for NATO-Authorised Information and Communications Systems (ICS) per AC/322(SC/4) Cryptographic Policy + STANAG 4774 Confidentiality Metadata Binding. Conduct continuous vulnerability scanning + patch management within risk-based timelines (Critical 7 days + High 30 days + Medium 90 days). Apply Software Bill of Materials (SBOM) requirements per NATO Software Supply Chain guidance + NCI Agency Acquisition Policy. Pre-screen suppliers via NATO Industrial Advisory Group (NIAG) + national agencies (NSA + GCHQ + ANSSI + BfV + AISI + AIVD + others) for cyber adversary nation linkages.
- NATO configuration baselines
- Vulnerability scan reports
- Patch management metrics with NATO timelines
- SBOM evidence per ICS
- Supplier pre-screening record
- NIAG submission
- National security agency screening evidence
- No NATO baselines
- Patches exceed timeline
- Missing SBOM
- No supplier pre-screening
Threat Intelligence
Participate in NATO cyber threat intelligence sharing via Malware Information Sharing Platform (MISP) instances operated by NCIRC + Cyber Threat Assessment Cell (CTAC) at SHAPE + bilateral channels with NATO Cooperative Cyber Defence Centre of Excellence (CCDCOE) in Tallinn Estonia. Apply STIX/TAXII formats per CCDCOE recommendations. Operate Coordinated Vulnerability Disclosure programme per CCDCOE Tallinn Manual 3.0 guidance + ISO/IEC 29147. Share indicators of compromise (IOCs) + tactics techniques and procedures (TTPs) with allied nations within 24-48 hours.
- MISP instance configuration
- CTAC liaison appointment
- CCDCOE collaboration record
- STIX/TAXII feed configuration
- CVD policy aligned with ISO 29147
- IOC sharing log
- TTP analysis reports
- No MISP integration
- Missing CTAC liaison
- No CVD policy
- Stale IOC feeds
Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the NATO Cyber Defence Policy and NATO Computer Incident Response Capability (NCIRC) framework page.