NATO Cyber Defence Policy and NATO Computer Incident Response Capability (NCIRC)
What is NATO Cyber Defence Policy and NATO Computer Incident Response Capability (NCIRC)?
The NATO cyber defence framework is defined by the NATO Cyber Defence Policy (original 2014, updated 2021) and operationalised through the NATO Computer Incident Response Capability (NCIRC) managed by the NATO Communications and Information Agency (NCI Agency). The CCDCOE provides research and the Tallinn Manual on the International Law Applicable to Cyber Operations, but these are not NATO policy documents. It comprises 8 controls organised across 8 domains, and applies in International (NATO - 32 members).
How NATO Cyber Defence Policy and NATO Computer Incident Response Capability (NCIRC) maps to other frameworks
All 8 controls, each one mapped to the equivalent requirement in other standards, with the evidence that carries across and the mappings that were judged and rejected shown alongside. No account needed to look.
See the control mappings →The 8 domains NATO Cyber Defence Policy and NATO Computer Incident Response Capability (NCIRC) groups its controls into
Frameworks that share controls with NATO Cyber Defence Policy and NATO Computer Incident Response Capability (NCIRC)
Each of these has at least one control mapped to a control in NATO Cyber Defence Policy and NATO Computer Incident Response Capability (NCIRC). The number is how many NATO Cyber Defence Policy and NATO Computer Incident Response Capability (NCIRC) controls are shared, counted from the mapping graph.
FFIEC Cybersecurity Assessment Tool (CAT)
2 shared controlsASD Strategies to Mitigate Cyber Security Incidents
1 shared controlSouth Korea Cloud Security Assurance Program (CSAP)
1 shared controlProtective Security Policy Framework (PSPF) Release 2024
1 shared controlNevada Gaming Control Board Cybersecurity Requirements
1 shared controlFFIEC IT Examination Handbook
1 shared controlAPRA CPS 234
1 shared controlIEC 62351 - Power Systems Communication Security
1 shared controlWhere NATO Cyber Defence Policy and NATO Computer Incident Response Capability (NCIRC) overlaps with the standards you already hold
What NATO Cyber Defence Policy and NATO Computer Incident Response Capability (NCIRC) means in your sector
What NATO Cyber Defence Policy and NATO Computer Incident Response Capability (NCIRC) means for your job
Questions people ask about NATO Cyber Defence Policy and NATO Computer Incident Response Capability (NCIRC)
What is NATO Cyber Defence Policy and NATO Computer Incident Response Capability?
How many controls does NATO Cyber Defence Policy and NATO Computer Incident Response Capability have?
Where does NATO Cyber Defence Policy and NATO Computer Incident Response Capability apply?
What frameworks does NATO Cyber Defence Policy and NATO Computer Incident Response Capability map to?
How do I get started with NATO Cyber Defence Policy and NATO Computer Incident Response Capability compliance?
Query NATO Cyber Defence Policy and NATO Computer Incident Response Capability (NCIRC) programmatically
NATO Cyber Defence Policy and NATO Computer Incident Response Capability (NCIRC), its 8 controls and every mapping into other standards are available over a REST endpoint and an MCP server, so an agent can read them directly. The free tier is 10 calls a day and needs no signup.
NATO Cyber Defence Policy and NATO Computer Incident Response Capability (NCIRC) API reference and MCP config →What NATO Cyber Defence Policy and NATO Computer Incident Response Capability (NCIRC) requires, control by control
Each page carries the requirement text for one NATO Cyber Defence Policy and NATO Computer Incident Response Capability (NCIRC) control and what an assessor expects to see as evidence.
How ready are you for NATO Cyber Defence Policy and NATO Computer Incident Response Capability (NCIRC)?
Answer 25 questions and get a professional readiness report with gap analysis, maturity scores, and prioritised action items. Results in 5 minutes.