CyFun Logo

CyFun® Changed Descriptions

Every requirement text that differs, quoted verbatim from the CCB templates

Reviewed September 2026

How to read this. Removed words are struck through in red, added words are highlighted in green. Nothing is paraphrased: both versions are the exact text of the CCB templates. A change of obligation verb (should, shall, must, may) is flagged, because it changes what the measure requires rather than how it is phrased.

CyFun 2025 v2025-10-21  →  BASIC and IMPORTANT v2026-02-20, ESSENTIAL v3.1 (2026-02-25)

Same measure identifiers, same publisher. 28 descriptions changed, covering 20 distinct measures — a measure worded differently at two levels is listed once per level (17 of the rows change the obligation verb). Every edit here is a small one, so any change of obligation verb is reported.

LevelMeasureDescription
BASIC PR.AA-06.1obligation verb changed
Physical access to all organisational assets, including critical zones, should be managed, monitored, and enforced based on risk.
Physical access to all organisational assets, including critical zones, shall be managed, monitored, and enforced based on risk.
IMPORTANT GV.OC-03.2
Legal, regulatory, and contractual obligations related to information and cybersecurity shall be continuously managed to ensure they remain accurate, up to date, and effectively applied.
Legal and regulatory obligations related to information and cybersecurity shall be continuously managed to ensure they remain accurate, up to date, and effectively applied.
IMPORTANT GV.RM-01.1
Information/cybersecurity objectives shall be identified, agreed to by organisational stakeholders and approved by senior management
Information and cybersecurity objectives shall be coherently established throughout the organisation and approved by senior management.
IMPORTANT GV.RR-02.1
Information security and cyber security roles, responsibilities and authorities for employees, suppliers, customers, and partners shall be documented, reviewed, authorised, kept up-to-date, communicated, and coordinated internally and externally..
Information security and cyber security roles, responsibilities and authorities for employees, suppliers, customers, and partners shall be documented, reviewed, authorised, kept up-to-date, communicated, and coordinated internally and externally.
IMPORTANT ID.AM-08.8obligation verb changed
The organisation should pre-approve, monitor and enforce maintenance tools for use on its critical systems.
The organisation shall pre-approve, monitor and enforce maintenance tools for use on its critical systems.
IMPORTANT PR.AA-06.1obligation verb changed
Physical access to all organisational assets, including critical zones, should be managed, monitored, and enforced based on risk.
Physical access to all organisational assets, including critical zones, shall be managed, monitored, and enforced based on risk.
IMPORTANT PR.AA-06.2obligation verb changed
Physical access controls should include specific procedures for emergency situations, ensuring continued protection of critical and non-critical assets during such events.
Physical access controls shall include specific procedures for emergency situations, ensuring continued protection of critical and non-critical assets during such events.
IMPORTANT DE.AE-02.1obligation verb changed
Cybersecurity and information security events must be reviewed and analysed to identify potential attack targets and methods, in accordance with applicable laws, regulations, standards, and policies.
Cybersecurity and information security events shall be reviewed and analysed to identify potential attack targets and methods, in accordance with applicable laws, regulations, standards, and policies.
IMPORTANT DE.AE-06.1obligation verb changed
Information about adverse events must be promptly delivered to authorised personnel and systems to enable timely detection, investigation, and response.
Information about adverse events shall be promptly delivered to authorised personnel and systems to enable timely detection, investigation, and response.
ESSENTIAL GV.OC-03.2
Legal, regulatory, and contractual obligations related to information and cybersecurity shall be continuously managed to ensure they remain accurate, up-to-date, and effectively applied.
Legal, regulatory, and contractual obligations related to information and cybersecurity shall be continuously managed to ensure they remain accurate, up to date, and effectively applied.
ESSENTIAL GV.RM-01.1
Information/cybersecurity objectives shall be identified, agreed to by organisational stakeholders and approved by senior management
Information and cybersecurity objectives shall be coherently established throughout the organisation and approved by senior management.
ESSENTIAL GV.RR-04.1
Personnel with access to the organisation’s most critical information or technology shall be authenticated..
Personnel with access to the organisation’s most critical information or technology shall be authenticated.
ESSENTIAL GV.OV-03.1
The organisation's cybersecurity risk management performance shall be evaluated, reviewed and adapted when necessary.
The organisation's cybersecurity risk management performance shall be evaluated, reviewed and adjusted when necessary.
ESSENTIAL ID.AM-08.7obligation verb changed
The organisation should prevent unauthorised removal of maintenance equipment which contains critical system information of the organisation.
The organisation shall prevent unauthorised removal of maintenance equipment which contains critical system information of the organisation.
ESSENTIAL ID.AM-08.8obligation verb changed
The organisation should pre-approve, monitor and enforce maintenance tools for use on its critical systems.
The organisation shall pre-approve, monitor and enforce maintenance tools for use on its critical systems.
ESSENTIAL ID.IM-03.1
The organisation shall conduct risk assessments in which risk is determined by threats, vulnerabilities and the impact on business processes and assets.
The organisation shall conduct post-incident evaluations to analyse lessons learned from incident response and recovery, and consequently improve processes / procedures / technologies to enhance its cyber resilience.
ESSENTIAL PR.AA-01.3
System credentials shall be deactivated following a specified period of inactivity, unless this would compromise the safe operation of (critical) processes.
System credentials shall be deactivated after a specified period of inactivity unless it would compromise the safe operation of (critical) processes.
ESSENTIAL PR.AA-02.2
TThe organisation shall ensure that unique credentials are used for each authenticated user, device, and process interacting with the organisation's critical systems. These credentials shall be verified, and the unique identifiers shall be captured during system interactions. Exceptions may be made for emergency access ("break-glass" procedures), provided such access is strictly controlled, logged, and reviewed.
The organisation shall ensure that unique credentials are used for each authenticated user, device, and process interacting with the organisation's critical systems. These credentials shall be verified, and the unique identifiers shall be captured during system interactions. Exceptions may be made for emergency access ("break-glass" procedures), provided such access is strictly controlled, logged, and reviewed.
ESSENTIAL PR.AA-04.1obligation verb changed
Identity assertions are protected, conveyed, and verified.
Identity assertions shall be protected, conveyed, and verified.
ESSENTIAL PR.AA-06.1obligation verb changed
Physical access to all organisational assets, including critical zones, should be managed, monitored, and enforced based on risk.
Physical access to all organisational assets, including critical zones, shall be managed, monitored, and enforced based on risk.
ESSENTIAL PR.AA-06.2obligation verb changed
Physical access controls should include specific procedures for emergency situations, ensuring continued protection of critical and non-critical assets during such events.
Physical access controls shall include specific procedures for emergency situations, ensuring continued protection of critical and non-critical assets during such events.
ESSENTIAL PR.AA-06.3obligation verb changed
Critical zones should have additional physical access controls beyond those applied to general facilities.
Critical zones shall have additional physical access controls beyond those applied to general facilities.
ESSENTIAL PR.AA-06.4obligation verb changed
Assets located within critical zones should be physically protected against unauthorised access, damage, or interference.
Assets located within critical zones shall be physically protected against unauthorised access, damage, or interference.
ESSENTIAL PR.PS-06.3obligation verb changed
Secure software development practices shall be integrated into all phases of the software development lifecycle, and their effectiveness should be regularly monitored and improved.
Secure software development practices shall be integrated into all phases of the software development lifecycle, and their effectiveness shall be regularly monitored and improved.
ESSENTIAL PR.IR-01.7
The organisation shall ensure that development and test environments are strictly separated from the production environment, particularly in ICS/OT systems where any crossover could compromise security, endanger health, or disrupt essential operations.
The organisation shall ensure that development and test environments are strictly separated from the production environment, particularly in ICS/OT systems where any crossover could compromise safety, endanger health, or disrupt essential operations.
ESSENTIAL DE.AE-02.1obligation verb changed
Cybersecurity and information security events must be reviewed and analysed to identify potential attack targets and methods, in accordance with applicable laws, regulations, standards, and policies.
Cybersecurity and information security events shall be reviewed and analysed to identify potential attack targets and methods, in accordance with applicable laws, regulations, standards, and policies.
ESSENTIAL DE.AE-06.1obligation verb changed
Information about adverse events must be promptly delivered to authorised personnel and systems to enable timely detection, investigation, and response.
Information about adverse events shall be promptly delivered to authorised personnel and systems to enable timely detection, investigation, and response.
ESSENTIAL RS.AN-07.1obligation verb changed
Incident data and metadata should be collected and protected to ensure their accuracy, authenticity, and traceability.
Incident data and metadata shall be collected and protected to ensure their accuracy, authenticity, and traceability.

Sources

How this page is produced

Most 2023 descriptions were redrafted for 2025, so in that table a change of obligation verb is reported only when the diff literally replaces one verb by another — a "shall" that merely appears in a rewritten sentence is not an obligation change. Between the two 2025 templates the edits are small, so any change of obligation verb is reported.

The texts are read straight from the CCB workbooks — the CyFun 2023 self-assessment tool (v2025-10-21) and the three CyFun 2025 templates — and compared word by word. A difference that is only spacing or an invisible character is not reported. The page is regenerated whenever the templates change, so it cannot drift away from them.

Every measure of the framework, with the 2023 measure it comes from and what changed, is listed on the measures page.