Ronan Blake
Reference

33 UK terms nobody explains.

BPSS, CAF, CBEST, CHECK, DDaT, SC clearance, Success Profiles. Terms that appear in UK job specifications and government security environments, and are rarely explained in textbooks or US-focused guides.

BCS
British Computer Society, now the Chartered Institute for IT. Provides the CISMP qualification and chartered IT professional status.
BPSS
Baseline Personnel Security Standard — the minimum vetting level for civil service and government contractor roles. Covers identity, right to work, three years of employment history, and a basic criminal record check.
CAF
Cyber Assessment Framework — the NCSC’s framework for assessing the cyber resilience of organisations delivering essential services. The framework UK critical national infrastructure and much of the public sector is actually assessed against, and worth knowing by name if you are interviewing anywhere near either.
CBEST
A CREST-managed framework for threat-intelligence-led penetration testing of critical financial infrastructure, commissioned by the Bank of England and the FCA. CREST CRT or higher is required to deliver CBEST engagements.
CHECK
A UK government scheme authorising penetration testers to test systems holding government information. CHECK Team Member (CTM) and CHECK Team Leader (CTL) are the designations, awarded via CREST or the Tiger Scheme.
CISMP
Certificate in Information Security Management Principles — a BCS foundation qualification in information security management, reasonably well recognised in UK government and public-sector contexts.
CIISec
Chartered Institute of Information Security — the UK professional body for information security practitioners, offering membership and Chartered (CIIS) status.
CREST
Council of Registered Ethical Security Testers — the UK accreditation body for offensive security practitioners. CREST accreditation is required to deliver penetration testing services to UK government and much of regulated industry, which is why testing interviews weight methodology and ethics so heavily.
CSTM / CCP
Certified Cyber Professional — an NCSC-assured certification scheme recognising practitioners against defined specialisms. Where present on a UK job specification, it usually signals a government or critical-infrastructure employer.
CTC
Counter Terrorism Check — a UK government vetting level above BPSS, adding a check of security service records. Required for access to some government sites.
CyBOK
Cyber Security Body of Knowledge — the academic reference framework for cybersecurity, commissioned by the NCSC and developed by UK universities. Used as a curriculum reference by UK degree programmes.
Cyber Essentials
A UK government-backed certification scheme setting a baseline of technical security controls across five areas. Required for organisations bidding for certain government contracts. Two levels: Cyber Essentials (self-assessed) and Cyber Essentials Plus (independently verified).
DDaT
Digital, Data and Technology — the UK civil service profession framework covering all technology roles in government, including cybersecurity. Defines role families, skills and pay bands.
DSIT
Department for Science, Innovation and Technology — the UK government department responsible for cyber policy, and publisher of the annual Cyber Security Breaches Survey and the Cyber Security Skills in the UK Labour Market report, which are the source of most UK cyber workforce statistics you will encounter.
DV
Developed Vetting — the highest standard of UK government personnel security clearance, required for access to the most sensitive information. Involves interviews with a vetting officer and examination of personal, financial and relationship history.
FCA
Financial Conduct Authority — the UK conduct regulator for financial services firms. Sets requirements for operational resilience and cybersecurity in regulated entities; cyber incidents may trigger FCA notification obligations.
HMG Security Policy Framework
The overarching security policy framework for UK government, setting mandatory requirements for protecting government assets, information and people. Anyone architecting in government needs to understand its requirements.
ICO
Information Commissioner’s Office — the UK data protection regulator, enforcing UK GDPR. Can impose fines of up to £17.5 million or four per cent of global turnover for serious breaches, and is the body to which personal data breaches are reported.
IR35
UK tax legislation determining whether a contractor is effectively a disguised employee. A contract assessed as ‘inside IR35’ means employment taxes are paid at source rather than through the contractor’s own company. Since the 2021 reform it significantly affects contractor take-home pay across the public sector and large private-sector engagements.
NCSC
National Cyber Security Centre — part of GCHQ, and the UK government’s technical authority on cybersecurity. Produces authoritative guidance, certifies training and products, and coordinates national cyber incident response. Its guidance is the most useful free resource in UK security, and citing it in an interview signals you have read the right things.
NIS Regulations
Network and Information Systems Regulations — UK legislation requiring operators of essential services and digital service providers to implement appropriate security measures and report significant incidents.
NPPV
Non-Police Personnel Vetting — the vetting standard applied to contractors and suppliers working with UK police forces, at several levels. Distinct from government clearance, and a requirement you will meet if you target policing or its supply chain.
PRA
Prudential Regulation Authority — the UK prudential regulator for banks, building societies and insurers, working alongside the FCA. Sets operational resilience expectations with direct cybersecurity implications.
SABSA
Sherwood Applied Business Security Architecture — an enterprise security architecture framework developed in the UK, providing a layered approach that maps from business context through to technical implementation. Widely referenced in UK financial services and government architecture work.
SC Clearance
Security Check — the standard UK government vetting level for most sensitive cybersecurity roles. Covers the past several years of employment, finances, overseas travel, relationships, and security and police records. Typically takes some months, and is normally sponsored by the employer after an offer.
SFIA
Skills Framework for the Information Age — a widely used UK skills and competency framework that many employers map roles and pay bands against. If a job specification refers to a numbered level, this is usually why.
SIEM
Security Information and Event Management — a platform that aggregates and analyses security event data from across an organisation’s infrastructure. Microsoft Sentinel and Splunk are the dominant platforms in UK enterprise, and SOC analysts work inside one daily.
STRIDE
Spoofing, Tampering, Repudiation, Information Disclosure, Denial of Service, Elevation of Privilege — the most widely used threat modelling framework in UK practice. A prompt for completeness during threat modelling, not a methodology in itself.
Success Profiles
The UK civil service recruitment framework. Assesses named behaviours through competency questions scored against published criteria at each grade, which is why structured, evidenced answers matter so much in government interviews.
Tiger Scheme
A UK government-approved scheme, alongside CREST, for qualifying and registering penetration testers to perform CHECK assessments on government systems.
UK Cyber Security Council
The professional body for UK cybersecurity, established to set standards for the profession and to grant chartered status — Chartered Cyber Security Professional and associated titles — across defined specialisms. The closest thing the field now has to the chartered structures long established in engineering and accountancy.
UK GDPR
The UK’s post-Brexit version of the EU General Data Protection Regulation. Substantially mirrors the EU GDPR but is governed by the ICO. Applies to all organisations processing the personal data of UK residents.
Zero Trust
An architectural principle — not a product — asserting that no user, device or system should be trusted by default regardless of network location, and that every access request must be verified explicitly. The NCSC publishes specific zero trust guidance for UK organisations. APPENDIX B

From Appendix A of The Honest Guide to UK Cybersecurity Interviews.

The list

Told when this page changes?

Salary bands, certifications and funding rules all move. The list covers material changes here as well as new books.

Never shared, never sold. One-click unsubscribe.