Libraries

Flexible assessments for every assurance requirement

Erebus Assure brings a wide range of cyber security, resilience, compliance and specialist assessment frameworks together in one flexible platform.

From established standards such as ISO 27001, NIST, NCSC CAF and Cyber Essentials through to Operational Technology, supply chain, cloud, AI and bespoke customer requirements, assessments can be configured to reflect the areas most relevant to each organisation.

Use the library below to explore the available assessment types, the standards and guidance they are based on, and the core areas each assessment can cover.

Category Erebus Assure Assessment Basis / Reference Core Coverage / Configurable Sections
Information Security ISO 27001 Readiness Assessment ISO/IEC 27001:2022
  • ISMS governance
  • Organisational context
  • Leadership
  • Risk management
  • Policies
  • Asset management
  • Access control
  • People security
  • Physical security
  • Operational security
  • Supplier security
  • Incident management
  • Business continuity
  • Compliance
  • Continual improvement
Information Security Cyber Essentials Readiness Assessment NCSC Cyber Essentials
  • Firewalls
  • Secure configuration
  • Security update management
  • User access control
  • Malware protection
  • CE / CE+ readiness
Information Security NCSC CAF Assessment NCSC Cyber Assessment Framework
  • Managing security risk
  • Protecting against cyber attack
  • Detecting cyber security events
  • Minimising the impact of incidents
  • Individual CAF objectives/principles selected as required
Information Security NIST Cybersecurity Framework Assessment NIST CSF 2.0
  • Govern
  • Identify
  • Protect
  • Detect
  • Respond
  • Recover
Information Security CIS Controls Assessment CIS Controls
  • Organisational controls
  • Technical controls
  • Asset management
  • Access management
  • Vulnerability management
  • Security monitoring
  • Incident response
  • Relevant Implementation Groups
Defence DEFSTAN 05-138 Readiness Assessment DEF STAN 05-138
  • High-level readiness against applicable requirements
  • Applicable sections selected according to requirement
  • RAG status only
  • No detailed sensitive or classified evidence captured due to classification implications
Operational Technology OT / ICS Cyber Security Assessment IEC 62443 / NCSC CAF / NIS good practice
  • Governance
  • Asset management
  • Architecture
  • Zones & conduits
  • Access control
  • Remote access
  • Vulnerability management
  • Patch management
  • Secure configuration
  • Monitoring
  • Incident response
  • Backup & recovery
  • Supplier access
  • Lifecycle management
Supply Chain Supplier Security Assessment ISO 27001 / NIST / NCSC / IEC 62443 / industry good practice
  • Security governance
  • Cyber controls
  • Data protection
  • Access control
  • Hosting & cloud
  • Incident management
  • Business resilience
  • Subcontractors
  • Personnel security
  • Supply-chain dependencies
  • OT / ICS security
  • OT remote access
  • OT asset interaction & dependencies
  • OT vulnerability & patch management
  • OT network / system access
  • OT incident notification & response
  • Light-touch, standard or critical-supplier options
Physical & Protective Security Physical & Protective Security Assessment ISO 27001 / NPSA good practice
  • Site perimeter
  • Physical access control
  • Visitors & contractors
  • CCTV
  • Intruder detection
  • Keys & access credentials
  • Secure areas
  • Comms/server rooms
  • Environmental threats
  • Security monitoring
  • Personnel arrangements
Protective Security Martyn’s Law Readiness Assessment Terrorism (Protection of Premises) Act / supporting guidance
  • Premises applicability
  • Governance
  • Terrorism risk
  • Protective procedures
  • Evacuation
  • Invacuation / lockdown
  • Communications
  • Staff awareness
  • Training
  • Preparedness
Privacy Data Protection & UK GDPR Assessment UK GDPR / DPA 2018 / ICO guidance
  • Governance
  • Lawful processing
  • Privacy information
  • Data subject rights
  • DPIAs
  • Records management
  • Retention
  • Data sharing
  • Processors
  • Breach management
  • Information security
Resilience Business Resilience Assessment ISO 22301 / NCSC / industry good practice
  • Business continuity
  • Business impact analysis
  • Disaster recovery
  • Backup & recovery
  • Cyber incident response
  • Crisis management
  • Exercises & testing
  • Critical dependencies
  • Recovery arrangements
Cloud & Technology Cloud Security Assessment ISO 27017 / CIS / NCSC / provider good practice
  • Cloud governance
  • Identity management
  • Privileged access
  • Secure configuration
  • Logging & monitoring
  • Encryption
  • Network security
  • Vulnerability management
  • Backup
  • Resilience
  • M365, Azure and AWS-specific sections where required
AI AI Governance & Security Assessment ISO/IEC 42001 / NIST AI RMF / industry good practice
  • AI governance
  • Approved AI use
  • AI risk assessment
  • Data protection
  • AI security
  • Third-party AI
  • Generative AI
  • Human oversight
  • Transparency
  • Monitoring
  • Shadow AI
Software Security Secure Development Assessment OWASP / NIST / secure development good practice
  • SDLC governance
  • Secure design
  • Secure coding
  • Code repositories
  • Software dependencies
  • CI/CD
  • Security testing
  • Vulnerability management
  • Secrets management
  • Open-source software
  • Software supply chain
General Assurance Cyber Security Maturity Assessment Erebus Assure methodology / ISO / NIST / NCSC / CIS
  • Governance
  • People
  • Technology
  • Data
  • Identity & access
  • Vulnerability management
  • Monitoring
  • Incident management
  • Resilience
  • Supplier security
Bespoke Customer-Specific Assurance Assessment Customer policies, contracts, standards or requirements
  • Customer-defined requirements
  • Customer policies
  • Contractual requirements
  • Bespoke control areas
  • Configurable questions
  • Configurable scoring
  • Configurable maturity criteria
  • Relevant Erebus library sections can be reused
Information Security

ISO 27001 Readiness Assessment

Basis / Reference

ISO/IEC 27001:2022

Core Coverage
  • ISMS governance
  • Organisational context
  • Leadership
  • Risk management
  • Policies
  • Asset management
  • Access control
  • People security
  • Physical security
  • Operational security
  • Supplier security
  • Incident management
  • Business continuity
  • Compliance
  • Continual improvement
Information Security

Cyber Essentials Readiness Assessment

Basis / Reference

NCSC Cyber Essentials

Core Coverage
  • Firewalls
  • Secure configuration
  • Security update management
  • User access control
  • Malware protection
  • CE / CE+ readiness
Information Security

NCSC CAF Assessment

Basis / Reference

NCSC Cyber Assessment Framework

Core Coverage
  • Managing security risk
  • Protecting against cyber attack
  • Detecting cyber security events
  • Minimising the impact of incidents
  • Individual CAF objectives/principles selected as required
Information Security

NIST Cybersecurity Framework Assessment

Basis / Reference

NIST CSF 2.0

Core Coverage
  • Govern
  • Identify
  • Protect
  • Detect
  • Respond
  • Recover
Information Security

CIS Controls Assessment

Basis / Reference

CIS Controls

Core Coverage
  • Organisational controls
  • Technical controls
  • Asset management
  • Access management
  • Vulnerability management
  • Security monitoring
  • Incident response
  • Relevant Implementation Groups
Defence

DEFSTAN 05-138 Readiness Assessment

Basis / Reference

DEF STAN 05-138

Core Coverage
  • High-level readiness against applicable requirements
  • Applicable sections selected according to requirement
  • RAG status only
  • No detailed sensitive or classified evidence captured due to classification implications
Operational Technology

OT / ICS Cyber Security Assessment

Basis / Reference

IEC 62443 / NCSC CAF / NIS good practice

Core Coverage
  • Governance
  • Asset management
  • Architecture
  • Zones & conduits
  • Access control
  • Remote access
  • Vulnerability management
  • Patch management
  • Secure configuration
  • Monitoring
  • Incident response
  • Backup & recovery
  • Supplier access
  • Lifecycle management
Supply Chain

Supplier Security Assessment

Basis / Reference

ISO 27001 / NIST / NCSC / IEC 62443 / industry good practice

Core Coverage
  • Security governance
  • Cyber controls
  • Data protection
  • Access control
  • Hosting & cloud
  • Incident management
  • Business resilience
  • Subcontractors
  • Personnel security
  • Supply-chain dependencies
  • OT / ICS security
  • OT remote access
  • OT asset interaction & dependencies
  • OT vulnerability & patch management
  • OT network / system access
  • OT incident notification & response
  • Light-touch, standard or critical-supplier options
Physical & Protective Security

Physical & Protective Security Assessment

Basis / Reference

ISO 27001 / NPSA good practice

Core Coverage
  • Site perimeter
  • Physical access control
  • Visitors & contractors
  • CCTV
  • Intruder detection
  • Keys & access credentials
  • Secure areas
  • Comms/server rooms
  • Environmental threats
  • Security monitoring
  • Personnel arrangements
Protective Security

Martyn’s Law Readiness Assessment

Basis / Reference

Terrorism (Protection of Premises) Act / supporting guidance

Core Coverage
  • Premises applicability
  • Governance
  • Terrorism risk
  • Protective procedures
  • Evacuation
  • Invacuation / lockdown
  • Communications
  • Staff awareness
  • Training
  • Preparedness
Privacy

Data Protection & UK GDPR Assessment

Basis / Reference

UK GDPR / DPA 2018 / ICO guidance

Core Coverage
  • Governance
  • Lawful processing
  • Privacy information
  • Data subject rights
  • DPIAs
  • Records management
  • Retention
  • Data sharing
  • Processors
  • Breach management
  • Information security
Resilience

Business Resilience Assessment

Basis / Reference

ISO 22301 / NCSC / industry good practice

Core Coverage
  • Business continuity
  • Business impact analysis
  • Disaster recovery
  • Backup & recovery
  • Cyber incident response
  • Crisis management
  • Exercises & testing
  • Critical dependencies
  • Recovery arrangements
Cloud & Technology

Cloud Security Assessment

Basis / Reference

ISO 27017 / CIS / NCSC / provider good practice

Core Coverage
  • Cloud governance
  • Identity management
  • Privileged access
  • Secure configuration
  • Logging & monitoring
  • Encryption
  • Network security
  • Vulnerability management
  • Backup
  • Resilience
  • M365, Azure and AWS-specific sections where required
AI

AI Governance & Security Assessment

Basis / Reference

ISO/IEC 42001 / NIST AI RMF / industry good practice

Core Coverage
  • AI governance
  • Approved AI use
  • AI risk assessment
  • Data protection
  • AI security
  • Third-party AI
  • Generative AI
  • Human oversight
  • Transparency
  • Monitoring
  • Shadow AI
Software Security

Secure Development Assessment

Basis / Reference

OWASP / NIST / secure development good practice

Core Coverage
  • SDLC governance
  • Secure design
  • Secure coding
  • Code repositories
  • Software dependencies
  • CI/CD
  • Security testing
  • Vulnerability management
  • Secrets management
  • Open-source software
  • Software supply chain
General Assurance

Cyber Security Maturity Assessment

Basis / Reference

Erebus Assure methodology / ISO / NIST / NCSC / CIS

Core Coverage
  • Governance
  • People
  • Technology
  • Data
  • Identity & access
  • Vulnerability management
  • Monitoring
  • Incident management
  • Resilience
  • Supplier security
Bespoke

Customer-Specific Assurance Assessment

Basis / Reference

Customer policies, contracts, standards or requirements

Core Coverage
  • Customer-defined requirements
  • Customer policies
  • Contractual requirements
  • Bespoke control areas
  • Configurable questions
  • Configurable scoring
  • Configurable maturity criteria
  • Relevant Erebus library sections can be reused

Why It Matters

Cyber security is not a one-time exercise—it’s an ongoing process of assessment, improvement and resilience.

Our platform transforms assessment data into practical, actionable insights, enabling organisations to make informed decisions, prioritise investment and strengthen their Operational Technology environments with confidence.

Ready to understand your cyber resilience?

Start your Operational Technology Cyber Assessment today and receive practical recommendations tailored to your organisation.

Your Account

Log in / Register

Get in touch

Contact

Connect

Erebus Assure

Copyright © 2026 Erebus Assure. All Rights Reserved.

2026