Cybersecurity
DETAIL

UK DEF STAN 05-138 — Cyber Security for Defence Systems

SmartSuite provides the system for managing controls, evidence, mappings, assessments, and reporting.
Framework text may require a separate license unless explicitly provided.

arrow_back
arrow_forward

Overview

UK DEF STAN 05-138 is a cybersecurity framework that helps organizations secure and assure the cyber resilience of defence systems throughout their lifecycle. It establishes mandatory requirements and controls to protect military platforms, networks, and associated digital assets from evolving cyber threats.

Issued by the UK Ministry of Defence (MOD), DEF STAN 05-138 is used by defence contractors, suppliers, and MOD internal teams to address cybersecurity, risk management, and compliance across design, procurement, integration, and operation of defence systems. The standard covers key areas such as risk assessment, security testing, supply chain security, incident management, and assurance processes specific to defence environments.

Organizations implement UK DEF STAN 05-138 by integrating its requirements into project risk management, security control design, and contract compliance activities. This framework supports alignment with other defence and governmental cybersecurity standards, ensuring robust protection of sensitive information and operational capabilities within the MOD’s broader risk management and governance programs.

Why it Matters

UK DEF STAN 05-138 establishes consistent and robust cyber security requirements for defence systems, helping organizations secure critical assets against evolving threats.

Key benefits include:

  • Strengthen governance of defence systems

Provide structured oversight and accountability, ensuring cyber risks are managed across lifecycle stages of defence technology.

  • Enhance supplier assurance

Mandate verifiable security requirements for third-party vendors, reducing the risk of vulnerabilities in the supply chain.

  • Align with defence regulations

Support compliance with UK Ministry of Defence directives, making it easier to meet contractual and regulatory obligations.

  • Improve incident response readiness

Standardize reporting and mitigation processes to accelerate detection and handling of cyber incidents impacting defence assets.

  • Promote operational resilience

Reduce operational disruption and mission risk by embedding security controls that protect against advanced cyber threats targeting defence environments.

How it Works

UK DEF STAN 05-138 structures its guidance around a set of cyber security principles and requirements tailored for defence systems throughout their lifecycle. The framework integrates risk management processes, control objectives, and security measures into defined governance domains. It emphasizes a lifecycle approach, ensuring that cyber security considerations are addressed from system conception, through development and operation, to decommissioning.

In practice, organizations adopting DEF STAN 05-138 conduct regular risk assessments, implement mandated security controls, and demonstrate compliance with regulatory standards specific to defence environments. Security teams work to align both technical and organizational practices with the standard's requirements, integrating monitoring and incident response processes to maintain a robust security posture. Assessment cycles and ongoing verification support assurance efforts across program and project management activities.

With SmartSuite, organizations operationalize DEF STAN 05-138 by utilizing control libraries mapped to the standard's requirements, maintaining risk registers, and coordinating compliance tracking. Capabilities for policy governance, evidence collection, and automated remediation workflows support effective implementation. Reporting dashboards facilitate audit readiness and enable continuous monitoring of security practices and compliance with defence sector regulations.

Key Elements

  • Cyber Security Management Framework

Establishes an overarching structure for defining, implementing, and maintaining cyber security controls across defence systems.

  • Risk and Threat Assessment Processes

Outlines methodologies for evaluating current and emerging threats, vulnerabilities, and associated risks within defence environments.

  • Supply Chain Security Requirements

Specifies criteria to ensure third-party suppliers adhere to cyber security standards throughout the acquisition lifecycle.

  • System Lifecycle Cyber Assurance

Describes cybersecurity activities integrated into each stage of the system development and operational lifecycle.

  • Incident Detection and Response Mechanisms

Defines processes for identifying, managing, and recovering from cyber incidents impacting defence systems.

  • Governance and Accountability Structures

Organizes roles, responsibilities, and oversight functions to maintain compliance and effective security governance.

Framework Scope

UK DEF STAN 05-138 is adopted by defence contractors and suppliers responsible for securing military and defence-related assets, including weapons systems, command and control platforms, and operational networks. The standard governs the implementation of cyber security controls across defence systems, typically to support risk management, assurance requirements, and meeting regulated defence security obligations.

Framework Objectives

UK DEF STAN 05-138 defines the essential objectives for cybersecurity, risk management, and data protection in defence systems.

Strengthen cybersecurity governance across all defence system lifecycle stages

Enhance risk management to reduce vulnerabilities and potential cyber threats

Ensure compliance with relevant regulatory and defence-specific security requirements

Improve operational resilience against evolving cyber attack vectors

Safeguard sensitive data through robust security controls and data protection measures

Support audit readiness with documented processes and control effectiveness

Framework in Context

UK DEF STAN 05-138 aligns with standards such as ISO 27001, NIST SP 800-53, and the NCSC Cyber Assessment Framework, focusing on cyber security for defense systems. Organizations implement it to meet UK Ministry of Defence requirements, ensure regulatory compliance, and enhance operational security within defense procurement and supply chain contexts.

Common Framework Mappings

UK DEF STAN 05-138 is often mapped to globally recognized cybersecurity and defense frameworks to ensure alignment with best practices, facilitate risk management, and streamline compliance across multinational operations.

Mapped frameworks include:

CIS Critical Security Controls

Cyber Essentials

ISO/IEC 27001

ISO/IEC 27002

NIST Cybersecurity Framework

NIST SP 800-53

SOC 2

UK NCSC Cyber Assessment Framework

UK National Cyber Security Strategy

US DoD Cybersecurity Maturity Model Certification (CMMC)

At a Glance
DEF STAN 05-138
  • checklist
    Classification
    Category
    info
    Cybersecurity
    Domain
    info
    Cybersecurity
    Framework Family
    info
    Other
  • info
    Regulatory Context
    Type
    info
    Standard
    Legal Instrument
    info
    Standard
    Sector
    info
    Defense Sector
    Industry
    info
    Aerospace & Defense
  • arrow_upload_ready
    Region / Publisher
    Region
    info
    Europe
    Region Detail
    info
    United Kingdom
    Publisher
    info
    UK Defence Standard 05‑138 — Cyber Security for Defence Systems Ministry of Defence (United Kingdom)
  • published_with_changes
    Versioning
    Version
    info
    Issue 4
    Effective Date
    info
    17 October 2017
    Issue Date
    info
    17 October 2017
  • graph_3
    Adoption
    Adoption Model
    info
    Regulatory Compliance
    Implementation Complexity
    info
    Very High
  • captive_portal
    Official Reference
License Information

License included / downloadable: Yes

DEF STAN 05-138 is published by the UK Ministry of Defence and is publicly available via official UK Defence Standards publications on gov.uk.License included with platform

Official Resources
DEF STAN 05-138 - Cyber Security for Defence Systems
Official document detailing cyber security requirements for UK defense systems.
chevron_forward
UK Ministry of Defence Cyber Security Guidance
Provides implementation guidance for organisations applying DEF STAN 05-138 standards.
chevron_forward
UK Cyber Assessment Framework
Outlines a comprehensive approach to cyber risk management in line with DEF STAN 05-138.
chevron_forward
UK Cyber Risk Management Framework
Describes the risk management strategies to support DEF STAN 05-138 compliance.
chevron_forward
SMARTSUITE

How SmartSuite Supports DEF STAN 05-138

Manage UK DEF STAN 05-138 defence cybersecurity requirements by organizing security controls, tracking system assurance activities, and maintaining evidence supporting compliance across defence systems and suppliers.

Defence Security Control Framework

Structure DEF STAN 05-138 controls with ownership, scope, and implementation tracking across programmes.

Defence Risk Assessment and Assurance

Link cybersecurity risks to defence systems and manage assurance activities throughout the lifecycle.

Governance, Policy, and Secure Design Oversight

Centralize security policies, design controls, and governance aligned to defence requirements.

Supplier and Secure Development Tracking

Track supplier requirements, component assurance, and secure development practices.

Incident Response and Security Operations

Manage detection, response workflows, and incident documentation across defence environments.

Control Coverage and Audit Readiness Reporting

Provide dashboards showing control coverage, system assurance status, and audit readiness.

Related frameworks

CIS Controls v8.1

CIS Controls v8.1 provides prioritized, practical security actions to help organizations mitigate common cyber threats and strengthen defenses.

Learn More
arrow_forward
ISO 27001:2022

ISO/IEC 27001:2022 is an international ISMS standard that helps organizations manage information security risks and protect data.

Learn More
arrow_forward
ISO 27002:2022

ISO/IEC 27002:2022 provides best-practice information security controls to help organizations select, implement, and manage protections for information assets.

Learn More
arrow_forward
ISO 27017

ISO/IEC 27017 provides cloud-specific security controls to help organizations protect data and manage cloud-related risks.

Learn More
arrow_forward
ISO 27018

ISO/IEC 27018 provides guidelines for protecting personally identifiable information processed in public cloud services.

Learn More
arrow_forward
NIST CSF 2.0

NIST Cybersecurity Framework (CSF) v2.0 is a risk-based framework that helps organizations manage and reduce cybersecurity risks.

Learn More
arrow_forward
NIST 800-53 Rev.5

NIST SP 800-53 Rev. 5 provides a catalog of security and privacy controls to manage risks to information systems.

Learn More
arrow_forward
ONBOARDING FAQS

Frequently Asked Questions For UK DEF STAN 05-138 (Cyber Security for Defence Systems)

What is UK DEF STAN 05-138 used for?

UK DEF STAN 05-138 establishes minimum cyber security requirements for defence systems procured by the UK Ministry of Defence (MOD). It is used to ensure that suppliers address cyber risks throughout the lifecycle of MOD systems, from concept through disposal. The standard focuses on protecting sensitive information and maintaining operational capability.

Is compliance with UK DEF STAN 05-138 mandatory?

Yes, UK DEF STAN 05-138 is mandatory for all relevant MOD contracts involving defence systems and equipment. Suppliers must demonstrate compliance as part of the procurement process, and ongoing adherence is regularly monitored by MOD accreditation authorities.

What is the scope of UK DEF STAN 05-138?

The scope of UK DEF STAN 05-138 covers all defence systems, including ICT, operational technology, and components that process, store, or transmit MOD information. It applies to both new projects and modifications to existing systems, regardless of whether systems are developed in-house or sourced from third parties.

What key cybersecurity requirements does UK DEF STAN 05-138 specify?

The standard requires suppliers to perform cyber risk assessments, implement technical and procedural controls, manage supply chain security, and produce key artifacts such as Cyber Security Management Plans (CSMPs) and Security Cases. Emphasis is placed on demonstrating proactive risk management and documenting compliance throughout system development.

How is UK DEF STAN 05-138 implemented in defence projects?

Implementation begins with a cyber risk assessment to identify threats and vulnerabilities. Organizations must then develop a CSMP outlining mitigation strategies, apply technical controls, ensure secure system design, and provide traceable evidence throughout the system lifecycle. Regular reviews and updates are required as threats and system scopes evolve.

How does UK DEF STAN 05-138 relate to other cybersecurity frameworks?

UK DEF STAN 05-138 aligns with MOD and wider UK Government policies, and is often used alongside standards such as ISO 27001 and NIST SP 800-53. However, it specifies requirements tailored for MOD operational environments and the unique nature of defence systems, providing more detailed guidance than some general-purpose frameworks.

What are the ongoing compliance requirements for UK DEF STAN 05-138?

Organizations must regularly review cyber risks, update security documentation, and conduct periodic audits to verify control effectiveness. Continual improvement processes should be in place to address new vulnerabilities, and any significant changes to systems require reassessment against the standard’s requirements.

How would SmartSuite support UK DEF STAN 05-138?

SmartSuite can help organizations manage UK DEF STAN 05-138 compliance by enabling risk tracking, managing cyber controls, and automating evidence collection for audits. The platform facilitates documentation of key artifacts such as CSMPs, supports workflow automation for compliance tasks, and provides robust reporting to demonstrate MOD audit readiness and ongoing compliance.

Operationalize DEF STAN 05-138 with Connected Workflows

Manage controls, risks, evidence, and audits in one platform designed for modern governance, risk, and compliance.

Schedule a Demo
chevron_forward
Demo Library
chevron_forward