NCA's OSMACC extends ECC to address risks to organisations' social-media accounts, including account theft, misuse and impersonation. Its scope concerns organisational accounts and their protection. See the NCA OSMACC publication page.
Use in a programme
Identify the official accounts, business owners, administrators and recovery arrangements. Review the controls and evidence for authorised access, account management and handling a compromised account.
Include service-provider and agency relationships where they affect control of an account. Keep ownership and access records current when staff or external contributors change.
Use in CSFaaS
The reviewed reference library lists NCA OSMACC-1:2021 - EN. Check the imported edition and assess the relevant requirements within the organisation's defined scope.
Use framework owners, policy links and evidence to document the arrangements. This reference addresses organisational social-media accounts; operational technology is covered by the separate OTCC reference.
A policy mapping supports review but does not verify that account settings, recovery methods or third-party access are actually operating as documented.