Skip to main content

💼 UK Cyber Essentials

  • ID: /frameworks/uk-cyber-essentials-v3.1

Stats​

not available

Description​

Empty...

Similar​

  • Internal
    • ID: dec-a-afea92d6

Sub Sections​

SectionSub SectionsInternal RulesPoliciesFlagsCompliance
💼 1 Firewalls64548no data
 💼 1.1 Change default administrative passwords11no data
 💼 1.2 Prevent access to the administrative interface from the internet4244no data
 💼 1.3 Block unauthenticated inbound connections by default23no data
 💼 1.4 Ensure inbound firewall rules are approved and documentedno data
 💼 1.5 Remove or disable unnecessary firewall rulesno data
 💼 1.6 Make sure you use a software firewall on devices which are used on untrusted networks.no data
💼 2 Secure configuration267no data
 💼 2.1 Computers and network devices667no data
  💼 2.1.1 Remove and disable unnecessary user accountsno data
  💼 2.1.2 Change any default or guessable account passwords23no data
  💼 2.1.3 Remove or disable unnecessary softwareno data
  💼 2.1.4 Disable any auto-run feature which allows file execution without user authorizationno data
  💼 2.1.5 Ensure users are authenticated before allowing them access to organizational data or services44no data
  💼 2.1.6 Ensure appropriate device locking controls for users that are physically presentno data
 💼 2.2 Device unlocking credentials3no data
  💼 2.2.1 A credential such as a biometric, password or PIN must be in place before a user can gain access to the services.no data
  💼 2.2.2 You must protect your chosen authentication method against brute-force attacks2no data
   💼 2.2.2.1 Shouldn’t allow more than 10 guesses in 5 minutesno data
   💼 2.2.2.2 Lock devices after more than 10 unsuccessful attempts.no data
  💼 2.2.3 Technical controls must be used to manage the quality of credentials.no data
💼 3 Security update management466no data
 💼 3.1 All software on in-scope devices must be licensed and supported66no data
 💼 3.2 All software on in-scope devices must be removed from devices when it becomes unsupportedno data
 💼 3.3 All software on in-scope devices must have automatic updates enabled where possible22no data
 💼 3.4 All software on in-scope devices must be updated within 14 days of an update being releasedno data
💼 4 User access control623no data
 💼 4.1 Have in place a process to create and approve user accountsno data
 💼 4.2 Authenticate users with unique credentials before granting access to applications or devices423no data
  💼 4.2.1 Passwords are protected against brute-force password guessingno data
  💼 4.2.2 Use technical controls to manage the quality of passwords.23no data
  💼 4.2.3 Support users to choose unique passwords for their work accounts11no data
  💼 4.2.4 The password element of the multi-factor authentication23no data
 💼 4.3 Remove or disable user accounts when they're no longer requiredno data
 💼 4.4 Implement MFA, where availableno data
 💼 4.5 Use separate accounts to perform administrative activities onlyno data
 💼 4.6 Remove or disable special access privileges when no longer requiredno data
💼 5 Malware protection2no data
 💼 5.1 Anti-malware software4no data
  💼 5.1.1 Anti-malware software must be configured to be updated in line with vendor recommendationsno data
  💼 5.1.2 Anti-malware software must be configured to prevent malware from runningno data
  💼 5.1.3 Anti-malware software must be configured to prevent the execution of malicious codeno data
  💼 5.1.4 Anti-malware software must be configured to prevent connections to malicious websites over the internet.no data
 💼 5.2 Application allow listing2no data
  💼 5.2.1 Must actively approve such applications before deploying them to devicesno data
  💼 5.2.2 Must maintain a current list of approved applicationsno data