UK Cyber Essentials: the evidence behind every control
36 controls. For each, the artefacts auditors ask for, which ones a system already holds, and the first move to stop evidencing it by periodic review.
User Access Control
AC.1User Account Approval Process easyAC.2Authenticate Users Before Granting Access easyAC.3Remove or Disable Accounts When No Longer Required moderateAC.4Privileged Account Approval and Tracking hardAC.5Separate Admin Accounts for Administrative Activities hardAC.6Periodic Review of Privileged Access moderateAC.7MFA for Administrative Accounts moderateAC.8Passwordless Authentication hardFirewalls
FW.1Boundary Firewalls Deployed moderateFW.2Change Default Firewall Passwords moderateFW.3Block Unauthenticated Inbound Connections moderateFW.4Approve and Document Inbound Rules moderateFW.5Remove or Disable Unused Rules easyFW.6Host-Based Firewall for Remote Workers hardFW.7Restrict Firewall Administrative Interface from the Internet easyMalware Protection
MP.1Anti-Malware Software Deployed hardMP.2Anti-Malware Signatures Updated hardMP.3Anti-Malware Scans Files on Access and Web Pages hardMP.4Application Allowlisting (Alternative) hardSecure Configuration
SC.1Remove or Disable Unused Software hardSC.2Change Default Passwords on Devices and Software hardSC.3Disable Auto-Run Features easySC.4Authenticate Users Before Access hardSC.5Password-Based Authentication Quality easySC.6Multi-Factor Authentication for Cloud Services moderateSC.7Educate Users on Strong Passwords hardSC.8Process for Compromised Passwords moderateSC.9Device Unlocking Credentials and Brute-Force Protection hardScope
SCOPE.1Scope Definition hardSCOPE.2Cloud Services in Scope hardSCOPE.3BYOD and Home Working moderate