Skip to content

Latest commit

 

History

History
48 lines (26 loc) · 3.54 KB

File metadata and controls

48 lines (26 loc) · 3.54 KB

Cyber Essentials Plus Overview

This document provides an overview of the Cyber Essentials Plus standards and outlines the key requirements for achieving compliance. Cyber Essentials Plus is a cybersecurity certification scheme developed by the UK Government to help organizations protect against common cyber threats.

What is Cyber Essentials Plus?

Cyber Essentials Plus is an extension of the Cyber Essentials certification, focusing on more advanced security controls and additional testing. It provides a higher level of assurance by subjecting the organization's systems to independent vulnerability testing and verification.

Key Requirements for Cyber Essentials Plus Compliance

  1. Boundary Firewalls and Internet Gateways: Ensure that your organization has a secure boundary firewall and internet gateway to protect your network from unauthorized access.

  2. Secure Configuration: Implement secure configurations for all devices used within your organization. This includes desktops, laptops, servers, and other network devices.

  3. Access Control: Control access to your systems and data by enforcing strong authentication mechanisms, including passwords, two-factor authentication, or biometric authentication.

  4. Malware Protection: Install and maintain up-to-date antivirus and antimalware software on all devices to protect against known threats.

  5. Patch Management: Regularly apply security patches and updates to all software and firmware used within your organization to address known vulnerabilities.

  6. Secure Network Configuration: Configure your network securely, ensuring that default settings are changed, unnecessary services are disabled, and access controls are implemented.

  7. User Education and Awareness: Educate your staff about cybersecurity best practices and provide regular training to help them identify and respond to common threats.

How to Achieve Cyber Essentials Plus Compliance

To achieve Cyber Essentials Plus compliance, organizations need to undergo a series of steps:

  1. Self-Assessment: Conduct a self-assessment using the Cyber Essentials Plus questionnaire to evaluate your organization's security practices.

  2. External Vulnerability Testing: Engage an external certifying body or an approved independent tester to perform vulnerability testing and verification of your systems.

  3. Remediation: Address any identified vulnerabilities and implement the necessary security controls to meet the Cyber Essentials Plus requirements.

  4. Verification: The external certifying body or independent tester will verify that your systems meet the Cyber Essentials Plus standards through further testing and evaluation.

  5. Certification: Once the verification process is successfully completed, you will receive the Cyber Essentials Plus certification, demonstrating your organization's commitment to cybersecurity best practices.

Additional Resources

For more information about Cyber Essentials Plus and detailed guidance on achieving compliance, refer to the following resources:

For specific technical guidance and implementation details, please refer to the documentation provided in this repository.