Published 08/10/2024 – est. 4 minutes to read.
Cyber Essentials Knowledge Hub
There are now references to the Cyber Essentials requirements quoted throughout the assessment. A Link is also provided to the Knowledge Hub, set up by IASME, to provide advice and guidance on scope, operating system support, and the five controls of Cyber Essentials. The Knowledge Hub can be accessed here: Cyber Essentials Knowledge Hub
The main changes to the questions are as follows:
- A2.7.1 How many staff are home or remote workers – remote workers are now included to reflect changes to flexible working in the past five years and that they may be connecting using untrusted networks in hotels and cafes.
- A2.8 Network Equipment – clarification has been made to confirm that firewalls and routers should be listed here. The notes field should also confirm that home and remote workers are using software firewalls as their boundary.
- Section 4 Firewalls – the wording of several questions has been revised to provide greater clarity on managing firewalls, the services enabled, and the regular review of firewall rules.
- Section 6 Security Update Management – clarification has been provided to confirm that configuration changes or registry fixes must be applied if advised by the operating system or application to remediate a critical or high-rated vulnerability.
- Passwordless Authentication – logging in without a password is now considered compliant under Cyber Essentials if it uses accepted authentication methods such as biometrics, security keys, tokens, one-time codes, and push notifications. Passwordless authentication is now an option in the answers to the following questions.
- A4.3 How is your firewall password configured
- A5.5 Authentication of external services
- A7.10 Where you have systems that require passwords – or where passwords are a backup for a passwordless system, how are they protected from brute-force attacks?
- A7.4 Do you ensure that staff only have the privileges that they need to do their current job – it is now a requirement that the principle of least privilege be applied.
The Cyber Essentials Plus assessment test specification is also being updated. Confirmation of the new specification was confirmed on January 2025. The planned changes are designed to provide greater confidence in the Cyber Security posture of companies completing the certification and higher levels of assurance to their customers.
To find out more about the Cyber Essentials changes or discuss our other services, connect directly with our technical team:
Telephone: 0161 706 0244
Email: info@cybersecurityspecialists.co.uk
