Cyber Essentials (Basic) is a foundational cybersecurity certification that helps organizations protect against common cyber threats. It is a self-assessment certification designed to ensure that essential security controls are in place.
Boundary Firewalls and Internet Gateways
Establish and maintain firewall policies to protect the network perimeter
Configure firewall devices securely changing default passwords and disabling unnecessary services
Secure Configuration
Implement secure configurations for all end-user devices (e.g. laptops desktops mobile devices)
Implement secure configurations for all network devices (e.g. routers switches)
Remove or disable any unnecessary software from systems and devices
User Access Control
Apply the principle of least privilege to user accounts granting only the necessary access rights
Use strong authentication methods for user accounts including strong passwords and multi-factor authentication where appropriate
Implement proper account management processes for creating managing and disabling user accounts
Malware Protection
Deploy and maintain up-to-date anti-malware software on all systems and devices
Implement measures to prevent the execution of known malicious code
Security Update Management
Establish and maintain a policy for managing security updates and patches
Apply security updates and patches to all software and operating systems in a timely manner
Identify and manage end-of-life (EOL) software either by upgrading or removing it