ANSSI-HYG-01 | Train Operational Teams in Information System Security | 24 |
ANSSI-HYG-02 | Raise User Awareness of Basic Security Practice | 25 |
ANSSI-HYG-03 | Control the Risks of Outsourced Information System Management | 25 |
ANSSI-HYG-04 | Identify the Most Sensitive Information and Servers and Maintain a Network Diagram | 24 |
ANSSI-HYG-05 | Maintain an Exhaustive Inventory of Privileged Accounts | 24 |
ANSSI-HYG-06 | Organise Joiner, Leaver and Role Change Procedures | 25 |
ANSSI-HYG-07 | Authorise Network Connection Only for Managed Equipment | 23 |
ANSSI-HYG-08 | Identify Each Person by Name and Separate User and Administrator Roles | 24 |
ANSSI-HYG-09 | Assign the Correct Rights on Sensitive Resources | 27 |
ANSSI-HYG-10 | Define and Verify Password Selection and Sizing Rules | 25 |
ANSSI-HYG-11 | Protect Passwords Stored on Systems | 23 |
ANSSI-HYG-12 | Change Default Authentication Elements on Equipment and Services | 23 |
ANSSI-HYG-13 | Prefer Strong Authentication Where Possible | 25 |
ANSSI-HYG-14 | Apply a Minimum Security Level Across the Whole Estate | 24 |
ANSSI-HYG-15 | Protect Against Threats Related to Removable Media | 21 |
ANSSI-HYG-16 | Use a Centralised Management Tool to Standardise Security Policies | 20 |
ANSSI-HYG-17 | Enable and Configure the Local Firewall on Workstations | 20 |
ANSSI-HYG-18 | Encrypt Sensitive Data Transmitted Over the Internet | 26 |
ANSSI-HYG-19 | Segment the Network and Partition the Zones | 22 |
ANSSI-HYG-20 | Secure Wi-Fi Access Networks and Separate Usage | 16 |
ANSSI-HYG-21 | Use Secure Protocols Wherever They Exist | 21 |
ANSSI-HYG-22 | Put in Place a Secure Internet Access Gateway | 21 |
ANSSI-HYG-23 | Partition Internet Facing Services from the Rest of the Information System | 20 |
ANSSI-HYG-24 | Protect the Corporate Mail Service | 22 |
ANSSI-HYG-25 | Secure Dedicated Network Interconnections with Partners | 23 |
ANSSI-HYG-26 | Control and Protect Access to Server Rooms and Technical Areas | 18 |
ANSSI-HYG-27 | Prohibit Internet Access from Administration Workstations and Servers | 22 |
ANSSI-HYG-28 | Use a Dedicated and Partitioned Network for Administration | 20 |
ANSSI-HYG-29 | Limit Administration Rights on Workstations to Operational Need | 25 |
ANSSI-HYG-30 | Apply Physical Protection Measures to Mobile Devices | 18 |
ANSSI-HYG-31 | Encrypt Sensitive Data, in Particular on Equipment That May Be Lost | 23 |
ANSSI-HYG-32 | Secure the Network Connection of Devices Used for Mobile Working | 22 |
ANSSI-HYG-33 | Adopt Security Policies Dedicated to Mobile Terminals | 20 |
ANSSI-HYG-34 | Define an Update Policy for Information System Components | 24 |
ANSSI-HYG-35 | Anticipate the End of Maintenance of Software and Systems | 23 |
ANSSI-HYG-36 | Enable and Configure Logging on the Most Important Components | 29 |
ANSSI-HYG-37 | Define and Apply a Backup Policy for Critical Components | 24 |
ANSSI-HYG-38 | Carry Out Regular Security Checks and Audits and Apply the Corrective Actions | 25 |
ANSSI-HYG-39 | Designate an Information System Security Officer and Make the Role Known | 23 |
ANSSI-HYG-40 | Define a Security Incident Management Procedure | 29 |
ANSSI-HYG-41 | Conduct a Formal Risk Analysis | 22 |
ANSSI-HYG-42 | Prefer Products and Services Qualified by ANSSI | 15 |