France

ANSSI Guide d'hygiene informatique (42 mesures, v2.0)

42 controls. 34 other frameworks in our corpus share controls with it. Here is all of it, and how much of it you are already doing.

Page built . This page is derived from the framework corpus, which changes when the corpus is extended rather than daily.

42 controls 34 frameworks share controls with it France verified against its source document

Every control below is one this framework asks for. The right hand column counts how many other frameworks in our corpus carry the same control, which is the difference between doing this work once and doing it again for the next standard.

There is no implementation kit for this framework yet. The control list and the overlap above are free and complete.

What you already have

Frameworks whose controls overlap this one, most first. If you run any of them, the count is roughly what you have already evidenced.

Every control

CodeControlAlso in
ANSSI-HYG-01Train Operational Teams in Information System Security24
ANSSI-HYG-02Raise User Awareness of Basic Security Practice25
ANSSI-HYG-03Control the Risks of Outsourced Information System Management25
ANSSI-HYG-04Identify the Most Sensitive Information and Servers and Maintain a Network Diagram24
ANSSI-HYG-05Maintain an Exhaustive Inventory of Privileged Accounts24
ANSSI-HYG-06Organise Joiner, Leaver and Role Change Procedures25
ANSSI-HYG-07Authorise Network Connection Only for Managed Equipment23
ANSSI-HYG-08Identify Each Person by Name and Separate User and Administrator Roles24
ANSSI-HYG-09Assign the Correct Rights on Sensitive Resources27
ANSSI-HYG-10Define and Verify Password Selection and Sizing Rules25
ANSSI-HYG-11Protect Passwords Stored on Systems23
ANSSI-HYG-12Change Default Authentication Elements on Equipment and Services23
ANSSI-HYG-13Prefer Strong Authentication Where Possible25
ANSSI-HYG-14Apply a Minimum Security Level Across the Whole Estate24
ANSSI-HYG-15Protect Against Threats Related to Removable Media21
ANSSI-HYG-16Use a Centralised Management Tool to Standardise Security Policies20
ANSSI-HYG-17Enable and Configure the Local Firewall on Workstations20
ANSSI-HYG-18Encrypt Sensitive Data Transmitted Over the Internet26
ANSSI-HYG-19Segment the Network and Partition the Zones22
ANSSI-HYG-20Secure Wi-Fi Access Networks and Separate Usage16
ANSSI-HYG-21Use Secure Protocols Wherever They Exist21
ANSSI-HYG-22Put in Place a Secure Internet Access Gateway21
ANSSI-HYG-23Partition Internet Facing Services from the Rest of the Information System20
ANSSI-HYG-24Protect the Corporate Mail Service22
ANSSI-HYG-25Secure Dedicated Network Interconnections with Partners23
ANSSI-HYG-26Control and Protect Access to Server Rooms and Technical Areas18
ANSSI-HYG-27Prohibit Internet Access from Administration Workstations and Servers22
ANSSI-HYG-28Use a Dedicated and Partitioned Network for Administration20
ANSSI-HYG-29Limit Administration Rights on Workstations to Operational Need25
ANSSI-HYG-30Apply Physical Protection Measures to Mobile Devices18
ANSSI-HYG-31Encrypt Sensitive Data, in Particular on Equipment That May Be Lost23
ANSSI-HYG-32Secure the Network Connection of Devices Used for Mobile Working22
ANSSI-HYG-33Adopt Security Policies Dedicated to Mobile Terminals20
ANSSI-HYG-34Define an Update Policy for Information System Components24
ANSSI-HYG-35Anticipate the End of Maintenance of Software and Systems23
ANSSI-HYG-36Enable and Configure Logging on the Most Important Components29
ANSSI-HYG-37Define and Apply a Backup Policy for Critical Components24
ANSSI-HYG-38Carry Out Regular Security Checks and Audits and Apply the Corrective Actions25
ANSSI-HYG-39Designate an Information System Security Officer and Make the Role Known23
ANSSI-HYG-40Define a Security Incident Management Procedure29
ANSSI-HYG-41Conduct a Formal Risk Analysis22
ANSSI-HYG-42Prefer Products and Services Qualified by ANSSI15

Tell me when ANSSI Guide d'hygiene informatique (42 mesures, v2.0) files something new

One email when a public company newly discloses something this framework governs, naming the company and what our corpus says it puts in scope. Nothing else, and one click to stop.

What an auditor will ask you to produce

The artefacts named on the failure modes this framework speaks to.

  • Identity proofing policy aligned to risk tiers
  • Issuance and binding records for credentials
  • Re proofing triggers for elevated access
  • Identity verification audit logs
  • Exception register for proofing variances
  • Account naming standard prohibiting shared accounts

How programmes fail on this

Failure modes named by this framework and others. Each opens the full record.

What this page is

A control-level reference for ANSSI Guide d'hygiene informatique (42 mesures, v2.0), drawn from our framework corpus. Control codes and titles are references to the standard, not reproductions of it. The overlap counts and the auditor artefacts are our own work and are the part you will not find elsewhere.

Measure this against what you already run · All frameworks · Today's edition