CE-AC.1 | User Account Approval Process | 23 |
CE-AC.2 | Authenticate Users Before Granting Access | 22 |
CE-AC.3 | Remove or Disable Accounts When No Longer Required | 23 |
CE-AC.4 | Privileged Account Approval and Tracking | 23 |
CE-AC.5 | Separate Admin Accounts for Administrative Activities | 21 |
CE-AC.6 | Periodic Review of Privileged Access | 22 |
CE-AC.7 | MFA for Administrative Accounts | 23 |
CE-AC.8 | Passwordless Authentication | 16 |
CE-FW.1 | Boundary Firewalls Deployed | 23 |
CE-FW.2 | Change Default Firewall Passwords | 16 |
CE-FW.3 | Block Unauthenticated Inbound Connections | 17 |
CE-FW.4 | Approve and Document Inbound Rules | 19 |
CE-FW.5 | Remove or Disable Unused Rules | 15 |
CE-FW.6 | Host-Based Firewall for Remote Workers | 22 |
CE-FW.7 | Restrict Firewall Administrative Interface from the Internet | 12 |
CE-MP.1 | Anti-Malware Software Deployed | 22 |
CE-MP.2 | Anti-Malware Signatures Updated | 22 |
CE-MP.3 | Anti-Malware Scans Files on Access and Web Pages | 23 |
CE-MP.4 | Application Allowlisting (Alternative) | 19 |
CE-SC.1 | Remove or Disable Unused Software | 23 |
CE-SC.2 | Change Default Passwords on Devices and Software | 22 |
CE-SC.3 | Disable Auto-Run Features | 15 |
CE-SC.4 | Authenticate Users Before Access | 17 |
CE-SC.5 | Password-Based Authentication Quality | 22 |
CE-SC.6 | Multi-Factor Authentication for Cloud Services | 19 |
CE-SC.7 | Educate Users on Strong Passwords | 19 |
CE-SC.8 | Process for Compromised Passwords | 21 |
CE-SC.9 | Device Unlocking Credentials and Brute-Force Protection | 18 |
CE-SCOPE.1 | Scope Definition | 22 |
CE-SCOPE.2 | Cloud Services in Scope | 21 |
CE-SCOPE.3 | BYOD and Home Working | 17 |
CE-SU.1 | Software Licensed and Supported | 20 |
CE-SU.2 | Automatic Updates Enabled Where Possible | 20 |
CE-SU.3 | Critical and High Updates within 14 Days | 21 |
CE-SU.4 | Remove Out-of-Support Software | 18 |
CE-SU.5 | Firmware Updates | 16 |