Controls
The controls a cyber schedule reads
Each control is what an applicant reports: in place, partly, not in place or not sure. Each page sets out the rule behind it in Australia, the United States and the United Kingdom, and the evidence an assessor asks for.
Multi-factor authentication
- Staff sign in to email and the online services that hold business data (office suite, accounting, practice or client software) with multi-factor authentication
- Customers who log in to an online service you run that holds their sensitive data are offered or required to use multi-factor authentication
- Remote access (VPN, remote desktop) and every administrator account use multi-factor authentication
- The multi-factor authentication staff use is phishing-resistant (security keys or passkeys rather than codes)
Backups
- Backups of data, applications and settings run on a schedule set by how critical each system is, and can be restored to a common point in time
- Backups are kept in a secure and resilient way (an isolated, offline or unchangeable copy), and ordinary staff accounts cannot change or delete them
- Administrator accounts (other than the backup administrator) cannot change or delete backups
- Restoring from backup is tested as part of a disaster recovery exercise
Patching
- Security patches for internet-facing services and devices (websites, remote access, firewalls, email gateways) are applied within the timeframes in the requirement
- Office software, web browsers, email clients, PDF readers, security products and workstation operating systems are patched within the timeframes in the requirement
- Other business applications are patched within the timeframe in the requirement
- Automated asset discovery and an up-to-date vulnerability scanner run on the schedules in the requirements
- Operating systems, office software, browsers, PDF software and online services that the vendor no longer supports are replaced or removed
Administrator accounts
- Administrators use a separate privileged account and environment for admin work only, with no internet or email on it
- Requests for privileged access are checked and signed off when first requested, and privileged accounts are tracked
- Privileged access is reviewed: switched off after 45 days of inactivity and after 12 months unless revalidated
- Break glass, local administrator and service account passwords are long, unique, unpredictable and managed, and default passwords are changed
Application control and hardening
- Application control on workstations lets only programs, scripts and installers the business has allowed run, including from user profiles and temporary folders
- Application control also covers internet-facing servers and all other locations, with the recommended blocklist and an annual ruleset review
- Macros in office files from the internet are blocked, macros are off for staff with no business need, are scanned, and users cannot change the settings
- Web browsers do not run internet ads or plug-in code from the internet, users cannot change browser security settings, and the old built-in browser is disabled or removed
- Office and PDF software are hardened, blocked from creating child processes and executable content, and users cannot change their security settings
Logging and incident response
- Privileged access events and logs from internet-facing servers are collected centrally, protected from change, and reviewed in a timely manner
- There is a written cyber security incident response plan, it is enacted when an incident is identified, and incidents are reported internally and to the authority the rule names
Other controls proposal forms ask about
- Every workstation and server runs centrally managed, behaviour-based anti-malware (often sold as endpoint detection and response)
- Inbound email is scanned for malware and phishing with unneeded attachment types blocked, and the domain publishes DMARC
- Staff are trained to recognise phishing and other social engineering, and to report a suspected incident
- Laptops, phones and removable media that hold sensitive data are encrypted
- Every device sits behind a correctly configured boundary or host firewall, with inbound rules signed off and unused rules removed
- IT and cloud providers with access to systems or data are listed, and their contracts carry security requirements
Sector rules (add-ons)
- A written information security program exists, owned by a named qualified individual or officer
- A written risk assessment of the information systems is done and repeated periodically
- The business knows the notice its rule requires after an incident or a data breach, to whom and by when
- Stored card numbers are rendered unreadable wherever they are kept
Privacy Act (Australia)
- Personal information held is protected by reasonable steps against misuse, interference, loss and unauthorised access
- A data breach response plan exists, and a suspected data breach is assessed within the 30 days the Notifiable Data Breaches scheme sets
- The business knows when and how to notify the Commissioner and the people affected by a data breach the scheme covers
- A clearly expressed, up-to-date privacy policy is published