{"id":70931,"date":"2023-04-19T09:29:42","date_gmt":"2023-04-19T13:29:42","guid":{"rendered":"https:\/\/jumpcloud.com\/?p=70931"},"modified":"2024-02-05T12:54:15","modified_gmt":"2024-02-05T17:54:15","slug":"cybersecurity-plus-compliance-get-ready","status":"publish","type":"post","link":"https:\/\/jumpcloud.com\/blog\/cybersecurity-plus-compliance-get-ready","title":{"rendered":"How to Prepare for the CyberSecurity Plus Compliance Assessment"},"content":{"rendered":"\n

UK businesses have experienced a sharp increase in cyber incidents over the past several years. In 2022, 39% of UK businesses reported having experienced a cyber attack, according to the government\u2019s Cyber Security Breaches Survey of 2022<\/a>.<\/p>\n\n\n\n

The most common offender by far was phishing, followed by more sophisticated security breach methods such as ransomware, malware, and denial of service. The UK government responded by increasing its list of security controls for Cyber Essentials Plus in early 2022<\/a>.\u00a0<\/p>\n\n\n\n

The recommended security framework for UK businesses now includes standards for multi-factor authentication (MFA), mobile device management (MDM)<\/a>, cloud systems, and Bring Your Own Device (BYOD)<\/a>, among other cybersecurity best practices. <\/p>\n\n\n\n

In addition, applicants must now provide evidence to support their self-assessment questionnaire responses. The good news?<\/p>\n\n\n

\n
\"\"<\/figure><\/div>\n\n\n

<\/p>\n\n\n\n

Meeting compliance requirements for Cyber Essentials Plus isn\u2019t as complex as it may initially seem. With the right tools and systems in place, IT admins can breeze through most checklist items fairly quickly. <\/p>\n\n\n\n

Keep reading to learn how to complete and document your organisation\u2019s Cyber Essentials Plus requirements with less stress.<\/p>\n\n\n\n

What Is Cyber Essentials Plus?<\/h2>\n\n\n\n

Cyber Essentials Plus is a government-backed data security framework designed to provide organisations with a strong defense against cybercrime. <\/p>\n\n\n\n

The National Cyber Security Center (NCSC)<\/a> and the IASME Consortium<\/a> worked in partnership to develop the latest security recommendations included within the Cyber Essentials framework<\/a>. <\/p>\n\n\n\n

Essentially, the standard provides a security baseline for every business in every industry against five key areas:<\/p>\n\n\n\n

    \n
  1. Access control<\/li>\n\n\n\n
  2. Firewalls and routers<\/li>\n\n\n\n
  3. Malware protection<\/li>\n\n\n\n
  4. Secure configurations<\/li>\n\n\n\n
  5. Software updates<\/li>\n<\/ol>\n\n\n\n

    Cyber Essentials Plus is the more stringent version of Cyber Essentials; the latter includes a lightweight self-assessment and internal vulnerability scan. <\/p>\n\n\n\n

    Cyber Essentials Plus, on the other hand, requires an additional technical audit of in-scope systems, an on-site or remote assessment, internal vulnerability scans, and an external vulnerability scan conducted by the certification body. <\/p>\n\n\n\n

    The internal scan is set up to check patches and system configurations. Security and anti-malware tests ensure your organisation\u2019s systems are resistant to malicious email attachments and web-downloadable binaries. <\/p>\n\n\n\n

    And, finally, the external scan verifies patches and system configurations for public-facing infrastructure.<\/p>\n\n\n\n

    Why Is Cyber Essentials Plus Important? <\/h2>\n\n\n\n

    Following the Cyber Essentials Plus security framework is crucial for any organisation wanting to avoid security breaches and safeguard stakeholder data. Here are the most common reasons businesses choose to achieve Cyber <\/p>\n\n\n\n

    Essentials Plus certification:<\/p>\n\n\n\n