What asset data does Cyber Essentials require?
Once the Cyber Essentials add-on is enabled, each of the five controls has specific fields you record against your devices, software, and user accounts. Here's exactly what feeds each control.
Firewalls & Secure Configuration (on Devices)
Open a device and fill in the Cyber Essentials section:
- Firewall Enabled
- Remote Admin (locked down or not)
- Default Creds Changed
- Hardening Baseline applied
- Auto-run Disabled
Malware Protection (on Devices)
Also on each device record:
- AV Product — the name of the anti-malware software installed
- AV Real-time Scan — whether it scans in real time
- AV Auto-update — whether definitions update automatically
- AV Last Updated — when definitions last refreshed
!
Warning
"Real-time AV scanning not confirmed" on the Cyber Essentials page means exactly what it says — the AV Real-time Scan field on that device is blank or set to No. Update it on the device record to clear the issue.
Patch Management (on Devices and Software)
- Devices: Auto-update OS, OS Last Patched
- Software: Auto-update, Last Patched, Still Supported, EOL Date
User Access Control (on User Accounts)
- Admin Account — whether the account has admin privileges
- MFA Enabled — whether multi-factor authentication is turned on
!
Important
Under Cyber Essentials v3.3, an admin account without MFA is an automatic fail for the whole assessment when MFA is available on that service — not just a point deduction. Keep admin accounts to a minimum and confirm MFA on every one of them.