Common Pitfalls Obtaining Cyber Essentials
What are the common pitfalls when obtaining a Cyber Essentials Certificate? Cyber Essentials is often treated as a pass or fail test. While the marking criteria is indeed that, the engagement itself is quite different. Inherently, a Cyber Essentials assessment is a consultant-led audit.
The basic Cyber Essentials certification is comprised of a questionnaire which asks the organisation about how they meet the necessary security controls, explanations of how certain processes work and checks on version usage and patching. The assessor <-> applicant relationship is an important element of the audit, and organisations that engage with their assessor are often complete the assessment with minimal friction.
Cyberis has many CE assessors, and technical leads across disciplines who can give an applicant an understanding of what needs to be in place to successfully get past the more difficult hurdles. Our CE assessors won’t tell you what to write, but they will help in translating your environment to the boundaries of the questions if you need the assistance.
The Hidden Complexity of the Questions
One element where we often see difficulties would be around the complexity of the questions and the answers themselves. Cyber Essentials follows a structure where the applicant will have binary 'yes' or 'no' questions, and then some with notes to give extra details. Sometimes a yes or no question will also provide a field for extra details, and in these cases organisations may feel that they need to provide additional details about their infrastructure.
Answers, of course, need to be accurate, but providing irrelevant detail can be counterproductive and confuse the situation. When filling out extra details where it is not necessary, there is an increased risk of introducing mistakes. An organisation may refer to something that was earlier deemed out of scope or paraphrase a control in a way that is not accurate, or simply mistype a word which will affect the context the assessor needs to apply to the whole certification.
When filling out the form, it’s helpful to keep in mind that even though these are largely standalone questions, your answers will need to reflect the rest of the questionnaire. Even something innocuous can result in a question failing or gaining noncompliance marks if the assessor believes the extra details contradicts other areas of the report.
Make sure your answers are accurate, and focused.
Scoping
A very common difficulty when running through an assessment is ensuring that an organisation has provided an appropriate scope, which is especially difficult in assessments that do not cover the whole organisation.
Many organisations face an issue where certain pieces of software need to be used to work within their standard business process but may not have been updated in a very long time or can only run on legacy equipment. This affects industries across the spectrum, and my personal experience is that even low-tech print shops may be running Windows 2000 somewhere for a platemaker. Cyber Essentials allow for this if you appropriately segment your network in a way that disconnects and descopes those devices from the other networks and users. Unfortunately, this is not always clear and can lead to difficulties obtaining Cyber Essentials, as declaring an unsupported operating system or software version can result in failure on an assessment. If not identified or declared during a CE+ assessment, that assessment would also result in a failure.
When we look at scoping, we use a model that is publicly available from the Cyber Essentials Knowledge Hub, and there are two key tests. Are the devices/software in any way able to access the internet? If they are protected by a firewall and only internal communication to them is allowed, we can accept it, without an acknowledgement on the assessment. If they are internet accessible, then we must question whether the unsupported device can, in any way, communicate with the rest of the internal network. If not, then we need to look at segmentation to descope this and specifically outline in the assessment that this segment is not in scope, what it is, why it exists and how you have dealt with it.
Other reasons for descoping do of course exist, and when this is unrelated to compliance then we can even allow the excluded network to have both internal and internet communication, but where user systems on the excluded network can still communicate with the in-scope network, those systems remain in scope.
Discussions with an assessor can help you with the particulars, but we generally would recommend, where possible, to always do a whole organisation assessment for simplicity.
Lack of Resources For the Assessment
The final element that can trouble an organisation is down to how the assessments work from a customer perspective. Completing the questionnaire with the expected technical accuracy and level of detail can be more resource intensive than many organisations may expect. Time is required to not only work through the questionnaire but to properly understand the question set and obtain all the necessary information from multiple departments at the organisation.
This can be dealt with via communication with the assessor, but this needs to be handled proactively as there is not a lot of time for the assessor to go through the question set, identify misunderstandings and then help the customer understand the identified mistakes. On rare occasions, this can lead to more time having to be scheduled for the assessment to allow for a thorough review and appropriate marking under the Cyber Essentials scheme.
Cyber Essentials at the heart of it is an audit guided by strict criteria, and that is a challenge that consultancy lends itself to solving. Organisations that engage early, ask questions and allocate the appropriate amount of time to the task will be the ones with the easiest time overall. If you would like to discuss how Cyberis can support your organisation through the process, please get in touch with our team.
References
Improve your security
Our experienced team will identify and address your most critical information security concerns.