Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.
Page Properties
hiddentrue

Document number:

DOC-XXX-XXXXXX

Document type:

Public

Responsibility for implementation & training:

Cyber Essentials Manager

CB contract doc/ schedule:

YES

Scheme

Cyber Essentials

Reason for change:

Initial Version

Approved by:

Approved date:

Next review:

Review and consultation process:

Reviewed Annually by CEO

Master Link:

Associated documentation:

Distribution:

Refined Knowledge Hub

idNavigation_Page

Area

Five Controls

Page Type

Content Page

Page Name

Malware Protection : FAQ

Last Updated

16/09/24

Update Notes

Reviewed

04/11/24

Reviewer

JC

Next Review

04/11/25

Frequently Asked Questions about the Cyber Essentials Control

Image Removed

Image Added

Image Removed

Question

Answer

For question A8.1, can you explain the option of allow listing, especially where BYOD is involved?

The allow listing option means that you must have a list of approved applications which can access organisational data or services. With company-owned devices, this can be accomplished using an MDM solution which only permits specific, approved applications restricted by code signing to be installed. For BYOD, bear in mind that Cyber Essentials is only concerned with applications which access org data, as it's not possible to control what users may install on their own devices. You must therefore ensure that only the applications on the allow list have access - so for example, users can only access email using an approved app. It's expected by the NCSC that technical controls are implemented to achieve this, although in organisations with fewer than 50 employees,  policy or training can be sufficient to meet compliance. 

Is using built-in anti-malware for Windows or MacOS (Windows Defender or Xprotect) considered compliant for Cyber Essentials?

While we do not provide endorsement of any particular product, both Windows Defender and MacOS Xprotect can be used to meet the anti-malware requirement for question A8.1

Insert excerpt
CKHR:M_Malware Protection : FAQ
CKHR:M_Malware Protection : FAQ
nameM_FAQ_MalwareProtection
nopaneltrue