Jump to content

Recommended Posts

Posted

I am going to to be putting my company forward for the cyber essential certification. Has anyone done this before? If so, please can you advise any snags you ran into or anything that could potentially go wrong in the process. Upon reviewing the self assessment, it looks very much like yes and no answers? Is this the case?

 

Many Thanks

Dan

Posted
I've not been involved personally but as an orginisation, its toughened up a lot in recent years, more than just yes and no from the bits I've heard. Got to have a tight ship for it, if its the first time I don't expect you to pass it first time around in my experience. Silly little things can let you down that you don't realise. Not seen the criteria for it as its changed but go through everything 2 or 3 times.
Posted

It can be very challenging under the current question set.

 

You need to audit all your servers and cloud services.

 

All admin accounts must have MFA enabled.

 

Access to organisational data can only be accessed from devices that are compliant. E.G patched within 2 weeks of release. This includes personal devices.

You must provide a list of devices that are accessing organisational data.

 

All clients and Servers in scope must have software updates applied within 2 weeks. Vulnerabilities with CVSS 7.0 or above need to be patched or remediated.

 

Nessus is good as it will highlight what you need to patch.

 

This isn’t an exhaustive list.

Posted

We're using the questions as a list of things we need to fix before we even try applying; you only have 14 days from failure to fix things and re-apply for free, otherwise you have to pay again.

 

Better to not submit until you're reasonably confident you've done what you can see needs doing, first.

  • Thanks 1
Posted

We're preparing for the renewal, like @free780 already stated, there are a number of changes in the new version...

 

Things that we're getting clarification on is whether or not with interactive screens (with built in OSs) are ok if the creator of the OS doesn't support it. Eg alot of interactive boards are based on Android 9 which Google has stopped supporting it, however if the interactive board still provides updates, is that ok? If it is, how much of the actual OS does the interactive board have to support, eg just the apps? the whole OS? etc...

 

MFA for cloud based services, what does everyone do with students? Secondary/Primary? Also questions about if the "Skip multi-factor authentication for requests from following range of IP address subnets" was enable would that be satisfactory or not.

 

What about BYOD that connects to the guest wifi (that doesn't touch the internal network), is that in scope or out of scope?

 

Plus alot more questions...

 

BTW, you do have to provide lists of what you have. And it covers both operating system and firmware versions...

Posted
MFA for cloud based services, what does everyone do with students? Secondary/Primary? Also questions about if the "Skip multi-factor authentication for requests from following range of IP address subnets" was enable would that be satisfactory or not.

 

Students are viewed as customers so are not in scope, only staff.

Posted
Students are viewed as customers so are not in scope, only staff.

 

Students *CAN* be viewed as customers, but that is a bloody stupid scope that misses out a significant portion of risk, effectively making the scheme almost pointless.

 

Ok ... I'll get my coat :getmecoat:

Posted
Students *CAN* be viewed as customers, but that is a bloody stupid scope that misses out a significant portion of risk, effectively making the scheme almost pointless.

 

Ok ... I'll get my coat :getmecoat:

 

You are correct. However implementing MDM for staff personal devices is hard work.

 

Doing it for students would be a massive under taking.

 

The requirements to list all devices that are accessing organisational data are probably the hardest to implement.

Posted
Students are viewed as customers so are not in scope, only staff.

 

Is there anything official stated anywhere that says that? Students have email access, they use the same system as staff for emails, both staff and students have access to some of the same drives/resources, etc...

  • 3 months later...
Posted

We have just started the process to apply for Cyber Essentials.

Our cyber consultants, has told us that Students now need MFA, We are starting to look at it this weekend and looking to enforce it from next monday.

Emails etc has been sent out to our students, god help the helpdesk that weekend.

Posted
I think you could argue that MFA for students is not really needed...CE is written with a business hat on. I was part of the DFE pilot that did CE for free last year with IASME that highlighted to me how they need to either adapt CE for schools or have a different type of certification for us.
Posted
I think you could argue that MFA for students is not really needed...CE is written with a business hat on. I was part of the DFE pilot that did CE for free last year with IASME that highlighted to me how they need to either adapt CE for schools or have a different type of certification for us.

 

I would be curious to hear your argument. I think it’s 100% necessary.

Posted
I would be curious to hear your argument. I think it’s 100% necessary.

 

Ditto

 

One the training videos (NCSC I think?) our staff had to watch points out that hackers start with the lowest level credentials then find their way around, elevating as they go.

 

2FA is our best defence against students who can't set themselves sensible secure passwords.

Posted

In an ideal world yes MFA for all is great.. but how do you implement that with students who don't have a phone at school maybe due to school policy? or maybe children who don't own a phone at all..we need to be careful that by implementing security we don't then put up barriers to learning.

 

Sorry but in my head I am just picturing an 8 year old sat in a computing lesson trying to login to their Google account realising they need their phone its in there locker wondering to the locker the phones out of battery, we charge the phone etc etc etc 20 mins of the lesson is gone and for what? because someone might access an account with the most limited access possible?

Posted (edited)
I would be curious to hear your argument. I think it’s 100% necessary.

 

We too were part of the DfE / RPA Pilot Scheme which started last year, though we didn't complete and pass Cyber Essentials until just before Summer with the DfE providing us with additional assistance from Education Data Hub.

 

This was with the original CE schema. But as many have mentioned, the expanded 'scope' to pass CE now is significantly larger and wider reaching. An element of the DfE / RPA scheme was to also better understand any obstacles schools may have (e.g., lack of skills, associated financial costs, personnel) to pass and obtain Cyber Essentials Accreditation. Or indeed, if CE is suitable for education at all and an alternative accreditation scheme would better suited?

 

I know that Marie Kearney, who helped us, was scheduled to work with schools using the new schema and we'll be keeping in contact with Education Data Hub to prepare for our renewal next year. Although based on current requirements will be difficult to achieve.

 

If you/r school are looking for CE assistance or guidance, I would certainly recommend contacting Education Data Hub. ([email protected])

Edited by MYK-IT
  • Thanks 2
Posted (edited)
In an ideal world yes MFA for all is great.. but how do you implement that with students who don't have a phone at school maybe due to school policy? or maybe children who don't own a phone at all..we need to be careful that by implementing security we don't then put up barriers to learning.

 

Sorry but in my head I am just picturing an 8 year old sat in a computing lesson trying to login to their Google account realising they need their phone its in there locker wondering to the locker the phones out of battery, we charge the phone etc etc etc 20 mins of the lesson is gone and for what? because someone might access an account with the most limited access possible?

 

Use conditional rules so that MFA isn’t required on the premises.

 

The big risk is people outside on the internet getting in their accounts. It’s those areas that you can require MFA without impacting lessons inside the school.

Edited by FN-GM
Posted
*MFA is only required outside of the premises, presumably...

 

Thanks for the correction. Good job nobody implemented it based on that advise!

 

I have corrected the post.

Posted
Use conditional rules so that MFA isn’t required on the premises.

 

The big risk is people outside on the internet getting in their accounts. It’s those areas that you can require MFA without impacting lessons inside the school.

 

Is there an equivalent of conditional MFA rules for Google as there is for Microsoft?

Posted
Is there an equivalent of conditional MFA rules for Google as there is for Microsoft?
From what i understand, Google sees MFA as on or off and no conditional access rules.

 

There is the ability for users to tick the "Don't ask again on this device" (which is actually browser) which adds the browser to the list of trusted devices.

  • Thanks 1
Posted
From what i understand, Google sees MFA as on or off and no conditional access rules.

 

There is the ability for users to tick the "Don't ask again on this device" (which is actually browser) which adds the browser to the list of trusted devices.

 

That would still be a pain when students can use any number of different computers in school and any number of different Chromebooks.

Posted
That would still be a pain when students can use any number of different computers in school and any number of different Chromebooks.

 

Yep, and with kids accounts anyone under 18 (unless google have changed something) they can only authenticate with a text message. They cannot authenticate with any of the other options which works great in parts of the building where there's not cellular signal.

  • Thanks 1

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...