01Scope
Identify which organisation, devices, networks, cloud services and internet-facing systems are included. Scope mistakes can undermine the rest of the assessment.
02Firewalls
Restrict unnecessary inbound access and make sure internet boundaries are securely configured.
03Secure configuration
Remove unnecessary software/services, address default settings and reduce avoidable attack surface.
04Security update management
Use supported software and apply qualifying security fixes within the required timeframe.
05User access control
Limit access to what people need, control privileged accounts and use MFA where the requirements call for it.
06Malware protection
Use appropriate malware protection, application allow-listing or equivalent controls for in-scope devices.