Skip to main content

Cyber Essentials Plus Pre-Audit Checklist - Nessus

Cyber Essentials Plus Pre-Audit Checklist - Nessus


A checklist you can run through to help prepare your organisation before a Cyber Essentials Plus audit.
​
​
​Pre-audit checklist to ensure a smooth onsite audit

  1. Confirm all software (including Adobe, Java, etc) is fully up to date on all devices including servers. (You must download and install Nessus Professional. They have a 7-day trial version of Nessus Professional for a Credentialed Patch Scan or speak to your assessor if you have a PCI approved scanning tool already in place).

  2. Ensure the installation of Nessus Pro (if using trial) is fully completed, so the installation goes through to create account and also downloads plugins -- can take up to 40 mins

  3. Remove all software that is rarely used on each device – old browsers such as Firefox are a common issue.

  4. For devices running Windows - please enable file and print sharing. The option is in advanced sharing settings.

  5. For the devices running Windows 10 or 11, the startup type set to "Manual" for the Windows service “RemoteRegistry". This option is opened by typing “services” in search bar on Windows 10 home screen

  6. Also for devices running Windows 10 or 11, the following registry value needs creating, this option is opened by typing "regedit" in search bar on the Windows 10 or 11 home screen.

  1. Hive and key path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\

  2. On System, right click then select New --> DWORD (32-bit) Value / REG_DWORD

  3. Value name: LocalAccountTokenFilterPolicy

  4. Value data: 1 (decimal)

  1. For devices running macOS please enable File Sharing and Remote Login. These options are in System Preferences --> Sharing

  2. Ensure all devices including laptops have up to date AV engines and signature files – preferably using an enterprise management dashboard app.

  3. Ensure all executable attachments are prevented from being delivered to the email client.

  4. Ensure the AV software is set to scan web pages visited and warn about accessing malicious websites for each browser in use and has been activated and updated.

The auditor will ask you to provide the following

  1. Domain administrator level access. Either create a new admin account for the audit process, or ensure someone with admin level is present during the audit.

  2. A list of all devices (Firewalls, Servers, PCs, laptops, workstations, tablets and mobile phones) that are in scope with details of their current operating system. Please note, if Windows 10 or 11 is in use a registry edit will be required for these devices to allow the scans to run.

  3. Email addresses of users that can be used for the email/web tests on the sample devices selected.

  4. A consent form will be required prior to starting the test and this will be prepared once the visit dates have been agreed.

The testing process includes the following tests

  1. Confirmation of the devices to be tested

  2. Scanning of devices to identify vulnerabilities using Nessus Professional scanning software – requires details of the admin credentials for each device

  3. Observing how devices process emails with test attachments – access to user device required

  4. Observing how devices handle downloads of file attachments from our test websites – access to user device required

  5. Checking the installation and configuration of anti-virus software

  6. Perform Multi Factor Authentication test on all listed Cloud Services provided in Cyber Essentials self-assessment

  7. Confirm Account separation between Admin and User accounts.

Did this answer your question?