Cyber Essentials Plus Pre-Audit Checklist - Qualys
This checklist is to help your organisation prepare for a Cyber Essentials Plus audit.
Pre-audit checklist to ensure a smooth onsite audit
Confirm all software (including Adobe, Java, etc) is fully up to date on all devices including servers
Remove all software that is rarely used on each device – old browsers such as Firefox are a common issue
Install the Qualys Agent provided by your auditor
Inform the auditor that the agents have been installed
The auditor will confirm the amount of agents reporting on their dashboard and provide an initial High Severity Vulnerability report
Ensure all devices including laptops have up to date anti-virus engines and signature files – preferably using an enterprise management dashboard app
Ensure all executable attachments are prevented from being delivered to the email client
Ensure the anti-virus plugin for each browser in use has been activated and updated
The auditor will ask you to provide the following
A list of all devices (firewalls, servers, PCs, laptops, workstations, tablets and mobile phones) that are in scope with details of their current operating system
Email addresses of users that can be used for the email/web tests on the sample devices selected
A consent form will be required prior to starting the test and this will be prepared once the visit dates have been agreed
The testing process includes the following tests
Confirmation of the devices to be tested
Review of latest Qualys Scan report
Observing how devices process emails with test attachments – access to user device required
Observing how devices handle downloads of file attachments from our test websites – access to user device required
Checking the installation and configuration of anti-virus software
Perform Multi Factor Authentication test on all listed Cloud Services provided in Cyber Essentials self-assessment
Confirm Account separation between Admin and User accounts