UK NCSC Cyber Assessment Framework
Objective B: Protecting against cyber attack – UK NCSC Cyber Assessment Framework

UK NCSC Cyber Assessment Framework B2.b: B2.b Device management

The organisation knows and trusts the devices used to access its systems and data. Partially achieved: only corporately owned and managed devices connect, privileged operations use managed devices separated from standard use, third-party devices' security is understood with risks mitigated, plugging into a port grants no access, and unknown devices can be detected. Achieved: privileged operations only from highly trusted devices such as privileged access workstations, independent assurance of third-party devices or only dedicated ones allowed, certificate-based device identity with only known devices permitted, and regular scans for unknown devices.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

Other controls in Objective B: Protecting against cyber attack – UK NCSC Cyber Assessment Framework

Query this from an agent

The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.