UK NCSC Cyber Assessment Framework
Objective B: Protecting against cyber attack – UK NCSC Cyber Assessment Framework

UK NCSC Cyber Assessment Framework B4.c: B4.c Secure management

Systems are managed so as to enable and maintain security. Partially achieved: administration is done only by authorised privileged users from devices separated from standard use, technical documentation and diagrams are regularly reviewed, and malware and unauthorised software are prevented, detected and removed. Achieved: administration only from highly trusted dedicated devices such as privileged access workstations, documentation kept current and securely stored, and malware controls using technical, procedural and physical measures.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

Other controls in Objective B: Protecting against cyber attack – UK NCSC Cyber Assessment Framework

Query this from an agent

The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.