Back to Frameworks

ANSSI Guide d'hygiene informatique (42 mesures, v2.0)

France
vVersion 2.0, September 2017 (ANSSI-GP-042), 42 measures across 10 themes
10 domains
42 controls

ANSSI Guide d'hygiene informatique, the French national cybersecurity agency baseline of 42 measures across 10 themes for strengthening the security of an information system.

Verified

Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.

Framework Domains (10)

ANSSI Hygiene I: Raise Awareness and Train (measures 1 to 3)

3 controls
Controls in the ANSSI Hygiene I: Raise Awareness and Train (measures 1 to 3) domain of ANSSI Guide d'hygiene informatique (42 mesures, v2.0)3 controls
CodeTitle
ANSSI-HYG-01Train Operational Teams in Information System Security
ANSSI-HYG-02Raise User Awareness of Basic Security Practice
ANSSI-HYG-03Control the Risks of Outsourced Information System Management

ANSSI Hygiene II: Know the Information System (measures 4 to 7)

4 controls
Controls in the ANSSI Hygiene II: Know the Information System (measures 4 to 7) domain of ANSSI Guide d'hygiene informatique (42 mesures, v2.0)4 controls
CodeTitle
ANSSI-HYG-04Identify the Most Sensitive Information and Servers and Maintain a Network Diagram
ANSSI-HYG-05Maintain an Exhaustive Inventory of Privileged Accounts
ANSSI-HYG-06Organise Joiner, Leaver and Role Change Procedures
ANSSI-HYG-07Authorise Network Connection Only for Managed Equipment

ANSSI Hygiene III: Authenticate and Control Access (measures 8 to 13)

6 controls
Controls in the ANSSI Hygiene III: Authenticate and Control Access (measures 8 to 13) domain of ANSSI Guide d'hygiene informatique (42 mesures, v2.0)6 controls
CodeTitle
ANSSI-HYG-08Identify Each Person by Name and Separate User and Administrator Roles
ANSSI-HYG-09Assign the Correct Rights on Sensitive Resources
ANSSI-HYG-10Define and Verify Password Selection and Sizing Rules
ANSSI-HYG-11Protect Passwords Stored on Systems
ANSSI-HYG-12Change Default Authentication Elements on Equipment and Services
ANSSI-HYG-13Prefer Strong Authentication Where Possible

ANSSI Hygiene IV: Secure Workstations (measures 14 to 18)

5 controls
Controls in the ANSSI Hygiene IV: Secure Workstations (measures 14 to 18) domain of ANSSI Guide d'hygiene informatique (42 mesures, v2.0)5 controls
CodeTitle
ANSSI-HYG-14Apply a Minimum Security Level Across the Whole Estate
ANSSI-HYG-15Protect Against Threats Related to Removable Media
ANSSI-HYG-16Use a Centralised Management Tool to Standardise Security Policies
ANSSI-HYG-17Enable and Configure the Local Firewall on Workstations
ANSSI-HYG-18Encrypt Sensitive Data Transmitted Over the Internet

ANSSI Hygiene IX: Supervise, Audit and Respond (measures 36 to 40)

5 controls
Controls in the ANSSI Hygiene IX: Supervise, Audit and Respond (measures 36 to 40) domain of ANSSI Guide d'hygiene informatique (42 mesures, v2.0)5 controls
CodeTitle
ANSSI-HYG-36Enable and Configure Logging on the Most Important Components
ANSSI-HYG-37Define and Apply a Backup Policy for Critical Components
ANSSI-HYG-38Carry Out Regular Security Checks and Audits and Apply the Corrective Actions
ANSSI-HYG-39Designate an Information System Security Officer and Make the Role Known
ANSSI-HYG-40Define a Security Incident Management Procedure

ANSSI Hygiene V: Secure the Network (measures 19 to 26)

8 controls
Controls in the ANSSI Hygiene V: Secure the Network (measures 19 to 26) domain of ANSSI Guide d'hygiene informatique (42 mesures, v2.0)8 controls
CodeTitle
ANSSI-HYG-19Segment the Network and Partition the Zones
ANSSI-HYG-20Secure Wi-Fi Access Networks and Separate Usage
ANSSI-HYG-21Use Secure Protocols Wherever They Exist
ANSSI-HYG-22Put in Place a Secure Internet Access Gateway
ANSSI-HYG-23Partition Internet Facing Services from the Rest of the Information System
ANSSI-HYG-24Protect the Corporate Mail Service
ANSSI-HYG-25Secure Dedicated Network Interconnections with Partners
ANSSI-HYG-26Control and Protect Access to Server Rooms and Technical Areas

ANSSI Hygiene VI: Secure Administration (measures 27 to 29)

3 controls
Controls in the ANSSI Hygiene VI: Secure Administration (measures 27 to 29) domain of ANSSI Guide d'hygiene informatique (42 mesures, v2.0)3 controls
CodeTitle
ANSSI-HYG-27Prohibit Internet Access from Administration Workstations and Servers
ANSSI-HYG-28Use a Dedicated and Partitioned Network for Administration
ANSSI-HYG-29Limit Administration Rights on Workstations to Operational Need

ANSSI Hygiene VII: Manage Mobile Working (measures 30 to 33)

4 controls
Controls in the ANSSI Hygiene VII: Manage Mobile Working (measures 30 to 33) domain of ANSSI Guide d'hygiene informatique (42 mesures, v2.0)4 controls
CodeTitle
ANSSI-HYG-30Apply Physical Protection Measures to Mobile Devices
ANSSI-HYG-31Encrypt Sensitive Data, in Particular on Equipment That May Be Lost
ANSSI-HYG-32Secure the Network Connection of Devices Used for Mobile Working
ANSSI-HYG-33Adopt Security Policies Dedicated to Mobile Terminals

ANSSI Hygiene VIII: Keep the Information System Up to Date (measures 34 and 35)

2 controls
Controls in the ANSSI Hygiene VIII: Keep the Information System Up to Date (measures 34 and 35) domain of ANSSI Guide d'hygiene informatique (42 mesures, v2.0)2 controls
CodeTitle
ANSSI-HYG-34Define an Update Policy for Information System Components
ANSSI-HYG-35Anticipate the End of Maintenance of Software and Systems

ANSSI Hygiene X: Going Further (measures 41 and 42)

2 controls
Controls in the ANSSI Hygiene X: Going Further (measures 41 and 42) domain of ANSSI Guide d'hygiene informatique (42 mesures, v2.0)2 controls
CodeTitle
ANSSI-HYG-41Conduct a Formal Risk Analysis
ANSSI-HYG-42Prefer Products and Services Qualified by ANSSI

Your Compliance Coverage

If you comply with ANSSI Guide d'hygiene informatique (42 mesures, v2.0), you already cover:

Maps to 34 other frameworks

42 total controls
NIST SP 800-161 Rev 1
42 source controls mapped|47 target controls covered
100%
NIST SP 800-53 Rev 5 MODERATE
42 source controls mapped|86 target controls covered
100%
FedRAMP Moderate
42 source controls mapped|102 target controls covered
100%
NIST SP 800-53 Revision 5.1 HIGH
42 source controls mapped|87 target controls covered
100%
FedRAMP High
42 source controls mapped|101 target controls covered
100%
NIST SP 800-53 Rev 5
42 source controls mapped|80 target controls covered
100%
NIST SP 800-171 Rev 3
42 source controls mapped|67 target controls covered
100%
NIST Cybersecurity Framework 2.0
42 source controls mapped|59 target controls covered
100%
ISO 27001:2022
42 source controls mapped|50 target controls covered
100%
ISO 27002:2022
41 source controls mapped|49 target controls covered
98%
Cloud Security Alliance Cloud Controls Matrix (CCM) v4.0.1
41 source controls mapped|88 target controls covered
98%
PCI DSS 4.0
41 source controls mapped|97 target controls covered
98%
NIST SP 800-53 Rev 5 LOW
40 source controls mapped|58 target controls covered
95%
CMMC 2.0
40 source controls mapped|79 target controls covered
95%
SOC 2
40 source controls mapped|25 target controls covered
95%
CIS Controls v8
38 source controls mapped|94 target controls covered
90%
Azure Security Benchmark
37 source controls mapped|57 target controls covered
88%
C5 (Germany)
36 source controls mapped|60 target controls covered
86%
AWS Well-Architected Security Pillar
32 source controls mapped|41 target controls covered
76%
HIPAA Security Rule
30 source controls mapped|42 target controls covered
71%
ASD Strategies to Mitigate Cyber Security Incidents
30 source controls mapped|27 target controls covered
71%
NIST SP 800-66 Rev 2
29 source controls mapped|40 target controls covered
69%
UK Cyber Essentials
26 source controls mapped|34 target controls covered
62%
ACSC Essential Eight
20 source controls mapped|14 target controls covered
48%
NIST SP 800-172
14 source controls mapped|15 target controls covered
33%
APRA CPS 234
11 source controls mapped|14 target controls covered
26%
APRA CPS 230 Operational Risk Management
8 source controls mapped|9 target controls covered
19%
APPI
8 source controls mapped|5 target controls covered
19%
ISO/IEC 42001:2023
6 source controls mapped|7 target controls covered
14%
Australian Privacy Principles (APPs)
4 source controls mapped|1 target controls covered
10%
ISO 27701:2019
2 source controls mapped|2 target controls covered
5%
ISO 27018:2019
1 source controls mapped|1 target controls covered
2%
ISO 27017:2015
1 source controls mapped|1 target controls covered
2%
ISO 37001:2016
1 source controls mapped|1 target controls covered
2%

Frequently Asked Questions

What is ANSSI Guide d'hygiene informatique (42 mesures, v2.0)?

ANSSI Guide d'hygiene informatique (42 mesures, v2.0) is a compliance framework from France with 10 domains and 42 controls. ANSSI Guide d'hygiene informatique, the French national cybersecurity agency baseline of 42 measures across 10 themes for strengthening the security of an information system. It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.

How many controls does ANSSI Guide d'hygiene informatique (42 mesures, v2.0) have?

ANSSI Guide d'hygiene informatique (42 mesures, v2.0) has 42 controls organised across 10 domains. The largest domains are ANSSI Hygiene V: Secure the Network (measures 19 to 26) (8 controls), ANSSI Hygiene III: Authenticate and Control Access (measures 8 to 13) (6 controls), ANSSI Hygiene IV: Secure Workstations (measures 14 to 18) (5 controls). Each control defines specific requirements that organisations must implement to achieve compliance.

What frameworks does ANSSI Guide d'hygiene informatique (42 mesures, v2.0) map to?

ANSSI Guide d'hygiene informatique (42 mesures, v2.0) maps to 34 other compliance frameworks. The top mapping partners are NIST SP 800-161 Rev 1 (100% coverage), NIST SP 800-53 Rev 5 MODERATE (100% coverage), FedRAMP Moderate (100% coverage). Use our comparison tool to explore control-level mappings between frameworks.

How do I get started with ANSSI Guide d'hygiene informatique (42 mesures, v2.0) compliance?

Start your ANSSI Guide d'hygiene informatique (42 mesures, v2.0) compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about ANSSI Guide d'hygiene informatique (42 mesures, v2.0) requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 42 controls and track your progress.

Start Your Compliance Journey

Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 686 frameworks.

Get Started Free →

Free forever — no credit card required