ANSSI Guide d'hygiene informatique (42 mesures, v2.0)
ANSSI Guide d'hygiene informatique, the French national cybersecurity agency baseline of 42 measures across 10 themes for strengthening the security of an information system.
Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.
Framework Domains (10)
ANSSI Hygiene I: Raise Awareness and Train (measures 1 to 3)
| Code | Title |
|---|---|
| ANSSI-HYG-01 | Train Operational Teams in Information System Security |
| ANSSI-HYG-02 | Raise User Awareness of Basic Security Practice |
| ANSSI-HYG-03 | Control the Risks of Outsourced Information System Management |
ANSSI Hygiene II: Know the Information System (measures 4 to 7)
| Code | Title |
|---|---|
| ANSSI-HYG-04 | Identify the Most Sensitive Information and Servers and Maintain a Network Diagram |
| ANSSI-HYG-05 | Maintain an Exhaustive Inventory of Privileged Accounts |
| ANSSI-HYG-06 | Organise Joiner, Leaver and Role Change Procedures |
| ANSSI-HYG-07 | Authorise Network Connection Only for Managed Equipment |
ANSSI Hygiene III: Authenticate and Control Access (measures 8 to 13)
| Code | Title |
|---|---|
| ANSSI-HYG-08 | Identify Each Person by Name and Separate User and Administrator Roles |
| ANSSI-HYG-09 | Assign the Correct Rights on Sensitive Resources |
| ANSSI-HYG-10 | Define and Verify Password Selection and Sizing Rules |
| ANSSI-HYG-11 | Protect Passwords Stored on Systems |
| ANSSI-HYG-12 | Change Default Authentication Elements on Equipment and Services |
| ANSSI-HYG-13 | Prefer Strong Authentication Where Possible |
ANSSI Hygiene IV: Secure Workstations (measures 14 to 18)
| Code | Title |
|---|---|
| ANSSI-HYG-14 | Apply a Minimum Security Level Across the Whole Estate |
| ANSSI-HYG-15 | Protect Against Threats Related to Removable Media |
| ANSSI-HYG-16 | Use a Centralised Management Tool to Standardise Security Policies |
| ANSSI-HYG-17 | Enable and Configure the Local Firewall on Workstations |
| ANSSI-HYG-18 | Encrypt Sensitive Data Transmitted Over the Internet |
ANSSI Hygiene IX: Supervise, Audit and Respond (measures 36 to 40)
| Code | Title |
|---|---|
| ANSSI-HYG-36 | Enable and Configure Logging on the Most Important Components |
| ANSSI-HYG-37 | Define and Apply a Backup Policy for Critical Components |
| ANSSI-HYG-38 | Carry Out Regular Security Checks and Audits and Apply the Corrective Actions |
| ANSSI-HYG-39 | Designate an Information System Security Officer and Make the Role Known |
| ANSSI-HYG-40 | Define a Security Incident Management Procedure |
ANSSI Hygiene V: Secure the Network (measures 19 to 26)
| Code | Title |
|---|---|
| ANSSI-HYG-19 | Segment the Network and Partition the Zones |
| ANSSI-HYG-20 | Secure Wi-Fi Access Networks and Separate Usage |
| ANSSI-HYG-21 | Use Secure Protocols Wherever They Exist |
| ANSSI-HYG-22 | Put in Place a Secure Internet Access Gateway |
| ANSSI-HYG-23 | Partition Internet Facing Services from the Rest of the Information System |
| ANSSI-HYG-24 | Protect the Corporate Mail Service |
| ANSSI-HYG-25 | Secure Dedicated Network Interconnections with Partners |
| ANSSI-HYG-26 | Control and Protect Access to Server Rooms and Technical Areas |
ANSSI Hygiene VI: Secure Administration (measures 27 to 29)
| Code | Title |
|---|---|
| ANSSI-HYG-27 | Prohibit Internet Access from Administration Workstations and Servers |
| ANSSI-HYG-28 | Use a Dedicated and Partitioned Network for Administration |
| ANSSI-HYG-29 | Limit Administration Rights on Workstations to Operational Need |
ANSSI Hygiene VII: Manage Mobile Working (measures 30 to 33)
| Code | Title |
|---|---|
| ANSSI-HYG-30 | Apply Physical Protection Measures to Mobile Devices |
| ANSSI-HYG-31 | Encrypt Sensitive Data, in Particular on Equipment That May Be Lost |
| ANSSI-HYG-32 | Secure the Network Connection of Devices Used for Mobile Working |
| ANSSI-HYG-33 | Adopt Security Policies Dedicated to Mobile Terminals |
ANSSI Hygiene VIII: Keep the Information System Up to Date (measures 34 and 35)
| Code | Title |
|---|---|
| ANSSI-HYG-34 | Define an Update Policy for Information System Components |
| ANSSI-HYG-35 | Anticipate the End of Maintenance of Software and Systems |
ANSSI Hygiene X: Going Further (measures 41 and 42)
| Code | Title |
|---|---|
| ANSSI-HYG-41 | Conduct a Formal Risk Analysis |
| ANSSI-HYG-42 | Prefer Products and Services Qualified by ANSSI |
Your Compliance Coverage
If you comply with ANSSI Guide d'hygiene informatique (42 mesures, v2.0), you already cover:
NIST SP 800-161 Rev 1
100%
42 controls mapped
Compare →NIST SP 800-53 Rev 5 MODERATE
100%
42 controls mapped
Compare →FedRAMP Moderate
100%
42 controls mapped
Compare →+ 31 more: NIST SP 800-53 Revision 5.1 HIGH (100%), FedRAMP High (100%)
See all 34 mapped frameworks ↓Maps to 34 other frameworks
Frequently Asked Questions
What is ANSSI Guide d'hygiene informatique (42 mesures, v2.0)?
ANSSI Guide d'hygiene informatique (42 mesures, v2.0) is a compliance framework from France with 10 domains and 42 controls. ANSSI Guide d'hygiene informatique, the French national cybersecurity agency baseline of 42 measures across 10 themes for strengthening the security of an information system. It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.
How many controls does ANSSI Guide d'hygiene informatique (42 mesures, v2.0) have?
ANSSI Guide d'hygiene informatique (42 mesures, v2.0) has 42 controls organised across 10 domains. The largest domains are ANSSI Hygiene V: Secure the Network (measures 19 to 26) (8 controls), ANSSI Hygiene III: Authenticate and Control Access (measures 8 to 13) (6 controls), ANSSI Hygiene IV: Secure Workstations (measures 14 to 18) (5 controls). Each control defines specific requirements that organisations must implement to achieve compliance.
What frameworks does ANSSI Guide d'hygiene informatique (42 mesures, v2.0) map to?
ANSSI Guide d'hygiene informatique (42 mesures, v2.0) maps to 34 other compliance frameworks. The top mapping partners are NIST SP 800-161 Rev 1 (100% coverage), NIST SP 800-53 Rev 5 MODERATE (100% coverage), FedRAMP Moderate (100% coverage). Use our comparison tool to explore control-level mappings between frameworks.
How do I get started with ANSSI Guide d'hygiene informatique (42 mesures, v2.0) compliance?
Start your ANSSI Guide d'hygiene informatique (42 mesures, v2.0) compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about ANSSI Guide d'hygiene informatique (42 mesures, v2.0) requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 42 controls and track your progress.
Start Your Compliance Journey
Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 686 frameworks.
Get Started Free →Free forever — no credit card required