Montpellier A4.10

If you answered yes in question A4.8, is the access to your firewall settings protected by either multi-factor authentication or by only allowing trusted IP addresses combined with managed authentication?

Section A4: Firewalls  ·  Cyber Essentials Montpellier

What this question is really asking

If you allow remote access to firewall configuration, document the specific business reason. Assessors will scrutinise this — convenience is not an acceptable justification. Managed service providers with a documented monitoring requirement are the most common valid use case.

What satisfies this requirement

Select the applicable option

Direct access to configuration via external interface must use MFA or trusted IP + managed auth.

Check how you answer this in the CE Explorer
Free tool — all 288 questions mapped across every CE version.
Open CE Explorer

What to prepare before your assessor visit

The broadly acceptable answer is 'our managed service provider requires it for contracted monitoring and management', with a documented service agreement. 'It's convenient for our IT team' is not a valid justification for an assessor. If remote access exists but was never formally documented or approved, do that documentation before the assessment — retrospective approval is better than no approval.

How this question sits across CE versions

Montpellier You are here
If you answered yes in question A4.8, is the access to your firewall settings protected by either multi-factor authentication or by only allowing trusted IP addresses combined with managed authentication?
Willow renumbered View →
If you answered yes in question A4.9, is the access to your firewall settings protected by either multi-factor authentication or by only allowing trusted IP addresses combined with managed authentication to access the settings?
Danzell View →
If you answered yes in question A4.9, is the access to your firewall settings protected by either multi-factor authentication or by only allowing trusted IP addresses combined with managed authentication?

Related policy templates

Getting certified means having documentation to back it up. These policy templates cover the controls this question tests.

Does your organisation meet this requirement?

Answer 30 plain-English questions and find out exactly where you stand across all 5 Cyber Essentials control areas — with a prioritised list of what to fix first.