Montpellier A5.6

Describe the process in place for changing passwords on your external services when you believe they have been compromised.

Section A5: Secure Configuration  ·  Cyber Essentials Montpellier

What this question is really asking

Describe your process for changing passwords on external services when compromise is suspected. Assessors want a defined response — a documented procedure specifying the trigger, who is responsible, and the expected timeline for the password reset.

What satisfies this requirement

A written response is required

Must know how to change the password following a compromise event.

Check how you answer this in the CE Explorer
Free tool — all 288 questions mapped across every CE version.
Open CE Explorer

What to prepare before your assessor visit

The same standard applies as A4.4 — a documented procedure with a named owner and a clearly defined trigger. The trigger should include suspected compromise, not just confirmed compromise: a user reporting suspicious activity, an unusual login from an unknown IP, or a phishing message that may have captured credentials all warrant a response. Document the process before an incident occurs, not while responding to one.

How this question sits across CE versions

Montpellier You are here
Describe the process in place for changing passwords on your external services when you believe they have been compromised.
Willow View →
Describe the process in place for changing passwords on your external services when you believe they have been compromised.
Danzell View →
Describe the process in place for changing passwords on your external services when you believe they have been compromised.

Does your organisation meet this requirement?

Answer 30 plain-English questions and find out exactly where you stand across all 5 Cyber Essentials control areas — with a prioritised list of what to fix first.