A7
CE Montpellier
User Access Control
Limiting user access to what is necessary. Covers account provisioning, least privilege, administrator account controls, password-based authentication, and MFA for cloud services.
17 questions
A7.1
A7.2
A7.3
A7.4
A7.5
A7.6
A7.7
A7.8
A7.9
A7.10
A7.11
A7.12
A7.13
A7.14
A7.15
A7.16
A7.17
Are users only provided with user accounts after a process has been followed to approve their creation?
yesnodescribe
Are all user and administrative accounts accessed by entering a unique username and password?
yesno
How do you ensure you have deleted, or disabled, any accounts for staff who are no longer with your organisation?
text
Do you ensure that staff only have the privileges that they need to do their current job? How do you do this?
yesnodescribe
Do you have a formal process for giving someone access to systems at an 'administrator' level and can you describe this process?
yesnodescribe
How does your organisation make sure that separate accounts are used to carry out administrative tasks (such as installing software or making configuration changes)?
text
How does your organisation prevent administrator accounts from being used to carry out every day tasks like browsing the web or accessing email?
text
Do you formally track which users have administrator accounts in your organisation?
yesno
Do you review who should have administrative access on a regular basis?
yesno
Describe how you protect accounts from brute-force password guessing in your organisation.
text
Which technical controls are used to manage the quality of your passwords within your organisation?
text
Please explain how you encourage people to use unique and strong passwords.
text
Do you have a process for when you believe the passwords or accounts have been compromised?
yesno
Do all of your cloud services have multi-factor authentication (MFA) available as part of the service?
yesno
If you have answered 'No' to question A7.14, please provide a list of your cloud services that do not provide any option for MFA.
list
Has MFA been applied to all administrators of your cloud services?
yesno
Has MFA been applied to all users of your cloud services?
yesno
Does your organisation meet the User Access Control requirements?
Check your real-world posture across all 5 Cyber Essentials control areas in 3 minutes. Free, no account needed.