Willow A5.4

Do you run or host external services that provide access to data (that shouldn't be made public) to users across the internet?

Section A5: Secure Configuration  ·  Cyber Essentials Willow

What this question is really asking

Confirm whether you run or host any external services that provide access to non-public data — webmail, remote desktop, VPNs, online portals, and so on. If yes, these services must be protected with a compliant authentication method, which you specify in A5.5.

What satisfies this requirement

Yes or No

VPN servers, mail servers, internally hosted internet applications providing confidential data. CE Requirement: ensure users are authenticated before allowing access to organisational data.

Check how you answer this in the CE Explorer
Free tool — all 288 questions mapped across every CE version.
Open CE Explorer

What to prepare before your assessor visit

The list of external services organisations run is longer than they initially think. VPN portals, webmail, online HR systems, customer portals, cloud management consoles — all of these count. Answering no when several external services actually exist will invalidate your A5.5 response and create a significant finding. Take time to compile a thorough list before answering.

How this question sits across CE versions

Willow You are here
Do you run or host external services that provide access to data (that shouldn't be made public) to users across the internet?
Montpellier minor View →
Do you run external services that provide access to data (that shouldn't be made public) to users across the internet?
Danzell View →
Do you run or host external services that provide access to data (that shouldn't be made public) to users across the internet?

Does your organisation meet this requirement?

Answer 30 plain-English questions and find out exactly where you stand across all 5 Cyber Essentials control areas — with a prioritised list of what to fix first.