Critical controls

For each control we provide a page summarising the intent and success measures for decision makers. We have a separate page providing implementation advice for practitioners.

Password manager

Providing a password manager for your staff to store their passwords, or other secrets like alarm codes, is a great way

Securing internet-exposed services

Limiting and securing your internet-exposed services will help you prevent unauthorised access.

Secure defaults for macros

While macros have a valid business function, they are often used by attackers too. Using secure default configurations w

Network segmentation and separation

When paired together, segmentation and separation can add an additional level of access control and security to your net

Centralised logging

Storing and securing your logs in a central place makes log analysis and alerting easier.

Implement and test backups

After an incident, restoring your data from backups is often the best way to return to business as usual. Performing and

Principle of least privilege

The principle of least privilege means only having the access you need to do your job. Restricting the level access to o

Multi-factor authentication

You can authenticate with something you know, something you have, or something you are. Multi-factor authentication (MFA

Application allowlisting

Application allowlisting (otherwise known as whitelisting) is a method of strictly controlling what programs can be run

Keeping your software up-to-date is one of the most simple and effective steps to take, to ensure your environment stays