A1 — Organisation
What are the reasons you have applied for the certification which you described as ‘other’?
A2 — Scope
If you are not certifying your whole organisation, what scope description would you like to appear on your certificate and website?
A4 — Firewalls
If you answered ‘no’ to question A4.1.1, is this because software firewalls are not installed by default as part of the operating system you are using? Please list the operating systems.
Please complete the relevant option below if applicable:
Option D: A passwordless system is being used as an alternative to username and password — please describe:
Option E: None of the above — please describe:
Have you reviewed your firewall rules in the last 12 months? Please describe your review process.
Please describe how you approve and document your allowed inbound connections.
A5 — Secure Configuration
Please complete the relevant option below if applicable:
Option D: Passwordless — please describe:
Option E: None of the above — please describe:
Which method do you use to unlock the devices?
A6 — Security Update Management
If yes to A6.3, please list the unsupported or unlicensed software or cloud services.
Where auto updates are not being used, how do you ensure all high-risk or critical security updates and vulnerability fixes are applied within 14 days of release?
Where you have a business need to use unsupported software, have you moved the devices and software out of scope of this assessment? Please explain how you achieve this.