Cyber Essentials 101: Device Locking March 21, 2025 – Posted in: Cyber Security, IT Support – Tags: Cyber Essentials 101, Cyber Security, cybersecurity, it support, ITSupport
This is the next article in our Cyber Essentials 101 series, if you haven’t yet read the first part covering why you should consider Cyber Essentials and how to answer the initial questions about your organisation you can find it here.
Questions in this section apply to: servers, desktop computers, laptops, thin clients, tablets, mobile phones, and cloud based software services.
A5.9 – When a device requires a user to be present, do you set a locking mechanism on your devices to access the software and services installed?
Why are they asking you this?
If someone can log into a secure station and walk away for 20 minutes or more and someone else can just pop onto their device and access the data – it is not secure.
What’s the detail?
Device locking mechanisms such as biometric, password or PIN, need to be enabled to prevent unauthorised access to devices accessing organisational data or services.
Example answer:
Yes or no.
A5.10 – Which method do you use to unlock the devices?
Why are they asking you this?
You only need to answer this one if you said yes to A5.9.
Following up to find out how you lock PCs.
Example answer:
PCs and laptops screens are set to lock after 5 minutes of inactivity. Users have to enter a complex password, minimum length 12 characters with complexity enforced by group policy. Following this, users then go through MFA using DUO. Phones are not used for business.
Next Time…
Next week we will cover the Security Update Management section of Cyber Essentials.
If you’d like help reviewing what you’d need to do to be compliant, filling in the paperwork, or working with your staff to smooth any required changes, we can help. Give us a call on 01245 265 100 or email .