Cyber Essentials 101: Scope of Assessment January 28, 2025 – Posted in: Cyber Security – Tags: Cyber Essentials, Cyber Essentials 101, Cyber Security, CyberEssentials, cybersecurity, cybersecurity 101
This is the second article in our Cyber Essentials 101 series, if you haven’t yet read the first part covering why you should consider Cyber Essentials and how to answer the initial questions about your organisation you can find it here.
Scope of Assessment
This is where you outline what parts of your business you want your Cyber Essentials certification to cover. The scope should be either the whole organisation or an organisational sub-set – for example, the UK operation of a multinational company. You’ll need to answer questions regarding the computers, laptops, servers, mobile phones, tablets and firewalls/routers that can access the internet and are used to access company data or services.
All locations that are owned or operated by the organisation or sub-set that you define here should be considered in-scope whether they’re based in the UK or internationally. A scope that does not include end user devices is not acceptable. Further guidance can be found here:
- https://iasme.co.uk/articles/scope/
- https://www.ncsc.gov.uk/files/Cyber-Essentials-Requirements-for-Infrastructure-v3-1-January-2023.pdf
The first half of this section is best filled in by your admin team, with support from management.
A2.1 – Does the scope of this assessment cover your whole organisation?
Why are they asking you this?
This is where you establish what parts of your business you want your certificate to cover.
What’s the detail?
You should note that you’ll only be eligible for the free cyber insurance offered by IASME if your assessment covers your whole company, if you answer no to this question you will not be invited to apply for insurance.
Example answer:
Yes or no.
A2.2 – If it is not the whole organisation, then what scope description would you like to appear on your certificate and website?
Why are they asking you this?
To clarify establish what parts of your business you want your certificate to cover.
What’s the detail?
You only need to answer this one if you answered no to A2.1.
Your description of the scope should provide details of any areas of your business that have internet access that you don’t want included in the assessment. You’ll need to have a clear excluding statement within your scope description.
Example answer:
Whole organisation excluding development network.
or
The Norfolk office of the company.
A2.3 – Please describe the geographical locations of your business which are in the scope of this assessment.
Why are they asking you this?
Your geographic location is an important part of your security posture – the obvious one is overseas locations, but having multiple locations inside the UK has implications for how these locations share data. Here you should outline the address of each office/location for the company.
Example answer:
Manchester Retail Office, London Admin Office, Brighton Head Office
The rest of the questions in this section will be best completed by your IT team, with support of management. It is vital that whoever signs off the assessment has a solid understanding of the questions and answers in all sections so they can officially sign off on the accuracy.
A2.4 – Please list the quantities and operating systems for your laptops, desktops and virtual desktops within the scope of this assessment.
Why are they asking you this?
The devices your staff use are fundamental to your data protection and cyber security – these are the devices that will be accessing your data.
What’s the detail?
You’ll need to include all devices that access company data whether you provided them or not. If users access their emails on their personal home computer then that is included, this includes devices that access could services through browsers or online. You’ll need to list the include make and operating system versions for all devices.
Example answer:
- 11x HP PCs and Laptops, Windows 11 version 23H2.
- 2x HP PCs, Windows 10 22H2.
- 6x Dell Laptops, Windows 11 23H2.
- 3x Apple Macbooks, MacOS Sequoia.
A2.4.1 – Please list the quantity of thin clients within scope of this assessment. Please include make and operating systems.
Why are they asking you this?
Similarly, thin clients are the portal to your data. Identifying them and ensuring they are secure is important.
What’s the detail?
Thin clients are devices with a minimal operating system that are used only to connect to a terminal server or remote desktop services. If it is a normal laptop or desktop computer with a full OS and nothing on the desktop but a link to a remote desktop server it counts as a full device and will need to be included in the section A2.4. You’ll only need to include devices that have no individual login and simply display a link to the remote desktop service when turned on in this section.
Example answer:
- 10x HP PCs, Windows 11 Kiosk version 23H2
A2.5 – Please list the quantity of servers, virtual servers and virtual server hosts (hypervisor).
Why are they asking you this?
These devices are the storage repository for all your data, and are likely where business critical software and all access control live.
What’s the detail?
You will need to list all your servers and their operating systems and versions.
Example answer:
- 1x Host server, HP on MS Server 2019 using HyperV to host:
- 3x Virtual servers on MS Server 2019.
- 1x Virtual server on Redhat Enterprise Linux 8.2
A2.6 – Please list the quantities of tablets and mobile devices within the scope of this assessment.
Why are they asking you this?
Tablets and mobile devices are often forgotten parts of your hardware environment. Even if you didn’t supply them – any device that can access your company data, including email, needs to be considered part of the scope of the assessment.
What’s the detail?
This is often a difficult part of the assessment. Your answer must include the make and operating system versions for all devices. Any devices that are connecting to cloud services or on premises services including email must be included. This means that if your staff use personal mobile devices to check their email then those devices will be in scope. You will need to have a plan and take action to ensure all of those devices are kept up to date and are replaced when their hardware will no longer support the latest software. For many small businesses faced with either providing company mobiles that they can register and maintain, or demanding access to (and a standard of) personal devices that their staff may well find intrusive – the best option is to update company policy to forbid accessing company emails or data on mobile devices.
Example answer:
- 12x Android mobiles on version 12
- 6x iPhones on version 18.1
- 4x Microsoft Surfaces on Windows 11 version 23H2
A2.7 – Please provide a list of your networks that will be in the scope for this assessment.
Why are they asking you this?
These networks are the information highways of your business. Securing them is vital to protect your data.
What’s the detail?
This will be a question very much for your IT team, essentially you’ll need to list each network used in your organisation.
Example answer:
- Head office main LAN
- Head office guest LAN (WiFi only)
- Birmingham office main LAN
- Birmingham office guest LAN (WiFi only)
A2.7.1 – How many staff are home and Remote workers?
Why are they asking you this?
Remote working staff will need to access company data from systems and networks that you don’t control. This will present a risk, so you need to put in place mitigations to protect your data when it is being accessed from outside the office.
What’s the detail?
Anyone who works from outside the office at any point needs to be included here.
Example answer:
- 5x flexible workers who work from home some of the time.
- 2x home workers.
- 4x on the road workers who work from other offices and public spaces.
A2.8 – Please provide a list of network equipment that will be in scope for this assessment.
Why are they asking you this?
To define what you are using so the assessor can review your later answers in context.
What’s the detail?
You need to include all equipment that controls the flow of data, this will be all routers and firewalls. You don’t need to include switches or wireless access points that do not contain a firewall or do not route internet traffic. If you don’t have an office and do not use network equipment, instead you are relying on software firewalls you will need to describe it in the notes field.
Example answer:
- 1x Draytek 2862 Firewall & Router – version 3.9.9.2_BT
A2.9 – Please list all of your cloud services that are in use by your organisation and provided by a third party.
Why are they asking you this?
Cloud services are essentially services that are hosted in the servers of the company you are buying the service from rather than locally. How these businesses secure your data and how your staff access the services is an important element of your overall data security.
For more on cloud services our white paper Cloud Solutions for Small to Medium Businesses covers the 101 on the cloud.
What’s the detail?
You’ll need to include all cloud services, any service that you access through a browser or over the internet and processes or stores company files or data cannot be excluded from the scope of the assessment.
Example answer:
- Microsoft 365
- SharePoint & OneDrive
- Zero or Quickbooks
- Citrix remote desktop services
A2.10 – Please provide the name and role of the person who is responsible for managing your IT systems in the scope of this assessment.
Why are they asking you this?
In any business it is important that one person takes responsibility for overall decision making for your IT. They may not be a specifically technical person, but they will need to be responsible for reviewing recommendations from experts and tying these in with business requirements – and have the final say on what you do.
What’s the detail?
This is the person in your organisation who influences and makes the majority of decisions about the computers, laptops, servers, tablets, mobile phones and network equipment. This person must be a member of your organisation and cannot be a person employed by your outsourced IT provider. For most small to medium businesses this will be the Owner or MD.
Example answer:
Valerie Smith, Managing Director
Next Week…
Next week we will cover the Insurance section of Cyber Essentials. This is an optional section which allows you to opt into the free Cyber Insurance that the IASME offers.
If you’d like help reviewing what you’d need to do to be compliant, filling in the paperwork, or working with your staff to smooth any required changes, we can help. Give us a call on 01245 265 100 or email .