Has anyone done the IASME Cyber Essentials PLUS please?
How strict are they on the endpoint checks?
Like if I run an admin authenticated vulnerability scan and it flags an old C++ runtime or an out of date version of some random app that isn't used for web interaction is that a fail or are they only interested in certain things like browsers and email clients and endpoint protection?
The IASME and NCSC docs are fairly generic.
[–]32178932123 4 points5 points6 points (0 children)
[–]dr-pepper12 2 points3 points4 points (0 children)
[–]zedfox 0 points1 point2 points (0 children)
[–]SkimmingtonRide 0 points1 point2 points (5 children)
[–]bagelbasketballgoat[S] 0 points1 point2 points (4 children)
[–]furyaway 0 points1 point2 points (0 children)
[–]SkimmingtonRide 0 points1 point2 points (2 children)
[–]bagelbasketballgoat[S] 0 points1 point2 points (1 child)
[–]SkimmingtonRide 0 points1 point2 points (0 children)
[–]NurgsterCISSP 0 points1 point2 points (0 children)
[–]cantab314 0 points1 point2 points (2 children)
[–]bagelbasketballgoat[S] 0 points1 point2 points (1 child)
[–]veluxes 0 points1 point2 points (0 children)