Skip to content
Reference

Compliance and security glossary

Understand the terms used in certification, cybersecurity and risk management. Search by name or abbreviation, then open a definition for further guidance.

1

14-Day Patching Rule

Apply qualifying vendor-approved security fixes within 14 days of vendor release. A high or critical vendor rating, CVSS v3 base score of at least 7, or a vulnerability with no vendor severity description can trigger the deadline. For example, a Tuesday update with an unclassified fix is due within 14 days even if a monthly window falls later; assess the whole bundle, release date and supported fix.

Read the full definition →

6

6-Hour Certification Guarantee

Fig Group’s service promise applies to a complete, compliant Cyber Essentials Basic self-assessment received before midday on a UK business day, subject to its published certification terms. For example, buying on Monday while still preparing evidence does not start the six-working-hour review clock; a qualifying submission does. This is a supplier guarantee, not an IASME scheme entitlement.

Read the full definition →

A

Account Lockout

Account lockout or throttling limits repeated failed attempts against an account. For an internet-facing password sign-in, five wrong attempts might trigger a delay or temporary block under the chosen control; other effective rate limiting can also protect it. Device-unlock rules and online account protection have different contexts. MFA adds protection but does not make weak password-guessing controls acceptable.

Read the full definition →

Administrative Account

An account able to change configuration, install software or manage users. Cyber Essentials requires separate privileged and everyday use, and MFA wherever available, including cloud authentication. For example, an administrator reads email with a daily account and uses a separate privileged account for tenant changes. Fig Group recommends phishing-resistant MFA for that account as additional recommended protection, not a universal scheme-specific factor.

Read the full definition →

Advanced Protection Program (APP)

Google’s Advanced Protection Program offers stronger account protection for higher-risk users, including passkeys or security keys and recovery controls. Fig Group recommends considering it for Google super administrators where appropriate. Cyber Essentials requires effective authentication under its own rules; subscribing to this Google programme is not a certification prerequisite.

Read the full definition →

Assessor

An individual trained and authorised for the relevant IASME scheme and level who reviews an applicant’s evidence. A Certification Body holds the organisational licence and issues certification; the assessor performs the review. Fig Group’s supported certification services use human assessor review, with software assisting evidence triage rather than deciding an outcome.

Read the full definition →

Asset Register

A documented inventory of every device, operating system, application, and cloud service in Cyber Essentials scope. The register underpins patch management, malware protection coverage, and evidence during assessor review.

Read the full definition →

Audit Trail

A traceable record of relevant events, such as “2026-09-29 09:00, admin@example.com changed the MFA policy”. It helps an organisation investigate who did what and when. Choose retention, completeness and tamper evidence to meet the applicable risk and obligations; one universal retention period is not implied. An audit trail is a record, distinct from the remote review performed during certification.

Read the full definition →

Auto-run

Automatic execution of software or media content when a device or file is opened or attached, including downloaded content and removable media where the platform supports it. Secure configuration should prevent untrusted content running without an intentional user action. Disabling USB AutoPlay alone is not the whole control, and blocking autorun does not forbid a user from deliberately opening an authorised application.

Read the full definition →

B

BitLocker

A Windows disk-encryption feature used to protect stored data. Check the supported edition, actual protection state and recovery-key arrangements. BitLocker can support broader security and contractual obligations, but Cyber Essentials does not universally mandate it or Intune. Disk encryption is separate from demonstrating the five certification controls.

Read the full definition →

Boundary Firewall

The firewall separating your internal network (or corporate VPN gateway) from the public internet. Under Cyber Essentials v3.3, the boundary firewall must have a non-default admin password, current firmware, and deny inbound traffic by default.

Read the full definition →

Break-Glass Account

A protected emergency administrative identity used when normal privileged access fails. This is a resilience pattern, not a universally required Cyber Essentials account type. Design independent authentication, monitoring and tested recovery; an exception from one Conditional Access policy must not become a blanket bypass of mandatory cloud MFA.

Read the full definition →

BYOD

Bring Your Own Device: personal devices used for work. Devices accessing organisational data or services are generally in Cyber Essentials scope, including endpoints accessing virtual desktops. The scheme has a specific exception for devices used only for native voice, native text or MFA applications. Ownership or the presence of MDM alone does not decide scope.

Read the full definition →

C

Certification Body

An organisation licensed by IASME to assess and certify applicants for the specific schemes and levels in its authorisation. Permission to deliver Cyber Essentials does not by itself establish Cyber Essentials Plus or DCC authorisation. Fig Group delivers certification through Fig Compliance Ltd; check each separate scheme licence on our licence evidence page.

Read the full definition →

CISA KEV

The US CISA Known Exploited Vulnerabilities catalogue records vulnerabilities with evidence of exploitation. Each entry carries its own due date for covered US federal agencies; other organisations can use KEV to prioritise risk. Cyber Essentials instead measures its qualifying 14-day update deadline from vendor release. Check the applicable obligation and fix rather than applying one universal KEV clock.

Read the full definition →

CMMC

The US defence Cybersecurity Maturity Model Certification programme, distinct from UK DCC and Cyber Essentials. CMMC 2.0 defines Levels 1, 2 and 3, replacing the legacy five-level model. The required assessment, current implementation phase and contract clause determine a supplier's obligations; verify the live official programme guidance rather than assuming every defence contract has the same requirement.

Read the full definition →

Compliance Automation

Technology can collect supported system evidence, remind owners, test selected configurations and flag changes. For example, a new device inventory export can refresh a patch-status record, which a control owner reviews before an assessment. People still decide scope, exceptions and certification outcomes; automation is not an autonomous compliance guarantee.

Read the full definition →

Conditional Access

An identity-provider policy that uses signals such as user, device and location to decide whether to allow access and require MFA. For example, a cloud administrator may need a trusted device and MFA before accessing a management portal. Review effective policies and session handling so location or risk exclusions do not bypass mandatory cloud MFA. Conditional Access is not a product universally required by the scheme, and a new MFA prompt on every request is not mandatory.

Read the full definition →

Control Framework

A structured set of security controls that an organisation implements to manage risk and meet regulatory requirements. Common control frameworks include ISO 27001 Annex A, NIST CSF, CIS Controls, and the Cyber Essentials five-category model.

Read the full definition →

CRP

An abbreviation for Cyber Risk Profile, the buyer-assigned level in the MOD Cyber Security Model. Current CSMv4 profiles are numbered 0 to 3. Obtain the assigned profile and Risk Assessment Reference from your customer, and use the full Cyber Risk Profile explanation when planning certification. Do not convert a legacy verbal risk band into a current level yourself.

Read the full definition →

CS&R

The UK Cyber Security and Resilience (Network and Information Systems) Bill proposes reforms to the NIS Regulations, including initial incident notification within 24 hours and a fuller report within 72 hours for relevant regulated entities and incidents. As reviewed on 27 September 2026, it remains a Bill in Parliament; proposals are not current enacted obligations. Confirm the final legislation, commencement and organisation-specific scope. Fig Group’s incident workflow can support preparation without establishing legal compliance.

Read the full definition →

CVE

A Common Vulnerabilities and Exposures identifier names a publicly recorded vulnerability; it is not itself a severity score or proof of active exploitation. An illustrative record such as CVE-YYYY-NNNN might have a CVSS score and separately appear in an exploited-vulnerability catalogue. Check the affected product, vendor fix and full Cyber Essentials update rule rather than assuming every CVE has the same deadline.

Read the full definition →

CVSS

The Common Vulnerability Scoring System describes technical severity. Scores can differ by version or assessor and do not by themselves show exploitation likelihood. CVSS answers “how severe?”, EPSS estimates exploitation probability, and CISA KEV records known exploitation. Cyber Essentials also considers vendor severity and unspecified-severity fixes; read the complete update rule.

Read the full definition →

Cyber Essentials

Cyber Essentials is a UK government-backed certification scheme, governed by the NCSC and operationally delivered by IASME, that validates an organisation has implemented five core cybersecurity controls: firewalls, secure configuration, user access control, malware protection, and security update management.

Read the full definition →

Cyber Essentials Plus

Cyber Essentials Plus independently tests the same five controls after a valid Cyber Essentials assessment for the matching scope. Testing includes specified internal and external checks, device configuration and authentication; it is more than an external scan. Fig Group Plus prices are £1,499.99–£4,499.99 + VAT by size, with the package and prerequisites on the Plus page.

Read the full definition →

Cyber Essentials v3.3

The April 2026 edition of the NCSC Requirements for IT Infrastructure, used with the Danzell question set for assessments opened from 27 April 2026. It clarifies cloud scope and passwordless authentication. MFA is required where available and for cloud authentication; it is not a universal fresh-prompt-on-every-sign-in rule. Check the version assigned to an existing assessment.

Read the full definition →

Cyber Risk Profile

The level assigned through the MOD Cyber Security Model risk assessment for a contract or activity. CSMv4 uses numeric Levels 0, 1, 2 and 3. These are not direct equivalents of the legacy Very Low, Low, Moderate and High labels. The buyer provides the required profile and Risk Assessment Reference; certification and contract-specific assurance remain distinct.

Read the full definition →

D

Data Sovereignty

Data sovereignty concerns the laws and authorities that can affect data; data residency concerns physical storage location. A UK region alone does not determine every legal obligation or international transfer: access, backups, telemetry and subprocessors also matter. Confirm the actual service and contractual data flow before asserting UK-only processing; UK GDPR does not universally require UK hosting.

Read the full definition →

DCC

Defence Cyber Certification provides independent assurance against the MOD Cyber Security Model. Its four levels align with the current numeric profiles, rather than replacing the contract process. A certificate does not remove the requirement to complete the contract-specific Supplier Assurance Questionnaire. Fig Group offers assessment at Levels 0 and 1; confirm the required level with your buyer.

Read the full definition →

DCC Level 0

The entry level of Defence Cyber Certification, corresponding to current numeric Level 0 requirements. It assesses the applicable controls and requires a separate, current Cyber Essentials certificate. Confirm organisational scope and the current scheme criteria before applying; do not infer this level from the old Very Low label. Fig Group offers Level 0 assessment.

Read the full definition →

DCC Level 1

Defence Cyber Certification against current numeric Level 1 requirements, with broader assurance than Level 0. Confirm the applicable Cyber Essentials prerequisite, scope and evidence with the certification body. It is not simply a renaming of the legacy Low risk band. Fig Group offers Level 1 assessment; contract-specific SAQ responsibilities continue.

Read the full definition →

DCC Level 2

A higher level of Defence Cyber Certification against current numeric Level 2 requirements. Use the official level criteria for prerequisites, assessment and organisational scope rather than treating it as a Cyber Essentials Plus audit or equating it to the legacy Moderate band. Fig Group does not deliver Level 2 assessment and refers this work to an appropriately authorised provider.

Read the full definition →

DCC Level 3

Defence Cyber Certification against the highest numeric level in the current four-level scheme. Confirm prerequisites and assessment scope through official guidance and the buyer requirement. It is not an automatic conversion from the legacy High band or a substitute for information-handling obligations. Fig Group does not deliver Level 3 assessment and refers this work to an appropriately authorised provider.

Read the full definition →

DCPP

The Defence Cyber Protection Partnership brought government and industry together on supply-chain cyber protection. It is distinct from the MOD Cyber Security Model, its controls standard and IASME-delivered Defence Cyber Certification. For a current contract, obtain the assigned numeric Cyber Risk Profile and Risk Assessment Reference from the buyer rather than treating an older partnership reference as a certification instruction.

Read the full definition →

Def Stan 05-138

The defence supplier cyber-security controls standard. CSMv4 uses Issue 4 and numeric Cyber Risk Profiles 0 to 3. Earlier Issue 3 and verbal risk bands are historical references, not a direct conversion table for current levels. Ask the buying authority to clarify the version, assigned profile and evidence required for the contract.

Read the full definition →

DEFCON 658

The MOD contractual condition supporting Cyber Security Model obligations, including supplier assurance and flow down to subcontractors. Follow the version and requirements in the actual contract. DCC provides independent evidence but does not currently replace the full contract-specific Supplier Assurance Questionnaire submitted through the Supplier Cyber Protection Service.

Read the full definition →

DORA

The Digital Operational Resilience Act - EU regulation applying to financial sector entities and their ICT providers. DORA requires ICT risk management, incident reporting, operational resilience testing, and oversight of third-party ICT providers. In effect from January 2025.

Read the full definition →

E

EDR (Endpoint Detection and Response)

Security software that continuously monitors endpoints for suspicious behaviour, investigates threats, and responds automatically. Examples: Microsoft Defender for Endpoint, CrowdStrike Falcon, SentinelOne. Exceeds Cyber Essentials minimum.

Read the full definition →

EPSS

Exploit Prediction Scoring System - a probabilistic score from 0 to 1 that estimates the likelihood a given CVE will be exploited in the wild in the next 30 days. Fig Group's vulnerability management workflow prioritises by EPSS and CISA KEV.

Read the full definition →

Evidence Collection

Gathering dated policies, logs, configuration exports and other records that demonstrate how a control operates. An integration may collect a device state, but a person still checks its scope, freshness and relevance before an assessor relies on it. Fig Group’s platform can help collect supported evidence; connector counts alone do not prove that every security control is verified.

Read the full definition →

F

FIDO2

Standards for public-key authentication, including WebAuthn and supported authenticators. FIDO2 authentication with user verification can satisfy Cyber Essentials MFA requirements. Phishing-resistant authentication is recommended hardening for privileged access; the scheme does not universally prescribe a particular FIDO2 device or product.

Read the full definition →

FileVault

The macOS feature that protects access to data using disk encryption. Hardware-backed storage encryption does not by itself establish that FileVault protection is enabled for the user configuration. Verify activation and recovery arrangements. Encryption is valuable security practice and may be required by other obligations, but it is not a universal requirement of the five Cyber Essentials controls.

Read the full definition →

Firewalls and Internet Gateways

One of the five Cyber Essentials controls. Manage boundary firewall and internet-gateway rules, allowing only necessary inbound traffic, with secure administration. Devices used away from an office boundary, such as roaming laptops, also need an appropriate software or host firewall. A compliant office appliance alone does not cover every in-scope endpoint.

Read the full definition →

G

GDPR

The EU General Data Protection Regulation and the separate UK GDPR govern personal-data processing within their respective territorial scopes. Applicability is not determined by a person's residence alone. Controllers assess breach-notification duties against the applicable risk threshold; under UK GDPR, report a qualifying breach without undue delay and, where feasible, within 72 hours of awareness. Processors notify their controller without undue delay.

Read the full definition →

Governance-First

An approach to security and compliance that starts with governance structures (policies, risk registers, accountability frameworks) before implementing technical controls. Ensures security investments align with business objectives and regulatory requirements.

Read the full definition →

GRC

Governance, Risk and Compliance connects decisions, risk records, controls, evidence, incidents and reviews so accountable people can see what is working. Platforms differ in scope and price; compare the same functions, organisation size, support and licence terms before choosing one. Fig Group provides GRC capabilities through its platform.

Read the full definition →

H

Home Worker Device

A device used for organisational data or services while working remotely. Employee-owned work devices are generally in scope, subject to the scheme exceptions. A worker- or ISP-supplied home router is outside assessment scope; an organisation-supplied router is included. Apply the required firewall controls to the actual remote-working arrangement.

Read the full definition →

I

IaaS

Infrastructure as a Service - virtualised compute, storage, and networking delivered on demand. Examples: AWS EC2, Azure VMs, Google Compute Engine. In Cyber Essentials scope if you run organisational data on it; the cloud provider handles the infrastructure, you handle OS, data, and identity.

Read the full definition →

IASME

The Information Assurance for Small and Medium Enterprises consortium is the NCSC-appointed delivery partner for Cyber Essentials. IASME licenses UK Certification Bodies, including Fig Compliance Ltd, to assess organisations. Each scheme licence is independently verifiable through Blockmark.

Read the full definition →

IASME Cyber Assurance

IASME Cyber Assurance is an independently assessed security standard with Level 1 and Level 2. It can help an organisation demonstrate broader security practices beyond Cyber Essentials, but it is not interchangeable with ISO 27001 certification: buyers must check their specified standard and assurance level. Jay Hopkins at Fig Group holds IASME Cyber Assurance assessor accreditation.

Read the full definition →

IL2

Impact Level 2, a historical information-impact designation. It is not a current DCC level and cannot by itself determine a modern classification or certification requirement. Read the current security requirements and buyer-assigned Cyber Risk Profile in the contract; ask the authority to clarify any retained legacy terminology.

Read the full definition →

IL3

Impact Level 3, a historical information-impact designation. It should not be presented as a direct equivalent of OFFICIAL-SENSITIVE or a particular DCC tier. Contract-specific handling requirements and the current buyer-assigned Cyber Risk Profile determine the required assurance. Obtain clarification where older labels remain in procurement documents.

Read the full definition →

IL4

Impact Level 4, a historical information-impact designation. It does not automatically translate to SECRET or a particular DCC tier. Establish the current classification, handling controls and numeric Cyber Risk Profile with the buyer. Fig Group delivers DCC Levels 0 and 1 and refers requirements outside that assessment scope to an appropriately authorised provider.

Read the full definition →

In Scope

Devices, users, networks, and services that access organisational data are "in scope" for Cyber Essentials. All five Cyber Essentials technical controls (firewall, secure configuration, user access control, malware protection, security update management) apply to in-scope assets.

Read the full definition →

Incident Response

The structured process of detecting, containing, eradicating, and recovering from security incidents. An effective IR programme includes pre-defined playbooks, clear roles and responsibilities, communication templates, and post-incident review.

Read the full definition →

Internet-Facing Device

Any device or service with an interface exposed to the public internet - web servers, VPN gateways, mail relays, public APIs. Cyber Essentials Plus external vulnerability scans focus on internet-facing devices.

Read the full definition →

Intune

Microsoft device and application management software. It can help enforce configuration, collect device information and manage access policies. Cyber Essentials does not prescribe Intune or another MDM vendor. A compliant-device policy does not automatically exclude a personal device or VDI endpoint from scope; agree the actual assessment boundary with the assessor.

Read the full definition →

ISO 27001

The international standard for information security management systems (ISMS). ISO 27001 provides a systematic framework for managing sensitive information through risk assessment, control implementation, and continuous improvement. Heavier than Cyber Essentials; Cyber Essentials is a practical first step towards ISO 27001.

Read the full definition →

ISO 27017 / ISO 27018

Cloud-security and public-cloud privacy standards that complement ISO 27001. They can support assurance beyond Cyber Essentials. Cloud services used for organisational data or services remain in Cyber Essentials scope; separate ISO assurance does not exclude production hosting. Document the provider/customer control responsibilities.

Read the full definition →

J

Jamf

Enterprise MDM for Apple (macOS, iOS) devices. Jamf Pro and Jamf Now enforce device policies, passcode complexity, FileVault, and app installation. Common BYOD and corporate-device management tool for UK organisations certifying under Cyber Essentials v3.3.

Read the full definition →

L

Least Privilege

The principle of granting users only the permissions they need to perform their job. Under Cyber Essentials v3.3, users must not have admin rights unless necessary, and admin rights must be documented and reviewed periodically.

Read the full definition →

Legacy Authentication

Older authentication mechanisms, commonly basic authentication, that do not support modern authentication controls. POP, IMAP and SMTP are protocols and can support OAuth in suitable implementations; they are not inherently basic authentication. Identify and remove authentication paths that bypass required MFA instead of relying on a protocol name alone.

Read the full definition →

M

Malware Protection

A Cyber Essentials control preventing malicious or untrusted software from running. Version 3.3 provides an anti-malware option for Windows and macOS and an application allow-listing option for all platforms. Verify the chosen mechanism is active, maintained and configured to meet its requirements. EDR, a product name or a licence alone does not prove compliance.

Read the full definition →

MAV (Minimum Acceptable Version)

Under Cyber Essentials v3.3, the vendor-defined minimum version of software that is still supported and receiving security updates. Anything below MAV is "unsupported software" and fails Cyber Essentials unless removed or segregated.

Read the full definition →

MFA

Multi-factor authentication verifies identity using independent factors. Cyber Essentials v3.3 requires its use wherever available and for authentication to cloud services. Check actual enforcement across user, administrator and third-party access. Having registered an authenticator does not establish compliance, and reusing an authenticated session is not the same as bypassing MFA.

Read the full definition →

MSP

A Managed Service Provider - an organisation that manages IT infrastructure, security, and compliance services on behalf of its clients. MSPs typically serve multiple clients and require multi-tenant platforms. Fig Group's MSP programme supports white-label Cyber Essentials reselling.

Read the full definition →

MSSP

A Managed Security Service Provider specialises in delivering security-focused services including threat monitoring, incident response, vulnerability management, and compliance. MSSPs differ from general MSPs in their specific focus on security operations.

Read the full definition →

N

NCSC

The UK National Cyber Security Centre, part of GCHQ. The NCSC sets UK government cybersecurity policy, authors the Cyber Essentials scheme requirements, and maintains guidance on secure configuration, incident response, and supply chain security.

Read the full definition →

NIS2

The Network and Information Systems Directive 2 - EU directive strengthening cybersecurity for essential and important entities across 18 sectors. NIS2 mandates risk management, incident reporting, supply chain security, and management accountability.

Read the full definition →

Number Matching

An MFA push-notification feature that displays a number on the sign-in screen which the user must type into their authenticator app. Prevents MFA-fatigue attacks. Microsoft Authenticator requires number matching as default from February 2023.

Read the full definition →

O

Out of Scope

An asset or service outside the agreed certification boundary. Exclusions need a valid scheme basis, not simply a statement that no files are stored locally. Cloud services used for organisational data or services cannot be excluded. Agree any separately managed, network-segregated subset with the assessor; an access policy alone does not establish that boundary.

Read the full definition →

OWASP Top 10

OWASP’s 2025 list groups common web-application security risks, such as broken access control; it is not a catalogue of ten individual vulnerabilities or a fixed biennial release. It can inform application risk reviews and secure configuration, but it is not a direct Cyber Essentials certification requirement.

Read the full definition →

P

PaaS

Platform as a Service - managed runtime environments for deploying code without managing underlying OS. Examples: AWS Lambda, Azure App Service, Vercel. In Cyber Essentials scope when they process organisational data.

Read the full definition →

Passkey

A public-key credential used for passwordless authentication. Passkeys may be device-bound or synchronised; they are not limited to Apple or Google accounts. Cyber Essentials v3.3 recognises FIDO2 authenticators with user verification as MFA. Check the actual authenticator and authentication flow rather than assuming every passwordless method meets the requirement.

Read the full definition →

Penetration Testing

An authorised attempt to identify and demonstrate exploitable weaknesses in a defined system or application. Its scope and methods differ from the Cyber Essentials Plus assessment specification. A penetration test does not replace the required Plus tests or its Cyber Essentials prerequisite; agree the right assurance exercise for the buyer requirement.

Read the full definition →

Policy Management

The lifecycle management of organisational security and compliance policies: drafting, reviewing, approving, distributing, tracking acknowledgement, and periodically updating. Effective policy management ensures staff understand their responsibilities and the organisation can demonstrate governance to auditors.

Read the full definition →

PPN 014

PPN 014 is the Cabinet Office policy for proportionate cyber-security assurance in relevant public procurement. It applies to specified central-government and NHS bodies and includes equivalent-control provisions. Check the contract and transitional rules rather than assuming every public supplier must hold a certificate. The former label PPN 014/21 is not the correct policy reference.

Read the full definition →

R

Re-Submission

An updated Cyber Essentials self-assessment submitted after assessor feedback. Fig Group includes three free re-submissions with its Cyber Essentials certification offer. Check the applicable terms and readiness requirements. Other providers set their own charges; do not assume a universal market fee. Formal Cyber Essentials Plus retesting follows separate scheme and engagement rules.

Read the full definition →

Remote Audit

The Cyber Essentials Plus audit format: the assessor reviews device samples, runs external scans, and tests malware protection via video call and screen share rather than in person. Fig Group Cyber Essentials Plus audits are remote by default.

Read the full definition →

Risk Register

A documented record of identified risks, their likelihood, potential impact, current controls, and treatment plans. A risk register is a living document that should be reviewed regularly and updated as new risks emerge or existing risks change.

Read the full definition →

S

SaaS

Software as a Service - full applications delivered over the internet. Examples: Microsoft 365, Google Workspace, Salesforce. Always in Cyber Essentials scope if it holds organisational data; the provider handles infrastructure, you handle identity and access configuration.

Read the full definition →

Scope Boundary

The agreed limit of a Cyber Essentials assessment, identifying the organisational unit, networks, locations, devices and services covered. A separately managed subset needs the prescribed network segregation and assessor agreement. An identity provider or Conditional Access rule can control authentication without creating the network boundary needed for a subset.

Read the full definition →

Scope Statement

A written declaration by the applicant, on the self-assessment form, of what devices, users, networks, and services are in and out of Cyber Essentials scope. The scope statement is the first thing an assessor reads and the first thing a feedback round tends to query.

Read the full definition →

Screen Lock

A device control that requires a user to unlock it before continuing access. Choose appropriate locking behaviour and protect unlocking credentials. Cyber Essentials v3.3 requires at least six characters for a device-only password or PIN, with full authentication requirements where the credential also authenticates. It does not prescribe a universal fifteen-minute inactivity timer or an MDM product.

Read the full definition →

Secure Configuration

One of the five Cyber Essentials controls. Remove unnecessary software and accounts, change insecure default credentials, disable unneeded services and autorun, and apply settings suited to the device. A default account can remain where needed if secured appropriately; the scheme does not automatically ban every pre-installed account. Extra vendor hardening may exceed the certification minimum.

Read the full definition →

Security Defaults

Microsoft Entra baseline identity protections, including MFA registration and controls against legacy authentication. The feature is not an automatic Cyber Essentials pass for organisations below a particular size. Review effective cloud authentication, service identities and session behaviour against the scheme requirements; registration and tenant size alone do not prove enforcement.

Read the full definition →

Security Update Management

One of the five Cyber Essentials control categories. Keep in-scope software licensed and supported, and apply qualifying fixes within 14 days of vendor release: vendor-rated high or critical vulnerabilities, CVSS v3 base scores of at least 7, or vulnerabilities without vendor severity details. A bundled update containing a qualifying fix inherits that deadline.

Read the full definition →

Segregation of Duties

Distributing incompatible responsibilities so one person cannot complete every stage of a sensitive transaction alone. Cyber Essentials separately requires administrators to use privileged accounts for administration and everyday accounts for routine work. That account separation does not itself require a second employee or constitute a universal dual-approval rule.

Read the full definition →

Self-Assessment Questionnaire (SAQ)

The core Cyber Essentials instrument: a structured questionnaire covering the five technical control categories. Completed by the organisation, submitted to an IASME-licensed certification body for review. Most organisations complete the SAQ in 1-3 hours given adequate preparation.

Read the full definition →

Shared Responsibility

The cloud security division of labour: the cloud provider secures the infrastructure (physical, network, hypervisor), the customer secures their application, data, and identity configuration. Cyber Essentials v3.3 tests the customer side.

Read the full definition →

SIEM

Security Information and Event Management - systems that collect, aggregate, and analyse log data from across an organisation's IT environment to detect security threats and anomalies. SIEM platforms provide real-time alerting and forensic investigation capabilities.

Read the full definition →

Single Sign-On (SSO)

Centralised authentication where the user signs in once at the identity provider and accesses all integrated SaaS tools without separate passwords. Under Cyber Essentials v3.3, SSO is the cleanest way to enforce MFA across multiple SaaS applications.

Read the full definition →

SOC 2 Type II

An independent attestation report on a service organisation's controls over a defined period. Its scope is set by the described system and applicable trust services criteria. It can complement Cyber Essentials, but neither report has a universal product-only or corporate-only boundary. Check the actual report and certificate scopes before relying on either.

Read the full definition →

SPF / DKIM / DMARC

Email authentication mechanisms that help receiving systems assess sender authority, message signatures and domain alignment. They support protection against spoofing. Cyber Essentials Plus includes specified email-delivered malware testing; that is not the same as a universal SPF, DKIM and DMARC certification test. Label any additional email-security assessment separately.

Read the full definition →

Standard Account

A non-privileged user account used for day-to-day activities. Users with administrative duties must have both a standard account for email/web/line-of-business apps and a separate administrative account for privileged actions.

Read the full definition →

Sub-Set Exclusion

An agreed exclusion of a separately managed part of the organisation with the required network segregation. Document the business unit, location, technical boundary and reason with the assessor. A VDI session, MDM policy or user-group restriction does not automatically exclude an endpoint that accesses organisational data or services.

Read the full definition →

Supply Chain Risk

The potential for security incidents caused by vulnerabilities in an organisation's third-party vendors and service providers. NIS2 and DORA both include specific supply chain requirements; Fig Group's supplier risk monitoring capability automates third-party risk scoring.

Read the full definition →

Supported Software

Software currently receiving security updates from its vendor. Unsupported software (end-of-life OS, discontinued applications) must be removed or isolated from scope under Cyber Essentials v3.3.

Read the full definition →

T

Tamper Protection

A Microsoft Defender feature that helps prevent unauthorised changes to security settings. It is useful hardening; Cyber Essentials v3.3 does not name tamper protection as a separate universal requirement. Verify the active malware-protection mechanism against all applicable scheme requirements.

Read the full definition →

Third-Party Risk Management

The discipline of assessing and monitoring risks introduced by external vendors, suppliers, and service providers. TPRM programmes include vendor due diligence, risk scoring, contractual security requirements, and ongoing monitoring.

Read the full definition →

U

Unsupported Software

Software no longer receiving security updates from the vendor. Under Cyber Essentials v3.3, unsupported software in scope is an automatic fail; must be removed, replaced, or isolated before submission.

Read the full definition →

User Access Control

A Cyber Essentials control governing approved individual access, appropriate privileges, separate administrative use and removal of access no longer needed. Apply MFA wherever available and to cloud authentication. Review third-party accounts and actual authentication paths as well as staff accounts; do not equate a list of registered users with effective enforcement.

Read the full definition →

V

Vulnerability Scanning

The automated process of identifying known security weaknesses in systems, applications, and network infrastructure. Continuous scanning, as opposed to periodic scans, provides ongoing visibility into an organisation's attack surface.

Read the full definition →

W

Windows Hello for Business

Microsoft’s device-bound passwordless authentication using a biometric or PIN to unlock a credential. Verify the actual deployment and authentication path against Cyber Essentials requirements. Using Intune is neither a universal prerequisite nor proof that every cloud authentication path enforces the required MFA.

Read the full definition →

Z

Zero Trust

A security architecture that removes inherent trust based on network location and authorises each resource request against a policy. For example, access to a finance application can use user identity, device health and least-privilege role before allowing a transaction. It guides design and monitoring; Cyber Essentials does not require an organisation to buy a “Zero Trust” product or obtain a separate Zero Trust certificate.

Read the full definition →

Zero-Day

A software vulnerability unknown to the vendor at the time of exploitation, or for which no patch is yet available. Under Cyber Essentials v3.3, zero-day exposure is addressed through compensating controls (EDR, network segregation) while a patch is awaited.

Read the full definition →

Explore the tools behind the terms

See how Fig brings asset visibility, risk management, security testing and compliance workflows together.

Explore the platform