Cyber Essentials Compliance Policy

FromiSolutions- Cyber Security  
Approval Date01/10/2025  
Approving authority IGISG (Information Governance and Information Security Group)
Review  Every two years  
Version1.1  

1. Policy intent

1.1 The Cyber Essentials Compliance Policy is designed to: 

1.1.1 Provide clarity on the University’s baseline technical controls to defend against common cyber threats. 

1.1.2 Ensure that systems and devices are securely configured, access is controlled, and patching and malware protection are consistently applied. 

1.1.3 Ensure consistency in meeting the requirements of the IASME-assured Cyber Essentials Standard across all in-scope University systems and services.  

1.2 This policy describes the steps which must be taken for individuals within the University to be able to state that they act in compliance with the NCSC Cyber Essentials scheme, as defined in the following documents 

1.2.1 Cyber Essentials: Requirements for IT Infrastructure v3.2 (April 2025)

1.2.2 Cyber Essentials Question Set (Willow)

2. Legislation

2.1 The University of Southampton has a responsibility to abide by and adhere to all current UK and EU legislation as well as a variety of other regulatory and contractual requirements.

2.2 Information in regards to the University’s data protection strategy can be found within the University’s Information Governance and Data Protection site

2.3 A non-exhaustive summary of the legislation and regulatory obligations that contribute to the form and content of this policy is provided in Relevant Legislation (ISMS).  

3. Definitions and Abbreviations  

3.1 It is intended that this policy be used in conjunction with other policies published as part of the University’s Information Security Management System, in particular the Information Security Policy, which sets out the formal scope for all policies and other documents within the Information Security Management System (ISMS)

3.2 A non-exhaustive list of definitions that contribute to the contents of this policy is provided in the Glossary of Abbreviations and Definitions (ISMS).  

3.3 For further Cyber Essentials specific information, including information about the Secure Research VPN, and the technical controls and policy settings which are managed by iSolutions on managed devices, please refer to our Cyber Essentials Page.  

4. Scope

4.1 Unlike other policies within the ISMS, this policy has a narrow scope of applicability. You must comply with this policy if: 

4.1.1 You are required as part of a research or other contract to act in compliance with the requirements of the NCSC Cyber Essentials scheme. 

4.1.2 You are working in an environment where compliance with the requirements of the NCSC Cyber Essentials scheme is required as part of a larger compliance attestation. 

4.2 This policy applies to end-user computing devices, mobile devices, servers, and cloud services which are used to store or process data during the activities outlined in 4.1. 

4.3 For the avoidance of doubt, this always includes the Microsoft 365 platform (OneDrive, SharePoint, Teams, etc), your email inbox and calendar, and all devices you may use to connect to these services.

4.4 This policy does not form part of any employee's contract of employment and the University may amend it at any time. 

4.5 For the purposes of this policy, the individuals listed in Section 4.1 under the defined scope shall hereafter be referred to collectively as ‘users’. 

5. University Policy Principles 

5.1 Users shall only use University provided computing devices which are managed and checked for Cyber Essentials compliance by the University’s IT Team. These include, but are not limited to: 

5.1.1 University Managed Windows 11 laptops and desktops (Latest Version) 

5.1.2 University Managed Microsoft Surface Pro (Intel chipsets only) 

5.1.3 University Managed Samsung Android Devices (Smartphones and Tablets)

5.1.4 University Managed Apple iOS Devices (iPad and iPhone) 

5.1.5 University Managed Microsoft Windows Server and RedHat Enterprise Linux servers (including virtual servers) 

Note: Please note that currently, MacOS devices are not included within our compliance scope. Please refer to the Cyber Security SharePoint site for details of the technical controls and policy settings which are managed by the University’s IT Team on these devices.  

5.2 The following activities are explicitly prohibited: 

5.2.1 Use of personally owned computing devices (aka ‘BYOD’), including laptops, desktops, servers, smartphones, and tablets. 

5.2.2 Use of other University purchased devices which are not managed or checked for compliance the University’s IT Team. 

5.2.3 Use of Dropbox, Google Drive, Box.com, or any other form of cloud storage service. 

5.3 The following activities are explicitly permitted: 

5.3.1 Use of the University Managed Research Filestore to store related data. 

5.3.2 Use of the University Managed ‘J-drive’ to store related data. 

5.4 All devices described in 5.2 should continue to be managed and checked for compliance by the University’s IT Team while they are still in use to store or process data during your activities outlined in scope. 

5.5 To access any network services used to store or process data during your activities outlined in the scope, you must connect to the Secure VPN first. This connection will also facilitate additional compliance checking of your device. 

Note: Please refer to the Secure Research, SECDR or NETSCC VPN’s guidance, found on the Cyber Security SharePoint site for more details.  

6. Cyber Essentials Technical Controls Principles  

6.1 Firewalls  

6.1.1 All Cyber Essentials managed devices shall be protected with a correctly configured firewall (or network device with firewall functionality). 

6.1.2 Default administrative passwords on all firewalls shall be changed to strong, unique passwords or have remote administrative access disabled entirely. 

6.1.3 Access to firewall admin interfaces from the internet should be blocked unless there is a documented business need, and access is secured with either multifactor authentication or a restricted IP allow list and strong password controls. 

6.1.4 All inbound firewall rules must be approved and documented by an authorised person, with the business need included in the documentation. 

6.1.5 Unnecessary firewall rules must be removed or disabled when no longer needed. 

6.1.6 Software firewalls shall be enabled on all devices in the Cyber Essentials environment, especially when connecting to untrusted networks like public Wi-Fi. 

6.2 Secure Configuration 

6.2.1 The University shall manage Cyber Essentials devices by removing or disabling unnecessary user accounts (such as guest or unused admin accounts), changing default or easily guessable passwords, and removing unneeded software including applications, system utilities, and network services. Auto-run features that allow file execution without user approval are disabled, users must authenticate before accessing University data or services, and device locking controls are in place to prevent unauthorised access. 

6.2.2 All devices requiring physical user access must use a credential such as a password, PIN, or biometric login. These credentials must be protected from bruteforce attacks through rate limiting or lockouts after 10 failed attempts. If used only to unlock a device, passwords or PINs must be at least 6 characters long; if also used for authentication, full password requirements apply. 

6.2.3 University-managed devices shall be configured with automatic screen locking after no more than 15 minutes of inactivity.  

6.2.4 Staff should set shorter automatic locking timeouts (5 minutes or less) for devices used in public or high-traffic areas.

6.2.5 Portable devices containing sensitive information should be encrypted according to University standards. 

6.3 Security Update Management 

6.3.1 All software on Cyber Essentials managed devices should be licensed, supported, and removed when no longer supported. 

6.3.2 Automatic updates should be enabled where possible, and all software shall be updated within 14 days when critical or high-risk vulnerabilities are identified. 

6.3.3 This includes updates for vulnerabilities classified by the vendor as critical or high risk, those with a CVSS v3 score of 7 or above, or those with no stated level of impact or risk. 

6.3.4 The University IT team shall be responsible for ensuring all managed devices receive necessary updates within the required timeframes. 

6.4 User Access Control

6.4.1 Cyber Essentials users shall not be granted administrative privileges on their dayto-day user accounts. 

6.4.2 For Microsoft Windows devices this means you must not be a member of the Local Administrators group or otherwise be granted administrative privileges for your primary University login. 

6.4.3 The University shall have a process to create and approve user accounts and shall authenticate users with unique credentials before granting access to applications or devices. 

6.4.4 The University shall remove or disable user accounts when no longer required and shall implement multi-factor authentication (MFA) where available, with MFA being mandatory for cloud services. 

6.4.5 The University shall use separate accounts for administrative activities only and shall remove or disable special access privileges when no longer required. 

6.4.6 Passwords shall be protected against brute-force password guessing by implementing security controls such as MFA, rate limits (no more than 10 guesses in 5 minutes) and device lockouts (no more than 10 unsuccessful attempts). 

6.4.7 Users must maintain their account password and MFA methods in accordance with the University’s Access Control policy. 

6.4.8 The University shall support users in choosing unique passwords by educating them about password hygiene, avoiding common passwords, and providing guidance on secure password management and storage. 

6.4.9 MFA shall be used for administrative accounts and accounts accessible from the internet. 

6.4.10 MFA factors should be chosen for usability and accessibility. 

6.4.11 The University supports passwordless authentication methods where appropriate, including Biometric authentication, Security keys or tokens, One-time codes, Passkeys and Push notifications. 

6.5 Malware Protection

6.5.1 All Cyber Essential managed devices as per section 4 must have active malware protection mechanisms that are kept up to date. 

6.5.2 Anti-malware software (for Windows and Linux devices) shall be configured to: 

a. Be updated automatically when updates are available. (when device is connected to internet).  

b. Prevent malware from running.

c. Prevent the execution of malicious code.  

d. Prevent connections to malicious websites over the internet.  

6.5.3 The Cyber Essentials standard requires that cloud services storing “organisational data” are to be considered in-scope. The University interprets this to mean those cloud services being used to store or process data during the activities outlined section 4. 

Note: The only sanctioned cloud platforms to be included within the scope of this policy are the Microsoft 365 platform including OneDrive, SharePoint, Teams, email and calendaring facilities.  

6.5.4 Users are expected to review and maintain appropriate access restrictions for data storage locations which are used to store or process data during the activities outlined in section 4.1. 

6.5.5 Users shall report violations of the Cyber Essentials policy through established security incident reporting channels. 

7. Compliance with this policy 

7.1.1 For employees, failure to comply with this and the other related policies in the ISMS may result in disciplinary action being taken against you under the relevant University procedures up to and including summary dismissal and/or in the withdrawal of permission to use the University’s facilities. If there is anything in this policy that you do not understand, please discuss it with your line manager. 

7.1.2 or non-employees, failure to comply with this and the other related policies in the ISMS may result in your network access being revoked until the non-compliance is rectified. 

7.1.3 The University reserves the right to audit compliance with this and the other related policies in the ISMS. 

7.1.4 Where evidence that a criminal offence may have been committed as a result of any misuse of the University’s information technology and communications systems, this may be referred to the police or the appropriate regulatory authority.

8. Roles and responsibilities 

Human Resources  HR is responsible for supporting the enforcement of the Cyber Essentials Policy through appropriate disciplinary processes where persistent non-compliance is identified. When notified of serious or recurring violations, HR will work with line managers and the Cyber Security team to address these issues through established performance management frameworks.  

Cyber Security and  

Information Governance  

Teams  

The Cyber Security and Information Governance teams are responsible for developing and maintaining the Cyber Essentials Policy. They conduct periodic compliance checks through physical inspections and technical monitoring. The team provides guidance materials, communicates policy requirements, and advises on implementing controls following risk assessments or security incidents.  
Line Manager  Line Managers are responsible for promoting a culture of security within their teams by encouraging adherence to security practices aligned with Cyber Essentials. They must ensure that their team members understand and comply with the policy requirements, and address instances of noncompliance promptly. Line Managers should escalate any persistent non-compliance or resource limitations.   

Users  

(as per scope in section 4)  

All Cyber Essentials users (as per scope in section 4) are responsible for following the requirements of this policy, including proper use of University managed devices, proper security practices, and reporting any security weaknesses that prevent compliance with this policy.   
University IT Team  The University’s IT Team is responsible for ensuring that all Cyber Essentials managed devices in the University meet the technical requirements of the policy, including firewall configuration, secure configuration, security updates, access control, and malware protection. They are also responsible for monitoring compliance and reporting on status to the Cyber Security team.  

9. Governance, Review, Oversight and Improvement 

9.1 The University assigns responsibility for overseeing the Cyber Essentials Policy to the Information Security and Information Governance Group (ISIG), with input from iSolutions, Facilities, and Cyber Security stakeholders.

9.2 This policy shall be reviewed at least every two years to ensure it remains aligned with the latest version of Cyber Essentials requirements, ISO/IEC 27001 requirements, and reflects evolving working practices. 

9.3 The Cyber Security team monitors policy compliance through regular audits, vulnerability assessments, and security testing to identify areas for improvement.

9.4 Feedback from staff and students may be collected to inform future revisions and improve usability and adoption of the policy.