| Patch applications | Online services scanned daily. Office software and browsers weekly. Critical online-service patches within 48 hours, everything else within two weeks. | Adds a fortnightly scan of every other application. Those patch within one month. | Critical office-suite and browser patches also move to 48 hours. Every unsupported application is removed. |
|---|
| Patch operating systems | Internet-facing systems scanned daily and workstations fortnightly. Critical internet-facing patches within 48 hours. Workstations within one month. | No new requirements. This strategy is identical at Maturity Level One and Two, which catches most teams out. | Adds fortnightly driver and firmware scanning. Critical workstation patches drop to 48 hours. Only the latest or previous release runs. |
|---|
| Multi-factor authentication | MFA on your own and third-party online services holding sensitive data. Also for customers of services holding sensitive customer data. | Extends MFA to privileged and unprivileged users of internal systems. It must be phishing-resistant. MFA events are centrally logged and analysed. | Adds MFA on access to data repositories. Phishing resistance extends across the remaining authentication paths. |
|---|
| Restrict administrative privileges | Privileged requests validated when first raised. Dedicated privileged accounts blocked from internet and email. Separate privileged and unprivileged environments. | Adds revalidation every 12 months and disablement after 45 days idle. Administration through jump servers. Managed break glass and service account credentials. Privileged events centrally logged. | Adds just-in-time administration and platform-enforced credential protection against theft. |
|---|
| Application control | Enforced on workstations, across user profiles and temporary folders. Restricts executables, libraries and scripts to an approved set. | Adds internet-facing servers and every remaining file location. Microsoft recommended blocklist deployed. Rulesets validated yearly. Allowed and blocked events logged. | Adds every server and control over vulnerable drivers using the Microsoft driver blocklist. |
|---|
| Restrict Microsoft Office macros | Macros disabled unless there is a demonstrated business need. Internet-sourced macros blocked. Antivirus scanning on. Settings locked against users. | Adds blocking macros from making Win32 API calls. That is the control that stops most macro payloads doing anything useful. | Adds running macros only from trusted locations or with a trusted signature. Macro execution is logged. |
|---|
| User application hardening | Internet Explorer 11 removed. Browsers do not process Java or web advertisements from the internet. Browser settings locked against users. | Adds ASD and vendor hardening for browsers, office suites and PDF software. Office blocked from child processes and code injection. PowerShell and command line logging required. | Adds removing .NET Framework 3.5 and PowerShell constrained language mode. |
|---|
| Regular backups | Backups retained to business criticality and synchronised to a common point in time. Restoration tested in disaster recovery exercises. | Adds blocking privileged accounts other than backup administrators from reaching, changing or deleting other accounts backups. | Adds blocking every account other than backup administrators from reading any backup at all. |
|---|