ANSSI Hygiene Guide, RGS & SecNumCloud
French national cybersecurity guidelines from the Agence nationale de la securite des systemes d'information. Includes the 42-measure Hygiene Guide (cyber hygiene essentials), Referentiel General de Securite (government IS security framework), and SecNumCloud 3.2 (cloud security qualification for trusted cloud providers).
Clauses: 96
Avg Coverage: 87.1%
Publisher: ANSSI (Agence nationale de la securite des systemes d'information) Version: 2022 | Clause | Title | SP 800-53 Controls |
|---|---|---|
| Hygiene.1 | Sensitise and train | |
| Hygiene.2 | Define and apply a security policy | |
| Hygiene.3 | Carry out regular audits | |
| Hygiene.4 | Identify the person responsible for information systems security | |
| Hygiene.5 | Establish an inventory of IT assets | |
| Hygiene.6 | Establish access control procedures | |
| Hygiene.7 | Manage arrivals, departures and movements of staff | |
| Hygiene.8 | Classify information to know how to protect it | |
| Hygiene.9 | Control access to external services | |
| Hygiene.10 | Implement strong authentication | |
| Hygiene.11 | Distinguish user, admin, and service accounts | |
| Hygiene.12 | Protect passwords and secret keys | |
| Hygiene.13 | Regularly review authorisations | |
| Hygiene.14 | Implement least privilege | |
| Hygiene.15 | Implement separation of duties | |
| Hygiene.16 | Control access to administration functions | |
| Hygiene.17 | Segment networks to limit admin access | |
| Hygiene.18 | Keep software up to date | |
| Hygiene.19 | Protect data stored on workstations | |
| Hygiene.20 | Restrict software installation | |
| Hygiene.21 | Protect against malware | |
| Hygiene.22 | Secure email usage | |
| Hygiene.23 | Segment and filter network flows | |
| Hygiene.24 | Implement secure remote access | |
| Hygiene.25 | Secure wireless networks | |
| Hygiene.26 | Secure interconnections with partners | |
| Hygiene.27 | Use firewalls to protect internal networks | |
| Hygiene.28 | Protect administration of network equipment | |
| Hygiene.29 | Implement centralised log management | |
| Hygiene.30 | Implement regular data backups | |
| Hygiene.31 | Perform vulnerability management | |
| Hygiene.32 | Manage user account lifecycle | |
| Hygiene.33 | Apply security patches promptly | |
| Hygiene.34 | Manage changes carefully | |
| Hygiene.35 | Define and test an incident response plan | |
| Hygiene.36 | Establish a governance and risk framework | |
| Hygiene.37 | Secure premises and physical access | |
| Hygiene.38 | Protect environmental infrastructure | |
| Hygiene.39 | Implement monitoring and detection | |
| Hygiene.40 | Report and handle incidents | |
| Hygiene.41 | Conduct risk assessments | |
| Hygiene.42 | Manage third-party and supply chain security | |
| RGS.1.2 | Security awareness and competence | |
| RGS.1.3 | Security policy framework | |
| RGS.2.1 | Non-repudiation and electronic signatures | |
| RGS.2.2 | Authentication mechanisms | |
| RGS.2.3 | Cryptographic requirements | |
| RGS.3.1 | Risk assessment methodology | |
| RGS.4.1 | Security qualification and compliance assessment | |
| SecNumCloud.6.1 | Information security policies for cloud services | |
| SecNumCloud.6.2 | Review and update of information security policies | |
| SecNumCloud.7.2 | Risk assessment specific to cloud services | |
| SecNumCloud.8.1 | Human resources screening and roles | |
| SecNumCloud.8.2 | Terms and conditions of employment | |
| SecNumCloud.8.3 | Information security awareness, education and training | |
| SecNumCloud.8.4 | Disciplinary process and termination | |
| SecNumCloud.9.1 | Asset inventory for cloud infrastructure | |
| SecNumCloud.9.2 | Media handling and disposal | |
| SecNumCloud.9.3 | Information disposal and data remanence | |
| SecNumCloud.10.1 | Access control policy for cloud services | |
| SecNumCloud.10.2 | User registration and identity management | |
| SecNumCloud.10.3 | Access rights management | |
| SecNumCloud.10.4 | Privileged access management | |
| SecNumCloud.10.5 | User authentication for cloud services | |
| SecNumCloud.10.6 | Session management and timeout | |
| SecNumCloud.10.7 | Remote access to cloud administration | |
| SecNumCloud.11.1 | Cryptographic controls and key management | |
| SecNumCloud.12.1 | Physical security of cloud data centres | |
| SecNumCloud.12.2 | Physical access controls for cloud facilities | |
| SecNumCloud.12.3 | Environmental protection for cloud infrastructure | |
| SecNumCloud.13.1 | Operational procedures and hardening | |
| SecNumCloud.13.2 | Change management for cloud services | |
| SecNumCloud.13.3 | Capacity management | |
| SecNumCloud.13.4 | Maintenance and support | |
| SecNumCloud.13.5 | Backup and restoration for cloud services | |
| SecNumCloud.13.6 | Vulnerability and patch management | |
| SecNumCloud.13.7 | Logging and monitoring for cloud services | |
| SecNumCloud.14.1 | Network security for cloud infrastructure | |
| SecNumCloud.14.2 | Secure communications and data in transit | |
| SecNumCloud.14.3 | Wireless network security | |
| SecNumCloud.14.4 | Protection against denial of service | |
| SecNumCloud.15.1 | Security in development and acquisition | |
| SecNumCloud.15.2 | System documentation and change control | |
| SecNumCloud.15.3 | Technical security requirements | |
| SecNumCloud.15.4 | Configuration management for cloud platforms | |
| SecNumCloud.15.5 | Security testing for cloud services | |
| SecNumCloud.16.1 | Supplier and subcontractor management | |
| SecNumCloud.16.2 | Supplier assessment and monitoring | |
| SecNumCloud.17.1 | Incident management for cloud services | |
| SecNumCloud.17.2 | Incident response testing and exercises | |
| SecNumCloud.18.1 | Business continuity planning for cloud services | |
| SecNumCloud.18.2 | Business continuity testing | |
| SecNumCloud.18.3 | Redundancy and disaster recovery | |
| SecNumCloud.19.1 | Compliance with legal and contractual requirements | |
| SecNumCloud.19.2 | Independent security audits and ANSSI qualification | |
| SecNumCloud.19.3 | Data protection and privacy compliance |