← Frameworks / Security Framework

ANSSI Hygiene Guide, RGS & SecNumCloud

French national cybersecurity guidelines from the Agence nationale de la securite des systemes d'information. Includes the 42-measure Hygiene Guide (cyber hygiene essentials), Referentiel General de Securite (government IS security framework), and SecNumCloud 3.2 (cloud security qualification for trusted cloud providers).

Clause Title SP 800-53 Controls
Hygiene.1 Sensitise and train
Hygiene.2 Define and apply a security policy
Hygiene.3 Carry out regular audits
Hygiene.4 Identify the person responsible for information systems security
Hygiene.5 Establish an inventory of IT assets
Hygiene.6 Establish access control procedures
Hygiene.7 Manage arrivals, departures and movements of staff
Hygiene.8 Classify information to know how to protect it
Hygiene.9 Control access to external services
Hygiene.10 Implement strong authentication
Hygiene.11 Distinguish user, admin, and service accounts
Hygiene.12 Protect passwords and secret keys
Hygiene.13 Regularly review authorisations
Hygiene.14 Implement least privilege
Hygiene.15 Implement separation of duties
Hygiene.16 Control access to administration functions
Hygiene.17 Segment networks to limit admin access
Hygiene.18 Keep software up to date
Hygiene.19 Protect data stored on workstations
Hygiene.20 Restrict software installation
Hygiene.21 Protect against malware
Hygiene.22 Secure email usage
Hygiene.23 Segment and filter network flows
Hygiene.24 Implement secure remote access
Hygiene.25 Secure wireless networks
Hygiene.26 Secure interconnections with partners
Hygiene.27 Use firewalls to protect internal networks
Hygiene.28 Protect administration of network equipment
Hygiene.29 Implement centralised log management
Hygiene.30 Implement regular data backups
Hygiene.31 Perform vulnerability management
Hygiene.32 Manage user account lifecycle
Hygiene.33 Apply security patches promptly
Hygiene.34 Manage changes carefully
Hygiene.35 Define and test an incident response plan
Hygiene.36 Establish a governance and risk framework
Hygiene.37 Secure premises and physical access
Hygiene.38 Protect environmental infrastructure
Hygiene.39 Implement monitoring and detection
Hygiene.40 Report and handle incidents
Hygiene.41 Conduct risk assessments
Hygiene.42 Manage third-party and supply chain security
RGS.1.2 Security awareness and competence
RGS.1.3 Security policy framework
RGS.2.1 Non-repudiation and electronic signatures
RGS.2.2 Authentication mechanisms
RGS.2.3 Cryptographic requirements
RGS.3.1 Risk assessment methodology
RGS.4.1 Security qualification and compliance assessment
SecNumCloud.6.1 Information security policies for cloud services
SecNumCloud.6.2 Review and update of information security policies
SecNumCloud.7.2 Risk assessment specific to cloud services
SecNumCloud.8.1 Human resources screening and roles
SecNumCloud.8.2 Terms and conditions of employment
SecNumCloud.8.3 Information security awareness, education and training
SecNumCloud.8.4 Disciplinary process and termination
SecNumCloud.9.1 Asset inventory for cloud infrastructure
SecNumCloud.9.2 Media handling and disposal
SecNumCloud.9.3 Information disposal and data remanence
SecNumCloud.10.1 Access control policy for cloud services
SecNumCloud.10.2 User registration and identity management
SecNumCloud.10.3 Access rights management
SecNumCloud.10.4 Privileged access management
SecNumCloud.10.5 User authentication for cloud services
SecNumCloud.10.6 Session management and timeout
SecNumCloud.10.7 Remote access to cloud administration
SecNumCloud.11.1 Cryptographic controls and key management
SecNumCloud.12.1 Physical security of cloud data centres
SecNumCloud.12.2 Physical access controls for cloud facilities
SecNumCloud.12.3 Environmental protection for cloud infrastructure
SecNumCloud.13.1 Operational procedures and hardening
SecNumCloud.13.2 Change management for cloud services
SecNumCloud.13.3 Capacity management
SecNumCloud.13.4 Maintenance and support
SecNumCloud.13.5 Backup and restoration for cloud services
SecNumCloud.13.6 Vulnerability and patch management
SecNumCloud.13.7 Logging and monitoring for cloud services
SecNumCloud.14.1 Network security for cloud infrastructure
SecNumCloud.14.2 Secure communications and data in transit
SecNumCloud.14.3 Wireless network security
SecNumCloud.14.4 Protection against denial of service
SecNumCloud.15.1 Security in development and acquisition
SecNumCloud.15.2 System documentation and change control
SecNumCloud.15.3 Technical security requirements
SecNumCloud.15.4 Configuration management for cloud platforms
SecNumCloud.15.5 Security testing for cloud services
SecNumCloud.16.1 Supplier and subcontractor management
SecNumCloud.16.2 Supplier assessment and monitoring
SecNumCloud.17.1 Incident management for cloud services
SecNumCloud.17.2 Incident response testing and exercises
SecNumCloud.18.1 Business continuity planning for cloud services
SecNumCloud.18.2 Business continuity testing
SecNumCloud.18.3 Redundancy and disaster recovery
SecNumCloud.19.1 Compliance with legal and contractual requirements
SecNumCloud.19.2 Independent security audits and ANSSI qualification
SecNumCloud.19.3 Data protection and privacy compliance