I've been thinking about getting Cyber Essentials for my limited company (as a prelude to become an assessor). Part of this process involves defining the boundary of scope; in an office building, this would normally include all the network infrastructure (e.g. routers) as per the attached diagram.
However, the documentation also says:
"Alternatively, where an organisation does not control the network a device is connected to, a host-based firewall must be configured on a device. This works in the same way as a boundary firewall but only protects the single device on which it is configured."
When I'm working from home, I have a laptop (owned by MyCo) but I'm using my home internet connection. I'm paying for that internet connection personally (not through MyCo), because it's not "wholly and exclusively" for business use.
So, does the network infrastructure [have to] fall within scope of Cyber Essentials? I.e. can I legitimately say "MyCo doesn't control the network" or is that splitting hairs?
Has anyone else been through this process?
However, the documentation also says:
"Alternatively, where an organisation does not control the network a device is connected to, a host-based firewall must be configured on a device. This works in the same way as a boundary firewall but only protects the single device on which it is configured."
When I'm working from home, I have a laptop (owned by MyCo) but I'm using my home internet connection. I'm paying for that internet connection personally (not through MyCo), because it's not "wholly and exclusively" for business use.
So, does the network infrastructure [have to] fall within scope of Cyber Essentials? I.e. can I legitimately say "MyCo doesn't control the network" or is that splitting hairs?
Has anyone else been through this process?
Comment