Foundation Cyber Security is built on 47 practical controls, organised into four pillars: Strategy, Protection, Response, and Recovery. Together they cover what a small to medium organisation needs to get right - the technical controls, and the strategy, governance, and planning that make them stick.
Each page below is the short version of a control: what it is, why it matters, the risk of leaving it, and where to start. Every control also maps to CIS Controls v8, NIST 800-53, the Essential Eight, and ISO 27001. The full detail - assessment questions, maturity levels, and recommendations matched to your score - is in the Foundation platform, free to start.
Strategy
Strategy is where most frameworks are weakest, and where Foundation starts. These controls cover your cybersecurity strategy, governance, asset management, and risk management - the things that get leadership on board and make every other control easier to land.
Assets
- ST.AS.01 - Maintain a current list of assets
- ST.AS.02 - Maintain processes for adding and removing assets
- ST.AS.03 - Include assets in on & off-boarding procedures
Governance
- ST.GO.01 - Document cybersecurity within roles and job descriptions
- ST.GO.02 - Document and store cybersecurity policies
- ST.GO.03 - Include cybersecurity in regular governance activities
- ST.GO.04 - Assess the need for independent guidance
Preparation
- ST.PR.01 - Create a documented cybersecurity strategy
- ST.PR.02 - Complete a cybersecurity maturity assessment
- ST.PR.03 - Plan and schedule ongoing maturity assessments
Risk
- ST.RI.01 - Centrally document cyber-risks
- ST.RI.02 - Review risks as part of regular governance activities
- ST.RI.03 - Understand your legal requirements regarding cyber-risks
- ST.RI.04 - Identify and prioritise risk reduction strategies
Protection
The technical heart of the framework. These controls protect your applications, data, devices, network, and people - from multi-factor authentication and patching through to backups, access management, and staff training.
Apps
- PR.AP.01 - Enforce Multi-Factor Authentication on all applicable cloud apps
- PR.AP.02 - Use modern, supported software with Single Sign On
- PR.AP.03 - Enforce regular patching and server updates
- PR.AP.04 - Enforce use of modern internet browsers
- PR.AP.05 - Use an email tool that blocks malicious links and attachments
Data
- PR.DA.01 - Back up critical data regularly, as defined by the data owners
- PR.DA.02 - Validate backups regularly to ensure integrity
- PR.DA.03 - Give users the minimum practical level of access required to conduct their role
- PR.DA.04 - Regularly audit access, including privileged user access and service accounts
- PR.DA.05 - Manage administrator passwords and keys centrally
Devices
- PR.DE.01 - Install and maintain anti-malware and anti-virus
- PR.DE.02 - Configure disk encryption, and macro settings on Microsoft products
- PR.DE.03 - Ensure staff use a basic, unprivileged account for daily work
- PR.DE.04 - Control the physical security and life cycle of devices
Network
- PR.NE.01 - Maintain physical access controls for network infrastructure
- PR.NE.02 - Maintain logical access controls on your wired and wireless networks
- PR.NE.03 - Limit remote access and open ports for internet-facing servers
Users
- PR.US.01 - Maintain onboarding and off-boarding processes that govern access to data and applications
- PR.US.02 - Provide all staff with relevant policy documents
- PR.US.03 - Provide all staff with adequate, ongoing cybersecurity training
- PR.US.04 - Maintain segregation of duties for important processes
Response
When something does happen, these controls determine how quickly you spot it and how well you respond - detection and logging, incident response, and business continuity.
Business Continuity
- RE.BC.01 - Document a business continuity plan and test your planned response to identified risks
- RE.BC.02 - Keep a copy of operational data independent from business applications
Detection
- RE.DT.01 - Ensure audit logging is enabled on all services
- RE.DT.02 - Review administrator and access logs regularly
- RE.DT.03 - Encourage staff to report unusual activity and cyber-risks
Incident Management
- RE.IN.01 - Document your incident response management plan
- RE.IN.02 - Regularly rehearse incident response plans
Recovery
Getting back to normal, and getting better. These controls cover recovery planning, disaster recovery testing, and managing the improvements that come out of incidents and assessments.
Improvement
- RC.IM.01 - Plan and finance a timeline of activities
- RC.IM.02 - Obtain approval for the target state cybersecurity maturity and timeline of activities
Planning
- RC.PL.01 - Document and test options for recovery systems in the event of total systems loss
- RC.PL.02 - Maintain a communications plan for recovery activities
- RC.PL.03 - Document your legal requirements for notifying authorities or governing bodies
If you’re not sure where to begin, take the free 5-question Quick Security Check for a 2-minute read on your posture, or create a free account and work through all 47 controls at your own pace.