Skip to content

Evidence request lists

ANSSI Guide d'hygiene informatique (42 mesures, v2.0)

Evidence request list. 42 controls, 42 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 11 September 2026. Published by The Art of Service.

ANSSI Hygiene I: Raise Awareness and Train (measures 1 to 3)

ANSSI-HYG-01
Train Operational Teams in Information System Security

Train the teams that operate the information system in security, covering security integration for project managers, secure development for developers and security frameworks for security officers, and require equivalent training of external providers by contract.

Artefacts an auditor will ask for
  • Training plan for operational and IT teams by role
  • Attendance and completion records
  • Contract clauses requiring provider staff training
  • Training content covering secure development and project security
Where this commonly fails
  • Training aimed at general users only with nothing role specific for IT staff
  • Outsourced staff excluded from the training requirement
  • No record of who completed which module
ANSSI-HYG-02
Raise User Awareness of Basic Security Practice

Inform every user on arrival and regularly thereafter of the security stakes, the rules to follow and the expected behaviours, covering sensitive information, legal obligations, daily security rules and the protective tools available.

Artefacts an auditor will ask for
  • Awareness programme content and schedule
  • Induction security briefing records
  • Acceptable use charter signed by users
  • Evidence of repeat awareness actions during the year
Where this commonly fails
  • Awareness delivered only at induction
  • No charter of use of information resources
  • Content does not cover password reuse, personal device connection or suspicious event reporting
ANSSI-HYG-03
Control the Risks of Outsourced Information System Management

Assess the risks specific to outsourcing before externalising the information system or its data, and reflect the resulting security needs and measures in the requirements placed on the provider.

Artefacts an auditor will ask for
  • Risk assessment carried out before the outsourcing decision
  • Security requirements annexed to the provider contract
  • Right to audit and reversibility clauses
  • Provider security reporting and review records
Where this commonly fails
  • Outsourcing risk assessed after contract signature or not at all
  • Security requirements absent from the contract
  • No reversibility or exit arrangements
  • Provider performance never reviewed against the security clauses

ANSSI Hygiene II: Know the Information System (measures 4 to 7)

ANSSI-HYG-04
Identify the Most Sensitive Information and Servers and Maintain a Network Diagram

Identify the information and servers that are most sensitive to the entity and maintain an up to date diagram of the network showing them.

Artefacts an auditor will ask for
  • Inventory of sensitive information and the servers holding it
  • Current network diagram with interconnections and the date of last update
  • Owner assigned to each sensitive asset
  • Change process keeping the diagram current
Where this commonly fails
  • Network diagram exists but is years out of date
  • Sensitivity classification not applied to servers
  • No named owner for sensitive assets
ANSSI-HYG-05
Maintain an Exhaustive Inventory of Privileged Accounts

Hold and keep up to date a complete inventory of privileged accounts across the information system.

Artefacts an auditor will ask for
  • Privileged account inventory covering domain, local, service and application accounts
  • Review evidence showing the inventory is refreshed
  • Owner and justification recorded for each privileged account
  • Reconciliation against directory extracts
Where this commonly fails
  • Inventory limited to domain administrator accounts
  • Service and application accounts omitted
  • No periodic reconciliation against the directory
ANSSI-HYG-06
Organise Joiner, Leaver and Role Change Procedures

Define and operate procedures covering the arrival, departure and change of function of users, so that access rights are created, adjusted and withdrawn in step with the user status.

Artefacts an auditor will ask for
  • Documented joiner, mover and leaver procedure
  • Ticket records showing access withdrawal on departure
  • Reconciliation between the human resources register and active accounts
  • Records of rights adjusted on role change
Where this commonly fails
  • Accounts of departed staff remain active
  • Role changes add rights without removing the previous ones
  • No reconciliation between human resources and the directory
ANSSI-HYG-07
Authorise Network Connection Only for Managed Equipment

Permit connection to the entity network only for equipment that the entity manages, and control the connection of any other device.

Artefacts an auditor will ask for
  • Network access control configuration or equivalent connection control
  • Register of managed equipment
  • Policy on personal and visitor devices
  • Records of unauthorised connection attempts and their handling
Where this commonly fails
  • Any device that reaches a wall port obtains network access
  • Visitor access shares the internal network
  • No inventory to determine what counts as managed equipment

ANSSI Hygiene III: Authenticate and Control Access (measures 8 to 13)

ANSSI-HYG-08
Identify Each Person by Name and Separate User and Administrator Roles

Give each person accessing the system a nominative account, and keep user roles separate from administrator roles so that administration is not performed from an ordinary user account.

Artefacts an auditor will ask for
  • Account naming standard prohibiting shared accounts
  • Evidence that administrators hold separate administration accounts
  • List of any remaining generic accounts with justification and compensating controls
  • Directory extract showing role separation
Where this commonly fails
  • Shared or generic accounts used for administration
  • Administrators use a single account for both mail and administration
  • Exceptions never reviewed
ANSSI-HYG-09
Assign the Correct Rights on Sensitive Resources

Grant rights on the sensitive resources of the information system according to need, and review them so that access remains limited to those who require it.

Artefacts an auditor will ask for
  • Access rights matrix for sensitive resources
  • Periodic access review records with sign off by the resource owner
  • Approval records for rights grants
  • Evidence of removal of rights found unnecessary
Where this commonly fails
  • Rights accumulate over time with no review
  • Access granted by group membership without an owner approving
  • Sensitive shares open to all staff
ANSSI-HYG-10
Define and Verify Password Selection and Sizing Rules

Define rules on the choice and length of passwords and verify that they are applied.

Artefacts an auditor will ask for
  • Password policy stating length and composition rules
  • Technical enforcement configuration
  • Evidence of verification such as strength auditing
  • Communication of the rules to users
Where this commonly fails
  • Policy published but not technically enforced
  • Rules never verified against live accounts
  • Service and application accounts exempt from the policy
ANSSI-HYG-11
Protect Passwords Stored on Systems

Protect passwords held on systems so that they cannot be recovered, avoiding storage in clear text or in reversible form.

Artefacts an auditor will ask for
  • Configuration standards covering password storage and hashing
  • Review of applications and scripts for stored credentials
  • Secret management tooling records
  • Remediation records for credentials found in scripts or configuration files
Where this commonly fails
  • Credentials embedded in scripts, configuration files or source control
  • Legacy applications storing reversible passwords
  • No search performed for stored secrets
ANSSI-HYG-12
Change Default Authentication Elements on Equipment and Services

Change the authentication elements supplied by default on equipment and services before they are placed in service.

Artefacts an auditor will ask for
  • Commissioning checklist including default credential change
  • Evidence of default credential scanning across the estate
  • Register of network devices, appliances and applications with the change confirmed
Where this commonly fails
  • Network appliances and printers left on factory credentials
  • Checklist exists but commissioning evidence is not retained
  • No periodic scan for default credentials
ANSSI-HYG-13
Prefer Strong Authentication Where Possible

Use strong authentication wherever it can be deployed, in particular for privileged access and for access from outside the entity.

Artefacts an auditor will ask for
  • Inventory of systems with strong authentication enabled
  • Deployment plan and exception register for systems not yet covered
  • Configuration evidence for remote and administrative access
  • Certificate or token management records
Where this commonly fails
  • Strong authentication limited to a small pilot
  • Remote access protected by password only
  • Exceptions granted without an end date

ANSSI Hygiene IV: Secure Workstations (measures 14 to 18)

ANSSI-HYG-14
Apply a Minimum Security Level Across the Whole Estate

Define and apply a minimum level of security across the whole computing estate, including hardening of the operating system and removal of unnecessary services.

Artefacts an auditor will ask for
  • Hardening baseline for each operating system in use
  • Compliance reporting showing estate conformance to the baseline
  • Exception register with justification
  • Build images reflecting the baseline
Where this commonly fails
  • Baseline defined but conformance never measured
  • Legacy machines excluded from the baseline
  • Unnecessary services and default applications left enabled
ANSSI-HYG-15
Protect Against Threats Related to Removable Media

Protect the information system against the threats associated with removable media, including control of their use and inspection of their content.

Artefacts an auditor will ask for
  • Removable media policy
  • Technical control on media ports or automatic scanning of media
  • Records of the decontamination station or equivalent where used
  • User communication on removable media risk
Where this commonly fails
  • Removable media unrestricted on all workstations
  • No scanning of media received from outside
  • Policy issued without any technical control
ANSSI-HYG-16
Use a Centralised Management Tool to Standardise Security Policies

Use a centralised management tool so that security policies are applied uniformly across the estate.

Artefacts an auditor will ask for
  • Central management platform covering the workstation and server estate
  • Policy objects or profiles applied
  • Coverage report showing devices under management
  • Exception list for unmanaged devices
Where this commonly fails
  • Significant part of the estate outside central management
  • Policies applied manually per machine
  • Coverage never measured
ANSSI-HYG-17
Enable and Configure the Local Firewall on Workstations

Enable and configure the local firewall on workstations so that unnecessary inbound connections are blocked.

Artefacts an auditor will ask for
  • Local firewall policy and rule set
  • Configuration compliance report across the workstation estate
  • Change control for firewall rule exceptions
Where this commonly fails
  • Local firewall disabled to simplify support
  • Rules permit any inbound traffic from the internal network
  • No compliance reporting
ANSSI-HYG-18
Encrypt Sensitive Data Transmitted Over the Internet

Encrypt sensitive data transmitted over the internet, using cryptographic mechanisms consistent with the published recommendations.

Artefacts an auditor will ask for
  • Inventory of flows carrying sensitive data over public networks
  • Encryption standard specifying algorithms and key sizes
  • Certificate and key management records
  • Configuration evidence for the protected flows
Where this commonly fails
  • Sensitive files exchanged by unprotected mail or file transfer
  • Encryption standard not aligned with the published recommendations
  • Expired or self signed certificates in production

ANSSI Hygiene IX: Supervise, Audit and Respond (measures 36 to 40)

ANSSI-HYG-36
Enable and Configure Logging on the Most Important Components

Enable and configure the logs of the most important components of the information system so that events can be reconstructed.

Artefacts an auditor will ask for
  • List of components in scope for logging and the events collected
  • Log retention configuration and period
  • Time synchronisation configuration
  • Evidence that logs are reviewed or alerted on
Where this commonly fails
  • Logging enabled but retained for a few days only
  • Clocks not synchronised so events cannot be correlated
  • Logs collected but never examined
  • Key components such as the directory and the gateway not logged
ANSSI-HYG-37
Define and Apply a Backup Policy for Critical Components

Define and apply a backup policy covering the critical components of the information system, and verify that restoration works.

Artefacts an auditor will ask for
  • Backup policy stating scope, frequency and retention
  • Backup job success reports
  • Restoration test records with dates and outcomes
  • Evidence that at least one copy is held offline or otherwise isolated
Where this commonly fails
  • Backups run but restoration never tested
  • Backup copies reachable from the production network
  • Critical systems missing from the backup scope
  • Retention shorter than the time needed to detect a compromise
ANSSI-HYG-38
Carry Out Regular Security Checks and Audits and Apply the Corrective Actions

Carry out regular security checks and audits of the information system and apply the corrective actions that they identify.

Artefacts an auditor will ask for
  • Audit and control plan with the scope and frequency
  • Audit reports including any carried out by a qualified provider
  • Corrective action plan with owners and dates
  • Evidence of closure of the actions raised
Where this commonly fails
  • Audits performed but findings not tracked to closure
  • No plan setting out what is audited and how often
  • Scope limited to a single system year after year
ANSSI-HYG-39
Designate an Information System Security Officer and Make the Role Known

Designate a person responsible for information system security and make that role known to the staff.

Artefacts an auditor will ask for
  • Appointment record naming the security officer
  • Role description and reporting line
  • Communication to staff announcing the role and how to contact it
  • Evidence the officer is involved in projects and incidents
Where this commonly fails
  • Role held informally by an IT team member with no mandate
  • Staff unaware whom to contact
  • No role description or reporting line
ANSSI-HYG-40
Define a Security Incident Management Procedure

Define a procedure for managing security incidents, covering how they are reported, handled and closed.

Artefacts an auditor will ask for
  • Documented incident management procedure with roles and escalation
  • Incident register with classification and closure
  • Reporting channel communicated to staff
  • Post incident review records and the resulting actions
Where this commonly fails
  • Procedure exists but staff do not know how to report
  • No incident register
  • Incidents closed without a review or lessons captured

ANSSI Hygiene V: Secure the Network (measures 19 to 26)

ANSSI-HYG-19
Segment the Network and Partition the Zones

Segment the network into zones and enforce partitioning between them so that a compromise in one zone does not extend to the whole information system.

Artefacts an auditor will ask for
  • Network segmentation design with the zones and their trust levels
  • Filtering rules between zones
  • Review evidence that the rules match the design
  • Diagram showing where sensitive systems sit
Where this commonly fails
  • Flat network with a perimeter firewall only
  • Segmentation designed but rules permit any to any between zones
  • No periodic rule review
ANSSI-HYG-20
Secure Wi-Fi Access Networks and Separate Usage

Secure the Wi-Fi access networks and separate the different uses so that guest and internal access do not share the same network.

Artefacts an auditor will ask for
  • Wi-Fi configuration standard including the authentication and encryption used
  • Separate guest network configuration
  • Access point inventory
  • Records of periodic review of the wireless estate
Where this commonly fails
  • Guest and corporate traffic on the same wireless network
  • Pre shared keys never rotated
  • Rogue access points not detected
ANSSI-HYG-21
Use Secure Protocols Wherever They Exist

Use the secure version of a protocol wherever one exists, in place of the unprotected equivalent.

Artefacts an auditor will ask for
  • Protocol standard listing permitted and prohibited protocols
  • Scan results showing use of unprotected protocols
  • Migration plan and exception register
  • Configuration evidence for the migrated services
Where this commonly fails
  • Legacy unprotected protocols left enabled alongside the secure version
  • No scanning to detect their use
  • Exceptions carried indefinitely
ANSSI-HYG-22
Put in Place a Secure Internet Access Gateway

Route outbound internet access through a secure gateway that filters and logs the traffic.

Artefacts an auditor will ask for
  • Gateway architecture and filtering policy
  • Logs demonstrating traffic passes through the gateway
  • Rules preventing direct outbound access that bypasses the gateway
  • Category and content filtering configuration
Where this commonly fails
  • Direct outbound routes bypass the gateway
  • Gateway present but not logging
  • Filtering policy never reviewed
ANSSI-HYG-23
Partition Internet Facing Services from the Rest of the Information System

Place services visible from the internet in a partitioned zone separated from the rest of the information system.

Artefacts an auditor will ask for
  • Inventory of internet facing services
  • Demilitarised zone design and its filtering rules
  • Evidence that internet facing servers hold no direct route to the internal network
  • Exposure review records
Where this commonly fails
  • Internet facing server joined to the internal domain
  • No inventory of exposed services
  • Filtering permits the exposed zone to reach internal systems freely
ANSSI-HYG-24
Protect the Corporate Mail Service

Protect the professional mail service, including filtering of malicious content and protection of the mail flows.

Artefacts an auditor will ask for
  • Mail filtering configuration for malicious attachments and links
  • Sender authentication records for the domains used
  • Encryption configuration on mail transport
  • Statistics on blocked messages
Where this commonly fails
  • No filtering of executable attachments
  • Sender authentication records absent or set to a permissive policy
  • Mail transport unencrypted
ANSSI-HYG-25
Secure Dedicated Network Interconnections with Partners

Secure the dedicated network interconnections established with partners so that partner access is limited and controlled.

Artefacts an auditor will ask for
  • Register of partner interconnections with the business owner
  • Filtering rules limiting each partner to the agreed resources
  • Security clauses in the partner agreement
  • Periodic review of the interconnections
Where this commonly fails
  • Partner links terminate directly on the internal network
  • No register of active interconnections
  • Links remain after the partnership ends
ANSSI-HYG-26
Control and Protect Access to Server Rooms and Technical Areas

Control and protect physical access to server rooms and technical areas.

Artefacts an auditor will ask for
  • Access list for server rooms and technical areas
  • Badge or key issue and return records
  • Access log review evidence
  • Visitor escort procedure for technical areas
Where this commonly fails
  • Access list not reviewed and includes departed staff
  • Physical access logs never reviewed
  • Technical areas used for general storage with uncontrolled access

ANSSI Hygiene VI: Secure Administration (measures 27 to 29)

ANSSI-HYG-27
Prohibit Internet Access from Administration Workstations and Servers

Prohibit internet access from the workstations and servers used to administer the information system.

Artefacts an auditor will ask for
  • Filtering rules blocking outbound internet from administration systems
  • Inventory of administration workstations and servers
  • Evidence that mail and web browsing are not available on those systems
  • Exception register with compensating controls
Where this commonly fails
  • Administrators browse the web and read mail from the administration workstation
  • Rule exists but exceptions are widespread
  • No inventory identifying which systems are administration systems
ANSSI-HYG-28
Use a Dedicated and Partitioned Network for Administration

Use a dedicated and partitioned network for administration of the information system.

Artefacts an auditor will ask for
  • Administration network design and its partitioning
  • Evidence that administration protocols are carried only on that network
  • Access path documentation including any jump host
  • Review records for the administration network rules
Where this commonly fails
  • Administration performed over the general user network
  • Jump host bypassed by direct connections
  • Design documented but not enforced by filtering
ANSSI-HYG-29
Limit Administration Rights on Workstations to Operational Need

Limit administration rights on workstations to what operational need requires.

Artefacts an auditor will ask for
  • Report of accounts holding local administrator rights on workstations
  • Justification and approval for each remaining grant
  • Periodic review of local administrator membership
  • Privilege elevation mechanism for tasks that require it
Where this commonly fails
  • Users routinely hold local administrator rights
  • Grants made for a temporary need and never withdrawn
  • No reporting of local administrator membership

ANSSI Hygiene VII: Manage Mobile Working (measures 30 to 33)

ANSSI-HYG-30
Apply Physical Protection Measures to Mobile Devices

Apply physical security measures to mobile terminals so that loss or theft is prevented or its effect limited.

Artefacts an auditor will ask for
  • Mobile device issue register
  • Physical protection guidance issued to travelling staff
  • Loss and theft reporting procedure and its records
  • Privacy screen or cable lock provision where applicable
Where this commonly fails
  • No register of which devices are held by whom
  • Loss and theft not reported through a defined route
  • Travel guidance not issued
ANSSI-HYG-31
Encrypt Sensitive Data, in Particular on Equipment That May Be Lost

Encrypt sensitive data, in particular on equipment that could be lost or stolen, so that the data remains protected if the device leaves the entity control.

Artefacts an auditor will ask for
  • Disk encryption coverage report for laptops and mobile devices
  • Encryption standard and recovery key management
  • Evidence of encryption on removable media used for sensitive data
  • Exception register
Where this commonly fails
  • Encryption enabled on new devices only
  • Recovery keys not escrowed
  • Removable media excluded from the encryption requirement
ANSSI-HYG-32
Secure the Network Connection of Devices Used for Mobile Working

Secure the network connection of workstations used away from the entity premises, so that traffic is protected when untrusted networks are used.

Artefacts an auditor will ask for
  • Remote access architecture and its configuration
  • Evidence that remote traffic is tunnelled and authenticated
  • Policy on the use of public and untrusted networks
  • Logs of remote connections
Where this commonly fails
  • Remote workers connect to services directly without a protected tunnel
  • Split tunnelling permitted without assessment
  • Remote connection logs not retained
ANSSI-HYG-33
Adopt Security Policies Dedicated to Mobile Terminals

Adopt security policies specific to mobile terminals such as smartphones and tablets, covering their configuration and the data they hold.

Artefacts an auditor will ask for
  • Mobile device policy and the enforced configuration profile
  • Enrolment records showing devices under management
  • Remote wipe capability and its test evidence
  • Application control rules for managed devices
Where this commonly fails
  • Mobile devices access corporate mail without any enforced policy
  • Personal devices unmanaged but permitted
  • Remote wipe never tested

ANSSI Hygiene VIII: Keep the Information System Up to Date (measures 34 and 35)

ANSSI-HYG-34
Define an Update Policy for Information System Components

Define a policy for updating the components of the information system and apply it so that corrections are deployed within defined timescales.

Artefacts an auditor will ask for
  • Patch and update policy stating timescales by criticality
  • Deployment reports for operating systems and applications
  • Exception register for components that cannot be updated
  • Vulnerability scan results demonstrating the outcome
Where this commonly fails
  • Policy states timescales that are not measured
  • Third party applications outside the patching process
  • Exceptions recorded without compensating controls
ANSSI-HYG-35
Anticipate the End of Maintenance of Software and Systems

Anticipate the end of maintenance of software and systems and limit software dependencies so that unsupported components are identified and dealt with before support ends.

Artefacts an auditor will ask for
  • Register of components with their end of support dates
  • Migration or replacement plan for components approaching end of support
  • Isolation measures for components kept beyond end of support
  • Record of software dependencies constraining upgrades
Where this commonly fails
  • Unsupported operating systems discovered only after an incident
  • No register of end of support dates
  • Dependencies on obsolete components undocumented

ANSSI Hygiene X: Going Further (measures 41 and 42)

ANSSI-HYG-41
Conduct a Formal Risk Analysis

Conduct a formal risk analysis of the information system so that the security measures applied follow from the risks identified.

Artefacts an auditor will ask for
  • Risk analysis report with the method used
  • Risk register with treatment decisions and owners
  • Evidence that the security measures trace back to identified risks
  • Record of review of the analysis after significant change
Where this commonly fails
  • Measures selected from a checklist with no risk basis
  • Risk analysis performed once and never revisited
  • Treatment decisions recorded without an owner
ANSSI-HYG-42
Prefer Products and Services Qualified by ANSSI

Prefer, where the need arises, products and services that carry an ANSSI qualification, drawing on the published catalogue of qualified products and service providers.

Artefacts an auditor will ask for
  • Procurement standard referring to the qualified products and providers catalogue
  • Record of the qualification status of security products and providers in use
  • Justification where a non qualified product or provider was selected
Where this commonly fails
  • Qualification status never considered during procurement
  • Security services bought without checking the provider qualification
  • No record of the products in use and their status
Assembled from the framework's own control set. Every line traces to a control in the graph, so this pack is regenerated rather than written, and stays current as the graph does.

Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does.