ANSSI Guide d'hygiene informatique (42 mesures, v2.0)
Evidence request list. 42 controls, 42 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 11 September 2026. Published by The Art of Service.
ANSSI Hygiene I: Raise Awareness and Train (measures 1 to 3)
Train the teams that operate the information system in security, covering security integration for project managers, secure development for developers and security frameworks for security officers, and require equivalent training of external providers by contract.
- Training plan for operational and IT teams by role
- Attendance and completion records
- Contract clauses requiring provider staff training
- Training content covering secure development and project security
- Training aimed at general users only with nothing role specific for IT staff
- Outsourced staff excluded from the training requirement
- No record of who completed which module
Inform every user on arrival and regularly thereafter of the security stakes, the rules to follow and the expected behaviours, covering sensitive information, legal obligations, daily security rules and the protective tools available.
- Awareness programme content and schedule
- Induction security briefing records
- Acceptable use charter signed by users
- Evidence of repeat awareness actions during the year
- Awareness delivered only at induction
- No charter of use of information resources
- Content does not cover password reuse, personal device connection or suspicious event reporting
Assess the risks specific to outsourcing before externalising the information system or its data, and reflect the resulting security needs and measures in the requirements placed on the provider.
- Risk assessment carried out before the outsourcing decision
- Security requirements annexed to the provider contract
- Right to audit and reversibility clauses
- Provider security reporting and review records
- Outsourcing risk assessed after contract signature or not at all
- Security requirements absent from the contract
- No reversibility or exit arrangements
- Provider performance never reviewed against the security clauses
ANSSI Hygiene II: Know the Information System (measures 4 to 7)
Identify the information and servers that are most sensitive to the entity and maintain an up to date diagram of the network showing them.
- Inventory of sensitive information and the servers holding it
- Current network diagram with interconnections and the date of last update
- Owner assigned to each sensitive asset
- Change process keeping the diagram current
- Network diagram exists but is years out of date
- Sensitivity classification not applied to servers
- No named owner for sensitive assets
Hold and keep up to date a complete inventory of privileged accounts across the information system.
- Privileged account inventory covering domain, local, service and application accounts
- Review evidence showing the inventory is refreshed
- Owner and justification recorded for each privileged account
- Reconciliation against directory extracts
- Inventory limited to domain administrator accounts
- Service and application accounts omitted
- No periodic reconciliation against the directory
Define and operate procedures covering the arrival, departure and change of function of users, so that access rights are created, adjusted and withdrawn in step with the user status.
- Documented joiner, mover and leaver procedure
- Ticket records showing access withdrawal on departure
- Reconciliation between the human resources register and active accounts
- Records of rights adjusted on role change
- Accounts of departed staff remain active
- Role changes add rights without removing the previous ones
- No reconciliation between human resources and the directory
Permit connection to the entity network only for equipment that the entity manages, and control the connection of any other device.
- Network access control configuration or equivalent connection control
- Register of managed equipment
- Policy on personal and visitor devices
- Records of unauthorised connection attempts and their handling
- Any device that reaches a wall port obtains network access
- Visitor access shares the internal network
- No inventory to determine what counts as managed equipment
ANSSI Hygiene III: Authenticate and Control Access (measures 8 to 13)
Give each person accessing the system a nominative account, and keep user roles separate from administrator roles so that administration is not performed from an ordinary user account.
- Account naming standard prohibiting shared accounts
- Evidence that administrators hold separate administration accounts
- List of any remaining generic accounts with justification and compensating controls
- Directory extract showing role separation
- Shared or generic accounts used for administration
- Administrators use a single account for both mail and administration
- Exceptions never reviewed
Grant rights on the sensitive resources of the information system according to need, and review them so that access remains limited to those who require it.
- Access rights matrix for sensitive resources
- Periodic access review records with sign off by the resource owner
- Approval records for rights grants
- Evidence of removal of rights found unnecessary
- Rights accumulate over time with no review
- Access granted by group membership without an owner approving
- Sensitive shares open to all staff
Define rules on the choice and length of passwords and verify that they are applied.
- Password policy stating length and composition rules
- Technical enforcement configuration
- Evidence of verification such as strength auditing
- Communication of the rules to users
- Policy published but not technically enforced
- Rules never verified against live accounts
- Service and application accounts exempt from the policy
Protect passwords held on systems so that they cannot be recovered, avoiding storage in clear text or in reversible form.
- Configuration standards covering password storage and hashing
- Review of applications and scripts for stored credentials
- Secret management tooling records
- Remediation records for credentials found in scripts or configuration files
- Credentials embedded in scripts, configuration files or source control
- Legacy applications storing reversible passwords
- No search performed for stored secrets
Change the authentication elements supplied by default on equipment and services before they are placed in service.
- Commissioning checklist including default credential change
- Evidence of default credential scanning across the estate
- Register of network devices, appliances and applications with the change confirmed
- Network appliances and printers left on factory credentials
- Checklist exists but commissioning evidence is not retained
- No periodic scan for default credentials
Use strong authentication wherever it can be deployed, in particular for privileged access and for access from outside the entity.
- Inventory of systems with strong authentication enabled
- Deployment plan and exception register for systems not yet covered
- Configuration evidence for remote and administrative access
- Certificate or token management records
- Strong authentication limited to a small pilot
- Remote access protected by password only
- Exceptions granted without an end date
ANSSI Hygiene IV: Secure Workstations (measures 14 to 18)
Define and apply a minimum level of security across the whole computing estate, including hardening of the operating system and removal of unnecessary services.
- Hardening baseline for each operating system in use
- Compliance reporting showing estate conformance to the baseline
- Exception register with justification
- Build images reflecting the baseline
- Baseline defined but conformance never measured
- Legacy machines excluded from the baseline
- Unnecessary services and default applications left enabled
Protect the information system against the threats associated with removable media, including control of their use and inspection of their content.
- Removable media policy
- Technical control on media ports or automatic scanning of media
- Records of the decontamination station or equivalent where used
- User communication on removable media risk
- Removable media unrestricted on all workstations
- No scanning of media received from outside
- Policy issued without any technical control
Use a centralised management tool so that security policies are applied uniformly across the estate.
- Central management platform covering the workstation and server estate
- Policy objects or profiles applied
- Coverage report showing devices under management
- Exception list for unmanaged devices
- Significant part of the estate outside central management
- Policies applied manually per machine
- Coverage never measured
Enable and configure the local firewall on workstations so that unnecessary inbound connections are blocked.
- Local firewall policy and rule set
- Configuration compliance report across the workstation estate
- Change control for firewall rule exceptions
- Local firewall disabled to simplify support
- Rules permit any inbound traffic from the internal network
- No compliance reporting
Encrypt sensitive data transmitted over the internet, using cryptographic mechanisms consistent with the published recommendations.
- Inventory of flows carrying sensitive data over public networks
- Encryption standard specifying algorithms and key sizes
- Certificate and key management records
- Configuration evidence for the protected flows
- Sensitive files exchanged by unprotected mail or file transfer
- Encryption standard not aligned with the published recommendations
- Expired or self signed certificates in production
ANSSI Hygiene IX: Supervise, Audit and Respond (measures 36 to 40)
Enable and configure the logs of the most important components of the information system so that events can be reconstructed.
- List of components in scope for logging and the events collected
- Log retention configuration and period
- Time synchronisation configuration
- Evidence that logs are reviewed or alerted on
- Logging enabled but retained for a few days only
- Clocks not synchronised so events cannot be correlated
- Logs collected but never examined
- Key components such as the directory and the gateway not logged
Define and apply a backup policy covering the critical components of the information system, and verify that restoration works.
- Backup policy stating scope, frequency and retention
- Backup job success reports
- Restoration test records with dates and outcomes
- Evidence that at least one copy is held offline or otherwise isolated
- Backups run but restoration never tested
- Backup copies reachable from the production network
- Critical systems missing from the backup scope
- Retention shorter than the time needed to detect a compromise
Carry out regular security checks and audits of the information system and apply the corrective actions that they identify.
- Audit and control plan with the scope and frequency
- Audit reports including any carried out by a qualified provider
- Corrective action plan with owners and dates
- Evidence of closure of the actions raised
- Audits performed but findings not tracked to closure
- No plan setting out what is audited and how often
- Scope limited to a single system year after year
Designate a person responsible for information system security and make that role known to the staff.
- Appointment record naming the security officer
- Role description and reporting line
- Communication to staff announcing the role and how to contact it
- Evidence the officer is involved in projects and incidents
- Role held informally by an IT team member with no mandate
- Staff unaware whom to contact
- No role description or reporting line
Define a procedure for managing security incidents, covering how they are reported, handled and closed.
- Documented incident management procedure with roles and escalation
- Incident register with classification and closure
- Reporting channel communicated to staff
- Post incident review records and the resulting actions
- Procedure exists but staff do not know how to report
- No incident register
- Incidents closed without a review or lessons captured
ANSSI Hygiene V: Secure the Network (measures 19 to 26)
Segment the network into zones and enforce partitioning between them so that a compromise in one zone does not extend to the whole information system.
- Network segmentation design with the zones and their trust levels
- Filtering rules between zones
- Review evidence that the rules match the design
- Diagram showing where sensitive systems sit
- Flat network with a perimeter firewall only
- Segmentation designed but rules permit any to any between zones
- No periodic rule review
Secure the Wi-Fi access networks and separate the different uses so that guest and internal access do not share the same network.
- Wi-Fi configuration standard including the authentication and encryption used
- Separate guest network configuration
- Access point inventory
- Records of periodic review of the wireless estate
- Guest and corporate traffic on the same wireless network
- Pre shared keys never rotated
- Rogue access points not detected
Use the secure version of a protocol wherever one exists, in place of the unprotected equivalent.
- Protocol standard listing permitted and prohibited protocols
- Scan results showing use of unprotected protocols
- Migration plan and exception register
- Configuration evidence for the migrated services
- Legacy unprotected protocols left enabled alongside the secure version
- No scanning to detect their use
- Exceptions carried indefinitely
Route outbound internet access through a secure gateway that filters and logs the traffic.
- Gateway architecture and filtering policy
- Logs demonstrating traffic passes through the gateway
- Rules preventing direct outbound access that bypasses the gateway
- Category and content filtering configuration
- Direct outbound routes bypass the gateway
- Gateway present but not logging
- Filtering policy never reviewed
Place services visible from the internet in a partitioned zone separated from the rest of the information system.
- Inventory of internet facing services
- Demilitarised zone design and its filtering rules
- Evidence that internet facing servers hold no direct route to the internal network
- Exposure review records
- Internet facing server joined to the internal domain
- No inventory of exposed services
- Filtering permits the exposed zone to reach internal systems freely
Protect the professional mail service, including filtering of malicious content and protection of the mail flows.
- Mail filtering configuration for malicious attachments and links
- Sender authentication records for the domains used
- Encryption configuration on mail transport
- Statistics on blocked messages
- No filtering of executable attachments
- Sender authentication records absent or set to a permissive policy
- Mail transport unencrypted
Secure the dedicated network interconnections established with partners so that partner access is limited and controlled.
- Register of partner interconnections with the business owner
- Filtering rules limiting each partner to the agreed resources
- Security clauses in the partner agreement
- Periodic review of the interconnections
- Partner links terminate directly on the internal network
- No register of active interconnections
- Links remain after the partnership ends
Control and protect physical access to server rooms and technical areas.
- Access list for server rooms and technical areas
- Badge or key issue and return records
- Access log review evidence
- Visitor escort procedure for technical areas
- Access list not reviewed and includes departed staff
- Physical access logs never reviewed
- Technical areas used for general storage with uncontrolled access
ANSSI Hygiene VI: Secure Administration (measures 27 to 29)
Prohibit internet access from the workstations and servers used to administer the information system.
- Filtering rules blocking outbound internet from administration systems
- Inventory of administration workstations and servers
- Evidence that mail and web browsing are not available on those systems
- Exception register with compensating controls
- Administrators browse the web and read mail from the administration workstation
- Rule exists but exceptions are widespread
- No inventory identifying which systems are administration systems
Use a dedicated and partitioned network for administration of the information system.
- Administration network design and its partitioning
- Evidence that administration protocols are carried only on that network
- Access path documentation including any jump host
- Review records for the administration network rules
- Administration performed over the general user network
- Jump host bypassed by direct connections
- Design documented but not enforced by filtering
Limit administration rights on workstations to what operational need requires.
- Report of accounts holding local administrator rights on workstations
- Justification and approval for each remaining grant
- Periodic review of local administrator membership
- Privilege elevation mechanism for tasks that require it
- Users routinely hold local administrator rights
- Grants made for a temporary need and never withdrawn
- No reporting of local administrator membership
ANSSI Hygiene VII: Manage Mobile Working (measures 30 to 33)
Apply physical security measures to mobile terminals so that loss or theft is prevented or its effect limited.
- Mobile device issue register
- Physical protection guidance issued to travelling staff
- Loss and theft reporting procedure and its records
- Privacy screen or cable lock provision where applicable
- No register of which devices are held by whom
- Loss and theft not reported through a defined route
- Travel guidance not issued
Encrypt sensitive data, in particular on equipment that could be lost or stolen, so that the data remains protected if the device leaves the entity control.
- Disk encryption coverage report for laptops and mobile devices
- Encryption standard and recovery key management
- Evidence of encryption on removable media used for sensitive data
- Exception register
- Encryption enabled on new devices only
- Recovery keys not escrowed
- Removable media excluded from the encryption requirement
Secure the network connection of workstations used away from the entity premises, so that traffic is protected when untrusted networks are used.
- Remote access architecture and its configuration
- Evidence that remote traffic is tunnelled and authenticated
- Policy on the use of public and untrusted networks
- Logs of remote connections
- Remote workers connect to services directly without a protected tunnel
- Split tunnelling permitted without assessment
- Remote connection logs not retained
Adopt security policies specific to mobile terminals such as smartphones and tablets, covering their configuration and the data they hold.
- Mobile device policy and the enforced configuration profile
- Enrolment records showing devices under management
- Remote wipe capability and its test evidence
- Application control rules for managed devices
- Mobile devices access corporate mail without any enforced policy
- Personal devices unmanaged but permitted
- Remote wipe never tested
ANSSI Hygiene VIII: Keep the Information System Up to Date (measures 34 and 35)
Define a policy for updating the components of the information system and apply it so that corrections are deployed within defined timescales.
- Patch and update policy stating timescales by criticality
- Deployment reports for operating systems and applications
- Exception register for components that cannot be updated
- Vulnerability scan results demonstrating the outcome
- Policy states timescales that are not measured
- Third party applications outside the patching process
- Exceptions recorded without compensating controls
Anticipate the end of maintenance of software and systems and limit software dependencies so that unsupported components are identified and dealt with before support ends.
- Register of components with their end of support dates
- Migration or replacement plan for components approaching end of support
- Isolation measures for components kept beyond end of support
- Record of software dependencies constraining upgrades
- Unsupported operating systems discovered only after an incident
- No register of end of support dates
- Dependencies on obsolete components undocumented
ANSSI Hygiene X: Going Further (measures 41 and 42)
Conduct a formal risk analysis of the information system so that the security measures applied follow from the risks identified.
- Risk analysis report with the method used
- Risk register with treatment decisions and owners
- Evidence that the security measures trace back to identified risks
- Record of review of the analysis after significant change
- Measures selected from a checklist with no risk basis
- Risk analysis performed once and never revisited
- Treatment decisions recorded without an owner
Prefer, where the need arises, products and services that carry an ANSSI qualification, drawing on the published catalogue of qualified products and service providers.
- Procurement standard referring to the qualified products and providers catalogue
- Record of the qualification status of security products and providers in use
- Justification where a non qualified product or provider was selected
- Qualification status never considered during procurement
- Security services bought without checking the provider qualification
- No record of the products in use and their status
Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does.