@RichBartlett@infosec.exchange
2026-08-27 13:57 UTC
Does anyone with an understanding (if such is possible) or #cyberessentials explain how the IASME guidance (https://ce-knowledge-hub.iasme.co.uk/space/CEKH/2751561800/The+Cyber+Essentials+guide+to+working+with+contractors) says third party contractor devices are IN scope, and the NCSC infrastructure requirements for CE (https://www.ncsc.gov.uk/files/cyber-essentials-requirements-for-it-infrastructure-v3-3.pdf) page 12 table 2 says they're NOT in scope? I'd trust the NCSC more, and it's their standard ultimately, and unless I'm missing something here these two sources are contradicting each other.
Replies (0)
No replies.