Evidence area

Cyber Essentials secure configuration evidence

Secure configuration is about turning off the things you don't need and locking down the things you do. Evidence needs to show a baseline applied to every in-scope device.

Where secure configuration evidence is thin

Many SMEs have sensible defaults but no written baseline. Without a documented standard, it's hard to prove every device is configured the same way.

Examples of secure configuration evidence

  • Device build / hardening baseline document
  • MDM (Intune, Jamf, Kandji) configuration profile export
  • Auto-lock and password length settings screenshot
  • List of unnecessary default accounts that have been disabled
  • Evidence that local admin and standard user accounts are separated
  • Auto-run / auto-play disabled on removable media

How Evaud helps

Baseline as evidence

Store your hardening baseline as a controlled document, with owners and review dates.

Linked to assets

Show which devices the baseline applies to via the asset register.

Annual reviews

Reminders prompt a refresh before renewal.

Frequently asked questions

Start building your Cyber Essentials evidence today.

Free to try. No credit card required.