|
Revisions: |
||
|
Date: |
Author: |
Description: |
|
March 2020 |
Emma Philpott |
First Version Published |
1 Introduction
1.1 This Schedule sets out:
1.1.1 NCSC’s requirements for the provision of Management Information (MI) from both the Cyber Essentials Partner and Certification Bodies; and
1.1.2 The Key Performance Indicators (KPIs) to be met by the Certification Bodies and/or the Cyber Essentials Partner and reported on by the Cyber Essentials Partner.
1.2 The CB shall provide to the CE Partner all the information set out below on a monthly basis in the Cyber Essentials Management Report.
2 Management Information (MI)
2.1 The Cyber Essentials Partner shall ensure that appropriate records and management information relating to the operation of the Cyber Essentials Scheme and delivery of the Partner Services are gathered and maintained in an industry recognised format, where applicable delegating responsibilities to the Certification Body. These records should include but may not be limited to the following:
2.2 Application Information: The Cyber Essentials Partner shall collect, maintain and report on information obtained from its Certification Bodies relating to applications from Organisations for Certification Services, including but not limited to:
i. Unique Business ID;
ii. The company name (aligned with Companies House or Charity Registration);
iii. The business sector;
iv. The number of employees in the company (denoting size);
v. Country/Town/City/Region & Postcode;
vi. Applicant Role;
vii. Certification Level;
viii. Certification Type (1st time/renewal);
ix. Application Status (Pass/Fail/Pending);
x. Certification Body;
xi. Scope of system to be certified
2.3 Certification Information: The Cyber Essentials Partner shall collect, maintain and report on information obtained from its Certification Bodies relating to the certification of Organisations, including but not limited to:
i. Unique Business ID;
ii. The company name (aligned with Companies House or Charity Registration);
iii. The business sector;
iv. The number of employees in the company (denoting size);
v. Country/Town/City/Region & Postcode;
vi. Applicant Role;
vii. Certification Level;
viii. Certification Type;
ix. Unique Certification ID;
x. Certification Body;
xi. Scope of system certified;
xii. Recommended renewal date.
2.4 Customer Satisfaction Information: The Cyber Essentials Partner shall collect, maintain and report on customer satisfaction information obtained from Organisations via its Cyber Essentials Suppliers, including but not limited to:
i. Unique Business ID
ii. The company name (aligned with Companies House or Charity Registration);
iii. The business sector;
iv. Where they heard about the Cyber Essentials Scheme;
v. Why did they decide to engage with the Cyber Essentials Scheme;
vi. Cost of Certification;
vii. Feedback on how easy and intuitive they found the consumer journey;
viii. Comments on their experience in applying for Cyber Essentials;
ix. Comments on their experience in using the Cyber Essentials Scheme.
2.5 Reasons for Failure: The Cyber Essentials Partner shall collect and provide to NCSC anonymised information on ‘reasons for failure’ of Organisations to achieve Cyber Essentials and/or Cyber Essentials Plus certification.
2.6 Additional Feedback: The Cyber Essentials Partner shall collect, maintain and report on the following information obtained from its Certification Bodies:
i. Common vulnerabilities;
ii. Common attacks.
iii. Organisations that haven’t chosen to renew
2.7 Web Stats: The Cyber Essentials Partner shall collect, maintain and report on the following information obtained from its website statistics, including but not limited to:
i. Sessions;
ii. Bounce rate/time spent on site;
iii. Site content;
iv. Dwell time analytics;
v. How many people are going through to use the Certification Search function;
vi. How many people are clicking through to “Getting Certified”;
vii. Where traffic to the website has arrived from.
3 Key Performance Indicators (KPIs)
3.1 The Cyber Essentials Partner shall work with NCSC during Transition to agree appropriate KPIs and/or service levels to be used to monitor the performance of the Cyber Essentials Partner and the Certification Bodies in relation to the Cyber Essentials Scheme. Such KPIs and service levels may include measures of performance relating to:
-
Management of Certification Body Relationships
-
Improvements to the Service;
-
Resolution of complaints;
-
Timeliness and quality of monthly reporting