Sectoral · SSB · TRTEST · Cyber Hygiene Emergency Measures Criteria Set
Cyber Hygiene Compliance and Certification Preparation Consultancy
Cyber Hygiene is not a document in the defense industry, but a condition for market entry
Created under the coordination of the Presidency of Defense Industries (SSB) and with the support of the Turkish Cyber Security Cluster, TRTEST Testing and Evaluation Inc. Cyber Hygiene Certification Program carried out by; It is designed to ensure that main contractors and sub-suppliers (SMEs) in the defense industry ecosystem reach the minimum security level against cyber attacks.
With its official name «Cyber Hygiene Emergency Measures Criteria Set»These standards focus directly on field technical configurations and the operational resilience of the organization, rather than on paper documentation processes (such as ISO 27001). The auditor wants to see your device's setting, not your policy.
Episode 01 · Evaluation Levels
Four maturity levels
Institutions are audited and certified for one of the following levels, depending on their goals and technological infrastructure. As the level increases, both the depth of control and the frequency of repetition increase; Therefore, choosing the target level correctly directly determines the cost and schedule of the project.
Awareness Level
Level 1It is the entry level that shows that you are aware of basic security steps and that basic policies are written down. It is often the first target for SMEs new to the defense ecosystem.
Basic Level
Level 2This is the stage where security rules are not only written but also begin to be implemented technically. A certain cyber defense routine consisting of antivirus, backup and similar checks has been established.
Intermediate
level 3It is an orderly and mature security environment where processes such as penetration tests, vulnerability scans, VPN and multi-factor authentication (MFA) are carried out proactively and at frequent intervals.
Advanced Level
Level 4It is the highest level where advanced security tools (SIEM, SOC, EDR), proactive threat hunting and continuous monitoring operations are used. Security is not a project here, but an uninterrupted operation.
Chapter 02 · Audit Criteria
13 basic control areas
TRTEST auditors examine the digital footprint and devices of the institution under the following thirteen main headings. Cast below what is inspected shows; The current status of each area in your institution and its closing road map are the subject of the gap analysis study.
- S1 · Asset Management«An unknown system cannot be protected» According to the rule, creating an up-to-date inventory of all hardware (server, computer, devices) and software connected to the network.
- S2 · System Update and Patch ManagementUploading patches for security vulnerabilities in operating systems, servers and third-party software to the system without delay.
- S3 · Authorization and Access ControlRequiring strong password policies; Mandatory use of VPN and multi-factor authentication (MFA/2FA) when connecting to the institution from untrusted external networks.
- Q4 · Endpoint (Client) SecurityHaving up-to-date Anti-Virus/EDR on all computers, restricting unauthorized USB and removable media use, and turning off default administrator (Root) privileges on devices.
- Q5 · Backup ManagementRegular backup of systems; Keeping at least one of the backups isolated from the corporate network, offline or in a different environment against ransomware and performing periodic restoration tests.
- Q6 · Vulnerability Management and Security TestsThe most critical step of the standard: having regular penetration tests performed by authorized/TSE approved companies according to the level and proving that the gaps are closed.
- Q7 · Risk ManagementThe institution determines the risk analysis methodology against cyber threats and carries out internal control activities.
- Q8 · Awareness TrainingsAll personnel undergo cyber security/hygiene training at least once a year and unannounced phishing simulations are conducted to measure human error.
- Q9 · System and Network Secure ConfigurationClear network topology, isolating internal and guest networks from each other, tightening firewall rules and using secure wireless networks (WPA2/WPA3).
- Q10 · App and Web Secure ConfigurationEnabling HTTPS/SSL usage on websites, not having OWASP Top 10 vulnerabilities, and using Web Application Firewall (WAF).
- Q11 · Security Monitoring and Records ManagementStoring trace records (logs) from firewalls and servers in accordance with legal periods and as unchangeable.
- Q12 · Data Security and Email SecurityConfidential data only «need to know» staff accessibility (DLP); Complete setting of SPF, DKIM and DMARC verification records against email spoofing.
- Q13 · Incident and Violation ManagementHaving an incident response procedure ready in case of an attack or violation; Immediate escalation commitment to the main contractor or directly to SSB in case of confidential data leak.
Chapter 03 · Red Lines
Class A (major) findings that are never compromised
In TRTEST audits, deficiencies are categorized as Class A, B and C. When auditors come to the organization, they look at real configurations rather than policies on paper. The following shortcomings immediate class A (major) finding counted; Unless these are closed, the institution cannot receive the certificate and therefore cannot participate in SSB tenders.
- 01 · Ports left openRDP (Remote Desktop) on servers — 3389) or unnecessary ports that are left open to the outside world and can be easily exploited, such as Telnet.
- 02 · Lack of email spoofing protectionSince phishing emails are most commonly used in supply chain attacks, SPF, DKIM and DMARC protocols are missing or incorrectly configured in DNS records.
- 03 · Admin panels open to the outsideWebsite or server administrator login panels are fully open to the internet. These panels should only be accessible from the internal network via VPN or with IP restriction.
- 04 · Not having a penetration testIncomplete penetration testing within the required periods or failure to prove that critical and high-risk vulnerabilities in the report have been closed.
- 05 · Default passwordsThe factory passwords of the devices on the network («admin/admin», «root/12345» etc.) letting go.
In summary
It requires operational discipline, not standard expensive equipment
TRTEST Cyber Hygiene Standards do not require institutions to purchase overly expensive cyber security devices; know the map of its network, protect its e-mail, lock its doors (ports), make timely updates, take offline backups and train its employees. demands. It is an extremely vital protection shield based on operational discipline.
Know your network
An institution without an inventory cannot know what it is protecting or what remains open. (S1, S9)
lock the doors
Open ports, exposed admin panels and default passwords are the fastest exploited vulnerabilities. (S3, S4, S9)
Reserve your backup
The only real insurance against ransomware is a restore-tested backup isolated from the network. (S5)
train your people
The starting point for supply chain attacks is often a phishing email. (S8, S12)
Roadmap with Scale
We set up the path to the document in a single program
TRTEST/SSB issues the Cyber Hygiene Certificate; Scale prepares for this audit and produces the technical assurance that the audit demands.
01
Gap Analysis and Target Level
Baseline assessment in all 13 control areas, preliminary screening for class A findings and closure plan prioritized by target level. Service detail →
02
TS 13638 Penetration Test
Penetration testing, which is a mandatory condition for certification, is carried out by our TSE approved and TS 13638 certified staff; The closure of the findings is proven by retesting. Service detail →
03
Post-Document Operation
The document is not a photograph, it is a maintained routine. Periodic testing, training, phishing drills and keeping the evidence file up to date. Service detail →
Free Pre-Assessment
Which level and with which calendar are you ready?
First, see your coverage with the online Liability Map tool; Then, let's clarify the target level and closing schedule together in an expert session.