← Scale Technology Group Cyber Hygiene Emergency Measures Criteria Set · 4 levels · 13 control areas

Sectoral · SSB · TRTEST · Cyber Hygiene Emergency Measures Criteria Set

Cyber Hygiene Compliance and Certification Preparation Consultancy

Cyber Hygiene is not a document in the defense industry, but a condition for market entry

Created under the coordination of the Presidency of Defense Industries (SSB) and with the support of the Turkish Cyber Security Cluster, TRTEST Testing and Evaluation Inc. Cyber ​​Hygiene Certification Program carried out by; It is designed to ensure that main contractors and sub-suppliers (SMEs) in the defense industry ecosystem reach the minimum security level against cyber attacks.

With its official name «Cyber Hygiene Emergency Measures Criteria Set»These standards focus directly on field technical configurations and the operational resilience of the organization, rather than on paper documentation processes (such as ISO 27001). The auditor wants to see your device's setting, not your policy.

4
Maturity Level
13
Basic Control Area
A · B · C
Finding Class
1+ per year
Mandatory Penetration Test
Presidency of Defense Industries (SSB) Türkiye Cyber Security Cluster TRTEST Testing and Evaluation Inc. TSE Approved Penetration Test Obligation Main Contractor + Sub-Supplier Scope

Episode 01 · Evaluation Levels

Four maturity levels

Institutions are audited and certified for one of the following levels, depending on their goals and technological infrastructure. As the level increases, both the depth of control and the frequency of repetition increase; Therefore, choosing the target level correctly directly determines the cost and schedule of the project.

Awareness Level

Level 1

It is the entry level that shows that you are aware of basic security steps and that basic policies are written down. It is often the first target for SMEs new to the defense ecosystem.

Who is it suitable for?New or small-scale sub-suppliers who have joined the ecosystem
Penetration test periodAt least once a year

Basic Level

Level 2

This is the stage where security rules are not only written but also begin to be implemented technically. A certain cyber defense routine consisting of antivirus, backup and similar checks has been established.

Who is it suitable for?Suppliers who take regular orders, provide production or software
Penetration test periodAt least 2 times a year

Intermediate

level 3

It is an orderly and mature security environment where processes such as penetration tests, vulnerability scans, VPN and multi-factor authentication (MFA) are carried out proactively and at frequent intervals.

Who is it suitable for?Companies that produce critical subsystems and process confidential data
Discriminative controlProactive and iterative technical verification

Advanced Level

Level 4

It is the highest level where advanced security tools (SIEM, SOC, EDR), proactive threat hunting and continuous monitoring operations are used. Security is not a project here, but an uninterrupted operation.

Who is it suitable for?Main contractors and strategic program executors
Discriminative controlContinuous monitoring and threat hunting
The choice of target level is as much a commercial decision as it is a technical choice: the contractual terms of your main contractor, the degree of confidentiality of the data you process and the tenders you plan to enter are decisive. We determine the right level for your organization together in a free pre-evaluation session.

Chapter 02 · Audit Criteria

13 basic control areas

TRTEST auditors examine the digital footprint and devices of the institution under the following thirteen main headings. Cast below what is inspected shows; The current status of each area in your institution and its closing road map are the subject of the gap analysis study.

  • S1 · Asset Management«An unknown system cannot be protected» According to the rule, creating an up-to-date inventory of all hardware (server, computer, devices) and software connected to the network.
  • S2 · System Update and Patch ManagementUploading patches for security vulnerabilities in operating systems, servers and third-party software to the system without delay.
  • S3 · Authorization and Access ControlRequiring strong password policies; Mandatory use of VPN and multi-factor authentication (MFA/2FA) when connecting to the institution from untrusted external networks.
  • Q4 · Endpoint (Client) SecurityHaving up-to-date Anti-Virus/EDR on all computers, restricting unauthorized USB and removable media use, and turning off default administrator (Root) privileges on devices.
  • Q5 · Backup ManagementRegular backup of systems; Keeping at least one of the backups isolated from the corporate network, offline or in a different environment against ransomware and performing periodic restoration tests.
  • Q6 · Vulnerability Management and Security TestsThe most critical step of the standard: having regular penetration tests performed by authorized/TSE approved companies according to the level and proving that the gaps are closed.
  • Q7 · Risk ManagementThe institution determines the risk analysis methodology against cyber threats and carries out internal control activities.
  • Q8 · Awareness TrainingsAll personnel undergo cyber security/hygiene training at least once a year and unannounced phishing simulations are conducted to measure human error.
  • Q9 · System and Network Secure ConfigurationClear network topology, isolating internal and guest networks from each other, tightening firewall rules and using secure wireless networks (WPA2/WPA3).
  • Q10 · App and Web Secure ConfigurationEnabling HTTPS/SSL usage on websites, not having OWASP Top 10 vulnerabilities, and using Web Application Firewall (WAF).
  • Q11 · Security Monitoring and Records ManagementStoring trace records (logs) from firewalls and servers in accordance with legal periods and as unchangeable.
  • Q12 · Data Security and Email SecurityConfidential data only «need to know» staff accessibility (DLP); Complete setting of SPF, DKIM and DMARC verification records against email spoofing.
  • Q13 · Incident and Violation ManagementHaving an incident response procedure ready in case of an attack or violation; Immediate escalation commitment to the main contractor or directly to SSB in case of confidential data leak.

Chapter 03 · Red Lines

Class A (major) findings that are never compromised

In TRTEST audits, deficiencies are categorized as Class A, B and C. When auditors come to the organization, they look at real configurations rather than policies on paper. The following shortcomings immediate class A (major) finding counted; Unless these are closed, the institution cannot receive the certificate and therefore cannot participate in SSB tenders.

  • 01 · Ports left openRDP (Remote Desktop) on servers — 3389) or unnecessary ports that are left open to the outside world and can be easily exploited, such as Telnet.
  • 02 · Lack of email spoofing protectionSince phishing emails are most commonly used in supply chain attacks, SPF, DKIM and DMARC protocols are missing or incorrectly configured in DNS records.
  • 03 · Admin panels open to the outsideWebsite or server administrator login panels are fully open to the internet. These panels should only be accessible from the internal network via VPN or with IP restriction.
  • 04 · Not having a penetration testIncomplete penetration testing within the required periods or failure to prove that critical and high-risk vulnerabilities in the report have been closed.
  • 05 · Default passwordsThe factory passwords of the devices on the network («admin/admin», «root/12345» etc.) letting go.
Attention: All five of these topics are not an expensive security investment correct configuration requires. Preliminary inspection of these items before entering the audit largely prevents delays in certification due to major findings.

In summary

It requires operational discipline, not standard expensive equipment

TRTEST Cyber Hygiene Standards do not require institutions to purchase overly expensive cyber security devices; know the map of its network, protect its e-mail, lock its doors (ports), make timely updates, take offline backups and train its employees. demands. It is an extremely vital protection shield based on operational discipline.

Know your network

An institution without an inventory cannot know what it is protecting or what remains open. (S1, S9)

lock the doors

Open ports, exposed admin panels and default passwords are the fastest exploited vulnerabilities. (S3, S4, S9)

Reserve your backup

The only real insurance against ransomware is a restore-tested backup isolated from the network. (S5)

train your people

The starting point for supply chain attacks is often a phishing email. (S8, S12)

Roadmap with Scale

We set up the path to the document in a single program

TRTEST/SSB issues the Cyber Hygiene Certificate; Scale prepares for this audit and produces the technical assurance that the audit demands.

01

Gap Analysis and Target Level

Baseline assessment in all 13 control areas, preliminary screening for class A findings and closure plan prioritized by target level. Service detail →

02

TS 13638 Penetration Test

Penetration testing, which is a mandatory condition for certification, is carried out by our TSE approved and TS 13638 certified staff; The closure of the findings is proven by retesting. Service detail →

03

Post-Document Operation

The document is not a photograph, it is a maintained routine. Periodic testing, training, phishing drills and keeping the evidence file up to date. Service detail →

In accordance with the principle of independence, penetration testing is planned separately from the consultancy team. For the national cyber security regime (Law no. 7545, SOME and violation notification) to which defense industry companies are subject in addition to SSB / MSB requirements Defense Industry page see

Free Pre-Assessment

Which level and with which calendar are you ready?

First, see your coverage with the online Liability Map tool; Then, let's clarify the target level and closing schedule together in an expert session.

Create My Liability Map Request Expert Session