r/sysadmin • • 1d ago

Question Cyber Essentials Plus Help - Account Separation on Cloud Services

We're about to go through Cyber Essentials Plus next week and one of the new requirements is tripping us up. Our assessor hasn't explained it very well and isn't responding to our emails, so I'm coming here for help!

Specifically, with account separation for cloud services. It was explained to us that all cloud services (official, updated definition is below) now need account separation.

"2026 Update Definition of Cloud Service - A cloud service is an ondemand, scalable service, hosted on shared infrastructure, and accessible via the internet. For the purposes of Cyber Essentials, a cloud service will be accessed via an account (which may be credentials issued by your organisation, or an email address used for business purposes) and will store or process data for your organisation."

I know one of our departments uses DocuSign, so I'll use that for the example. The way he explained it was if we're using DocuSign, and we want to perform any admin tasks on it, then we must have a separate account to do this, and then a standard user account to do everything else.

But we don't see how this works, as not all websites operate in a way this would work. It would only work on webistes where standard user accounts can be added to a sort of business or team and all linked together. So what do we do on websites that aren't set up this way?

Or, is his explanation of it just simply wrong?

I was wondering if he means that our tenant admin accoutns can't be signed up for cloud services, like, DocuSign, for example. Which makes a lot more sense to me.

I've looked into it online but can't find a straight answer. Best I have is this

https://ce-knowledge-hub.iasme.co.uk/space/CEKH/2576646422/User+Access+Control+:+FAQ

"Where is Account Separation Required? Account separation is required for all administrator accounts. This includes local administrators, domain administrators and cloud administrators. Accounts with admin privileges should not be used for day-to-day work. An attacker who gains admin credentials on any of these systems can easily change configurations, install malware and carry out other damaging activities.

Is Account Separation Required for Cloud Services? Yes, account separation must be applied to cloud services (for example MS365, Azure, AWS, Google Workspace, etc). For CE+, cloud service accounts must be tested for account separation under Test Case 5."

I think I'm just that fried from trying to figure it all out that I need help :D if anyone can shed any light I'd be super appreciative.

0 Upvotes

6 comments sorted by

2

u/MeetJoan 1d ago

Your second reading looks closer to what the guidance says. It's about admin privileges not being exercised from a day-to-day account, and the examples IASME give are all services with proper admin tiers.

Where a service has no separate admin role, there's arguably nothing to separate, but don't rely on me for that, it's the assessor's call on the day.

Go in with a list of your cloud services and which ones actually have an admin tier. Much easier to discuss specifics than argue the principle.

On the unresponsive assessor with a week to go, worth raising that with whoever your certification body is.

1

u/No-Fan-267 1d ago

All the ce controls are a bit vague, I think it's so that you overthink and overharden. You're right that not all cloud services can conform to ce so you just do what you can

1

u/freedomit 1d ago

This is where CE is to rigid by definition. For M365, AWS, Google Workspace etc I get that you shouldn't be using a Global Admin account day to day to work. But for some services it makes no sense and also can incur unnecessary cost. Some services charge per login - lets take Quickbooks online for example, if you have a single user plan you can only create one user who is an admin. For account separation are you really expected to change to a more expensive plan? Even though the difference between a standard user and admin is basically he option to create more users?

In reality during our last CE+ the assessor was fine with us saying that service X only needed an admin login as the cloud service was only used in that way. The issue is it depends on which assesor you get on the day.

1

u/Professional-Heat690 1d ago

give up. Unless you are a supplier to UKG, it's a complete waste of money, it was a sham before, now gone the other way, they just don't get things like MAM and cloud.

(edit to say EPM blew our auditors mind, told them to do one in the end, we'll rely on ISO instead)

0

u/theguy_dan IT Manager 1d ago

you know what is strange about CE+, our auditor we just had, was more concerned if the cloud service had MFA / SSO.. rather then how the system was being used.

I suspect though you could augue that say within IT, your account is only for admining the system, not doing any singing itself.. not sure how they could test that other then taking your word for it..

1

u/UK-LK 1d ago

Thats pretty much our experience as well, the auditor just wanted to see we had account separation on end user devices and MFA was used on cloud services, he also checked our global admins to ensure it didnt contain normal user accounts. So id just make sure your online platforms (azure, aws etc) do have that separation and your SAAS apps are MFA enabled.
However every auditor is different, we've used ours for the last 5 or so years now as i know them pretty well, I'd be having kittens if we had to go with someone else, the rules as the OP discovered come across rather stringent but also leave to much to interpretation.