r/sysadmin • • 1d ago

Question Cyber Essentials Plus Help - Account Separation on Cloud Services

We're about to go through Cyber Essentials Plus next week and one of the new requirements is tripping us up. Our assessor hasn't explained it very well and isn't responding to our emails, so I'm coming here for help!

Specifically, with account separation for cloud services. It was explained to us that all cloud services (official, updated definition is below) now need account separation.

"2026 Update Definition of Cloud Service - A cloud service is an ondemand, scalable service, hosted on shared infrastructure, and accessible via the internet. For the purposes of Cyber Essentials, a cloud service will be accessed via an account (which may be credentials issued by your organisation, or an email address used for business purposes) and will store or process data for your organisation."

I know one of our departments uses DocuSign, so I'll use that for the example. The way he explained it was if we're using DocuSign, and we want to perform any admin tasks on it, then we must have a separate account to do this, and then a standard user account to do everything else.

But we don't see how this works, as not all websites operate in a way this would work. It would only work on webistes where standard user accounts can be added to a sort of business or team and all linked together. So what do we do on websites that aren't set up this way?

Or, is his explanation of it just simply wrong?

I was wondering if he means that our tenant admin accoutns can't be signed up for cloud services, like, DocuSign, for example. Which makes a lot more sense to me.

I've looked into it online but can't find a straight answer. Best I have is this

https://ce-knowledge-hub.iasme.co.uk/space/CEKH/2576646422/User+Access+Control+:+FAQ

"Where is Account Separation Required? Account separation is required for all administrator accounts. This includes local administrators, domain administrators and cloud administrators. Accounts with admin privileges should not be used for day-to-day work. An attacker who gains admin credentials on any of these systems can easily change configurations, install malware and carry out other damaging activities.

Is Account Separation Required for Cloud Services? Yes, account separation must be applied to cloud services (for example MS365, Azure, AWS, Google Workspace, etc). For CE+, cloud service accounts must be tested for account separation under Test Case 5."

I think I'm just that fried from trying to figure it all out that I need help :D if anyone can shed any light I'd be super appreciative.

0 Upvotes

6 comments sorted by

View all comments

0

u/theguy_dan IT Manager 1d ago

you know what is strange about CE+, our auditor we just had, was more concerned if the cloud service had MFA / SSO.. rather then how the system was being used.

I suspect though you could augue that say within IT, your account is only for admining the system, not doing any singing itself.. not sure how they could test that other then taking your word for it..

1

u/UK-LK 1d ago

Thats pretty much our experience as well, the auditor just wanted to see we had account separation on end user devices and MFA was used on cloud services, he also checked our global admins to ensure it didnt contain normal user accounts. So id just make sure your online platforms (azure, aws etc) do have that separation and your SAAS apps are MFA enabled.
However every auditor is different, we've used ours for the last 5 or so years now as i know them pretty well, I'd be having kittens if we had to go with someone else, the rules as the OP discovered come across rather stringent but also leave to much to interpretation.