← Back to Library
ANSSI

ANSSI 40 Essential Measures (v2.0)

Full Name:
French National Cybersecurity Agency (ANSSI)
Acronym:
ANSSI
Type:
Cyber Hygiene Standard
Organization:
Agence nationale de la sécurité des systèmes d'information (ANSSI)
Version:
2
Year Published:
2017
Popularity:
Low

Overview of ANSSI 40 Essential Measures v2.0

ANSSI published version 2.0 of the 40 Essential Measures in 2017, updating and expanding the original 2013 guidance to address evolving cyber threats, emerging technologies, and lessons learned from major cyber incidents. The updated framework maintains the practical, cost-effective approach of the original while incorporating guidance on cloud computing security, mobile device management, ransomware prevention, IoT security, and supply chain risk management. Version 2.0 reflects the dramatically changed threat landscape of 2017, including widespread ransomware campaigns, state-sponsored attacks, and sophisticated phishing operations.

The 2017 update emphasizes defense-in-depth strategies, recognizing that no single control prevents all attacks. Organizations must implement layered defenses across people, processes, and technology domains. ANSSI v2.0 also places greater emphasis on detection and response capabilities, acknowledging that prevention alone is insufficient against determined adversaries. The updated measures provide more prescriptive implementation guidance compared to the original version, including specific technical configurations and operational procedures that organizations can adopt directly.

Key Enhancements Over Version 1.0

While maintaining the core structure of 40 essential measures, version 2.0 introduces significant enhancements reflecting four years of threat evolution and implementation experience.

Cloud Security Guidance

Version 2.0 includes extensive guidance on securing cloud services, recognizing widespread enterprise adoption of SaaS, IaaS, and PaaS. New measures address cloud provider selection and due diligence, data sovereignty and location controls, encryption of data stored in cloud environments, secure API authentication and authorization, cloud access security broker (CASB) deployment for visibility and control, and regular review of cloud service configurations. Organizations must understand shared responsibility models and implement appropriate controls for their portions of the security responsibility.

Mobile Device Management

The proliferation of smartphones and tablets accessing corporate data necessitated new mobile security measures. Version 2.0 requires mobile device management (MDM) solutions that enforce security policies, separate corporate and personal data through containerization, enable remote wipe capabilities for lost or stolen devices, require device encryption and strong authentication, maintain current mobile operating systems and applications, and restrict installation of unvetted applications. The framework recognizes both corporate-owned and employee-owned (BYOD) device scenarios with appropriate controls for each.

Ransomware Prevention and Recovery

Responding to the explosion of ransomware attacks between 2013-2017, version 2.0 emphasizes ransomware-specific controls including offline or air-gapped backup storage that ransomware cannot access, application whitelisting preventing unauthorized executable code, email attachment filtering blocking high-risk file types, network segmentation limiting ransomware spread, user training on ransomware delivery mechanisms, and tested incident response procedures for ransomware scenarios. The framework stresses that paying ransoms should never be plan A—effective backups and incident response capabilities enable recovery without payment.

Enhanced Security Monitoring

Version 2.0 expands security monitoring requirements, advocating for Security Operations Center (SOC) capabilities scaled appropriately to organization size. Enhanced measures include centralized logging of security events from all systems, automated correlation and analysis of logs to identify attack patterns, threat intelligence integration to recognize indicators of compromise, 24/7 monitoring for critical systems (or engagement of MSSPs for after-hours coverage), defined escalation procedures from detection through response, and regular testing of detection capabilities through simulated attacks. The framework recognizes that many successful breaches persist for weeks or months undetected—effective monitoring reduces dwell time significantly.

Supply Chain Security

High-profile supply chain compromises prompted new guidance on third-party risk management. Version 2.0 requires documented inventory of all third-party service providers and software suppliers, security assessments of vendors before engagement, contractual requirements for vendor security practices and incident notification, restrictions on vendor remote access to corporate environments, and monitoring of software updates for unexpected or malicious changes. Organizations should recognize that adversaries increasingly target vulnerable supply chain partners as pathways to ultimate targets.

Implementation Priorities for Version 2.0

Organizations already implementing version 1.0 should prioritize new or enhanced measures addressing their most significant risk exposures. Cloud-dependent organizations should focus on cloud security controls, mobile-heavy environments should prioritize MDM, and organizations experiencing ransomware threats should emphasize backup and recovery enhancements.

Assess Cloud and Mobile Posture: Conduct comprehensive assessments of cloud service usage (including shadow IT), mobile device access to corporate data, and current security controls. Gap analyses against v2.0 cloud and mobile measures identify priorities for remediation. Organizations often discover undocumented cloud services and unmanaged mobile devices during these assessments—bring shadow IT under management before attempting advanced controls.

Harden Backup Infrastructure: Ransomware's targeting of backups makes backup hardening a top priority. Implement offline backup copies, test restoration procedures quarterly, ensure backups cover all critical systems and data, and document recovery procedures. Organizations should assume adversaries will attempt to destroy backups—immutable storage prevents deletion even with administrative credentials. Calculate and document recovery time objectives (RTOs) and recovery point objectives (RPOs) to set stakeholder expectations.

Expand Security Monitoring: Organizations with basic logging should expand to comprehensive security monitoring with correlation, alerting, and investigation capabilities. Start with critical assets (internet-facing systems, authentication services, data repositories) before expanding to full enterprise coverage. Consider managed security service providers (MSSPs) or managed detection and response (MDR) providers if internal 24/7 SOC capabilities are not feasible. Effective monitoring requires both technology and processes—define runbooks for investigating common alert types.

Implement Vendor Risk Management: Document all vendors with access to corporate systems or data, categorize by risk level, and require security attestations or certifications (SOC 2, ISO 27001) for high-risk vendors. Implement vendor risk assessment processes for new vendor engagements and periodic reassessments for existing vendors. Vendor risks often receive insufficient attention until supply chain compromises occur—proactive management prevents surprises.

Framework Applicability and Adoption

ANSSI version 2.0 targets the same broad audience as the original—French organizations across all sectors and sizes seeking pragmatic cybersecurity guidance. The enhanced measures make v2.0 particularly valuable for organizations that have implemented v1.0 fundamentals and seek to advance their security maturity. While originally published in French for domestic audiences, English translations and international recognition have made ANSSI measures valuable globally.

The framework aligns with European Union cybersecurity initiatives including the NIS Directive (Network and Information Security Directive) and GDPR (General Data Protection Regulation). French organizations subject to these regulations find ANSSI measures provide practical implementation guidance supporting compliance. Version 2.0's cloud security guidance specifically addresses GDPR requirements for processor selection and data protection impact assessments.

Relationship to Other Frameworks and Standards

ANSSI v2.0 maintains strong alignment with international frameworks while providing French-specific context and recommendations. The measures map comprehensively to ISO 27001 Annex A controls with v2.0's cloud and mobile guidance particularly relevant to ISO 27017 (cloud) and ISO 27001 (mobile) standards. The NIST Cybersecurity Framework aligns closely with ANSSI measures across Identify, Protect, Detect, Respond, and Recover functions.

Organizations can reference related frameworks including ANSSI v1.0 for foundational guidance, CIS Controls for detailed technical control implementation, ACSC Essential Eight for similar risk-based prioritization approaches, and NIST SP 800-171 for controlled information protection in cloud and mobile contexts.

Frequently Asked Questions

Should organizations implement ANSSI v1.0 or v2.0?

Organizations should implement version 2.0, which supersedes v1.0 with updated guidance addressing modern threats and technologies. Version 2.0 maintains all fundamental measures from v1.0 while adding critical capabilities for cloud, mobile, ransomware, and supply chain scenarios. Organizations that implemented v1.0 should assess v2.0 enhancements and implement relevant updates based on their technology environment and threat exposure.

How does ANSSI v2.0 address GDPR compliance?

ANSSI v2.0's security measures support GDPR's requirement for "appropriate technical and organizational measures" to protect personal data. Specific measures addressing encryption, access control, backup and recovery, vendor management, and security monitoring directly satisfy GDPR security requirements. The framework's risk-based approach aligns with GDPR's principle of implementing security measures commensurate with risk. However, ANSSI focuses on cybersecurity while GDPR includes broader privacy requirements—organizations must address both for comprehensive compliance.

Does ANSSI v2.0 provide sufficient protection against ransomware?

ANSSI v2.0's ransomware-focused measures significantly reduce ransomware risk and enable recovery when prevention fails. Offline backups, application whitelisting, email filtering, and network segmentation create layered defenses that prevent most ransomware attacks. However, no framework guarantees complete ransomware prevention—determined adversaries with sophisticated techniques may still succeed. The framework's emphasis on tested backup restoration enables organizations to recover without paying ransoms, which is often more valuable than preventing all attacks.

Can ANSSI v2.0 be implemented in cloud-native organizations?

Yes, version 2.0 explicitly addresses cloud computing security with measures applicable to cloud-native organizations. The framework recognizes that traditional perimeter security concepts don't apply in cloud environments—instead emphasizing identity-centric security, data encryption, API security, and cloud-specific monitoring. Cloud-native organizations should focus on ANSSI's cloud security measures while adapting traditional network security measures to cloud contexts (security groups instead of firewalls, cloud access control instead of network segmentation).

What resources are needed to implement ANSSI v2.0?

Resource requirements vary significantly based on organization size and starting security posture. Small organizations can implement many measures through policy and process changes with minimal technology investment, leveraging cloud providers' built-in security capabilities. Larger organizations typically invest in security tools (MDM, SIEM, CASB, backup solutions), additional security personnel (1-3 FTEs per 500 employees is common), and professional services for implementation support. Budget allocations of 3-7% of IT spending for cybersecurity are typical for comprehensive implementation, though percentages vary by industry and risk profile.