[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"doc-detail-166382-en":3,"doc-seo-166382-105":30,"detail-sidebar-cat-1-en-105":91},{"code":4,"msg":5,"data":6},0,"success",{"doc_id":7,"user_id":8,"nickname":9,"user_avatar":10,"doc_module":11,"category_id":12,"category_name":13,"doc_title":14,"doc_description":15,"doc_content":16,"file_id":17,"file_url":18,"file_type":19,"file_size":20,"view_count":4,"is_deleted":4,"is_public":11,"is_downloadable":11,"audit_status":11,"page_count":21,"language":22,"language_code":23,"site_id":24,"html_lang":23,"table_of_contents":25,"faqs":26,"seo_title":27,"seo_description":15,"update_tm":28,"read_time":29},166382,1374391974468,"Eden","https://ap-avatar.wpscdn.com/davatar_29158cc5080c5b710cf443261637dec0",1,17,"Forms","CE-Plus Findings Template V2 - Test details and findings","The document provides an introduction for a Cyber Essentials Plus on-site vulnerability assessment report template. It explains how PASS/FAIL status is determined across the Cyber Essentials Plus Common Test Specification V1.2 and clarifies the purpose and scope of testing, including what is explicitly excluded such as APT-focused testing, complex application testing, database audits, and denial-of-service attacks. It also states that detailed findings and additional information are organized in later sections, including failings, action points, observations, and the overall conclusion.","\u0003\n\u000f\u0004\n\u0003Contents\n\u0013 TOC \\o \"1-3\" \\h \\z \\u \u0014\u0013 HYPERLINK \\l \"_Toc417035181\" \u00141. Introduction\t\u0013 PAGEREF _Toc417035181 \\h \u00143\u0015\u0015\n\u0013 HYPERLINK \\l \"_Toc417035182\" \u00141.1 Disclaimer\t\u0013 PAGEREF _Toc417035182 \\h \u00144\u0015\u0015\n\u0013 HYPERLINK \\l \"_Toc417035183\" \u00142. Certification Body Details\t\u0013 PAGEREF _Toc417035183 \\h \u00144\u0015\u0015\n\u0013 HYPERLINK \\l \"_Toc417035184\" \u00143. Client Details\t\u0013 PAGEREF _Toc417035184 \\h \u00144\u0015\u0015\n\u0013 HYPERLINK \\l \"_Toc417035185\" \u00144. Business Scope\t\u0013 PAGEREF _Toc417035185 \\h \u00146\u0015\u0015\n\u0013 HYPERLINK \\l \"_Toc417035186\" \u00144.1Target systems\t\u0013 PAGEREF _Toc417035186 \\h \u00146\u0015\u0015\n\u0013 HYPERLINK \\l \"_Toc417035187\" \u00145. Executive summary\t\u0013 PAGEREF _Toc417035187 \\h \u00147\u0015\u0015\n\u0013 HYPERLINK \\l \"_Toc417035188\" \u00145.1 Value added reporting\t\u0013 PAGEREF _Toc417035188 \\h \u00147\u0015\u0015\n\u0013 HYPERLINK \\l \"_Toc417035189\" \u00146 Test details and findings\t\u0013 PAGEREF _Toc417035189 \\h \u00147\u0015\u0015\n\u0013 HYPERLINK \\l \"_Toc417035190\" \u00146.1 Test 1 - External Vulnerability Scan for stated IP range\t\u0013 PAGEREF _Toc417035190 \\h \u00147\u0015\u0015\n\u0013 HYPERLINK \\l \"_Toc417035191\" \u00146.2 Test 2 – Email Binaries and Payloads\t\u0013 PAGEREF _Toc417035191 \\h \u00148\u0015\u0015\n\u0013 HYPERLINK \\l \"_Toc417035192\" \u00146.3 Test 3 – Web site page with URLs linking to binaries\t\u0013 PAGEREF _Toc417035192 \\h \u00149\u0015\u0015\n\u0013 HYPERLINK \\l \"_Toc417035193\" \u00146.4 Test 4 – Authenticated vulnerability scan of host(s)\t\u0013 PAGEREF _Toc417035193 \\h \u001410\u0015\u0015\n\u0013 HYPERLINK \\l \"_Toc417035194\" \u00146.5 Mobile Devices\t\u0013 PAGEREF _Toc417035194 \\h \u001411\u0015\u0015\n\u0013 HYPERLINK \\l \"_Toc417035195\" \u00147 Additional Information\t\u0013 PAGEREF _Toc417035195 \\h \u001413\u0015\u0015\n\u0013 HYPERLINK \\l \"_Toc417035196\" \u00147.1 Test 1 - External Vulnerability Scan for stated IP range\t\u0013 PAGEREF _Toc417035196 \\h \u001413\u0015\u0015\n\u0013 HYPERLINK \\l \"_Toc417035197\" \u00147.2 Test 2 – Email Binaries and Payloads\t\u0013 PAGEREF _Toc417035197 \\h \u001413\u0015\u0015\n\u0013 HYPERLINK \\l \"_Toc417035198\" \u00147.3 Test 3 – Web site page with URLs linking to binaries\t\u0013 PAGEREF _Toc417035198 \\h \u001413\u0015\u0015\n\u0013 HYPERLINK \\l \"_Toc417035199\" \u00147.4 Test 4 – Authenticated vulnerability scan of host(s)\t\u0013 PAGEREF _Toc417035199 \\h \u001414\u0015\u0015\n\u0013 HYPERLINK \\l \"_Toc417035200\" \u00147.5 Value added checks - internal\t\u0013 PAGEREF _Toc417035200 \\h \u001416\u0015\u0015\n\u0013 HYPERLINK \\l \"_Toc417035201\" \u00147.6 Value added checks – website (optional)\t\u0013 PAGEREF _Toc417035201 \\h \u001416\u0015\u0015\n\u0013 HYPERLINK \\l \"_Toc417035202\" \u00148 Summary of Failings, Action Points and Observations.\t\u0013 PAGEREF _Toc417035202 \\h \u001417\u0015\u0015\n\u0013 HYPERLINK \\l \"_Toc417035203\" \u00148.1 Failings\t\u0013 PAGEREF _Toc417035203 \\h \u001417\u0015\u0015\n\u0013 HYPERLINK \\l \"_Toc417035204\" \u00148.2 Action Points\t\u0013 PAGEREF _Toc417035204 \\h \u001417\u0015\u0015\n\u0013 HYPERLINK \\l \"_Toc417035205\" \u00148.3 Observations\t\u0013 PAGEREF _Toc417035205 \\h \u001417\u0015\u0015\n\u0013 HYPERLINK \\l \"_Toc417035206\" \u00149 Conclusion\t\u0013 PAGEREF _Toc417035206 \\h \u001418\u0015\u0015\n\u0015\u0004\n\u000f\nRevision history\n\u000f\n1. Introduction\nThank you for selecting [COMPANY NAME) to conduct the on-site vulnerability assessment against the Cyber Essentials Plus Common Test Specification V1.2\nA copy of the test specification can be found at the following web address:\nhttps://www.cesg.gov.uk/servicecatalogue/cyber-essentials/Pages/Scheme-Library.aspx\nIf the organisation is awarded a “fail” status for ANY test within this specification document, then it is deemed to have failed overall. Otherwise, a pass status is awarded.\nWe are pleased to say that the company, within the scope specified in section 4, has been awarded a PASS Status.\nUnfortunately, on this occasion, the company has been awarded a FAIL status.\nDetails of all failings and/or action points or can be found in section 7 of this report and these are summarised along with any observations to improve cyber security in section 8.\nThe overall conclusion can be found in section 9.\nSection 7.5 contains a random sample of tests that do not form part of the Common Test Specification v1.2 therefore only passes and action points are awarded in this section, however, as your company has attested to complying with them in the questionnaire you should quickly address any issues found.\nThe aim of the onsite vulnerability assessment is to identify easily exploitable vulnerabilities within an organisation’s Internet facing infrastructure and user workstati","cbCaitbEQEUzAEO9","https://ap.wps.com/l/cbCaitbEQEUzAEO9","docx",86045,19,"English","en",105,"# 1. Introduction\n## 1.1 Disclaimer\n# 2. Certification Body Details\n# 3. Client Details\n# 4. Business Scope\n## 4.1 Target systems\n# 5. Executive summary\n## 5.1 Value added reporting\n# 6. Test details and findings\n## 6.1 Test 1 - External Vulnerability Scan for stated IP range\n## 6.2 Test 2 – Email Binaries and Payloads\n## 6.3 Test 3 – Web site page with URLs linking to binaries\n## 6.4 Test 4 – Authenticated vulnerability scan of host(s)\n## 6.5 Mobile Devices\n# 7. Additional Information\n## 7.1 Test 1 - External Vulnerability Scan for stated IP range\n## 7.2 Test 2 – Email Binaries and Payloads\n## 7.3 Test 3 – Web site page with URLs linking to binaries\n## 7.4 Test 4 – Authenticated vulnerability scan of host(s)\n## 7.5 Value added checks - internal\n## 7.6 Value added checks – website (optional)\n# 8. Summary of Failings, Action Points and Observations.\n## 8.1 Failings\n## 8.2 Action Points\n## 8.3 Observations\n# 9. Conclusion","[{\"question\":\"How is the overall PASS or FAIL status determined in the assessment?\",\"answer\":\"A “fail” status for ANY test within the Cyber Essentials Plus specification results in an overall “fail”. Otherwise, a “pass” status is awarded.\"},{\"question\":\"What is the goal of the on-site vulnerability assessment?\",\"answer\":\"It identifies easily exploitable vulnerabilities in an organisation’s internet-facing infrastructure and user workstations that create high exposure to potential attackers with low skill requirements.\"},{\"question\":\"What activities are explicitly out of scope for the Cyber Essentials Plus testing?\",\"answer\":\"Advanced Persistent Threat-style targeting, complex application testing (thick client and web applications), database audits beyond trivial credential checks, and denial-of-service attacks in all forms are excluded.\"}]","CE-Plus Findings Template V2 - Test details and findings | DOCX",1788190488,7,{"code":4,"msg":31,"data":32},"ok",{"site_id":24,"language":23,"slug":33,"title":14,"keywords":34,"description":15,"schema_data":35,"social_meta":86,"head_meta":88,"extra_data":90,"updated_unix":28},"ce-plus-findings-template-v2-test-details-and-findings","",{"@graph":36,"@context":85},[37,54,68],{"@type":38,"itemListElement":39},"BreadcrumbList",[40,44,48,51],{"item":41,"name":42,"@type":43,"position":11},"https://docshare.wps.com","Home","ListItem",{"item":45,"name":46,"@type":43,"position":47},"https://docshare.wps.com/template/","Template",2,{"item":49,"name":13,"@type":43,"position":50},"https://docshare.wps.com/template/forms/",3,{"item":52,"name":14,"@type":43,"position":53},"https://docshare.wps.com/template/ce-plus-findings-template-v2-test-details-and-findings/166382/",4,{"url":52,"name":14,"@type":55,"author":56,"headline":14,"publisher":58,"fileFormat":61,"inLanguage":23,"description":15,"dateModified":62,"datePublished":62,"encodingFormat":61,"isAccessibleForFree":63,"interactionStatistic":64},"DigitalDocument",{"name":9,"@type":57},"Person",{"url":41,"name":59,"@type":60},"DocShare","Organization","application/vnd.openxmlformats-officedocument.wordprocessingml.document","2026-08-31",true,{"@type":65,"interactionType":66,"userInteractionCount":4},"InteractionCounter",{"@type":67},"ViewAction",{"@type":69,"mainEntity":70},"FAQPage",[71,77,81],{"name":72,"@type":73,"acceptedAnswer":74},"How is the overall PASS or FAIL status determined in the assessment?","Question",{"text":75,"@type":76},"A “fail” status for ANY test within the Cyber Essentials Plus specification results in an overall “fail”. Otherwise, a “pass” status is awarded.","Answer",{"name":78,"@type":73,"acceptedAnswer":79},"What is the goal of the on-site vulnerability assessment?",{"text":80,"@type":76},"It identifies easily exploitable vulnerabilities in an organisation’s internet-facing infrastructure and user workstations that create high exposure to potential attackers with low skill requirements.",{"name":82,"@type":73,"acceptedAnswer":83},"What activities are explicitly out of scope for the Cyber Essentials Plus testing?",{"text":84,"@type":76},"Advanced Persistent Threat-style targeting, complex application testing (thick client and web applications), database audits beyond trivial credential checks, and denial-of-service attacks in all forms are excluded.","https://schema.org",{"og:url":52,"og:type":87,"og:title":14,"og:site_name":59,"og:description":15},"article",{"robots":89,"canonical":52},"index,follow",{"doc_id":7,"site_id":24},{"code":4,"msg":5,"data":92},[93,98,103,108,113,118,121,126,131],{"id":94,"doc_module":11,"doc_module_name":46,"category_name":95,"show_sort_weight":96,"slug":97},11,"Presentations",90,"presentations",{"id":99,"doc_module":11,"doc_module_name":46,"category_name":100,"show_sort_weight":101,"slug":102},12,"Resumes",80,"resumes",{"id":104,"doc_module":11,"doc_module_name":46,"category_name":105,"show_sort_weight":106,"slug":107},14,"Invoices",70,"invoices",{"id":109,"doc_module":11,"doc_module_name":46,"category_name":110,"show_sort_weight":111,"slug":112},15,"Posters",60,"posters",{"id":114,"doc_module":11,"doc_module_name":46,"category_name":115,"show_sort_weight":116,"slug":117},16,"Social Media",50,"social-media",{"id":12,"doc_module":11,"doc_module_name":46,"category_name":13,"show_sort_weight":119,"slug":120},40,"forms",{"id":122,"doc_module":11,"doc_module_name":46,"category_name":123,"show_sort_weight":124,"slug":125},18,"Letters",30,"letters",{"id":127,"doc_module":11,"doc_module_name":46,"category_name":128,"show_sort_weight":129,"slug":130},21,"Paper Templates",5,"papers-templates",{"id":132,"doc_module":11,"doc_module_name":46,"category_name":133,"show_sort_weight":4,"slug":134},158,"General","general-158"]