Scoping guide
Scoping cloud services under v3.3
How to find, record and review the cloud services your Cyber Essentials scope needs to cover.
6 min read
Start with how work actually happens
A cloud register built only from invoices will miss free tools and services bought on individual cards. Ask each team how it stores files, communicates, manages customers, processes payments, publishes content and shares data with suppliers.
Review browser bookmarks, single sign-on applications and finance records to catch services that interviews miss. The goal is a usable register, not a perfect procurement database.
What to record
Keep the fields focused on decisions the assessment needs. Avoid collecting credentials, recovery codes or other secrets.
- Service name, business purpose and accountable owner.
- Whether MFA is available natively or through federated sign-in.
- Whether MFA is enforced for administrators and all other users.
- How leavers are removed and access is reviewed.
Do not forget business social accounts
A company LinkedIn page, advertising account or other social presence may be operated through organisational accounts and process business data. Include these services in the discovery exercise and make ownership explicit.
Connect the register to access controls
The register becomes valuable when it drives action. Filter for services where MFA exists but is not enforced, stale administrators remain, or ownership is unclear. Resolve those exceptions and re-check them on a regular schedule.
The planned Kelvane Comply cloud services register will connect these records directly to the relevant readiness questions, so a gap cannot disappear behind a confident manual answer.