Central Government departments and certain suppliers are required to carry out testing under the NCSC CHECK scheme to provide a greater level of assurance in the security of their technical systems. In the context of the NCSC CHECK scheme, the term “IT Health Check” means a penetration test with the following additional requirements:
- It must be carried out by an NCSC approved CHECK company.
- It must be led by an individual holding the CHECK Team Leader (CTL) qualification.
- All testers must hold at least CHECK Team Member (CTM) qualifications.
- All testers must hold at least SC clearance.
- Upon completion of the test, a copy of the report is sent to NCSC.
- Exploitation of identified vulnerabilities must be permitted.
The NCSC CHECK scheme is strictly limited to penetration testing. Other assurance activities such as build reviews, cloud configuration reviews or firewall reviews reviews cannot be performed under the CHECK scheme. If these are required then CODA can still perform them as a CHECK company - but this cannot be done under the CHECK scheme itself, and must be reported separately if performed alongside an NCSC CHECK IT Health Check.
NCSC define a specific set of areas that must be included in the scope for all CHECK tests, detailed in Annexes A and B of the Assured CHECK Scheme Standard document, and provide further guidance in the Buyer’s Guide.
Please note that the NCSC CHECK scheme is completely separate from the similarly named PSN IT Health Check scheme. If you are asked to carry out an “IT Health Check” and it’s not clear whether this should fall under the NCSC CHECK scheme, then please get in touch with us and we can review the requirements with you to establish the most appropriate type of security testing.