To gain certification, your organisation needs to implement five core controls: secure internet gateways or firewalls, secure configuration of devices, access control to limit user privileges, malware protection, and a strong approach to applying software updates and patches promptly.
