Guide · Checklists

Ticking off CyberFundamentals Basic: the checklist for an office on Canvos

The CyberFundamentals framework of the Centre for Cybersecurity Belgium is the Belgian yardstick for NIS2 and for any organisation that wants to show the basics are in order. This checklist walks through the measures of the Basic level and shows per measure what Canvos handles by default, what you configure yourself and what falls outside the workplace. With a printable PDF.

Canvos · Checklists8 min readCyFun Basic · NIS2 · CCB · Checklist

CyberFundamentals (CyFun) has four levels: Small, Basic, Important and Essential. Basic is the level the CCB recommends for every organisation and the minimum for many NIS2 entities. It follows the five functions of the NIST framework: identify, protect, detect, respond and recover. Below is, per function, what Basic concretely asks and whether Canvos handles it for you. Three labels: built in is on by default or done with one setting, partly needs a choice or addition from you, your policy lies outside the workplace and remains your responsibility. Print the PDF and tick.

Checklist CyFun Basic on Canvos (PDF)Printable, with room for date and owner per measure.
Download the checklist

Step by stepThe five functions

1. Identify: know what you have 2. Protect: access, data, backup, awareness 3. Detect: see what happens 4. Respond: when things go wrong 5. Recover: back to work

1

Identify: know what you have

  • Inventory of users and access built in
    The user list in organisation management shows every account with role, status, storage and mailbox. Export as CSV for your inventory.
  • Inventory of devices partly
    Active sessions show device and browser per user. Laptops and phones themselves you keep in your own register.
  • Inventory of software and cloud services partly
    Canvos replaces mail, files, office suite, chat, meetings and password vault: one supplier on the list instead of six. Other software you keep inventorying yourself.
  • Policy and legal requirements your policy
    An information security policy, GDPR processing register and NIS2 registration at the CCB. See the checklist for the processing register.
  • Supplier risk built in
    Canvos runs in Europe with a Belgian provider, without a US parent company; the processing agreement and the location of the data are fixed.
2

Protect: access, data, backup, awareness

  • Identities and strong authentication (MFA) built in
    Two-factor authentication with authenticator app or hardware key per user; one login for all modules.
  • Least privilege and roles built in
    Roles & Apps decide who sees which module; company folders give rights per group.
  • Remote and mobile access built in
    Mobile policy with screen protection (biometric unlock and automatic locking follow in the app). Sessions can be ended remotely.
  • Data protected at rest and in transit built in
    TLS everywhere, encrypted backups (AES-256), data classification with labels, DLP on national register numbers and IBANs, sharing policy with password and expiry.
  • Backups made, kept and tested partly
    Daily encrypted backups with retention are one setting. The yearly restore test you plan and document yourself.
  • Secure baseline configuration and patching built in
    Servers, updates and security patches are managed by Canvos; executable files and attachments are blocked by default.
  • Removing access on departure built in
    Disabling one account closes mail, files, calendar, chat and vault at once; sessions expire.
  • Awareness and training your policy
    A yearly session on phishing and passwords remains necessary. The guides on this site can serve as training material.
  • Logs kept built in
    Login log and governance events, hashed and anchored daily, kept according to the retention policy.
3

Detect: see what happens

  • Events collected and correlated built in
    Every policy action in the evidence chain; export as CEF to a SIEM, or CSV and JSON.
  • Suspicious sign-ins built in
    New country or new IP is flagged, repeated failed attempts lock temporarily, approval may be required.
  • Malicious code partly
    Executable files and attachments are blocked and mail is filtered for spam and malware. Endpoint protection on laptops remains your choice.
  • Alerts to the right people built in
    Real-time alerts and a monthly compliance report to the addresses you set.
4

Respond: when things go wrong

  • Incident plan your policy
    Who calls whom, what is reported to the CCB within 24 and 72 hours. One page suffices for Basic; keep it in the vault.
  • Analysis: what happened built in
    Login log plus evidence chain reconstruct in minutes who shared or opened which file.
  • Containment built in
    End sessions, disable account, reset password, legal hold on affected files.
  • Communication and notification partly
    The export delivers the facts for the notification; the notifying itself and communication with those affected is yours.
5

Recover: back to work

  • Restore from backup built in
    Restorable yourself with your own key, without a ticket to a vendor.
  • Recovery plan and test partly
    Document who restores, where the key is and how long it may take. Test at least yearly.
  • Lessons and improvement your policy
    After an incident: what do we change in policy and settings? The compliance score shows the effect immediately.
What this means for you. Of the more than twenty measures of CyFun Basic, Canvos covers the majority fully or largely for your office environment, from day one and without extra tools. What remains is policy, awareness and your own devices: exactly the things a provider cannot do for you. The checklist is meant as a working document for the self-assessment in the CyFun portal and as evidence for your NIS2 file. For the levels Important and Essential more measures are added; there too Canvos delivers the logging and the evidence.

FAQFrequently asked questions

Is this an official CyFun assessment?

No. This is a practical translation of the Basic level to an office on Canvos. The official self-assessment is done in the CCB's CyFun portal; for Important and Essential, verification by an accredited body is required.

Does my organisation have to do this?

NIS2 entities must have a conformity assessment carried out; CyFun is the Belgian reference framework for it. Other organisations use Basic voluntarily as evidence for customers, insurers or tenders.

How long does it take to reach Basic with Canvos?

The technical measures are largely in place after setting up Canvos. Policy, training and the device inventory usually take a few days of work, spread over a few weeks.

Where do I find the evidence for the auditor?

Compliance report, login log and the export of the evidence chain in the Governance Center, plus the backup history. Everything can be downloaded and dated.

Related guidesRelated guides

Want to try it yourself?

Book a 20-minute demo, or set up your workspace today.

Book a demo