Files
old-riskletpy/controls.csv

12 KiB

1Safeguard IDNameDescription
21.1Establish and Maintain Detailed Enterprise Asset InventoryInventory and Control of Enterprise Assets
31.2Address Unauthorized AssetsInventory and Control of Enterprise Assets
41.3Utilize an Active Discovery ToolInventory and Control of Enterprise Assets
51.4Use Dynamic Host Configuration Protocol (DHCP) Logging to Update Enterprise Asset InventoryInventory and Control of Enterprise Assets
61.5Use a Passive Asset Discovery ToolInventory and Control of Enterprise Assets
72.1Establish and Maintain a Software InventoryInventory and Control of Software Assets
82.2Ensure Authorized Software is Currently SupportedInventory and Control of Software Assets
92.3Address Unauthorized SoftwareInventory and Control of Software Assets
102.4Utilize Automated Software Inventory ToolsInventory and Control of Software Assets
112.5Allowlist Authorized SoftwareInventory and Control of Software Assets
122.6Allowlist Authorized LibrariesInventory and Control of Software Assets
132.7Allowlist Authorized ScriptsInventory and Control of Software Assets
143.1Establish and Maintain a Data Management ProcessData Protection
153.2Establish and Maintain a Data InventoryData Protection
163.3Configure Data Access Control ListsData Protection
173.4Enforce Data RetentionData Protection
183.5Securely Dispose of DataData Protection
193.6Encrypt Data on End-User DevicesData Protection
203.7Establish and Maintain a Data Classification SchemeData Protection
213.8Document Data FlowsData Protection
223.9Encrypt Data on Removable MediaData Protection
233.10Encrypt Sensitive Data in TransitData Protection
243.11Encrypt Sensitive Data At RestData Protection
253.12Segment Data Processing and Storage Based on SensitivityData Protection
263.13Deploy a Data Loss Prevention SolutionData Protection
273.14Log Sensitive Data AccessData Protection
284.1Establish and Maintain a Secure Configuration ProcessSecure Configuration of Enterprise Assets and Software
294.2Establish and Maintain a Secure Configuration Process for Network InfrastructureSecure Configuration of Enterprise Assets and Software
304.3Configure Automatic Session Locking on Enterprise AssetsSecure Configuration of Enterprise Assets and Software
314.4Implement and Manage a Firewall on ServersSecure Configuration of Enterprise Assets and Software
324.5Implement and Manage a Firewall on End-User DevicesSecure Configuration of Enterprise Assets and Software
334.6Securely Manage Enterprise Assets and SoftwareSecure Configuration of Enterprise Assets and Software
344.7Manage Default Accounts on Enterprise Assets and SoftwareSecure Configuration of Enterprise Assets and Software
354.8Uninstall or Disable Unnecessary Services on Enterprise Assets and ApplicationsSecure Configuration of Enterprise Assets and Software
364.9Configure Trusted Domain Name System (DNS) Servers on Enterprise AssetsSecure Configuration of Enterprise Assets and Software
374.10Enforce Automatic Device Lockout on Portable End-User DevicesSecure Configuration of Enterprise Assets and Software
384.11Enforce Remote Wipe Capability on Portable End-User DevicesSecure Configuration of Enterprise Assets and Software
394.12Separate Enterprise Workspaces on Mobile End-User DevicesSecure Configuration of Enterprise Assets and Software
405.1Establish and Maintain an Inventory of AccountsAccount Management
415.2Use Unique PasswordsAccount Management
425.3Disable Dormant AccountsAccount Management
435.4Restrict Administrator Privileges to Dedicated Administrator AccountsAccount Management
445.5Establish and Maintain an Inventory of Service AccountsAccount Management
455.6Centralize Account ManagementAccount Management
466.1Establish an Access Granting ProcessAccess Control Management
476.2Establish an Access Revolving ProcessAccess Control Management
486.3Require MFA for Externally-Exposed ApplicationsAccess Control Management
496.4Require MFA for Remote Network AccessAccess Control Management
506.5Require MFA for Administrative AccessAccess Control Management
516.6Establish and Maintain an Inventory of Authentication and Authorization SystemsAccess Control Management
526.7Centralize Access ControlAccess Control Management
536.8Define and Maintain Role-Based Access ControlAccess Control Management
547.1Establish and Maintain a Vulnerability Management ProcessContinuous Vulnerability Management
557.2Establish and Maintain a Remediation ProcessContinuous Vulnerability Management
567.3Perform Automated Operating System Patch ManagementContinuous Vulnerability Management
577.4Perform Automated Application Patch ManagementContinuous Vulnerability Management
587.5Perform Automated Vulnerability Scans of Internal Enterprise AssetsContinuous Vulnerability Management
597.6Perform Automated Vulnerability Scans of Externally-Exposed Enterprise AssetsContinuous Vulnerability Management
607.7Remediate Detected VulnerabilitiesContinuous Vulnerability Management
618.1Establish and Maintain an Audit Log Management ProcessAudit Log Management
628.2Collect Audit LogsAudit Log Management
638.3Ensure Adequate Audit Log StorageAudit Log Management
648.4Standardize Time SynchronizationAudit Log Management
658.5Collect Detailed Audit LogsAudit Log Management
668.6Collect DNS Query Audit LogsAudit Log Management
678.7Collect URL Request Audit LogsAudit Log Management
688.8Collect Command-Line Audit LogsAudit Log Management
698.9Centralize Audit LogsAudit Log Management
708.10Retain Audit LogsAudit Log Management
718.11Conduct Audit Log ReviewsAudit Log Management
728.12Collect Service Provider LogsAudit Log Management
739.1Ensure Use of Only Fully Supported Browsers and Email ClientsEmail and Web Browser Protections
749.2Use DNS Filtering ServicesEmail and Web Browser Protections
759.3Maintain and Enforce Network-Based URL FiltersEmail and Web Browser Protections
769.4Restrict Unnecessary or Unauthorized Browser and Email Client ExtensionsEmail and Web Browser Protections
779.5Implement DMARCEmail and Web Browser Protections
789.6Block Unnecessary File TypesEmail and Web Browser Protections
799.7Deploy and Maintain Email Server Anti-Malware ProtectionsEmail and Web Browser Protections
8010.1Deploy and Maintain Anti-Malware SoftwareMalware Defenses
8110.2Configure Automatic Anti-Malware Signature UpdatesMalware Defenses
8210.3Disable Autorun and Autoplay for Removable MediaMalware Defenses
8310.4Configure Automatic Anti-Malware Scanning of Removable MediaMalware Defenses
8410.5Enable Anti-Exploitation FeaturesMalware Defenses
8510.6Centrally Manage Anti-Malware SoftwareMalware Defenses
8610.7Use Behavior-Based Anti-Malware SoftwareMalware Defenses
8711.1Establish and Maintain a Data Recovery ProcessData Recovery
8811.2Perform Automated BackupsData Recovery
8911.3Protect Recovery DataData Recovery
9011.4Establish and Maintain an Isolated Instance of Recovery DataData Recovery
9111.5Test Data RecoveryData Recovery
9212.1Ensure Network Infrastructure is Up-to-DateNetwork Infrastructure Management
9312.2Establish and Maintain a Secure Network ArchitectureNetwork Infrastructure Management
9412.3Securely Manage Network InfrastructureNetwork Infrastructure Management
9512.4Establish and Maintain Architecture Diagram(s)Network Infrastructure Management
9612.5Centralize Network AuthenticationAuthorizationand Auditing (AAA)Network Infrastructure Management
9712.6Use of Secure Network Management and Communication ProtocolsNetwork Infrastructure Management
9812.7Ensure Remote Devices Utilize a VPN and are Connecting to an Enterprise’s AAA InfrastructureNetwork Infrastructure Management
9912.8Establish and Maintain Dedicated Computing Resources For All Administrative WorkNetwork Infrastructure Management
10013.1Centralize Security Event AlertingNetwork Monitoring and Defense
10113.2Deploy a Host-Based Intrusion Detection SolutionNetwork Monitoring and Defense
10213.3Deploy a Network Intrusion Detection SolutionNetwork Monitoring and Defense
10313.4Perform Traffic Filtering Between Network SegmentsNetwork Monitoring and Defense
10413.5Manage Access Control for Remote AssetsNetwork Monitoring and Defense
10513.6Collect Network Traffic Flow LogsNetwork Monitoring and Defense
10613.7Deploy a Host-Based Intrusion Prevention SolutionNetwork Monitoring and Defense
10713.8Deploy a Network Intrusion Prevention SolutionNetwork Monitoring and Defense
10813.9Deploy Port-Level Access ControlNetwork Monitoring and Defense
10913.10Perform Application Layer FilteringNetwork Monitoring and Defense
11013.11Tune Security Event Alerting ThresholdsNetwork Monitoring and Defense
11114.1Establish and Maintain a Security Awareness ProgramSecurity Awareness and Skills Training
11214.2Train Workforce Members to Recognize Social Engineering AttacksSecurity Awareness and Skills Training
11314.3Train Workforce Members on Authentication Best PracticesSecurity Awareness and Skills Training
11414.4Train Workforce on Data Handling Best PracticesSecurity Awareness and Skills Training
11514.5Train Workforce Members on Causes of Unintentional Data ExposureSecurity Awareness and Skills Training
11614.6Train Workforce Members on Recognizing and Reporting Security IncidentsSecurity Awareness and Skills Training
11714.7Train Workforce on How to Identify and Report if their Enterprise Assets are Missing Security UpdatesSecurity Awareness and Skills Training
11814.8Train Workforce on the Dangers of Connecting to and Transmitting Enterprise Data Over Insecure NetworksSecurity Awareness and Skills Training
11914.9Conduct Role-Specific Security Awareness and Skills TrainingSecurity Awareness and Skills Training
12015.1Establish and Maintain an Inventory of Service ProvidersService Provider Management
12115.2Establish and Maintain a Service Provider Management PolicyService Provider Management
12215.3Classify Service ProvidersService Provider Management
12315.4Ensure Service Provider Contracts Include Security RequirementsService Provider Management
12415.5Assess Service ProvidersService Provider Management
12515.6Monitor Service ProvidersService Provider Management
12615.7Securely Decommission Service ProvidersService Provider Management
12716.1Establish and Maintain a Secure Application Development ProcessApplication Software Security
12816.2Establish and Maintain a Process to Accept and Address Software VulnerabilitiesApplication Software Security
12916.3Perform Root Cause Analysis on Security VulnerabilitiesApplication Software Security
13016.4Establish and Manage an Inventory of Third-Party Software ComponentsApplication Software Security
13116.5Use Up-to-Date and Trusted Third-Party Software ComponentsApplication Software Security
13216.6Establish and Maintain a Severity Rating System and Process for Application VulnerabilitiesApplication Software Security
13316.7Use Standard Hardening Configuration Templates for Application InfrastructureApplication Software Security
13416.8Separate Production and Non-Production SystemsApplication Software Security
13516.9Train Developers in Application Security Concepts and Secure CodingApplication Software Security
13616.10Apply Secure Design Principles in Application ArchitecturesApplication Software Security
13716.11Leverage Vetted Modules or Services for Application Security ComponentsApplication Software Security
13816.12Implement Code-Level Security ChecksApplication Software Security
13916.13Conduct Application Penetration TestingApplication Software Security
14016.14Conduct Threat ModelingApplication Software Security
14117.1Designate Personnel to Manage Incident HandlingIncident Response Management
14217.2Establish and Maintain Contact Information for Reporting Security IncidentsIncident Response Management
14317.3Establish and Maintain an Enterprise Process for Reporting IncidentsIncident Response Management
14417.4Establish and Maintain an Incident Response ProcessIncident Response Management
14517.5Assign Key Roles and ResponsibilitiesIncident Response Management
14617.6Define Mechanisms for Communicating During Incident ResponseIncident Response Management
14717.7Conduct Routine Incident Response ExercisesIncident Response Management
14817.8Conduct Post-Incident ReviewsIncident Response Management
14917.9Establish and Maintain Security Incident ThresholdsIncident Response Management
15018.1Establish and Maintain a Penetration Testing ProgramPenetration Testing
15118.2Perform Periodic External Penetration TestsPenetration Testing
15218.3Remediate Penetration Test FindingsPenetration Testing
15318.4Validate Security MeasuresPenetration Testing
15418.5Perform Periodic Internal Penetration TestsPenetration Testing