Files
old-riskletpy/controls.csv
2025-02-12 05:46:21 +01:00

51 KiB

1Risk #Risk DescriptionCIS v8.1 Safeguards (Sub-Controls)Weight (0-10)
21Ransomware Attack on Critical Systems3.1 - Establish and Maintain Inventory of Enterprise Assets3
31Ransomware Attack on Critical Systems3.3 - Manage Assets4
41Ransomware Attack on Critical Systems5.1 - Establish and Maintain a Secure Configuration Process5
51Ransomware Attack on Critical Systems5.3 - Securely Configure Enterprise Assets and Software7
61Ransomware Attack on Critical Systems8.1 - Establish and Maintain a Vulnerability Management Process6
71Ransomware Attack on Critical Systems9.2 - Deploy and Maintain Anti-Malware Software9
81Ransomware Attack on Critical Systems10.8 - Perform and Test Data Backups10
91Ransomware Attack on Critical Systems15.1 - Develop an Incident Response Plan8
102Large-Scale Data Breach Due to External Attack3.1 - Establish and Maintain Inventory of Enterprise Assets4
112Large-Scale Data Breach Due to External Attack3.4 - Manage Sensitive Assets8
122Large-Scale Data Breach Due to External Attack4.1 - Establish and Maintain a Secure Access Control Policy and Procedures7
132Large-Scale Data Breach Due to External Attack4.2 - Implement and Manage Multi-Factor Authentication for Enterprise Accounts9
142Large-Scale Data Breach Due to External Attack6.3 - Implement and Manage Network Segmentation8
152Large-Scale Data Breach Due to External Attack7.1 - Establish and Maintain a Data Management Process6
162Large-Scale Data Breach Due to External Attack7.2 - Implement and Enforce Data Retention5
172Large-Scale Data Breach Due to External Attack7.3 - Implement Data Loss Prevention (DLP)9
182Large-Scale Data Breach Due to External Attack12.5 - Enforce Encryption of Data-at-Rest8
192Large-Scale Data Breach Due to External Attack12.6 - Enforce Encryption of Data-in-Transit7
203Insider Threat Leading to Data Exfiltration4.1 - Establish and Maintain a Secure Access Control Policy and Procedures8
213Insider Threat Leading to Data Exfiltration4.3 - Manage Privileged Access9
223Insider Threat Leading to Data Exfiltration4.4 - Manage Service Accounts6
233Insider Threat Leading to Data Exfiltration4.6 - Manage External Accounts5
243Insider Threat Leading to Data Exfiltration7.3 - Implement Data Loss Prevention (DLP)8
253Insider Threat Leading to Data Exfiltration14.5 - Establish and Maintain an Audit Log Review and Analysis Process7
263Insider Threat Leading to Data Exfiltration16.1 - Conduct Security Awareness and Skills Training6
274Supply Chain Disruption Impacting Operations3.1 - Establish and Maintain Inventory of Enterprise Assets2
284Supply Chain Disruption Impacting Operations3.6 - Establish and Maintain an Inventory of Non-Enterprise Assets1
294Supply Chain Disruption Impacting Operations4.6 - Manage External Accounts6
304Supply Chain Disruption Impacting Operations13.1 - Establish and Maintain a Security Awareness Program3
314Supply Chain Disruption Impacting Operations18.1 - Establish and Maintain a Penetration Testing Program4
324Supply Chain Disruption Impacting Operations19.1 - Establish and Maintain an Incident Response Plan7
334Supply Chain Disruption Impacting Operations20.1 - Establish and Maintain a Business Continuity Plan10
345Reputational Damage from Social Media Incident13.1 - Establish and Maintain a Security Awareness Program9
355Reputational Damage from Social Media Incident16.1 - Conduct Security Awareness and Skills Training8
365Reputational Damage from Social Media Incident16.2 - Train Workforce Members on Social Engineering Attacks7
375Reputational Damage from Social Media Incident19.1 - Establish and Maintain an Incident Response Plan6
385Reputational Damage from Social Media Incident19.8 - Perform Post-Incident Reviews5
396Compliance Failure Leading to Fines1.1 - Establish and Maintain Enterprise Governance10
406Compliance Failure Leading to Fines1.2 - Establish and Maintain Enterprise Security Policies9
416Compliance Failure Leading to Fines1.3 - Establish and Maintain Enterprise Agreements8
426Compliance Failure Leading to Fines2.1 - Establish and Maintain an Inventory of Authorized Software4
436Compliance Failure Leading to Fines3.4 - Manage Sensitive Assets7
447Loss of Critical Business Data Due to System Failure10.8 - Perform and Test Data Backups10
457Loss of Critical Business Data Due to System Failure10.9 - Perform Off-Site Backups9
467Loss of Critical Business Data Due to System Failure10.10 - Securely Store Backups8
477Loss of Critical Business Data Due to System Failure5.3 - Securely Configure Enterprise Assets and Software6
487Loss of Critical Business Data Due to System Failure19.1 - Establish and Maintain an Incident Response Plan5
498Business Email Compromise (BEC) Attack4.2 - Implement and Manage Multi-Factor Authentication for Enterprise Accounts9
508Business Email Compromise (BEC) Attack16.2 - Train Workforce Members on Social Engineering Attacks8
518Business Email Compromise (BEC) Attack11.1 - Implement and Manage Email Protections7
528Business Email Compromise (BEC) Attack14.5 - Establish and Maintain an Audit Log Review and Analysis Process5
539Physical Security Breach Leading to Asset Theft17.1 - Implement Physical Access Controls10
549Physical Security Breach Leading to Asset Theft17.2 - Monitor Physical Environment9
559Physical Security Breach Leading to Asset Theft3.1 - Establish and Maintain Inventory of Enterprise Assets6
569Physical Security Breach Leading to Asset Theft14.5 - Establish and Maintain an Audit Log Review and Analysis Process4
5710Denial-of-Service (DoS) Attack Disrupting Services6.1 - Establish and Maintain a Baseline Configuration of Network Devices6
5810Denial-of-Service (DoS) Attack Disrupting Services6.4 - Implement and Manage Network Infrastructure Device Hardening7
5910Denial-of-Service (DoS) Attack Disrupting Services6.5 - Implement and Manage Distributed Denial of Service (DDoS) Mitigation Techniques10
6010Denial-of-Service (DoS) Attack Disrupting Services14.1 - Establish and Maintain a Security Logging and Monitoring Process8
6111Unpatched Software Vulnerabilities Exploited8.2 - Remediate Vulnerabilities Based on Risk10
6211Unpatched Software Vulnerabilities Exploited8.3 - Verify Application of Security Patches9
6311Unpatched Software Vulnerabilities Exploited3.2 - Utilize an Automated Asset Discovery Tool4
6412Third-Party Vendor Security Breach Impacting Data4.6 - Manage External Accounts8
6512Third-Party Vendor Security Breach Impacting Data13.5 - Manage Supplier Access9
6612Third-Party Vendor Security Breach Impacting Data13.6 - Monitor Supplier Security7
6713Mobile Device Compromise Leading to Data Loss3.5 - Manage Enterprise Assets Connected to the Enterprise Network Remotely8
6813Mobile Device Compromise Leading to Data Loss4.5 - Manage Mobile Devices9
6913Mobile Device Compromise Leading to Data Loss12.5 - Enforce Encryption of Data-at-Rest7
7014Cloud Service Configuration Errors Exposing Data5.4 - Securely Configure Cloud Infrastructure9
7114Cloud Service Configuration Errors Exposing Data5.5 - Securely Configure Cloud Workloads8
7214Cloud Service Configuration Errors Exposing Data14.1 - Establish and Maintain a Security Logging and Monitoring Process6
7315Lack of Employee Security Awareness Leading to Phishing Success16.1 - Conduct Security Awareness and Skills Training10
7415Lack of Employee Security Awareness Leading to Phishing Success16.2 - Train Workforce Members on Social Engineering Attacks9
7515Lack of Employee Security Awareness Leading to Phishing Success11.1 - Implement and Manage Email Protections7
7616Unsecured APIs Exposing Sensitive Information6.2 - Establish and Maintain a Baseline Configuration of Endpoints6
7716Unsecured APIs Exposing Sensitive Information12.6 - Enforce Encryption of Data-in-Transit9
7816Unsecured APIs Exposing Sensitive Information18.1 - Establish and Maintain a Penetration Testing Program7
7917Accidental Data Leak by Employee7.3 - Implement Data Loss Prevention (DLP)8
8017Accidental Data Leak by Employee16.1 - Conduct Security Awareness and Skills Training7
8117Accidental Data Leak by Employee14.5 - Establish and Maintain an Audit Log Review and Analysis Process5
8218Weak Password Policies Leading to Account Compromise4.7 - Enforce Account Password Requirements9
8318Weak Password Policies Leading to Account Compromise4.8 - Enforce Multi-Factor Authentication for All Users8
8418Weak Password Policies Leading to Account Compromise4.2 - Implement and Manage Multi-Factor Authentication for Enterprise Accounts7
8519Uncontrolled Use of Shadow IT3.6 - Establish and Maintain an Inventory of Non-Enterprise Assets8
8619Uncontrolled Use of Shadow IT2.1 - Establish and Maintain an Inventory of Authorized Software7
8719Uncontrolled Use of Shadow IT13.1 - Establish and Maintain a Security Awareness Program6
8820Insider Trading Based on Stolen Information4.3 - Manage Privileged Access9
8920Insider Trading Based on Stolen Information7.3 - Implement Data Loss Prevention (DLP)7
9020Insider Trading Based on Stolen Information14.5 - Establish and Maintain an Audit Log Review and Analysis Process8
9121Loss of Key Personnel with Critical Security Knowledge16.4 - Establish and Maintain a Role-Based Security Training Program7
9221Loss of Key Personnel with Critical Security Knowledge16.5 - Conduct Skills Gap Assessments6
9321Loss of Key Personnel with Critical Security Knowledge1.3 - Establish and Maintain Enterprise Agreements5
9422Natural Disaster Impacting Data Centers17.3 - Plan and Implement Environmental Protections9
9522Natural Disaster Impacting Data Centers20.1 - Establish and Maintain a Business Continuity Plan10
9622Natural Disaster Impacting Data Centers10.9 - Perform Off-Site Backups8
9723Industrial Control System (ICS) Compromise5.6 - Securely Configure Industrial Control Systems (ICS)10
9823Industrial Control System (ICS) Compromise6.6 - Implement and Manage Network Segmentation for ICS9
9923Industrial Control System (ICS) Compromise9.2 - Deploy and Maintain Anti-Malware Software7
10024Misconfiguration of Network Devices6.1 - Establish and Maintain a Baseline Configuration of Network Devices9
10124Misconfiguration of Network Devices6.4 - Implement and Manage Network Infrastructure Device Hardening8
10224Misconfiguration of Network Devices14.1 - Establish and Maintain a Security Logging and Monitoring Process7
10325Lack of Regular Security Audits1.5 - Conduct Periodic Security Risk Assessments9
10425Lack of Regular Security Audits14.7 - Conduct Security Controls Testing and Validation8
10525Lack of Regular Security Audits18.1 - Establish and Maintain a Penetration Testing Program7
10626AI/ML System Bias Leading to Unfair Outcomes1.2 - Establish and Maintain Enterprise Security Policies6
10726AI/ML System Bias Leading to Unfair Outcomes7.1 - Establish and Maintain a Data Management Process7
10826AI/ML System Bias Leading to Unfair Outcomes15.4 - Establish and Maintain a Security Architecture5
10927IoT Device Vulnerabilities Exploited3.5 - Manage Enterprise Assets Connected to the Enterprise Network Remotely8
11027IoT Device Vulnerabilities Exploited5.3 - Securely Configure Enterprise Assets and Software7
11127IoT Device Vulnerabilities Exploited9.2 - Deploy and Maintain Anti-Malware Software6
11228Geopolitical Risks Impacting Cybersecurity1.4 - Establish and Maintain a Threat Intelligence Program9
11328Geopolitical Risks Impacting Cybersecurity19.1 - Establish and Maintain an Incident Response Plan7
11428Geopolitical Risks Impacting Cybersecurity13.1 - Establish and Maintain a Security Awareness Program6
11529Unsecured Code in Custom Applications2.2 - Utilize Standard Security Configurations for Enterprise Software and Hardware7
11629Unsecured Code in Custom Applications8.4 - Perform Application Security Testing9
11729Unsecured Code in Custom Applications12.1 - Establish and Maintain a Software Development Life Cycle (SDLC)8
11830Failure to Adequately Vet New Technologies15.4 - Establish and Maintain a Security Architecture7
11930Failure to Adequately Vet New Technologies1.5 - Conduct Periodic Security Risk Assessments8
12030Failure to Adequately Vet New Technologies13.1 - Establish and Maintain a Security Awareness Program6
12131Social Engineering Attack Targeting Executives16.2 - Train Workforce Members on Social Engineering Attacks10
12231Social Engineering Attack Targeting Executives4.2 - Implement and Manage Multi-Factor Authentication for Enterprise Accounts8
12331Social Engineering Attack Targeting Executives11.1 - Implement and Manage Email Protections7
12432Vulnerability in Open-Source Software Components2.1 - Establish and Maintain an Inventory of Authorized Software6
12532Vulnerability in Open-Source Software Components8.1 - Establish and Maintain a Vulnerability Management Process9
12632Vulnerability in Open-Source Software Components8.2 - Remediate Vulnerabilities Based on Risk8
12733Cryptojacking on Enterprise Assets9.2 - Deploy and Maintain Anti-Malware Software9
12833Cryptojacking on Enterprise Assets5.3 - Securely Configure Enterprise Assets and Software7
12933Cryptojacking on Enterprise Assets14.1 - Establish and Maintain a Security Logging and Monitoring Process6
13034Data Spillage in Cloud Environments7.3 - Implement Data Loss Prevention (DLP)8
13134Data Spillage in Cloud Environments5.4 - Securely Configure Cloud Infrastructure7
13234Data Spillage in Cloud Environments12.5 - Enforce Encryption of Data-at-Rest6
13335Malicious Browser Extensions Compromising Users9.1 - Establish and Maintain a Software Allow List8
13435Malicious Browser Extensions Compromising Users16.1 - Conduct Security Awareness and Skills Training7
13535Malicious Browser Extensions Compromising Users11.2 - Implement and Manage Web Browser Protections9
13636Domain Name System (DNS) Attacks6.7 - Implement and Manage Domain Name System (DNS) Security9
13736Domain Name System (DNS) Attacks14.1 - Establish and Maintain a Security Logging and Monitoring Process7
13836Domain Name System (DNS) Attacks6.5 - Implement and Manage Distributed Denial of Service (DDoS) Mitigation Techniques6
13937Quantum Computing Breaking Encryption12.7 - Plan and Implement Cryptographic Key Management7
14037Quantum Computing Breaking Encryption15.4 - Establish and Maintain a Security Architecture6
14137Quantum Computing Breaking Encryption1.4 - Establish and Maintain a Threat Intelligence Program5
14238Deepfake Technology Used for Fraud16.2 - Train Workforce Members on Social Engineering Attacks8
14338Deepfake Technology Used for Fraud11.1 - Implement and Manage Email Protections7
14438Deepfake Technology Used for Fraud14.5 - Establish and Maintain an Audit Log Review and Analysis Process6
14539Misinformation Campaigns Damaging Reputation13.1 - Establish and Maintain a Security Awareness Program9
14639Misinformation Campaigns Damaging Reputation19.1 - Establish and Maintain an Incident Response Plan7
14739Misinformation Campaigns Damaging Reputation1.4 - Establish and Maintain a Threat Intelligence Program6
14840Lack of a Formal Security Culture13.1 - Establish and Maintain a Security Awareness Program10
14940Lack of a Formal Security Culture16.1 - Conduct Security Awareness and Skills Training9
15040Lack of a Formal Security Culture1.2 - Establish and Maintain Enterprise Security Policies8
15141Insufficient Physical Security at Remote Offices17.1 - Implement Physical Access Controls9
15241Insufficient Physical Security at Remote Offices17.2 - Monitor Physical Environment8
15341Insufficient Physical Security at Remote Offices3.5 - Manage Enterprise Assets Connected to the Enterprise Network Remotely6
15442Compromise of Building Management Systems (BMS)5.6 - Securely Configure Industrial Control Systems (ICS)8
15542Compromise of Building Management Systems (BMS)6.6 - Implement and Manage Network Segmentation for ICS7
15642Compromise of Building Management Systems (BMS)14.1 - Establish and Maintain a Security Logging and Monitoring Process6
15743Failure to Securely Dispose of Sensitive Data7.4 - Securely Dispose of Assets9
15843Failure to Securely Dispose of Sensitive Data3.3 - Manage Assets7
15943Failure to Securely Dispose of Sensitive Data1.2 - Establish and Maintain Enterprise Security Policies6
16044Man-in-the-Middle (MitM) Attacks6.2 - Establish and Maintain a Baseline Configuration of Endpoints7
16144Man-in-the-Middle (MitM) Attacks12.6 - Enforce Encryption of Data-in-Transit9
16244Man-in-the-Middle (MitM) Attacks4.2 - Implement and Manage Multi-Factor Authentication for Enterprise Accounts8
16345Session Hijacking4.1 - Establish and Maintain a Secure Access Control Policy and Procedures8
16445Session Hijacking4.2 - Implement and Manage Multi-Factor Authentication for Enterprise Accounts9
16545Session Hijacking14.1 - Establish and Maintain a Security Logging and Monitoring Process7
16646Cross-Site Scripting (XSS) Attacks8.4 - Perform Application Security Testing9
16746Cross-Site Scripting (XSS) Attacks12.2 - Secure Software via Secure Coding Practices8
16846Cross-Site Scripting (XSS) Attacks6.2 - Establish and Maintain a Baseline Configuration of Endpoints6
16947SQL Injection Attacks8.4 - Perform Application Security Testing10
17047SQL Injection Attacks12.2 - Secure Software via Secure Coding Practices9
17147SQL Injection Attacks6.2 - Establish and Maintain a Baseline Configuration of Endpoints7
17248Zero-Day Exploits8.1 - Establish and Maintain a Vulnerability Management Process7
17348Zero-Day Exploits9.2 - Deploy and Maintain Anti-Malware Software8
17448Zero-Day Exploits6.3 - Implement and Manage Network Segmentation6
17549Rogue Access Points on the Network6.1 - Establish and Maintain a Baseline Configuration of Network Devices8
17649Rogue Access Points on the Network6.3 - Implement and Manage Network Segmentation7
17749Rogue Access Points on the Network14.1 - Establish and Maintain a Security Logging and Monitoring Process6
17850Wireless Network Attacks6.8 - Secure Wireless Access Points9
17950Wireless Network Attacks4.2 - Implement and Manage Multi-Factor Authentication for Enterprise Accounts7
18050Wireless Network Attacks14.1 - Establish and Maintain a Security Logging and Monitoring Process6
18151Stolen Credentials4.1 - Establish and Maintain a Secure Access Control Policy and Procedures9
18251Stolen Credentials4.2 - Implement and Manage Multi-Factor Authentication for Enterprise Accounts10
18351Stolen Credentials14.1 - Establish and Maintain a Security Logging and Monitoring Process7
18452Unsecured Public Wi-Fi Usage16.1 - Conduct Security Awareness and Skills Training7
18552Unsecured Public Wi-Fi Usage12.6 - Enforce Encryption of Data-in-Transit8
18652Unsecured Public Wi-Fi Usage4.9 - Manage Access to Enterprise Applications6
18753Vishing Attacks16.2 - Train Workforce Members on Social Engineering Attacks9
18853Vishing Attacks13.1 - Establish and Maintain a Security Awareness Program8
18953Vishing Attacks11.1 - Implement and Manage Email Protections5
19054Smishing Attacks16.2 - Train Workforce Members on Social Engineering Attacks9
19154Smishing Attacks13.1 - Establish and Maintain a Security Awareness Program8
19254Smishing Attacks11.3 - Implement and Manage Endpoint Protections6
19355Watering Hole Attacks11.2 - Implement and Manage Web Browser Protections8
19455Watering Hole Attacks14.1 - Establish and Maintain a Security Logging and Monitoring Process7
19555Watering Hole Attacks1.4 - Establish and Maintain a Threat Intelligence Program6
19656Typosquatting Attacks11.1 - Implement and Manage Email Protections7
19756Typosquatting Attacks13.1 - Establish and Maintain a Security Awareness Program8
19856Typosquatting Attacks1.4 - Establish and Maintain a Threat Intelligence Program6
19957Malvertising11.2 - Implement and Manage Web Browser Protections9
20057Malvertising9.2 - Deploy and Maintain Anti-Malware Software7
20157Malvertising14.1 - Establish and Maintain a Security Logging and Monitoring Process6
20258Fileless Malware Attacks9.2 - Deploy and Maintain Anti-Malware Software8
20358Fileless Malware Attacks14.1 - Establish and Maintain a Security Logging and Monitoring Process7
20458Fileless Malware Attacks11.3 - Implement and Manage Endpoint Protections6
20559Advanced Persistent Threats (APTs)1.4 - Establish and Maintain a Threat Intelligence Program9
20659Advanced Persistent Threats (APTs)14.1 - Establish and Maintain a Security Logging and Monitoring Process8
20759Advanced Persistent Threats (APTs)18.1 - Establish and Maintain a Penetration Testing Program7
20860Remote Code Execution (RCE) Vulnerabilities8.2 - Remediate Vulnerabilities Based on Risk10
20960Remote Code Execution (RCE) Vulnerabilities8.3 - Verify Application of Security Patches9
21060Remote Code Execution (Rulnerabilities6.4 - Implement and Manage Network Infrastructure Device Hardening7
21161Formjacking Attacks12.2 - Secure Software via Secure Coding Practices8
21261Formjacking Attacks11.2 - Implement and Manage Web Browser Protections7
21361Formjacking Attacks14.1 - Establish and Maintain a Security Logging and Monitoring Process6
21462SIM Swapping Attacks4.2 - Implement and Manage Multi-Factor Authentication for Enterprise Accounts9
21562SIM Swapping Attacks16.1 - Conduct Security Awareness and Skills Training7
21662SIM Swapping Attacks1.3 - Establish and Maintain Enterprise Agreements6
21763Unsecured Database Configurations5.3 - Securely Configure Enterprise Assets and Software9
21863Unsecured Database Configurations7.1 - Establish and Maintain a Data Management Process8
21963Unsecured Database Configurations14.1 - Establish and Maintain a Security Logging and Monitoring Process7
22064API Sprawl and Lack of API Governance12.1 - Establish and Maintain a Software Development Life Cycle (SDLC)8
22164API Sprawl and Lack of API Governance6.2 - Establish and Maintain a Baseline Configuration of Endpoints7
22264API Sprawl and Lack of API Governance15.4 - Establish and Maintain a Security Architecture6
22365Insecure Default Configurations5.1 - Establish and Maintain a Secure Configuration Process9
22465Insecure Default Configurations5.3 - Securely Configure Enterprise Assets and Software8
22565Insecure Default Configurations6.1 - Establish and Maintain a Baseline Configuration of Network Devices7
22666Insufficient Data Encryption12.5 - Enforce Encryption of Data-at-Rest10
22766Insufficient Data Encryption7.2 - Implement and Enforce Data Retention6
22867Legacy Systems with Known Vulnerabilities3.3 - Manage Assets7
22967Legacy Systems with Known Vulnerabilities8.2 - Remediate Vulnerabilities Based on Risk9
23067Legacy Systems with Known Vulnerabilities6.3 - Implement and Manage Network Segmentation8
23168Poorly Implemented Patch Management8.2 - Remediate Vulnerabilities Based on Risk10
23268Poorly Implemented Patch Management8.3 - Verify Application of Security Patches9
23368Poorly Implemented Patch Management3.2 - Utilize an Automated Asset Discovery Tool6
23469Unsecured Configuration Management Practices5.1 - Establish and Maintain a Secure Configuration Process9
23569Unsecured Configuration Management Practices5.3 - Securely Configure Enterprise Assets and Software8
23669Unsecured Configuration Management Practices6.1 - Establish and Maintain a Baseline Configuration of Network Devices7
23770Lack of Network Segmentation6.3 - Implement and Manage Network Segmentation10
23870Lack of Network Segmentation6.1 - Establish and Maintain a Baseline Configuration of Network Devices7
23970Lack of Network Segmentation14.1 - Establish and Maintain a Security Logging and Monitoring Process6
24071Compromised Software Update Mechanisms8.3 - Verify Application of Security Patches8
24171Compromised Software Update Mechanisms9.2 - Deploy and Maintain Anti-Malware Software7
24271Compromised Software Update Mechanisms14.1 - Establish and Maintain a Security Logging and Monitoring Process6
24372Weaknesses in Cloud Identity and Access Management4.1 - Establish and Maintain a Secure Access Control Policy and Procedures9
24472Weaknesses in Cloud Identity and Access Management4.2 - Implement and Manage Multi-Factor Authentication for Enterprise Accounts8
24572Weaknesses in Cloud Identity and Access Management5.4 - Securely Configure Cloud Infrastructure7
24673Insufficient Security Logging and Monitoring14.1 - Establish and Maintain a Security Logging and Monitoring Process10
24773Insufficient Security Logging and Monitoring14.2 - Integrate Threat Intelligence into Security Monitoring8
24873Insufficient Security Logging and Monitoring14.3 - Establish and Maintain Alerting and Escalation Processes7
24974Lack of an Effective Incident Response Plan19.1 - Establish and Maintain an Incident Response Plan10
25074Lack of an Effective Incident Response Plan19.2 - Establish and Maintain an Incident Response Team9
25174Lack of an Effective Incident Response Plan19.3 - Develop and Conduct Incident Response Exercises8
25275Poor Data Backup and Recovery Procedures10.8 - Perform and Test Data Backups10
25375Poor Data Backup and Recovery Procedures10.9 - Perform Off-Site Backups9
25475Poor Data Backup and Recovery Procedures10.10 - Securely Store Backups8
25576Insufficient Security Awareness Training for Employees16.1 - Conduct Security Awareness and Skills Training10
25676Insufficient Security Awareness Training for Employees16.2 - Train Workforce Members on Social Engineering Attacks9
25776Insufficient Security Awareness Training for Employees13.1 - Establish and Maintain a Security Awareness Program8
25877Lack of a Formal Risk Management Program1.5 - Conduct Periodic Security Risk Assessments10
25977Lack of a Formal Risk Management Program1.1 - Establish and Maintain Enterprise Governance9
26077Lack of a Formal Risk Management Program1.2 - Establish and Maintain Enterprise Security Policies8
26178Inadequate Third-Party Risk Management13.5 - Manage Supplier Access9
26278Inadequate Third-Party Risk Management13.6 - Monitor Supplier Security8
26378Inadequate Third-Party Risk Management4.6 - Manage External Accounts7
26479Failure to Enforce Least Privilege4.3 - Manage Privileged Access10
26579Failure to Enforce Least Privilege4.1 - Establish and Maintain a Secure Access Control Policy and Procedures8
26679Failure to Enforce Least Privilege4.4 - Manage Service Accounts7
26780Unsecured Remote Access Solutions4.9 - Manage Access to Enterprise Applications9
26880Unsecured Remote Access Solutions4.2 - Implement and Manage Multi-Factor Authentication for Enterprise Accounts8
26980Unsecured Remote Access Solutions12.6 - Enforce Encryption of Data-in-Transit7
27081Insufficient Protection of Critical Infrastructure17.1 - Implement Physical Access Controls8
27181Insufficient Protection of Critical Infrastructure6.3 - Implement and Manage Network Segmentation7
27281Insufficient Protection of Critical Infrastructure14.1 - Establish and Maintain a Security Logging and Monitoring Process6
27382Lack of Data Loss Prevention (DLP) Measures7.3 - Implement Data Loss Prevention (DLP)10
27482Lack of Data Loss Prevention (DLP) Measures3.4 - Manage Sensitive Assets8
27582Lack of Data Loss Prevention (DLP) Measures14.5 - Establish and Maintain an Audit Log Review and Analysis Process7
27683Ineffective Vulnerability Scanning Practices8.1 - Establish and Maintain a Vulnerability Management Process9
27783Ineffective Vulnerability Scanning Practices8.2 - Remediate Vulnerabilities Based on Risk8
27883Ineffective Vulnerability Scanning Practices3.2 - Utilize an Automated Asset Discovery Tool7
27984Poorly Defined Security Roles and Responsibilities1.2 - Establish and Maintain Enterprise Security Policies8
28084Poorly Defined Security Roles and Responsibilities1.3 - Establish and Maintain Enterprise Agreements7
28184Poorly Defined Security Roles and Responsibilities16.4 - Establish and Maintain a Role-Based Security Training Program6
28285Lack of a Formal Change Management Process5.2 - Implement and Manage a Change Management Process9
28385Lack of a Formal Change Management Process5.3 - Securely Configure Enterprise Assets and Software7
28485Lack of a Formal Change Management Process14.1 - Establish and Maintain a Security Logging and Monitoring Process6
28586Insufficient Security Architecture and Design15.4 - Establish and Maintain a Security Architecture10
28686Insufficient Security Architecture and Design6.3 - Implement and Manage Network Segmentation8
28786Insufficient Security Architecture and Design12.1 - Establish and Maintain a Software Development Life Cycle (SDLC)7
28887Failure to Secure Containerized Environments5.7 - Securely Configure Containers9
28987Failure to Secure Containerized Environments4.1 - Establish and Maintain a Secure Access Control Policy and Procedures7
29087Failure to Secure Containerized Environments14.1 - Establish and Maintain a Security Logging and Monitoring Process6
29188Inadequate Protection of API Keys and Secrets12.3 - Manage Credentials9
29288Inadequate Protection of API Keys and Secrets12.5 - Enforce Encryption of Data-at-Rest7
29388Inadequate Protection of API Keys and Secrets14.1 - Establish and Maintain a Security Logging and Monitoring Process6
29489Lack of a Formal Security Assessment Process for New Projects1.5 - Conduct Periodic Security Risk Assessments8
29589Lack of a Formal Security Assessment Process for New Projects15.4 - Establish and Maintain a Security Architecture7
29689Lack of a Formal Security Assessment Process for New Projects12.1 - Establish and Maintain a Software Development Life Cycle (SDLC)6
29790Insufficient Budget Allocation for Cybersecurity1.1 - Establish and Maintain Enterprise Governance9
29890Insufficient Budget Allocation for Cybersecurity1.2 - Establish and Maintain Enterprise Security Policies8
29990Insufficient Budget Allocation for Cybersecurity1.5 - Conduct Periodic Security Risk Assessments7
30091Lack of Executive Support for Security Initiatives1.1 - Establish and Maintain Enterprise Governance10
30191Lack of Executive Support for Security Initiatives1.2 - Establish and Maintain Enterprise Security Policies9
30291Lack of Executive Support for Security Initiatives13.1 - Establish and Maintain a Security Awareness Program7
30392Mergers and Acquisitions Leading to Security Integration Challenges1.3 - Establish and Maintain Enterprise Agreements8
30492Mergers and Acquisitions Leading to Security Integration Challenges15.4 - Establish and Maintain a Security Architecture7
30592Mergers and Acquisitions Leading to Security Integration Challenges3.1 - Establish and Maintain Inventory of Enterprise Assets6
30693Decentralized Security Management Leading to Inconsistencies1.1 - Establish and Maintain Enterprise Governance8
30793Decentralized Security Management Leading to Inconsistencies1.2 - Establish and Maintain Enterprise Security Policies7
30893Decentralized Security Management Leading to Inconsistencies4.1 - Establish and Maintain a Secure Access Control Policy and Procedures6
30994Rapid Cloud Adoption Without Adequate Security Controls5.4 - Securely Configure Cloud Infrastructure9
31094Rapid Cloud Adoption Without Adequate Security Controls4.1 - Establish and Maintain a Secure Access Control Policy and Procedures8
31194Rapid Cloud Adoption Without Adequate Security Controls14.1 - Establish and Maintain a Security Logging and Monitoring Process7
31295Increased Use of Personal Devices for Work (BYOD)3.5 - Manage Enterprise Assets Connected to the Enterprise Network Remotely8
31395Increased Use of Personal Devices for Work (BYOD)4.5 - Manage Mobile Devices7
31495Increased Use of Personal Devices for Work (BYOD)12.5 - Enforce Encryption of Data-at-Rest6
31596Growing Attack Surface Due to Digital Transformation3.1 - Establish and Maintain Inventory of Enterprise Assets7
31696Growing Attack Surface Due to Digital Transformation15.4 - Establish and Maintain a Security Architecture8
31796Growing Attack Surface Due to Digital Transformation8.1 - Establish and Maintain a Vulnerability Management Process6
31897Talent Shortage in Cybersecurity16.3 - Establish and Maintain a Security Skills Development Program9
31997Talent Shortage in Cybersecurity16.5 - Conduct Skills Gap Assessments8
32097Talent Shortage in Cybersecurity1.3 - Establish and Maintain Enterprise Agreements5
32198Increased Regulatory Scrutiny and Complexity1.1 - Establish and Maintain Enterprise Governance9
32298Increased Regulatory Scrutiny and Complexity1.2 - Establish and Maintain Enterprise Security Policies8
32398Increased Regulatory Scrutiny and Complexity3.4 - Manage Sensitive Assets7
32499Evolving Threat Landscape1.4 - Establish and Maintain a Threat Intelligence Program10
32599Evolving Threat Landscape18.1 - Establish and Maintain a Penetration Testing Program8
32699Evolving Threat Landscape13.1 - Establish and Maintain a Security Awareness Program7
327100Failure to Adapt Security Strategy to Business Changes1.2 - Establish and Maintain Enterprise Security Policies8
328100Failure to Adapt Security Strategy to Business Changes1.5 - Conduct Periodic Security Risk Assessments9
329100Failure to Adapt Security Strategy to Business Changes15.4 - Establish and Maintain a Security Architecture7
330101Advanced Persistent Threats (APTs) Evading Existing Defenses14.2 - Integrate Threat Intelligence into Security Monitoring9
331101Advanced Persistent Threats (APTs) Evading Existing Defenses18.1 - Establish and Maintain a Penetration Testing Program8
332101Advanced Persistent Threats (APTs) Evading Existing Defenses9.3 - Implement and Manage Endpoint Detection and Response (EDR)8
333102Zero-Day Exploits Targeting Unpatched Applications8.2 - Remediate Vulnerabilities Based on Risk9
334102Zero-Day Exploits Targeting Unpatched Applications6.3 - Implement and Manage Network Segmentation7
335102Zero-Day Exploits Targeting Unpatched Applications9.3 - Implement and Manage Endpoint Detection and Response (EDR)7
336103Sophisticated Phishing Campaigns Bypassing Email Security11.1 - Implement and Manage Email Protections8
337103Sophisticated Phishing Campaigns Bypassing Email Security16.2 - Train Workforce Members on Social Engineering Attacks9
338103Sophisticated Phishing Campaigns Bypassing Email Security4.2 - Implement and Manage Multi-Factor Authentication for Enterprise Accounts7
339104Malware Delivered Through Supply Chain Compromise13.3 - Implement and Manage Secure Software Supply Chain Practices9
340104Malware Delivered Through Supply Chain Compromise9.2 - Deploy and Maintain Anti-Malware Software7
341104Malware Delivered Through Supply Chain Compromise14.1 - Establish and Maintain a Security Logging and Monitoring Process6
342105Ransomware Targeting Backup Infrastructure10.8 - Perform and Test Data Backups8
343105Ransomware Targeting Backup Infrastructure10.10 - Securely Store Backups9
344105Ransomware Targeting Backup Infrastructure6.3 - Implement and Manage Network Segmentation7
345106Data Exfiltration Through DNS Tunneling6.7 - Implement and Manage Domain Name System (DNS) Security9
346106Data Exfiltration Through DNS Tunneling14.1 - Establish and Maintain a Security Logging and Monitoring Process8
347106Data Exfiltration Through DNS Tunneling7.3 - Implement Data Loss Prevention (DLP)7
348107Compromise of Cloud Service Provider Credentials4.1 - Establish and Maintain a Secure Access Control Policy and Procedures8
349107Compromise of Cloud Service Provider Credentials4.2 - Implement and Manage Multi-Factor Authentication for Enterprise Accounts9
350107Compromise of Cloud Service Provider Credentials5.4 - Securely Configure Cloud Infrastructure7
351108Lateral Movement within the Network Post-Breach6.3 - Implement and Manage Network Segmentation10
352108Lateral Movement within the Network Post-Breach14.1 - Establish and Maintain a Security Logging and Monitoring Process8
353108Lateral Movement within the Network Post-Breach9.3 - Implement and Manage Endpoint Detection and Response (EDR)7
354109Exploitation of Unsecured APIs6.2 - Establish and Maintain a Baseline Configuration of Endpoints7
355109Exploitation of Unsecured APIs12.4 - Implement and Manage Security for Software Applications9
356109Exploitation of Unsecured APIs18.1 - Establish and Maintain a Penetration Testing Program8
357110Credential Stuffing Attacks Against Web Applications4.7 - Enforce Account Password Requirements7
358110Credential Stuffing Attacks Against Web Applications4.8 - Enforce Multi-Factor Authentication for All Users9
359110Credential Stuffing Attacks Against Web Applications14.1 - Establish and Maintain a Security Logging and Monitoring Process6
360111Brute-Force Attacks Targeting Cloud Services4.7 - Enforce Account Password Requirements8
361111Brute-Force Attacks Targeting Cloud Services4.8 - Enforce Multi-Factor Authentication for All Users9
362111Brute-Force Attacks Targeting Cloud Services5.4 - Securely Configure Cloud Infrastructure7
363112Cryptojacking Exploiting Web Browser Vulnerabilities11.2 - Implement and Manage Web Browser Protections9
364112Cryptojacking Exploiting Web Browser Vulnerabilities9.2 - Deploy and Maintain Anti-Malware Software7
365112Cryptojacking Exploiting Web Browser Vulnerabilities14.1 - Establish and Maintain a Security Logging and Monitoring Process6
366113Business Logic Flaws in Applications Leading to Data Breach12.4 - Implement and Manage Security for Software Applications9
367113Business Logic Flaws in Applications Leading to Data Breach8.4 - Perform Application Security Testing8
368113Business Logic Flaws in Applications Leading to Data Breach7.1 - Establish and Maintain a Data Management Process7
369114Malicious Insiders Exfiltrating Data Using Approved Tools4.3 - Manage Privileged Access8
370114Malicious Insiders Exfiltrating Data Using Approved Tools7.3 - Implement Data Loss Prevention (DLP)9
371114Malicious Insiders Exfiltrating Data Using Approved Tools14.5 - Establish and Maintain an Audit Log Review and Analysis Process7
372115Rogue or Shadow IT Devices on the Network3.6 - Establish and Maintain an Inventory of Non-Enterprise Assets9
373115Rogue or Shadow IT Devices on the Network6.3 - Implement and Manage Network Segmentation7
374115Rogue or Shadow IT Devices on the Network14.1 - Establish and Maintain a Security Logging and Monitoring Process6
375116Compromise of CI/CD Pipelines Leading to Malicious Code Injection12.1 - Establish and Maintain a Software Development Life Cycle (SDLC)9
376116Compromise of CI/CD Pipelines Leading to Malicious Code Injection4.1 - Establish and Maintain a Secure Access Control Policy and Procedures8
377116Compromise of CI/CD Pipelines Leading to Malicious Code Injection14.1 - Establish and Maintain a Security Logging and Monitoring Process7
378117Insecurely Configured Cloud Storage Buckets5.4 - Securely Configure Cloud Infrastructure10
379117Insecurely Configured Cloud Storage Buckets7.1 - Establish and Maintain a Data Management Process8
380117Insecurely Configured Cloud Storage Buckets14.1 - Establish and Maintain a Security Logging and Monitoring Process7
381118Exploitation of Memory Corruption Vulnerabilities8.2 - Remediate Vulnerabilities Based on Risk9
382118Exploitation of Memory Corruption Vulnerabilities9.3 - Implement and Manage Endpoint Detection and Response (EDR)8
383118Exploitation of Memory Corruption Vulnerabilities6.4 - Implement and Manage Network Infrastructure Device Hardening7
384119Data Breaches Due to Misconfigured Security Groups5.4 - Securely Configure Cloud Infrastructure9
385119Data Breaches Due to Misconfigured Security Groups4.1 - Establish and Maintain a Secure Access Control Policy and Procedures8
386119Data Breaches Due to Misconfigured Security Groups14.1 - Establish and Maintain a Security Logging and Monitoring Process7
387120Use of Default or Weak Encryption Keys12.7 - Plan and Implement Cryptographic Key Management9
388120Use of Default or Weak Encryption Keys12.5 - Enforce Encryption of Data-at-Rest8
389120Use of Default or Weak Encryption Keys12.6 - Enforce Encryption of Data-in-Transit7
390121Vulnerabilities in Third-Party Libraries and Dependencies8.1 - Establish and Maintain a Vulnerability Management Process8
391121Vulnerabilities in Third-Party Libraries and Dependencies12.1 - Establish and Maintain a Software Development Life Cycle (SDLC)9
392121Vulnerabilities in Third-Party Libraries and Dependencies2.1 - Establish and Maintain an Inventory of Authorized Software7
393122Targeted Attacks on Operational Technology (OT) Systems5.6 - Securely Configure Industrial Control Systems (ICS)9
394122Targeted Attacks on Operational Technology (OT) Systems6.6 - Implement and Manage Network Segmentation for ICS10
395122Targeted Attacks on Operational Technology (OT) Systems14.1 - Establish and Maintain a Security Logging and Monitoring Process8
396123Data Aggregation from Multiple Sources Leading to Privacy Violations7.1 - Establish and Maintain a Data Management Process8
397123Data Aggregation from Multiple Sources Leading to Privacy Violations3.4 - Manage Sensitive Assets9
398123Data Aggregation from Multiple Sources Leading to Privacy Violations1.2 - Establish and Maintain Enterprise Security Policies7
399124AI Poisoning Attacks Manipulating Machine Learning Models15.4 - Establish and Maintain a Security Architecture8
400124AI Poisoning Attacks Manipulating Machine Learning Models14.1 - Establish and Maintain a Security Logging and Monitoring Process7
401124AI Poisoning Attacks Manipulating Machine Learning Models1.4 - Establish and Maintain a Threat Intelligence Program6
402125Quantum Computing Attacks Breaking Current Encryption12.7 - Plan and Implement Cryptographic Key Management9
403125Quantum Computing Attacks Breaking Current Encryption15.4 - Establish and Maintain a Security Architecture7
404125Quantum Computing Attacks Breaking Current Encryption1.4 - Establish and Maintain a Threat Intelligence Program6
405126Deepfake Technology Used for Social Engineering16.2 - Train Workforce Members on Social Engineering Attacks9
406126Deepfake Technology Used for Social Engineering11.1 - Implement and Manage Email Protections7
407126Deepfake Technology Used for Social Engineering13.1 - Establish and Maintain a Security Awareness Program6
408127Blockchain Vulnerabilities Leading to Financial Loss12.4 - Implement and Manage Security for Software Applications8
409127Blockchain Vulnerabilities Leading to Financial Loss4.1 - Establish and Maintain a Secure Access Control Policy and Procedures7
410127Blockchain Vulnerabilities Leading to Financial Loss14.1 - Establish and Maintain a Security Logging and Monitoring Process6
411128Serverless Function Vulnerabilities5.4 - Securely Configure Cloud Infrastructure8
412128Serverless Function Vulnerabilities12.4 - Implement and Manage Security for Software Applications7
413128Serverless Function Vulnerabilities14.1 - Establish and Maintain a Security Logging and Monitoring Process6
414129Insider Threats Leveraging Data in Motion7.3 - Implement Data Loss Prevention (DLP)8
415129Insider Threats Leveraging Data in Motion12.6 - Enforce Encryption of Data-in-Transit7
416129Insider Threats Leveraging Data in Motion14.5 - Establish and Maintain an Audit Log Review and Analysis Process6
417130Compromise of Hardware Supply Chain (Hardware Implants)13.4 - Implement and Manage Secure Hardware Supply Chain Practices9
418130Compromise of Hardware Supply Chain (Hardware Implants)3.1 - Establish and Maintain Inventory of Enterprise Assets7
419130Compromise of Hardware Supply Chain (Hardware Implants)18.1 - Establish and Maintain a Penetration Testing Program6
420131Formjacking Attacks Stealing Payment Card Data12.4 - Implement and Manage Security for Software Applications9
421131Formjacking Attacks Stealing Payment Card Data11.2 - Implement and Manage Web Browser Protections7
422131Formjacking Attacks Stealing Payment Card Data14.1 - Establish and Maintain a Security Logging and Monitoring Process6
423132SIM Swapping Leading to Account Takeover4.2 - Implement and Manage Multi-Factor Authentication for Enterprise Accounts9
424132SIM Swapping Leading to Account Takeover16.1 - Conduct Security Awareness and Skills Training7
425132SIM Swapping Leading to Account Takeover4.1 - Establish and Maintain a Secure Access Control Policy and Procedures6
426133Attacks Targeting APIs of Third-Party Services6.2 - Establish and Maintain a Baseline Configuration of Endpoints7
427133Attacks Targeting APIs of Third-Party Services12.4 - Implement and Manage Security for Software Applications8
428133Attacks Targeting APIs of Third-Party Services13.6 - Monitor Supplier Security7
429134Insufficient Segmentation of Cloud Workloads5.4 - Securely Configure Cloud Infrastructure9
430134Insufficient Segmentation of Cloud Workloads6.3 - Implement and Manage Network Segmentation8
431134Insufficient Segmentation of Cloud Workloads4.1 - Establish and Maintain a Secure Access Control Policy and Procedures7
432135Compromise of Managed Service Provider (MSP) Infrastructure4.6 - Manage External Accounts8
433135Compromise of Managed Service Provider (MSP) Infrastructure13.5 - Manage Supplier Access9
434135Compromise of Managed Service Provider (MSP) Infrastructure14.1 - Establish and Maintain a Security Logging and Monitoring Process7
435136Abuse of Stored Cross-Site Scripting (XSS) Vulnerabilities8.4 - Perform Application Security Testing9
436136Abuse of Stored Cross-Site Scripting (XSS) Vulnerabilities12.2 - Secure Software via Secure Coding Practices8
437136Abuse of Stored Cross-Site Scripting (XSS) Vulnerabilities6.2 - Establish and Maintain a Baseline Configuration of Endpoints6
438137Exploitation of Race Conditions in Applications12.2 - Secure Software via Secure Coding Practices8
439137Exploitation of Race Conditions in Applications8.4 - Perform Application Security Testing7
440137Exploitation of Race Conditions in Applications14.1 - Establish and Maintain a Security Logging and Monitoring Process6
441138ARP Spoofing and Man-in-the-Middle Attacks on Local Networks6.4 - Implement and Manage Network Infrastructure Device Hardening8
442138ARP Spoofing and Man-in-the-Middle Attacks on Local Networks6.3 - Implement and Manage Network Segmentation7
443138ARP Spoofing and Man-in-the-Middle Attacks on Local Networks14.1 - Establish and Maintain a Security Logging and Monitoring Process6
444139DNS Spoofing and Cache Poisoning Attacks6.7 - Implement and Manage Domain Name System (DNS) Security9
445139DNS Spoofing and Cache Poisoning Attacks14.1 - Establish and Maintain a Security Logging and Monitoring Process7
446139DNS Spoofing and Cache Poisoning Attacks11.2 - Implement and Manage Web Browser Protections6
447140Border Gateway Protocol (BGP) Hijacking6.4 - Implement and Manage Network Infrastructure Device Hardening8
448140Border Gateway Protocol (BGP) Hijacking14.1 - Establish and Maintain a Security Logging and Monitoring Process7
449140Border Gateway Protocol (BGP) Hijacking1.4 - Establish and Maintain a Threat Intelligence Program6
450141ICMP Flood Attacks6.5 - Implement and Manage Distributed Denial of Service (DDoS) Mitigation Techniques8
451141ICMP Flood Attacks6.4 - Implement and Manage Network Infrastructure Device Hardening7
452141ICMP Flood Attacks14.1 - Establish and Maintain a Security Logging and Monitoring Process6
453142SYN Flood Attacks6.5 - Implement and Manage Distributed Denial of Service (DDoS) Mitigation Techniques9
454142SYN Flood Attacks6.4 - Implement and Manage Network Infrastructure Device Hardening8
455142SYN Flood Attacks14.1 - Establish and Maintain a Security Logging and Monitoring Process7
456143Smurf Attacks6.5 - Implement and Manage Distributed Denial of Service (DDoS) Mitigation Techniques8
457143Smurf Attacks6.4 - Implement and Manage Network Infrastructure Device Hardening7
458143Smurf Attacks14.1 - Establish and Maintain a Security Logging and Monitoring Process6
459144Fraggle Attacks6.5 - Implement and Manage Distributed Denial of Service (DDoS) Mitigation Techniques8
460144Fraggle Attacks6.4 - Implement and Manage Network Infrastructure Device Hardening7
461144Fraggle Attacks14.1 - Establish and Maintain a Security Logging and Monitoring Process6
462145GTP Tunneling Exploits in Mobile Networks6.4 - Implement and Manage Network Infrastructure Device Hardening7
463145GTP Tunneling Exploits in Mobile Networks14.1 - Establish and Maintain a Security Logging and Monitoring Process6
464145GTP Tunneling Exploits in Mobile Networks1.4 - Establish and Maintain a Threat Intelligence Program5
465146SIP Flood Attacks Targeting VoIP Infrastructure6.5 - Implement and Manage Distributed Denial of Service (DDoS) Mitigation Techniques9
466146SIP Flood Attacks Targeting VoIP Infrastructure6.4 - Implement and Manage Network Infrastructure Device Hardening7
467146SIP Flood Attacks Targeting VoIP Infrastructure14.1 - Establish and Maintain a Security Logging and Monitoring Process6
468147LLMNR/NBT-NS Poisoning4.1 - Establish and Maintain a Secure Access Control Policy and Procedures7
469147LLMNR/NBT-NS Poisoning6.3 - Implement and Manage Network Segmentation8
470147LLMNR/NBT-NS Poisoning14.1 - Establish and Maintain a Security Logging and Monitoring Process6
471148Pass-the-Hash Attacks4.1 - Establish and Maintain a Secure Access Control Policy and Procedures9
472148Pass-the-Hash Attacks4.3 - Manage Privileged Access8
473148Pass-the-Hash Attacks14.1 - Establish and Maintain a Security Logging and Monitoring Process7
474149Pass-the-Ticket Attacks (Kerberoasting)4.1 - Establish and Maintain a Secure Access Control Policy and Procedures8
475149Pass-the-Ticket Attacks (Kerberoasting)4.3 - Manage Privileged Access9
476149Pass-the-Ticket Attacks (Kerberoasting)14.1 - Establish and Maintain a Security Logging and Monitoring Process7
477150Golden SAML Attacks4.1 - Establish and Maintain a Secure Access Control Policy and Procedures9
478150Golden SAML Attacks4.3 - Manage Privileged Access8
479150Golden SAML Attacks14.1 - Establish and Maintain a Security Logging and Monitoring Process7