Files
old-riskletpy/test_cs.csv

4.6 KiB

1CIS v8.1 Safeguards (Sub-Controls)
23.1 - Establish and Maintain Inventory of Enterprise Assets
33.3 - Manage Assets
45.1 - Establish and Maintain a Secure Configuration Process
55.3 - Securely Configure Enterprise Assets and Software
68.1 - Establish and Maintain a Vulnerability Management Process
79.2 - Deploy and Maintain Anti-Malware Software
810.8 - Perform and Test Data Backups
915.1 - Develop an Incident Response Plan
103.4 - Manage Sensitive Assets
114.1 - Establish and Maintain a Secure Access Control Policy and Procedures
124.2 - Implement and Manage Multi-Factor Authentication for Enterprise Accounts
136.3 - Implement and Manage Network Segmentation
147.1 - Establish and Maintain a Data Management Process
157.2 - Implement and Enforce Data Retention
167.3 - Implement Data Loss Prevention (DLP)
1712.5 - Enforce Encryption of Data-at-Rest
1812.6 - Enforce Encryption of Data-in-Transit
194.3 - Manage Privileged Access
204.4 - Manage Service Accounts
214.6 - Manage External Accounts
2214.5 - Establish and Maintain an Audit Log Review and Analysis Process
2316.1 - Conduct Security Awareness and Skills Training
243.6 - Establish and Maintain an Inventory of Non-Enterprise Assets
2513.1 - Establish and Maintain a Security Awareness Program
2618.1 - Establish and Maintain a Penetration Testing Program
2719.1 - Establish and Maintain an Incident Response Plan
2820.1 - Establish and Maintain a Business Continuity Plan
2916.2 - Train Workforce Members on Social Engineering Attacks
3019.8 - Perform Post-Incident Reviews
311.1 - Establish and Maintain Enterprise Governance
321.2 - Establish and Maintain Enterprise Security Policies
331.3 - Establish and Maintain Enterprise Agreements
342.1 - Establish and Maintain an Inventory of Authorized Software
3510.9 - Perform Off-Site Backups
3610.10 - Securely Store Backups
3711.1 - Implement and Manage Email Protections
3817.1 - Implement Physical Access Controls
3917.2 - Monitor Physical Environment
406.1 - Establish and Maintain a Baseline Configuration of Network Devices
416.4 - Implement and Manage Network Infrastructure Device Hardening
426.5 - Implement and Manage Distributed Denial of Service (DDoS) Mitigation Techniques
4314.1 - Establish and Maintain a Security Logging and Monitoring Process
448.2 - Remediate Vulnerabilities Based on Risk
458.3 - Verify Application of Security Patches
463.2 - Utilize an Automated Asset Discovery Tool
4713.5 - Manage Supplier Access
4813.6 - Monitor Supplier Security
493.5 - Manage Enterprise Assets Connected to the Enterprise Network Remotely
504.5 - Manage Mobile Devices
515.4 - Securely Configure Cloud Infrastructure
525.5 - Securely Configure Cloud Workloads
536.2 - Establish and Maintain a Baseline Configuration of Endpoints
544.7 - Enforce Account Password Requirements
554.8 - Enforce Multi-Factor Authentication for All Users
5616.4 - Establish and Maintain a Role-Based Security Training Program
5716.5 - Conduct Skills Gap Assessments
5817.3 - Plan and Implement Environmental Protections
595.6 - Securely Configure Industrial Control Systems (ICS)
606.6 - Implement and Manage Network Segmentation for ICS
611.5 - Conduct Periodic Security Risk Assessments
6214.7 - Conduct Security Controls Testing and Validation
6315.4 - Establish and Maintain a Security Architecture
641.4 - Establish and Maintain a Threat Intelligence Program
652.2 - Utilize Standard Security Configurations for Enterprise Software and Hardware
668.4 - Perform Application Security Testing
6712.1 - Establish and Maintain a Software Development Life Cycle (SDLC)
689.1 - Establish and Maintain a Software Allow List
6911.2 - Implement and Manage Web Browser Protections
706.7 - Implement and Manage Domain Name System (DNS) Security
7112.7 - Plan and Implement Cryptographic Key Management
727.4 - Securely Dispose of Assets
7312.2 - Secure Software via Secure Coding Practices
746.8 - Secure Wireless Access Points
754.9 - Manage Access to Enterprise Applications
7611.3 - Implement and Manage Endpoint Protections
7712.6 - Enforce Encryption of Data-in-Transit 66,Insufficient Data Encryption"
7814.2 - Integrate Threat Intelligence into Security Monitoring
7914.3 - Establish and Maintain Alerting and Escalation Processes
8019.2 - Establish and Maintain an Incident Response Team
8119.3 - Develop and Conduct Incident Response Exercises
825.2 - Implement and Manage a Change Management Process
835.7 - Securely Configure Containers
8412.3 - Manage Credentials
8516.3 - Establish and Maintain a Security Skills Development Program
869.3 - Implement and Manage Endpoint Detection and Response (EDR)
8713.3 - Implement and Manage Secure Software Supply Chain Practices
8812.4 - Implement and Manage Security for Software Applications
8913.4 - Implement and Manage Secure Hardware Supply Chain Practices