Skip to content
Release: Australia · Updated: 2026-03-12 · Official documentation · View source

Indicator templates for controls

The Technology Controls Monitoring Accelerator includes 273 indicator templates (94 Basic, 174 Manual, and 5 Scripted) for CIS v7 and includes new 67 indicator templates (64 Basic and 3 Scripted) for CIS v8.

When the Technology Controls Monitoring Accelerator is used along with the Cybersecurity Controls Accelerator application, you can manage indicator templates within the Cybersecurity Controls Accelerator application.

When Technology Controls Monitoring Accelerator is run as a standalone application; however, it can be run with the Policy and Compliance Management application. You can also map UCF controls to indicator templates from with the Policy and Compliance Management application.

Note: For information on the different types of indicator templates, see Using indicator templates.

Indicator templates for CIS v8 Controls

The following table lists the indicator templates for CIS v8 Controls.

Note: Controls currently not covered by either basic or scripted indicator templates have manual indicator templates defined for the purposes of compliance validation. For more information on CIS v8 indicator templates, see KB0555526.

ControlName/DescriptionTypeCompliance validated bySource tableRelated control objectives
CIS Control V8 1.1Establish and Maintain Detailed Enterprise Asset Inventory: Establish and maintain an accurate, detailed, and up-to-date inventory of all enterprise assets with the potential to store or process data, to include: end-user devices \(including portable and mobile\), network devices, non-computing/IoT devices, and servers. Ensure the inventory records the network address \(if static\), hardware address, machine name, data asset owner, department for each asset, and whether the asset has been approved to connect to the network. For mobile end-user devices, MDM type tools can support this process, where appropriate. This inventory includes assets connected to the infrastructure physically, virtually, remotely, and those within cloud environments. Additionally, it includes assets that are regularly connected to the enterprise’s network infrastructure, even if they are not under control of the enterprise. Review and update the inventory of all enterprise assets bi-annually, or more frequently.BASICHAMcmdb\_ci\_hardwareCIS v8 \(1.1\) CSF \(ID.AM-1, PR.DS-3\) ISO 27002 \(5.9, 8.8\) PCI \(9.5.1, 9.5.1.1, 11.2, 11.2.1, 11.2.2, 12.5, 12.5.1\) CCM \(UEM-04\)
CIS Control V8 1.2Address Unauthorized Assets: Ensure that a process exists to address unauthorized assets on a weekly basis. The enterprise may choose to remove the asset from the network, deny the asset from connecting remotely to the network, or quarantine the asset.BASICCMDBcmdb\_ciCIS v8 \(1.2\) NIST \(CM-8\) PCI \(11.2.1\)
CIS Control V8 1.3Utilize an Active Discovery Tool: Utilize an active discovery tool to identify assets connected to the enterprise’s network. Configure the active discovery tool to execute daily, or more frequently.BASICDiscoverycmdb\_discoveryCIS v8 \(1.3\) CSF \(DE.CM-7\) NIST \(CM-8\(1\)\) CCM \(UEM-05\)
CIS Control V8 1.4Use Dynamic Host Configuration Protocol \(DHCP\) Logging to Update Enterprise Asset Inventory: Use DHCP logging on all DHCP servers or Internet Protocol \(IP\) address management tools to update the enterprise’s asset inventory. Review and use logs to update the enterprise’s asset inventory weekly, or more frequently.ManualNANA 
CIS Control V8 1.5Use a Passive Asset Discovery Tool: Use a passive discovery tool to identify assets connected to the enterprise’s network. Review and use scans to update the enterprise’s asset inventory at least weekly, or more frequently.BASICDiscoverydiscovery\_network\_trackCIS v8 \(1.5\) CSF \(DE.CM-7\) NIST \(CM-8\(3\)\)
CIS Control V8 2.1Establish and Maintain a Software Inventory: Establish and maintain a detailed inventory of all licensed software installed on enterprise assets. The software inventory must document the title, publisher, initial install/use date, and business purpose for each entry; where appropriate, include the Uniform Resource Locator \(URL\), app store\(s\), version\(s\), deployment mechanism, and decommission date. Review and update the software inventory bi-annually, or more frequently.BASICSAMcmdb\_ci\_application\_softwareCIS v8 \(2.1\) CSF \(ID.AM-2\) ISO \(5.9\) NIST \(SI-4\) PCI \(1.2.5, 6.3.2\) CCM \(UEM-02\)
CIS Control V8 2.2Ensure Authorized Software is Currently Supported Ensure that only currently supported software is designated as authorized in the software inventory for enterprise assets. If software is unsupported, yet necessary for the fulfillment of the enterprise’s mission, document an exception detailing mitigating controls and residual risk acceptance. For any unsupported software without an exception documentation, designate as unauthorized. Review the software list to verify software support at least monthly, or more frequently.ManualNANA 
CIS Control V8 2.3Address Unauthorized Software: Ensure that unauthorized software is either removed from use on enterprise assets or receives a documented exception. Review monthly, or more frequently.SCRIPTEDSAMcmdb\_sam\_sw\_installCIS v8 \(2.3\) CSF \(DE.CM-7\) ISO \(8.7\) NIST \(CM-8\(3\)\) PCI \(12.3.4\)
CIS Control V8 2.4Utilize Automated Software Inventory Tools: Utilize software inventory tools, when possible, throughout the enterprise to automate the discovery and documentation of installed software.BASICSAMcmdb\_ci\_application\_softwareCIS v8 \(2.4\) CSF \(DE.CM-7\) NIST \(SI-4\)
CIS Control V8 2.5Allowlist Authorized Software: Use technical controls, such as application allowlisting, to ensure that only authorized software can execute or be accessed. Reassess bi-annually, or more frequently.SCRIPTEDSAMcmdb\_sam\_sw\_installCIS v8 \(2.5\) CSF \(DE.CM-7\) ISO \(8.7, 8.17\) PCI \(1.2.5, 2.2.4\)
CIS Control V8 2.6Allowlist Authorized Libraries: Use technical controls to ensure that only authorized software libraries, such as specific .dll, .ocx, .so, etc., files, are allowed to load into a system process. Block unauthorized libraries from loading into a system process. Reassess bi-annually, or more frequently.BASICVRsn\_vulc\_resultCIS v8 \(2.6\) CSF \(DE.CM-7\) ISO \(8.19\) PCI \(1.2.5, 2.2.4\)
CIS Control V8 2.7Allowlist Authorized Scripts: Use technical controls, such as digital signatures and version control, to ensure that only authorized scripts, such as specific .ps1, .py, etc., files, are allowed to execute. Block unauthorized scripts from executing. Reassess bi-annually, or more frequently.BASICVRsn\_vulc\_resultCIS v8 \(2.7\) CSF \(PR.IP-1, PR.PT-3\) NIST \(CM-8\) PCI \(1.2.5, 2.2.4, 6.4.3\)
CIS Control V8 3.1Establish and Maintain a Data Management Process: Establish and maintain a data management process. In the process, address data sensitivity, data owner, handling of data, data retention limits, and disposal requirements, based on sensitivity and retention standards for the enterprise. Review and update documentation annually, or when significant enterprise changes occur that could impact this Safeguard.ManualNANA 
CIS Control V8 3.10Encrypt Sensitive Data in Transit: Encrypt sensitive data in transit. Example implementations can include, Transport Layer Security \(TLS\) and Open Secure Shell \(OpenSSH\).BASICDiscoverysn\_disco\_certmgmt\_cmdb\_installed\_certificateCIS v8 \(3.10\) CSF \(PR.IP-6, PR.DS-2\) ISO \(5.1, 5.9, 8.1, 5.14\) NIST \(CM-7\(1\), CM-10\) PCI \(9.4, 9.4.2, 2.2.7, 4.1.1, 4.2.1, 4.2.1.2, 4.2.2, 8.3.2\) CCM \(DSP-01, DSP-06, GRC-03, CEK-03\)
CIS Control V8 3.11Encrypt Sensitive Data At Rest: Encrypt sensitive data at rest on servers, applications, and databases containing sensitive data. Storage-layer encryption, also known as server-side encryption, meets the minimum requirement of this Safeguard. Additional encryption methods may include application-layer encryption, also known as client-side encryption, where access to the data storage device\(s\) does not permit access to the plain-text data.BASICCMDBcmdb\_rel\_ciCIS v8 \(3.11\) CSF \(PR.DS-1\) ISO \(5.33\) NIST \(CM-7\) PCI \(3.1.1, 3.3.2, 3.3.3, 3.5.1, 3.5.1.2, 3.5.1.3, 8.3.2\) CCM \(DSP-10, CEK-03\)
CIS Control V8 3.12Segment Data Processing and Storage Based on Sensitivity: Segment data processing and storage based on the sensitivity of the data. Do not process sensitive data on enterprise assets intended for lower sensitivity data.ManualNANA 
CIS Control V8 3.13Deploy a Data Loss Prevention Solution: Implement an automated tool, such as a host-based Data Loss Prevention \(DLP\) tool to identify all sensitive data stored, processed, or transmitted through enterprise assets, including those located onsite or at a remote service provider, and update the enterprise's sensitive data inventory.BASICCMDBcmdb\_rel\_ciCIS v8 \(3.13\) CSF \(PR.DS-5\) ISO \(5.13, 8.12\) NIST \(CM-7\) CCM \(DSP-10, UEM-11\)
CIS Control V8 3.14Log Sensitive Data Access: Log sensitive data access, including modification and disposal.BASICVRsn\_vulc\_resultCIS v8 \(3.14\) ISO \(-8.15\) NIST \(CM-7\(1\)\) PCI \(10.2.1, 10.2.1.1\) CCM \(DSP-17, IAM-12, LOG-04\)
CIS Control V8 3.2Establish and Maintain a Data Inventory: Establish and maintain a data inventory, based on the enterprise’s data management process. Inventory sensitive data, at a minimum. Review and update inventory annually, at a minimum, with a priority on sensitive data.ManualNANA 
CIS Control V8 3.3Configure Data Access Control Lists: Configure data access control lists based on a user’s need to know. Apply data access control lists, also known as access permissions, to local and remote file systems, databases, and applications.BASICVRsn\_vulc\_resultCIS v8 \(3.3\) CSF \(PR.AC-4\) ISO \(5.1, 5.15, 8.3, 8.4\) NIST \(SA-22\) PCI \(1.3. 1, 7.1\) CCM \(DSP-17, IAM-05\)
CIS Control V8 3.4Enforce Data Retention: Retain data according to the enterprise’s data management process. Data retention must include both minimum and maximum timelines.ManualNANA 
CIS Control V8 3.5Securely Dispose of Data: Securely dispose of data as outlined in the enterprise’s data management process. Ensure the disposal process and method are commensurate with the data sensitivity.ManualNANA 
CIS Control V8 3.6Encrypt Data on End-User Devices: Encrypt data on end-user devices containing sensitive data. Example implementations can include Windows BitLocker™, Apple FileVault™ , Linux dm-crypt™.BASICCMDBcmdb\_rel\_ciCIS v8 \(3.6\) ISO \(6.7, 7.1, 8.1\) NIST \(CM-100\) CCM \(CEK-03, UEM-08\)
CIS Control V8 3.7Establish and Maintain a Data Classification Scheme: Establish and maintain an overall data classification scheme for the enterprise. Enterprises may use labels, such as “Sensitive,” “Confidential,” and “Public,” and classify their data according to those labels. Review and update the classification scheme annually, or when significant enterprise changes occur that could impact this Safeguard.ManualNANA 
CIS Control V8 3.8Document Data Flows: Document data flows. Data flow documentation includes service provider data flows and should be based on the enterprise’s data management process. Review and update documentation annually, or when significant enterprise changes occur that could impact this Safeguard.ManualNANA 
CIS Control V8 3.9Encrypt Data on Removable Media: Encrypt data on removable media.ManualNANA 
CIS Control V8 4.1Establish and Maintain a Secure Configuration Process: Establish and maintain a secure configuration process for enterprise assets \(end-user devices, including portable and mobile; non-computing/IoT devices; and servers\) and software \(operating systems and applications\). Review and update documentation annually, or when significant enterprise changes occur that could impact this Safeguard.ManualNANA 
CIS Control V8 4.10Enforce Automatic Device Lockout on Portable End-User Devices: Enforce automatic device lockout following a predetermined threshold of local failed authentication attempts on portable end-user devices, where supported. For laptops, do not allow more than 20 failed authentication attempts; for tablets and smartphones, no more than 10 failed authentication attempts. Example implementations include Microsoft InTune Device Lock and Apple Configuration Profile maxFailedAttempts.BASICVRsn\_vulc\_resultCIS v8 \(4.10\) CSF \(PR.IP-1\) ISO \(8.1, 8.5, 8.9\) NIST \(SI-7, PM-5\(1\)\) PCI \(1.1.1, 1.2.1, 1.2.6, 1.5.1, 1.2.7, 2.1.1, 2.2.1, 8.3.4\) CCM \(CCC-01, GRC-03, IVS-04\)
CIS Control V8 4.11Enforce Remote Wipe Capability on Portable End-User Devices: Remotely wipe enterprise data from enterprise-owned portable end-user devices when deemed appropriate such as lost or stolen devices, or when an individual no longer supports the enterprise.ManualNANA 
CIS Control V8 4.12Separate Enterprise Workspaces on Mobile End-User Devices: Ensure separate enterprise workspaces are used on mobile end-user devices, where supported. Example implementations include using an Apple Configuration Profile or Android Work Profile to separate enterprise applications and data from personal applications and data.ManualNANA 
CIS Control V8 4.2Establish and Maintain a Secure Configuration Process for Network Infrastructure: Establish and maintain a secure configuration process for network devices. Review and update documentation annually, or when significant enterprise changes occur that could impact this Safeguard.ManualNANA 
CIS Control V8 4.3Configure Automatic Session Locking on Enterprise Assets: Configure automatic session locking on enterprise assets after a defined period of inactivity. For general purpose operating systems, the period must not exceed 15 minutes. For mobile end-user devices, the period must not exceed 2 minutes.BASICVRsn\_vulc\_resultCIS v8 \(4.3\) CSF \(PR.IP-1\) ISO \(8.5, 8.9\) PCI \(8.2.8\) CCM \(UEM-06\)
CIS Control V8 4.4Implement and Manage a Firewall on Servers: Implement and manage a firewall on servers, where supported. Example implementations include a virtual firewall, operating system firewall, or a third-party firewall agent.BASICVRsn\_vulc\_resultCIS v8 \(4.4\) PCI \(1.2.1, 1.4.1\)
CIS Control V8 4.5Implement and Manage a Firewall on End-User Devices: Implement and manage a host-based firewall or port-filtering tool on end-user devices, with a default-deny rule that drops all traffic except those services and ports that are explicitly allowed.ManualNANA 
CIS Control V8 4.6Securely Manage Enterprise Assets and Software: Securely manage enterprise assets and software. Example implementations include managing configuration through version-controlled-infrastructure-as-code and accessing administrative interfaces over secure network protocols, such as Secure Shell \(SSH\) and Hypertext Transfer Protocol Secure \(HTTPS\). Do not use insecure management protocols, such as Telnet \(Teletype Network\) and HTTP, unless operationally essential.ManualNANA 
CIS Control V8 4.7Manage Default Accounts on Enterprise Assets and Software: Manage default accounts on enterprise assets and software, such as root, administrator, and other pre-configured vendor accounts. Example implementations can include: disabling default accounts or making them unusable.BASICVRsn\_vulc\_resultCIS v8 \(4.7\) CSF \(PR.AC-1\) ISO \(8.2, 8.9\) NIST \(SI-12\) PCI \(2.2.2, 2.3.1\)
CIS Control V8 4.8Uninstall or Disable Unnecessary Services on Enterprise Assets and Software: Uninstall or disable unnecessary services on enterprise assets and software, such as an unused file sharing service, web application module, or service function.ManualNANA 
CIS Control V8 4.9Configure Trusted DNS Servers on Enterprise Assets: Configure trusted DNS servers on enterprise assets. Example implementations include: configuring assets to use enterprise-controlled DNS servers and/or reputable externally accessible DNS servers.BASICVRsn\_vulc\_resultCIS v8 \(4.9\) NIST \(PM-5\(1\)\)
CIS Control V8 5.1Establish and Maintain an Inventory of Accounts: Establish and maintain an inventory of all accounts managed in the enterprise. The inventory must include both user and administrator accounts. The inventory, at a minimum, should contain the person’s name, username, start/stop dates, and department. Validate that all active accounts are authorized, on a recurring schedule at a minimum quarterly, or more frequently.ManualNANA 
CIS Control V8 5.2Use Unique Passwords: Use unique passwords for all enterprise assets. Best practice implementation includes, at a minimum, an 8-character password for accounts using MFA and a 14-character password for accounts not using MFA.BASICVRsn\_vulc\_resultCIS v8 \(5.2\) ISO \(5.17\) NIST \(AC-5\) PCI \(2.2.2, 8.3.5, 8.5.6, 8.6.3\) CCM \(IAM-02\)
CIS Control V8 5.3Disable Dormant Accounts: Delete or disable any dormant accounts after a period of 45 days of inactivity, where supported.ManualNANA 
CIS Control V8 5.4Restrict Administrator Privileges to Dedicated Administrator Accounts: Restrict administrator privileges to dedicated administrator accounts on enterprise assets. Conduct general computing activities, such as internet browsing, email, and productivity suite use, from the user’s primary, non-privileged account.ManualNANA 
CIS Control V8 5.5Establish and Maintain an Inventory of Service Accounts: Establish and maintain an inventory of service accounts. The inventory, at a minimum, must contain department owner, review date, and purpose. Perform service account reviews to validate all active accounts are authorized, on a recurring schedule at a minimum quarterly, or more frequently.ManualNANA 
CIS Control V8 5.6Centralize Account Management: Centralize account management through a directory or identity service.ManualNANA 
CIS Control V8 6.1Establish an Access Granting Process: Establish and follow a process, preferably automated, for granting access to enterprise assets upon new hire, rights grant, or role change of a user.ManualNANA 
CIS Control V8 6.2Establish an Access Revoking Process: Establish and follow a process, preferably automated, for revoking access to enterprise assets, through disabling accounts immediately upon termination, rights revocation, or role change of a user. Disabling accounts, instead of deleting accounts, may be necessary to preserve audit trails.ManualNANA 
CIS Control V8 6.3Require MFA for Externally-Exposed Applications: Require all externally-exposed enterprise or third-party applications to enforce MFA, where supported. Enforcing MFA through a directory service or SSO provider is a satisfactory implementation of this Safeguard.ManualNANA 
CIS Control V8 6.4Require MFA for Remote Network Access: Require MFA for remote network access.ManualNANA 
CIS Control V8 6.5Require MFA for Administrative Access: Require MFA for all administrative access accounts, where supported, on all enterprise assets, whether managed on-site or through a third-party provider.ManualNANA 
CIS Control V8 6.6Establish and Maintain an Inventory of Authentication and Authorization Systems: Establish and maintain an inventory of the enterprise’s authentication and authorization systems, including those hosted on-site or at a remote service provider. Review and update the inventory, at a minimum, annually, or more frequently.ManualNANA 
CIS Control V8 6.7Centralize Access Control: Centralize access control for all enterprise assets through a directory service or SSO provider, where supported.ManualNANA 
CIS Control V8 6.8Define and Maintain Role-Based Access Control: Define and maintain role-based access control, through determining and documenting the access rights necessary for each role within the enterprise to successfully carry out its assigned duties. Perform access control reviews of enterprise assets to validate that all privileges are authorized, on a recurring schedule at a minimum annually, or more frequently.ManualNANA 
CIS Control V8 7.1Establish and Maintain a Vulnerability Management Process: Establish and maintain a documented vulnerability management process for enterprise assets. Review and update documentation annually, or when significant enterprise changes occur that could impact this Safeguard.ManualNANA 
CIS Control V8 7.2Establish and Maintain a Remediation Process: Establish and maintain a risk-based remediation strategy documented in a remediation process, with monthly, or more frequent, reviews.BASICVRsn\_vul\_m2m\_ttr\_statusCIS v8 \(7.2\) CSF \(ID.RA-1\) ISO \(8.8\) NIST \(IA-5\) PCI \(6.3.1, 6.4.1\) CCM \(A&A-03, TVM-08, TVM-10\)
CIS Control V8 7.3Perform Automated Operating System Patch Management: Perform operating system updates on enterprise assets through automated patch management on a monthly, or more frequent, basis.ManualNANA 
CIS Control V8 7.4Perform Automated Application Patch Management: Perform application updates on enterprise assets through automated patch management on a monthly, or more frequent, basis.ManualNANA 
CIS Control V8 7.5Perform Automated Vulnerability Scans of Internal Enterprise Assets: Perform automated vulnerability scans of internal enterprise assets on a quarterly, or more frequent, basis. Conduct both authenticated and unauthenticated scans, using a SCAP-compliant vulnerability scanning tool.BASICVRsn\_vul\_ds\_import\_q\_entryCIS v8 \(7.5\) CSF \(DE.CM-8\) ISO \(8.8\) NIST \(SC-8\(1\)\) PCI \(11.3.1, 11.3.1.1, 11.3.1.2, 11.3.1.3\) CCM \(TVM-07\)
CIS Control V8 7.6Perform Automated Vulnerability Scans of Externally-Exposed Enterprise Assets: Perform automated vulnerability scans of externally-exposed enterprise assets using a SCAP-compliant vulnerability scanning tool. Perform scans on a monthly, or more frequent, basis.BASICVRsn\_vul\_ds\_import\_q\_entry 
CIS Control V8 7.7Remediate Detected Vulnerabilities: Remediate detected vulnerabilities in software through processes and tooling on a monthly, or more frequent, basis, based on the remediation process.BASICVRsn\_vul\_app\_vulnerabilityCIS v8 \(7.7\) ISO \(8.8\) NIST \(SC-28\) PCI \(11.3.1, 11.3.2, 11.3.2.1\) CCM \(TVM-03\)
CIS Control V8 8.1Establish and Maintain an Audit Log Management Process: Establish and maintain an audit log management process that defines the enterprise’s logging requirements. At a minimum, address the collection, review, and retention of audit logs for enterprise assets. Review and update documentation annually, or when significant enterprise changes occur that could impact this Safeguard.ManualNANA 
CIS Control V8 8.1Retain Audit Logs: Retain audit logs across enterprise assets for a minimum of 90 days.ManualNANA 
CIS Control V8 8.11Conduct Audit Log Reviews: Conduct reviews of audit logs to detect anomalies or abnormal events that could indicate a potential threat. Conduct reviews on a weekly, or more frequent, basis.ManualNANA 
CIS Control V8 8.12Collect Service Provider Logs: Collect service provider logs, where supported. Example implementations include collecting authentication and authorization events, data creation and disposal events, and user management events.ManualNANA 
CIS Control V8 8.2Collect Audit Logs: Collect audit logs. Ensure that logging, per the enterprise’s audit log management process, has been enabled across enterprise assets.BASICVRsn\_vulc\_resultCIS v8 \(8.2\) CSF \(PR.PT-1, DE.AE-3\) ISO \(8.15, 8.2\) PCI \(5.3.4, 6.4.1, 6.4.2, 10.2.1, 10.2.1.1, 10.2.1.2, 10.2.1.3, 10.2.1.4, 10.2.1.5, 10.2.1.6, 10.2.1.7, 10.2.2\) CCM \(LOG-08\)
CIS Control V8 8.3Ensure Adequate Audit Log Storage: Ensure that logging destinations maintain adequate storage to comply with the enterprise’s audit log management process.ManualNANA 
CIS Control V8 8.4Standardize Time Synchronization: Standardize time synchronization. Configure at least two synchronized time sources across enterprise assets, where supported.ManualNANA 
CIS Control V8 8.5Collect Detailed Audit Logs: Configure detailed audit logging for enterprise assets containing sensitive data. Include event source, date, username, timestamp, source addresses, destination addresses, and other useful elements that could assist in a forensic investigation.ManualNANA 
CIS Control V8 8.6Collect DNS Query Audit Logs: Collect DNS query audit logs on enterprise assets, where appropriate and supported.ManualNANA 
CIS Control V8 8.7Collect URL Request Audit Logs: Collect URL request audit logs on enterprise assets, where appropriate and supported.ManualNANA 
CIS Control V8 8.8Collect Command-Line Audit Logs: Collect command-line audit logs. Example implementations include collecting audit logs from PowerShell™, BASH™, and remote administrative terminals.ManualNANA 
CIS Control V8 8.9Centralize Audit Logs: Centralize, to the extent possible, audit log collection and retention across enterprise assets.BASICCMDBcmdb\_ciCIS v8 \(8.9\) NIST \(AU-12\) PCI \(10.3.3\)
CIS Control V8 9.1Ensure Use of Only Fully Supported Browsers and Email Clients: Ensure only fully supported browsers and email clients are allowed to execute in the enterprise, only using the latest version of browsers and email clients provided through the vendor.BASICVRsn\_vulc\_resultCIS v8 \(9.1\) CSF \(PR.IP-1\) ISO \(8.1\) NIST \(CM-2\)
CIS Control V8 9.2Use DNS Filtering Services: Use DNS filtering services on all enterprise assets to block access to known malicious domains.ManualNANA 
CIS Control V8 9.3Maintain and Enforce Network-Based URL Filters: Enforce and update network-based URL filters to limit an enterprise asset from connecting to potentially malicious or unapproved websites. Example implementations include category-based filtering, reputation-based filtering, or through the use of block lists. Enforce filters for all enterprise assets.BASICVRsn\_vulc\_resultCIS v8 \(9.3\) CSF \(PR.AC-5\) ISO \(8.7, 8.23\) NIST \(CM-7\) PCI \(1.2.6, 1.4.2\)
CIS Control V8 9.4Restrict Unnecessary or Unauthorized Browser and Email Client Extensions: Restrict, either through uninstalling or disabling, any unauthorized or unnecessary browser or email client plugins, extensions, and add-on applications.BASICVRsn\_vulc\_resultCIS v8 \(9.4\) CSF \(PR.IP-1\) NIST \(CM-7\(1\)\) PCI \(2.2.4\)
CIS Control V8 9.5Implement DMARC: To lower the chance of spoofed or modified emails from valid domains, implement DMARC policy and verification, starting with implementing the Sender Policy Framework \(SPF\) and the DomainKeys Identified Mail \(DKIM\) standards.ManualNANA 
CIS Control V8 9.6Block Unnecessary File Types: Block unnecessary file types attempting to enter the enterprise’s email gateway.ManualNANA 
CIS Control V8 9.7Deploy and Maintain Email Server Anti-Malware Protections: Deploy and maintain email server anti-malware protections, such as attachment scanning and/or sandboxing.BASICCMDBcmdb\_rel\_ciCIS v8 \(9.7\) CSF \(DE.CM-4\) ISO \(8.7\) NIST \(SA-80\) PCI \(5.2.1, 5.4.1\) CCM \(TVM-02\)
CIS Control V8 10.1Deploy and Maintain Anti-Malware Software: Deploy and maintain anti-malware software on all enterprise assets.BASICCMDBcmdb\_ciCIS v8 \(10.1\) CSF \(DE.CM-4\) ISO \(8.1, 8.7\) NIST \(SA-10\) PCI \(5.1.1, 5.2.1, 5.2.2, 5.3.2\) CCM \(TVM-02, UEM-09\)
CIS Control V8 10.2Configure Automatic Anti-Malware Signature Updates: Configure automatic updates for anti-malware signature files on all enterprise assets.ManualNANA 
CIS Control V8 10.3Disable Autorun and Autoplay for Removable Media: Disable autorun and autoplay auto-execute functionality for removable media.BASICVRsn\_vulc\_resultCIS v8 \(10.3\) CSF \(PR.PT-2\) ISO \(7.1\) NIST \(AC-18\(1\)\)
CIS Control V8 10.4Configure Automatic Anti-Malware Scanning of Removable Media: Configure anti-malware software to automatically scan removable media.BASICVRsn\_vulc\_resultCIS v8 \(10.4\) CSF \(DE.CM-4\) ISO \(7.1, 8.7\) NIST \(AC-18\(3\)\) PCI \(5.3.3\)
CIS Control V8 10.5Enable Anti-Exploitation Features: Enable anti-exploitation features on enterprise assets and software, where possible, such as Microsoft Data Execution Prevention \(DEP\), Windows Defender Exploit Guard \(WDEG\), or Apple System Integrity Protection \(SIP\) and Gatekeeper™.BASICVRsn\_vulc\_resultCIS v8 \(10.5\) CSF \(DE.CM-4\) ISO \(8.7\) NIST \(CM-2\)
CIS Control V8 10.6Centrally Manage Anti-Malware Software: Centrally manage anti-malware software.ManualNANA 
CIS Control V8 10.7Use Behavior-Based Anti-Malware Software: Use behavior-based anti-malware software.BASICCMDBcmdb\_rel\_ciCIS v8 \(10.7\) CSF \(DE.CM-4\) ISO \(8.1, 8.7\) NIST \(CM-7\) PCI \(5.3.2\)
CIS Control V8 11.1Establish and Maintain a Data Recovery Process : Establish and maintain a data recovery process. In the process, address the scope of data recovery activities, recovery prioritization, and the security of backup data. Review and update documentation annually, or when significant enterprise changes occur that could impact this Safeguard.ManualNANA 
CIS Control V8 11.2Perform Automated Backups : Perform automated backups of in-scope enterprise assets. Run backups weekly, or more frequently, based on the sensitivity of the data.ManualNANA 
CIS Control V8 11.3Protect Recovery Data: Protect recovery data with equivalent controls to the original data. Reference encryption or data separation, based on requirements.ManualNANA 
CIS Control V8 11.4Establish and Maintain an Isolated Instance of Recovery Data : Establish and maintain an isolated instance of recovery data. Example implementations include version controlling backup destinations through offline, cloud, or off-site systems or services.ManualNANA 
CIS Control V8 11.5Test Data Recovery: Test backup recovery quarterly, or more frequently, for a sampling of in-scope enterprise assets.ManualNANA 
CIS Control V8 12.1Ensure Network Infrastructure is Up-to-Date: Ensure network infrastructure is kept up-to-date. Example implementations include running the latest stable release of software and/or using currently supported network-as-a-service \(NaaS\) offerings. Review software versions monthly, or more frequently, to verify software support.ManualNANA 
CIS Control V8 12.2Establish and Maintain a Secure Network Architecture: Establish and maintain a secure network architecture. A secure network architecture must address segmentation, least privilege, and availability, at a minimum.ManualNANA 
CIS Control V8 12.3Securely Manage Network Infrastructure: Securely manage network infrastructure. Example implementations include version-controlled-infrastructure-as-code, and the use of secure network protocols, such as SSH and HTTPS.ManualNANA 
CIS Control V8 12.4Establish and Maintain Architecture Diagram\(s\): Establish and maintain architecture diagram\(s\) and/or other network system documentation. Review and update documentation annually, or when significant enterprise changes occur that could impact this Safeguard.ManualNANA 
CIS Control V8 12.5Centralize Network Authentication, Authorization, and Auditing \(AAA\): Centralize network AAA.ManualNANA 
CIS Control V8 12.6Use of Secure Network Management and Communication Protocols : Use secure network management and communication protocols \(e.g., 802.1X, Wi-Fi Protected Access 2 \(WPA2\) Enterprise or greater\).BASICVRsn\_vulc\_resultCIS v8 \(12.6\) CSF \(PR.AC-7, PR.DS-2\) ISO \(8.21\) NIST \(SC-7\(5\)\)
CIS Control V8 12.7Ensure Remote Devices Utilize a VPN and are Connecting to an Enterprise’s AAA Infrastructure: Require users to authenticate to enterprise-managed VPN and authentication services prior to accessing enterprise resources on end-user devices.ManualNANA 
CIS Control V8 12.8Establish and Maintain Dedicated Computing Resources for All Administrative Work: Establish and maintain dedicated computing resources, either physically or logically separated, for all administrative tasks or tasks requiring administrative access. The computing resources should be segmented from the enterprise's primary network and not be allowed internet access.ManualNANA 
CIS Control V8 13.1Centralize Security Event Alerting: Centralize security event alerting across enterprise assets for log correlation and analysis. Best practice implementation requires the use of a SIEM, which includes vendor-defined event correlation alerts. A log analytics platform configured with security-relevant correlation alerts also satisfies this Safeguard.ManualNANA 
CIS Control V8 13.1Perform Application Layer Filtering: Perform application layer filtering. Example implementations include a filtering proxy, application layer firewall, or gateway.ManualNANA 
CIS Control V8 13.11Tune Security Event Alerting Thresholds: Tune security event alerting thresholds monthly, or more frequently.ManualNANA 
CIS Control V8 13.2Deploy a Host-Based Intrusion Detection Solution: Deploy a host-based intrusion detection solution on enterprise assets, where appropriate and/or supported.BASICCMDBcmdb\_rel\_ciCIS v8 \(13.2\) CSF \(DE.CM-1\) ISO \(8.16\) NIST \(CM-6\) PCI \(6.4.2\)
CIS Control V8 13.3Deploy a Network Intrusion Detection Solution: Deploy a network intrusion detection solution on enterprise assets, where appropriate. Example implementations include the use of a Network Intrusion Detection System \(NIDS\) or equivalent cloud service provider \(CSP\) service.BASICCMDBcmdb\_ciCIS v8 \(13.3\) CSF \(DE.CM-1\) ISO \(8.16, 8.21\) NIST \(CM-7\) PCI \(11.5.1, 12.10.5\) CCM \(IVS-09\)
CIS Control V8 13.4Perform Traffic Filtering Between Network Segments: Perform traffic filtering between network segments, where appropriate.ManualNANA 
CIS Control V8 13.5Manage Access Control for Remote Assets: Manage access control for assets remotely connecting to enterprise resources. Determine amount of access to enterprise resources based on: up-to-date anti-malware software installed; configuration compliance with the enterprise’s secure configuration process; and ensuring the operating system and applications are up-to-date.ManualNANA 
CIS Control V8 13.6Collect Network Traffic Flow Logs: Collect network traffic flow logs and/or network traffic to review and alert upon from network devices.ManualNANA 
CIS Control V8 13.7Deploy a Host-Based Intrusion Prevention Solution: Deploy a host-based intrusion prevention solution on enterprise assets, where appropriate and/or supported. Example implementations include use of an Endpoint Detection and Response \(EDR\) client or host-based IPS agent.BASICCMDBcmdb\_ciCIS v8 \(13.7\) CSF \(DE.CM-1\) ISO \(8.8\) NIST \(AC-7\)
CIS Control V8 13.8Deploy a Network Intrusion Prevention Solution: Deploy a network intrusion prevention solution, where appropriate. Example implementations include the use of a Network Intrusion Prevention System \(NIPS\) or equivalent CSP service.BASICCMDBcmdb\_ciCIS v8 \(13.8\) CSF \(DE.CM-1\) ISO \(8.8\) NIST \(AC-19\) PCI \(6.4.2, 11.5.1, 12.10.5\) CCM \(IVS-09\)
CIS Control V8 13.9Deploy Port-Level Access Control: Deploy port-level access control. Port-level access control utilizes 802.1x, or similar network access control protocols, such as certificates, and may incorporate user and/or device authentication.BASICCMDBcmdb\_ci\_endpoint\_aclCIS v8 \(13.9\) CSF \(PR.AC-1\) ISO \(8.8\) NIST \(AC-19\) PCI \(1.2.1, 1.2.5, 1.2.6, 2.2.4\) CCM \(IVS-03\)
CIS Control V8 14.1Establish and Maintain a Security Awareness Program: Establish and maintain a security awareness program. The purpose of a security awareness program is to educate the enterprise’s workforce on how to interact with enterprise assets and data in a secure manner. Conduct training at hire and, at a minimum, annually. Review and update content annually, or when significant enterprise changes occur that could impact this Safeguard.BASICLearning Coresn\_lc\_user\_course\_activityCIS v8 \(14.1\) CSF \(ID.AM-6, ID.GV-1, PR.AT-1\) ISO \(6.3\) NIST \(SC-39\) PCI \(12.6, 12.6.1, 12.6.2, 12.6.3, 12.6.3.2\) CCM \(GRC-05, HRS-11, GRC-03\)
CIS Control V8 14.2Train Workforce Members to Recognize Social Engineering Attacks: Train workforce members to recognize social engineering attacks, such as phishing, pre-texting, and tailgating. BASICLearning Coresn\_lc\_user\_course\_activityCIS v8 \(14.2\) CSF \(PR.AT-1\) ISO \(8.7\) PCI \(12.6.3.1\) CCM \(HRS-11\)
CIS Control V8 14.3Train Workforce Members on Authentication Best Practices: Train workforce members on authentication best practices. Example topics include MFA, password composition, and credential management.BASICLearning Coresn\_lc\_user\_course\_activityCIS v8 \(14.3\) CSF \(PR.AT-1\) ISO \(6.3\) PCI \(8.3.8\) CCM \(GRC-05, HRS-11\)
CIS Control V8 14.4Train Workforce on Data Handling Best Practices: Train workforce members on how to identify and properly store, transfer, archive, and destroy sensitive data. This also includes training workforce members on clear screen and desk best practices, such as locking their screen when they step away from their enterprise asset, erasing physical and virtual whiteboards at the end of meetings, and storing data and assets securely.BASICLearning Coresn\_lc\_user\_course\_activityCIS v8 \(14.4\) CSF \(PR.AT-1\) ISO \(5.1\) NIST \(AC-2\) CCM \(DSP-17, GRC-01, HRS-03, HRS-12\)
CIS Control V8 14.5Train Workforce Members on Causes of Unintentional Data Exposure: Train workforce members to be aware of causes for unintentional data exposure. Example topics include mis-delivery of sensitive data, losing a portable end-user device, or publishing data to unintended audiences.BASICLearning Coresn\_lc\_user\_course\_activityCIS v8 \(14.5\) CSF \(PR.AT-1\) ISO \(6.3\) NIST \(IA-5\(1\)\) CCM \(GRC-01, HRS-11\)
CIS Control V8 14.6Train Workforce Members on Recognizing and Reporting Security Incidents: Train workforce members to be able to recognize a potential incident and be able to report such an incident. BASICLearning Coresn\_lc\_user\_course\_activityCIS v8 \(14.6\) CSF \(PR.AT-1\) ISO \(6.8\) NIST \(AC-2\(3\)\) CCM \(HRS-11\)
CIS Control V8 14.7Train Workforce on How to Identify and Report if Their Enterprise Assets are Missing Security Updates: Train workforce to understand how to verify and report out-of-date software patches or any failures in automated processes and tools. Part of this training should include notifying IT personnel of any failures in automated processes and tools.BASICLearning Coresn\_lc\_user\_course\_activityCIS v8 \(14.7\) CSF \(PR.AT-1\) ISO \(6.3\) NIST \(AC-6\(2\)\) CCM \(HRS-11\)
CIS Control V8 14.8Train Workforce on the Dangers of Connecting to and Transmitting Enterprise Data Over Insecure Networks: Train workforce members on the dangers of connecting to, and transmitting data over, insecure networks for enterprise activities. If the enterprise has remote workers, training must include guidance to ensure that all users securely configure their home network infrastructure.BASICLearning Coresn\_lc\_user\_course\_activityCIS v8 \(14.8\) CSF \(PR.AT-1\) ISO \(6.3\) NIST \(AC-6\(5\)\) PCI \(12.6.3.2\) CCM \(GRC-01, HRS-04\)
CIS Control V8 14.9Conduct Role-Specific Security Awareness and Skills Training: Conduct role-specific security awareness and skills training. Example implementations include secure system administration courses for IT professionals, \(OWASP ™ Top 10 vulnerability awareness and prevention training for web application developers, and advanced social engineering awareness training for high-profile roles.BASICLearning Coresn\_lc\_user\_course\_activityCIS v8 \(14.9\) CSF \(PR.AT-1, PR.AT-2, R.AT-4, PR.AT-5\) ISO \(6.3\) NIST \(AC-2\) PCI \(9.5.1, 9.5.1.3, 12.10.40 CCM \(HRS-09, HRS-12\)
CIS Control V8 15.1Establish and Maintain an Inventory of Service Providers: Establish and maintain an inventory of service providers. The inventory is to list all known service providers, include classification\(s\), and designate an enterprise contact for each service provider. Review and update the inventory annually, or when significant enterprise changes occur that could impact this Safeguard.BASICVRMcore\_companyCIS v8 \(15.1\) CSF \(ID.SC-2\) ISO \(5.19\) NIST \(AC-2\(1\)\) PCI \(12.8.1\) CCM \(STA-07\)
CIS Control V8 15.2Establish and Maintain a Service Provider Management Policy: Establish and maintain a service provider management policy. Ensure the policy addresses the classification, inventory, assessment, monitoring, and decommissioning of service providers. Review and update the policy annually, or when significant enterprise changes occur that could impact this Safeguard.ManualNANA 
CIS Control V8 15.3Classify Service Providers: Classify service providers. Classification consideration may include one or more characteristics, such as data sensitivity, data volume, availability requirements, applicable regulations, inherent risk, and mitigated risk. Update and review classifications annually, or when significant enterprise changes occur that could impact this Safeguard.BASICVRMcore\_companyCIS v8 \(15.3\) CSF \(ID.SC-2\) ISO \(5.19\) PCI \(12.8.5\) CCM \(GRC-02, STA-08\)
CIS Control V8 15.4Ensure Service Provider Contracts Include Security Requirements: Ensure service provider contracts include security requirements. Example requirements may include minimum security program requirements, security incident and/or data breach notification and response, data encryption requirements, and data disposal commitments. These security requirements must be consistent with the enterprise’s service provider management policy. Review service provider contracts annually to ensure contracts are not missing security requirements.ManualNANA 
CIS Control V8 15.5Assess Service Providers: Assess service providers consistent with the enterprise’s service provider management policy. Assessment scope may vary based on classification\(s\), and may include review of standardized assessment reports, such as Service Organization Control 2 \(SOC 2\) and Payment Card Industry \(PCI\) Attestation of Compliance \(AoC\), customized questionnaires, or other appropriately rigorous processes. Reassess service providers annually, at a minimum, or with new and renewed contracts.BASICVRMcore\_companyCIS v8 \(15.5\) CSF \(ID.SC-4, ID.SC-2\) ISO \(5.19\) NIST \(IA-5\) PCI \(12.8.3\) CCM \(STA-12, STA-13\)
CIS Control V8 15.5Assess Service Providers: Assess service providers consistent with the enterprise’s service provider management policy. Assessment scope may vary based on classification\(s\), and may include review of standardized assessment reports, such as Service Organization Control 2 \(SOC 2\) and Payment Card Industry \(PCI\) Attestation of Compliance \(AoC\), customized questionnaires, or other appropriately rigorous processes. Reassess service providers annually, at a minimum, or with new and renewed contracts.BASICVRMcore\_companyCIS v8 \(15.5\) CSF \(ID.SC-4, ID.SC-2\) ISO \(5.22, 5.23\) NIST \(IA-5\) PCI \(12.8.30\) CCM \(STA-12, STA-13\)
CIS Control V8 15.6Monitor Service Providers: Monitor service providers consistent with the enterprise’s service provider management policy. Monitoring may include periodic reassessment of service provider compliance, monitoring service provider release notes, and dark web monitoring.BASICVRMcore\_companyCIS v8 \(15.6\) CSF \(DE.CM-6\) ISO \(5.2, 5.19, 5.21, 5.22\) NIST \(AC-1\) PCI \(8.2.7, 12.4.2, 12.4.2.1, 12.8.4 CCM \(STA-14\)
CIS Control V8 15.7Securely Decommission Service Providers: Securely decommission service providers. Example considerations include user and service account deactivation, termination of data flows, and secure disposal of enterprise data within service provider systems.BASICVRMcore\_companyCIS v8 \(15.7\) CSF \(PR.AC-1\) ISO \(5.19, 5.2\) NIST \(AC-2, AC-2\(1\)\)
CIS Control V8 16.1Establish and Maintain a Secure Application Development Process: Establish and maintain a secure application development process. In the process, address such items as: secure application design standards, secure coding practices, developer training, vulnerability management, security of third-party code, and application security testing procedures. Review and update documentation annually, or when significant enterprise changes occur that could impact this Safeguard.ManualNANA 
CIS Control V8 16.1Apply Secure Design Principles in Application Architectures: Apply secure design principles in application architectures. Secure design principles include the concept of least privilege and enforcing mediation to validate every operation that the user makes, promoting the concept of "never trust user input." Examples include ensuring that explicit error checking is performed and documented for all input, including for size, data type, and acceptable ranges or formats. Secure design also means minimizing the application infrastructure attack surface, such as turning off unprotected ports and services, removing unnecessary programs and files, and renaming or removing default accounts.ManualNANA 
CIS Control V8 16.11Leverage Vetted Modules or Services for Application Security Components: Leverage vetted modules or services for application security components, such as identity management, encryption, and auditing and logging. Using platform features in critical security functions will reduce developers’ workload and minimize the likelihood of design or implementation errors. Modern operating systems provide effective mechanisms for identification, authentication, and authorization and make those mechanisms available to applications. Use only standardized, currently accepted, and extensively reviewed encryption algorithms. Operating systems also provide mechanisms to create and maintain secure audit logs.ManualNANA 
CIS Control V8 16.12Implement Code-Level Security Checks: Apply static and dynamic analysis tools within the application lifecycle to verify that secure coding practices are being followed.ManualNA  
CIS Control V8 16.13Conduct Application Penetration Testing: Conduct application penetration testing. For critical applications, authenticated penetration testing is better suited to finding business logic vulnerabilities than code scanning and automated security testing. Penetration testing relies on the skill of the tester to manually manipulate an application as an authenticated and unauthenticated user. ManualNANA 
CIS Control V8 16.14Conduct Threat Modeling: Conduct threat modeling. Threat modeling is the process of identifying and addressing application security design flaws within a design, before code is created. It is conducted through specially trained individuals who evaluate the application design and gauge security risks for each entry point and access level. The goal is to map out the application, architecture, and infrastructure in a structured way to understand its weaknesses.ManualNANA 
CIS Control V8 16.2Establish and Maintain a Process to Accept and Address Software Vulnerabilities: Establish and maintain a process to accept and address reports of software vulnerabilities, including providing a means for external entities to report. The process is to include such items as: a vulnerability handling policy that identifies reporting process, responsible party for handling vulnerability reports, and a process for intake, assignment, remediation, and remediation testing. As part of the process, use a vulnerability tracking system that includes severity ratings, and metrics for measuring timing for identification, analysis, and remediation of vulnerabilities. Review and update documentation annually, or when significant enterprise changes occur that could impact this Safeguard.BASICVRsn\_vul\_remediation\_taskCIS v8 \(16.2\) CSF \(RS.AN-5\) ISO \(8.8\) NIST \(AC-2\) PCI \(6.3.1\) CCM \(AIS-07, AIS-03\)
CIS Control V8 16.3Perform Root Cause Analysis on Security Vulnerabilities: Perform root cause analysis on security vulnerabilities. When reviewing vulnerabilities, root cause analysis is the task of evaluating underlying issues that create vulnerabilities in code, and allows development teams to move beyond just fixing individual vulnerabilities as they arise.ManualNANA 
CIS Control V8 16.4Establish and Manage an Inventory of Third-Party Software Components: Establish and manage an updated inventory of third-party components used in development, often referred to as a “bill of materials,” as well as components slated for future use. This inventory is to include any risks that each third-party component could pose. Evaluate the list at least monthly to identify any changes or updates to these components, and validate the component is still supported. ManualNANA 
CIS Control V8 16.5Use Up-to-Date and Trusted Third-Party Software Components: Use up-to-date and trusted third-party software components. When possible, choose established and proven frameworks and libraries that provide adequate security. Acquire these components from trusted sources or evaluate the software for vulnerabilities before use.ManualNANA 
CIS Control V8 16.6Establish and Maintain a Severity Rating System and Process for Application Vulnerabilities: Establish and maintain a severity rating system and process for application vulnerabilities that facilitates prioritizing the order in which discovered vulnerabilities are fixed. This process includes setting a minimum level of security acceptability for releasing code or applications. Severity ratings bring a systematic way of triaging vulnerabilities that improves risk management and helps ensure the most severe bugs are fixed first. Review and update the system and process annually.BASICVRsn\_vul\_vulnerable\_itemCIS v8 \(16.6\) CSF \(RS.AN-1\) ISO \(8.8\) NIST \(AC-19\) PCI \(6.3.1\) CCM \(AIS-07, TVM-08\)
CIS Control V8 16.7Use Standard Hardening Configuration Templates for Application Infrastructure: Use standard, industry-recommended hardening configuration templates for application infrastructure components. This includes underlying servers, databases, and web servers, and applies to cloud containers, Platform as a Service \(PaaS\) components, and SaaS components. Do not allow in-house developed software to weaken configuration hardening.ManualNANA 
CIS Control V8 16.8Separate Production and Non-Production Systems: Maintain separate environments for production and non-production systems.SCRIPTEDCMDBcmdb\_ciCIS v8 \(16.8\) CSF \(PR.DS-7\) ISO \(8.31\) NIST \(IA-2\(2\)\) PCI \(6.5.3\) CCM \(IVS-05\)
CIS Control V8 16.9Train Developers in Application Security Concepts and Secure Coding: Ensure that all software development personnel receive training in writing secure code for their specific development environment and responsibilities. Training can include general security principles and application security standard practices. Conduct training at least annually and design in a way to promote security within the development team, and build a culture of security among the developers.BASICLearning Coresn\_lc\_user\_course\_activityCIS v8 \(16.9\) CSF \(PR.AT-1, PR.AT-2\) ISO \(8.28\) NIST \(IA-2\(1\)\) PCI \(6.2.2\)
CIS Control V8 17.1Designate Personnel to Manage Incident Handling: Designate one key person, and at least one backup, who will manage the enterprise’s incident handling process. Management personnel are responsible for the coordination and documentation of incident response and recovery efforts and can consist of employees internal to the enterprise, third-party vendors, or a hybrid approach. If using a third-party vendor, designate at least one person internal to the enterprise to oversee any third-party work. Review annually, or when significant enterprise changes occur that could impact this Safeguard.BASICSIRsys\_user\_has\_roleCIS v8 \(17.1\) CSF \(PR.IP-9, DE.DP-1\) ISO \(5.24\) NIST \(AC-5\) PCI \(12.10.3, 12.10.4\) CCM \(BCR-01, SEF-03\)
CIS Control V8 17.2Establish and Maintain Contact Information for Reporting Security Incidents: Establish and maintain contact information for parties that need to be informed of security incidents. Contacts may include internal staff, third-party vendors, law enforcement, cyber insurance providers, relevant government agencies, Information Sharing and Analysis Center \(ISAC\) partners, or other stakeholders. Verify contacts annually to ensure that information is up-to-date.ManualNANA 
CIS Control V8 17.3Establish and Maintain an Enterprise Process for Reporting Incidents: Establish and maintain an enterprise process for the workforce to report security incidents. The process includes reporting timeframe, personnel to report to, mechanism for reporting, and the minimum information to be reported. Ensure the process is publicly available to all of the workforce. Review annually, or when significant enterprise changes occur that could impact this Safeguard.BASICSIRkb\_knowledgeCIS v8 \(17.3\) CSF \(PR.IP-9, PR.AT-1\) ISO \(6.8\) NIST \(AC-6\(1\)\) PCI \(12.10\)
CIS Control V8 17.4Establish and Maintain an Incident Response Process: Establish and maintain an incident response process that addresses roles and responsibilities, compliance requirements, and a communication plan. Review annually, or when significant enterprise changes occur that could impact this Safeguard.ManualSIRNA 
CIS Control V8 17.5Assign Key Roles and Responsibilities: Assign key roles and responsibilities for incident response, including staff from legal, IT, information security, facilities, public relations, human resources, incident responders, and analysts, as applicable. Review annually, or when significant enterprise changes occur that could impact this Safeguard.BASICSIRsys\_user\_has\_roleCIS v8 \(17.5\) CSF \(DE.DP-4, RS.CO-2, RS.CO-3, RS.CO-4\) ISO \(5.2, 5.24\) NIST \(AU-9\(4\)\) PCI \(12.10.3\) CCM \(SEF-03\)
CIS Control V8 17.6Define Mechanisms for Communicating During Incident Response: Determine which primary and secondary mechanisms will be used to communicate and report during a security incident. Mechanisms can include phone calls, emails, or letters. Keep in mind that certain mechanisms, such as emails, can be affected during a security incident. Review annually, or when significant enterprise changes occur that could impact this Safeguard.ManualNANA 
CIS Control V8 17.7Conduct Routine Incident Response Exercises: Plan and conduct routine incident response exercises and scenarios for key personnel involved in the incident response process to prepare for responding to real-world incidents. Exercises need to test communication channels, decision making, and workflows. Conduct testing on an annual basis, at a minimum.ManualNANA 
CIS Control V8 17.8Conduct Post-Incident Reviews: Conduct post-incident reviews. Post-incident reviews help prevent incident recurrence through identifying lessons learned and follow-up action.ManualNANA 
CIS Control V8 17.9Establish and Maintain Security Incident Thresholds: Establish and maintain security incident thresholds, including, at a minimum, differentiating between an incident and an event. Examples can include: abnormal activity, security vulnerability, security weakness, data breach, privacy incident, etc. Review annually, or when significant enterprise changes occur that could impact this Safeguard.BASICSIRsn\_si\_calculatorCIS v8 \(17.9\) CSF \(RS.AN-5\) ISO \(5.24, 5.25\) NIST \(RA-5\) PCI \(12.10.5\) CCM \(SEF-05\)
CIS Control V8 18.1Establish and Maintain a Penetration Testing Program: Establish and maintain a penetration testing program appropriate to the size, complexity, and maturity of the enterprise. Penetration testing program characteristics include scope, such as network, web application, Application Programming Interface \(API\), hosted services, and physical premise controls; frequency; limitations, such as acceptable hours, and excluded attack types; point of contact information; remediation, such as how findings will be routed internally; and retrospective requirements.ManualNANA 
CIS Control V8 18.2Perform Periodic External Penetration Tests: Perform periodic external penetration tests based on program requirements, no less than annually. External penetration testing must include enterprise and environmental reconnaissance to detect exploitable information. Penetration testing requires specialized skills and experience and must be conducted through a qualified party. The testing may be clear box or opaque box.BASICVRsn\_vul\_remediation\_taskCIS v8 \(18.2\) ISO \(8.8\) NIST \(RA-7\) PCI \(11.4.3\)
CIS Control V8 18.3Remediate Penetration Test Findings: Remediate penetration test findings based on the enterprise’s policy for remediation scope and prioritization.ManualNANA 
CIS Control V8 18.4Validate Security Measures: Validate security measures after each penetration test. If deemed necessary, modify rulesets and capabilities to detect the techniques used during testing.ManualNANA 
CIS Control V8 18.5Perform Periodic Internal Penetration Tests: NABASICVRsn\_vul\_remediation\_taskCIS v8 \(18.5\) ISO \(8.8\) NIST \(RA-5\) PCI \(11.4.2\)

Indicator templates for CIS v7 Controls

The following tables list the Basic and Script indicator templates for CIS v7 Controls.

Note: Controls currently not covered by either basic or scripted indicator templates have manual indicator templates defined for the purposes of compliance validation.

ControlName/DescriptionCompliance validated bySource tableRelated UCF IDs
CIS Control 1.1Utilize an Active Discovery Tool:Utilize an active discovery tool to identify devices connected to the organization's network and update the hardware asset inventory.Configuration Management \(CMDB\)CMDB Discovery \[cmdb\_discovery\]07054 00693
CIS Control 1.2Use a Passive Asset Discovery Tool: Utilize a passive discovery tool to identify devices connected to the organization's network and automatically update the organization's hardware asset inventory.DiscoveryNetwork Discovery Tracking \[discovery\_network\_track\]01472
CIS Control 1.4Maintain Detailed Asset Inventory:Maintain an accurate and up-to-date inventory of all technology assets with the potential to store or process information. This inventory shall include all hardware assets, whether connected to the organization's network or not.Configuration Management \(CMDB\)Hardware \[cmdb\_ci\_hardware\]06631 00691
CIS Control 1.5Maintain Asset Inventory Information:Ensure that the hardware asset inventory records the network address, hardware address, machine name, data asset owner, and department for each asset and whether the hardware asset has been approved to connect to the network.Configuration Management \(CMDB\)Base Configuration Item \[cmdb\]06638 06640 12084 06636 13721 13722
CIS Control 1.7Deploy Port Level Access Control:Utilize port level access control, following 802.1x standards, to control which devices can authenticate to the network. The authentication system shall be tied into the hardware asset inventory data to ensure only authorized devices can connect to the network.Configuration Management \(CMDB\)ACL Endpoint \[cmdb\_ci\_endpoint\_acl\]11841 13718
CIS Control 1.8Utilize Client Certificates to Authenticate Hardware Assets:Use client certificates to authenticate hardware assets connecting to the organization's trusted network.Certification CoreAudit \[cert\_audit\]01429
CIS Control 2.1Maintain Inventory of Authorized Software:Maintain an up-to-date list of all authorized software that is required in the enterprise for any business purpose on any business system.Configuration Management \(CMDB\)Application Software \[cmdb\_ci\_application\_software\]12093 13723
CIS Control 2.2Ensure Software is Supported by Vendor:Ensure that only software applications or operating systems currently supported by the software's vendor are added to the organization's authorized software inventory. Unsupported software should be tagged as unsupported in the inventory system.Software Asset ManagementSoftware Product Lifecycle \[sam\_sw\_product\_lifecycle\]07054
CIS Control 2.3Utilize Software Inventory Tools:Utilize software inventory tools throughout the organization to automate the documentation of all software on business systems.Configuration Management \(CMDB\)Application Software \[cmdb\_ci\_application\_software\]11736 12196 13720 13725
CIS Control 2.4Track Software Inventory Information:The software inventory system should track the name, version, publisher, and installation date for all software, including operating systems authorized by the organization.Software Asset Management CoreSoftware Installation \[cmdb\_sam\_sw\_install\]12085
CIS Control 2.5Integrate Software and Hardware Asset Inventories:The software inventory system should be tied into the hardware asset inventory so all devices and associated software are tracked from a single location.Configuration Management \(CMDB\)Application Software \[cmdb\_ci\_application\_software\]11637 11857
CIS Control 3.1Run Automated Vulnerability Scanning Tools:Utilize an up-to-date SCAP-compliant vulnerability scanning tool to automatically scan all systems on the network on a weekly or more frequent basis to identify all potential vulnerabilities on the organization's systems.Vulnerability ResponseVulnerability Data Source Import Queue Entry \[sn\_vul\_ds\_import\_q\_entry\]10635
CIS Control 3.2Perform Authenticated Vulnerability Scanning:Perform authenticated vulnerability scanning with agents running locally on each system or with remote scanners that are configured with elevated rights on the system being tested.Security OperationsDiscovered Item \[sn\_sec\_cmn\_src\_ci\]00706
CIS Control 3.6Compare Back-to-back Vulnerability Scans:Regularly compare the results from back-to-back vulnerability scans to verify that vulnerabilities have been remediated in a timely manner.Vulnerability ResponseVulnerability Remediation Status \[sn\_vul\_m2m\_ttr\_status\]06080
CIS Control 4.2Change Default PasswordsBefore deploying any new asset, change all default passwords to have values consistent with administrative level accounts.Configuration ComplianceConfiguration Test \[sn\_vulc\_test\]01698 12122
CIS Control 4.4Use Unique PasswordsWhere multi-factor authentication is not supported \(such as local administrator, root, or service accounts\), accounts will use passwords that are unique to that system.Configuration ComplianceConfiguration Test \[sn\_vulc\_test\]01915 01337
CIS Control 4.8Log and Alert on Changes to Administrative Group MembershipConfigure systems to issue a log entry and alert when an account is added to or removed from any group assigned administrative privileges.Configuration ComplianceConfiguration Test \[sn\_vulc\_test\]06312
CIS Control 4.9Log and Alert on Unsuccessful Administrative Account LoginConfigure systems to issue a log entry and alert on unsuccessful logins to an administrative account.Configuration ComplianceConfiguration Test \[sn\_vulc\_test\]06312 06331
CIS Control 6.2Activate audit logging:Ensure that local logging has been enabled on all systems and networking devices.Configuration ComplianceConfiguration Test \[sn\_vulc\_test\]00897
CIS Control 6.3Enable Detailed Logging:Enable system logging to include detailed information such as a event source, date, user, timestamp, source addresses, destination addresses, and other useful elements.Configuration ComplianceConfiguration Test \[sn\_vulc\_test\]00575
CIS Control 7.1Ensure Use of Only Fully Supported Browsers and Email Clients:Ensure that only fully supported web browsers and email clients are allowed to execute in the organization, ideally only using the latest version of the browsers and email clients provided by the vendor.Vulnerability ResponseApplication Vulnerable Item \[sn\_vul\_app\_vulnerable\_item\]00575 00576
CIS Control 8.1Utilize Centrally Managed Anti-malware Software Any enterprise class AV software will have this capability. By having a centrally managed AV, you can easily enable individual requirements.Configuration ComplianceConfiguration Test \[sn\_vulc\_test\]11861
CIS Control 8.2Ensure Anti-Malware Software and Signatures are UpdatedThe AV is only as good as it's signatures. While pure signature-based detection is no longer viable, even anomaly-based engines need to be updated on a regular basis. Ensure that the updates are rolled out automatically and use tools to verify that the signatures are actually up-to-date.Configuration ComplianceConfiguration Test \[sn\_vulc\_test\]01790
CIS Control 8.3Enable Operating System Anti-Exploitation Features/ Deploy Anti-Exploit TechnologiesThe DISA hardening guides provide step-by-step instructions on enabling these settings and so much more.Configuration ComplianceConfiguration Test \[sn\_vulc\_test\]11637 10678
CIS Control 8.4Configure Anti-Malware Scanning of Removable Devices Most AVs have this capability turned on by default, but it's still important to verify that it's actually still enabled. Malware coming in via a USB stick is a viable attack vector for nearly every organization.Configuration ComplianceConfiguration Test \[sn\_vulc\_test\]11927 04824 06735 00561 00564 04546
CIS Control 8.5Configure Devices Not To Auto-run ContentFor the same reason why you do not want to scan it, you also don't want it to run when it's mounted. This is a pretty quick setting to enable, and both CIS and DISA hardening guides have step-by-step instructions on disabling auto-run. Some SCM tools can quickly check every endpoint in your environment to make sure this setting is disabled.Configuration ComplianceConfiguration Test \[sn\_vulc\_test\]N/A
CIS Control 9.3Perform Regular Automated Port Scans:Perform automated port scans on a regular basis against all systems and alert if unauthorized ports are detected on a system.Vulnerability ResponseVulnerability Scanner \[sn\_vul\_scanner\]N/A
CIS Control 11.3Use Automated Tools to Verify Standard Device Configurations and Detect ChangesCompare all network device configuration against approved security configurations defined for each network device in use and alert when any deviations are discovered.Configuration ComplianceConfiguration Test \[sn\_vulc\_test\]06428 07058
CIS Control 11.4Install the Latest Stable Version of Any Security-related Updates on All Network Devices:Install the latest stable version of any security-related updates on all network devices.Vulnerability ResponseVulnerable Item \[sn\_vul\_vulnerable\_item\]01696
CIS Control 12.6Deploy Network-based IDS Sensor:Deploy network-based Intrusion Detection Systems \(IDS\) sensors to look for unusual attack mechanisms and detect compromise of these systems at each of the organization's network boundaries.Configuration Management \(CMDB\)Intrusion Detection System \[cmdb\_ci\_ids\_network\]00581
CIS Control 13.2Remove Sensitive Data or Systems Not Regularly Accessed by Organization:Remove sensitive data or systems not regularly accessed by the organization from the network. These systems shall only be used as stand alone systems \(disconnected from the network\) by the business unit needing to occasionally use the system or completely virtualized and powered off until needed.Configuration ComplianceConfiguration Test \[sn\_vulc\_test\]13726 13727
CIS Control 13.9Encrypt Data on USB Storage DevicesProvide the training to employees so they are aware of the risks of data on USB drives. Then provide them with the tools to secure your organization's critical data.Configuration ComplianceConfiguration Test \[sn\_vulc\_test\]11927
CIS Control 14.4Encrypt All Sensitive Information in Transit:Encrypt all sensitive information in transit.Configuration ComplianceConfiguration Test \[sn\_vulc\_test\]00564
CIS Control 15.1Maintain an Inventory of Authorized Wireless Access Points:Maintain an inventory of authorized wireless access points connected to the wired network.Configuration Management \(CMDB\)Wireless Access Point \[cmdb\_ci\_wap\_network\]00693
CIS Control 16.1Maintain an Inventory of Authentication Systems:Maintain an inventory of each of the organization's authentication systems, including those located onsite or at a remote service provider.Configuration Management \(CMDB\)Active Directory Domain Controller \[cmdb\_ci\_ad\_controller\]13724
CIS Control 16.4Encrypt or Hash all Authentication Credentials:Encrypt or hash with a salt all authentication credentials when stored.Configuration ComplianceConfiguration Test \[sn\_vulc\_test\]06735
CIS Control 16.5Encrypt Transmittal of Username and Authentication Credentials:Ensure that all account usernames and authentication credentials are transmitted across networks using encrypted channels.Configuration ComplianceConfiguration Test \[sn\_vulc\_test\]00564
CIS Control 16.11Lock Workstation Sessions After Inactivity:Automatically lock workstation sessions after a standard period of inactivity.Configuration ComplianceConfiguration Test \[sn\_vulc\_test\]04490
CIS Control 16.13Alert on Account Login Behavior Deviation:Alert when users deviate from normal login behavior, such as time-of-day, workstation location and duration.Security Incident ResponseSecurity Incident \[sn\_si\_incident\]07068 07070 07069
CIS Control 18.5Use Only Standardized and Extensively Reviewed Encryption Algorithms:Use only standardized and extensively reviewed encryption algorithms.CMDB CI Class ModelsUnique Certificate \[cmdb\_ci\_certificate\]00037
CIS Control 18.8Establish a Process to Accept and Address Reports of Software Vulnerabilities:Establish a process to accept and address reports of software vulnerabilities, including providing a means for external entities to contact your security group.Vulnerability ResponseDiscovery Model Vulnerable Software Match \[sn\_vul\_discovery\_model\_software\_match\]04810
CIS Control 19.2Assign Job Titles and Duties for Incident Response:Assign job titles and duties for handling computer and network incidents to specific individuals and ensure tracking and documentation throughout the incident through resolution.Incident ManagementUser Roles \[sys\_user\_has\_role\]07061 00691
CIS Control 19.3Designate Management Personnel to Support Incident Handling:Designate management personnel, as well as backups, who will support the incident handling process by acting in key decision-making roles.Incident ManagementUser Roles \[sys\_user\_has\_role\]01211
CIS Control 19.6Publish Information Regarding Reporting Computer Anomalies and Incidents:Publish information for all workforce members, regarding reporting computer anomalies and incidents to the incident handling team. Such information should be included in routine employee awareness activities.Security Incident ResponseKnowledge \[kb\_knowledge\]12093
CIS Control 19.8Create Incident Scoring and Prioritization Schema:Maintain separate environments for production and non-production systems. Developers should not have unmonitored access to production environments.Security Incident ResponseSecurity Incident Calculator \[sn\_si\_calculator\]12093 13723
ControlName/DescriptionCompliance validated bySource tableRelated UCF IDs
CIS Control 18.9Separate Production and Non-Production Systems:Maintain separate environments for production and nonproduction systems. Developers should not have unmonitored access to production environments.Configuration Management \(CMDB\)Configuration Item \[cmdb\_ci\]00922

Indicator templates for ISO Controls

The following tables list the Basic and Script indicator templates for ISO Controls.

Note: Controls currently not covered by either basic or scripted indicator templates have manual indicator templates defined for the purposes of compliance validation.

ControlName/DescriptionCompliance validated bySource tableRelated UCF IDs
ISO27002 - 5.1.1Policies for information security:Define an “information security policy” which is approved by management and which sets out the organization’s approach to managing its information security objectives. The information security policy are supported by topic-specific policies, which further mandate the implementation of information security controls to include: access control; information classification \(and handling\); physical and environmental security; backup; information transfer; protection from malware; management of technical vulnerabilities; cryptographic controls; communications security; privacy and protection of personally identifiable information; supplier relationships and end user oriented topics such as: 1\) acceptable use of assets; 2\) clear desk and clear screen; 3\) information transfer; 4\) mobile devices and teleworking; 5\) restrictions on software installations and use.GRC: Policy and Compliance ManagementCompliance Policy \[sn\_compliance\_policy\]N/A
ISO27002 - 6.1.1Information security roles and responsibilities:Ensure responsibilities for the protection of individual assets are identified in the asset inventory. Ensure roles and responsibilities for the development and implementation of information security are clearly defined.GRC: Policy and Compliance ManagementControl \[sn\_compliance\_control\]N/A
ISO27002 - 6.2.1Mobile device policy:Utilize approved whole disk encryption software to encrypt the hard drive of all mobile devices.GRC: Policy and Compliance ManagementCompliance Policy \[sn\_compliance\_policy\]07054 01472 12109 06631 00691 06638 06640 12084 06636 13721 13722 12093 11736 12196 13720 13725 00693 13724
ISO27002 - 6.2.2Teleworking:Enforce remote access policies for employees and contractors.GRC: Policy and Compliance ManagementCompliance Policy \[sn\_compliance\_policy\]N/A
ISO27002 - 7.1.1Screening:Ensure background verification check are performed for all employees and contractors prior to granting access to company's assets.Human Resources: CoreHR Talent Management Cases \[sn\_hr\_core\_case\_talent\_management\]12001 00897 04490 12100 12099 04594 04476
ISO27002 - 7.1.2Terms and conditions of employment:Ensure all new hire employees or contractors signed and agreed to the terms and conditions of employment, including their responsibility for information security.Human Resources: Coresn\_hr\_core\_task01429
ISO27002 - 8.1.1Inventory of assets:Ensure that the hardware asset inventory records the network address, hardware address, machine name, data asset owner, and department for each asset and whether the hardware asset has been approved to connect to the network.Configuration Management \(CMDB\)Base Configuration Item \[cmdb\]00562 00561 01915 01337 01421 06440
ISO27002 - 8.1.2Ownership of assets:Ensure that the hardware asset inventory records the network address, hardware address, machine name, data asset owner, and department for each asset and whether the hardware asset has been approved to connect to the network.Configuration Management \(CMDB\)Base Configuration Item \[cmdb\]06080 01273
ISO27002 - 8.1.3Acceptable use of assets:Ensure employees and contractors are made aware of the information security requirements of the organizations assets associated with information and information processing facilities and resources. They should be responsible for their use of any information processing resources and of any such use carried out under their responsibility.GRC: Policy and Compliance ManagementCompliance Policy \[sn\_compliance\_policy\]12001 00897 04490 12100 12099 04594 04476
ISO27002 - 9.3.1Use of secret authentication information:Use client certificates to authenticate hardware assets connecting to the organization's trusted network.Configuration ComplianceConfiguration Test \[sn\_vulc\_test\]01429
ISO27002 - 9.4.2Secure log-on procedures:Require all remote login access to the organization's network to encrypt data in transit and use multi-factor authentication.Configuration ComplianceConfiguration Test \[sn\_vulc\_test\]00562 00561 01915 01337 01421 06440
ISO27002 - 9.4.3Password management system:Where multi-factor authentication is not supported \(such as local administrator, root, or service accounts\), accounts will use passwords that are unique to that system.Configuration ComplianceConfiguration Test \[sn\_vulc\_test\]06080 01273
ISO27002 - 10.1.1Policy on the use of cryptographic controls:Ensure policy surrounding encryption exist and are applied, implemented and enforced in accordance to data classification requirements.GRC: Policy and Compliance ManagementCompliance Policy \[sn\_compliance\_policy\]07058 06428
ISO27002 - 10.1.2Key management:Ensure management of encryption keys are managed following a formal policy and procedure for the entire lifecycle of the key.GRC: Policy and Compliance ManagementCompliance Policy \[sn\_compliance\_policy\]00897 00575 00576 11861 01790
ISO27002 - 11.2.9Clear desk and clear screen policy:Ensure clear desk policy is adapted by employees and contractors.GRC: Policy and Compliance ManagementCompliance Policy \[sn\_compliance\_policy\]06312 00577 12210
ISO27002 - 12.1.2Controls against malware:Ensure that only fully supported web browsers and email clients are allowed to execute in the organization, ideally only using the latest version of the browsers and email clients provided by the vendor.Configuration ComplianceConfiguration Test \[sn\_vulc\_test\]N/A
ISO27002 - 12.2.1Controls against malware:Ensure that only fully supported web browsers and email clients are allowed to execute in the organization, ideally only using the latest version of the browsers and email clients provided by the vendor.Configuration ComplianceConfiguration Test \[sn\_vulc\_test\]N/A
ISO27002 - 12.4.1Event logging:Ensure that local logging has been enabled on all systems and networking devices.Instance Security CenterSecurity Dashboard Event Logs \[appsec\_security\_dashboard\_event\_logs\]N/A
ISO27002 - 12.4.2Protection of log information:Ensure logs are securely protected from unauthorized access. Access Roles \[sys\_security\_acl\_role\]N/A
ISO27002 - 12.4.3Administrator and operator logs:Enforce detailed audit logging for access to sensitive data or changes to sensitive data \(utilizing tools such as File Integrity Monitoring or Security Information and Event Monitoring\).Configuration ComplianceConfiguration Test \[sn\_vulc\_test\]N/A
ISO27002 - 13.2.1Information transfer policies and procedures:Ensure formal transfer policies, procedures and controls are in place to protect the transfer of information through the use of all types of communication facilities.GRC: Policy and Compliance ManagementCompliance Policy \[sn\_compliance\_policy\]N/A
ISO27002 - 14.1.1Information security requirements analysis and specification:Ensure information security related requirements are included in the requirements for new information systems or enhancements to existing information systems.GRC: Advanced RiskRisk Assessments \[sn\_risk\_advanced\_risk\_assessment\_instance\]N/A
ISO27002 - 14.2.2Technical review of applications after operating platform changes:Ensure business critical applications are reviewed and tested to ensure there is no adverse impact on organizational operations or security when ever there are changes to the operating platforms.Change RequestChange Request \[change\_request\]N/A
ISO27002 - 14.2.3Restrictions on changes to software packages:Ensure modifications to software packages are discouraged, or limited to necessary changes and all changes are strictly controlled.Change RequestChange Request \[change\_request\]N/A
ISO27002 - 14.2.4System security testing:Ensure security testing such as secure code reviews and vulnerability scan are performed during development lifecycle. Ensure identified vulnerabilities are documented and remediation are performed.Change RequestChange Request \[change\_request\]N/A
ISO27002 - 14.2.8System acceptance testing:Ensure system acceptance testing includes testing of information security requirements and adherence to secure system development practices.DevOpsBuild Test Results \[sn\_devops\_build\_test\_result\]N/A
ISO27002 - 14.2.9System acceptance testing:Ensure system acceptance testing includes testing of information security requirements and adherence to secure system development practices.DevOpsTask Executions \[sn\_devops\_task\_execution\]N/A
ISO27002 - 15.1.1Information security policy for supplier relationships:Ensure information security controls are addressed and resolved with the supplier prior to conducting business or granting vendor access to assets.GRC: Vendor Risk ManagementVendor Risk Assessment \[sn\_vdr\_risk\_asmt\_assessmentsn\_vdr\_risk\_asmt\_assessment\]N/A
ISO27002 - 15.1.3Information and communication technology supply chain:Ensure risk assessment are performed to prior to doing business and granting suppliers and vendors access to assets and security controls and requirements are agreed upon and documented in the suppliers/vendors agreement.GRC: Vendor Risk ManagementVendor Risk Assessment \[sn\_vdr\_risk\_asmt\_assessmentsn\_vdr\_risk\_asmt\_assessment\]N/A
ISO27002 - 15.2.1Monitoring and review of supplier services:Ensure supplier are regularly monitoring and review to ensure that the information security terms and conditions of the agreements are being adhered to and that information security incidents and problems are managed properly.GRC: Vendor Risk ManagementVendor Risk Assessment \[sn\_vdr\_risk\_asmt\_assessmentsn\_vdr\_risk\_asmt\_assessment\]N/A
ISO27002 - 15.2.2Managing changes to supplier services:Ensure 3rd Party risk assessment are performed when ever there are changes to provision of services. Ensure changes to the provision of services by suppliers, including maintaining and improving existing information security policies, procedures and controls, are managed.GRC: Vendor Risk ManagementRepeating Assessments \[sn\_vdr\_risk\_asmt\_repeating\_assessment\]N/A
ISO27002 - 16.1.2Reporting information security events:Ensure there is a formal Incident Management program in place and all personnel and third parties are trained on how to recognize and report security incidents.Security Incident ResponseSecurity Incident \[sn\_si\_incident\]N/A
ISO27002 - 16.1.4Assessment of and decision on information security events:Ensure there is a formal information security event management to include agreed security event and incident classification scale for reporting and escalation. Ensure threat and risk classification scheme are documented. Ensure incident response notifications are maintained. Ensure impact thresholds to be used in categorizing incidents are documented.Security Incident ResponseSecurity Incident \[sn\_si\_incident\]N/A
ISO27002 - 16.1.5Response to information security incidents:Ensure information security incidents are responded to and managed in accordance with the documented procedures.Security Incident ResponseSecurity Incident \[sn\_si\_incident\]N/A
ISO27002 - 16.1.6Learning from information security incidents:Ensure incident monitoring procedures are included in the Incident Management Program to document incidents and ensuring security event are periodically analyzed to reduce future incident.Security Incident ResponseSecurity Incident \[sn\_si\_incident\]N/A
ISO27002 - 17.1.1Planning information security continuity:Ensure information security and the continuity of information security management are planned and included in business continuity plan or within the disaster recovery plan.GRC: Business Impact AnalysisImpact Analysis \[sn\_bia\_analysis\]N/A
ISO27002 - 17.1.2Implementing information security continuity:Ensure business continuity or disaster recovery plan are formally documented.GRC: Business Impact AnalysisImpact Analysis \[sn\_bia\_analysis\]N/A
ISO27002 - 17.1.3Verify, review and evaluate information security continuity:Ensure business continuity or disaster recovery plan are annual exercise to validate adequate security control are valid and effective during adverse situation.GRC: Business Impact AnalysisImpact Analysis \[sn\_bia\_analysis\]N/A
ISO27002 - 17.2.1Availability of information processing facilities:Ensure failover and recovery components work as intended.GRC: Crisis ManagementEvents \[sn\_recovery\_event\]N/A
ISO27002 - 18.1.3Protection of records:Ensure records and data are protected from loss, destruction, falsification, unauthorized access and unauthorized release, in accordance with legislator, regulatory, contractual and business requirements.GRC: Policy and Compliance ManagementCompliance Policy \[sn\_compliance\_policy\]N/A
ISO27002 - 18.1.4Privacy and protection of personally identifiable information:Ensure privacy and protection of personally identifiable information are protected and handled in accordance with legislation and regulation where applicable.GRC: Policy and Compliance ManagementCompliance Policy \[sn\_compliance\_policy\]N/A
ISO27002 - 18.2.2Compliance with security policies and standards:Ensure testing of in scope systems configuration against compliance and regulatory requirements are regularly performed. Ensure baseline configuration standards for systems are documented and based upon industry best practices.Configuration CompliancePolicies \[sn\_vulc\_policy\]01422 01355
ISO27002 - 18.2.3Technical compliance review:Ensure periodic vulnerability scan and penetration test are performed and testing of in scope systems configuration against compliance and regulatory requirements.Configuration ComplianceTest Results \[sn\_vulc\_result\]N/A
ControlName/DescriptionCompliance validated bySource tableRelated UCF IDs
ISO27002 - 8.1.4Return of assets:Ensure the termination process is formalized to include the return of all previously issued physical and electronic assets owned by or entrusted to the organization.Human Resources: Core Asset Management- HR Profiles \[sn\_hr\_core\_profile\] - Asset \[alm\_asset\]N/A
ISO27002 - 12.1.4Separation of development, testing and operational environments:Maintain separate environments for production and nonproduction systems. Developers should not have unmonitored access to production environments.Configuration Management \(CMDB\)Configuration Item \[cmdb\_ci\]01698 12122 00644 00596

Indicator templates common to CIS and ISO Controls

The following tables list the Basic and Script indicator templates that are common to both CIS and ISO Controls.

Note: Controls currently not covered by either basic or scripted indicator templates have manual indicator templates defined for the purposes of compliance validation.

ControlName/DescriptionIndicator template typeCompliance validated bySource tableRelated UCF IDs
CIS Control 2.6, ISO27002 - 12.5.1Address unapproved software:Ensure software assets are managed and regularly updated.Script- Software Asset Management Core - Software Asset Management Professional Core- Software Installation \[cmdb\_sam\_sw\_install\] - Software Models \[cmdb\_software\_product\_model\]11637 00656 11624
CIS Control 3.7, ISO27002 - 12.6.1Utilize a Risk-rating Process:Utilize a risk-rating process to prioritize the remediation of discovered vulnerabilities.BasicVulnerability ResponseVulnerable Item \[sn\_vul\_vulnerable\_item\]01273
CIS Control 7.2, ISO27002 - 12.6.2Restrictions on software installation:Uninstall or disable any unauthorized browser or email client plugins or add-on applications.Script- Software Asset Management Core - Software Asset Management Professional Core- Software Installation \[cmdb\_sam\_sw\_install\] - Software Models \[cmdb\_software\_product\_model\]00575 00574
CIS Controls 18.1, ISO27002 - 14.2.1Establish Secure Coding Practices:Establish secure coding practices appropriate to the programming language and development environment being used.BasicGRC: Policy and Compliance ManagementPolicy \[sn\_compliance\_policy\]11863
CIS Control 19.1, ISO27002 - 16.1.1Document Incident Response Procedures:Ensure that there are written incident response plans that defines roles of personnel as well as phases of incident handling/management.BasicSecurity Incident ResponseSecurity Incident \[sn\_si\_incident\]11780
CIS Control 19.4, ISO27002 - 16.1.3Reporting information security weaknesses:Devise organization-wide standards for the time required for system administrators and other workforce members to report anomalous events to the incident handling team, the mechanisms for such reporting, and the kind of information that should be included in the incident notification.BasicSecurity Incident ResponseSecurity Incident \[sn\_si\_incident\]07183 12975 10033

Parent Topic:Technology Controls Monitoring Accelerator