CIS Critical Security Controls (CSC)
What are the Critical Security Controls?
The CIS Critical Security Controls (CIS Controls) are a prioritized collection of cybersecurity best practices, first developed by the SANS Institute in 2008 and now maintained by the Center for Internet Security. An informal community process updates the CIS Controls so they keep pace with the most effective security controls and the most relevant cyber attacks.
Who is the intended audience?
The CIS Critical Security Controls are for organizations of any size that want a prioritized approach to defending against cyber attacks. The framework is voluntary and does not replace any industry standard, regulatory framework, or other legal obligation.
Where can I find more information?
Download the CIS Critical Security Controls from the Center for Internet Security website.
How can runZero help me with these controls?
The table below maps runZero to the CIS Critical Security Controls v8. Strong alignment means runZero can play a significant role in helping an organization implement safeguards; Partial alignment means runZero can play a complementary role.
| No | Control | Strong alignment | Partial alignment |
|---|---|---|---|
| 01 | Inventory and Control of Enterprise Assets | ✔ | |
| 02 | Inventory and Control of Software Assets | ✔ | |
| 03 | Data Protection | ||
| 04 | Secure Configuration of Enterprise Assets and Software | ✔ | |
| 05 | Account Management | ||
| 06 | Access Control Management | ||
| 07 | Continuous Vulnerability Management | ✔ | |
| 08 | Audit Log Management | ||
| 09 | Email and Web Server Protection | ||
| 10 | Malware Defenses | ✔ | |
| 11 | Data Recovery | ||
| 12 | Network Infrastructure Management | ✔ | |
| 13 | Network Monitoring and Defense | ||
| 14 | Security Awareness and Skills Training | ||
| 15 | Service Provider Management | ||
| 16 | Application Software Security | ||
| 17 | Incident Response Management | ||
| 18 | Penetration Testing |