Compliance alignment

View as Markdown

runZero customers face many compliance obligations, from industry standards to state, federal, and international laws and regulations. Each has its own particulars, but most IT and cybersecurity frameworks share common themes. The sections below summarize several of those themes and how runZero can help organizations achieve and maintain compliance.

Establish and maintain an asset inventory

A common adage in cybersecurity is that you can’t protect what you can’t see, so an inventory of assets is the foundation of an effective cybersecurity program. Most cybersecurity standards and frameworks include provisions for establishing one. Examples of asset inventory controls include:

  • C2M2 ASSET-1a: IT and OT assets that are important to the delivery of the function are inventoried […].
  • CIS Critical Security Control 1.1: Establish and Maintain Detailed Enterprise Asset Inventory.
  • NIST CSF ID.AM-1: Physical devices and systems within the organization are inventoried.

An organization can build an asset inventory in any number of ways, but many standards and frameworks go a step further and require active network scanning. Scanning helps keep your inventory current and complete, including the assets you didn’t know about. Examples include:

  • CIS Critical Security Control 1.3: Utilize an Active Discovery Tool.
  • CMMC 3.4.3e: Employ automated discovery and management tools to maintain an […] inventory of system components.
  • CISA Binding Operational Directive 23-01 Requirement 1a: Perform automated asset discovery every 7 days.

runZero helps organizations discover assets connected to their networks and in the cloud. With unauthenticated active scanning, runZero can identify both managed and unmanaged devices across IT and OT networks. It also integrates with cloud service providers and many other platforms to ingest asset information, so it can be a system of record for all your connected assets.

Related runZero resources

Secure configuration of assets

System hardening is central to maintaining cyber hygiene in an enterprise security program. It includes documenting baseline configurations for IT and OT assets, disabling unnecessary or insecure software and services, and continuously monitoring for changes to asset configurations. Examples of secure configuration management controls include:

  • CIS Critical Security Control 4.1: Establish and Maintain a Secure Configuration Process.
  • CMMC 3.4.7: Restrict, disable or prevent the use of nonessential programs, functional, ports, portocols and services.
  • NIST CSF PR.IP-1: A baseline configuration of IT/ICS is created and maintained incorporating security principles.
  • PCI DSS 2.2.4: Only necessary services, protocols, daemons, and functions are enabled, and all unnecessary functionality is removed or disabled.

runZero can augment an organization’s secure configuration practices by continually scanning assets for unnecessary or insecure software, services, and protocols. It can discover and alert on insecure protocols such as FTP, TFTP, Telnet, and HTTP, and it can identify and alert on end-of-life operating systems, out-of-date software, insecure cryptographic libraries, and many other configuration attributes. runZero can also identify potential weaknesses in an organization’s network, such as multihomed assets with both a public and a private IP address, assets running both IPv4 and IPv6, and unauthorized wireless access points.

Related runZero resources

Malware protection

Malware remains prevalent in cybersecurity breaches. Organizations protect their assets against malicious software in several ways; one of the most common is deploying an anti-malware solution to workstations, servers, and mobile devices. Some frameworks call for anti-malware software on all assets; others are more flexible and leave room for organizations to define a defense-in-depth approach to malware protection. Examples of malware protection controls include:

  • CIS Critical Control 10.1: Deploy and maintain anti-malware software on all enterprise assets.
  • CMMC 3.14.2: Provide protection from malicious code at designated locations within organizational systems.
  • NIST CSF DE.CM-4: Malicious code is detected.
  • PCI DSS 5.2: Malicious software is prevented, or detected and addressed.

runZero’s endpoint protection integrations enrich your asset inventory with EDR platform data for a fuller view of each asset. With that data you can find gaps in your endpoint protection deployment: endpoints missing an endpoint protection agent, and endpoints running an out-of-date version of the agent. Beyond integrations, runZero can also fingerprint other endpoint protection platforms, including Avast, AVG, Kaspersky, McAfee, and Tanium.

Related runZero resources

Vulnerability management

Vulnerability scanning belongs in every enterprise security program. It shows which assets are unpatched, misconfigured, or vulnerable to known exploits. Examples of vulnerability management controls include:

  • CIS Critical Security Control 7.5: Perform automated vulnerability scans of internal enterprise assets on a quarterly […] basis.
  • CMMC 3.11.2: Scan for vulnerabilities in organization systems and applications […].
  • NIST CSF PR.IP-12: A vulnerability management plan is developed and implemented.
  • PCI DSS 6.3: Security vulnerabilities are identified and addressed.

runZero’s vulnerability management integrations enrich your asset inventory with vulnerability data, for a fuller view of each asset and a faster response to new vulnerabilities. runZero can also find gaps in your vulnerability scan coverage: assets it has discovered that your vulnerability management platform has not scanned.

Related runZero resources

Compliance frameworks

We evaluated these standards and frameworks to help you map the runZero platform to your compliance requirements.

Updated