Critical Security Controls Version 7.1
IDNameImplementation GroupsThreats
IG1IG2IG3
5.3Securely Store Master Images STRIDE-LM
7Email and Web Browser Protections   STRIDE-LM
10.4Protect BackupsSTRIDE-LM
11.5Manage Network Devices Using Multi-Factor Authentication and Encrypted Sessions STRIDE-LM
13Data Protection   STRIDE-LM
13.1Maintain an Inventory of Sensitive InformationSTRIDE-LM
13.2Remove Sensitive Data or Systems Not Regularly Accessed by OrganizationSTRIDE-LM
13.3Monitor and Block Unauthorized Network Traffic  STRIDE-LM
13.4Only Allow Access to Authorized Cloud Storage or Email Providers STRIDE-LM
13.6Encrypt Mobile Device DataSTRIDE-LM
13.7Manage USB Devices STRIDE-LM
13.8Manage System's External Removable Media's Read/Write Configurations  STRIDE-LM
13.9Encrypt Data on USB Storage Devices  STRIDE-LM
14Controlled Access Based on the Need to Know   STRIDE-LM
14.1Segment the Network Based on Sensitivity STRIDE-LM
14.4Encrypt All Sensitive Information in Transit STRIDE-LM
14.5Utilize an Active Discovery Tool to Identify Sensitive Data  STRIDE-LM
14.6Protect Information Through Access Control ListsSTRIDE-LM
14.7Enforce Access Control to Data Through Automated Tools  STRIDE-LM
14.8Encrypt Sensitive Information at Rest  STRIDE-LM
15Wireless Access Control   STRIDE-LM
15.4Disable Wireless Access on Devices if Not Required  STRIDE-LM
15.7Leverage the Advanced Encryption Standard (AES) to Encrypt Wireless DataSTRIDE-LM
16.4Encrypt or Hash all Authentication Credentials STRIDE-LM
16.5Encrypt Transmittal of Username and Authentication Credentials STRIDE-LM
16.11Lock Workstation Sessions After InactivitySTRIDE-LM
17Implement a Security Awareness and Training Program   STRIDE-LM
17.6Train Workforce on Identifying Social Engineering AttacksSTRIDE-LM
17.7Train Workforce on Sensitive Data HandlingSTRIDE-LM
17.8Train Workforce on Causes of Unintentional Data ExposureSTRIDE-LM
18Application Software Security   STRIDE-LM
18.1Establish Secure Coding Practices STRIDE-LM
18.5Use Only Standardized and Extensively Reviewed Encryption Algorithms STRIDE-LM
18.6Ensure Software Development Personnel are Trained in Secure Coding STRIDE-LM
18.7Apply Static and Dynamic Code Analysis Tools STRIDE-LM
18.8Establish a Process to Accept and Address Reports of Software Vulnerabilities STRIDE-LM
18.11Use Standard Hardening Configuration Templates for Databases STRIDE-LM
20.1Establish a Penetration Testing Program STRIDE-LM
20.2Conduct Regular External and Internal Penetration Tests STRIDE-LM
20.4Include Tests for Presence of Unprotected System Information and Artifacts STRIDE-LM