Critical Security Controls Version 7.1
IDNameImplementation GroupsThreats
IG1IG2IG3
2.10Physically or Logically Segregate High Risk Applications  STRIDE-LM
4.4Use Unique Passwords STRIDE-LM
4.7Limit Access to Script Tools STRIDE-LM
11.6Use Dedicated Machines For All Network Administrative Tasks STRIDE-LM
11.7Manage Network Infrastructure Through a Dedicated Network STRIDE-LM
12.2Scan for Unauthorized Connections Across Trusted Network Boundaries STRIDE-LM
13.3Monitor and Block Unauthorized Network Traffic  STRIDE-LM
14.1Segment the Network Based on Sensitivity STRIDE-LM
14.2Enable Firewall Filtering Between VLANs STRIDE-LM
14.3Disable Workstation to Workstation Communication STRIDE-LM
15.6Disable Peer-to-Peer Wireless Network Capabilities on Wireless Clients STRIDE-LM
15.10Create Separate Wireless Network for Personal and Untrusted DevicesSTRIDE-LM
20Penetration Tests and Red Team Exercises   STRIDE-LM
20.2Conduct Regular External and Internal Penetration Tests STRIDE-LM
20.3Perform Periodic Red Team Exercises  STRIDE-LM