Critical Security Controls Version 7.1
The Critical Security Controls published by the Center for Internet Security are designed to be fundamental controls for all organizations. The 20 controls included in the set are intended to be the basis for any information security program.
| ID | Name | Implementation Groups | Threats | ||
|---|---|---|---|---|---|
| IG1 | IG2 | IG3 | |||
| 6 | Maintenance, Monitoring and Analysis of Audit Logs | STRIDE-LM | |||
| 6.2 | Activate Audit Logging | • | • | • | STRIDE-LM |
| 6.3 | Enable Detailed Logging | • | • | STRIDE-LM | |
| 12 | Boundary Defense | STRIDE-LM | |||
| 12.5 | Configure Monitoring Systems to Record Network Packets | • | • | STRIDE-LM | |
| 12.8 | Deploy NetFlow Collection on Networking Boundary Devices | • | • | STRIDE-LM | |
| 14 | Controlled Access Based on the Need to Know | STRIDE-LM | |||
| 14.8 | Encrypt Sensitive Information at Rest | • | STRIDE-LM | ||
| 15 | Wireless Access Control | STRIDE-LM | |||
| 15.8 | Use Wireless Authentication Protocols That Require Mutual, Multi-Factor Authentication | • | STRIDE-LM | ||
| 16 | Account Monitoring and Control | STRIDE-LM | |||
| 16.8 | Disable Any Unassociated Accounts | • | • | • | STRIDE-LM |
| 16.9 | Disable Dormant Accounts | • | • | • | STRIDE-LM |
| 16.11 | Lock Workstation Sessions After Inactivity | • | • | • | STRIDE-LM |