Critical Security Controls Version 7.1
The Critical Security Controls published by the Center for Internet Security are designed to be fundamental controls for all organizations. The 20 controls included in the set are intended to be the basis for any information security program.
| ID | Name | Implementation Groups | Threats | ||
|---|---|---|---|---|---|
| IG1 | IG2 | IG3 | |||
| 4.8 | Log and Alert on Changes to Administrative Group Membership | • | • | STRIDE-LM | |
| 6 | Maintenance, Monitoring and Analysis of Audit Logs | STRIDE-LM | |||
| 6.2 | Activate Audit Logging | • | • | • | STRIDE-LM |
| 6.3 | Enable Detailed Logging | • | • | STRIDE-LM | |
| 6.5 | Central Log Management | • | • | STRIDE-LM | |
| 6.6 | Deploy SIEM or Log Analytic Tools | • | • | STRIDE-LM | |
| 6.7 | Regularly Review Logs | • | • | STRIDE-LM | |
| 7.6 | Log All URL requester | • | • | STRIDE-LM | |
| 8.8 | Enable Command-Line Audit Logging | • | • | STRIDE-LM | |
| 14.9 | Enforce Detail Logging for Access or Changes to Sensitive Data | • | STRIDE-LM | ||