Critical Security Controls Version 7.1
IDNameImplementation GroupsThreats
IG1IG2IG3
1.8Utilize Client Certificates to Authenticate Hardware Assets  •STRIDE-LM
4.2Change Default Passwords•••STRIDE-LM
4.5Use Multi-Factor Authentication for All Administrative Access ••STRIDE-LM
4.9Log and Alert on Unsuccessful Administrative Account Login ••STRIDE-LM
7.8Implement DMARC and Enable Receiver-Side Verification ••STRIDE-LM
11.5Manage Network Devices Using Multi-Factor Authentication and Encrypted Sessions ••STRIDE-LM
12.11Require All Remote Login to Use Multi-Factor Authentication ••STRIDE-LM
15Wireless Access Control   STRIDE-LM
15.1Maintain an Inventory of Authorized Wireless Access Points ••STRIDE-LM
15.8Use Wireless Authentication Protocols That Require Mutual, Multi-Factor Authentication  •STRIDE-LM
16.2Configure Centralized Point of Authentication ••STRIDE-LM
16.3Require Multi-Factor Authentication ••STRIDE-LM
16.4Encrypt or Hash all Authentication Credentials ••STRIDE-LM
16.13Alert on Account Login Behavior Deviation  •STRIDE-LM
17.5Train Workforce on Secure Authentication•••STRIDE-LM
17.6Train Workforce on Identifying Social Engineering Attacks•••STRIDE-LM