Critical Security Controls Version 7.1
The Critical Security Controls published by the Center for Internet Security are designed to be fundamental controls for all organizations. The 20 controls included in the set are intended to be the basis for any information security program.
| ID | Name | Implementation Groups | Threats | ||
|---|---|---|---|---|---|
| IG1 | IG2 | IG3 | |||
| 2.8 | Implement Application Whitelisting of Libraries | • | STRIDE-LM | ||
| 5 | Secure Configuration for Hardware and Software on Mobile Devices, Laptops, Workstations and Servers | STRIDE-LM | |||
| 5.1 | Establish Secure Configurations | • | • | • | STRIDE-LM |
| 5.2 | Maintain Secure Images | • | • | STRIDE-LM | |
| 5.3 | Securely Store Master Images | • | • | STRIDE-LM | |
| 5.4 | Deploy System Configuration Management Tools | • | • | STRIDE-LM | |
| 5.5 | Implement Automated Configuration Monitoring Systems | • | • | STRIDE-LM | |
| 10 | Data Recovery Capabilities | STRIDE-LM | |||
| 10.4 | Protect Backups | • | • | • | STRIDE-LM |
| 10.5 | Ensure All Backups Have at Least One Offline Backup Destination | • | • | • | STRIDE-LM |
| 11.3 | Use Automated Tools to Verify Standard Device Configurations and Detect Changes | • | • | STRIDE-LM | |
| 13 | Data Protection | STRIDE-LM | |||
| 18 | Application Software Security | STRIDE-LM | |||
| 18.1 | Establish Secure Coding Practices | • | • | STRIDE-LM | |
| 18.10 | Deploy Web Application Firewalls | • | • | STRIDE-LM | |