Critical Security Controls Version 7.1
IDNameImplementation GroupsThreats
IG1IG2IG3
8.4Configure Anti-Malware Scanning of Removable DevicesSTRIDE-LM
8.5Configure Devices to Not Auto-Run ContentSTRIDE-LM
8.6Centralize Anti-Malware Logging STRIDE-LM
8.7Enable DNS Query Logging STRIDE-LM
8.8Enable Command-Line Audit Logging STRIDE-LM
9.1Associate Active Ports, Services, and Protocols to Asset Inventory STRIDE-LM
9.2Ensure Only Approved Ports, Protocols, and Services Are Running STRIDE-LM
9.3Perform Regular Automated Port Scans STRIDE-LM
9.4Apply Host-Based Firewalls or Port-FilteringSTRIDE-LM
10.1Ensure Regular Automated BackUpsSTRIDE-LM
10.2Perform Complete System BackupsSTRIDE-LM
10.3Test Data on Backup Media STRIDE-LM
10.4Protect BackupsSTRIDE-LM
10.5Ensure All Backups Have at Least One Offline Backup DestinationSTRIDE-LM
11.1Maintain Standard Security Configurations for Network Devices STRIDE-LM
11.2Document Traffic Configuration Rules STRIDE-LM
11.3Use Automated Tools to Verify Standard Device Configurations and Detect Changes STRIDE-LM
11.4Install the Latest Stable Version of Any Security-Related Updates on All Network DevicesSTRIDE-LM
11.5Manage Network Devices Using Multi-Factor Authentication and Encrypted Sessions STRIDE-LM
11.6Use Dedicated Machines For All Network Administrative Tasks STRIDE-LM
11.7Manage Network Infrastructure Through a Dedicated Network STRIDE-LM
12.1Maintain an Inventory of Network BoundariesSTRIDE-LM
12.2Scan for Unauthorized Connections Across Trusted Network Boundaries STRIDE-LM
12.3Deny Communications With Known Malicious IP Addresses STRIDE-LM
12.4Deny Communication Over Unauthorized PortsSTRIDE-LM
12.5Configure Monitoring Systems to Record Network Packets STRIDE-LM
12.6Deploy Network-Based IDS Sensors STRIDE-LM
12.8Deploy NetFlow Collection on Networking Boundary Devices STRIDE-LM
12.11Require All Remote Login to Use Multi-Factor Authentication STRIDE-LM
13.1Maintain an Inventory of Sensitive InformationSTRIDE-LM
13.2Remove Sensitive Data or Systems Not Regularly Accessed by OrganizationSTRIDE-LM
13.4Only Allow Access to Authorized Cloud Storage or Email Providers STRIDE-LM
13.6Encrypt Mobile Device DataSTRIDE-LM
13.7Manage USB Devices STRIDE-LM
14.1Segment the Network Based on Sensitivity STRIDE-LM
14.2Enable Firewall Filtering Between VLANs STRIDE-LM
14.3Disable Workstation to Workstation Communication STRIDE-LM
14.4Encrypt All Sensitive Information in Transit STRIDE-LM
14.6Protect Information Through Access Control ListsSTRIDE-LM
15.1Maintain an Inventory of Authorized Wireless Access Points STRIDE-LM
15.2Detect Wireless Access Points Connected to the Wired Network STRIDE-LM
15.3Use a Wireless Intrusion Detection System STRIDE-LM
15.6Disable Peer-to-Peer Wireless Network Capabilities on Wireless Clients STRIDE-LM
15.7Leverage the Advanced Encryption Standard (AES) to Encrypt Wireless DataSTRIDE-LM
15.9Disable Wireless Peripheral Access of Devices STRIDE-LM
15.10Create Separate Wireless Network for Personal and Untrusted DevicesSTRIDE-LM
16.1Maintain an Inventory of Authentication Systems STRIDE-LM
16.2Configure Centralized Point of Authentication STRIDE-LM
16.3Require Multi-Factor Authentication STRIDE-LM
16.4Encrypt or Hash all Authentication Credentials STRIDE-LM