Critical Security Controls Version 8.1
IDNameImplementation GroupsThreats
IG1IG2IG3
1.1Establish and Maintain Detailed Enterprise Asset Inventory•••STRIDE-LM
1.2Address Unauthorized Assets•••STRIDE-LM
2.1Establish and Maintain a Software Inventory•••STRIDE-LM
2.2Ensure Authorized Software is Currently Supported•••STRIDE-LM
2.3Address Unauthorized Software•••STRIDE-LM
3.1Establish and Maintain a Data Management Process•••STRIDE-LM
3.2Establish and Maintain a Data Inventory•••STRIDE-LM
3.3Configure Data Access Control Lists•••STRIDE-LM
3.4Enforce Data Retention•••STRIDE-LM
3.5Securely Dispose of Data•••STRIDE-LM
3.6Encrypt Data on End-User Devices•••STRIDE-LM
4.1Establish and Maintain a Secure Configuration Process•••STRIDE-LM
4.2Establish and Maintain a Secure Configuration Process for Network Infrastructure•••STRIDE-LM
4.3Configure Automatic Session Locking on Enterprise Assets•••STRIDE-LM
4.4Implement and Manage a Firewall on Servers•••STRIDE-LM
4.5Implement and Manage a Firewall on End-User Devices•••STRIDE-LM
4.6Securely Manage Enterprise Assets and Software•••STRIDE-LM
4.7Manage Default Accounts on Enterprise Assets and Software•••STRIDE-LM
5.1Establish and Maintain an Inventory of Accounts•••STRIDE-LM
5.2Use Unique Passwords•••STRIDE-LM
5.3Disable Dormant Accounts•••STRIDE-LM
5.4Restrict Administrator Privileges to Dedicated Administrator Accounts•••STRIDE-LM
6.1Establish an Access Granting Process•••STRIDE-LM
6.2Establish an Access Revoking Process•••STRIDE-LM
6.3Require MFA for Externally-Exposed Applications•••STRIDE-LM
6.4Require MFA for Remote Network Access•••STRIDE-LM
6.5Require MFA for Administrative Access•••STRIDE-LM
7.1Establish and Maintain a Vulnerability Management Process•••STRIDE-LM
7.2Establish and Maintain a Remediation Process•••STRIDE-LM
7.3Perform Automated Operating System Patch Management•••STRIDE-LM
7.4Perform Automated Application Patch Management•••STRIDE-LM
8.1Establish and Maintain an Audit Log Management Process•••STRIDE-LM
8.2Collect Audit Logs•••STRIDE-LM
8.3Ensure Adequate Audit Log Storage•••STRIDE-LM
9.1Ensure Use of Only Fully Supported Browsers and Email Clients•••STRIDE-LM
9.2Use DNS Filtering Services•••STRIDE-LM
10.1Deploy and Maintain Anti-Malware Software•••STRIDE-LM
10.2Configure Automatic Anti-Malware Signature Updates•••STRIDE-LM
10.3Disable Autorun and Autoplay for Removable Media•••STRIDE-LM
11.1Establish and Maintain a Data Recovery Process•••STRIDE-LM
11.2Perform Automated Backups•••STRIDE-LM
11.3Protect Recovery Data•••STRIDE-LM
11.4Establish and Maintain an Isolated Instance of Recovery Data•••STRIDE-LM
12.1Ensure Network Infrastructure is Up-to-Date•••STRIDE-LM
14.1Establish and Maintain a Security Awareness Program•••STRIDE-LM
14.2Train Workforce Members to Recognize Social Engineering Attacks•••STRIDE-LM
14.3Train Workforce Members on Authentication Best Practices•••STRIDE-LM
14.4Train Workforce on Data Handling Best Practices•••STRIDE-LM
14.5Train Workforce Members on Causes of Unintentional Data Exposure•••STRIDE-LM
14.6Train Workforce Members on Recognizing and Reporting Security Incidents•••STRIDE-LM