Critical Security Controls Version 8.1
IDNameImplementation GroupsThreats
IG1IG2IG3
2.2Ensure Authorized Software is Currently Supported•••STRIDE-LM
4Secure Configuration of Enterprise Assets and Software   STRIDE-LM
4.1Establish and Maintain a Secure Configuration Process•••STRIDE-LM
4.7Manage Default Accounts on Enterprise Assets and Software•••STRIDE-LM
5Account Management   STRIDE-LM
5.4Restrict Administrator Privileges to Dedicated Administrator Accounts•••STRIDE-LM
5.6Centralize Account Management ••STRIDE-LM
6Access Control Management   STRIDE-LM
6.1Establish an Access Granting Process•••STRIDE-LM
6.7Centralize Access Control ••STRIDE-LM
6.8Define and Maintain Role-Based Access Control  •STRIDE-LM
7Continuous Vulnerability Management   STRIDE-LM
7.1Establish and Maintain a Vulnerability Management Process•••STRIDE-LM
7.3Perform Automated Operating System Patch Management•••STRIDE-LM
7.4Perform Automated Application Patch Management•••STRIDE-LM
7.7Remediate Detected Vulnerabilities ••STRIDE-LM
10.5Enable Anti-Exploitation Features ••STRIDE-LM
12.5Centralize Network Authentication, Authorization, and Auditing (AAA) ••STRIDE-LM
13.5Manage Access Control for Remote Assets ••STRIDE-LM
13.7Deploy a Host-Based Intrusion Prevention Solution  •STRIDE-LM
16Application Software Security   STRIDE-LM
16.1Establish and Maintain a Secure Application Development Process ••STRIDE-LM
16.2Establish and Maintain a Process to Accept and Address Software Vulnerabilities ••STRIDE-LM
16.5Use Up-to-Date and Trusted Third-Party Software Components ••STRIDE-LM
16.9Train Developers in Application Security Concepts and Secure Coding ••STRIDE-LM
16.10Apply Secure Design Principles in Application Architectures ••STRIDE-LM
18Penetration Testing   STRIDE-LM
18.1Establish and Maintain a Penetration Testing Program ••STRIDE-LM
18.3Remediate Penetration Test Findings ••STRIDE-LM
18.5Perform Periodic Internal Penetration Tests  •STRIDE-LM