Critical Security Controls Version 8.1
IDNameImplementation GroupsThreats
IG1IG2IG3
3Data Protection   STRIDE-LM
3.1Establish and Maintain a Data Management Process•••STRIDE-LM
3.2Establish and Maintain a Data Inventory•••STRIDE-LM
3.3Configure Data Access Control Lists•••STRIDE-LM
3.5Securely Dispose of Data•••STRIDE-LM
3.6Encrypt Data on End-User Devices•••STRIDE-LM
3.7Establish and Maintain a Data Classification Scheme ••STRIDE-LM
3.9Encrypt Data on Removable Media ••STRIDE-LM
3.10Encrypt Sensitive Data in Transit ••STRIDE-LM
3.11Encrypt Sensitive Data at Rest ••STRIDE-LM
3.12Segment Data Processing and Storage Based on Sensitivity ••STRIDE-LM
3.13Deploy a Data Loss Prevention Solution  •STRIDE-LM
4.3Configure Automatic Session Locking on Enterprise Assets•••STRIDE-LM
4.10Enforce Automatic Device Lockout on Portable End-User Devices ••STRIDE-LM
4.11Enforce Remote Wipe Capability on Portable End-User Devices ••STRIDE-LM
4.12Separate Enterprise Workspaces on Mobile End-User Devices  •STRIDE-LM
6Access Control Management   STRIDE-LM
6.1Establish an Access Granting Process•••STRIDE-LM
7Continuous Vulnerability Management   STRIDE-LM
7.1Establish and Maintain a Vulnerability Management Process•••STRIDE-LM
7.7Remediate Detected Vulnerabilities ••STRIDE-LM
9.4Restrict Unnecessary or Unauthorized Browser and Email Client Extensions ••STRIDE-LM
11.3Protect Recovery Data•••STRIDE-LM
12.6Use of Secure Network Management and Communication Protocols ••STRIDE-LM
12.7Ensure Remote Devices Utilize a VPN and are Connecting to an Enterprise's AAA Infrastructure ••STRIDE-LM
14Security Awareness and Skills Training   STRIDE-LM
14.1Establish and Maintain a Security Awareness Program•••STRIDE-LM
14.2Train Workforce Members to Recognize Social Engineering Attacks•••STRIDE-LM
14.4Train Workforce on Data Handling Best Practices•••STRIDE-LM
14.5Train Workforce Members on Causes of Unintentional Data Exposure•••STRIDE-LM
14.8Train Workforce on the Dangers of Connecting to and Transmitting Enterprise Data Over Insecure Networks•••STRIDE-LM
14.9Conduct Role-Specific Security Awareness and Skills Training ••STRIDE-LM
15Service Provider Management   STRIDE-LM
15.4Ensure Service Provider Contracts Include Security Requirements ••STRIDE-LM
15.7Securely Decommission Service Providers  •STRIDE-LM
16Application Software Security   STRIDE-LM
16.2Establish and Maintain a Process to Accept and Address Software Vulnerabilities ••STRIDE-LM
16.9Train Developers in Application Security Concepts and Secure Coding ••STRIDE-LM
16.10Apply Secure Design Principles in Application Architectures ••STRIDE-LM
16.11Leverage Vetted Modules or Services for Application Security Components ••STRIDE-LM
16.13Conduct Application Penetration Testing  •STRIDE-LM
16.14Conduct Threat Modeling  •STRIDE-LM
18Penetration Testing   STRIDE-LM
18.1Establish and Maintain a Penetration Testing Program ••STRIDE-LM
18.3Remediate Penetration Test Findings ••STRIDE-LM