Critical Security Controls Version 8.1
Formerly known as the SANS Critical Controls, the Critical Security Controls published by the Center for Internet Security are designed to be fundamental controls for all organizations. The 18 controls included in the set are intended to be the basis for any information security program.
| ID | Name | Implementation Groups | Threats | ||
|---|---|---|---|---|---|
| IG1 | IG2 | IG3 | |||
| 4.7 | Manage Default Accounts on Enterprise Assets and Software | • | • | • | STRIDE-LM |
| 5.2 | Use Unique Passwords | • | • | • | STRIDE-LM |
| 12 | Network Infrastructure Management | STRIDE-LM | |||
| 12.2 | Establish and Maintain a Secure Network Architecture | • | • | STRIDE-LM | |
| 12.8 | Establish and Maintain Dedicated Computing Resources for All Administrative Work | • | STRIDE-LM | ||
| 13 | Network Monitoring and Defense | STRIDE-LM | |||
| 13.4 | Perform Traffic Filtering Between Network Segments | • | • | STRIDE-LM | |
| 13.6 | Collect Network Traffic Flow Logs | • | • | STRIDE-LM | |
| 16.8 | Separate Production and Non-Production Systems | • | • | STRIDE-LM | |
| 18.5 | Perform Periodic Internal Penetration Tests | • | STRIDE-LM | ||