Critical Security Controls Version 8.1
Formerly known as the SANS Critical Controls, the Critical Security Controls published by the Center for Internet Security are designed to be fundamental controls for all organizations. The 18 controls included in the set are intended to be the basis for any information security program.
| ID | Name | Implementation Groups | Threats | ||
|---|---|---|---|---|---|
| IG1 | IG2 | IG3 | |||
| 3.14 | Log Sensitive Data Access | • | STRIDE-LM | ||
| 8 | Audit Log Management | STRIDE-LM | |||
| 8.1 | Establish and Maintain an Audit Log Management Process | • | • | • | STRIDE-LM |
| 8.2 | Collect Audit Logs | • | • | • | STRIDE-LM |
| 8.3 | Ensure Adequate Audit Log Storage | • | • | • | STRIDE-LM |
| 8.4 | Standardize Time Synchronization | • | • | STRIDE-LM | |
| 8.5 | Collect Detailed Audit Logs | • | • | STRIDE-LM | |
| 8.8 | Collect Command-Line Audit Logs | • | • | STRIDE-LM | |
| 8.9 | Centralize Audit Logs | • | • | STRIDE-LM | |
| 8.10 | Retain Audit Logs | • | • | STRIDE-LM | |
| 8.11 | Conduct Audit Log Reviews | • | • | STRIDE-LM | |
| 8.12 | Collect Service Provider Logs | • | STRIDE-LM | ||
| 12.5 | Centralize Network Authentication, Authorization, and Auditing (AAA) | • | • | STRIDE-LM | |
| 13.1 | Centralize Security Event Alerting | • | • | STRIDE-LM | |