Critical Security Controls Version 8.1
IDNameImplementation GroupsThreats
IG1IG2IG3
4.7Manage Default Accounts on Enterprise Assets and SoftwareSTRIDE-LM
4.9Configure Trusted DNS Servers on Enterprise Assets STRIDE-LM
5Account Management   STRIDE-LM
5.2Use Unique PasswordsSTRIDE-LM
6Access Control Management   STRIDE-LM
6.3Require MFA for Externally-Exposed ApplicationsSTRIDE-LM
6.4Require MFA for Remote Network AccessSTRIDE-LM
6.5Require MFA for Administrative AccessSTRIDE-LM
6.7Centralize Access Control STRIDE-LM
9.5Implement DMARC STRIDE-LM
12.5Centralize Network Authentication, Authorization, and Auditing (AAA) STRIDE-LM
12.6Use of Secure Network Management and Communication Protocols STRIDE-LM
12.7Ensure Remote Devices Utilize a VPN and are Connecting to an Enterprise's AAA Infrastructure STRIDE-LM
13.5Manage Access Control for Remote Assets STRIDE-LM
14.2Train Workforce Members to Recognize Social Engineering AttacksSTRIDE-LM
14.3Train Workforce Members on Authentication Best PracticesSTRIDE-LM