Critical Security Controls Version 8.1
IDNameImplementation GroupsThreats
IG1IG2IG3
2.3Address Unauthorized Software•••STRIDE-LM
2.6Allowlist Authorized Libraries ••STRIDE-LM
2.7Allowlist Authorized Scripts  •STRIDE-LM
3.3Configure Data Access Control Lists•••STRIDE-LM
4Secure Configuration of Enterprise Assets and Software   STRIDE-LM
4.6Securely Manage Enterprise Assets and Software•••STRIDE-LM
11.3Protect Recovery Data•••STRIDE-LM
11.4Establish and Maintain an Isolated Instance of Recovery Data•••STRIDE-LM
12.6Use of Secure Network Management and Communication Protocols ••STRIDE-LM
13.2Deploy a Host-Based Intrusion Detection Solution ••STRIDE-LM
13.7Deploy a Host-Based Intrusion Prevention Solution  •STRIDE-LM
16Application Software Security   STRIDE-LM
16.1Establish and Maintain a Secure Application Development Process ••STRIDE-LM
16.9Train Developers in Application Security Concepts and Secure Coding ••STRIDE-LM
16.12Implement Code-Level Security Checks  •STRIDE-LM