Critical Security Controls Version 8.1
Formerly known as the SANS Critical Controls, the Critical Security Controls published by the Center for Internet Security are designed to be fundamental controls for all organizations. The 18 controls included in the set are intended to be the basis for any information security program.
| ID | Name | Implementation Groups | Threats | ||
|---|---|---|---|---|---|
| IG1 | IG2 | IG3 | |||
| 2.3 | Address Unauthorized Software | • | • | • | STRIDE-LM |
| 2.6 | Allowlist Authorized Libraries | • | • | STRIDE-LM | |
| 2.7 | Allowlist Authorized Scripts | • | STRIDE-LM | ||
| 3.3 | Configure Data Access Control Lists | • | • | • | STRIDE-LM |
| 4 | Secure Configuration of Enterprise Assets and Software | STRIDE-LM | |||
| 4.6 | Securely Manage Enterprise Assets and Software | • | • | • | STRIDE-LM |
| 11.3 | Protect Recovery Data | • | • | • | STRIDE-LM |
| 11.4 | Establish and Maintain an Isolated Instance of Recovery Data | • | • | • | STRIDE-LM |
| 12.6 | Use of Secure Network Management and Communication Protocols | • | • | STRIDE-LM | |
| 13.2 | Deploy a Host-Based Intrusion Detection Solution | • | • | STRIDE-LM | |
| 13.7 | Deploy a Host-Based Intrusion Prevention Solution | • | STRIDE-LM | ||
| 16 | Application Software Security | STRIDE-LM | |||
| 16.1 | Establish and Maintain a Secure Application Development Process | • | • | STRIDE-LM | |
| 16.9 | Train Developers in Application Security Concepts and Secure Coding | • | • | STRIDE-LM | |
| 16.12 | Implement Code-Level Security Checks | • | STRIDE-LM | ||