Critical Security Controls Version 8.1
IDNameImplementation GroupsThreats
IG1IG2IG3
13.3Deploy a Network Intrusion Detection Solution ••STRIDE-LM
13.4Perform Traffic Filtering Between Network Segments ••STRIDE-LM
13.5Manage Access Control for Remote Assets ••STRIDE-LM
13.6Collect Network Traffic Flow Logs ••STRIDE-LM
13.7Deploy a Host-Based Intrusion Prevention Solution  •STRIDE-LM
13.8Deploy a Network Intrusion Prevention Solution  •STRIDE-LM
13.9Deploy Port-Level Access Control  •STRIDE-LM
13.10Perform Application Layer Filtering  •STRIDE-LM
13.11Tune Security Event Alerting Thresholds  •STRIDE-LM
14.1Establish and Maintain a Security Awareness Program•••STRIDE-LM
14.2Train Workforce Members to Recognize Social Engineering Attacks•••STRIDE-LM
14.3Train Workforce Members on Authentication Best Practices•••STRIDE-LM
14.4Train Workforce on Data Handling Best Practices•••STRIDE-LM
14.5Train Workforce Members on Causes of Unintentional Data Exposure•••STRIDE-LM
14.6Train Workforce Members on Recognizing and Reporting Security Incidents•••STRIDE-LM
14.7Train Workforce on How to Identify and Report if Their Enterprise Assets are Missing Security Updates•••STRIDE-LM
14.8Train Workforce on the Dangers of Connecting to and Transmitting Enterprise Data Over Insecure Networks•••STRIDE-LM
14.9Conduct Role-Specific Security Awareness and Skills Training ••STRIDE-LM
15.1Establish and Maintain an Inventory of Service Providers•••STRIDE-LM
15.2Establish and Maintain a Service Provider Management Policy ••STRIDE-LM
15.3Classify Service Providers ••STRIDE-LM
15.4Ensure Service Provider Contracts Include Security Requirements ••STRIDE-LM
15.5Assess Service Providers  •STRIDE-LM
15.6Monitor Service Providers  •STRIDE-LM
15.7Securely Decommission Service Providers  •STRIDE-LM
16.1Establish and Maintain a Secure Application Development Process ••STRIDE-LM
16.2Establish and Maintain a Process to Accept and Address Software Vulnerabilities ••STRIDE-LM
16.3Perform Root Cause Analysis on Security Vulnerabilities ••STRIDE-LM
16.4Establish and Manage an Inventory of Third-Party Software Components ••STRIDE-LM
16.5Use Up-to-Date and Trusted Third-Party Software Components ••STRIDE-LM
16.6Establish and Maintain a Severity Rating System and Process for Application Vulnerabilities ••STRIDE-LM
16.7Use Standard Hardening Configuration Templates for Application Infrastructure ••STRIDE-LM
16.8Separate Production and Non-Production Systems ••STRIDE-LM
16.9Train Developers in Application Security Concepts and Secure Coding ••STRIDE-LM
16.10Apply Secure Design Principles in Application Architectures ••STRIDE-LM
16.11Leverage Vetted Modules or Services for Application Security Components ••STRIDE-LM
16.12Implement Code-Level Security Checks  •STRIDE-LM
16.13Conduct Application Penetration Testing  •STRIDE-LM
16.14Conduct Threat Modeling  •STRIDE-LM
17.1Designate Personnel to Manage Incident Handling•••STRIDE-LM
17.2Establish and Maintain Contact Information for Reporting Security Incidents•••STRIDE-LM
17.3Establish and Maintain an Enterprise Process for Reporting Incidents•••STRIDE-LM
17.4Establish and Maintain an Incident Response Process ••STRIDE-LM
17.5Assign Key Roles and Responsibilities ••STRIDE-LM
17.6Define Mechanisms for Communicating During Incident Response ••STRIDE-LM
17.7Conduct Routine Incident Response Exercises ••STRIDE-LM
17.8Conduct Post-Incident Reviews ••STRIDE-LM
17.9Establish and Maintain Security Incident Thresholds  •STRIDE-LM
18.1Establish and Maintain a Penetration Testing Program ••STRIDE-LM
18.2Perform Periodic External Penetration Tests ••STRIDE-LM