AM-2 | Use only approved services | 23 |
AM-3 | Ensure security of asset lifecycle management | 32 |
ASBv3-AM-1 | Track asset inventory and their risks | 30 |
ASBv3-AM-4 | Limit access to asset management | 25 |
ASBv3-AM-5 | Use only approved applications in virtual machine | 24 |
ASBv3-BR-3 | Monitor backups | 20 |
ASBv3-BR-4 | Regularly test backup | 24 |
ASBv3-DP-1 | Discover, classify, and label sensitive data | 26 |
ASBv3-DP-5 | Use customer-managed key option in data at rest encryption when required | 22 |
ASBv3-DP-6 | Use a secure key management process | 22 |
ASBv3-DP-7 | Use a secure certificate management process | 15 |
ASBv3-DP-8 | Ensure security of key and certificate repository | 18 |
ASBv3-DS-1 | Conduct threat modeling | 25 |
ASBv3-DS-3 | Secure DevOps infrastructure | 21 |
ASBv3-DS-4 | Integrate static application security testing into DevOps pipeline | 19 |
ASBv3-DS-5 | Integrate dynamic application security testing into DevOps pipeline | 18 |
ASBv3-DS-7 | Enable logging and monitoring in DevOps | 19 |
ASBv3-ES-3 | Ensure anti-malware software and signatures are updated | 25 |
ASBv3-GS-10 | Define and implement DevOps security strategy | 21 |
ASBv3-GS-2 | Define and implement enterprise segmentation/separation of duties strategy | 25 |
ASBv3-GS-3 | Define and implement data protection strategy | 26 |
ASBv3-GS-4 | Define and implement network security strategy | 25 |
ASBv3-GS-5 | Define and implement security posture management strategy | 27 |
ASBv3-GS-6 | Define and implement identity and privileged access strategy | 27 |
ASBv3-GS-7 | Define and implement logging, threat detection and incident response strategy | 26 |
ASBv3-GS-8 | Define and implement backup and recovery strategy | 23 |
ASBv3-GS-9 | Define and implement endpoint security strategy | 22 |
ASBv3-IM-2 | Protect identity and authentication systems | 25 |
ASBv3-IM-5 | Use single sign-on (SSO) for application access | 14 |
ASBv3-IM-8 | Restrict the exposure of credential and secrets | 26 |
ASBv3-IM-9 | Secure user access to existing applications | 12 |
ASBv3-IR-1 | Preparation - update incident response plan and handling process | 33 |
ASBv3-IR-2 | Preparation - setup incident notification | 28 |
ASBv3-IR-3 | Detection and analysis - create incidents based on high-quality alerts | 26 |
ASBv3-IR-4 | Detection and analysis - investigate an incident | 26 |
ASBv3-IR-5 | Detection and analysis - prioritize incidents | 24 |
ASBv3-IR-6 | Containment, eradication and recovery - automate the incident handling | 22 |
ASBv3-IR-7 | Post-incident activity - conduct lesson learned and retain evidence | 28 |
ASBv3-LT-1 | Enable threat detection capabilities | 27 |
ASBv3-LT-2 | Enable threat detection for identity and access management | 24 |
ASBv3-LT-6 | Configure log storage retention | 25 |
ASBv3-LT-7 | Use approved time synchronization sources | 16 |
ASBv3-NS-10 | Ensure Domain Name System (DNS) security | 11 |
ASBv3-NS-4 | Deploy intrusion detection/intrusion prevention systems (IDS/IPS) | 21 |
ASBv3-NS-6 | Deploy web application firewall | 18 |
ASBv3-NS-7 | Simplify network security configuration | 17 |
ASBv3-NS-8 | Detect and disable insecure services and protocols | 27 |
ASBv3-NS-9 | Connect on-premises or cloud network privately | 21 |
ASBv3-PA-4 | Review and reconcile user access regularly | 27 |
ASBv3-PA-5 | Set up emergency access | 16 |
ASBv3-PA-6 | Use privileged access workstations | 24 |
ASBv3-PA-7 | Follow just enough administration (least privilege) principle | 32 |
ASBv3-PA-8 | Determine access process for cloud provider support | 24 |
ASBv3-PV-1 | Define and establish secure configurations | 29 |
ASBv3-PV-3 | Define and establish secure configurations for compute resources | 25 |
ASBv3-PV-4 | Audit and enforce secure configurations for compute resources | 27 |
ASBv3-PV-6 | Rapidly and automatically remediate vulnerabilities | 30 |
ASBv3-PV-7 | Conduct regular red team operations | 27 |
BR-1 | Ensure regular automated backups | 25 |
BR-2 | Protect backup and recovery data | 26 |
DP-2 | Monitor anomalies and threats targeting sensitive data | 24 |
DP-3 | Encrypt sensitive data in transit | 26 |
DP-4 | Enable data at rest encryption by default | 26 |
DS-2 | Ensure software supply chain security | 133 |
DS-6 | Enforce security of workload throughout DevOps lifecycle | 21 |
ES-1 | Use Endpoint Detection and Response (EDR) | 26 |
ES-2 | Use modern anti-malware software | 27 |
GS-1 | Align organization roles, responsibilities and accountabilities | 31 |
IM-1 | Use centralized identity and authentication system | 28 |
IM-3 | Manage application identities securely and automatically | 24 |
IM-4 | Authenticate server and services | 18 |
IM-6 | Use strong authentication controls | 29 |
IM-7 | Restrict resource access based on conditions | 26 |
LT-3 | Enable logging for security investigation | 29 |
LT-4 | Enable network logging for security investigation | 23 |
LT-5 | Centralize security log management and analysis | 27 |
NS-1 | Establish network segmentation boundaries | 27 |
NS-2 | Secure cloud services with network controls | 25 |
NS-3 | Deploy firewall at the edge of enterprise network | 24 |
NS-5 | Deploy DDOS protection | 13 |
PA-1 | Separate and limit highly privileged/administrative users | 28 |
PA-2 | Avoid standing access for user accounts and permissions | 24 |
PA-3 | Manage lifecycle of identities and entitlements | 26 |
PV-2 | Audit and enforce secure configurations | 30 |
PV-5 | Perform vulnerability assessments | 34 |