CIS-1.1 | Establish and Maintain Detailed Enterprise Asset Inventory | 32 |
CIS-1.2 | Address Unauthorized Assets | 23 |
CIS-1.3 | Utilize an Active Discovery Tool | 19 |
CIS-1.4 | Use Dynamic Host Configuration Protocol (DHCP) Logging to Update Enterprise Asset Inventory | 8 |
CIS-1.5 | Use a Passive Asset Discovery Tool | 13 |
CIS-10.1 | Deploy and Maintain Anti-Malware Software | 28 |
CIS-10.2 | Configure Automatic Anti-Malware Signature Updates | 23 |
CIS-10.3 | Disable Autorun and Autoplay for Removable Media | 18 |
CIS-10.4 | Configure Automatic Anti-Malware Scanning of Removable Media | 20 |
CIS-10.5 | Enable Anti-Exploitation Features | 16 |
CIS-10.6 | Centrally Manage Anti-Malware Software | 22 |
CIS-10.7 | Use Behavior-Based Anti-Malware Software | 22 |
CIS-11.1 | Establish and Maintain a Data Recovery Process | 30 |
CIS-11.2 | Perform Automated Backups | 26 |
CIS-11.3 | Protect Recovery Data | 27 |
CIS-11.4 | Establish and Maintain an Isolated Instance of Recovery Data | 25 |
CIS-11.5 | Test Data Recovery | 29 |
CIS-12.1 | Ensure Network Infrastructure is Up-to-Date | 25 |
CIS-12.2 | Establish and Maintain a Secure Network Architecture | 27 |
CIS-12.3 | Securely Manage Network Infrastructure | 19 |
CIS-12.4 | Establish and Maintain Architecture Diagram(s) | 22 |
CIS-12.5 | Centralize Network Authentication, Authorization, and Auditing (AAA) | 14 |
CIS-12.6 | Use of Secure Network Management and Communication Protocols | 25 |
CIS-12.7 | Ensure Remote Devices Utilize a VPN and are Connecting to an Enterprise’s AAA Infrastructure | 24 |
CIS-12.8 | Establish and Maintain Dedicated Computing Resources for All Administrative Work | 26 |
CIS-13.1 | Centralize Security Event Alerting | 29 |
CIS-13.10 | Perform Application Layer Filtering | 19 |
CIS-13.11 | Tune Security Event Alerting Thresholds | 19 |
CIS-13.2 | Deploy a Host-Based Intrusion Detection Solution | 20 |
CIS-13.3 | Deploy a Network Intrusion Detection Solution | 24 |
CIS-13.4 | Perform Traffic Filtering Between Network Segments | 25 |
CIS-13.5 | Manage Access Control for Remote Assets | 24 |
CIS-13.6 | Collect Network Traffic Flow Logs | 22 |
CIS-13.7 | Deploy a Host-Based Intrusion Prevention Solution | 17 |
CIS-13.8 | Deploy a Network Intrusion Prevention Solution | 20 |
CIS-13.9 | Deploy Port-Level Access Control | 17 |
CIS-14.1 | Establish and Maintain a Security Awareness Program | 34 |
CIS-14.2 | Train Workforce Members to Recognize Social Engineering Attacks | 21 |
CIS-14.3 | Train Workforce Members on Authentication Best Practices | 20 |
CIS-14.4 | Train Workforce on Data Handling Best Practices | 24 |
CIS-14.5 | Train Workforce Members on Causes of Unintentional Data Exposure | 18 |
CIS-14.6 | Train Workforce Members on Recognizing and Reporting Security Incidents | 26 |
CIS-14.7 | Train Workforce on How to Identify and Report if Their Enterprise Assets are Missing Security Updates | 10 |
CIS-14.8 | Train Workforce on the Dangers of Connecting to and Transmitting Enterprise Data Over Insecure Networks | 17 |
CIS-14.9 | Conduct Role-Specific Security Awareness and Skills Training | 34 |
CIS-15.1 | Establish and Maintain an Inventory of Service Providers | 28 |
CIS-15.2 | Establish and Maintain a Service Provider Management Policy | 30 |
CIS-15.3 | Classify Service Providers | 24 |
CIS-15.4 | Ensure Service Provider Contracts Include Security Requirements | 32 |
CIS-15.5 | Assess Service Providers | 32 |
CIS-15.6 | Monitor Service Providers | 28 |
CIS-15.7 | Securely Decommission Service Providers | 20 |
CIS-16.1 | Establish and Maintain a Secure Application Development Process | 29 |
CIS-16.10 | Apply Secure Design Principles in Application Architectures | 23 |
CIS-16.11 | Leverage Vetted Modules or Services for Application Security Components | 18 |
CIS-16.12 | Implement Code-Level Security Checks | 18 |
CIS-16.13 | Conduct Application Penetration Testing | 20 |
CIS-16.14 | Conduct Threat Modeling | 20 |
CIS-16.2 | Establish and Maintain a Process to Accept and Address Software Vulnerabilities | 23 |
CIS-16.3 | Perform Root Cause Analysis on Security Vulnerabilities | 21 |
CIS-16.4 | Establish and Manage an Inventory of Third-Party Software Components | 24 |
CIS-16.5 | Use Up-to-Date and Trusted Third-Party Software Components | 28 |
CIS-16.6 | Establish and Maintain a Severity Rating System and Process for Application Vulnerabilities | 21 |
CIS-16.7 | Use Standard Hardening Configuration Templates for Application Infrastructure | 23 |
CIS-16.8 | Separate Production and Non-Production Systems | 25 |
CIS-16.9 | Train Developers in Application Security Concepts and Secure Coding | 24 |
CIS-17.1 | Designate Personnel to Manage Incident Handling | 32 |
CIS-17.2 | Establish and Maintain Contact Information for Reporting Security Incidents | 28 |
CIS-17.3 | Establish and Maintain an Enterprise Process for Reporting Incidents | 33 |
CIS-17.4 | Establish and Maintain an Incident Response Process | 36 |
CIS-17.5 | Assign Key Roles and Responsibilities | 32 |
CIS-17.6 | Define Mechanisms for Communicating During Incident Response | 30 |
CIS-17.7 | Conduct Routine Incident Response Exercises | 30 |
CIS-17.8 | Conduct Post-Incident Reviews | 29 |
CIS-17.9 | Establish and Maintain Security Incident Thresholds | 27 |
CIS-18.1 | Establish and Maintain a Penetration Testing Program | 31 |
CIS-18.2 | Perform Periodic External Penetration Tests | 28 |
CIS-18.3 | Remediate Penetration Test Findings | 30 |
CIS-18.4 | Validate Security Measures | 28 |
CIS-18.5 | Perform Periodic Internal Penetration Tests | 25 |
CIS-2.1 | Establish and Maintain a Software Inventory | 26 |
CIS-2.2 | Ensure Authorized Software is Currently Supported | 28 |
CIS-2.3 | Address Unauthorized Software | 27 |
CIS-2.4 | Utilize Automated Software Inventory Tools | 12 |
CIS-2.5 | Allowlist Authorized Software | 25 |
CIS-2.6 | Allowlist Authorized Libraries | 21 |
CIS-2.7 | Allowlist Authorized Scripts | 21 |
CIS-3.1 | Establish and Maintain a Data Management Process | 27 |
CIS-3.10 | Encrypt Sensitive Data in Transit | 27 |
CIS-3.11 | Encrypt Sensitive Data at Rest | 28 |
CIS-3.12 | Segment Data Processing and Storage Based on Sensitivity | 25 |
CIS-3.13 | Deploy a Data Loss Prevention Solution | 24 |
CIS-3.14 | Log Sensitive Data Access | 24 |
CIS-3.2 | Establish and Maintain a Data Inventory | 26 |
CIS-3.3 | Configure Data Access Control Lists | 26 |
CIS-3.4 | Enforce Data Retention | 26 |
CIS-3.5 | Securely Dispose of Data | 27 |
CIS-3.6 | Encrypt Data on End-User Devices | 19 |
CIS-3.7 | Establish and Maintain a Data Classification Scheme | 24 |
CIS-3.8 | Document Data Flows | 22 |
CIS-3.9 | Encrypt Data on Removable Media | 20 |
CIS-4.1 | Establish and Maintain a Secure Configuration Process | 33 |
CIS-4.10 | Enforce Automatic Device Lockout on Portable End-User Devices | 19 |
CIS-4.11 | Enforce Remote Wipe Capability on Portable End-User Devices | 18 |
CIS-4.12 | Separate Enterprise Workspaces on Mobile End-User Devices | 16 |
CIS-4.2 | Establish and Maintain a Secure Configuration Process for Network Infrastructure | 22 |
CIS-4.3 | Configure Automatic Session Locking on Enterprise Assets | 16 |
CIS-4.4 | Implement and Manage a Firewall on Servers | 24 |
CIS-4.5 | Implement and Manage a Firewall on End-User Devices | 19 |
CIS-4.6 | Securely Manage Enterprise Assets and Software | 22 |
CIS-4.7 | Manage Default Accounts on Enterprise Assets and Software | 23 |
CIS-4.8 | Uninstall or Disable Unnecessary Services on Enterprise Assets and Software | 25 |
CIS-4.9 | Configure Trusted DNS Servers on Enterprise Assets | 12 |
CIS-5.1 | Establish and Maintain an Inventory of Accounts | 26 |
CIS-5.2 | Use Unique Passwords | 26 |
CIS-5.3 | Disable Dormant Accounts | 24 |
CIS-5.4 | Restrict Administrator Privileges to Dedicated Administrator Accounts | 29 |
CIS-5.5 | Establish and Maintain an Inventory of Service Accounts | 20 |
CIS-5.6 | Centralize Account Management | 18 |
CIS-6.1 | Establish an Access Granting Process | 30 |
CIS-6.2 | Establish an Access Revoking Process | 28 |
CIS-6.3 | Require MFA for Externally-Exposed Applications | 28 |
CIS-6.4 | Require MFA for Remote Network Access | 26 |
CIS-6.5 | Require MFA for Administrative Access | 28 |
CIS-6.6 | Establish and Maintain an Inventory of Authentication and Authorization Systems | 18 |
CIS-6.7 | Centralize Access Control | 21 |
CIS-6.8 | Define and Maintain Role-Based Access Control | 32 |
CIS-7.1 | Establish and Maintain a Vulnerability Management Process | 32 |
CIS-7.2 | Establish and Maintain a Remediation Process | 31 |
CIS-7.3 | Perform Automated Operating System Patch Management | 26 |
CIS-7.4 | Perform Automated Application Patch Management | 27 |
CIS-7.5 | Perform Automated Vulnerability Scans of Internal Enterprise Assets | 27 |
CIS-7.6 | Perform Automated Vulnerability Scans of Externally-Exposed Enterprise Assets | 26 |
CIS-7.7 | Remediate Detected Vulnerabilities | 31 |
CIS-8.1 | Establish and Maintain an Audit Log Management Process | 27 |
CIS-8.10 | Retain Audit Logs | 23 |
CIS-8.11 | Conduct Audit Log Reviews | 31 |
CIS-8.12 | Collect Service Provider Logs | 19 |
CIS-8.2 | Collect Audit Logs | 27 |
CIS-8.3 | Ensure Adequate Audit Log Storage | 17 |
CIS-8.4 | Standardize Time Synchronization | 16 |
CIS-8.5 | Collect Detailed Audit Logs | 26 |
CIS-8.6 | Collect DNS Query Audit Logs | 16 |
CIS-8.7 | Collect URL Request Audit Logs | 13 |
CIS-8.8 | Collect Command-Line Audit Logs | 16 |
CIS-8.9 | Centralize Audit Logs | 22 |
CIS-9.1 | Ensure Use of Only Fully Supported Browsers and Email Clients | 19 |
CIS-9.2 | Use DNS Filtering Services | 17 |
CIS-9.3 | Maintain and Enforce Network-Based URL Filters | 17 |
CIS-9.4 | Restrict Unnecessary or Unauthorized Browser and Email Client Extensions | 17 |
CIS-9.5 | Implement DMARC | 9 |
CIS-9.6 | Block Unnecessary File Types | 17 |
CIS-9.7 | Deploy and Maintain Email Server Anti-Malware Protections | 22 |