Skip to main content

Critical Security Control V7.0.1

SANS Institute and Center for Internet Security (CIS) together with other organizations, developed the 20 Critical Security Controls (CSC) for Effective Cyber Defense.

CIS Controls are not a replacement for any existing compliance framework such ISMS, NIST, CSF, PCI etc, rather it’s core building block toward any GRC journey.
What is CSC?
  1. Critical security Controls are recommended sets of actions for effective cyber defence.
  2. Provides specific and actionable ways to stop today's most pervasive and dangerous attacks.
Whys CSC? 
  1. A principal benefit of the controls is that they prioritize and focus on smaller number of actions with high pay-off results.
  2. The controls are effective because they are derived from the most common attack patterns highlighted in the leading threat report and vetted across by a very broad community of government and industry practitioners.
  3. Created by people who know how attacks work such as:
    • NSA Red & Blue team
    • US Dept of Energy.
    • Nuclear energy labs
    • Law enforcement org.
    • Nations top forensics and incident response org.
  4. Continued value is that controls are updated based on new attacks that are identified and analyzed by groups from Verizon to Symantec.
  5. Addresses the key control requirement from various standards, frameworks & regulations at operational level.
More details on CSC v7.0.1 can be found at https://www.cisecurity.org/controls/

Comments

Post a Comment

Popular posts from this blog

MTBF MTTR MTTD

Cisco ASA on GNS3

My struggle for installing Cisco ASA on GNS3 lead me to write this procedure which is already floating around in various versions around the internet but this attempt was to write a concise and still informative  procedure to configure Cisco ASA successfully on GNS3. The relevant snapshots will be updated shortly  :-)