This repository is created and maintained by the State of Oregon Enterprise Information Services Cybersecurity Assessment Team for the purpose of creating transparency around its assessment methodology and supporting processes. The primary methodological source is the Center for Internet Security "Controls Assessment Specification" (CISCAS or CIS-CAS) with modifications to align with the 2023 Statewide Information Technology Control Standards. For more information, please email us at: CSS.CyberAssessments@das.oregon.gov.
A high-level index of the CIS Safeguards included in the CSS Cybersecurity Assessment Team "IG1+" review baseline with brief explanations of how each included Safeguard aligns to the 2023 Statewide Information Technology Control Standards and, where applicable, ratonale for included "IG2" and "IG3" Safeguards. Included under each Safeguard are links to the relevant items from the Artifact Request, Internal Testing, and Methodology.
A list of all assessed Safeguards and their "dependencies," "dependents," and MITRE ATT&CK "mitigations." Information is gleaned from the CIS Community Defense Model and Controls Assessment Specification.
Implementation Recommendations
A list of recommended actions for the implementation of the Safeguards included in a CSS Cybersecurity Assessment.
The standardized list of artifacts requested at the outset of an assessment for evaluating the implementation of the Center for Internet Security’s (CIS) Critical Security Controls, in accordance with the Controls Assessment Specification.
The template utilized by the Assessment Team for the "IG1+" assessments. Although the template includes functionality to adjust the scope to an "IG1," "IG2," or "IG3" assessment, it should be noted that the calculation methods within the workbook have been adjusted for the purposes of the Assessment Team and may deviate from the Controls Assessment Specification. Please also note that the workbook is made available under the Creative Commons Attribution-NonCommercial-No Derivatives 4.0 International Public License.
Powershell Scripts for Artifact Collector
A set of scripts, listed by CIS Safeguard, for extracting data from Artifact Collector, an internally developed, monolithic PowerShell script that collects artifacts for cybersecurity assessments using native tools.
A set of scripts, listed by CIS Safeguard, developed specifically for the State of Oregon, to enable discovery and configuration checking within the Oregon Defender environment.
A list of CIS L1 Benchmark settings, organized by CIS Safegurd, reviewed during a CSS assessment. Note that the list in not comprehensive of the CIS Benchmark.