Skip to content

Repository files navigation

This repository is created and maintained by the State of Oregon Enterprise Information Services Cybersecurity Assessment Team for the purpose of creating transparency around its assessment methodology and supporting processes. The primary methodological source is the Center for Internet Security "Controls Assessment Specification" (CISCAS or CIS-CAS) with modifications to align with the 2023 Statewide Information Technology Control Standards. For more information, please email us at: CSS.CyberAssessments@das.oregon.gov.

Table of Contents

Assessment Index

A high-level index of the CIS Safeguards included in the CSS Cybersecurity Assessment Team "IG1+" review baseline with brief explanations of how each included Safeguard aligns to the 2023 Statewide Information Technology Control Standards and, where applicable, ratonale for included "IG2" and "IG3" Safeguards. Included under each Safeguard are links to the relevant items from the Artifact Request, Internal Testing, and Methodology.

Interrelationships Index

A list of all assessed Safeguards and their "dependencies," "dependents," and MITRE ATT&CK "mitigations." Information is gleaned from the CIS Community Defense Model and Controls Assessment Specification.

Implementation Recommendations

A list of recommended actions for the implementation of the Safeguards included in a CSS Cybersecurity Assessment.

Artifact Request

The standardized list of artifacts requested at the outset of an assessment for evaluating the implementation of the Center for Internet Security’s (CIS) Critical Security Controls, in accordance with the Controls Assessment Specification.

Assessment Workbook Template

The template utilized by the Assessment Team for the "IG1+" assessments. Although the template includes functionality to adjust the scope to an "IG1," "IG2," or "IG3" assessment, it should be noted that the calculation methods within the workbook have been adjusted for the purposes of the Assessment Team and may deviate from the Controls Assessment Specification. Please also note that the workbook is made available under the Creative Commons Attribution-NonCommercial-No Derivatives 4.0 International Public License.

Powershell Scripts for Artifact Collector

A set of scripts, listed by CIS Safeguard, for extracting data from Artifact Collector, an internally developed, monolithic PowerShell script that collects artifacts for cybersecurity assessments using native tools.

Defender KQL Scripts

A set of scripts, listed by CIS Safeguard, developed specifically for the State of Oregon, to enable discovery and configuration checking within the Oregon Defender environment.

Group Policy Settings

A list of CIS L1 Benchmark settings, organized by CIS Safegurd, reviewed during a CSS assessment. Note that the list in not comprehensive of the CIS Benchmark.

About

Reference and supplemental materials to support CSS "CIS v8 IG1+" Assessments

Resources

Stars

3 stars

Watchers

2 watching

Forks

Releases

Packages

Used by

Contributors