Skip to content

Latest commit

 

History

History
948 lines (563 loc) · 64.8 KB

File metadata and controls

948 lines (563 loc) · 64.8 KB

Browser Notes: To open the any of the hyperlinks found on this page in a new tab, Ctrl+Click or right-click and select ‘Open link in new tab.’”

Purpose

This document serves as a high-level index of the CIS Safeguards included in the CSS Cybersecurity Assessment Team "IG1+" review baseline with brief explanations of how each included Safeguard aligns to the 2023 Statewide Information Technology Control Standards and, where applicable, rationale for included "IG2" and "IG3" Safeguards. Included under each Safeguard are links to the relevant items from the Artifact Request, Internal Testing, and Methodology.

Safeguard 1.01 (IG1) Establish and Maintain Detailed Enterprise Asset Inventory

The implementation of Safeguard 1.01 is a critical element in the defensive mitigations for 2023 Statewide Information Technology Control Standard CM-8(1); and contributes to the defensive mitigation for Standards CM-8 and PM-5.

Assessed Elements:

Assessment Methodology

Safeguard 1.02 (IG1) Address Unauthorized Assets

The implementation of Safeguard 1.02 contributes to the defensive mitigation for 2023 Statewide Information Technology Control Standard CM-8(3).

Assessed Elements:

Assessment Methodology

Safeguard 2.01 (IG1) Establish and Maintain a Software Inventory

The implementation of Safeguard 2.01 is a critical element in the defensive mitigations for 2023 Statewide Information Technology Control Standard MA-3; and contributes to the defensive mitigation for Standards CM-7(1) and CM-8.

Assessed Elements:

Assessment Methodology

Safeguard 2.02 (IG1) Ensure Authorized Software is Currently Supported

The implementation of Safeguard 2.02 is operationally equivalent to the defensive mitigation for 2023 Statewide Information Technology Control Standard SA-22.

Assessed Elements:

Assessment Methodology

Safeguard 2.03 (IG1) Address Unauthorized Software

The implementation of Safeguard 2.03 contributes to the defensive mitigation for 2023 Statewide Information Technology Control Standards CM-7(2), CM-8(3), CM-10, and CM-11.

Assessed Elements:

Assessment Methodology

Safeguard 2.04 (IG2) Utilize Automated Software Inventory Tools

Included in the Assessment as Enterprise Solutions (Tenable/Defender) enable subscribers to automate software discovery.

The implementation of Safeguard 2.04 contributes to the defensive mitigation for 2023 Statewide Information Technology Control Standard CM-8(3).

Assessed Elements:

Assessment Methodology

Safeguard 3.01 (IG1) Establish and Maintain a Data Management Process

The implementation of Safeguard 3.01 is operationally equivalent to the defensive mitigation for 2023 Statewide Information Technology Control Standard SI-12; a critical element in the defensive mitigations for Standard AU-11; and contributes to the defensive mitigation for Standard CM-12.

Assessed Elements:

Assessment Methodology

Safeguard 3.02 (IG1) Establish and Maintain a Data Inventory

The implementation of Safeguard 3.02 is a critical element in the defensive mitigations for 2023 Statewide Information Technology Control Standards CM-12 and PM-5(1); and contributes to the defensive mitigation for Standard RA-2.

Assessed Elements:

Assessment Methodology

Safeguard 3.04 (IG1) Enforce Data Retention

The implementation of Safeguard 3.04 contributes to the defensive mitigation for 2023 Statewide Information Technology Control Standards AU-11 and SI-12.

Assessed Elements:

Assessment Methodology

Safeguard 3.05 (IG1) Securely Dispose of Data

The implementation of Safeguard 3.05 contributes to the defensive mitigation for 2023 Statewide Information Technology Control Standards MP-6 and SR-12.

Assessed Elements:

Assessment Methodology

Safeguard 3.06 (IG1) Encrypt Data on End-User Devices

The implementation of Safeguard 3.06 contributes to the defensive mitigation for 2023 Statewide Information Technology Control Standard SC-28.

Assessed Elements:

Assessment Methodology

Safeguard 3.07 (IG2) Establish and Maintain a Data Classification Scheme

Included in the Assessment in accordance with Statewide Policy 107-004-050.

The implementation of Safeguard 3.07 contributes to the defensive mitigation for 2023 Statewide Information Technology Control Standard RA-2.

Assessed Elements:

Assessment Methodology

Safeguard 4.01 (IG1) Establish and Maintain a Secure Configuration Process

The implementation of Safeguard 4.01 is operationally equivalent to the defensive mitigation for 2023 Statewide Information Technology Control Standards CM-1 and CM-9; a critical element in the defensive mitigations for Standards CM-2, CM-6, CM-7(1), SA-3, SA-8, and SA-10; and contributes to the defensive mitigation for Standard CM-7.

Assessed Elements:

Assessment Methodology

Safeguard 4.03 (IG1) Configure Automatic Session Locking on Enterprise Assets

The implementation of Safeguard 4.03 is operationally equivalent to the defensive mitigation for 2023 Statewide Information Technology Control Standard AC-11; a critical element in the defensive mitigations for Standards AC-11 and AC-12; and contributes to the defensive mitigation for Standard AC-2(5).

Assessed Elements:

Assessment Methodology

Safeguard 4.04 (IG1) Implement and Manage a Firewall on Servers

The implementation of Safeguard 4.04 contributes to the defensive mitigation for 2023 Statewide Information Technology Control Standards CA-9, SC-7, and SC-7(5).

Assessed Elements:

Assessment Methodology

Safeguard 4.05 (IG1) Implement and Manage a Firewall on End-User Devices

The implementation of Safeguard 4.05 contributes to the defensive mitigation for 2023 Statewide Information Technology Control Standards SC-7 and SC-7(5).

Assessed Elements:

Assessment Methodology

Safeguard 4.07 (IG1) Manage Default Accounts on Enterprise Assets and Software

The implementation of Safeguard 4.07 contributes to the defensive mitigation for 2023 Statewide Information Technology Control Standard IA-5.

Assessed Elements:

Assessment Methodology

Safeguard 5.01 (IG1) Establish and Maintain an Inventory of Accounts

The implementation of Safeguard 5.01 contributes to the defensive mitigation for 2023 Statewide Information Technology Control Standard AC-2.

Assessed Elements:

Assessment Methodology

Safeguard 5.02 (IG1) Use Unique Passwords

The implementation of Safeguard 5.02 contributes to the defensive mitigation for 2023 Statewide Information Technology Control Standard IA-5(1).

Assessed Elements:

Assessment Methodology

Safeguard 5.03 (IG1) Disable Dormant Accounts

The implementation of Safeguard 5.03 contributes to the defensive mitigation for 2023 Statewide Information Technology Control Standard AC-2(3).

Assessed Elements:

Assessment Methodology

Safeguard 5.04 (IG1) Restrict Administrator Privileges to Dedicated Administrator Accounts

The implementation of Safeguard 5.04 is a critical element in the defensive mitigations for 2023 Statewide Information Technology Control Standards AC-6(2) and AC-6(5).

Assessed Elements:

Assessment Methodology

Safeguard 6.01 (IG1) Establish an Access Granting Process

The implementation of Safeguard 6.01 contributes to the defensive mitigation for 2023 Statewide Information Technology Control Standards AC-1, AC-2, AC-2(1), IA-4, and IA-5.

Assessed Elements:

Assessment Methodology

Safeguard 6.02 (IG1) Establish an Access Revoking Process

The implementation of Safeguard 6.02 contributes to the defensive mitigation for 2023 Statewide Information Technology Control Standards AC-1, AC-2, and AC-2(1).

Assessed Elements:

Assessment Methodology

Safeguard 6.04 (IG1) Require MFA for Remote Network Access

The implementation of Safeguard 6.04 contributes to the defensive mitigation for 2023 Statewide Information Technology Control Standards AC-19, IA-2(1), and IA-2(2).

Assessed Elements:

Assessment Methodology

Safeguard 6.05 (IG1) Require MFA for Administrative Access

The implementation of Safeguard 6.05 is operationally equivalent to the defensive mitigation for 2023 Statewide Information Technology Control Standard IA-2(1).

Assessed Elements:

Assessment Methodology

Safeguard 7.01 (IG1) Establish and Maintain a Vulnerability Management Process

The implementation of Safeguard 7.01 is a critical element in the defensive mitigations for 2023 Statewide Information Technology Control Standard RA-5.

Assessed Elements:

Assessment Methodology

Safeguard 7.02 (IG1) Establish and Maintain a Remediation Process

The implementation of Safeguard 7.02 is a critical element in the defensive mitigations for 2023 Statewide Information Technology Control Standard RA-5.

Assessed Elements:

Assessment Methodology

Safeguard 7.03 (IG1) Perform Automated Operating System Patch Management

The implementation of Safeguard 7.03 contributes to the defensive mitigation for 2023 Statewide Information Technology Control Standards RA-5, RA-7, SI-2, and SI-2(2).

Assessed Elements:

Assessment Methodology

Safeguard 7.04 (IG1) Perform Automated Application Patch Management

The implementation of Safeguard 7.04 contributes to the defensive mitigation for 2023 Statewide Information Technology Control Standards RA-5, RA-7, SI-2, and SI-2(2).

Assessed Elements:

Assessment Methodology

Safeguard 7.05 (IG2) Perform Automated Vulnerability Scans of Internal Enterprise Assets

Included in the Assessment as an Enterprise Solution (Tenable) enables subscribers to automate vulnerability scanning.

The implementation of Safeguard 7.05 contributes to the defensive mitigation for 2023 Statewide Information Technology Control Standard RA-5.

Assessed Elements:

Assessment Methodology

Safeguard 7.06 (IG2) Perform Automated Vulnerability Scans of Externally-Exposed Enterprise Assets

Included in the Assessment as an Enterprise Solution (CISA Cyber Hygiene) enables subscribers to automate external vulnerability scanning.

The implementation of Safeguard 7.06 contributes to the defensive mitigation for 2023 Statewide Information Technology Control Standard RA-5.

Assessed Elements:

Assessment Methodology

Safeguard 8.01 (IG1) Establish and Maintain an Audit Log Management Process

The implementation of Safeguard 8.01 is operationally equivalent to the defensive mitigation for 2023 Statewide Information Technology Control Standard AU-1; and a critical element in the defensive mitigations for Standard AU-2.

Assessed Elements:

  • CIS|SOC SEIM Audit Log Management Process

Assessment Methodology

Safeguard 8.02 (IG1) Collect Audit Logs

The implementation of Safeguard 8.02 is operationally equivalent to the defensive mitigation for 2023 Statewide Information Technology Control Standards AU-2 and AU-12; and contributes to the defensive mitigation for Standards AU-7.

Assessed Elements:

  • Hardware Assets discovered during Internal Testing (See Safeguard 1.01)
  • Event Log Storage Locations (CIS L1 Benchmarks) observed during Internal Testing

Assessment Methodology

Safeguard 8.03 (IG1) Ensure Adequate Audit Log Storage

The implementation of Safeguard 8.03 is operationally equivalent to the defensive mitigation for 2023 Statewide Information Technology Control Standard AU-4.

Assessed Elements:

  • Hardware Assets discovered during Internal Testing (See Safeguard 1.01)
  • Event Log Storage Space (CIS L1 Benchmarks) observed during Internal Testing

Assessment Methodology

Safeguard 8.04 (IG2) Standardize Time Synchronization

Included in the Assessment as an Enterprise Solution (NTP Servers) enables time synchronization.

The implementation of Safeguard 8.04 contributes to the defensive mitigation for 2023 Statewide Information Technology Control Standard AU-8.

Assessed Elements:

Assessment Methodology

Safeguard 8.05 (IG2) Collect Detailed Audit Logs

Included in the Assessment as an Enterprise Solution (Sentinel SIEM) enables subscribers to collect audit logs.

The implementation of Safeguard 8.05 is operationally equivalent to the defensive mitigation for 2023 Statewide Information Technology Control Standard AU-3; and contributes to the defensive mitigation for Standards AU-3(1), AU-7, and AU-12.

Assessed Elements:

  • CIS|SOC SEIM Audit Log Management Process
  • Hardware Assets discovered during Internal Testing (See Safeguard 1.01)
  • Event Log Generation Settings (CIS L1 Benchmarks) observed during Internal Testing

Assessment Methodology

Safeguard 8.09 (IG2) Centralize Audit Logs

Included in the Assessment as an Enterprise Solution (Sentinel SIEM) enables subscribers to centralize audit logs.

The implementation of Safeguard 8.09 contributes to the defensive mitigation for 2023 Statewide Information Technology Control Standard AU-6(3).

Assessed Elements:

  • Hardware Assets discovered during Internal Testing (See Safeguard 1.01)
  • Log Aggregation Implementation observed during Internal Testing

Assessment Methodology

Safeguard 8.10 (IG2) Retain Audit Logs

Included in the Assessment as an Enterprise Solution (Sentinel SIEM) enables subscribers to retain audit logs.

The implementation of Safeguard 8.10 is operationally equivalent to the defensive mitigation for 2023 Statewide Information Technology Control Standard AU-11.

Assessed Elements:

  • Hardware Assets discovered during Internal Testing (See Safeguard 1.01)
  • Audit Record Retention observed during Internal Testing

Assessment Methodology

Safeguard 8.11 (IG2) Conduct Audit Log Reviews

Included in the Assessment as an Enterprise Solution (Sentinel SIEM) provides subscribers with triage services and review capabilities.

The implementation of Safeguard 8.11 is operationally equivalent to the defensive mitigation for 2023 Statewide Information Technology Control Standard AU-6; and contributes to the defensive mitigation for Standards AU-6(1) and AU-7(1).

Assessed Elements:

  • Audit Record Review Schedule observed during Internal Testing

Assessment Methodology

Safeguard 9.01 (IG1) Ensure Use of Only Fully Supported Browsers and Email Clients

The implementation of Safeguard 9.01 contributes to the defensive mitigation for 2023 Statewide Information Technology Control Standards CM-10 and SC-18.

Assessed Elements:

Assessment Methodology

Safeguard 9.02 (IG1) Use DNS Filtering Services

The implementation of Safeguard 9.02 is a critical element in the defensive mitigations for 2023 Statewide Information Technology Control Standard SI-8.

Assessed Elements:

Assessment Methodology

Safeguard 10.01 (IG1) Deploy and Maintain Anti-Malware Software

The implementation of Safeguard 10.01 contributes to the defensive mitigation for 2023 Statewide Information Technology Control Standard SI-3.

Assessed Elements:

Assessment Methodology

Safeguard 10.02 (IG1) Configure Automatic Anti-Malware Signature Updates

The implementation of Safeguard 10.02 contributes to the defensive mitigation for 2023 Statewide Information Technology Control Standard SI-3.

Assessed Elements:

Assessment Methodology

Safeguard 10.03 (IG1) Disable Autorun and Autoplay for Removable Media

The implementation of Safeguard 10.03 contributes to the defensive mitigation for 2023 Statewide Information Technology Control Standard MP-7.

Assessed Elements:

Assessment Methodology

Safeguard 11.01 (IG1) Establish and Maintain a Data Recovery Process

The implementation of Safeguard 11.01 contributes to the defensive mitigation for 2023 Statewide Information Technology Control Standards CP-2 and CP-10.

Assessed Elements:

Assessment Methodology

Safeguard 11.02 (IG1) Perform Automated Backups

The implementation of Safeguard 11.02 contributes to the defensive mitigation for 2023 Statewide Information Technology Control Standards CP-9 and CP-10.

Assessed Elements:

Assessment Methodology

Safeguard 11.03 (IG1) Protect Recovery Data

The implementation of Safeguard 11.03 contributes to the defensive mitigation for 2023 Statewide Information Technology Control Standards CP-9, CP-9(8) and SC-28.

Assessed Elements:

  • Hardware Assets discovered during Internal Testing (See Safeguard 1.01)
  • Backup Data Protections observed during Internal Testing

Assessment Methodology

Safeguard 11.04 (IG1) Establish and Maintain an Isolated Instance of Recovery Data

The implementation of Safeguard 11.04 is a critical element in the defensive mitigations for 2023 Statewide Information Technology Control Standards CP-6 and CP-6(1).

Assessed Elements:

  • Hardware Assets discovered during Internal Testing (See Safeguard 1.01)
  • Backup Data Protections observed during Internal Testing

Assessment Methodology

Safeguard 13.01 (IG2) Centralize Security Event Alerting

Included in the Assessment as an Enterprise Solution (Sentinel SIEM) provides subscribers with triage services and review capabilities.

The implementation of Safeguard 13.01 is a critical element in the defensive mitigations for 2023 Statewide Information Technology Control Standards IR-4(1) and SI-4(2); and contributes to the defensive mitigation for Standards AU-6(1), AU-7, and SI-4(5).

Assessed Elements:

Assessment Methodology

Safeguard 13.07 (IG3) Deploy a Host-Based Intrusion Prevention Solution

Included in the Assessment as an Enterprise Solution (Sentinel SIEM) provides subscribers with Endpoint Detection and Response (EDR).

The implementation of Safeguard 13.07 is not directly related to the defensive mitigation of a 2023 Statewide Information Technology Control Standard; rather, it contributes to the organization's overall security posture.

Assessed Elements:

Assessment Methodology

Safeguard 14.01 (IG1) Establish and Maintain a Security Awareness Program

The implementation of Safeguard 14.01 contributes to the defensive mitigation for 2023 Statewide Information Technology Control Standards AT-1, AT-2, and PM-13.

Assessed Elements:

Assessment Methodology

Safeguard 14.02 (IG1) Train Workforce Members to Recognize Social Engineering Attacks

The implementation of Safeguard 14.02 is operationally equivalent to the defensive mitigation for 2023 Statewide Information Technology Control Standard AT-2(3).

Assessed Elements:

Assessment Methodology

Safeguard 14.03 (IG1) Train Workforce Members on Authentication Best Practices

The implementation of Safeguard 14.03 contributes to the defensive mitigation for 2023 Statewide Information Technology Control Standard AT-2.

Assessed Elements:

Assessment Methodology

Safeguard 14.04 (IG1) Train Workforce on Data Handling Best Practices

The implementation of Safeguard 14.04 contributes to the defensive mitigation for 2023 Statewide Information Technology Control Standard AT-2.

Assessed Elements:

Assessment Methodology

Safeguard 14.05 (IG1) Train Workforce Members on Causes of Unintentional Data Exposure

The implementation of Safeguard 14.05 contributes to the defensive mitigation for 2023 Statewide Information Technology Control Standard AC-22.

Assessed Elements:

Assessment Methodology

Safeguard 14.06 (IG1) Train Workforce Members on Recognizing and Reporting Security Incidents

The implementation of Safeguard 14.06 contributes to the defensive mitigation for 2023 Statewide Information Technology Control Standard AT-2.

Assessed Elements:

Assessment Methodology

Safeguard 14.08 (IG1) Train Workforce on the Dangers of Connecting to and Transmitting Enterprise Data Over Insecure Networks

The implementation of Safeguard 14.08 contributes to the defensive mitigation for 2023 Statewide Information Technology Control Standard AT-2.

Assessed Elements:

Assessment Methodology

Safeguard 15.01 (IG1) Establish and Maintain an Inventory of Service Providers

The implementation of Safeguard 15.01 is a critical element in the defensive mitigations for 2023 Statewide Information Technology Control Standard PM-30(1).

Assessed Elements:

Assessment Methodology

Safeguard 17.01 (IG1) Designate Personnel to Manage Incident Handling

The implementation of Safeguard 17.01 is a critical element in the defensive mitigations for 2023 Statewide Information Technology Control Standard IR-7; and contributes to the defensive mitigation for Standards IR-1 and IR-8.

Assessed Elements:

Assessment Methodology

Safeguard 17.02 (IG1) Establish and Maintain Contact Information for Reporting Security Incidents

The implementation of Safeguard 17.02 is a critical element in the defensive mitigations for 2023 Statewide Information Technology Control Standard IR-6(3); and contributes to the defensive mitigation for Standard IR-6.

Assessed Elements:

Assessment Methodology

Safeguard 17.03 (IG1) Establish and Maintain an Enterprise Process for Reporting Incidents

The implementation of Safeguard 17.03 is a critical element in the defensive mitigations for 2023 Statewide Information Technology Control Standard IR-6(1); and contributes to the defensive mitigation for Standards IR-5, IR-6, and IR-8.

Assessed Elements:

Assessment Methodology

Safeguard 18.02 (IG2) Perform Periodic External Penetration Tests

Included in the Assessment as an Enterprise Solution (CISA RVA) provides subscribers with external penetration testing.

The implementation of Safeguard 18.02 contributes to the defensive mitigation for 2023 Statewide Information Technology Control Standard CA-8.

Assessed Elements:

Assessment Methodology