Browser Notes: To open the any of the hyperlinks found on this page in a new tab, Ctrl+Click or right-click and select ‘Open link in new tab.’”
This document serves as a high-level index of the CIS Safeguards included in the CSS Cybersecurity Assessment Team "IG1+" review baseline with brief explanations of how each included Safeguard aligns to the 2023 Statewide Information Technology Control Standards and, where applicable, rationale for included "IG2" and "IG3" Safeguards. Included under each Safeguard are links to the relevant items from the Artifact Request, Internal Testing, and Methodology.
The implementation of Safeguard 1.01 is a critical element in the defensive mitigations for 2023 Statewide Information Technology Control Standard CM-8(1); and contributes to the defensive mitigation for Standards CM-8 and PM-5.
Assessed Elements:
- GV01: Detailed Hardware Asset Inventory
- Hardware Assets discovered during Internal Testing
- Powershell Script to enumerate Hardware Assets from Artifact Collector
- KQL Script to enumerate Hardware Assets using Advanced Hunting in Defender
- Both Defender and Tenable have a pre-built report to list Agency Hardware Assets
Assessment Methodology
- CIS Controls Assessment Specification for CIS Safeguard 1.01
- Score is based on the accuracy (assets detected/assets authorized) and completeness (presence of required elements) of the Authorized Hardware Asset Inventory.
The implementation of Safeguard 1.02 contributes to the defensive mitigation for 2023 Statewide Information Technology Control Standard CM-8(3).
Assessed Elements:
- AD02: Agency policy documentation that defines the timeframe for removing unauthorized devices
- Hardware Assets discovered during Internal Testing (See Safeguard 1.01)
Assessment Methodology
- CIS Controls Assessment Specification for CIS Safeguard 1.02
- Score is based on the unauthorized assets (detected but not in Authorized Hardware Asset Inventory) present for more than 1 day.
The implementation of Safeguard 2.01 is a critical element in the defensive mitigations for 2023 Statewide Information Technology Control Standard MA-3; and contributes to the defensive mitigation for Standards CM-7(1) and CM-8.
Assessed Elements:
Assessment Methodology
- CIS Controls Assessment Specification for CIS Safeguard 2.01
- Score is based on the presence of required elements in the Authorized Software Inventory.
The implementation of Safeguard 2.02 is operationally equivalent to the defensive mitigation for 2023 Statewide Information Technology Control Standard SA-22.
Assessed Elements:
- GV05: Authorized Software Inventory
- AD04: Exception Documentation for Unsupported Software That is Necessary for the Fulfillment of the Organization's Mission
- Software Assets discovered during Internal Testing
Assessment Methodology
- CIS Controls Assessment Specification for CIS Safeguard 2.02
- Score is based on the percentage of authorized software that is not unsupported without an exception.
The implementation of Safeguard 2.03 contributes to the defensive mitigation for 2023 Statewide Information Technology Control Standards CM-7(2), CM-8(3), CM-10, and CM-11.
Assessed Elements:
- AD02: Agency policy documentation that defines the timeframe for removing unauthorized devices
- Software Assets discovered during Internal Testing
Assessment Methodology
- CIS Controls Assessment Specification for CIS Safeguard 2.03
- Score is based on the unautorized software (detected but not in Authorized Software Inventory) present for more than 1 day.
Included in the Assessment as Enterprise Solutions (Tenable/Defender) enable subscribers to automate software discovery.
The implementation of Safeguard 2.04 contributes to the defensive mitigation for 2023 Statewide Information Technology Control Standard CM-8(3).
Assessed Elements:
- GV01: Detailed Hardware Asset Inventory
- AD05: Policy Documentation That Defines the Timeframe Between Consecutive Active Software Discovery Scans
- AD06: List of Software Inventory Tools in use by the Organization
- Visibility of Hardware Assets in Software Inventory Tools observed during Internal Testing (See Safeguard 1.01)
Assessment Methodology
- CIS Controls Assessment Specification for CIS Safeguard 2.04
- Score is based on the percentage of software capable assets covered by automated software inventory tools.
The implementation of Safeguard 3.01 is operationally equivalent to the defensive mitigation for 2023 Statewide Information Technology Control Standard SI-12; a critical element in the defensive mitigations for Standard AU-11; and contributes to the defensive mitigation for Standard CM-12.
Assessed Elements:
Assessment Methodology
- CIS Controls Assessment Specification for CIS Safeguard 3.01
- Score is based on the completeness of the Data Management Process (presence of required elements).
The implementation of Safeguard 3.02 is a critical element in the defensive mitigations for 2023 Statewide Information Technology Control Standards CM-12 and PM-5(1); and contributes to the defensive mitigation for Standard RA-2.
Assessed Elements:
- GV10: Organization's Data Management Process
- GV01: Detailed Hardware Asset Inventory (Specifically those storing sensitive data)
Assessment Methodology
- CIS Controls Assessment Specification for CIS Safeguard 3.02
- Score is based on the percentage of sensitive data mapped to sensitivity designations (defined in Data Management Process) and assets.
The implementation of Safeguard 3.04 contributes to the defensive mitigation for 2023 Statewide Information Technology Control Standards AU-11 and SI-12.
Assessed Elements:
Assessment Methodology
- CIS Controls Assessment Specification for CIS Safeguard 3.04
- Score is based on the percentage of sensitive data types mapped to retention periods.
The implementation of Safeguard 3.05 contributes to the defensive mitigation for 2023 Statewide Information Technology Control Standards MP-6 and SR-12.
Assessed Elements:
Assessment Methodology
- CIS Controls Assessment Specification for CIS Safeguard 3.05
- Score is based on the percentage of sensitive data types mapped to secure disposal methods.
The implementation of Safeguard 3.06 contributes to the defensive mitigation for 2023 Statewide Information Technology Control Standard SC-28.
Assessed Elements:
- GV01: Detailed Hardware Asset Inventory
- Group Policy Objects evaluated
- Encryption settings observed during Internal Testing
Assessment Methodology
- CIS Controls Assessment Specification for CIS Safeguard 3.06
- Score is based on the percentage of hardware assets equipped with approved encryption software.
Included in the Assessment in accordance with Statewide Policy 107-004-050.
The implementation of Safeguard 3.07 contributes to the defensive mitigation for 2023 Statewide Information Technology Control Standard RA-2.
Assessed Elements:
- GV10: Organization's Data Management Process
- AD13: Agency Data Classification Scheme
- GV12: Sensitive Data Inventory
Assessment Methodology
- CIS Controls Assessment Specification for CIS Safeguard 3.07
- Score is based on the implementation percentage of classification scheme.
The implementation of Safeguard 4.01 is operationally equivalent to the defensive mitigation for 2023 Statewide Information Technology Control Standards CM-1 and CM-9; a critical element in the defensive mitigations for Standards CM-2, CM-6, CM-7(1), SA-3, SA-8, and SA-10; and contributes to the defensive mitigation for Standard CM-7.
Assessed Elements:
Assessment Methodology
- CIS Controls Assessment Specification for CIS Safeguard 4.01
- Score is based on the implementation of secure configuration standards for operating systems, web servers, browsers, databases, and office suites.
The implementation of Safeguard 4.03 is operationally equivalent to the defensive mitigation for 2023 Statewide Information Technology Control Standard AC-11; a critical element in the defensive mitigations for Standards AC-11 and AC-12; and contributes to the defensive mitigation for Standard AC-2(5).
Assessed Elements:
- Hardware Assets discovered during Internal Testing (See Safeguard 1.01)
- Session Locking settings observed during Internal Testing
Assessment Methodology
- CIS Controls Assessment Specification for CIS Safeguard 4.03
- Score is based on the percentage of agency hardware assets properly configured for automatic session locking.
The implementation of Safeguard 4.04 contributes to the defensive mitigation for 2023 Statewide Information Technology Control Standards CA-9, SC-7, and SC-7(5).
Assessed Elements:
- Hardware Assets discovered during Internal Testing (See Safeguard 1.01)
- Firewall settings observed during Internal Testing
Assessment Methodology
- CIS Controls Assessment Specification for CIS Safeguard 4.04
- Score is based on the percentage of agency hardware assets with firewalls configured according to CIS Level 1 Benchmarks.
The implementation of Safeguard 4.05 contributes to the defensive mitigation for 2023 Statewide Information Technology Control Standards SC-7 and SC-7(5).
Assessed Elements:
- Hardware Assets discovered during Internal Testing (See Safeguard 1.01)
- Firewall settings observed during Internal Testing
Assessment Methodology
- CIS Controls Assessment Specification for CIS Safeguard 4.05
- Score is based on the percentage of agency hardware assets with firewalls configured according to CIS Level 1 Benchmarks.
The implementation of Safeguard 4.07 contributes to the defensive mitigation for 2023 Statewide Information Technology Control Standard IA-5.
Assessed Elements:
- Hardware Assets discovered during Internal Testing (See Safeguard 1.01)
- Default Account and Group Policy settings observed during Internal Testing
Assessment Methodology
- CIS Controls Assessment Specification for CIS Safeguard 4.07
- Score is based on the percentage of agency hardware assets with the default "Guest" account disabled and the default "Administrator" account properly protected.
The implementation of Safeguard 5.01 contributes to the defensive mitigation for 2023 Statewide Information Technology Control Standard AC-2.
Assessed Elements:
- GV22: Inventory of Accounts
- Domain Accounts discovered during Internal Testing
Assessment Methodology
- CIS Controls Assessment Specification for CIS Safeguard 5.01
- Score is based on the completeness (presence of required elements) in the Inventory of Accounts.
The implementation of Safeguard 5.02 contributes to the defensive mitigation for 2023 Statewide Information Technology Control Standard IA-5(1).
Assessed Elements:
- GV20: Unique Password Policy
- Password settings observed during Internal Testing
Assessment Methodology
- CIS Controls Assessment Specification for CIS Safeguard 5.02
- Score is based on the percentage of accounts configured in accordance to settings defined in the Statewide Standards.
The implementation of Safeguard 5.03 contributes to the defensive mitigation for 2023 Statewide Information Technology Control Standard AC-2(3).
Assessed Elements:
- Domain Accounts discovered during Internal Testing (See Safeguard 5.01)
- Domain Account status observed during Internal Testing
Assessment Methodology
- CIS Controls Assessment Specification for CIS Safeguard 5.03
- Score is based on the percentage of dormant accounts (last logon more than 90 days prior to sampling) that are still enabled.
The implementation of Safeguard 5.04 is a critical element in the defensive mitigations for 2023 Statewide Information Technology Control Standards AC-6(2) and AC-6(5).
Assessed Elements:
- GV22: Inventory of Accounts
- Domain and Local Administrator Accounts discovered during Internal Testing
Assessment Methodology
- CIS Controls Assessment Specification for CIS Safeguard 5.04
- Score is based on the percentage of discovered administrator accounts listed in the Inventory of Accounts with associated non-administrative credentials.
The implementation of Safeguard 6.01 contributes to the defensive mitigation for 2023 Statewide Information Technology Control Standards AC-1, AC-2, AC-2(1), IA-4, and IA-5.
Assessed Elements:
Assessment Methodology
- CIS Controls Assessment Specification for CIS Safeguard 6.01
- Score is based on the completeness (presence of required elements) in the Access Granting Process.
The implementation of Safeguard 6.02 contributes to the defensive mitigation for 2023 Statewide Information Technology Control Standards AC-1, AC-2, and AC-2(1).
Assessed Elements:
Assessment Methodology
- CIS Controls Assessment Specification for CIS Safeguard 6.02
- Score is based on the completeness (presence of required elements) in the Access Revoking Process.
The implementation of Safeguard 6.04 contributes to the defensive mitigation for 2023 Statewide Information Technology Control Standards AC-19, IA-2(1), and IA-2(2).
Assessed Elements:
- GV03.h - Configuration Standards: MFA Mechanisms for Admin Accounts & Remote Access
- Domain Accounts and MFA tags discovered during Internal Testing
Assessment Methodology
- CIS Controls Assessment Specification for CIS Safeguard 6.04
- Score is based on the presence of multi-factor authentication methodologies in place for remote access.
The implementation of Safeguard 6.05 is operationally equivalent to the defensive mitigation for 2023 Statewide Information Technology Control Standard IA-2(1).
Assessed Elements:
- GV03.h - Configuration Standards: MFA Mechanisms for Admin Accounts & Remote Access
- Domain Accounts and MFA tags discovered during Internal Testing
Assessment Methodology
- CIS Controls Assessment Specification for CIS Safeguard 6.05
- Score is based on the percentage of administrative accounts with multi-factor authentication configured.
The implementation of Safeguard 7.01 is a critical element in the defensive mitigations for 2023 Statewide Information Technology Control Standard RA-5.
Assessed Elements:
Assessment Methodology
- CIS Controls Assessment Specification for CIS Safeguard 7.01
- Score is based on the presence of a current Vulnerability Management Process.
The implementation of Safeguard 7.02 is a critical element in the defensive mitigations for 2023 Statewide Information Technology Control Standard RA-5.
Assessed Elements:
Assessment Methodology
- CIS Controls Assessment Specification for CIS Safeguard 7.02
- Score is based on the completeness (presence of required elements) of the Vulnerability Remediation Process.
The implementation of Safeguard 7.03 contributes to the defensive mitigation for 2023 Statewide Information Technology Control Standards RA-5, RA-7, SI-2, and SI-2(2).
Assessed Elements:
- GV03.a Configuration Standards: Operating Systems & Software
- Operating System Versions observed during Internal Testing
Assessment Methodology
- CIS Controls Assessment Specification for CIS Safeguard 7.03
- Score is based on the percentage of sampled operating systems that are up-to-date or have a documented exception.
The implementation of Safeguard 7.04 contributes to the defensive mitigation for 2023 Statewide Information Technology Control Standards RA-5, RA-7, SI-2, and SI-2(2).
Assessed Elements:
- GV24: Authorized Automated Patch Management Software
- GV03.f - Configuration Standards: Automated Patch Management Software
- Application Versions observed during Internal Testing
Assessment Methodology
- CIS Controls Assessment Specification for CIS Safeguard 7.04
- Score is based on the percentage of sampled applications that are up-to-date or have a documented exception.
Included in the Assessment as an Enterprise Solution (Tenable) enables subscribers to automate vulnerability scanning.
The implementation of Safeguard 7.05 contributes to the defensive mitigation for 2023 Statewide Information Technology Control Standard RA-5.
Assessed Elements:
- GV25: List of Vulnerability Scanning Software
- GV03.g - Configuration Standards: Vulnerability Scanners / Scanning Software
- Internal Vulnerability Scan Coverage observed during Internal Testing
Assessment Methodology
- CIS Controls Assessment Specification for CIS Safeguard 7.05
- Score is based on the percentage of sampled internal assets covered by an authenticated vulnerbaility scanner.
Included in the Assessment as an Enterprise Solution (CISA Cyber Hygiene) enables subscribers to automate external vulnerability scanning.
The implementation of Safeguard 7.06 contributes to the defensive mitigation for 2023 Statewide Information Technology Control Standard RA-5.
Assessed Elements:
- GV03.g - Configuration Standards: Vulnerability Scanners / Scanning Software
- External Vulnerability Scan Coverage observed during Internal Testing
Assessment Methodology
- CIS Controls Assessment Specification for CIS Safeguard 7.06
- Score is based on the percenatge of sampled externally-exposed assets covered by a vulnerability scanner.
The implementation of Safeguard 8.01 is operationally equivalent to the defensive mitigation for 2023 Statewide Information Technology Control Standard AU-1; and a critical element in the defensive mitigations for Standard AU-2.
Assessed Elements:
- CIS|SOC SEIM Audit Log Management Process
Assessment Methodology
- CIS Controls Assessment Specification for CIS Safeguard 8.01
- Score is based on the completeness (presence of required elements) of the Audit Log Management Process.
The implementation of Safeguard 8.02 is operationally equivalent to the defensive mitigation for 2023 Statewide Information Technology Control Standards AU-2 and AU-12; and contributes to the defensive mitigation for Standards AU-7.
Assessed Elements:
- Hardware Assets discovered during Internal Testing (See Safeguard 1.01)
- Event Log Storage Locations (CIS L1 Benchmarks) observed during Internal Testing
Assessment Methodology
- CIS Controls Assessment Specification for CIS Safeguard (8.02
- Score is based on the percentage of sampled assets with local log storage locations configured in accordance with CIS Level 1 Benchmarks.
The implementation of Safeguard 8.03 is operationally equivalent to the defensive mitigation for 2023 Statewide Information Technology Control Standard AU-4.
Assessed Elements:
- Hardware Assets discovered during Internal Testing (See Safeguard 1.01)
- Event Log Storage Space (CIS L1 Benchmarks) observed during Internal Testing
Assessment Methodology
- CIS Controls Assessment Specification for CIS Safeguard 8.03
- Score is based on the percentage of sampled assets with local log storage capacity configured in accordance with CIS Level 1 Benchmarks.
Included in the Assessment as an Enterprise Solution (NTP Servers) enables time synchronization.
The implementation of Safeguard 8.04 contributes to the defensive mitigation for 2023 Statewide Information Technology Control Standard AU-8.
Assessed Elements:
- Hardware Assets discovered during Internal Testing (See Safeguard 1.01)
- Network Time Protocol Settings observed during Internal Testing
Assessment Methodology
- CIS Controls Assessment Specification for CIS Safeguard 8.04
- Score is based on the percentage of sampled assets properly configured with at least two approved, synchronized time sources.
Included in the Assessment as an Enterprise Solution (Sentinel SIEM) enables subscribers to collect audit logs.
The implementation of Safeguard 8.05 is operationally equivalent to the defensive mitigation for 2023 Statewide Information Technology Control Standard AU-3; and contributes to the defensive mitigation for Standards AU-3(1), AU-7, and AU-12.
Assessed Elements:
- CIS|SOC SEIM Audit Log Management Process
- Hardware Assets discovered during Internal Testing (See Safeguard 1.01)
- Event Log Generation Settings (CIS L1 Benchmarks) observed during Internal Testing
Assessment Methodology
- CIS Controls Assessment Specification for CIS Safeguard 8.05
- Score is based on the percentage of sampled assets with event logging configured in accordance with the Statewide Standards.
Included in the Assessment as an Enterprise Solution (Sentinel SIEM) enables subscribers to centralize audit logs.
The implementation of Safeguard 8.09 contributes to the defensive mitigation for 2023 Statewide Information Technology Control Standard AU-6(3).
Assessed Elements:
- Hardware Assets discovered during Internal Testing (See Safeguard 1.01)
- Log Aggregation Implementation observed during Internal Testing
Assessment Methodology
- CIS Controls Assessment Specification for CIS Safeguard 8.09
- Score is based on the percentage of sampled assets configured to centralize event logs in accordance with the Statewide Standards.
Included in the Assessment as an Enterprise Solution (Sentinel SIEM) enables subscribers to retain audit logs.
The implementation of Safeguard 8.10 is operationally equivalent to the defensive mitigation for 2023 Statewide Information Technology Control Standard AU-11.
Assessed Elements:
- Hardware Assets discovered during Internal Testing (See Safeguard 1.01)
- Audit Record Retention observed during Internal Testing
Assessment Methodology
- CIS Controls Assessment Specification for CIS Safeguard 8.10
- Score is based on the percentage of sampled assets configured to retain event logs in accordance with the Statewide Standards.
Included in the Assessment as an Enterprise Solution (Sentinel SIEM) provides subscribers with triage services and review capabilities.
The implementation of Safeguard 8.11 is operationally equivalent to the defensive mitigation for 2023 Statewide Information Technology Control Standard AU-6; and contributes to the defensive mitigation for Standards AU-6(1) and AU-7(1).
Assessed Elements:
- Audit Record Review Schedule observed during Internal Testing
Assessment Methodology
- CIS Controls Assessment Specification for CIS Safeguard 8.11
- Score is based on the frequency of audit record reviews.
The implementation of Safeguard 9.01 contributes to the defensive mitigation for 2023 Statewide Information Technology Control Standards CM-10 and SC-18.
Assessed Elements:
- GV05: Authorized Software Inventory
- Unsupported Browsers and Email Clients discovered during Internal Testing
Assessment Methodology
- CIS Controls Assessment Specification for CIS Safeguard 9.01
- Score is based on the percentage of sampled web browser and email client software that are supported and correctly labeled as such in the Authorized Software Inventory.
The implementation of Safeguard 9.02 is a critical element in the defensive mitigations for 2023 Statewide Information Technology Control Standard SI-8.
Assessed Elements:
- GV01: Detailed Hardware Asset Inventory
- GV03.d - Configuration Standards: DNS Servers
- DNS Filtering observed during Internal Testing
Assessment Methodology
- CIS Controls Assessment Specification for CIS Safeguard 9.02
- Score is based on the percentage of sampled hardware assets configured to use authorized DNS filters.
The implementation of Safeguard 10.01 contributes to the defensive mitigation for 2023 Statewide Information Technology Control Standard SI-3.
Assessed Elements:
- GV31: List of Authorized Anti‐malware Software
- Hardware Assets discovered during Internal Testing (See Safeguard 1.01)
- Anti-malware Deployment observed during Internal Testing
Assessment Methodology
- CIS Controls Assessment Specification for CIS Safeguard 10.01
- Score is based on the percentage of sampled hardware assets with properly configured and authorized anti-malware software.
The implementation of Safeguard 10.02 contributes to the defensive mitigation for 2023 Statewide Information Technology Control Standard SI-3.
Assessed Elements:
- GV31: List of Authorized Anti‐malware Software
- Hardware Assets discovered during Internal Testing (See Safeguard 1.01)
- Anti-malware Update Settings and Implementation observed during Internal Testing
Assessment Methodology
- CIS Controls Assessment Specification for CIS Safeguard 10.02
- Score is based on the percentage of sampled hardware assets properly configured to automatically update anti-malware signatures.
The implementation of Safeguard 10.03 contributes to the defensive mitigation for 2023 Statewide Information Technology Control Standard MP-7.
Assessed Elements:
- Hardware Assets discovered during Internal Testing (See Safeguard 1.01)
- Removable Media Settings observed during Internal Testing
Assessment Methodology
- CIS Controls Assessment Specification for CIS Safeguard 10.03
- Score is based on the percentage of sampled hardware assets properly configured to disable autorun, autoplay, and auto-execute functions.
The implementation of Safeguard 11.01 contributes to the defensive mitigation for 2023 Statewide Information Technology Control Standards CP-2 and CP-10.
Assessed Elements:
Assessment Methodology
- CIS Controls Assessment Specification for CIS Safeguard 11.01
- Score is based on the completeness (presence of required elements) of the Data Recovery Process.
The implementation of Safeguard 11.02 contributes to the defensive mitigation for 2023 Statewide Information Technology Control Standards CP-9 and CP-10.
Assessed Elements:
- Hardware Assets discovered during Internal Testing (See Safeguard 1.01)
- Automated Backup Implementation observed during Internal Testing
- KQL Script to enumerate all systems with CommVault Agent installed using Advanced Hunting in Defender
- CommVault backup reporting (statistical data obtained from DCS Backup Team)
Assessment Methodology
- CIS Controls Assessment Specification for CIS Safeguard 11.02
- Score is based on the percentage of sampled hardware assets properly configured with a backup solution which have been backed up within one week of sampling.
The implementation of Safeguard 11.03 contributes to the defensive mitigation for 2023 Statewide Information Technology Control Standards CP-9, CP-9(8) and SC-28.
Assessed Elements:
- Hardware Assets discovered during Internal Testing (See Safeguard 1.01)
- Backup Data Protections observed during Internal Testing
Assessment Methodology
- CIS Controls Assessment Specification for CIS Safeguard 11.03
- Score is based on the percentage of sampled backup soutions properly configured to encrypt backup data.
The implementation of Safeguard 11.04 is a critical element in the defensive mitigations for 2023 Statewide Information Technology Control Standards CP-6 and CP-6(1).
Assessed Elements:
- Hardware Assets discovered during Internal Testing (See Safeguard 1.01)
- Backup Data Protections observed during Internal Testing
Assessment Methodology
- CIS Controls Assessment Specification for CIS Safeguard 11.04
- Score is based on the percentage of sampled backup soutions properly configured to maintain an isolated instance of recovery data.
Included in the Assessment as an Enterprise Solution (Sentinel SIEM) provides subscribers with triage services and review capabilities.
The implementation of Safeguard 13.01 is a critical element in the defensive mitigations for 2023 Statewide Information Technology Control Standards IR-4(1) and SI-4(2); and contributes to the defensive mitigation for Standards AU-6(1), AU-7, and SI-4(5).
Assessed Elements:
- Hardware Assets discovered during Internal Testing (See Safeguard 1.01)
- Agency adoption of Defender/Sentinel SIEM Solution observed during Internal Testing
Assessment Methodology
- CIS Controls Assessment Specification for CIS Safeguard 13.01
- Score is based on the percentage of sampled assets configured to centralize event logs in accordance with the Statewide Standards.
Included in the Assessment as an Enterprise Solution (Sentinel SIEM) provides subscribers with Endpoint Detection and Response (EDR).
The implementation of Safeguard 13.07 is not directly related to the defensive mitigation of a 2023 Statewide Information Technology Control Standard; rather, it contributes to the organization's overall security posture.
Assessed Elements:
- Hardware Assets discovered during Internal Testing (See Safeguard 1.01)
- Agency adoption of Defender/Sentinel SIEM Solution observed during Internal Testing
Assessment Methodology
- CIS Controls Assessment Specification for CIS Safeguard 13.07
- Score is based on the percentage of sampled assets configured with a Host-Based Intrusion Prevention or Endpoint Detection and Response (EDR) solution.
The implementation of Safeguard 14.01 contributes to the defensive mitigation for 2023 Statewide Information Technology Control Standards AT-1, AT-2, and PM-13.
Assessed Elements:
- AD12: Agency Security Awareness Training Program Plan
- AD14: Security Awareness and Training metrics for the prior year
- Training Statistics observed during Internal Testing
- Report available through Workday Learning or Enterprise Iformation Security & Awareness Program
Assessment Methodology
- CIS Controls Assessment Specification for CIS Safeguard 14.01
- Score is based on the percentage of personnel who have completed initial training and whose training is up-to-date.
The implementation of Safeguard 14.02 is operationally equivalent to the defensive mitigation for 2023 Statewide Information Technology Control Standard AT-2(3).
Assessed Elements:
- AD12: Agency Security Awareness Training Program Plan
- GV43: List of workforce members
- Training Statistics observed during Internal Testing
- Report available through Workday Learning or Enterprise Iformation Security & Awareness Program
Assessment Methodology
- CIS Controls Assessment Specification for CIS Safeguard 14.02
- Score is based on the presence of social engineering components in security training.
The implementation of Safeguard 14.03 contributes to the defensive mitigation for 2023 Statewide Information Technology Control Standard AT-2.
Assessed Elements:
- AD12: Agency Security Awareness Training Program Plan
- GV43: List of workforce members
- Training Statistics observed during Internal Testing
- Report available through Workday Learning or Enterprise Iformation Security & Awareness Program
Assessment Methodology
- CIS Controls Assessment Specification for CIS Safeguard 14.03
- Score is based on the presence of authentication components in security training.
The implementation of Safeguard 14.04 contributes to the defensive mitigation for 2023 Statewide Information Technology Control Standard AT-2.
Assessed Elements:
- AD12: Agency Security Awareness Training Program Plan
- GV43: List of workforce members
- Training Statistics observed during Internal Testing
- Report available through Workday Learning or Enterprise Iformation Security & Awareness Program
Assessment Methodology
- CIS Controls Assessment Specification for CIS Safeguard 14.04
- Score is based on the presence of data handling components in security training.
The implementation of Safeguard 14.05 contributes to the defensive mitigation for 2023 Statewide Information Technology Control Standard AC-22.
Assessed Elements:
- AD12: Agency Security Awareness Training Program Plan
- GV43: List of workforce members
- Training Statistics observed during Internal Testing
- Report available through Workday Learning or Enterprise Iformation Security & Awareness Program
Assessment Methodology
- CIS Controls Assessment Specification for CIS Safeguard 14.05
- Score is based on the presence of data exposure (breach/leakage) components in security training.
The implementation of Safeguard 14.06 contributes to the defensive mitigation for 2023 Statewide Information Technology Control Standard AT-2.
Assessed Elements:
- AD12: Agency Security Awareness Training Program Plan
- GV43: List of workforce members
- Training Statistics observed during Internal Testing
- Report available through Workday Learning or Enterprise Iformation Security & Awareness Program
Assessment Methodology
- CIS Controls Assessment Specification for CIS Safeguard 14.06
- Score is based on the presence of security incident response components in security training.
Safeguard 14.08 (IG1) Train Workforce on the Dangers of Connecting to and Transmitting Enterprise Data Over Insecure Networks
The implementation of Safeguard 14.08 contributes to the defensive mitigation for 2023 Statewide Information Technology Control Standard AT-2.
Assessed Elements:
- AD12: Agency Security Awareness Training Program Plan
- GV43: List of workforce members
- Training Statistics observed during Internal Testing
- Report available through Workday Learning or Enterprise Iformation Security & Awareness Program
Assessment Methodology
- CIS Controls Assessment Specification for CIS Safeguard 14.08
- Score is based on the presence of secure networking components in security training.
The implementation of Safeguard 15.01 is a critical element in the defensive mitigations for 2023 Statewide Information Technology Control Standard PM-30(1).
Assessed Elements:
- GV44: Service Provider Inventory List
- Service Providers identified during Internal Testing
Assessment Methodology
- CIS Controls Assessment Specification for CIS Safeguard 15.01
- Score is based on the completeness (presence of required elements) of the Service Provider Inventory.
The implementation of Safeguard 17.01 is a critical element in the defensive mitigations for 2023 Statewide Information Technology Control Standard IR-7; and contributes to the defensive mitigation for Standards IR-1 and IR-8.
Assessed Elements:
Assessment Methodology
- CIS Controls Assessment Specification for CIS Safeguard 17.01
- Score is based on the completeness (presence of required elements) of the Incident Handling Documentation.
The implementation of Safeguard 17.02 is a critical element in the defensive mitigations for 2023 Statewide Information Technology Control Standard IR-6(3); and contributes to the defensive mitigation for Standard IR-6.
Assessed Elements:
Assessment Methodology
- CIS Controls Assessment Specification for CIS Safeguard 17.02
- Score is based on the presence and currentness of contact information in the Incident Handling Documentation.
The implementation of Safeguard 17.03 is a critical element in the defensive mitigations for 2023 Statewide Information Technology Control Standard IR-6(1); and contributes to the defensive mitigation for Standards IR-5, IR-6, and IR-8.
Assessed Elements:
Assessment Methodology
- CIS Controls Assessment Specification for CIS Safeguard 17.03
- Score is based on the completeness (presence of required elements) of the Incident Reporting Process.
Included in the Assessment as an Enterprise Solution (CISA RVA) provides subscribers with external penetration testing.
The implementation of Safeguard 18.02 contributes to the defensive mitigation for 2023 Statewide Information Technology Control Standard CA-8.
Assessed Elements:
Assessment Methodology
- CIS Controls Assessment Specification for CIS Safeguard 18.02
- Score is based on the performance of annual penetration testing in accordance with Statewide Standards.