Citations: CIS Controls® V7.1
No citations match the current filters.
Data Protection
SNow
The processes and tools used to prevent data exfiltration, mitigate the effects of exfiltrated data, and ensure the privacy and integrity of sensitive information.
Authority Document
SNow Control Objectives (1)
Email and Web Browser Protections
SNow
Minimize the attack surface and the opportunities for attackers to manipulate human behavior though their interaction with web browsers and email systems.
Authority Document
Limitation and Control of Network Ports, Protocols, and Services
SNow
Manage (track/control/correct) the ongoing operational use of ports, protocols, and services on networked devices in order to minimize windows of vulnerability available to attackers.
Authority Document
Controlled Access Based on the Need to Know
SNow
Reference: Access Management
The processes and tools used to track/control/prevent/correct secure access to critical assets (e.g., information, resources, systems) according to the formal determination of which persons, computers, and applications have a need and right to access these critical assets based on an approved classi
Authority Document
Mapped Processes (1)
Controlled Use of Administrative Privileges
SNow
Reference: Access Management
The processes and tools used to track/control/prevent/correct the use, assignment, and configuration of administrative privileges on computers, networks, and applications.
Authority Document
Mapped Processes (1)
Utilize an Active Discovery Tool
SNow
Reference: Active Device Discovery System
Utilize an active discovery tool to identify devices connected to the organization's network and update the hardware asset inventory.
Authority Document
Block Unnecessary File Types
SNow
Reference: Anti-Spam Gateway
Block all e-mail attachments entering the organization's e-mail gateway if the file types are unnecessary for the organization's business.
Authority Document
SNow Control Objectives (1)
Implement DMARC and Enable Receiver-Side Verification
SNow
Reference: Anti-Spam Gateway
To lower the chance of spoofed or modified emails from valid domains, implement Domain-based Message Authentication, Reporting and Conformance (DMARC) policy and verification, starting by implementing the Sender Policy Framework (SPF) and the DomainKeys Identified Mail(DKIM) standards.
Authority Document
Sandbox All Email Attachments
SNow
Reference: Anti-Spam Gateway
Use sandboxing to analyze and block inbound email attachments with malicious behavior.
Authority Document
Implement Application Firewalls
SNow
Reference: Application Aware Firewall
Place application firewalls in front of any critical servers to verify and validate the traffic going to the server. Any unauthorized traffic should be blocked and logged.
Authority Document
Address Unauthorized Assets
SNow
Reference: Asset Inventory System
Ensure that unauthorized assets are either removed from the network, quarantined, or the inventory is updated in a timely manner.
Authority Document
Mapped Processes (1)
Maintain Asset Inventory Information
SNow
Reference: Asset Inventory System
Ensure that the hardware asset inventory records the network address, hardware address, machine name, data asset owner, and department for each asset and whether the hardware asset has been approved to connect to the network.
Authority Document
Mapped Processes (2)
Maintain Detailed Asset Inventory
SNow
Reference: Asset Inventory System
Maintain an accurate and up-to-date inventory of all technology assets with the potential to store or process information. This inventory shall include all hardware assets, whether connected to the organization's network or not.
Authority Document
Mapped Processes (2)
Data Recovery Capabilities
SNow
Reference: Backup / Recovery System
The processes and tools used to properly back up critical information with a proven methodology for timely recovery of it.
Authority Document
Mapped Processes (1)
Ensure Backups Have At least One Non-Continuously Addressable Destination
SNow
Reference: Backup / Recovery System
Ensure that all backups have at least one backup destination that is not continuously addressable through operating system calls.
Authority Document
SNow Control Objectives (1)
Mapped Processes (1)
Ensure Protection of Backups
SNow
Reference: Backup / Recovery System
Ensure that backups are properly protected via physical security or encryption when they are stored, as well as when they are moved across the network. This includes remote backups and cloud services.
Authority Document
Mapped Processes (1)
Ensure Regular Automated Back Ups
SNow
Reference: Backup / Recovery System
Ensure that all system data is automatically backed up on regular basis.
Authority Document
SNow Control Objectives (1)
Mapped Processes (1)
Perform Complete System Backups
SNow
Reference: Backup / Recovery System
Ensure that each of the organization's key systems are backed up as a complete system, through processes such as imaging, to enable the quick recovery of an entire system.
Authority Document
Mapped Processes (1)
Test Data on Backup Media
SNow
Reference: Backup / Recovery System
Test data integrity on backup media on a regular basis by performing a data restoration process to ensure that the backup is properly working.
Authority Document
Mapped Processes (1)
Boundary Defense
SNow
Reference: Boundary Defense
Detect/prevent/correct the flow of information transferring networks of different trust levels with a focus on security-damaging data.
Authority Document
SNow Control Objectives (1)
Continuous Vulnerability Management
SNow
Reference: Correct or mitigate vulnerabilities.
Continuously acquire, assess, and take action on new information in order to identify vulnerabilities, remediate, and minimize the window of opportunity for attackers.
Authority Document
SNow Control Objectives (1)
Enable DNS Query Logging
SNow
Reference: DNS Domain Filtering System
This is a great passive way to monitor for malware in an environment. these sensors can log all of these queries without having to pull them off of the endpoint. Looking for new DNS queries and those that look to be computer-generated will be quick wins in terms of hunting out malware infections.
Authority Document
SNow Control Objectives (1)
Use of DNS Filtering Services
SNow
Reference: DNS Domain Filtering System
Use DNS filtering services to help block access to known malicious domains.
Authority Document
Maintain an Inventory of Sensitive Information
SNow
Reference: Data Inventory / Classification System
Maintain an inventory of all sensitive information stored, processed, or transmitted by the organization's technology systems, including those located onsite or at a remote service provider.
Authority Document
Mapped Processes (1)
Remove Sensitive Data or Systems Not Regularly Accessed by Organization
SNow
Reference: Data Inventory / Classification System
Remove sensitive data or systems not regularly accessed by the organization from the network. These systems shall only be used as stand alone systems (disconnected from the network) by the business unit needing to occasionally use the system or completely virtualized and powered off until needed.
Authority Document
Mapped Processes (2)
Utilize an Active Discovery Tool to Identify Sensitive Data
SNow
Reference: Data Inventory / Classification System
Utilize an active discovery tool to identify all sensitive information stored, processed, or transmitted by the organization's technology systems, including those located onsite or at a remote service provider and update the organization's sensitive information inventory.
Authority Document
Manage Network Infrastructure Through a Dedicated Network
SNow
Reference: Dedicated Administration Systems
Manage the network infrastructure across network connections that are separated from the business use of that network, relying on separate VLANs or, preferably, on entirely different physical connectivity for management sessions for network devices.
Authority Document
Use Dedicated Machines For All Network Administrative Tasks
SNow
Reference: Dedicated Administration Systems
Ensure network engineers use a dedicated machine for all administrative tasks or tasks requiring elevated access. This machine shall be segmented from the organization's primary network and not be allowed Internet access. This machine shall not be used for reading e-mail, composing documents, or sur
Authority Document
Use of Dedicated Machines For All Administrative Tasks
SNow
Reference: Dedicated Administration Systems
Ensure administrators use a dedicated machine for all administrative tasks or tasks requiring administrative access. This machine will be segmented from the organization's primary network and not be allowed Internet access. This machine will not be used for reading e-mail, composing documents, or br
Authority Document
Centralize Anti-malware Logging
SNow
Reference: Endpoint Protection System
The important aspect of this requirement is getting the logs off of the endpoint so a malware infection doesnt clear them out.
Authority Document
Configure Anti-Malware Scanning of Removable Devices
SNow
Reference: Endpoint Protection System
Most AVs have this capability turned on by default, but its still important to verify that its actually still enabled. Malware coming in via a USB stick is a viable attack vector for nearly every organization.
Authority Document
Encrypt Data on USB Storage Devices
SNow
Reference: Endpoint Protection System
Provide the training to employees so they are aware of the risks of data on USB drives. Then provide them with the tools to secure your organizations critical data.
Authority Document
Ensure Anti-Malware Software and Signatures are Updated
SNow
Reference: Endpoint Protection System
The AV is only as good as its signatures. While pure signature-based detection is no longer viable, even anomaly-based engines need to be updated on a regular basis. Ensure that the updates are rolled out automatically and use tools to verify that the signatures are actually up-to-date
Authority Document
SNow Control Objectives (1)
Mapped Processes (1)
Malware Defenses
SNow
Reference: Endpoint Protection System
Install AV and run updates regularly. This has been ingrained in IT professionals for decades. The only key aspects is to make sure the AV solution meets the needs of your organization in terms of capabilities.
Authority Document
Mapped Processes (1)
Manage System's External Removable Media's Read/write Configurations
SNow
Reference: Endpoint Protection System
Configure systems not to write data to external removable media, if there is no business need for supporting such devices.
Authority Document
Manage USB Devices
SNow
Reference: Endpoint Protection System
If USB storage devices are required, enterprise software should be used that can configure systems to allow the use of specific devices. An inventory of such devices should be maintained.
Authority Document
Utilize Centrally Managed Anti-malware Software
SNow
Reference: Endpoint Protection System
Any enterprise class AV software will have this capability. By having a centrally managed AV, you can easily enable individual requirements.
Authority Document
Encrypt Sensitive Information at Rest
SNow
Reference: Host Based Data Loss Prevention (DLP) System
Encrypt all sensitive information at rest using a tool that requires a secondary authentication mechanism not integrated into the operating system, in order to access the information.
Authority Document
SNow Control Objectives (1)
Mapped Processes (2)
Enforce Access Control to Data through Automated Tools
SNow
Reference: Host Based Data Loss Prevention (DLP) System
Use an automated tool, such as host-based Data Loss Prevention, to enforce access controls to data even when data is copied off a system.
Authority Document
Mapped Processes (1)
Apply Host-based Firewalls or Port Filtering
SNow
Reference: Host Based Firewall
Apply host-based firewalls or port filtering tools on end systems, with a default-deny rule that drops all traffic except those services and ports that are explicitly allowed.
Authority Document
Account Monitoring and Control
SNow
Reference: Identity & Access Management System
Actively manage the life cycle of system and application accounts - their creation, use, dormancy, deletion - in order to minimize opportunities for attackers to leverage them.
Authority Document
Configure Centralized Point of Authentication
SNow
Reference: Identity & Access Management System
Configure access for all accounts through as few centralized points of authentication as possible, including network, security, and cloud systems.
Authority Document
Disable Any Unassociated Accounts
SNow
Reference: Identity & Access Management System
Disable any account that cannot be associated with a business process or business owner.
Authority Document
SNow Control Objectives (1)
Mapped Processes (1)
Disable Dormant Accounts
SNow
Reference: Identity & Access Management System
Automatically disable dormant accounts after a set period of inactivity.
Authority Document
Encrypt Transmittal of Username and Authentication Credentials
SNow
Reference: Identity & Access Management System
Ensure that all account usernames and authentication credentials are transmitted across networks using encrypted channels.
Authority Document
Mapped Processes (1)
Encrypt or Hash all Authentication Credentials
SNow
Reference: Identity & Access Management System
Encrypt or hash with a salt all authentication credentials when stored.
Authority Document
Ensure All Accounts Have An Expiration Date
SNow
Reference: Identity & Access Management System
Ensure that all accounts have an expiration date that is monitored and enforced.
Authority Document
SNow Control Objectives (1)
Mapped Processes (1)
Establish Process for Revoking Access
SNow
Reference: Identity & Access Management System
Establish and follow an automated process for revoking system access by disabling accounts immediately upon termination or change of responsibilities of an employee or contractor . Disabling these accounts, instead of deleting accounts, allows preservation of audit trails.
Authority Document
Lock Workstation Sessions After Inactivity
SNow
Reference: Identity & Access Management System
Automatically lock workstation sessions after a standard period of inactivity.
Authority Document
Mapped Processes (1)
Maintain an Inventory of Accounts
SNow
Reference: Identity & Access Management System
Maintain an inventory of all accounts organized by authentication system.
Authority Document
Mapped Processes (1)
Maintain an Inventory of Authentication Systems
SNow
Reference: Identity & Access Management System
Maintain an inventory of each of the organization's authentication systems, including those located onsite or at a remote service provider.
Authority Document
Mapped Processes (1)
Assign Job Titles and Duties for Incident Response
SNow
Reference: Incident Management Plans
Assign job titles and duties for handling computer and network incidents to specific individuals and ensure tracking and documentation throughout the incident through resolution.
Authority Document
SNow Control Objectives (1)
Conduct Periodic Incident Scenario Sessions for Personnel
SNow
Reference: Incident Management Plans
Plan and conduct routine incident response exercises and scenarios for the workforce involved in the incident response to maintain awareness and comfort in responding to real world threats. Exercises should test communication channels, decision making, and incident responders technical capabilities
Authority Document
Mapped Processes (2)
Create Incident Scoring and Prioritization Schema
SNow
Reference: Incident Management Plans
Create incident scoring and prioritization schema based on known or potential impact to your organization. Utilize score to define frequency of status updates and escalation procedures.
Authority Document
SNow Control Objectives (1)
Mapped Processes (2)
Designate Management Personnel to Support Incident Handling
SNow
Reference: Incident Management Plans
Designate management personnel, as well as backups, who will support the incident handling process by acting in key decision-making roles.
Authority Document
Mapped Processes (2)
Devise Organization-wide Standards for Reporting Incidents
SNow
Reference: Incident Management Plans
Devise organization-wide standards for the time required for system administrators and other workforce members to report anomalous events to the incident handling team, the mechanisms for such reporting, and the kind of information that should be included in the incident notification.
Authority Document
SNow Control Objectives (1)
Mapped Processes (2)
Document Incident Response Procedures
SNow
Reference: Incident Management Plans
Ensure that there are written incident response plans that defines roles of personnel as well as phases of incident handling/management.
Authority Document
SNow Control Objectives (1)
Mapped Processes (2)
Incident Response and Management
SNow
Reference: Incident Management Plans
Protect the organization's information, as well as its reputation, by developing and implementing an incident response infrastructure (e.g., plans, defined roles, training, communications, management oversight) for quickly discovering an attack and then effectively containing the damage, eradicating
Authority Document
Mapped Processes (2)
Maintain Contact Information For Reporting Security Incidents
SNow
Reference: Incident Management Plans
Assemble and maintain information on third-party contact information to be used to report a security incident, such as Law Enforcement, relevant government departments, vendors, and ISAC partners.
Authority Document
Mapped Processes (2)
Publish Information Regarding Reporting Computer Anomalies and Incidents
SNow
Reference: Incident Management Plans
Publish information for all workforce members, regarding reporting computer anomalies and incidents to the incident handling team. Such information should be included in routine employee awareness activities.
Authority Document
Mapped Processes (2)
Activate audit logging
SNow
Reference: Log Management System / SIEM
Ensure that local logging has been enabled on all systems and networking devices.
Authority Document
Mapped Processes (2)
Alert on Account Login Behavior Deviation
SNow
Reference: Log Management System / SIEM
Alert when users deviate from normal login behavior, such as time-of-day, workstation location and duration.
Authority Document
SNow Control Objectives (1)
Mapped Processes (2)
Central Log Management
SNow
Reference: Log Management System / SIEM
Ensure that appropriate logs are being aggregated to a central log management system for analysis and review.
Authority Document
SNow Control Objectives (1)
Mapped Processes (1)
Deploy SIEM or Log Analytic tool
SNow
Reference: Log Management System / SIEM
Deploy Security Information and Event Management (SIEM) or log analytic tool for log correlation and analysis.
Authority Document
SNow Control Objectives (1)
Enable Command-line Audit Logging
SNow
Reference: Log Management System / SIEM
On high interaction systems, this can be quite noisy. From a forensics standpoint, it will be quite valuable.
Authority Document
SNow Control Objectives (1)
Enable Detailed Logging
SNow
Reference: Log Management System / SIEM
Enable system logging to include detailed information such as a event source, date, user, timestamp, source addresses, destination addresses, and other useful elements.
Authority Document
SNow Control Objectives (1)
Mapped Processes (1)
Enforce Detail Logging for Access or Changes to Sensitive Data
SNow
Reference: Log Management System / SIEM
Enforce detailed audit logging for access to sensitive data or changes to sensitive data (utilizing tools such as File Integrity Monitoring or Security Information and Event Monitoring).
Authority Document
SNow Control Objectives (1)
Mapped Processes (1)
Ensure adequate storage for logs
SNow
Reference: Log Management System / SIEM
Ensure that all systems that store logs have adequate storage space for the logs generated.
Authority Document
SNow Control Objectives (1)
Log all URL requests
SNow
Reference: Log Management System / SIEM
Log all URL requests from each of the organization's systems, whether onsite or a mobile device, in order to identify potentially malicious activity and assist incident handlers with identifying potentially compromised systems.
Authority Document
Log and Alert on Changes to Administrative Group Membership
SNow
Reference: Log Management System / SIEM
Configure systems to issue a log entry and alert when an account is added to or removed from any group assigned administrative privileges.
Authority Document
Mapped Processes (1)
Log and Alert on Unsuccessful Administrative Account Login
SNow
Reference: Log Management System / SIEM
Configure systems to issue a log entry and alert on unsuccessful logins to an administrative account.
Authority Document
Mapped Processes (1)
Monitor Attempts to Access Deactivated Accounts
SNow
Reference: Log Management System / SIEM
Monitor attempts to access deactivated accounts through audit logging.
Authority Document
Regularly Review Logs
SNow
Reference: Log Management System / SIEM
On a regular basis, review logs to identify anomalies or abnormal events.
Authority Document
Mapped Processes (2)
Regularly Tune SIEM
SNow
Reference: Log Management System / SIEM
On a regular basis, tune your SIEM system to better identify actionable events and decrease event noise.
Authority Document
Use DHCP Logging to Update Asset Inventory
SNow
Reference: Log Management System / SIEM
Use Dynamic Host Configuration Protocol (DHCP) logging on all DHCP servers or IP address management tools to update the organization's hardware asset inventory.
Authority Document
Mapped Processes (1)
Maintenance, Monitoring and Analysis of Audit Logs
SNow
Reference: Logging and Auditing
Collect, manage, and analyze audit logs of events that could help detect, understand, or recover from an attack.
Authority Document
Mapped Processes (2)
Manage Network Devices Using Multi-Factor Authentication and Encrypted Sessions
SNow
Reference: Multi-Factor Authentication System
Manage all network devices using multi-factor authentication and encrypted sessions.
Authority Document
Require All Remote Login to Use Multi-factor Authentication
SNow
Reference: Multi-Factor Authentication System
Require all remote login access to the organization's network to encrypt data in transit and use multi-factor authentication.
Authority Document
Mapped Processes (1)
Require Multi-factor Authentication
SNow
Reference: Multi-Factor Authentication System
Require multi-factor authentication for all user accounts, on all systems, whether managed onsite or by a third-party provider.
Authority Document
Mapped Processes (1)
Use Multifactor Authentication For All Administrative Access
SNow
Reference: Multi-Factor Authentication System
Use multi-factor authentication and encrypted channels for all administrative account access.
Authority Document
Monitor and Block Unauthorized Network Traffic
SNow
Reference: Network Based Data Loss Prevention (DLP) System
Deploy an automated tool on network perimeters that monitors for unauthorized transfer of sensitive information and blocks such transfers while alerting information security professionals.
Authority Document
Monitor and Detect Any Unauthorized Use of Encryption
SNow
Reference: Network Based Data Loss Prevention (DLP) System
Monitor all traffic leaving the organization and detect any unauthorized use of encryption.
Authority Document
Deploy Network-based IDS Sensor
SNow
Reference: Network Based Intrusion Detection System (NIDS)
Deploy network-based Intrusion Detection Systems (IDS) sensors to look for unusual attack mechanisms and detect compromise of these systems at each of the organization's network boundaries.
Authority Document
Deploy Network-Based Intrusion Prevention Systems
SNow
Reference: Network Based Intrusion Prevention System (IPS)
Deploy network-based Intrusion Prevention Systems (IPS) to block malicious network traffic at each of the organization's network boundaries.
Authority Document
Create Separate Wireless Network for Personal and Untrusted Devices
SNow
Reference: Network Device Management System
Create a separate wireless network for personal or untrusted devices. Enterprise access from this network should be treated as untrusted and filtered and audited accordingly.
Authority Document
SNow Control Objectives (1)
Deploy NetFlow Collection on Networking Boundary Devices
SNow
Reference: Network Device Management System
Enable the collection of NetFlow and logging data on all network boundary devices.
Authority Document
SNow Control Objectives (1)
Document Traffic Configuration Rules
SNow
Reference: Network Device Management System
All configuration rules that allow traffic to flow through network devices should be documented in a configuration management system with a specific business reason for each rule, a specific individuals name responsible for that business need, and an expected duration of the need.
Authority Document
Mapped Processes (1)
Leverage the Advanced Encryption Standard (AES) to Encrypt Wireless Data
SNow
Reference: Network Device Management System
Leverage the Advanced Encryption Standard (AES) to encrypt wireless data in transit.
Authority Document
Maintain Standard Security Configurations for Network Devices
SNow
Reference: Network Device Management System
Maintain standard, documented security configuration standards for all authorized network devices.
Authority Document
Mapped Processes (2)
Maintain an Inventory of Authorized Wireless Access Points
SNow
Reference: Network Device Management System
Maintain an inventory of authorized wireless access points connected to the wired network.
Authority Document
Secure Configuration for Network Devices, such as Firewalls, Routers and Switches
SNow
Reference: Network Device Management System
Establish, implement, and actively manage (track, report on, correct) the security configuration of network infrastructure devices using a rigorous configuration management and change control process in order to prevent attackers from exploiting vulnerable services and settings.
Authority Document
Use Automated Tools to Verify Standard Device Configurations and Detect Changes
SNow
Reference: Network Device Management System
Compare all network device configuration against approved security configurations defined for each network device in use and alert when any deviations are discovered.
Authority Document
Mapped Processes (1)
Use Wireless Authentication Protocols that Require Mutual, Multi-Factor Authentication
SNow
Reference: Network Device Management System
Ensure that wireless networks use authentication protocols such as Extensible Authentication Protocol-Transport Layer Security (EAP/TLS), that requires mutual, multi-factor authentication.
Authority Document
Wireless Access Control
SNow
Reference: Network Device Management System
The processes and tools used to track/control/prevent/correct the security use of wireless local area networks (WLANs), access points, and wireless client systems.
Authority Document
Decrypt Network Traffic at Proxy
SNow
Reference: Network Firewall / Access Control System
Decrypt all encrypted network traffic at the boundary proxy prior to analyzing the content. However, the organization may use whitelists of allowed sites that can be accessed through the proxy without decrypting the traffic.
Authority Document
SNow Control Objectives (1)
Deny Communication over Unauthorized Ports
SNow
Reference: Network Firewall / Access Control System
Deny communication over unauthorized TCP or UDP ports or application traffic to ensure that only authorized protocols are allowed to cross the network boundary in or out of the network at each of the organization's network boundaries.
Authority Document
Deny Communications with Known Malicious IP Addresses
SNow
Reference: Network Firewall / Access Control System
Deny communications with known malicious or unused Internet IP addresses and limit access only to trusted and necessary IP address ranges at each of the organization's network boundaries,.
Authority Document
SNow Control Objectives (1)
Deploy Application Layer Filtering Proxy Server
SNow
Reference: Network Firewall / Access Control System
Ensure that all network traffic to or from the Internet passes through an authenticated application layer proxy that is configured to filter unauthorized connections.
Authority Document
Disable Workstation to Workstation Communication
SNow
Reference: Network Firewall / Access Control System
Disable all workstation to workstation communication to limit an attacker's ability to move laterally and compromise neighboring systems, through technologies such as Private VLANs or microsegmentation.
Authority Document
SNow Control Objectives (1)
Enable Firewall Filtering Between VLANs
SNow
Reference: Network Firewall / Access Control System
Enable firewall filtering between VLANs to ensure that only authorized systems are able to communicate with other systems necessary to fulfill their specific responsibilities.
Authority Document
SNow Control Objectives (1)
Maintain an Inventory of Network Boundaries
SNow
Reference: Network Firewall / Access Control System
Maintain an up-to-date inventory of all of the organization's network boundaries.
Authority Document
Mapped Processes (1)
Only Allow Access to Authorized Cloud Storage or Email Providers
SNow
Reference: Network Firewall / Access Control System
Only allow access to authorized cloud storage or email providers.
Authority Document
Physically or Logically Segregate High Risk Applications
SNow
Reference: Network Firewall / Access Control System
Physically or logically segregated systems should be used to isolate and run software that is required for business operations but incur higher risk for the organization.
Authority Document
Mapped Processes (1)
Segment the Network Based on Sensitivity
SNow
Reference: Network Firewall / Access Control System
Segment the network based on the label or classification level of the information stored on the servers, locate all sensitive information on separated Virtual Local Area Networks (VLANs).
Authority Document
Mapped Processes (1)
Deploy Port Level Access Control
SNow
Reference: Network Level Authentication (NLA)
Utilize port level access control, following 802.1x standards, to control which devices can authenticate to the network. The authentication system shall be tied into the hardware asset inventory data to ensure only authorized devices can connect to the network.
Authority Document
SNow Control Objectives (1)
Configure Monitoring Systems to Record Network Packets
SNow
Reference: Network Packet Capture System
Configure monitoring systems to record network packets passing through the boundary at each of the organization's network boundaries.
Authority Document
Utilize Three Synchronized Time Sources
SNow
Reference: Network Time Protocol (NTP) Systems
Use at least three synchronized time sources from which all servers and network devices retrieve time information on a regular basis so that timestamps in logs are consistent.
Authority Document
Maintain and Enforce Network-Based URL Filters
SNow
Reference: Network URL Filtering System
Enforce network-based URL filters that limit a system's ability to connect to websites not approved by the organization. This filtering shall be enforced for each of the organization's systems, whether they are physically at an organization's facilities or not.
Authority Document
Subscribe to URL-Categorization service
SNow
Reference: Network URL Filtering System
Subscribe to URL categorization services to ensure that they are up-to-date with the most recent website category definitions available. Uncategorized sites shall be blocked by default.
Authority Document
Use a Passive Asset Discovery Tool
SNow
Reference: Passive Device Discovery System
Utilize a passive discovery tool to identify devices connected to the organization's network and automatically update the organization's hardware asset inventory.
Authority Document
Deploy Automated Operating System Patch Management Tools
SNow
Reference: Patch Management System
Deploy automated software update tools in order to ensure that the operating systems are running the most recent security updates provided by the software vendor.
Authority Document
SNow Control Objectives (1)
Deploy Automated Software Patch Management Tools
SNow
Reference: Patch Management System
Deploy automated software update tools in order to ensure that third-party software on all systems is running the most recent security updates provided by the software vendor.
Authority Document
SNow Control Objectives (1)
Mapped Processes (1)
Conduct Regular External and Internal Penetration Tests
SNow
Reference: Penetration Testing Plans
Conduct regular external and internal penetration tests to identify vulnerabilities and attack vectors that can be used to exploit enterprise systems successfully.
Authority Document
SNow Control Objectives (1)
Control and Monitor Accounts Associated with Penetration Testing
SNow
Reference: Penetration Testing Plans
Any user or system accounts used to perform penetration testing should be controlled and monitored to make sure they are only being used for legitimate purposes, and are removed or restored to normal function after testing is over.
Authority Document
Mapped Processes (1)
Create Test Bed for Elements Not Typically Tested in Production
SNow
Reference: Penetration Testing Plans
Create a test bed that mimics a production environment for specific penetration tests and Red Team attacks against elements that are not typically tested in production, such as attacks against supervisory control and data acquisition and other control systems.
Authority Document
Ensure Results from Penetration Test are Documented Using Open, Machine-readable Standards
SNow
Reference: Penetration Testing Plans
Wherever possible, ensure that Red Teams results are documented using open, machine-readable standards (e.g., SCAP). Devise a scoring method for determining the results of Red Team exercises so that results can be compared over time.
Authority Document
Mapped Processes (1)
Establish a Penetration Testing Program
SNow
Reference: Penetration Testing Plans
Establish a program for penetration tests that includes a full scope of blended attacks, such as wireless, client-based, and web application attacks.
Authority Document
Mapped Processes (1)
Include Tests for Presence of Unprotected System Information and Artifacts
SNow
Reference: Penetration Testing Plans
Include tests for the presence of unprotected system information and artifacts that would be useful to attackers, including network diagrams, configuration files, older penetration test reports, e-mails or documents containing passwords or other information critical to system operation.
Authority Document
Mapped Processes (1)
Penetration Tests and Red Team Exercises
SNow
Reference: Penetration Testing Plans
Test the overall strength of an organization's defense (the technology, the processes, and the people) by simulating the objectives and actions of an attacker.
Authority Document
Mapped Processes (1)
Perform Periodic Red Team Exercises
SNow
Reference: Penetration Testing Plans
Perform periodic Red Team exercises to test organizational readiness to identify and stop attacks or to respond quickly and effectively.
Authority Document
Mapped Processes (1)
Use Vulnerability Scanning and Penetration Testing Tools in Concert
SNow
Reference: Penetration Testing Plans
Use vulnerability scanning and penetration testing tools in concert. The results of vulnerability scanning assessments should be used as a starting point to guide and focus penetration testing efforts.
Authority Document
Mapped Processes (1)
Change Default Passwords
SNow
Reference: Privileged Account Management System
Before deploying any new asset, change all default passwords to have values consistent with administrative level accounts.
Authority Document
SNow Control Objectives (1)
Ensure the Use of Dedicated Administrative Accounts
SNow
Reference: Privileged Account Management System
Ensure that all users with administrative account access use a dedicated or secondary account for elevated activities. This account should only be used for administrative activities and not internet browsing, email, or similar activities.
Authority Document
Mapped Processes (1)
Maintain Inventory of Administrative Accounts
SNow
Reference: Privileged Account Management System
Use automated tools to inventory all administrative accounts, including domain and local accounts, to ensure that only authorized individuals have elevated privileges.
Authority Document
Mapped Processes (1)
Use Unique Passwords
SNow
Reference: Privileged Account Management System
Where multi-factor authentication is not supported (such as local administrator, root, or service accounts), accounts will use passwords that are unique to that system.
Authority Document
Mapped Processes (1)
Utilize Client Certificates to Authenticate Hardware Assets
SNow
Reference: Public Key Infrastructure (PKI)
Use client certificates to authenticate hardware assets connecting to the organization's trusted network.
Authority Document
Associate Active Ports, Services and Protocols to Asset Inventory
SNow
Reference: SCAP Based Vulnerability Management System
Associate active ports, services and protocols to the hardware assets in the asset inventory.
Authority Document
Mapped Processes (2)
Compare Back-to-back Vulnerability Scans
SNow
Reference: SCAP Based Vulnerability Management System
Regularly compare the results from back-to-back vulnerability scans to verify that vulnerabilities have been remediated in a timely manner.
Authority Document
SNow Control Objectives (1)
Mapped Processes (1)
Detect Wireless Access Points Connected to the Wired Network
SNow
Reference: SCAP Based Vulnerability Management System
Configure network vulnerability scanning tools to detect and alert on unauthorized wireless access points connected to the wired network.
Authority Document
SNow Control Objectives (1)
Ensure Only Approved Ports, Protocols and Services Are Running
SNow
Reference: SCAP Based Vulnerability Management System
Ensure that only network ports, protocols, and services listening on a system with validated business needs, are running on each system.
Authority Document
SNow Control Objectives (1)
Mapped Processes (1)
Implement Automated Configuration Monitoring Systems
SNow
Reference: SCAP Based Vulnerability Management System
Utilize a Security Content Automation Protocol (SCAP) compliant configuration monitoring system to verify all security configuration elements, catalog approved exceptions, and alert when unauthorized changes occur.
Authority Document
Mapped Processes (2)
Perform Authenticated Vulnerability Scanning
SNow
Reference: SCAP Based Vulnerability Management System
Perform authenticated vulnerability scanning with agents running locally on each system or with remote scanners that are configured with elevated rights on the system being tested.
Authority Document
Perform Regular Automated Port Scans
SNow
Reference: SCAP Based Vulnerability Management System
Perform automated port scans on a regular basis against all systems and alert if unauthorized ports are detected on a system.
Authority Document
Protect Dedicated Assessment Accounts
SNow
Reference: SCAP Based Vulnerability Management System
Use a dedicated account for authenticated vulnerability scans, which should not be used for any other administrative activities and should be tied to specific machines at specific IP addresses.
Authority Document
Run Automated Vulnerability Scanning Tools
SNow
Reference: SCAP Based Vulnerability Management System
Utilize an up-to-date SCAP-compliant vulnerability scanning tool to automatically scan all systems on the network on a weekly or more frequent basis to identify all potential vulnerabilities on the organization's systems.
Authority Document
Utilize a Risk-rating Process
SNow
Reference: SCAP Based Vulnerability Management System
Utilize a risk-rating process to prioritize the remediation of discovered vulnerabilities.
Authority Document
Application Software Security
SNow
Reference: Secure Coding Standards
Manage the security life cycle of all in-house developed and acquired software in order to prevent, detect, and correct security weaknesses.
Authority Document
SNow Control Objectives (1)
Ensure Explicit Error Checking is Performed for All In-house Developed Software
SNow
Reference: Secure Coding Standards
For in-house developed software, ensure that explicit error checking is performed and documented for all input, including for size, data type, and acceptable ranges or formats.
Authority Document
SNow Control Objectives (1)
Mapped Processes (1)
Establish Secure Coding Practices
SNow
Reference: Secure Coding Standards
Establish secure coding practices appropriate to the programming language and development environment being used.
Authority Document
Mapped Processes (1)
Only Use Up-to-date And Trusted Third-Party Components
SNow
Reference: Secure Coding Standards
Only use up-to-date and trusted third-party components for the software developed by the organization.
Authority Document
Separate Production and Non-Production Systems
SNow
Reference: Secure Coding Standards
Maintain separate environments for production and nonproduction systems. Developers should not have unmonitored access to production environments.
Authority Document
Use Only Standardized and Extensively Reviewed Encryption Algorithms
SNow
Reference: Secure Coding Standards
Use only standardized and extensively reviewed encryption algorithms.
Authority Document
Verify That Acquired Software is Still Supported
SNow
Reference: Secure Coding Standards
Verify that the version of all software acquired from outside your organization is still supported by the developer or appropriately hardened based on developer security recommendations.
Authority Document
Secure Configuration for Hardware and Software on Mobile Devices, Laptops, Workstations and Servers
SNow
Reference: Secure Configuration
Establish, implement, and actively manage (track, report on, correct) the security configuration of mobile devices, laptops, servers, and workstations using a rigorous configuration management and change control process in order to prevent attackers from exploiting vulnerable services and settings.
Authority Document
Address unapproved software
SNow
Reference: Software Application Inventory
Ensure that unauthorized software is either removed or the inventory is updated in a timely manner.
Authority Document
SNow Control Objectives (1)
Mapped Processes (2)
Ensure Software is Supported by Vendor
SNow
Reference: Software Application Inventory
Ensure that only software applications or operating systems currently supported by the software's vendor are added to the organization's authorized software inventory. Unsupported software should be tagged as unsupported in the inventory system.
Authority Document
SNow Control Objectives (1)
Mapped Processes (2)
Integrate Software and Hardware Asset Inventories
SNow
Reference: Software Application Inventory
The software inventory system should be tied into the hardware asset inventory so all devices and associated software are tracked from a single location.
Authority Document
Mapped Processes (2)
Maintain Inventory of Authorized Software
SNow
Reference: Software Application Inventory
Maintain an up-to-date list of all authorized software that is required in the enterprise for any business purpose on any business system.
Authority Document
Mapped Processes (1)
Track Software Inventory Information
SNow
Reference: Software Application Inventory
The software inventory system should track the name, version, publisher, and install date for all software, including operating systems authorized by the organization.
Authority Document
Mapped Processes (2)
Utilize Software Inventory Tools
SNow
Reference: Software Application Inventory
Utilize software inventory tools throughout the organization to automate the documentation of all software on business systems.
Authority Document
Mapped Processes (1)
Apply Static and Dynamic Code Analysis Tools
SNow
Reference: Software Vulnerability Scanning Tool
Apply static and dynamic analysis tools to verify that secure coding practices are being adhered to for internally developed software.
Authority Document
SNow Control Objectives (1)
Establish a Process to Accept and Address Reports of Software Vulnerabilities
SNow
Reference: Software Vulnerability Scanning Tool
Establish a process to accept and address reports of software vulnerabilities, including providing a means for external entities to contact your security group.
Authority Document
Mapped Processes (2)
Disable Unnecessary or Unauthorized Browser or Email Client Plugins
SNow
Reference: Software Whitelisting System
Uninstall or disable any unauthorized browser or email client plugins or add-on applications.
Authority Document
SNow Control Objectives (1)
Ensure Use of Only Fully Supported Browsers and Email Clients
SNow
Reference: Software Whitelisting System
Ensure that only fully supported web browsers and email clients are allowed to execute in the organization, ideally only using the latest version of the browsers and email clients provided by the vendor.
Authority Document
Implement Application Whitelisting of Libraries
SNow
Reference: Software Whitelisting System
The organization's application whitelisting software must ensure that only authorized software libraries (such as *.dll, *.ocx, *.so, etc) are allowed to load into a system process.
Authority Document
Implement Application Whitelisting of Scripts
SNow
Reference: Software Whitelisting System
The organization's application whitelisting software must ensure that only authorized, digitally signed scripts (such as *.ps1, *.py, macros, etc) are allowed to run on a system.
Authority Document
Limit Access to Script Tools
SNow
Reference: Software Whitelisting System
Limit access to scripting tools (such as Microsoft PowerShell and Python) to only administrative or development users with the need to access those capabilities.
Authority Document
Utilize Application Whitelisting
SNow
Reference: Software Whitelisting System
Utilize application whitelisting technology on all assets to ensure that only authorized software executes and all unauthorized software is blocked from executing on assets.
Authority Document
Establish Secure Configurations
SNow
Reference: System Configuration Baselines & Images
Maintain documented, standard security configuration standards for all authorized operating systems and software.
Authority Document
Mapped Processes (2)
Maintain Secure Images
SNow
Reference: System Configuration Baselines & Images
Maintain secure images or templates for all systems in the enterprise based on the organization's approved configuration standards. Any new system deployment or existing system that becomes compromised should be imaged using one of those images or templates.
Authority Document
Mapped Processes (1)
Securely Store Master Images
SNow
Reference: System Configuration Baselines & Images
Store the master images and templates on securely configured servers, validated with integrity monitoring tools, to ensure that only authorized changes to the images are possible.
Authority Document
Configure Devices Not To Auto-run Content
SNow
Reference: System Configuration Enforcement System
For the same reason why you do not want to scan it, you also dont want it to run when its mounted. This is a pretty quick setting to enable, and both CIS and DISA hardening guides have step-by-step instructions on disabling auto-run. Some SCM tools can quickly check every endpoint in your environm
Authority Document
SNow Control Objectives (1)
Deploy System Configuration Management Tools
SNow
Reference: System Configuration Enforcement System
Deploy system configuration management tools that will automatically enforce and redeploy configuration settings to systems at regularly scheduled intervals.
Authority Document
SNow Control Objectives (1)
Mapped Processes (2)
Disable Peer-to-peer Wireless Network Capabilities on Wireless Clients
SNow
Reference: System Configuration Enforcement System
Disable peer-to-peer (adhoc) wireless network capabilities on wireless clients.
Authority Document
Disable Wireless Access on Devices if Not Required
SNow
Reference: System Configuration Enforcement System
Disable wireless access on devices that do not have a business purpose for wireless access.
Authority Document
Disable Wireless Peripheral Access of Devices
SNow
Reference: System Configuration Enforcement System
Disable wireless peripheral access of devices (such as Bluetooth and NFC), unless such access is required for a business purpose.
Authority Document
SNow Control Objectives (1)
Enable Operating System Anti-Exploitation Features/ Deploy Anti-Exploit Technologies
SNow
Reference: System Configuration Enforcement System
The DISA hardening guides provide step-by-step instructions on enabling these settings and so much more.
Authority Document
SNow Control Objectives (1)
Encrypt All Sensitive Information in Transit
SNow
Reference: System Configuration Enforcement System
Encrypt all sensitive information in transit.
Authority Document
SNow Control Objectives (1)
Mapped Processes (1)
Limit Use of Scripting Languages in Web Browsers and Email Clients
SNow
Reference: System Configuration Enforcement System
Ensure that only authorized scripting languages are able to run in all web browsers and email clients.
Authority Document
Limit Wireless Access on Client Devices
SNow
Reference: System Configuration Enforcement System
Configure wireless access on client machines that do have an essential wireless business purpose, to allow access only to authorized wireless networks and to restrict access to other wireless networks.
Authority Document
Manage All Devices Remotely Logging into Internal Network
SNow
Reference: System Configuration Enforcement System
Scan all enterprise devices remotely logging into the organization's network prior to accessing the network to ensure that each of the organization's security policies has been enforced in the same manner as local network devices.
Authority Document
Protect Information through Access Control Lists
SNow
Reference: System Configuration Enforcement System
Protect all information stored on systems with file system, network share, claims, application, or database specific access control lists. These controls will enforce the principle that only authorized individuals should have access to the information based on their need to access the information as
Authority Document
Mapped Processes (1)
Scan for Unauthorized Connections across Trusted Network Boundaries
SNow
Reference: System Configuration Enforcement System
Perform regular scans from outside each trusted network boundary to detect any unauthorized connections which are accessible across the boundary.
Authority Document
Use Standard Hardening Configuration Templates for Databases
SNow
Reference: System Configuration Enforcement System
For applications that rely on a database, use standard hardening configuration templates. All systems that are part of critical business processes should also be tested.
Authority Document
Mapped Processes (1)
Deliver Training to Fill the Skills Gap
SNow
Reference: Training / Awareness Education Plans
Deliver training to address the skills gap identified to positively impact workforce members' security behavior.
Authority Document
Mapped Processes (1)
Ensure Software Development Personnel are Trained in Secure Coding
SNow
Reference: Training / Awareness Education Plans
Ensure that all software development personnel receive training in writing secure code for their specific development environment and responsibilities.
Authority Document
SNow Control Objectives (1)
Mapped Processes (2)
Implement a Security Awareness Program
SNow
Reference: Training / Awareness Education Plans
Create a security awareness program for all workforce members to complete on a regular basis to ensure they understand and exhibit the necessary behaviors and skills to help ensure the security of the organization. The organization's security awareness program should be communicated in a continuous
Authority Document
Mapped Processes (1)
Implement a Security Awareness and Training Program
SNow
Reference: Training / Awareness Education Plans
For all functional roles in the organization (prioritizing those mission-critical to the business and its security), identify the specific knowledge, skills, and abilities needed to support defense of the enterprise; develop and execute an integrated plan to assess, identify gaps, and remediate thro
Authority Document
Mapped Processes (1)
Perform a Skills Gap Analysis
SNow
Reference: Training / Awareness Education Plans
Perform a skills gap analysis to understand the skills and behaviors workforce members are not adhering to, using this information to build a baseline education roadmap.
Authority Document
Mapped Processes (1)
Train Workforce Members on Identifying and Reporting Incidents
SNow
Reference: Training / Awareness Education Plans
Train employees to be able to identify the most common indicators of an incident and be able to report such an incident.
Authority Document
Mapped Processes (1)
Train Workforce on Causes of Unintentional Data Exposure
SNow
Reference: Training / Awareness Education Plans
Train workforce members to be aware of causes for unintentional data exposures, such as losing their mobile devices or emailing the wrong person due to autocomplete in email.
Authority Document
Mapped Processes (1)
Train Workforce on Identifying Social Engineering Attacks
SNow
Reference: Training / Awareness Education Plans
Train the workforce on how to identify different forms of social engineering attacks, such as phishing, phone scams and impersonation calls.
Authority Document
Mapped Processes (1)
Train Workforce on Secure Authentication
SNow
Reference: Training / Awareness Education Plans
Train workforce members on the importance of enabling and utilizing secure authentication.
Authority Document
Mapped Processes (1)
Train Workforce on Sensitive Data Handling
SNow
Reference: Training / Awareness Education Plans
Train workforce on how to identify and properly store, transfer, archive and destroy sensitive information.
Authority Document
Mapped Processes (1)
Update Awareness Content Frequently
SNow
Reference: Training / Awareness Education Plans
Ensure that the organization's security awareness program is updated frequently (at least annually) to address new technologies, threats, standards and business requirements.
Authority Document
Mapped Processes (1)
Inventory and Control of Hardware Assets
SNow
Reference: Unauthorized Hardware
Actively manage (inventory, track, and correct) all hardware devices on the network so that only authorized devices are given access, and unauthorized and unmanaged devices are found and prevented from gaining access.
Authority Document
Mapped Processes (2)
Inventory and Control of Software Assets
SNow
Reference: Unauthorized Software
Actively manage (inventory, track, and correct) all software on the network so that only authorized software is installed and can execute, and that unauthorized and unmanaged software is found and prevented from installation or execution.
Authority Document
Mapped Processes (1)
Deploy Web Application Firewalls (WAFs)
SNow
Reference: Web Application Firewall (WAF)
Protect web applications by deploying web application firewalls (WAFs) that inspect all traffic flowing to the web application for common web application attacks. For applications that are not web-based, specific application firewalls should be deployed if such tools are available for the given appl
Authority Document
Encrypt the Hard Drive of All Mobile Devices.
SNow
Reference: Whole Disk Encryption System
Utilize approved whole disk encryption software to encrypt the hard drive of all mobile devices.
Authority Document
Use a Wireless Intrusion Detection System
SNow
Reference: Wireless Intrusion Detection System (WIDS)
Use a wireless intrusion detection system (WIDS) to detect and alert on unauthorized wireless access points connected to the network.
Authority Document