Control Objectives: Data
No control objectives match the current filters.
11.1 Establish and Maintain a Data Recovery Process
SNow
Classification: RespondState: Published
Establish and maintain a data recovery process. In the process, address the scope of data recovery activities, recovery prioritization, and the security of backup data. Review and update documentation annually, or when significant enterprise changes occur that could impact this Safeguard.
Parent
11.2 Perform Automated Backups
SNow
Classification: RespondState: Published
Perform automated backups of in-scope enterprise assets. Run backups weekly, or more frequently, based on the sensitivity of the data.
Parent
11.3 Protect Recovery Data
SNow
Classification: ProtectState: Published
Protect recovery data with equivalent controls to the original data. Reference encryption or data separation, based on requirements.
Parent
11.4 Establish and Maintain an Isolated Instance of Recovery Data
SNow
Classification: RespondState: Published
Establish and maintain an isolated instance of recovery data. Example implementations include, version controlling backup destinations through offline, cloud, or off-site systems or services.
Parent
11.5 Test Data Recovery
SNow
Classification: RespondState: Published
Test backup recovery quarterly, or more frequently, for a sampling of in-scope enterprise assets.
Parent
15.6 Monitor Service Providers
SNow
Classification: DetectState: Published
Monitor service providers consistent with the enterprises service provider management policy. Monitoring may include periodic reassessment of service provider compliance, monitoring service provider release notes, and dark web monitoring.
15.7 Securely Decommission Service Providers
SNow
Classification: ProtectState: Published
Securely decommission service providers. Example considerations include user and service account deactivation, termination of data flows, and secure disposal of enterprise data within service provider systems.
3.1 Establish and Maintain a Data Management Process
SNow
Classification: IdentifyState: Published
Establish and maintain a data management process. In the process, address data sensitivity, data owner, handling of data, data retention limits, and disposal requirements, based on sensitivity and retention standards for the enterprise. Review and update documentation annually, or when significant e
Parent
3.10 Encrypt Sensitive Data in Transit
SNow
Classification: ProtectState: Published
Encrypt sensitive data in transit. Example implementations can include: Transport Layer Security (TLS) and Open Secure Shell (OpenSSH).
Parent
3.11 Encrypt Sensitive Data at Rest
SNow
Classification: ProtectState: Published
Encrypt sensitive data at rest on servers, applications, and databases containing sensitive data. Storage-layer encryption, also known as server-side encryption, meets the minimum requirement of this Safeguard. Additional encryption methods may include application-layer encryption, also known as cli
Parent
3.13 Deploy a Data Loss Prevention Solution
SNow
Classification: ProtectState: Published
Implement an automated tool, such as a host-based Data Loss Prevention (DLP) tool to identify all sensitive data stored, processed, or transmitted through enterprise assets, including those located onsite or at a remote service provider, and update the enterprise's sensitive data inventory.
Parent
3.14 Log Sensitive Data Access
SNow
Classification: DetectState: Published
Log sensitive data access, including modification and disposal.
Parent
3.2 Establish and Maintain a Data Inventory
SNow
Classification: IdentifyState: Published
Establish and maintain a data inventory, based on the enterprises data management process. Inventory sensitive data, at a minimum. Review and update inventory annually, at a minimum, with a priority on sensitive data.
Parent
3.3 Configure Data Access Control Lists
SNow
Classification: ProtectState: Published
Configure data access control lists based on a users need to know. Apply data access control lists, also known as access permissions, to local and remote file systems, databases, and applications.
Parent
3.4 Enforce Data Retention
SNow
Classification: ProtectState: Published
Retain data according to the enterprises data management process. Data retention must include both minimum and maximum timelines.
Parent
3.5 Securely Dispose of Data
SNow
Classification: ProtectState: Published
Securely dispose of data as outlined in the enterprises data management process. Ensure the disposal process and method are commensurate with the data sensitivity.
Parent
3.7 Establish and Maintain a Data Classification Scheme
SNow
Classification: IdentifyState: Published
Establish and maintain an overall data classification scheme for the enterprise. Enterprises may use labels, such as Sensitive, Confidential, and Public, and classify their data according to those labels. Review and update the classification scheme annually, or when significant enterprise chan
Parent
3.8 Document Data Flows
SNow
Classification: IdentifyState: Published
Document data flows. Data flow documentation includes service provider data flows and should be based on the enterprises data management process. Review and update documentation annually, or when significant enterprise changes occur that could impact this Safeguard.
Parent
3.9 Encrypt Data on Removable Media
SNow
Classification: ProtectState: Published
Encrypt data on removable media.
Parent
6.8 Define and Maintain Role-Based Access Control
SNow
Classification: ProtectState: Published
Define and maintain role-based access control, through determining and documenting the access rights necessary for each role within the enterprise to successfully carry out its assigned duties. Perform access control reviews of enterprise assets to validate that all privileges are authorized, on a r
8.12 Collect Service Provider Logs
SNow
Classification: DetectState: Published
Collect service provider logs, where supported. Example implementations include collecting authentication and authorization events, data creation and disposal events, and user management events.
Parent
Conduct Regular External and Internal Penetration Tests
SNow
Classification: DetectState: Published
Conduct regular external and internal penetration tests to identify vulnerabilities and attack vectors that can be used to exploit enterprise systems successfully.
Data Protection
SNow
Classification: IdentifyState: Published
The processes and tools used to prevent data exfiltration, mitigate the effects of exfiltrated data, and ensure the privacy and integrity of sensitive information.
Citations (1)
Children (9)
- Encrypt Data on USB Storage Devices
- Encrypt the Hard Drive of All Mobile Devices.
- Maintain an Inventory of Sensitive Information
- Manage System's External Removable Media's Read/write Config...
- Manage USB Devices
- Monitor and Block Unauthorized Network Traffic
- Monitor and Detect Any Unauthorized Use of Encryption
- Only Allow Access to Authorized Cloud Storage or Email Provi...
- Remove Sensitive Data or Systems Not Regularly Accessed by O...
Data Recovery Capabilities
SNow
Classification: ProtectState: Published
The processes and tools used to properly back up critical information with a proven methodology for timely recovery of it.
Document Incident Response Procedures
SNow
Classification: ProtectState: Published
Ensure that there are written incident response plans that defines roles of personnel as well as phases of incident handling/management.
Citations (1)
Encrypt All Sensitive Information in Transit
SNow
Classification: ProtectState: Published
Encrypt all sensitive information in transit.
Encrypt Data on USB Storage Devices
SNow
Classification: ProtectState: Published
Provide the training to employees so they are aware of the risks of data on USB drives. Then provide them with the tools to secure your organizations critical data.
Parent
Encrypt Sensitive Information at Rest
SNow
Classification: ProtectState: Published
Encrypt all sensitive information at rest using a tool that requires a secondary authentication mechanism not integrated into the operating system, in order to access the information.
Encrypt the Hard Drive of All Mobile Devices.
SNow
Classification: ProtectState: Published
Utilize approved whole disk encryption software to encrypt the hard drive of all mobile devices.
Parent
Enforce Access Control to Data through Automated Tools
SNow
Classification: ProtectState: Published
Use an automated tool, such as host-based Data Loss Prevention, to enforce access controls to data even when data is copied off a system.
Enforce Detail Logging for Access or Changes to Sensitive Data
SNow
Classification: DetectState: Published
Enforce detailed audit logging for access to sensitive data or changes to sensitive data (utilizing tools such as File Integrity Monitoring or Security Information and Event Monitoring).
Ensure Backups Have At least One Non-Continuously Addressable Destination
SNow
Classification: ProtectState: Published
Ensure that all backups have at least one backup destination that is not continuously addressable through operating system calls.
Ensure Protection of Backups
SNow
Classification: ProtectState: Published
Ensure that backups are properly protected via physical security or encryption when they are stored, as well as when they are moved across the network. This includes remote backups and cloud services.
Ensure Regular Automated Back Ups
SNow
Classification: ProtectState: Published
Ensure that all system data is automatically backed up on regular basis.
Citations (1)
Establish a Penetration Testing Program
SNow
Classification: ProtectState: Published
Establish a program for penetration tests that includes a full scope of blended attacks, such as wireless, client-based, and web application attacks.
Incident Response and Management
SNow
Classification: ProtectState: Published
Protect the organization's information, as well as its reputation, by developing and implementing an incident response infrastructure (e.g., plans, defined roles, training, communications, management oversight) for quickly discovering an attack and then effectively containing the damage, eradicating
Children (8)
- Assign Job Titles and Duties for Incident Response
- Conduct Periodic Incident Scenario Sessions for Personnel
- Create Incident Scoring and Prioritization Schema
- Designate Management Personnel to Support Incident Handling
- Devise Organization-wide Standards for Reporting Incidents
- Document Incident Response Procedures
- Maintain Contact Information For Reporting Security Incident...
- Publish Information Regarding Reporting Computer Anomalies a...
Maintain an Inventory of Sensitive Information
SNow
Classification: IdentifyState: Published
Maintain an inventory of all sensitive information stored, processed, or transmitted by the organization's technology systems, including those located onsite or at a remote service provider.
Parent
Manage System's External Removable Media's Read/write Configurations
SNow
Classification: ProtectState: Published
Configure systems not to write data to external removable media, if there is no business need for supporting such devices.
Parent
Manage USB Devices
SNow
Classification: ProtectState: Published
If USB storage devices are required, enterprise software should be used that can configure systems to allow the use of specific devices. An inventory of such devices should be maintained.
Parent
Monitor and Block Unauthorized Network Traffic
SNow
Classification: DetectState: Published
Deploy an automated tool on network perimeters that monitors for unauthorized transfer of sensitive information and blocks such transfers while alerting information security professionals.
Parent
Monitor and Detect Any Unauthorized Use of Encryption
SNow
Classification: DetectState: Published
Monitor all traffic leaving the organization and detect any unauthorized use of encryption.
Parent
Only Allow Access to Authorized Cloud Storage or Email Providers
SNow
Classification: ProtectState: Published
Only allow access to authorized cloud storage or email providers.
Parent
Penetration Tests and Red Team Exercises
SNow
Classification: ProtectState: Published
Test the overall strength of an organization's defense (the technology, the processes, and the people) by simulating the objectives and actions of an attacker.
Children (8)
- Conduct Regular External and Internal Penetration Tests
- Control and Monitor Accounts Associated with Penetration Tes...
- Create Test Bed for Elements Not Typically Tested in Product...
- Ensure Results from Penetration Test are Documented Using Op...
- Establish a Penetration Testing Program
- Include Tests for Presence of Unprotected System Information...
- Perform Periodic Red Team Exercises
- Use Vulnerability Scanning and Penetration Testing Tools in ...
Perform Complete System Backups
SNow
Classification: ProtectState: Published
Ensure that each of the organization's key systems are backed up as a complete system, through processes such as imaging, to enable the quick recovery of an entire system.
Protect Information through Access Control Lists
SNow
Classification: ProtectState: Published
Protect all information stored on systems with file system, network share, claims, application, or database specific access control lists. These controls will enforce the principle that only authorized individuals should have access to the information based on their need to access the information as
Remove Sensitive Data or Systems Not Regularly Accessed by Organization
SNow
Classification: ProtectState: Published
Remove sensitive data or systems not regularly accessed by the organization from the network. These systems shall only be used as stand alone systems (disconnected from the network) by the business unit needing to occasionally use the system or completely virtualized and powered off until needed.
Parent
Separate Production and Non-Production Systems
SNow
Classification: ProtectState: Published
Maintain separate environments for production and nonproduction systems. Developers should not have unmonitored access to production environments.
Test Data on Backup Media
SNow
Classification: ProtectState: Published
Test data integrity on backup media on a regular basis by performing a data restoration process to ensure that the backup is properly working.
Use Standard Hardening Configuration Templates for Databases
SNow
Classification: ProtectState: Published
For applications that rely on a database, use standard hardening configuration templates. All systems that are part of critical business processes should also be tested.
Utilize an Active Discovery Tool to Identify Sensitive Data
SNow
Classification: DetectState: Published
Utilize an active discovery tool to identify all sensitive information stored, processed, or transmitted by the organization's technology systems, including those located onsite or at a remote service provider and update the organization's sensitive information inventory.