Control Objectives: Data

No control objectives match the current filters.
11.1 Establish and Maintain a Data Recovery Process
SNow
Classification: RespondState: Published
Establish and maintain a data recovery process. In the process, address the scope of data recovery activities, recovery prioritization, and the security of backup data. Review and update documentation annually, or when significant enterprise changes occur that could impact this Safeguard.
11.2 Perform Automated Backups
SNow
Classification: RespondState: Published
Perform automated backups of in-scope enterprise assets. Run backups weekly, or more frequently, based on the sensitivity of the data.
11.3 Protect Recovery Data
SNow
Classification: ProtectState: Published
Protect recovery data with equivalent controls to the original data. Reference encryption or data separation, based on requirements.
11.4 Establish and Maintain an Isolated Instance of Recovery Data
SNow
Classification: RespondState: Published
Establish and maintain an isolated instance of recovery data. Example implementations include, version controlling backup destinations through offline, cloud, or off-site systems or services.
11.5 Test Data Recovery
SNow
Classification: RespondState: Published
Test backup recovery quarterly, or more frequently, for a sampling of in-scope enterprise assets.
15.6 Monitor Service Providers
SNow
Classification: DetectState: Published
Monitor service providers consistent with the enterprise’s service provider management policy. Monitoring may include periodic reassessment of service provider compliance, monitoring service provider release notes, and dark web monitoring.
15.7 Securely Decommission Service Providers
SNow
Classification: ProtectState: Published
Securely decommission service providers. Example considerations include user and service account deactivation, termination of data flows, and secure disposal of enterprise data within service provider systems.
3.1 Establish and Maintain a Data Management Process
SNow
Classification: IdentifyState: Published
Establish and maintain a data management process. In the process, address data sensitivity, data owner, handling of data, data retention limits, and disposal requirements, based on sensitivity and retention standards for the enterprise. Review and update documentation annually, or when significant e
3.10 Encrypt Sensitive Data in Transit
SNow
Classification: ProtectState: Published
Encrypt sensitive data in transit. Example implementations can include: Transport Layer Security (TLS) and Open Secure Shell (OpenSSH).
3.11 Encrypt Sensitive Data at Rest
SNow
Classification: ProtectState: Published
Encrypt sensitive data at rest on servers, applications, and databases containing sensitive data. Storage-layer encryption, also known as server-side encryption, meets the minimum requirement of this Safeguard. Additional encryption methods may include application-layer encryption, also known as cli
3.13 Deploy a Data Loss Prevention Solution
SNow
Classification: ProtectState: Published
Implement an automated tool, such as a host-based Data Loss Prevention (DLP) tool to identify all sensitive data stored, processed, or transmitted through enterprise assets, including those located onsite or at a remote service provider, and update the enterprise's sensitive data inventory.
3.14 Log Sensitive Data Access
SNow
Classification: DetectState: Published
Log sensitive data access, including modification and disposal.
3.2 Establish and Maintain a Data Inventory
SNow
Classification: IdentifyState: Published
Establish and maintain a data inventory, based on the enterprise’s data management process. Inventory sensitive data, at a minimum. Review and update inventory annually, at a minimum, with a priority on sensitive data.
3.3 Configure Data Access Control Lists
SNow
Classification: ProtectState: Published
Configure data access control lists based on a user’s need to know. Apply data access control lists, also known as access permissions, to local and remote file systems, databases, and applications.
3.4 Enforce Data Retention
SNow
Classification: ProtectState: Published
Retain data according to the enterprise’s data management process. Data retention must include both minimum and maximum timelines.
3.5 Securely Dispose of Data
SNow
Classification: ProtectState: Published
Securely dispose of data as outlined in the enterprise’s data management process. Ensure the disposal process and method are commensurate with the data sensitivity.
3.7 Establish and Maintain a Data Classification Scheme
SNow
Classification: IdentifyState: Published
Establish and maintain an overall data classification scheme for the enterprise. Enterprises may use labels, such as “Sensitive,” “Confidential,” and “Public,” and classify their data according to those labels. Review and update the classification scheme annually, or when significant enterprise chan
3.8 Document Data Flows
SNow
Classification: IdentifyState: Published
Document data flows. Data flow documentation includes service provider data flows and should be based on the enterprise’s data management process. Review and update documentation annually, or when significant enterprise changes occur that could impact this Safeguard.
3.9 Encrypt Data on Removable Media
SNow
Classification: ProtectState: Published
Encrypt data on removable media.
6.8 Define and Maintain Role-Based Access Control
SNow
Classification: ProtectState: Published
Define and maintain role-based access control, through determining and documenting the access rights necessary for each role within the enterprise to successfully carry out its assigned duties. Perform access control reviews of enterprise assets to validate that all privileges are authorized, on a r
8.12 Collect Service Provider Logs
SNow
Classification: DetectState: Published
Collect service provider logs, where supported. Example implementations include collecting authentication and authorization events, data creation and disposal events, and user management events.
Conduct Regular External and Internal Penetration Tests
SNow
Classification: DetectState: Published
Conduct regular external and internal penetration tests to identify vulnerabilities and attack vectors that can be used to exploit enterprise systems successfully.
Data Recovery Capabilities
SNow
Classification: ProtectState: Published
The processes and tools used to properly back up critical information with a proven methodology for timely recovery of it.
Document Incident Response Procedures
SNow
Classification: ProtectState: Published
Ensure that there are written incident response plans that defines roles of personnel as well as phases of incident handling/management.
Encrypt All Sensitive Information in Transit
SNow
Classification: ProtectState: Published
Encrypt all sensitive information in transit.
Encrypt Data on USB Storage Devices
SNow
Classification: ProtectState: Published
Provide the training to employees so they are aware of the risks of data on USB drives. Then provide them with the tools to secure your organization’s critical data.
Encrypt Sensitive Information at Rest
SNow
Classification: ProtectState: Published
Encrypt all sensitive information at rest using a tool that requires a secondary authentication mechanism not integrated into the operating system, in order to access the information.
Encrypt the Hard Drive of All Mobile Devices.
SNow
Classification: ProtectState: Published
Utilize approved whole disk encryption software to encrypt the hard drive of all mobile devices.
Enforce Access Control to Data through Automated Tools
SNow
Classification: ProtectState: Published
Use an automated tool, such as host-based Data Loss Prevention, to enforce access controls to data even when data is copied off a system.
Enforce Detail Logging for Access or Changes to Sensitive Data
SNow
Classification: DetectState: Published
Enforce detailed audit logging for access to sensitive data or changes to sensitive data (utilizing tools such as File Integrity Monitoring or Security Information and Event Monitoring).
Ensure Backups Have At least One Non-Continuously Addressable Destination
SNow
Classification: ProtectState: Published
Ensure that all backups have at least one backup destination that is not continuously addressable through operating system calls.
Ensure Protection of Backups
SNow
Classification: ProtectState: Published
Ensure that backups are properly protected via physical security or encryption when they are stored, as well as when they are moved across the network. This includes remote backups and cloud services.
Ensure Regular Automated Back Ups
SNow
Classification: ProtectState: Published
Ensure that all system data is automatically backed up on regular basis.
Establish a Penetration Testing Program
SNow
Classification: ProtectState: Published
Establish a program for penetration tests that includes a full scope of blended attacks, such as wireless, client-based, and web application attacks.
Incident Response and Management
SNow
Classification: ProtectState: Published
Protect the organization's information, as well as its reputation, by developing and implementing an incident response infrastructure (e.g., plans, defined roles, training, communications, management oversight) for quickly discovering an attack and then effectively containing the damage, eradicating
Maintain an Inventory of Sensitive Information
SNow
Classification: IdentifyState: Published
Maintain an inventory of all sensitive information stored, processed, or transmitted by the organization's technology systems, including those located onsite or at a remote service provider.
Manage System's External Removable Media's Read/write Configurations
SNow
Classification: ProtectState: Published
Configure systems not to write data to external removable media, if there is no business need for supporting such devices.
Manage USB Devices
SNow
Classification: ProtectState: Published
If USB storage devices are required, enterprise software should be used that can configure systems to allow the use of specific devices. An inventory of such devices should be maintained.
Monitor and Block Unauthorized Network Traffic
SNow
Classification: DetectState: Published
Deploy an automated tool on network perimeters that monitors for unauthorized transfer of sensitive information and blocks such transfers while alerting information security professionals.
Monitor and Detect Any Unauthorized Use of Encryption
SNow
Classification: DetectState: Published
Monitor all traffic leaving the organization and detect any unauthorized use of encryption.
Only Allow Access to Authorized Cloud Storage or Email Providers
SNow
Classification: ProtectState: Published
Only allow access to authorized cloud storage or email providers.
Perform Complete System Backups
SNow
Classification: ProtectState: Published
Ensure that each of the organization's key systems are backed up as a complete system, through processes such as imaging, to enable the quick recovery of an entire system.
Protect Information through Access Control Lists
SNow
Classification: ProtectState: Published
Protect all information stored on systems with file system, network share, claims, application, or database specific access control lists. These controls will enforce the principle that only authorized individuals should have access to the information based on their need to access the information as
Remove Sensitive Data or Systems Not Regularly Accessed by Organization
SNow
Classification: ProtectState: Published
Remove sensitive data or systems not regularly accessed by the organization from the network. These systems shall only be used as stand alone systems (disconnected from the network) by the business unit needing to occasionally use the system or completely virtualized and powered off until needed.
Separate Production and Non-Production Systems
SNow
Classification: ProtectState: Published
Maintain separate environments for production and nonproduction systems. Developers should not have unmonitored access to production environments.
Test Data on Backup Media
SNow
Classification: ProtectState: Published
Test data integrity on backup media on a regular basis by performing a data restoration process to ensure that the backup is properly working.
Use Standard Hardening Configuration Templates for Databases
SNow
Classification: ProtectState: Published
For applications that rely on a database, use standard hardening configuration templates. All systems that are part of critical business processes should also be tested.
Utilize an Active Discovery Tool to Identify Sensitive Data
SNow
Classification: DetectState: Published
Utilize an active discovery tool to identify all sensitive information stored, processed, or transmitted by the organization's technology systems, including those located onsite or at a remote service provider and update the organization's sensitive information inventory.
Graph Explorer