Control Objectives: Devices

No control objectives match the current filters.
1.1 Establish and Maintain Detailed Enterprise Asset Inventory
SNow
Classification: IdentifyState: Published
Establish and maintain an accurate, detailed, and up-to-date inventory of all enterprise assets with the potential to store or process data, to include: end-user devices (including portable and mobile), network devices, non-computing/IoT devices, and servers. Ensure the inventory records the network
1.2 Establish and Maintain Detailed Enterprise Asset Inventory
SNow
Classification: RespondState: Published
Ensure that a process exists to address unauthorized assets on a weekly basis. The enterprise may choose to remove the asset from the network, deny the asset from connecting remotely to the network, or quarantine the asset.
1.3 Utilize an Active Discovery Tool
SNow
Classification: DetectState: Published
Utilize an active discovery tool to identify assets connected to the enterprise’s network. Configure the active discovery tool to execute daily, or more frequently.
1.4 Use Dynamic Host Configuration Protocol (DHCP) Logging to Update Enterprise Asset Inventory
SNow
Classification: IdentifyState: Published
Use DHCP logging on all DHCP servers or Internet Protocol (IP) address management tools to update the enterprise’s asset inventory. Review and use logs to update the enterprise’s asset inventory weekly, or more frequently.
1.5 Use a Passive Asset Discovery Tool
SNow
Classification: DetectState: Published
Use a passive discovery tool to identify assets connected to the enterprise’s network. Review and use scans to update the enterprise’s asset inventory at least weekly, or more frequently.
10.1 Deploy and Maintain Anti-Malware Software
SNow
Classification: ProtectState: Published
Deploy and maintain anti-malware software on all enterprise assets.
10.2 Configure Automatic Anti-Malware Signature Updates
SNow
Classification: ProtectState: Published
Configure automatic updates for anti-malware signature files on all enterprise assets.
10.3 Disable Autorun and Autoplay for Removable Media
SNow
Classification: ProtectState: Published
Disable autorun and autoplay auto-execute functionality for removable media.
10.4 Configure Automatic Anti-Malware Scanning of Removable Media
SNow
Classification: DetectState: Published
Configure anti-malware software to automatically scan removable media.
10.5 Enable Anti-Exploitation Features
SNow
Classification: ProtectState: Published
Enable anti-exploitation features on enterprise assets and software, where possible, such as Microsoft® Data Execution Prevention (DEP), Windows® Defender Exploit Guard (WDEG), or Apple® System Integrity Protection (SIP) and Gatekeeper™.
10.6 Centrally Manage Anti-Malware Software
SNow
Classification: ProtectState: Published
Centrally manage anti-malware software.
10.7 Use Behavior-Based Anti-Malware Software
SNow
Classification: DetectState: Published
Use behavior-based anti-malware software.
12.7 Ensure Remote Devices Utilize a VPN and are Connecting to an Enterprise’s AAA Infrastructure
SNow
Classification: ProtectState: Published
Require users to authenticate to enterprise-managed VPN and authentication services prior to accessing enterprise resources on end-user devices.
12.8 Establish and Maintain Dedicated Computing Resources for All Administrative Work
SNow
Classification: ProtectState: Published
Establish and maintain dedicated computing resources, either physically or logically separated, for all administrative tasks or tasks requiring administrative access. The computing resources should be segmented from the enterprise's primary network and not be allowed internet access.
13.2 Deploy a Host-Based Intrusion Detection Solution
SNow
Classification: DetectState: Published
Deploy a host-based intrusion detection solution on enterprise assets, where appropriate and/or supported.
13.5 Manage Access Control for Remote Assets
SNow
Classification: ProtectState: Published
Manage access control for assets remotely connecting to enterprise resources. Determine amount of access to enterprise resources based on: up-to-date anti-malware software installed, configuration compliance with the enterprise’s secure configuration process, and ensuring the operating system and ap
13.7 Deploy a Host-Based Intrusion Prevention Solution
SNow
Classification: ProtectState: Published
Deploy a host-based intrusion prevention solution on enterprise assets, where appropriate and/or supported. Example implementations include use of an Endpoint Detection and Response (EDR) client or host-based IPS agent.
13.9 Deploy Port-Level Access Control
SNow
Classification: ProtectState: Published
Deploy port-level access control. Port-level access control utilizes 802.1x, or similar network access control protocols, such as certificates, and may incorporate user and/or device authentication.
3.6 Encrypt Data on End-User Devices
SNow
Classification: ProtectState: Published
Encrypt data on end-user devices containing sensitive data. Example implementations can include: Windows BitLocker®, Apple FileVault®, Linux® dm-crypt.
4.10 Enforce Automatic Device Lockout on Portable End-User Devices
SNow
Classification: RespondState: Published
Enforce automatic device lockout following a predetermined threshold of local failed authentication attempts on portable end-user devices, where supported. For laptops, do not allow more than 20 failed authentication attempts; for tablets and smartphones, no more than 10 failed authentication attemp
4.11 Enforce Remote Wipe Capability on Portable End-User Devices
SNow
Classification: ProtectState: Published
Remotely wipe enterprise data from enterprise-owned portable end-user devices when deemed appropriate such as lost or stolen devices, or when an individual no longer supports the enterprise.
4.12 Separate Enterprise Workspaces on Mobile End-User Devices
SNow
Classification: ProtectState: Published
Ensure separate enterprise workspaces are used on mobile end-user devices, where supported. Example implementations include using an Apple® Configuration Profile or Android™ Work Profile to separate enterprise applications and data from personal applications and data.
4.4 Implement and Manage a Firewall on Servers
SNow
Classification: ProtectState: Published
Implement and manage a firewall on servers, where supported. Example implementations include a virtual firewall, operating system firewall, or a third-party firewall agent.
4.5 Implement and Manage a Firewall on End-User Devices
SNow
Classification: ProtectState: Published
Implement and manage a host-based firewall or port-filtering tool on end-user devices, with a default-deny rule that drops all traffic except those services and ports that are explicitly allowed.
4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
SNow
Classification: ProtectState: Published
Uninstall or disable unnecessary services on enterprise assets and software, such as an unused file sharing service, web application module, or service function.
4.9 Configure Trusted DNS Servers on Enterprise Assets
SNow
Classification: ProtectState: Published
Configure trusted DNS servers on enterprise assets. Example implementations include: configuring assets to use enterprise-controlled DNS servers and/or reputable externally accessible DNS servers.
8.8 Collect Command-Line Audit Logs
SNow
Classification: DetectState: Published
Collect command-line audit logs. Example implementations include collecting audit logs from PowerShell®, BASH™, and remote administrative terminals.
Address Unauthorized Assets
SNow
Classification: RespondState: Published
Ensure that unauthorized assets are either removed from the network, quarantined, or the inventory is updated in a timely manner.
Apply Host-based Firewalls or Port Filtering
SNow
Classification: ProtectState: Published
Apply host-based firewalls or port filtering tools on end systems, with a default-deny rule that drops all traffic except those services and ports that are explicitly allowed.
Associate Active Ports, Services and Protocols to Asset Inventory
SNow
Classification: IdentifyState: Published
Associate active ports, services and protocols to the hardware assets in the asset inventory.
Centralize Anti-malware Logging
SNow
Classification: DetectState: Published
The important aspect of this requirement is getting the logs off of the endpoint so a malware infection doesn’t clear them out.
Configure Anti-Malware Scanning of Removable Devices
SNow
Classification: DetectState: Published
Most AVs have this capability turned on by default, but it’s still important to verify that it’s actually still enabled. Malware coming in via a USB stick is a viable attack vector for nearly every organization.
Configure Devices Not To Auto-run Content
SNow
Classification: ProtectState: Published
For the same reason why you do not want to scan it, you also don’t want it to run when it’s mounted. This is a pretty quick setting to enable, and both CIS and DISA hardening guides have step-by-step instructions on disabling auto-run. Some SCM tools can quickly check every endpoint in your environm
Deploy Port Level Access Control
SNow
Classification: ProtectState: Published
Utilize port level access control, following 802.1x standards, to control which devices can authenticate to the network. The authentication system shall be tied into the hardware asset inventory data to ensure only authorized devices can connect to the network.
Disable Peer-to-peer Wireless Network Capabilities on Wireless Clients
SNow
Classification: ProtectState: Published
Disable peer-to-peer (adhoc) wireless network capabilities on wireless clients.
Disable Wireless Access on Devices if Not Required
SNow
Classification: ProtectState: Published
Disable wireless access on devices that do not have a business purpose for wireless access.
Disable Wireless Peripheral Access of Devices
SNow
Classification: ProtectState: Published
Disable wireless peripheral access of devices (such as Bluetooth and NFC), unless such access is required for a business purpose.
Enable Command-line Audit Logging
SNow
Classification: DetectState: Published
On high interaction systems, this can be quite noisy. From a forensics standpoint, it will be quite valuable.
Enable Operating System Anti-Exploitation Features/ Deploy Anti-Exploit Technologies
SNow
Classification: ProtectState: Published
The DISA hardening guides provide step-by-step instructions on enabling these settings and so much more.
Ensure Anti-Malware Software and Signatures are Updated
SNow
Classification: ProtectState: Published
The AV is only as good as it’s signatures. While pure signature-based detection is no longer viable, even anomaly-based engines need to be updated on a regular basis. Ensure that the updates are rolled out automatically and use tools to verify that the signatures are actually up-to-date
Ensure Only Approved Ports, Protocols and Services Are Running
SNow
Classification: ProtectState: Published
Ensure that only network ports, protocols, and services listening on a system with validated business needs, are running on each system.
Implement Application Firewalls
SNow
Classification: ProtectState: Published
Place application firewalls in front of any critical servers to verify and validate the traffic going to the server. Any unauthorized traffic should be blocked and logged.
Inventory and Control of Hardware Assets
SNow
Classification: IdentifyState: Published
Actively manage (inventory, track, and correct) all hardware devices on the network so that only authorized devices are given access, and unauthorized and unmanaged devices are found and prevented from gaining access.
Limit Wireless Access on Client Devices
SNow
Classification: ProtectState: Published
Configure wireless access on client machines that do have an essential wireless business purpose, to allow access only to authorized wireless networks and to restrict access to other wireless networks.
Limitation and Control of Network Ports, Protocols, and Services
SNow
Classification: IdentifyState: Published
Manage (track/control/correct) the ongoing operational use of ports, protocols, and services on networked devices in order to minimize windows of vulnerability available to attackers.
Maintain Asset Inventory Information
SNow
Classification: IdentifyState: Published
Ensure that the hardware asset inventory records the network address, hardware address, machine name, data asset owner, and department for each asset and whether the hardware asset has been approved to connect to the network.
Maintain Detailed Asset Inventory
SNow
Classification: IdentifyState: Published
Maintain an accurate and up-to-date inventory of all technology assets with the potential to store or process information. This inventory shall include all hardware assets, whether connected to the organization's network or not.
Malware Defenses
SNow
Classification: ProtectState: Published
Install AV and run updates regularly. This has been ingrained in IT professionals for decades. The only key aspects is to make sure the AV solution meets the needs of your organization in terms of capabilities.
Manage All Devices Remotely Logging into Internal Network
SNow
Classification: ProtectState: Published
Scan all enterprise devices remotely logging into the organization's network prior to accessing the network to ensure that each of the organization's security policies has been enforced in the same manner as local network devices.
Perform Regular Automated Port Scans
SNow
Classification: DetectState: Published
Perform automated port scans on a regular basis against all systems and alert if unauthorized ports are detected on a system.
Use DHCP Logging to Update Asset Inventory
SNow
Classification: IdentifyState: Published
Use Dynamic Host Configuration Protocol (DHCP) logging on all DHCP servers or IP address management tools to update the organization's hardware asset inventory.
Use a Passive Asset Discovery Tool
SNow
Classification: IdentifyState: Published
Utilize a passive discovery tool to identify devices connected to the organization's network and automatically update the organization's hardware asset inventory.
Utilize Centrally Managed Anti-malware Software
SNow
Classification: ProtectState: Published
Any enterprise class AV software will have this capability. By having a centrally managed AV, you can easily enable individual requirements.
Utilize Client Certificates to Authenticate Hardware Assets
SNow
Classification: ProtectState: Published
Use client certificates to authenticate hardware assets connecting to the organization's trusted network.
Utilize an Active Discovery Tool
SNow
Classification: IdentifyState: Published
Utilize an active discovery tool to identify devices connected to the organization's network and update the hardware asset inventory.
Graph Explorer