Control Objectives: Users

No control objectives match the current filters.
4.3 Configure Automatic Session Locking on Enterprise Assets
SNow
Classification: ProtectState: Published
Configure automatic session locking on enterprise assets after a defined period of inactivity. For general purpose operating systems, the period must not exceed 15 minutes. For mobile end-user devices, the period must not exceed 2 minutes.
4.7 Manage Default Accounts on Enterprise Assets and Software
SNow
Classification: ProtectState: Published
Manage default accounts on enterprise assets and software, such as root, administrator, and other pre-configured vendor accounts. Example implementations can include: disabling default accounts or making them unusable.
5.1 Establish and Maintain an Inventory of Accounts
SNow
Classification: IdentifyState: Published
Establish and maintain an inventory of all accounts managed in the enterprise. The inventory must include both user and administrator accounts. The inventory, at a minimum, should contain the person’s name, username, start/stop dates, and department. Validate that all active accounts are authorized,
5.2 Use Unique Passwords
SNow
Classification: ProtectState: Published
Use unique passwords for all enterprise assets. Best practice implementation includes, at a minimum, an 8-character password for accounts using MFA and a 14-character password for accounts not using MFA.
5.3 Disable Dormant Accounts
SNow
Classification: RespondState: Published
Delete or disable any dormant accounts after a period of 45 days of inactivity, where supported.
5.4 Restrict Administrator Privileges to Dedicated Administrator Accounts
SNow
Classification: ProtectState: Published
Restrict administrator privileges to dedicated administrator accounts on enterprise assets. Conduct general computing activities, such as internet browsing, email, and productivity suite use, from the user’s primary, non-privileged account.
5.5 Establish and Maintain an Inventory of Service Accounts
SNow
Classification: IdentifyState: Published
Establish and maintain an inventory of service accounts. The inventory, at a minimum, must contain department owner, review date, and purpose. Perform service account reviews to validate that all active accounts are authorized, on a recurring schedule at a minimum quarterly, or more frequently.
5.6 Centralize Account Management
SNow
Classification: ProtectState: Published
Centralize account management through a directory or identity service.
6.1 Establish an Access Granting Process
SNow
Classification: ProtectState: Published
Establish and follow a process, preferably automated, for granting access to enterprise assets upon new hire, rights grant, or role change of a user
6.2 Establish an Access Revoking Process
SNow
Classification: ProtectState: Published
Establish and follow a process, preferably automated, for revoking access to enterprise assets, through disabling accounts immediately upon termination, rights revocation, or role change of a user. Disabling accounts, instead of deleting accounts, may be necessary to preserve audit trails.
6.3 Require MFA for Externally-Exposed Applications
SNow
Classification: ProtectState: Published
Require all externally-exposed enterprise or third-party applications to enforce MFA, where supported. Enforcing MFA through a directory service or SSO provider is a satisfactory implementation of this Safeguard.
6.4 Require MFA for Remote Network Access
SNow
Classification: ProtectState: Published
Require MFA for remote network access.
6.5 Require MFA for Administrative Access
SNow
Classification: ProtectState: Published
Require MFA for all administrative access accounts, where supported, on all enterprise assets, whether managed on-site or through a third-party provider.
6.6 Establish and Maintain an Inventory of Authentication and Authorization Systems
SNow
Classification: IdentifyState: Published
Establish and maintain an inventory of the enterprise’s authentication and authorization systems, including those hosted on-site or at a remote service provider. Review and update the inventory, at a minimum, annually, or more frequently.
6.7 Centralize Access Control
SNow
Classification: ProtectState: Published
Centralize access control for all enterprise assets through a directory service or SSO provider, where supported.
Alert on Account Login Behavior Deviation
SNow
Classification: DetectState: Published
Alert when users deviate from normal login behavior, such as time-of-day, workstation location and duration.
Assign Job Titles and Duties for Incident Response
SNow
Classification: ProtectState: Published
Assign job titles and duties for handling computer and network incidents to specific individuals and ensure tracking and documentation throughout the incident through resolution.
Change Default Passwords
SNow
Classification: ProtectState: Published
Before deploying any new asset, change all default passwords to have values consistent with administrative level accounts.
Conduct Periodic Incident Scenario Sessions for Personnel
SNow
Classification: ProtectState: Published
Plan and conduct routine incident response exercises and scenarios for the workforce involved in the incident response to maintain awareness and comfort in responding to real world threats. Exercises should test communication channels, decision making, and incident responders technical capabilities
Configure Centralized Point of Authentication
SNow
Classification: ProtectState: Published
Configure access for all accounts through as few centralized points of authentication as possible, including network, security, and cloud systems.
Control and Monitor Accounts Associated with Penetration Testing
SNow
Classification: DetectState: Published
Any user or system accounts used to perform penetration testing should be controlled and monitored to make sure they are only being used for legitimate purposes, and are removed or restored to normal function after testing is over.
Controlled Use of Administrative Privileges
SNow
Classification: DetectState: Published
The processes and tools used to track/control/prevent/correct the use, assignment, and configuration of administrative privileges on computers, networks, and applications.
Create Incident Scoring and Prioritization Schema
SNow
Classification: ProtectState: Published
Create incident scoring and prioritization schema based on known or potential impact to your organization. Utilize score to define frequency of status updates and escalation procedures.
Deliver Training to Fill the Skills Gap
SNow
Classification: ProtectState: Published
Deliver training to address the skills gap identified to positively impact workforce members' security behavior.
Designate Management Personnel to Support Incident Handling
SNow
Classification: ProtectState: Published
Designate management personnel, as well as backups, who will support the incident handling process by acting in key decision-making roles.
Devise Organization-wide Standards for Reporting Incidents
SNow
Classification: ProtectState: Published
Devise organization-wide standards for the time required for system administrators and other workforce members to report anomalous events to the incident handling team, the mechanisms for such reporting, and the kind of information that should be included in the incident notification.
Disable Any Unassociated Accounts
SNow
Classification: ProtectState: Published
Disable any account that cannot be associated with a business process or business owner.
Disable Dormant Accounts
SNow
Classification: ProtectState: Published
Automatically disable dormant accounts after a set period of inactivity.
Encrypt Transmittal of Username and Authentication Credentials
SNow
Classification: ProtectState: Published
Ensure that all account usernames and authentication credentials are transmitted across networks using encrypted channels.
Encrypt or Hash all Authentication Credentials
SNow
Classification: ProtectState: Published
Encrypt or hash with a salt all authentication credentials when stored.
Ensure All Accounts Have An Expiration Date
SNow
Classification: ProtectState: Published
Ensure that all accounts have an expiration date that is monitored and enforced.
Ensure Software Development Personnel are Trained in Secure Coding
SNow
Classification: ProtectState: Published
Ensure that all software development personnel receive training in writing secure code for their specific development environment and responsibilities.
Ensure the Use of Dedicated Administrative Accounts
SNow
Classification: ProtectState: Published
Ensure that all users with administrative account access use a dedicated or secondary account for elevated activities. This account should only be used for administrative activities and not internet browsing, email, or similar activities.
Establish Process for Revoking Access
SNow
Classification: ProtectState: Published
Establish and follow an automated process for revoking system access by disabling accounts immediately upon termination or change of responsibilities of an employee or contractor . Disabling these accounts, instead of deleting accounts, allows preservation of audit trails.
Implement a Security Awareness Program
SNow
Classification: ProtectState: Published
Create a security awareness program for all workforce members to complete on a regular basis to ensure they understand and exhibit the necessary behaviors and skills to help ensure the security of the organization. The organization's security awareness program should be communicated in a continuous
Implement a Security Awareness and Training Program
SNow
Classification: IdentifyState: Published
For all functional roles in the organization (prioritizing those mission-critical to the business and its security), identify the specific knowledge, skills, and abilities needed to support defense of the enterprise; develop and execute an integrated plan to assess, identify gaps, and remediate thro
Limit Access to Script Tools
SNow
Classification: ProtectState: Published
Limit access to scripting tools (such as Microsoft PowerShell and Python) to only administrative or development users with the need to access those capabilities.
Lock Workstation Sessions After Inactivity
SNow
Classification: ProtectState: Published
Automatically lock workstation sessions after a standard period of inactivity.
Log and Alert on Changes to Administrative Group Membership
SNow
Classification: DetectState: Published
Configure systems to issue a log entry and alert when an account is added to or removed from any group assigned administrative privileges.
Log and Alert on Unsuccessful Administrative Account Login
SNow
Classification: DetectState: Published
Configure systems to issue a log entry and alert on unsuccessful logins to an administrative account.
Maintain Contact Information For Reporting Security Incidents
SNow
Classification: ProtectState: Published
Assemble and maintain information on third-party contact information to be used to report a security incident, such as Law Enforcement, relevant government departments, vendors, and ISAC partners.
Maintain Inventory of Administrative Accounts
SNow
Classification: DetectState: Published
Use automated tools to inventory all administrative accounts, including domain and local accounts, to ensure that only authorized individuals have elevated privileges.
Maintain an Inventory of Accounts
SNow
Classification: IdentifyState: Published
Maintain an inventory of all accounts organized by authentication system.
Maintain an Inventory of Authentication Systems
SNow
Classification: IdentifyState: Published
Maintain an inventory of each of the organization's authentication systems, including those located onsite or at a remote service provider.
Monitor Attempts to Access Deactivated Accounts
SNow
Classification: DetectState: Published
Monitor attempts to access deactivated accounts through audit logging.
Perform Periodic Red Team Exercises
SNow
Classification: DetectState: Published
Perform periodic Red Team exercises to test organizational readiness to identify and stop attacks or to respond quickly and effectively.
Perform a Skills Gap Analysis
SNow
Classification: IdentifyState: Published
Perform a skills gap analysis to understand the skills and behaviors workforce members are not adhering to, using this information to build a baseline education roadmap.
Protect Dedicated Assessment Accounts
SNow
Classification: ProtectState: Published
Use a dedicated account for authenticated vulnerability scans, which should not be used for any other administrative activities and should be tied to specific machines at specific IP addresses.
Publish Information Regarding Reporting Computer Anomalies and Incidents
SNow
Classification: ProtectState: Published
Publish information for all workforce members, regarding reporting computer anomalies and incidents to the incident handling team. Such information should be included in routine employee awareness activities.
Require All Remote Login to Use Multi-factor Authentication
SNow
Classification: ProtectState: Published
Require all remote login access to the organization's network to encrypt data in transit and use multi-factor authentication.
Require Multi-factor Authentication
SNow
Classification: ProtectState: Published
Require multi-factor authentication for all user accounts, on all systems, whether managed onsite or by a third-party provider.
Security Awareness Training
SNow
Classification: PreventiveState: Published
Establish and maintain a security awareness program to influence behavior among the workforce to be security conscious and properly skilled to reduce cybersecurity risks to the enterprise.
Train Workforce Members on Identifying and Reporting Incidents
SNow
Classification: ProtectState: Published
Train employees to be able to identify the most common indicators of an incident and be able to report such an incident.
Train Workforce on Causes of Unintentional Data Exposure
SNow
Classification: ProtectState: Published
Train workforce members to be aware of causes for unintentional data exposures, such as losing their mobile devices or emailing the wrong person due to autocomplete in email.
Train Workforce on Identifying Social Engineering Attacks
SNow
Classification: ProtectState: Published
Train the workforce on how to identify different forms of social engineering attacks, such as phishing, phone scams and impersonation calls.
Train Workforce on Secure Authentication
SNow
Classification: ProtectState: Published
Train workforce members on the importance of enabling and utilizing secure authentication.
Train Workforce on Sensitive Data Handling
SNow
Classification: ProtectState: Published
Train workforce on how to identify and properly store, transfer, archive and destroy sensitive information.
Update Awareness Content Frequently
SNow
Classification: ProtectState: Published
Ensure that the organization's security awareness program is updated frequently (at least annually) to address new technologies, threats, standards and business requirements.
Use Multifactor Authentication For All Administrative Access
SNow
Classification: ProtectState: Published
Use multi-factor authentication and encrypted channels for all administrative account access.
Use Unique Passwords
SNow
Classification: ProtectState: Published
Where multi-factor authentication is not supported (such as local administrator, root, or service accounts), accounts will use passwords that are unique to that system.
Use of Dedicated Machines For All Administrative Tasks
SNow
Classification: ProtectState: Published
Ensure administrators use a dedicated machine for all administrative tasks or tasks requiring administrative access. This machine will be segmented from the organization's primary network and not be allowed Internet access. This machine will not be used for reading e-mail, composing documents, or br
Graph Explorer