December 2021
Intermediate to advanced
224 pages
4h 41m
English
There are several control frameworks available to address the more tactical elements of cybersecurity. One industry-recognized framework is the Center for Internet Security (CIS) Controls, formerly known as the SANS Top 20. This mapping demonstrates connections between NIST Cybersecurity Framework (CSF) and the CIS Controls Version 8.0. The CIS Controls provide security best practices to help organizations defend assets in cyberspace.
Use this mapping to help identify specific technical implementations, modifications, or best practices that can aid in meeting a respective NIST CSF Subcategory Control. (Please note that not all CIS elements map directly to the NIST Framework.)
| CIS Sub-Control | CIS Control | NIST CSF |
|---|---|---|
| Inventory and Control of Hardware Assets | ||
| 1.1 | Establish and Maintain Detailed Asset Inventory |
ID.AM-1 PR.DS-3 |
| 1.2 | Address Unauthorized Assets | |
| 1.3 | Utilize an Active Discovery Tool | DE.CM-7 |
| 1.4 | Use Dynamic Host Configuration Protocol (DHCP) Logging to Update Enterprise Asset Inventory | DE.CM-7 |
| 1.5 | Use a Passive Asset Discovery Tool | DE.CM-7 |
| Inventory and Control of Software Assets | ||
| 2.1 | Establish and Maintain a Software Inventory | ID.AM-2 |
| 2.2 | Ensure Authorized Software is Currently Supported | ID.AM-2 |
| 2.3 | Address Unauthorized Software | DE.CM-7 |
| 2.4 | Utilize Automated Software Inventory Tools | DE.CM-7 |
| 2.5 | Allowlist Authorized Software | DE.CM-7 |
| 2.6 | Allowlist Authorized Libraries ... |
Read now
Unlock full access