CIS Controls Assessment Specification (CIS Controls Assessment Specification) (2024)

The Center for Internet Security (CIS) and Tenable partnered together to create a guide to help customers understand how to implement the CIS Controls. Starting with the SANS Top 20 Controls published several years ago, Tenable has continuously helped our customers leverage Tenable Security Center to understand their security posture using these controls. CIS Controls version 7.1 introduced the concept of Implementation Groups (IGs), which are self-assessed categories for organizations based on specific cybersecurity attributes. The security community has assessed the Controls and identified these 20 controls to be reasonable for an organization to implement. Other standards such as Cybersecurity Maturity Model Certification (CMMC) and Cyber Security Framework (CSF) also have a tiered approach to deployment. By grouping the controls into three categories, the implementation is easier to understand and integrate into security operations.

This guide is focused on Implementation Groups 1 (IG1); however, many of the controls have requirements for input that come from active or passive network scanning. As Tenable is a Cyber Exposure and Vulnerability Management company, any guidance provided will best serve the organization with Tenable Security Center Continuous View deployed using active and passive scanning. For controls that Tenable is not able to directly assist with, suggestions on how to use Tenable products will be provided to aid in the successful completion of the control.

CIS Controls Assessment Specification (CIS Controls Assessment Specification) (2)

The 20 CIS Controls are broken down into three categories:Basic, Foundational, and Organizational. The Basic Controls (first six controls) are commonly referred to as the “cyber hygiene” controls. These controls focus on basic security guidelines; for example, Configuration Management, Vulnerability Assessment, and Continuous Monitoring. The next group, Foundational Controls (7 - 16), enable an organization to build a framework for a good security program. The last category, Organizational Controls (final four controls) provide more guidance with respect to people and process.

Tenable assists organizations in taking charge of their cybersecurity program with five steps to successful cybersecurity. These five steps are Discover, Assess, Analyze, Fix, and Measure. For IG1 organizations, these five steps align closely with efforts across the Basic and Foundational categories. With Cyber Hygiene being the focus of the first six controls, these actions align closely with the Discover step. Starting with controls 1 & 2, organizations begin to discover hardware and software assets. The remaining steps Assess, Analyze, Fix and Measure are seen throughout the remaining controls. Controls 3, 4, 5, 8, and 11 are all key aspects to Tenable’s core ability to help assess risk. For the other categories, Tenable can often aid in the understanding of configuration problems or situational context based on discovered vulnerabilities.

By combining Tenable's Five Steps To Cybersecurity Success and the CIS Controls into a unified process, an organization can more easily secure their network. Using the CIS Control Assessment Specification (CAS) as a detailed guide, the security team can easily align their efforts in vulnerability management to meet the CIS Control requirements. Using the inputs and measures found in the CAS, the security team can operationalize the controls and use Tenable Security Center as the source of truth for many controls, and for other controls the data within Tenable Security Center will add value.

This guide provides a section for each CIS Control, and sub-sections for each Sub-Control. Examples of queries and dashboard use cases are provided. The security team can follow the CAS and this guide for a more successful deployment of the CIS Controls.

Copyright © 2023 Tenable, Inc. All rights reserved. Tenable, Tenable Nessus, Tenable Lumin, Assure, and the Tenable logo are registered trademarks of Tenable, Inc. or its affiliates. All other products or services are trademarks of their respective owners.

CIS Controls Assessment Specification (CIS Controls Assessment Specification) (2024)
Top Articles
Zhang Xin
5 Easy Tips to Start Door-Knocking Today - LabCoat Agents - The Largest Online Real Estate Community In The World
Xre-02022
Friskies Tender And Crunchy Recall
Comcast Xfinity Outage in Kipton, Ohio
How To Get Free Credits On Smartjailmail
Delectable Birthday Dyes
Www Thechristhospital Billpay
How Many Cc's Is A 96 Cubic Inch Engine
Trini Sandwich Crossword Clue
180 Best Persuasive Essay Topics Ideas For Students in 2024
Letter F Logos - 178+ Best Letter F Logo Ideas. Free Letter F Logo Maker. | 99designs
Leader Times Obituaries Liberal Ks
Does Breckie Hill Have An Only Fans – Repeat Replay
Harem In Another World F95
Nail Salon Goodman Plaza
Voy Boards Miss America
List of all the Castle's Secret Stars - Super Mario 64 Guide - IGN
Fraction Button On Ti-84 Plus Ce
Lcwc 911 Live Incident List Live Status
Copart Atlanta South Ga
V-Pay: Sicherheit, Kosten und Alternativen - BankingGeek
Wisconsin Volleyball Team Boobs Uncensored
Construction Management Jumpstart 3Rd Edition Pdf Free Download
Foolproof Module 6 Test Answers
Koninklijk Theater Tuschinski
Used Patio Furniture - Craigslist
Telegram Voyeur
How do you get noble pursuit?
Sandals Travel Agent Login
Harrison 911 Cad Log
Nurofen 400mg Tabletten (24 stuks) | De Online Drogist
Stouffville Tribune (Stouffville, ON), March 27, 1947, p. 1
Gus Floribama Shore Drugs
Pfcu Chestnut Street
Boneyard Barbers
Pnc Bank Routing Number Cincinnati
Gideon Nicole Riddley Read Online Free
Atlantic Broadband Email Login Pronto
Jennifer Reimold Ex Husband Scott Porter
Wattengel Funeral Home Meadow Drive
Smith And Wesson Nra Instructor Discount
Timberwolves Point Guard History
Firestone Batteries Prices
Senior Houses For Sale Near Me
Chubbs Canton Il
From Grindr to Scruff: The best dating apps for gay, bi, and queer men in 2024
Adams-Buggs Funeral Services Obituaries
Hughie Francis Foley – Marinermath
Meee Ruh
Latest Posts
Article information

Author: Domingo Moore

Last Updated:

Views: 6239

Rating: 4.2 / 5 (73 voted)

Reviews: 88% of readers found this page helpful

Author information

Name: Domingo Moore

Birthday: 1997-05-20

Address: 6485 Kohler Route, Antonioton, VT 77375-0299

Phone: +3213869077934

Job: Sales Analyst

Hobby: Kayaking, Roller skating, Cabaret, Rugby, Homebrewing, Creative writing, amateur radio

Introduction: My name is Domingo Moore, I am a attractive, gorgeous, funny, jolly, spotless, nice, fantastic person who loves writing and wants to share my knowledge and understanding with you.