CSC-MASTER-VER 6.0 CIS Critical Security Controls 10.15.2015

Embed Size (px)

Citation preview

  • 7/25/2019 CSC-MASTER-VER 6.0 CIS Critical Security Controls 10.15.2015

    1/94

    "#$ %&' %()*)+,- '$+.()*/ %01*(0-2

    30(

    433$+*)5$ %/6$( 7$3$12$

    !"#$%&' )*+

  • 7/25/2019 CSC-MASTER-VER 6.0 CIS Critical Security Controls 10.15.2015

    2/94

    "

    "#$ %$1*$( 30( &1*$(1$* '$+.()*/

    %()*)+,- '$+.()*/ %01*(0-2 30( 433$+*)5$ %/6$( 7$3$12$

    8$(2)01 9:;

    ? @;=>

    "#)2 A0(B )2 -)+$12$C .1C$( , %($,*)5$ %0DD012 E**()6.*)01FG01 %0DD$(+),-FG0 7$()5,*)5$2 H:;

    &1*$(1,*)01,- I.6-)+ J)+$12$: "#$ -)1B *0 *#$ -)+$12$ *$(D2 +,1 6$ 30.1C ,*#**K2LMM+($,*)5$+0DD012:0(NM-)+$12$2M6/F1+F1CMH:;M-$N,-+0C$

    "0 3.(*#$( +-,()3/ *#$ %($,*)5$ %0DD012 -)+$12$ ($-,*$C *0 *#$ %&' %()*)+,- '$+.()*/ %01*(0-2 +01*$1*? /0. ,($

    ,.*#0()O$C *0 +0K/ ,1C ($C)2*()6.*$ *#$ +01*$1* ,2 , 3(,D$A0(B 30( .2$ 6/ /0.? A)*#)1 /0.( 0(N,1)O,*)01 ,1C

    0.*2)C$ 03 /0.( 0(N,1)O,*)01 30( 101F+0DD$(+),- K.(K02$2 01-/? K(05)C$C *#,* P)Q ,KK(0K(),*$ +($C)* )2 N)5$1

    *0 %&'? ,1C P))Q , -)1B *0 *#$ -)+$12$ )2 K(05)C$C: ECC)*)01,--/? )3 /0. ($D)R? *(,1230(D 0( 6.)-C .K01 *#$ %&'

    %()*)+,- '$+.()*/ %01*(0-2? /0. D,/ 10* C)2*()6.*$ *#$ D0C)3)$C D,*$(),-2: S2$(2 03 *#$ %&' %()*)+,- '$+.()*/

    %01*(0-2 3(,D$A0(B ,($ ,-20 ($T.)($C *0 ($3$( *0 #**K2LMMAAA:+)2$+.()*/:0(NM+()*)+,-F+01*(0-2:+3DA#$1

    ($3$(()1N *0 *#$ %&' %()*)+,- '$+.()*/ %01*(0-2 )1 0(C$( *0 $12.($ *#,* .2$(2 ,($ $DK-0/)1N *#$ D02* .K *0 C,*$

    N.)C,1+$: %0DD$(+),- .2$ 03 *#$ %&' %()*)+,- '$+.()*/ %01*(0-2 )2 2.6U$+* *0 *#$ K()0( ,KK(05,- 03 "#$ %$1*$(

    30( &1*$(1$* '$+.()*/:

  • 7/25/2019 CSC-MASTER-VER 6.0 CIS Critical Security Controls 10.15.2015

    3/94

    ""

    "#$ %&' %()*)+,- '$+.()*/ %01*(0-2 30( 433$+*)5$ %/6$( 7$3$12$

    "#$%&'()$* +

    ,-, +. "#/0#$&%1 &2 3($4&%*50' 6#' 7#6($4&%*50' 80/*)09 :

    ,-, ;. "#/0#$&%1 &2 3($4&%*50' 6#' 7#6($4&%*50' -&2$. -0)(%0 ,*?(%6$* 2&% @6%'

    ,-, P. QK6*C 6#' G0B R%&>

    ,-, +O. 86$6 L0)&/0%1 ,6F6B*C*$1 >M

    ,-, ++. -0)(%0 ,*?(%6$* 2&% T0$. 86$6 N%&$0)$* IM

    ,-, +I. ,$%&CC0' 3))099 R690' $40 T00' $& V#&< I=

    ,-, +M. G*%0C099 3))099 ,$%&C M;

    ,-, +:. 3))&(#$ A*$&%*#? 6#' ,$%&C MM

    ,-, +P. -0)(%*$1 -H*CC9 399099K0#$ 6#' 3FF%&F%*6$0 W%6*#*#? $& U*CC X6F9 MS

    ,-, +S. 3FFC*)6$* -&2$

  • 7/25/2019 CSC-MASTER-VER 6.0 CIS Critical Security Controls 10.15.2015

    4/94

    """

    3FF0#'*Y 3. Q/&C/*#? 3# 3$$6)H A&'0C 2&% $40 ,"- ,%*$*)6C -0)(%*$1 ,$%&C9Z P;

    3FF0#'*Y R. 3$$6)H W1F09 PM

    3FF0#'*Y ,. W40 T"-W U%6K0

  • 7/25/2019 CSC-MASTER-VER 6.0 CIS Critical Security Controls 10.15.2015

    5/94

    #

    "#$%&'()$*

    V$ ,($ ,* , 3,2+)1,*)1N K0)1* )1 *#$ $50-.*)01 03 A#,* A$ 10A +,-- +/6$( C$3$12$: W,22)5$

    C,*, -022$2? *#$3* 03 )1*$--$+*.,- K(0K$(*/? +($C)* +,(C 6($,+#$2? )C$1*)*/ *#$3*? *#($,*2 *0 0.(

    K()5,+/? C$1),- 03 2$(5)+$ X *#$2$ #,5$ 6$+0D$ , A,/ 03 -)3$ 30( ,-- 03 .2 )1 +/6$(2K,+$:

    &(01)+,--/? ,2 C$3$1C$(2 A$ #,5$ ,++$22 *0 ,1 $R*(,0(C)1,(/ ,((,/ 03 2$+.()*/ *00-2 ,1C

    *$+#10-0N/? 2$+.()*/ 2*,1C,(C2? *(,)1)1N ,1C +-,22$2? +$(*)3)+,*)012? 5.-1$(,6)-)*/ C,*,6,2$2?

    N.)C,1+$? 6$2* K(,+*)+$2? +,*,-0N2 03 2$+.()*/ +01*(0-2? ,1C +0.1*-$22 2$+.()*/ +#$+B-)2*2?

    6$1+#D,(B2? ,1C ($+0DD$1C,*)012: "0 #$-K .2 .1C$(2*,1C *#$ *#($,*? A$Y5$ 2$$1 *#$

    $D$(N$1+$ 03 *#($,* )130(D,*)01 3$$C2? ($K0(*2? *00-2? ,-$(* 2$(5)+$2? 2*,1C,(C2? ,1C *#($,*

    2#,()1N 3(,D$A0(B2: "0 *0K )* ,-- 033? A$ ,($ 2.((0.1C$C 6/ 2$+.()*/ ($T.)($D$1*2? ()2B

    D,1,N$D$1* 3(,D$A0(B2? +0DK-),1+$ ($N)D$2? ($N.-,*0(/ D,1C,*$2? ,1C 20 30(*#: "#$($ )2

    10 2#0(*,N$ 03 )130(D,*)01 ,5,)-,6-$ *0 2$+.()*/ K(,+*)*)01$(2 01 A#,* *#$/ 2#0.-C C0 *0

    2$+.($ *#$)( )13(,2*(.+*.($:

    Z.* ,-- 03 *#)2 *$+#10-0N/? )130(D,*)01? ,1C 05$(2)N#* #,2 6$+0D$ , 5$()*,6-$ [\0N 03 W0($L]+0DK$*)1N 0K*)012? K()0()*)$2? 0K)1)012? ,1C +-,)D2 *#,* +,1 K,(,-/O$ 0( C)2*(,+* ,1

    $1*$(K()2$ 3(0D 5)*,- ,+*)01: Z.2)1$22 +0DK-$R)*/ )2 N(0A)1N? C$K$1C$1+)$2 ,($ $RK,1C)1N?.2$(2 ,($ 6$+0D)1N D0($ D06)-$? ,1C *#$ *#($,*2 ,($ $50-5)1N: G$A *$+#10-0N/ 6()1N2 .2

    N($,* 6$1$3)*2? 6.* )* ,-20 D$,12 *#,* 0.( C,*, ,1C ,KK-)+,*)012 ,($ 10A C)2*()6.*$C ,+(022

    D.-*)K-$ -0+,*)012? D,1/ 03 A#)+# ,($ 10* A)*#)1 0.( 0(N,1)O,*)01Y2 )13(,2*(.+*.($: &1 *#)2+0DK-$R? )1*$(+011$+*$C A0(-C? 10 $1*$(K()2$ +,1 *#)1B 03 )*2 2$+.()*/ ,2 , 2*,1C,-01$

    K(06-$D:

    '0 #0A +,1 A$ ,2 , +0DD.1)*/ X *#$ +0DD.1)*/F,*F-,(N$? ,2 A$-- ,2 A)*#)1 )1C.2*()$2?2$+*0(2? K,(*1$(2#)K2? ,1C +0,-)*)012 F 6,1C *0N$*#$( *0 $2*,6-)2# K()0()*/ 03 ,+*)01? 2.KK0(*

    $,+# 0*#$(? ,1C B$$K 0.( B10A-$CN$ ,1C *$+#10-0N/ +.(($1* )1 *#$ 3,+$ 03 , (,K)C-/

    $50-5)1N K(06-$D ,1C ,1 ,KK,($1*-/ )13)1)*$ 1.D6$( 03 K022)6-$ 20-.*)012^ V#,* ,($ *#$

    D02* +()*)+,- ,($,2 A$ 1$$C *0 ,CC($22 ,1C #0A 2#0.-C ,1 $1*$(K()2$ *,B$ *#$ 3)(2* 2*$K *0

    D,*.($ *#$)( ()2B D,1,N$D$1* K(0N(,D^ _,*#$( *#,1 +#,2$ $5$(/ 1$A $R+$K*)01,- *#($,*

    ,1C 1$N-$+* *#$ 3.1C,D$1*,-2? #0A +,1 A$ N$* 01 *(,+B A)*# , (0,CD,K 03 3.1C,D$1*,-2?

    ,1C N.)C,1+$ *0 D$,2.($ ,1C )DK(05$^V#)+# C$3$12)5$ 2*$K2 #,5$ *#$ N($,*$2* 5,-.$^

    "#$2$ ,($ *#$ B)1C2 03 )22.$2 *#,* -$C *0 ,1C 10A C()5$ *#$ %&' %()*)+,- '$+.()*/ %01*(0-2:

    "#$/ 2*,(*$C ,2 , N(,22F(00*2 ,+*)5)*/ *0 +.* *#(0.N# *#$ [\0N 03 W0($] ,1C 30+.2 01 *#$

    D02* 3.1C,D$1*,- ,1C 5,-.,6-$ ,+*)012 *#,* $5$(/ $1*$(K()2$ 2#0.-C *,B$: E1C /6C(0#$($

    )2 C$*$(D)1$C 6/ B10A-$CN$ ,1C C,*, X *#$ ,6)-)*/ *0 K($5$1*? ,-$(*? ,1C ($2K01C *0 *#$

    ,**,+B2 *#,* ,($ K-,N.)1N $1*$(K()2$2 *0C,/:

    J$C 6/ *#$ %$1*$( 30( &1*$(1$* '$+.()*/ P%&'Q? *#$ %&' %()*)+,- '$+.()*/ %01*(0-2 P[*#$

    %01*(0-2]Q #,5$ 6$$1 D,*.($C 6/ ,1 )1*$(1,*)01,- +0DD.1)*/ 03 )1C)5)C.,-2 ,1C

    )12*)*.*)012 *#,*L

  • 7/25/2019 CSC-MASTER-VER 6.0 CIS Critical Security Controls 10.15.2015

    6/94

    $

    2#,($ )12)N#* )1*0 ,**,+B2 ,1C ,**,+B$(2? )C$1*)3/ (00* +,.2$2? ,1C *(,12-,*$ *#,* )1*0

    +-,22$2 03 C$3$12)5$ ,+*)01`

    C0+.D$1* 2*0()$2 03 ,C0K*)01 ,1C 2#,($ *00-2 *0 20-5$ K(06-$D2`

    *(,+B *#$ $50-.*)01 03 *#($,*2? *#$ +,K,6)-)*)$2 03 ,C5$(2,()$2? ,1C +.(($1* 5$+*0(2 03

    )1*(.2)012`

    D,K *#$ %01*(0-2 *0 ($N.-,*0(/ ,1C +0DK-),1+$ 3(,D$A0(B2 ,1C 6()1N +0--$+*)5$K()0()*/ ,1C 30+.2 *0 *#$D`

    2#,($ *00-2? A0(B)1N ,)C2? ,1C *(,12-,*)012` ,1C

    )C$1*)3/ +0DD01 K(06-$D2 P-)B$ )1)*),- ,22$22D$1* ,1C )DK-$D$1*,*)01 (0,CD,K2Q

    ,1C 20-5$ *#$D ,2 , +0DD.1)*/ )12*$,C 03 ,-01$:

    "#$2$ ,+*)5)*)$2 $12.($ *#,* *#$ %01*(0-2 ,($ 10* U.2*

    ,10*#$( -)2* 03 N00C *#)1N2 *0 C0? 6.* , K()0()*)O$C?

    #)N#-/ 30+.2$C 2$* 03 ,+*)012 *#,* #,5$ , +0DD.1)*/

    2.KK0(* 1$*A0(B *0 D,B$ *#$D )DK-$D$1*,6-$? .2,6-$?

    2+,-,6-$? ,1C +0DK-),1* A)*# ,-- )1C.2*(/ 0( N05$(1D$1*

    2$+.()*/ ($T.)($D$1*2:

    G41 $40 ,"- ,%*$*)6C -0)(%*$1 ,$%&C9 G&%H.

    A0$4&'&C&?1 6#' ,$%*B($&%9

    "#$ %&' %()*)+,- '$+.()*/ %01*(0-2 ,($ )130(D$C 6/ ,+*.,-

    ,**,+B2 ,1C $33$+*)5$ C$3$12$2 ,1C ($3-$+* *#$ +0D6)1$C

    B10A-$CN$ 03 $RK$(*2 3(0D $5$(/ K,(* 03 *#$ $+02/2*$D

    P+0DK,1)$2? N05$(1D$1*2? )1C)5)C.,-2Q` A)*# $5$(/ (0-$ P*#($,* ($2K01C$(2 ,1C ,1,-/2*2?*$+#10-0N)2*2? 5.-1$(,6)-)*/F3)1C$(2? *00- D,B$(2? 20-.*)01 K(05)C$(2? C$3$1C$(2? .2$(2?

    K0-)+/FD,B$(2? ,.C)*0(2? $*+:Q` ,1C A)*#)1 D,1/ 2$+*0(2 PN05$(1D$1*? K0A$(? C$3$12$?3)1,1+$? *(,12K0(*,*)01? ,+,C$D),? +012.-*)1N? 2$+.()*/? &"Q A#0 #,5$ 6,1C$C *0N$*#$( *0

    +($,*$? ,C0K*? ,1C 2.KK0(* *#$ %01*(0-2: "0K $RK$(*2 3(0D 0(N,1)O,*)012 K00-$C *#$)(

    $R*$12)5$ 3)(2*F#,1C B10A-$CN$ 3(0D C$3$1C)1N ,N,)12* ,+*.,- +/6$(F,**,+B2 *0 $50-5$ *#$

    +012$12.2 -)2* 03 %01*(0-2? ($K($2$1*)1N *#$ 6$2* C$3$12)5$ *$+#1)T.$2 *0 K($5$1* 0( *(,+B

    *#$D: "#)2 $12.($2 *#,* *#$ %01*(0-2 ,($ *#$ D02* $33$+*)5$ ,1C 2K$+)3)+ 2$* 03 *$+#1)+,-

    D$,2.($2 ,5,)-,6-$ *0 C$*$+*? K($5$1*? ($2K01C? ,1C D)*)N,*$ C,D,N$ 3(0D *#$ D02*

    +0DD01 *0 *#$ D02* ,C5,1+$C 03 *#02$ ,**,+B2:

    "#$ %01*(0-2 ,($ 10* -)D)*$C *0 6-0+B)1N *#$ )1)*),- +0DK(0D)2$ 03 2/2*$D2? 6.* ,-20 ,CC($22

    C$*$+*)1N ,-($,C/F+0DK(0D)2$C D,+#)1$2 ,1C K($5$1*)1N 0( C)2(.K*)1N ,**,+B$(2Y 30--0AF

    01 ,+*)012: "#$ C$3$12$2 )C$1*)3)$C *#(0.N# *#$2$ %01*(0-2 C$,- A)*# ($C.+)1N *#$ )1)*),-,**,+B 2.(3,+$ 6/ #,(C$1)1N C$5)+$ +013)N.(,*)012? )C$1*)3/)1N +0DK(0D)2$C D,+#)1$2 *0

    ,CC($22 -01NF*$(D *#($,*2 )12)C$ ,1 0(N,1)O,*)01Y2 1$*A0(B? C)2(.K*)1N ,**,+B$(2Y

    +0DD,1CF,1CF+01*(0- 03 )DK-,1*$C D,-)+)0.2 +0C$? ,1C $2*,6-)2#)1N ,1 ,C,K*)5$?

    +01*)1.0.2 C$3$12$ ,1C ($2K012$ +,K,6)-)*/ *#,* +,1 6$ D,)1*,)1$C ,1C )DK(05$C:

    "#$ 3)5$ +()*)+,- *$1$*2 03 ,1 $33$+*)5$ +/6$( C$3$12$ 2/2*$D ,2 ($3-$+*$C )1 *#$ %&' %()*)+,-

    '$+.()*/ %01*(0-2 ,($L

    "#$ %$1*$( 30( &1*$(1$* '$+.()*/? &1+:

    P%&'Q )2 , >;=+a 101K(03)*

    0(N,1)O,*)01 A#02$ D)22)01 )2 *0

    )C$1*)3/? C$5$-0K? 5,-)C,*$? K(0D0*$?

    ,1C 2.2*,)1 6$2* K(,+*)+$2 )1 +/6$(

    2$+.()*/` C$-)5$( A0(-CF+-,22 +/6$(2$+.()*/ 20-.*)012 *0 K($5$1* ,1C

    (,K)C-/ ($2K01C *0 +/6$( )1+)C$1*2`

    ,1C 6.)-C ,1C -$,C +0DD.1)*)$2 *0

    $1,6-$ ,1 $15)(01D$1* 03 *(.2* )1

    +/6$(2K,+$:

    \0( ,CC)*)01,- )130(D,*)01? N0 *0

    b#**KLMMAAA:+)2$+.()*/:0(NM c

  • 7/25/2019 CSC-MASTER-VER 6.0 CIS Critical Security Controls 10.15.2015

    7/94

    %

    ,--"'$" %'-.$ /"-"'$"0 S2$ B10A-$CN$ 03 ,+*.,- ,**,+B2 *#,* #,5$

    +0DK(0D)2$C 2/2*$D2 *0 K(05)C$ *#$ 30.1C,*)01 *0 +01*)1.,--/ -$,(1 3(0D

    *#$2$ $5$1*2 *0 6.)-C $33$+*)5$? K(,+*)+,- C$3$12$2: &1+-.C$ 01-/ *#02$ +01*(0-2

    *#,* +,1 6$ 2#0A1 *0 2*0K B10A1 ($,-FA0(-C ,**,+B2:

    1#%%2%342%&'0&15$2* 3)(2* )1 %01*(0-2 *#,* A)-- K(05)C$ *#$ N($,*$2* ()2B($C.+*)01 ,1C K(0*$+*)01 ,N,)12* *#$ D02* C,1N$(0.2 *#($,* ,+*0(2 ,1C *#,*+,1 6$ 3$,2)6-/ )DK-$D$1*$C )1 /0.( +0DK.*)1N $15)(01D$1*:

    5"2#%6$0 42*,6-)2# +0DD01 D$*()+2 *0 K(05)C$ , 2#,($C -,1N.,N$ 30($R$+.*)5$2? &" 2K$+),-)2*2? ,.C)*0(2? ,1C 2$+.()*/ 033)+),-2 *0 D$,2.($ *#$

    $33$+*)5$1$22 03 2$+.()*/ D$,2.($2 A)*#)1 ,1 0(N,1)O,*)01 20 *#,* ($T.)($C,CU.2*D$1*2 +,1 6$ )C$1*)3)$C ,1C )DK-$D$1*$C T.)+B-/:

    7&'2%'8&8$ /%49'&$2%6$ 4'/ .%2%942%&'0 %,((/ 0.* +01*)1.0.2 D$,2.($D$1* *0

    *$2* ,1C 5,-)C,*$ *#$ $33$+*)5$1$22 03 +.(($1* 2$+.()*/ D$,2.($2 ,1C *0 #$-K

    C()5$ *#$ K()0()*/ 03 1$R* 2*$K2:

    :82&.42%&'0 E.*0D,*$ C$3$12$2 20 *#,* 0(N,1)O,*)012 +,1 ,+#)$5$ ($-),6-$?

    2+,-,6-$? ,1C +01*)1.0.2 D$,2.($D$1*2 03 *#$)( ,C#$($1+$ *0 *#$ %01*(0-2

    ,1C ($-,*$C D$*()+2:

    @&< $& X0$ -$6%$0'

    "#$ %&' %()*)+,- '$+.()*/ %01*(0-2 ,($ , ($-,*)5$-/ 2D,-- 1.D6$( 03 K()0()*)O$C? A$--F5$**$C?,1C 2.KK0(*$C 2$+.()*/ ,+*)012 *#,* 0(N,1)O,*)012 +,1 *,B$ *0 ,22$22 ,1C )DK(05$ *#$)(

    +.(($1* 2$+.()*/ 2*,*$: "#$/ ,-20 +#,1N$ *#$ C)2+.22)01 3(0D [A#,* 2#0.-C D/ $1*$(K()2$

    C0] *0 [A#,* 2#0.-C A$ EJJ 6$ C0)1N] *0 )DK(05$ 2$+.()*/ ,+(022 , 6(0,C 2+,-$:

    Z.* *#)2 )2 10* , 01$F2)O$F3)*2F,-- 20-.*)01? )1 $)*#$( +01*$1* 0( K()0()*/: d0. D.2* 2*)--.1C$(2*,1C A#,* )2 +()*)+,- *0 /0.( 6.2)1$22? C,*,? 2/2*$D2? 1$*A0(B2? ,1C )13(,2*(.+*.($2?

    ,1C /0. D.2* +012)C$( *#$ ,C5$(2,(/ ,+*)012 *#,* +0.-C )DK,+* /0.( ,6)-)*/ *0 6$ 2.++$223.-)1 *#$ 6.2)1$22 0( 0K$(,*)012: 45$1 , ($-,*)5$-/ 2D,-- 1.D6$( 03 %01*(0-2 +,110* 6$

    $R$+.*$C ,-- ,* 01+$? 20 /0. A)-- 1$$C *0 C$5$-0K , K-,1 30( ,22$22D$1*? )DK-$D$1*,*)01?

    ,1C K(0+$22 D,1,N$D$1*:

    %01*(0-2 %'% = *#(0.N# %'% > ,($ $22$1*),- *0 2.++$22 ,1C 2#0.-C 6$ +012)C$($C ,D01N *#$

    5$(/ 3)(2* *#)1N2 *0 6$ C01$: V$ ($3$( *0 *#$2$ ,2 [\0.1C,*)01,- %/6$( e/N)$1$] X *#$ 6,2)+*#)1N2 *#,* /0. D.2* C0 *0 +($,*$ , 2*(01N 30.1C,*)01 30( /0.( C$3$12$: "#)2 )2 *#$ ,KK(0,+#*,B$1 6/? 30( $R,DK-$? *#$ 7e' %01*)1.0.2 7),N102*)+ ,1C W)*)N,*)01 P%7WQ I(0N(,D? 01$

    03 *#$ K,(*1$(2 )1 *#$ %&' %()*)+,- '$+.()*/ %01*(0-2: E 2)D)-,( ,KK(0,+# )2 ($+0DD$1C$C 6/

    0.( K,(*1$(2 )1 *#$ E.2*(,-),1 ')N1,-2 7)($+*0(,*$ PE'7Q A)*# *#$)( ["0K \0.( '*(,*$N)$2 *0

  • 7/25/2019 CSC-MASTER-VER 6.0 CIS Critical Security Controls 10.15.2015

    8/94

    &

    W)*)N,*$ ",(N$*$C &1*(.2)012]=X , A$--F($N,(C$C ,1C C$D012*(,6-/ $33$+*)5$ 2$* 03 +/6$(F

    C$3$12$ ,+*)012 *#,* D,K 5$(/ +-02$-/ )1*0 *#$ %&' %()*)+,- '$+.()*/ %01*(0-2: "#)2 ,-20

    +-02$-/ +0(($2K01C2 *0 *#$ D$22,N$ 03 *#$ S' %4_" P%0DK.*$( 4D$(N$1+/ _$,C)1$22

    "$,DQ:

    \0( , K-,)1F-,1N.,N$? ,++$22)6-$? ,1C -0AF+02* ,KK(0,+# *0 *#$2$ )C$,2? +012)C$( *#$ %$1*$(30( &1*$(1$* '$+.()*/Y2 [ G,*)01,- %/6$( e/N)$1$ %,DK,)N1]: PEKK$1C)R 7 ,1C

    AAA:+)2$+.()*/:0(NQ

    W4*9 J0%9* &2 $40 ,"- ,%*$*)6C -0)(%*$1 ,$%&C9

    "#$ %01*(0-2 A$($ C$5$-0K$C 6,2$C 01 2K$+)3)+ B10A-$CN$ 03 *#$ *#($,* $15)(01D$1* ,2

    A$-- ,2 *#$ +.(($1* *$+#10-0N)$2 )1 *#$ D,(B$*K-,+$ .K01 A#)+# 0.( +0DD.1)+,*)012 ,1C

    C,*, ($-/:

  • 7/25/2019 CSC-MASTER-VER 6.0 CIS Critical Security Controls 10.15.2015

    9/94

    >

    "0 2.KK0(* *#)2? *#$ %$1*$( 30( &1*$(1$* '$+.()*/ ,+*2 ,2 , +,*,-/2* ,1C +-$,()1N#0.2$ *0 #$-K

    .2 ,-- -$,(1 3(0D $,+# 0*#$(: I-$,2$ +01*,+* *#$ %$1*$( 30( &1*$(1$* '$+.()*/ 30( *#$

    30--0A)1N B)1C2 03 A0(B)1N ,)C2 ,1C 0*#$( 2.KK0(* D,*$(),-2L

    W,KK)1N2 3(0D *#$ %01*(0-2 *0 , 5$(/ A)C$ 5,()$*/ 30( 30(D,- _)2B W,1,N$D$1*

    \(,D$A0(B2 P-)B$ \&'WE? &'

  • 7/25/2019 CSC-MASTER-VER 6.0 CIS Critical Security Controls 10.15.2015

    10/94

    ?

    ,-, +. "#/0#$&%1 &2 3($4&%*50' 6#' 7#6($4&%*50' 80/*)09

    !"#$ %& '( *+ ,+ -& .$, %& ,# /0 (1 #0 +"21 +, 3 "/0 0&"# 4 +' ' 5+ 036+ 0& 3& %$ "& 7 /, #5 &

    ,/02 7/ #5+# /,'( +8#5/0$9&3 3&%$"&7 +0& -$ %&, +""&771 +,3 8,+8#5/0$9&3 +,3

    8,*+,+-&3 3&%$"&7 +0& :/8,3 +,3 ;0&%&,#&3 :0/* -+$,$,- +""&77A Q."5(."5 .5 .//7( "5375(2;A 26 .== /A/(7:/ 825578(70 (2 ('7

    57(,2;E .50 ('7 57(,2;E 073"87/ ('7:/7=37/M ;782;0"51 .(=7./( ('7 57(,2;E .00;7//7/M :.8'"57 5.:7F/GM )4;)2/7 26

    7.8' /A/(7:M .5 .//7( 2,57; ;7/)25/"B=7 62; 7.8' 073"87M .50

    ('7 07).;(:75( .//28".(70 ,"(' 7.8' 073"87- R'7 "5375(2;A

    /'24=0 "58=407 737;A /A/(7: ('.( './ .5 I5(7;57( );2(282= FIJG

    .00;7// 25 ('7 57(,2;EM "58=40"51 B4( 52( =":"(70 (2 07/E(2)/M

    =.)(2)/M /7;37;/M 57(,2;E 7P4"):75( F;24(7;/M /,"(8'7/M

    6";7,.==/M 7(8-GM );"5(7;/M /(2;.17 .;7. 57(,2;E/M S2"87 T37;9IJ

    (7=7)'257/M :4=("9'2:70 .00;7//7/M 3";(4.= .00;7//7/M 7(8-

    R'7 .//7( "5375(2;A 8;7.(70 :4/( .=/2 "58=407 0.(. 25 ,'7('7;

    ('7 073"87 "/ . )2;(.B=7 .50+2; )7;/25.= 073"87- @73"87/ /48'

    ./ :2B"=7 )'257/M (.B=7(/M =.)(2)/M .50 2('7; )2;(.B=77=78(;25"8 073"87/ ('.( /(2;7 2; );287// 0.(. :4/( B7

    "075("6"70M ;71.;0=7// 26 ,'7('7; ('7A .;7 .((.8'70 (2 ('7

    2;1.5"C.("25D/ 57(,2;E-

    "-9*); $>B @7)=2A 57(,2;E =737= .4('75("8.("25 3". UV$-#< (2 =":"( .50

    825(;2= ,'"8' 073"87/ 8.5 B7 825578(70 (2 ('7 57(,2;E- R'7

    UV$-#< :4/( B7 ("70 "5(2 ('7 "5375(2;A 0.(. (2 07(7;:"57

    .4('2;"C70 37;/4/ 45.4('2;"C70 /A/(7:/-

    "-9*); $>C W/7 8="75( 87;("6"8.(7/ (2 3.="0.(7 .50 .4('75("8.(7 /A/(7:/

    );"2; (2 825578("51 (2 ('7 );"3.(7 57(,2;E-

    ,-, + N%&)0'(%09 6#' W&&C9

    "#)2 %01*(0- ($T.)($2 60*# *$+#1)+,- ,1C K(0+$C.(,- ,+*)012? .1)*$C )1 , K(0+$22 *#,*

    ,++0.1*2 30( ,1C D,1,N$2 *#$ )15$1*0(/ 03 #,(CA,($ ,1C ,-- ,220+),*$C )130(D,*)01

    *#(0.N#0.* )*2 -)3$ +/+-$: &* -)1B2 *0 6.2)1$22 N05$(1,1+$ 6/ $2*,6-)2#)1N )130(D,*)01M,22$*

    0A1$(2 A#0 ,($ ($2K012)6-$ 30( $,+# +0DK01$1* 03 , 6.2)1$22 K(0+$22 *#,* )1+-.C$2)130(D,*)01? 203*A,($? ,1C #,(CA,($:

  • 7/25/2019 CSC-MASTER-VER 6.0 CIS Critical Security Controls 10.15.2015

    12/94

    U

    K)1N K,+B$*2? )1 ,CC)*)01 *0 *(,C)*)01,- K)1N2? 2+,11$(2 +,1 ,-20 )C$1*)3/ C$5)+$2 01 *#$

    1$*A0(B .2)1N *(,12D)22)01 +01*(0- K(0*0+0- P"%IQ 2/1+#(01)O$ P'dGQ 0( ,+B10A-$CN$

    PE%jQ K,+B$*2:

  • 7/25/2019 CSC-MASTER-VER 6.0 CIS Critical Security Controls 10.15.2015

    13/94

  • 7/25/2019 CSC-MASTER-VER 6.0 CIS Critical Security Controls 10.15.2015

    14/94

    #V

    !"! ?% &'()'*+,- +. /0*1+,23)4 5'4 6'50*1+,23)4 "+.*D5,)

    "-9*); ?>? @7)=2A .))="8.("25 ,'"(7="/("51 ('.( .==2,/ /A/(7:/ (2 ;45

    /26(,.;7 25=A "6 "( "/ "58=4070 25 ('7 ,'"(7="/( .50 );7375(/

    7

  • 7/25/2019 CSC-MASTER-VER 6.0 CIS Critical Security Controls 10.15.2015

    15/94

    ##

    ,-, ; -19$0K Q#$*$1 L0C6$*^*F 8*6?%6K

    !""#$ &'(#'$)*+,-$-.-"#

    /)012$3'4 5+"$#0"

    5)6$7-*#

    &'(#'$)*+ 8))9

    5)6$7-*#

    :;3$#93"$3'4

    -$3)'

    5+"$#0

    !9#*$3'4 ? @#1)*$3'4 !'-9+$3A" 5+"$#0

  • 7/25/2019 CSC-MASTER-VER 6.0 CIS Critical Security Controls 10.15.2015

    16/94

    #$

    ,-, >. -0)(%0 ,*?(%6$* 2&% @6%'7#+?'$751 $*;'&*&,#1 +,3 +"#$%&'( *+,+-& .#0+"21 0&;/0# /,1 "/00&"#4 #5& 7&"80$#(

    "/,:$-80+#$/, /: '+;#/;71 7&0%&071 +,3 6/027#+#$/,7 87$,- + 0$-/0/87 "/,:$-80+#$/,

    *+,+-&*&,# +,3 "5+,-& "/,#0/' ;0/"&77 $, /03&0 #/ ;0&%&,# +##+"2&07 :0/*

    &=;'/$#$,- %8',&0+?'& 7&0%$"&7 +,3 7#$,-7? Z2==2, /(;"8( 8256"14;.("25 :.5.17:75(M B4"=0"51 . /784;7

    ":.17 ('.( "/ 4/70 (2 B4"=0 .== 57, /A/(7:/ ('.( .;7 07)=2A70 "5

    ('7 75(7;);"/7- [5A 7

  • 7/25/2019 CSC-MASTER-VER 6.0 CIS Critical Security Controls 10.15.2015

    18/94

    #&

    !"! @% ")80,) !+'.2E0,5*2+'9 .+, F5,4D5,) 5'4 "+.*D5,)

    [4(2:.("25 J;2(282= FYL[JG "5 2;07; (2 /(;7.:="57 ;7)2;("51

    .50 "5(71;.("25-

    "-9*); @>G @7)=2A /A/(7: 8256"14;.("25 :.5.17:75( (22=/M /48' ./ [8("37

    @";78(2;A b;24) J2="8A TB`78(/ 62; Q"8;2/26( a"502,/ /A/(7:/

    2; J4))7( 62; W]Ic /A/(7:/ ('.( ,"== .4(2:.("8.==A 7562;87 .50

    ;707)=2A 8256"14;.("25 /7(("51/ (2 /A/(7:/ .( ;714=.;=A

    /8'704=70 "5(7;3.=/- R'7A /'24=0 B7 8.).B=7 26 (;"117;"51

    ;707)=2A:75( 26 8256"14;.("25 /7(("51/ 25 . /8'704=70M

    :.54.=M 2; 7375(90;"375 B./"/-

    ,-, > N%&)0'(%09 6#' W&&C9

    _,*#$( *#,1 2*,(* 3(0D 2+(,*+# C$5$-0K)1N , 2$+.()*/ 6,2$-)1$ 30( $,+# 203*A,($ 2/2*$D?

    0(N,1)O,*)012 2#0.-C 2*,(* 3(0D K.6-)+-/ C$5$-0K$C? 5$**$C? ,1C 2.KK0(*$C 2$+.()*/

    6$1+#D,(B2? 2$+.()*/ N.)C$2? 0( +#$+B-)2*2: 4R+$--$1* ($20.(+$2 )1+-.C$L

    "#$ %$1*$( 30( &1*$(1$* '$+.()*/ Z$1+#D,(B2 I(0N(,D PAAA:+)2$+.()*/:0(NQ

    "#$ G&'" G,*)01,- %#$+B-)2* I(0N(,D P+#$+B-)2*2:1)2*:N05Q

  • 7/25/2019 CSC-MASTER-VER 6.0 CIS Critical Security Controls 10.15.2015

    19/94

    #>

    )2 )1)*),*$C? , *$DK0(,(/ 0( C/1,D)+ ,N$1* )2 C$K-0/$C 01 *#$ *,(N$* 2/2*$D 30( *#$ 2+,1?

    ,1C *#$1 *#$ ,N$1* )2 ($D05$C:

    ,-, > -19$0K Q#$*$1 L0C6$*^*F 8*6?%6K

    !"#$%&'() +,-&.#-

    /'0. 1(&.)2'&,

    3--.--#.(& 4/135

    +,-&.# 1#6).-

    7 86-.0'(.-

    +!39 !"(:')%26&'"(

    +;6((.2

    !"(:')%26&'"(

  • 7/25/2019 CSC-MASTER-VER 6.0 CIS Critical Security Controls 10.15.2015

    20/94

    #?

    ,-, I. ,$*#(&(9 J(C#0%6B*C*$1 399099K0#$ 6#' L0K0'*6$*

    @/,#$,8/87'( +"A8$0&1 +77&771 +,3 #+2& +"#$/, /, ,&6 $,:/0*+#$/, $, /03&0 #/

    $3&,#$:( %8',&0+?$'$#$&71 0&*&3$+#&1 +,3 *$,$*$9& #5& 6$,3/6 /: /;;/0#8,$#( :/0

    +##+"2&07G L2:).;7 ('7 ;7/4=(/ 6;2: B.8E9(29B.8E 34=57;.B"="(A /8.5/ (2

    37;"6A ('.( 34=57;.B"="("7/ ,7;7 .00;7//70M 7"('7; BA ).(8'"51M

    ":)=7:75("51 . 82:)75/.("51 825(;2=M 2; 0284:75("51 .50

    .887)("51 . ;7./25.B=7 B4/"57// ;"/E- Y48' .887)(.587 26

    B4/"57// ;"/E/ 62; 7

  • 7/25/2019 CSC-MASTER-VER 6.0 CIS Critical Security Controls 10.15.2015

    22/94

    #U

    !"! A% !+'*2'0+09 H0

  • 7/25/2019 CSC-MASTER-VER 6.0 CIS Critical Security Controls 10.15.2015

    23/94

    #X

    E2 5.-1$(,6)-)*)$2 ($-,*$C *0 .1K,*+#$C 2/2*$D2 ,($ C)2+05$($C 6/ 2+,11)1N *00-2? 2$+.()*/

    K$(2011$- 2#0.-C C$*$(D)1$ ,1C C0+.D$1* *#$ ,D0.1* 03 *)D$ *#,* $-,K2$2 6$*A$$1 *#$

    K.6-)+ ($-$,2$ 03 , K,*+# 30( *#$ 2/2*$D ,1C *#$ 0++.(($1+$ 03 *#$ 5.-1$(,6)-)*/ 2+,1: &3 *#)2

    *)D$ A)1C0A $R+$$C2 *#$ 0(N,1)O,*)01Y2 6$1+#D,(B2 30( C$K-0/D$1* 03 *#$ N)5$1 K,*+#Y2

    +()*)+,-)*/ -$5$-? 2$+.()*/ K$(2011$- 2#0.-C 10*$ *#$ C$-,/ ,1C C$*$(D)1$ )3 , C$5),*)01 A,2

    30(D,--/ C0+.D$1*$C 30( *#$ 2/2*$D ,1C )*2 K,*+#: &3 10*? *#$ 2$+.()*/ *$,D 2#0.-C A0(BA)*# D,1,N$D$1* *0 )DK(05$ *#$ K,*+#)1N K(0+$22:

    ECC)*)01,--/? 20D$ ,.*0D,*$C K,*+#)1N *00-2 D,/ 10* C$*$+* 0( )12*,-- +$(*,)1 K,*+#$2 C.$

    *0 ,1 $((0( 6/ *#$ 5$1C0( 0( ,CD)1)2*(,*0(: Z$+,.2$ 03 *#)2? ,-- K,*+# +#$+B2 2#0.-C

    ($+01+)-$ 2/2*$D K,*+#$2 A)*# , -)2* 03 K,*+#$2 $,+# 5$1C0( #,2 ,110.1+$C 01 )*2 A$62)*$:

    ,-, I -19$0K Q#$*$1 L0C6$*^*F 8*6?%6K

    !"#$%&'() +,-&.#-

    +!/0 1%2(.345'2'&,

    +64((.3

    04&67

    84(4).#.(&

    /2.3&'() 9 :.$"3&'() /(42,&'6- +,-&.#

  • 7/25/2019 CSC-MASTER-VER 6.0 CIS Critical Security Controls 10.15.2015

    24/94

    $V

    ,-, M. ,$%&CC0' 790 &2 3'K*#*9$%6$*/0 N%*/*C0?09

    B5& ;0/"&77&7 +,3 #//'7 87&3 #/ #0+"2C"/,#0/'C;0&%&,#C"/00&"# #5& 87&1 +77$ -,*&,#1

    +,3 "/,:$-80+#$/, /: +3*$,$7#0+#$%& ;0$%$'&-&7 /, "/*;8#&071 ,/0271 +,3

    +;;'$"+#$/,7C R'7 2;1.5"C.("25 /'.== :."5(."5 .50 7562;87 57(,2;E B./70

    W\^ 6"=(7;/ ('.( =":"( . /A/(7:e/ .B"="(A (2 825578( (2 ,7B/"(7/

    52( .));2370 BA ('7 2;1.5"C.("25- R'7 2;1.5"C.("25 /'.==

    /4B/8;"B7 (2 W\^ 8.(712;"C.("25 /7;3"87/ (2 75/4;7 ('.( ('7A

    .;7 4)9(290.(7 ,"(' ('7 :2/( ;7875( ,7B/"(7 8.(712;A076"5"("25/ .3."=.B=7- W58.(712;"C70 /"(7/ /'.== B7 B=28E70 BA

    076.4=(- R'"/ 6"=(7;"51 /'.== B7 7562;870 62; 7.8' 26 ('7

    2;1.5"C.("25e/ /A/(7:/M ,'7('7; ('7A .;7 )'A/"8.==A .( .5

    2;1.5"C.("25e/ 6.8"="("7/ 2; 52(-

    "-9*); G>G R2 =2,7; ('7 8'.587 26 /)22670 7:."= :7//.17/M ":)=7:75(

    ('7 Y7507; J2="8A Z;.:7,2;E FYJZG BA 07)=2A"51 YJZ ;782;0/ "5

    @]Y .50 75.B="51 ;787"37;9/"07 37;"6"8.("25 "5 :."= /7;37;/-

    "-9*); G>K Y8.5 .50 B=28E .== 7:."= .((.8':75(/ 75(7;"51 ('7

    2;1.5"C.("25e/ 7:."= 1.(7,.A "6 ('7A 825(."5 :.="8"24/ 8207 2;

    6"=7 (A)7/ ('.( .;7 455787//.;A 62; ('7 2;1.5"C.("25e/ B4/"57//-

    R'"/ /8.55"51 /'24=0 B7 0257 B762;7 ('7 7:."= "/ )=.870 "5 ('74/7;e/ "5B2

  • 7/25/2019 CSC-MASTER-VER 6.0 CIS Critical Security Controls 10.15.2015

    32/94

    $U

    %/6$(+()D)1,-2 +,1 $RK-0)* +00B)$2 )1 D,-)+)0.2 A,/2: %#,1N)1N /0.( 6(0A2$( 2$**)1N2 *0

    6-0+B *#)(C K,(*/ +00B)$2 A)-- #$-K ($C.+$ *#)2 ()2B: "#$ ,.*0+0DK-$*$ 0( ,.*03)-- 3$,*.($

    2,5$2 B$/2*(0B$2 6/ 2*0()1N )130(D,*)01 /0. ($+$1*-/ */K$C: e0A$5$(? ,.*0+0DK-$*$ 30(

    -0N)1 )130(D,*)01 K02$2 , 6)N ()2B )3 /0.( -,K*0K )2 -02* 0( 2*0-$1: E1C ($2*()+*)1N ,CCF012 *0

    ,1 ,620-.*$ D)1)D.D A)-- ($C.+$ *#$ ,**,+B 2.(3,+$: ECCF012 +,1 #,(60( D,-A,($ ,1C

    )1+($,2$ *#$ K022)6)-)*)$2 30( ,**,+B)1N /0.( 6(0A2$(: %013)N.($ /0.( 6(0A2$(2 *0 K($5$1**#$D 3(0D )12*,--)1N ,CCF012 A)*#0.* , K(0DK*:

    W02* K0K.-,( 6(0A2$(2 $DK-0/ , C,*,6,2$ 03 K#)2#)1N ,1CM0( D,-A,($ 2)*$2 *0 K(0*$+*

    ,N,)12* *#$ D02* +0DD01 *#($,*2: W,B$ 2.($ *#,* /0. ,1C /0.( .2$(2 $1,6-$ +01*$1* 3)-*$(2:

    E1C *.(1 01 *#$ K0K.K 6-0+B$(2: I0K.K2 ,($ 10* 01-/ ,110/)1N? *#$/ ,-20 +,1 #02*

    $D6$CC$C D,-A,($ C)($+*-/ 0( -.($ .2$(2 )1*0 +-)+B)1N 01 20D$*#)1N .2)1N 20+),-$1N)1$$()1N *()+B2: Z$ 2.($ *#,* /0.( 2$-$+*$C 6(0A2$( #,2 K0K.K 6-0+B)1N $1,6-$C

    QK6*C

    4D,)- ($K($2$1*2 01$ *#$ D02* )1*$(,+*)5$ A,/2 #.D,12 A0(B A)*# +0DK.*$(2?

    $1+0.(,N)1N *#$ ()N#* 6$#,5)0( )2 U.2* ,2 )DK0(*,1* ,2 *#$ *$+#1)+,- 2$**)1N2:

    I,22A0(C2 +01*,)1)1N +0DD01 A0(C2 0( K#(,2$2 ,($ $,2/ *0 +(,+B: 412.($ +0DK-$R

    K,22A0(C2 ,($ +($,*$C` , +0D6)1,*)01 03 -$**$(2? 1.D6$(2 ,1C 2K$+),- +#,(,+*$(2 )2 +0DK-$R

    $10.N#: I,22A0(C2 2#0.-C 6$ +#,1N$C 01 , ($N.-,( 6,2)2? $5$(/ H>F9; C,/2:

    &DK-$D$1*)1N *A0F3,+*0( ,.*#$1*)+,*)01 )2 ,10*#$( A,/ *0 $12.($ *#$ .2$( )2 ,.*#$1*)+?($C.+)1N *#$ ,**,+B 2.(3,+$: S2)1N , 2K,DF3)-*$()1N *00- ($C.+$2 *#$ 1.D6$( 03 D,-)+)0.2

    $D,)-2 *#,* +0D$ )1*0 /0.( 1$*A0(B: &1)*),*)1N , '$1C$( I0-)+/ \(,D$A0(B *0 5$()3/ *#,* *#$C0D,)1 ,1 $D,)- )2 +0D)1N 3(0D )2 ,.*#$1*)+? #$-K2 ($C.+$ 'K,D ,1C I#)2#)1N ,+*)5)*)$2:

    &12*,--)1N ,1 $1+(/K*)01 *00- *0 2$+.($ $D,)- ,1C +0DD.1)+,*)012 ,CC2 ,10*#$( -,/$( 03

    .2$( ,1C 1$*A0(B$C 6,2$C 2$+.()*/:

  • 7/25/2019 CSC-MASTER-VER 6.0 CIS Critical Security Controls 10.15.2015

    33/94

    $X

    ,-, P -19$0K Q#$*$1 L0C6$*^*F 8*6?%6K

    !"#$%&' )"*+,"-

    ./"+01 2 3"4%+01 .05/6#+,- 76-#"89%0:+1;&5#+%0

  • 7/25/2019 CSC-MASTER-VER 6.0 CIS Critical Security Controls 10.15.2015

    34/94

    %V

    ,-, S. A6C

  • 7/25/2019 CSC-MASTER-VER 6.0 CIS Critical Security Controls 10.15.2015

    35/94

    %#

    !"! K% N5A O5.B=7 .5("97C O5.B=7 02:."5 5.:7 /A/(7: F@]YG P47;A =211"51 (2 07(78(

    '2/(5.:7 =22E4) 62; E52,5 :.="8"24/ L$ 02:."5/-

    ,-, S N%&)0'(%09 6#' W&&C9

    "0 $12.($ ,1*)F5)(.2 2)N1,*.($2 ,($ .K *0 C,*$? 0(N,1)O,*)012 .2$ ,.*0D,*)01: "#$/ .2$ *#$

    6.)-*F)1 ,CD)1)2*(,*)5$ 3$,*.($2 03 $1*$(K()2$ $1CK0)1* 2$+.()*/ 2.)*$2 *0 5$()3/ *#,* ,1*)F

    5)(.2? ,1*)F2K/A,($? ,1C #02*F6,2$C &7' 3$,*.($2 ,($ ,+*)5$ 01 $5$(/ D,1,N$C 2/2*$D: "#$/

    (.1 ,.*0D,*$C ,22$22D$1*2 C,)-/ ,1C ($5)$A *#$ ($2.-*2 *0 3)1C ,1C D)*)N,*$ 2/2*$D2 *#,*

    #,5$ C$,+*)5,*$C 2.+# K(0*$+*)012? ,2 A$-- ,2 2/2*$D2 *#,* C0 10* #,5$ *#$ -,*$2* D,-A,($

    C$3)1)*)012:

    '0D$ $1*$(K()2$2 C$K-0/ 3($$ 0( +0DD$(+),- #01$/K0* ,1C [*,(K)*] *00-2 *0 )C$1*)3/

    ,**,+B$(2 )1 *#$)( $15)(01D$1*: '$+.()*/ K$(2011$- 2#0.-C +01*)1.0.2-/ D01)*0( *#$2$ *00-2

    *0 C$*$(D)1$ A#$*#$( *(,33)+ )2 C)($+*$C *0 *#$D ,1C ,++0.1* -0N)12 ,($ ,**$DK*$C: V#$1

    *#$/ )C$1*)3/ 2.+# $5$1*2? *#$2$ K$(2011$- 2#0.-C N,*#$( *#$ 20.(+$ ,CC($22 3(0D A#)+#*#)2 *(,33)+ 0()N)1,*$2 ,1C 0*#$( C$*,)-2 ,220+),*$C A)*# *#$ ,**,+B 30( 30--0AF01

    )15$2*)N,*)01:

  • 7/25/2019 CSC-MASTER-VER 6.0 CIS Critical Security Controls 10.15.2015

    36/94

    %$

    ,-, S -19$0K Q#$*$1 L0C6$*^*F 8*6?%6K

    !"#$%&'() +,-&.#-

    /.&0"12 345041.6.&.7&'"(

    8(9:"'(& :1"&.7&'"(

    +";&041. < 838=

    >5.1&'() < ?.$"1&'() >(45,&'7- +,-&.#

  • 7/25/2019 CSC-MASTER-VER 6.0 CIS Critical Security Controls 10.15.2015

    37/94

    %%

    ,-, =. E*K*$6$* 6#' ,$%&C &2 T0$B T)7;.(7 8;"("8.= /7;3"87/ 25 /7).;.(7 )'A/"8.= 2; =21"8.= '2/(

    :.8'"57/M /48' ./ @]YM 6"=7M :."=M ,7BM .50 0.(.B./7 /7;37;/-

    "-9*); M>C J=.87 .))="8.("25 6";7,.==/ "5 6;25( 26 .5A 8;"("8.= /7;37;/ (2

    37;"6A .50 3.="0.(7 ('7 (;.66"8 12"51 (2 ('7 /7;37;- [5A

    45.4('2;"C70 /7;3"87/ 2; (;.66"8 /'24=0 B7 B=28E70 .50 .5 .=7;(

    1757;.(70-

  • 7/25/2019 CSC-MASTER-VER 6.0 CIS Critical Security Controls 10.15.2015

    38/94

    %&

    ,-, = N%&)0'(%09 6#' W&&C9

    I0(* 2+,11)1N *00-2 ,($ .2$C *0 C$*$(D)1$ A#)+# 2$(5)+$2 ,($ -)2*$1)1N 01 *#$ 1$*A0(B 30( ,(,1N$ 03 *,(N$* 2/2*$D2: &1 ,CC)*)01 *0 C$*$(D)1)1N A#)+# K0(*2 ,($ 0K$1? $33$+*)5$ K0(*

    2+,11$(2 +,1 6$ +013)N.($C *0 )C$1*)3/ *#$ 5$(2)01 03 *#$ K(0*0+0- ,1C 2$(5)+$ -)2*$1)1N 01

    $,+# C)2+05$($C 0K$1 K0(*: "#)2 -)2* 03 2$(5)+$2 ,1C *#$)( 5$(2)012 ,($ +0DK,($C ,N,)12* ,1)15$1*0(/ 03 2$(5)+$2 ($T.)($C 6/ *#$ 0(N,1)O,*)01 30( $,+# 2$(5$( ,1C A0(B2*,*)01 )1 ,1

    ,22$* D,1,N$D$1* 2/2*$D: _$+$1*-/ ,CC$C 3$,*.($2 )1 *#$2$ K0(* 2+,11$(2 ,($ 6$)1N .2$C

    *0 C$*$(D)1$ *#$ +#,1N$2 )1 2$(5)+$2 033$($C 6/ 2+,11$C D,+#)1$2 01 *#$ 1$*A0(B 2)1+$ *#$

    K($5)0.2 2+,1? #$-K)1N 2$+.()*/ K$(2011$- )C$1*)3/ C)33$($1+$2 05$( *)D$:

    ,-, = -19$0K Q#$*$1 L0C6$*^*F 8*6?%6K

    !"#$%&'() +,-&.#-

    +!/0 1%2(.345'2'&,+64((.3

    7"-& 8 /$$2'64&'"(

    9'3.:422 +,-&.#-

    /2.3&'() 8 ;.$"3&'() /(42,&'6- +,-&.#

  • 7/25/2019 CSC-MASTER-VER 6.0 CIS Critical Security Controls 10.15.2015

    39/94

    %>

    ,-, +O. 86$6 L0)&/0%1 ,6F6B*C*$1

    B5& ;0/"&77&7 +,3 #//'7 87&3 #/ ;0/;&0'( ?+"2 8; "0$#$"+' $,:/0*+#$/, 6$ #5 + ;0/%&,

    */3/'/-( :/0 #$*&'( 0&"/%&0( /: $#C ]7(,2;E 751"577;/ /'.== 4/7 . 070"8.(70 :.8'"57 62; .==.0:"5"/(;.("37 (./E/ 2; (./E/ ;7P4";"51 7=73.(70 .887//- R'"/

    :.8'"57 /'.== B7 "/2=.(70 6;2: ('7 2;1.5"C.("25e/ );":.;A

    57(,2;E .50 52( B7 .==2,70 I5(7;57( .887//- R'"/ :.8'"57

    /'.== 52( B7 4/70 62; ;7.0"51 7:."=M 82:)2/"51 0284:75(/M 2;

    /4;6"51 ('7 I5(7;57(-

    T)*D+,U $$>G Q.5.17 ('7 57(,2;E "56;./(;48(4;7 .8;2// 57(,2;E

    825578("25/ ('.( .;7 /7).;.(70 6;2: ('7 B4/"57// 4/7 26 ('.(

    57(,2;EM ;7=A"51 25 /7).;.(7 S^[]/ 2;M );767;.B=AM 25 75(";7=A

    0"667;75( )'A/"8.= 825578("3"(A 62; :.5.17:75( /7//"25/ 62;

    57(,2;E 073"87/-

    ,-, ++ N%&)0'(%09 6#' W&&C9

    '0D$ 0(N,1)O,*)012 .2$ +0DD$(+),- *00-2 *#,* $5,-.,*$ *#$ (.-$ 2$* 03 1$*A0(B 3)-*$()1N

    C$5)+$2 *0 C$*$(D)1$ A#$*#$( *#$/ ,($ +012)2*$1* 0( )1 +013-)+*? K(05)C)1N ,1 ,.*0D,*$C2,1)*/ +#$+B 03 1$*A0(B 3)-*$(2 ,1C 2$,(+# 30( $((0(2 )1 (.-$ 2$*2 0( ,++$22 +01*(0-2 -)2*2

    PE%J2Q *#,* D,/ ,--0A .1)1*$1C$C 2$(5)+$2 *#(0.N# *#$ C$5)+$: '.+# *00-2 2#0.-C 6$ (.1

    $,+# *)D$ 2)N1)3)+,1* +#,1N$2 ,($ D,C$ *0 3)($A,-- (.-$ 2$*2? (0.*$( E%J2? 0( 0*#$( 3)-*$()1N

    *$+#10-0N)$2:

  • 7/25/2019 CSC-MASTER-VER 6.0 CIS Critical Security Controls 10.15.2015

    43/94

    %X

    ,-, ++ -19$0K Q#$*$1 L0C6$*^*F 8*6?%6K

    !"#$%&' )"*+,"

    -./.0"1"/# 234#"1

    !"#$%&' )"*+,"4

    56"+/0 7 8"9%+/0 5/.63#+,4 234#"1

    )":+,.#":

    5:1+/+4#&.#+%/ 234#"14

    5;#

  • 7/25/2019 CSC-MASTER-VER 6.0 CIS Critical Security Controls 10.15.2015

    44/94

    &V

    ,-, +;. R&(#'6%1 8020#90

    E&"#C;0&%&,#C"/00&"# #5& :'/6 /: $,:/0*+#$/, #0+,7:&00$,- ,/027 /: 3$::&0&,#

    #087# '&%&'7 6$#5 + :/"87 /, 7&"80$#(F3+*+-$,- 3+#+K J7;"20"8.==A /8.5 62; B.8E98'.557= 825578("25/ (2 ('7 I5(7;57(

    ('.( BA).// ('7 @QdM "58=40"51 45.4('2;"C70 SJ] 825578("25/

    .50 04.=9'2:70 '2/(/ 825578(70 (2 ('7 75(7;);"/7 57(,2;E

    .50 (2 2('7; 57(,2;E/ 3". ,";7=7//M 0".=94) :207:/M 2; 2('7;

    :78'.5"/:/-

    T)*D+,U $?>M @7)=2A ]7(Z=2, 82==78("25 .50 .5.=A/"/ (2 @Qd 57(,2;E 6=2,/(2 07(78( .52:.=24/ .8("3"(A-

    T)*D+,U $?>$V R2 '7=) "075("6A 8237;( 8'.557=/ 7

  • 7/25/2019 CSC-MASTER-VER 6.0 CIS Critical Security Controls 10.15.2015

    47/94

    &%

    *#$ 1$*A0(B ,1C K(0*$+*)1N $,+# 2$ND$1* A)*# , K(0R/ ,1C , 3)($A,-- A)-- N($,*-/ ($C.+$ ,1

    )1*(.C$(Y2 ,++$22 *0 *#$ 0*#$( K,(*2 03 *#$ 1$*A0(B:

  • 7/25/2019 CSC-MASTER-VER 6.0 CIS Critical Security Controls 10.15.2015

    48/94

    &&

    ,-, +; -19$0K Q#$*$1 L0C6$*^*F 8*6?%6K

    !"#$%&' )"*+,"-

    !"#$%&' .%/+#%&+/0

    12-#"3- 45)1 6 5718

    9:#;"/#+,

  • 7/25/2019 CSC-MASTER-VER 6.0 CIS Critical Security Controls 10.15.2015

    49/94

    &>

    ,-, +>. 86$6 N%&$0)$*

    B5& ;0/"&77&7 +,3 #//'7 87&3 #/ ;0&%&,# 3+#+ &=:$'#0+#$/,1 *$#$-+#& #5& &::&"#7 /:

    &=:$'#0+#&3 3+#+1 +,3 &,780& #5& ;0$%+"( +,3 $,#&-0$#( /: 7&,7$#$%& $,:/0*+#$/,h:

    %,($ 2#0.-C ,-20 6$ *,B$1 *0 $12.($ *#,* K(0C.+*2 .2$C A)*#)1 ,1 $1*$(K()2$ )DK-$D$1*A$-- B10A1 ,1C 5$**$C +(/K*0N(,K#)+ ,-N0()*#D2? ,2 )C$1*)3)$C 6/ G&'": _$F$5,-.,*)01 03

    *#$ ,-N0()*#D2 ,1C B$/ 2)O$2 .2$C A)*#)1 *#$ $1*$(K()2$ 01 ,1 ,11.,- 6,2)2 )2 ,-20($+0DD$1C$C *0 $12.($ *#,* 0(N,1)O,*)012 ,($ 10* 3,--)1N 6$#)1C )1 *#$ 2*($1N*# 03

    K(0*$+*)01 ,KK-)$C *0 *#$)( C,*,:

    \0( 0(N,1)O,*)012 *#,* ,($ D05)1N C,*, *0 *#$ +-0.C? )* )2 )DK0(*,1* *0 .1C$(2*,1C *#$2$+.()*/ +01*(0-2 ,KK-)$C *0 C,*, )1 *#$ +-0.C D.-*)F*$1,1* $15)(01D$1*? ,1C C$*$(D)1$ *#$6$2* +0.(2$ 03 ,+*)01 30( ,KK-)+,*)01 03 $1+(/K*)01 +01*(0-2 ,1C 2$+.()*/ 03 B$/2: V#$1

    K022)6-$? B$/2 2#0.-C 6$ 2*0($C A)*#)1 2$+.($ +01*,)1$(2 2.+# ,2 e,(CA,($ '$+.()*/

    W0C.-$2 Pe'W2Q:

    41+(/K*)1N C,*, K(05)C$2 , -$5$- 03 ,22.(,1+$ *#,* $5$1 )3 C,*, )2 +0DK(0D)2$C? )* )2

    )DK(,+*)+,- *0 ,++$22 *#$ K-,)1*$R* A)*#0.* 2)N1)3)+,1* ($20.(+$2? #0A$5$( +01*(0-2 2#0.-C

    ,-20 6$ K.* )1 K-,+$ *0 D)*)N,*$ *#$ *#($,* 03 C,*, $R3)-*(,*)01 )1 *#$ 3)(2* K-,+$: W,1/ ,**,+B20++.(($C ,+(022 *#$ 1$*A0(B? A#)-$ 0*#$(2 )150-5$C K#/2)+,- *#$3* 03 -,K*0K2 ,1C 0*#$(

    $T.)KD$1* #0-C)1N 2$12)*)5$ )130(D,*)01: d$*? )1 D02* +,2$2? *#$ 5)+*)D2 A$($ 10* ,A,($

    *#,* *#$ 2$12)*)5$ C,*, A$($ -$,5)1N *#$)( 2/2*$D2 6$+,.2$ *#$/ A$($ 10* D01)*0()1N C,*,0.*3-0A2: "#$ D05$D$1* 03 C,*, ,+(022 1$*A0(B 60.1C,()$2 60*# $-$+*(01)+,--/ ,1C

    K#/2)+,--/ D.2* 6$ +,($3.--/ 2+(.*)1)O$C *0 D)1)D)O$ )*2 $RK02.($ *0 ,**,+B$(2:

    "#$ -022 03 +01*(0- 05$( K(0*$+*$C 0( 2$12)*)5$ C,*, 6/ 0(N,1)O,*)012 )2 , 2$()0.2 *#($,* *0

    6.2)1$22 0K$(,*)012 ,1C , K0*$1*),- *#($,* *0 1,*)01,- 2$+.()*/: V#)-$ 20D$ C,*, ,($ -$,B$C

    0( -02* ,2 , ($2.-* 03 *#$3* 0( $2K)01,N$? *#$ 5,2* D,U0()*/ 03 *#$2$ K(06-$D2 ($2.-* 3(0D

    K00(-/ .1C$(2*00C C,*, K(,+*)+$2? , -,+B 03 $33$+*)5$ K0-)+/ ,(+#)*$+*.($2? ,1C .2$( $((0(:

  • 7/25/2019 CSC-MASTER-VER 6.0 CIS Critical Security Controls 10.15.2015

    50/94

    &?

    7,*, -022 +,1 $5$1 0++.( ,2 , ($2.-* 03 -$N)*)D,*$ ,+*)5)*)$2 2.+# ,2 $F7)2+05$(/ C.()1N

    -)*)N,*)01? K,(*)+.-,(-/ A#$1 ($+0(C2 ($*$1*)01 K(,+*)+$2 ,($ )1$33$+*)5$ 0( 101$R)2*$1*:

    7,*, -022 K($5$1*)01 P7JIQ ($3$(2 *0 , +0DK($#$12)5$ ,KK(0,+# +05$()1N K$0K-$? K(0+$22$2?

    ,1C 2/2*$D2 *#,* )C$1*)3/? D01)*0(? ,1C K(0*$+* C,*, )1 .2$ P$:N:? $1CK0)1* ,+*)012Q? C,*, )1

    D0*)01 P$:N:? 1$*A0(B ,+*)012Q? ,1C C,*, ,* ($2* P$:N:? C,*, 2*0(,N$Q *#(0.N# C$$K +01*$1*)12K$+*)01 ,1C A)*# , +$1*(,-)O$C D,1,N$D$1* 3(,D$A0(B: @ @7)=2A .5 .4(2:.(70 (22= 25 57(,2;E )7;":7(7;/ ('.(

    :25"(2;/ 62; /75/"("37 "562;:.("25 F7-1-M )7;/25.==A "075("6".B=7

    "562;:.("25GM E7A,2;0/M .50 2('7; 0284:75( 8'.;.8(7;"/("8/ (2

    0"/8237; 45.4('2;"C70 .((7:)(/ (2 7B I6 ('7;7 "/ 52 B4/"57// 5770 62; /4))2;("51 /48' 073"87/M

    8256"14;7 /A/(7:/ /2 ('.( ('7A ,"== 52( ,;"(7 0.(. (2 WYH

    (2E75/ 2; WYH '.;0 0;"37/- I6 /48' 073"87/ .;7 ;7P4";70M

    75(7;);"/7 /26(,.;7 /'24=0 B7 4/70 ('.( 8.5 8256"14;7 /A/(7:/

    (2 .==2, 25=A /)78"6"8 WYH 073"87/ FB./70 25 /7;".= 54:B7; 2;

    2('7; 45"P47 );2)7;(AG (2 B7 .887//70M .50 ('.( 8.5

    .4(2:.("8.==A 758;A)( .== 0.(. )=.870 25 /48' 073"87/- [5

    "5375(2;A 26 .== .4('2;"C70 073"87/ :4/( B7 :."5(."570-

  • 7/25/2019 CSC-MASTER-VER 6.0 CIS Critical Security Controls 10.15.2015

    51/94

    &N

    !"! $@% 75*5 L,+*)8*2+'

    T)*D+,U $@>C W/7 57(,2;E9B./70 @^J /2=4("25/ (2 :25"(2; .50 825(;2= ('7

    6=2, 26 0.(. ,"('"5 ('7 57(,2;E- [5A .52:.="7/ ('.( 7M W/7 '2/(9B./70 0.(. =2// );7375("25 F@^JG (2 7562;87 [L^/

    7375 ,'75 0.(. "/ 82)"70 266 . /7;37;- I5 :2/( 2;1.5"C.("25/M

    .887// (2 ('7 0.(. "/ 825(;2==70 BA [L^/ ('.( .;7 ":)=7:75(70

    25 ('7 /7;37;- T587 ('7 0.(. '.37 B775 82)"70 (2 . 07/E(2)

    /A/(7:M ('7 [L^/ .;7 52 =2517; 7562;870 .50 ('7 4/7;/ 8.5

    /750 ('7 0.(. (2 ,'2:737; ('7A ,.5(-

    ,-, +> N%&)0'(%09 6#' W&&C9

    %0DD$(+),- *00-2 ,($ ,5,)-,6-$ *0 2.KK0(* $1*$(K()2$ D,1,N$D$1* 03 $1+(/K*)01 ,1C B$/

    D,1,N$D$1* A)*#)1 ,1 $1*$(K()2$ ,1C )1+-.C$ *#$ ,6)-)*/ *0 2.KK0(* )DK-$D$1*,*)01 03

    $1+(/K*)01 +01*(0-2 A)*#)1 +-0.C ,1C D06)-$ $15)(01D$1*2:

    7$3)1)*)01 03 -)3$ +/+-$ K(0+$22$2 ,1C (0-$2 ,1C ($2K012)6)-)*)$2 ,220+),*$C A)*# B$/

    D,1,N$D$1* 2#0.-C 6$ .1C$(*,B$1 6/ $,+# 0(N,1)O,*)01:

    %0DD$(+),- 7JI 20-.*)012 ,($ ,5,)-,6-$ *0 -00B 30( $R3)-*(,*)01 ,**$DK*2 ,1C C$*$+* 0*#$(

    2.2K)+)0.2 ,+*)5)*)$2 ,220+),*$C A)*# , K(0*$+*$C 1$*A0(B #0-C)1N 2$12)*)5$ )130(D,*)01:

  • 7/25/2019 CSC-MASTER-VER 6.0 CIS Critical Security Controls 10.15.2015

    52/94

    &U

    ,-, +> Q#$*$1 L0C6$*^*F 8*6?%6K

    !"#$%&' ) *%+# ,-+".

    /01

    234&56#7%3

    85+#"9+ !"#$%&' /":74"+

    23.1%73# 1&%#"4#7%3 ;

  • 7/25/2019 CSC-MASTER-VER 6.0 CIS Critical Security Controls 10.15.2015

    53/94

    &X

    ,-, +I. ,$%&CC0' 3))099 R690' $40 T00' $& V#

    ,-, +I -19$0K Q#$*$1 L0C6$*^*F 8*6?%6K

    !"#$ &'#() *'$' +"##

    ,-(.(/$0"/ 1*+,2

    3/4-56$0"/

    75#$(8#

    9($:"-; *(.04(#

    ? @(6"-$0/>

  • 7/25/2019 CSC-MASTER-VER 6.0 CIS Critical Security Controls 10.15.2015

    56/94

    >$

    ,-, +M. G*%0C099 3))099 ,$%&C

    B5& ;0/"&77&7 +,3 #//'7 87&3 #/ #0+"2C"/,#0/'C;0&%&,#C"/00&"# #5& 7&"80$#( 87& /:

    6$0&'&77 '/"+' +0&+ ,/027 .G!HI41 +""&77 ;/$,#71 +,3 6$0&'&77 "'$&,# 7(7#&*7@ W/7 ,";7=7// "5(;4/"25 07(78("25 /A/(7:/ FaI@YG (2 "075("6A

    ;2147 ,";7=7// 073"87/ .50 07(78( .((.8E .((7:)(/ .50

    /4887//64= 82:);2:"/7/- I5 .00"("25 (2 aI@YM .== ,";7=7//

    (;.66"8 /'24=0 B7 :25"(2;70 BA aI@Y ./ (;.66"8 ).//7/ "5(2 ('7

    ,";70 57(,2;E-

    T)*D+,U $B>A a'7;7 . /)78"6"8 B4/"57// 5770 62; ,";7=7// .887// './ B775

    "075("6"70M 8256"14;7 ,";7=7// .887// 25 8="75( :.8'"57/ (2

    .==2, .887// 25=A (2 .4('2;"C70 ,";7=7// 57(,2;E/- Z2; 073"87/

    ('.( 02 52( '.37 .5 7//75(".= ,";7=7// B4/"57// )4;)2/7M

    0"/.B=7 ,";7=7// .887// "5 ('7 '.;0,.;7 8256"14;.("25 FB./"8

    "5)4(+24()4( /A/(7: 2; 7

  • 7/25/2019 CSC-MASTER-VER 6.0 CIS Critical Security Controls 10.15.2015

    57/94

    >%

    !"! $B% R2,)C O5/4;7 ('.( ,";7=7// 57(,2;E/ 4/7 .4('75("8.("25 );2(282=/

    /48' ./ OK @"/.B=7 ,";7=7// )7;")'7;.= .887// 26 073"87/ F/48' ./

    H=47(22('GM 45=7// /48' .887// "/ ;7P4";70 62; . 0284:75(70

    B4/"57// 5770-

    T)*D+,U $B>M L;7.(7 /7).;.(7 3";(4.= =28.= .;7. 57(,2;E/ FS^[]/G 62; HiT@

    /A/(7:/ 2; 2('7; 45(;4/(70 073"87/- I5(7;57( .887// 6;2: ('"/

    S^[] /'24=0 12 (';241' .( =7./( ('7 /.:7 B2;07; ./ 82;)2;.(7(;.66"8- O5(7;);"/7 .887// 6;2: ('"/ S^[] /'24=0 B7 (;7.(70 ./

    45(;4/(70 .50 6"=(7;70 .50 .40"(70 .882;0"51=A-

    ,-, +M N%&)0'(%09 6#' W&&C9

    433$+*)5$ 0(N,1)O,*)012 (.1 +0DD$(+),- A)($-$22 2+,11)1N? C$*$+*)01? ,1C C)2+05$(/ *00-2 ,2

    A$-- ,2 +0DD$(+),- A)($-$22 )1*(.2)01 C$*$+*)01 2/2*$D2:

    ECC)*)01,--/? *#$ 2$+.()*/ *$,D 2#0.-C K$()0C)+,--/ +,K*.($ A)($-$22 *(,33)+ 3(0D A)*#)1 *#$

    60(C$(2 03 , 3,+)-)*/ ,1C .2$ 3($$ ,1C +0DD$(+),- ,1,-/2)2 *00-2 *0 C$*$(D)1$ A#$*#$( *#$

    A)($-$22 *(,33)+ A,2 *(,12D)**$C .2)1N A$,B$( K(0*0+0-2 0( $1+(/K*)01 *#,1 *#$

    0(N,1)O,*)01 D,1C,*$2: V#$1 C$5)+$2 ($-/)1N 01 A$,B A)($-$22 2$+.()*/ 2$**)1N2 ,($

    )C$1*)3)$C? *#$/ 2#0.-C 6$ 30.1C A)*#)1 *#$ 0(N,1)O,*)01Y2 ,22$* )15$1*0(/ ,1C $)*#$(

    ($+013)N.($C D0($ 2$+.($-/ 0( C$1)$C ,++$22 *0 *#$ 0(N,1)O,*)01 1$*A0(B:

    ECC)*)01,--/? *#$ 2$+.()*/ *$,D 2#0.-C $DK-0/ ($D0*$ D,1,N$D$1* *00-2 01 *#$ A)($C

    1$*A0(B *0 K.-- )130(D,*)01 ,60.* *#$ A)($-$22 +,K,6)-)*)$2 ,1C C$5)+$2 +011$+*$C *0

    D,1,N$C 2/2*$D2:

  • 7/25/2019 CSC-MASTER-VER 6.0 CIS Critical Security Controls 10.15.2015

    58/94

    >&

    ,-, +M -19$0K Q#$*$1 L0C6$*^*F 8*6?%6K

    !"#$%&'() +,-&.#-

    +!/0 1%2(.345'2'&,

    +64((.3

    !"(7')%34&'"(

    8(7"36.#.(& +,-&.#

    9'3.2.-- :(&3%-'"(

    ;.&.6&'"( +,-&.#

  • 7/25/2019 CSC-MASTER-VER 6.0 CIS Critical Security Controls 10.15.2015

    59/94

    >>

    ,-, +:. 3))&(#$ A*$&%*#? 6#' ,$%&C

    !"#$ %& '( *+ ,+ -& #5 & '$ :& "("' & /: 7( 7# &* +, 3 +; ;' $"+ #$ /, +" "/ 8, #7 J #5& $0 "0 &+#$/ ,1

    87&1 3/0*+,"(1 3&'$/, F $, /03&0 #/ *$,$*$9& /;;/0#8,$#$&7 :/0 +##+"2&07 #/

    '&%&0+-& #5&*?

    !"! $C% /88+0'* N+'2*+,2'E 5'4 !+'*,+X

    !"! $G% ")80,2*- "U2@I:)=7:75( . /784;"(A .,.;757// );21;.: ('.( F#G 6284/7/

    25 ('7 :7('20/ 82::25=A 4/70 "5 "5(;4/"25/ ('.( 8.5 B7

    B=28E70 (';241' "50"3"04.= .8("25M F$G "/ 07="37;70 "5 /'2;(

    25="57 :204=7/ 825375"75( 62; 7:)=2A77/ F%G "/ 4)0.(70

    6;7P475(=A F.( =7./( .554.==AG (2 ;7);7/75( ('7 =.(7/( .((.8E

    (78'5"P47/M F&G "/ :.50.(70 62; 82:)=7("25 BA .== 7:)=2A77/

    .( =7./( .554.==AM F>G "/ ;7=".B=A :25"(2;70 62; 7:)=2A77

    82:)=7("25M .50 ?G "58=407/ ('7 /75"2; =7.07;/'") (7.:D/)7;/25.= :7//.1"51M "532=37:75( "5 (;."5"51M .50

    .88245(.B"="(A (';241' )7;62;:.587 :7(;"8/-

    /==

  • 7/25/2019 CSC-MASTER-VER 6.0 CIS Critical Security Controls 10.15.2015

    64/94

    ?V

    )C$1*)3/ *#$2$ D)22)01F+()*)+,- U062 )2 *0 ($3$($1+$ *#$ A0(B 03 *#$ @;=@ ",2B \0(+$ 01

    %/6$( 'B)--2 $2*,6-)2#$C 6/ *#$ '$+($*,(/ 03 e0D$-,1C '$+.()*/L =Q '/2*$D ,1C G$*A0(B

    I$1$*(,*)01 "$2*$(2? @Q EKK-)+,*)01 I$1$*(,*)01 "$2*$(2? aQ '$+.()*/ W01)*0()1N ,1C 45$1*

    E1,-/2*2? HQ &1+)C$1* _$2K01C$(2 &1F7$K*#? >Q %0.1*$(F&1*$--)N$1+$M&12)C$( "#($,*

    E1,-/2*2? 9Q _)2B E22$22D$1* 41N)1$$(2? hQ '$+.($ %0C$(2 ,1C %0C$ _$5)$A$(2? kQ '$+.()*/

    41N)1$$(2ME(+#)*$+*.($ ,1C 7$2)N1? gQ '$+.()*/ 41N)1$$(2M

  • 7/25/2019 CSC-MASTER-VER 6.0 CIS Critical Security Controls 10.15.2015

    65/94

    ?#

    ,-, +P -19$0K Q#$*$1 L0C6$*^*F 8*6?%6K

    !"#$ &""#""'#()"

    *+,-.)/0( 12.(" 3

    4$./(/(5 1$05$.'"

    60$780$-#

    9#':#$"

    &2#$)/(5 3 ;#

  • 7/25/2019 CSC-MASTER-VER 6.0 CIS Critical Security Controls 10.15.2015

    66/94

    ?$

    ,-, +S. 3FFC*)6$* -&2$

  • 7/25/2019 CSC-MASTER-VER 6.0 CIS Critical Security Controls 10.15.2015

    67/94

    ?%

    !"! $K% /==? J;2(78( ,7B .))="8.("25/ BA 07)=2A"51 ,7B .))="8.("25

    6";7,.==/ Fa[Z/G ('.( "5/)78( .== (;.66"8 6=2,"51 (2 ('7 ,7B

    .))="8.("25 62; 82::25 ,7B .))="8.("25 .((.8E/M "58=40"51

    B4( 52( =":"(70 (2 8;2//9/"(7 /8;")("51M Yj^ "5`78("25M

    82::.50 "5`78("25M .50 0";78(2;A (;.37;/.= .((.8E/- Z2;

    .))="8.("25/ ('.( .;7 52( ,7B9B./70M /)78"6"8 .))="8.("25

    6";7,.==/ /'24=0 B7 07)=2A70 "6 /48' (22=/ .;7 .3."=.B=7 62;

    ('7 1"375 .))="8.("25 (A)7- I6 ('7 (;.66"8 "/ 758;A)(70M ('7

    073"87 /'24=0 7"('7; /"( B7'"50 ('7 758;A)("25 2; B7 8.).B=7

    26 078;A)("51 ('7 (;.66"8 );"2; (2 .5.=A/"/- I6 57"('7; 2)("25 "/

    .));2);".(7M . '2/(9B./70 ,7B .))="8.("25 6";7,.== /'24=0

    B7 07)=2A70-

    /==M Z2; "59'24/7 0737=2)70 .))="8.("25/M 75/4;7 ('.(

    0737=2):75( .;("6.8(/ F/.:)=7 0.(. .50 /8;")(/_ 454/70

    ="B;.;"7/M 82:)2575(/M 07B41 8207_ 2; (22=/G .;7 52(

    "58=4070 "5 ('7 07)=2A70 /26(,.;7M 2; .887//"B=7 "5 ('7

    );2048("25 753";25:75(-

  • 7/25/2019 CSC-MASTER-VER 6.0 CIS Critical Security Controls 10.15.2015

    68/94

    ?&

    ,-, +S N%&)0'(%09 6#' W&&C9

    "#$ 2$+.()*/ 03 ,KK-)+,*)012 P)1F#0.2$ C$5$-0K$C 0( ,+T.)($CQ )2 , +0DK-$R ,+*)5)*/

    ($T.)()1N , +0DK-$*$ K(0N(,D $1+0DK,22)1N $1*$(K()2$FA)C$ K0-)+/? *$+#10-0N/? ,1C *#$(0-$ 03 K$0K-$: "#$2$ ,($ 03*$1 6(0,C-/ C$3)1$C 0( ($T.)($C 6/ 30(D,- _)2B W,1,N$D$1*\(,D$A0(B2 ,1C K(0+$22$2:

    E +0DK($#$12)5$ *($,*D$1* 03 *#)2 *0K)+ )2 6$/01C *#$ 2+0K$ 03 *#$ %()*)+,- '$+.()*/

    %01*(0-2: e0A$5$(? *#$ ,+*)012 )1 %'% 9 K(05)C$ 2K$+)3)+? #)N#FK()0()*/ 2*$K2 *#,* +,1)DK(05$ EKK-)+,*)01 '03*A,($ '$+.()*/: &1 ,CC)*)01? A$ ($+0DD$1C .2$ 03 *#$ D,1/

    $R+$--$1* +0DK($#$12)5$ ($20.(+$2 C$C)+,*$C *0 *#)2 *0K)+: 4R,DK-$2 )1+-.C$L *#$ 7e'

    [Z.)-C '$+.()*/ &1] I(0N(,D b 6.)-C2$+.()*/)1:.2F+$(*:N05c? ,1C "#$

  • 7/25/2019 CSC-MASTER-VER 6.0 CIS Critical Security Controls 10.15.2015

    69/94

    ?>

    ,-, +=. "#)*'0#$ L09FZ 6#' A6#6?0K0#$

    M0/#&"# #5& /0-+,$9+#$/,N7 $,:/0*+#$/,1 +7 6&'' +7 $#7 0&;8#+#$/,1 ?( 3&%&'/;$,- +,3

    $*;'&*&,#$,- +, $,"$3&,# 0&7;/,7& $,:0+7#08"#80& .&@ @76"57 :.5.17:75( )7;/2557= ,'2 ,"== /4))2;( ('7 "58"075(

    '.50="51 );287// BA .8("51 "5 E7A 078"/"259:.E"51 ;2=7/-

  • 7/25/2019 CSC-MASTER-VER 6.0 CIS Critical Security Controls 10.15.2015

    70/94

    ??

    !"! $M% &'824)'* J)9=+'9) 5'4 N5'5E);)'*

    /==

  • 7/25/2019 CSC-MASTER-VER 6.0 CIS Critical Security Controls 10.15.2015

    71/94

    ?N

    ,-, += -19$0K Q#$*$1 L0C6$*^*F 8*6?%6K

    !"#$%&"' )*"*+&,&"'

    -.#/,&"'*'$."

    0.123.1#&

    )&,4&15

    67$1% 8*1'9

    :/'7.1$'$&5

    :;&1'$"+ < =&>.1'$"+ :"*;9'$#5 ?95'&,

  • 7/25/2019 CSC-MASTER-VER 6.0 CIS Critical Security Controls 10.15.2015

    72/94

    ?U

    ,-, ;O. N0#0$%6$* W09$9 6#' L0' W06K QY0%)*909

    B&7# #5& /%&0+'' 7#0&,-#5 /: +, /0-+,$9+#$/,N7 3&:&,7&7 .#5& #&"5,/'/-(1 #5&

    ;0 /"&7 7& 71 +, 3 #5 & ;&/; '&4 ?( 7$ *8'+# $,- #5 & /? O&"#$ %&7 +, 3 +" #$ /, 7 /: +, +# #+ "2 &0

    3FF0#'*Y R. 3$$6)H W1F09

    e)2*0()+,--/? *#$ 30--0A)1N E**,+B "/K$2 A$($ *#$ K()D,(/ 01$2 +012)C$($C A#$1

    C$5$-0K)1N *#$ %()*)+,- '$+.()*/ %01*(0-2: "#$ */K$2 A$($ ,-20 D,KK$C 6,+B )1*0 *#$

    %01*(0-2 ,2 K,(* 03 *#$ C)2+.22)01 *0 $12.($ N00C +05$(,N$ 6/ *#$ %01*(0-2: "#)2 ,KK(0,+#

    #,2 6$$1 K#,2$C 0.* )1 3,50( 03 *#$ %&' %0DD.1)*/ E**,+B W0C$-:

    3$$6)H -(KK6%1

    E**,+B$(2 +01*)1.,--/ 2+,1 30( 1$A? .1K(0*$+*$C 2/2*$D2? )1+-.C)1N *$2* 0( $RK$()D$1*,-

    2/2*$D2? ,1C $RK-0)* 2.+# 2/2*$D2 *0 N,)1 +01*(0- 03 *#$D:

    E**,+B$(2 C)2*()6.*$ #02*)-$ +01*$1* 01 &1*$(1$*F,++$22)6-$ P,1C 20D$*)D$2 )1*$(1,-Q

    A$62)*$2 *#,* $RK-0)* .1K,*+#$C ,1C )DK(0K$(-/ 2$+.($C +-)$1* 203*A,($ (.11)1N 01 5)+*)D

    D,+#)1$2:

    E**,+B$(2 +01*)1.,--/ 2+,1 30( 5.-1$(,6-$ 203*A,($ ,1C $RK-0)* )* *0 N,)1 +01*(0- 03 *,(N$*

    D,+#)1$2:E**,+B$(2 .2$ +.(($1*-/ )13$+*$C 0( +0DK(0D)2$C D,+#)1$2 *0 )C$1*)3/ ,1C $RK-0)* 0*#$(

    5.-1$(,6-$ D,+#)1$2 ,+(022 ,1 )1*$(1,- 1$*A0(B:

    E**,+B$(2 $RK-0)* A$,B C$3,.-* +013)N.(,*)012 03 2/2*$D2 *#,* ,($ D0($ N$,($C *0 $,2$ 03

    .2$ *#,1 2$+.()*/:

    E**,+B$(2 $RK-0)* 1$A 5.-1$(,6)-)*)$2 01 2/2*$D2 *#,* -,+B +()*)+,- K,*+#$2 )1 0(N,1)O,*)012

    *#,* C0 10* B10A *#,* *#$/ ,($ 5.-1$(,6-$ 6$+,.2$ *#$/ -,+B +01*)1.0.2 5.-1$(,6)-)*/

    ,22$22D$1*2 ,1C $33$+*)5$ ($D$C),*)01:

    E**,+B$(2 +0DK(0D)2$ *,(N$* 0(N,1)O,*)012 *#,* C0 10* $R$(+)2$ *#$)( C$3$12$2 *0

    C$*$(D)1$ ,1C +01*)1.,--/ )DK(05$ *#$)( $33$+*)5$1$22:

    E**,+B$(2 .2$ D,-)+)0.2 +0C$ *0 N,)1 ,1C D,)1*,)1 +01*(0- 03 *,(N$* D,+#)1$2? +,K*.($2$12)*)5$ C,*,? ,1C *#$1 2K($,C )* *0 0*#$( 2/2*$D2? 20D$*)D$2 A)$-C)1N +0C$ *#,* C)2,6-$2

    0( C0CN$2 2)N1,*.($F6,2$C ,1*)F5)(.2 *00-2:

    E**,+B$(2 2+,1 30( ($D0*$-/ ,++$22)6-$ 2$(5)+$2 01 *,(N$* 2/2*$D2 *#,* ,($ 03*$1 .11$$C$C

    30( 6.2)1$22 ,+*)5)*)$2? 6.* K(05)C$ ,1 ,5$1.$ 03 ,**,+B ,1C +0DK(0D)2$ 03 *#$ 0(N,1)O,*)01:

    E**,+B$(2 $RK-0)* A$,B ,KK-)+,*)01 203*A,($? K,(*)+.-,(-/ A$6 ,KK-)+,*)012? *#(0.N# ,**,+B

    5$+*0(2 2.+# ,2 'pJ )1U$+*)01? +(022F2)*$ 2+()K*)1N? ,1C 2)D)-,( *00-2:

    E**,+B$(2 $RK-0)* A)($-$22 ,++$22 K0)1*2 *0 N,)1 $1*(/ )1*0 , *,(N$* 0(N,1)O,*)01Y2 )1*$(1,-

    1$*A0(B? ,1C $RK-0)* A)($-$22 +-)$1* 2/2*$D2 *0 2*$,- 2$12)*)5$ )130(D,*)01:

    E**,+B$(2 $RK-0)* .2$(2 ,1C 2/2*$D ,CD)1)2*(,*0(2 5), 20+),- $1N)1$$()1N 2+,D2 *#,* A0(B6$+,.2$ 03 , -,+B 03 2$+.()*/ 2B)--2 ,1C ,A,($1$22:

    E**,+B$(2 $RK-0)* ,1C )13)-*(,*$ *#(0.N# 1$*A0(B C$5)+$2 A#02$ 2$+.()*/ +013)N.(,*)01 #,26$$1 A$,B$1$C 05$( *)D$ 6/ N(,1*)1N? 30( 2K$+)3)+ 2#0(*F*$(D 6.2)1$22 1$$C2? 2.KK02$C-/

    *$DK0(,(/ $R+$K*)012 *#,* ,($ 1$5$( ($D05$C:

    E**,+B$(2 *()+B , .2$( A)*# ,1 ,CD)1)2*(,*0(F-$5$- ,++0.1* )1*0 0K$1)1N , K#)2#)1NF2*/-$

    $D,)- A)*# ,1 ,**,+#D$1* 0( 2.(3)1N *0 *#$ ,**,+B$(Y2 +01*$1* 01 ,1 &1*$(1$* A$62)*$?

  • 7/25/2019 CSC-MASTER-VER 6.0 CIS Critical Security Controls 10.15.2015

    80/94

    N?

    ,--0A)1N *#$ ,**,+B$(Y2 D,-)+)0.2 +0C$ 0( $RK-0)* *0 (.1 01 *#$ 5)+*)D D,+#)1$ A)*# 3.--

    ,CD)1)2*(,*0( K()5)-$N$2:

    E**,+B$(2 $RK-0)* 60.1C,(/ 2/2*$D2 01 &1*$(1$*F,++$22)6-$ 7Wl 1$*A0(B2? ,1C *#$1 K)50**0 N,)1 C$$K$( ,++$22 01 )1*$(1,- 1$*A0(B2:

    E**,+B$(2 $RK-0)* K00(-/ C$2)N1$C 1$*A0(B ,(+#)*$+*.($2 6/ -0+,*)1N .11$$C$C 0(.1K(0*$+*$C +011$+*)012? A$,B 3)-*$()1N? 0( , -,+B 03 2$K,(,*)01 03 )DK0(*,1* 2/2*$D2 0(

    6.2)1$22 3.1+*)012:

    E**,+B$(2 0K$(,*$ .1C$*$+*$C 30( $R*$1C$C K$()0C2 03 *)D$ 01 +0DK(0D)2$C 2/2*$D2

    6$+,.2$ 03 , -,+B 03 -0NN)1N ,1C -0N ($5)$A:

    E**,+B$(2 N,)1 ,++$22 *0 2$12)*)5$ C0+.D$1*2 )1 ,1 0(N,1)O,*)01 *#,* C0$2 10* K(0K$(-/

    )C$1*)3/ ,1C K(0*$+* 2$12)*)5$ )130(D,*)01 0( 2$K,(,*$ )* 3(0D 101F2$12)*)5$ )130(D,*)01:

    E**,+B$(2 +0DK(0D)2$ )1,+*)5$ .2$( ,++0.1*2 -$3* 6$#)1C 6/ *$DK0(,(/ A0(B$(2?

    +01*(,+*0(2? ,1C 30(D$( $DK-0/$$2? )1+-.C)1N ,++0.1*2 -$3* 6$#)1C 6/ *#$ ,**,+B$(2

    *#$D2$-5$2 A#0 ,($ 30(D$( $DK-0/$$2:

    E**,+B$(2 $2+,-,*$ *#$)( K()5)-$N$2 01 5)+*)D D,+#)1$2 6/ -,.1+#)1N K,22A0(C N.$22)1N?

    K,22A0(C +(,+B)1N? 0( K()5)-$N$ $2+,-,*)01 $RK-0)*2 *0 N,)1 ,CD)1)2*(,*0( +01*(0- 03

    2/2*$D2? A#)+# )2 *#$1 .2$C *0 K(0K,N,*$ *0 0*#$( 5)+*)D D,+#)1$2 ,+(022 ,1 $1*$(K()2$:

    E**,+B$(2 N,)1 ,++$22 *0 )1*$(1,- $1*$(K()2$ 2/2*$D2 ,1C N,*#$( ,1C $R3)-*(,*$ 2$12)*)5$

    )130(D,*)01 A)*#0.* C$*$+*)01 6/ *#$ 5)+*)D 0(N,1)O,*)01:

    E**,+B$(2 +0DK(0D)2$ 2/2*$D2 ,1C ,-*$( )DK0(*,1* C,*,? K0*$1*),--/ U$0K,(C)O)1N

    0(N,1)O,*)01,- $33$+*)5$1$22 5), K0--.*$C )130(D,*)01:

    E**,+B$(2 0K$(,*$ .1C)2+05$($C )1 0(N,1)O,*)012 A)*#0.* $33$+*)5$ )1+)C$1*F($2K012$

    +,K,6)-)*)$2? ,1C A#$1 *#$ ,**,+B$(2 ,($ C)2+05$($C? *#$ 0(N,1)O,*)012 03*$1 +,110*K(0K$(-/ +01*,)1 *#$ ,**,+B? $(,C)+,*$ *#$ ,**,+B$(Y2 K($2$1+$? 0( ($+05$( *0 , 2$+.($

    K(0C.+*)01 2*,*$:

  • 7/25/2019 CSC-MASTER-VER 6.0 CIS Critical Security Controls 10.15.2015

    81/94

    NN

    3FF0#'*Y ,. W40 T"-W U%6K0

  • 7/25/2019 CSC-MASTER-VER 6.0 CIS Critical Security Controls 10.15.2015

    82/94

    NU

    !-I),9)80,2*- :,5;)D+,U [!":\ !+,)

    !&" !,2*285< ")80,2*- !+'*,+V\ &4)'*2.- L,+*)8* 7)*)8* J)9=+'4 J)8+(),

    LYL %* Y784;7 L256"14;.("25 26

    O50 4/7; 073"87/IJ

    LYL &* L25("5424/ S4=57;.B"="(A

    [//7//:75( .50 \7:70".("25\[ LQ QI

    LYL >* L25(;2==70 W/7 26

    [0:"5"/(;.("37 J;"3"=717/[L

    LYL ?* Q."5(75.587M Q25"(2;"51M

    .50 [5.=A/"/ 26 [40"( 21/[O []

    LYL N* O:."= .50 a7B H;2,/7;

    J;2(78("25/JR

    LYL U* Q.=,.;7 @7675/7 JR LQ

    LYL X* ^":"(.("25 .50 L25(;2= 26

    ]7(,2;E J2;(/M J;2(282=/M .50

    Y7;3"87

    IJ

    LYL #V* @.(. \78237;A L.).B"="(A \J

    LYL ##* Y784;7 L256"14;.("25 26

    ]7(,2;E @73"87/IJ

    LYL #$* H2450.;A @7675/7 @J

    LYL #%* @.(. J;2(78("25 @Y

    LYL #&* L25(;2==70 [887// H./70

    25 ]770 (2 m52,[L

    LYL #>* a";7=7// [887// L25(;2= [L

    LYL #?* [88245( Q25"(2;"51 .50

    L25(;2=[L LQ

    LYL #N* Y784;"(A YE"==/

    [//7//:75( .50 [));2);".(7

    R;."5"51

    [R

    LYL #U* [))="8.("25 Y26(,.;7Y784;"(A

    IJ

    LYL #X* I58"075( \7/)25/7 .50

    Q.5.17:75([O \J

    LYL $V* J757(;.("25 R7/(/ .50

    \70 R7.: O

  • 7/25/2019 CSC-MASTER-VER 6.0 CIS Critical Security Controls 10.15.2015

    83/94

    NX

    3FF0#'*Y 8. W40 T6$*C ,1B0% @1?*0#0 ,6KF6*?#

    "#$ G,*)01,- %,DK,)N1 30( %/6$( e/N)$1$ A,2 C$5$-0K$C *0 K(05)C$ , K-,)1F-,1N.,N$?

    ,++$22)6-$? ,1C -0AF+02* 30.1C,*)01 30( )DK-$D$1*,*)01 03 *#$ %&' %()*)+,- '$+.()*/ %01*(0-2:

    E-*#0.N# *#$ %01*(0-2 ,-($,C/ 2)DK-)3/ *#$ C,.1*)1N +#,--$1N$2 03 +/6$( C$3$12$ 6/ +($,*)1N

    +0DD.1)*/ K()0()*)$2 ,1C ,+*)01? D,1/ $1*$(K()2$2 ,($ 2*,(*)1N 3(0D , 5$(/ 6,2)+ -$5$- 032$+.()*/:

    "#$ %,DK,)N1 2*,(*2 A)*# , 3$A 6,2)+ T.$2*)012 *#,* $5$(/ +0(K0(,*$ ,1C N05$(1D$1*

    -$,C$( 0.N#* *0 6$ ,6-$ *0 ,12A$(:

    70 A$ B10A A#,* )2 +011$+*$C *0 0.( 2/2*$D2 ,1C 1$*A0(B2^ P%'% =Q

    70 A$ B10A A#,* 203*A,($ )2 (.11)1N P0( *(/)1N *0 (.1Q 01 0.( 2/2*$D2 ,1C1$*A0(B2^ P%'% @Q

    E($ A$ +01*)1.0.2-/ D,1,N)1N 0.( 2/2*$D2 .2)1N [B10A1 N00C] +013)N.(,*)012^P%'% aQ

    E($ A$ +01*)1.0.2-/ -00B)1N 30( ,1C D,1,N)1N [B10A1 6,C] 203*A,($^ P%'% HQ

    70 A$ -)D)* ,1C *(,+B *#$ K$0K-$ A#0 #,5$ *#$ ,CD)1)2*(,*)5$ K()5)-$N$2 *0 +#,1N$?

    6/K,22? 0( 05$(F()C$ 0.( 2$+.()*/ 2$**)1N2^ P%'% >Q

    "#$2$ T.$2*)012? ,1C *#$ ,+*)012 ($T.)($C *0 ,12A$( *#$D? ,($ ($K($2$1*$C )1 [K-,)1

    -,1N.,N$] 6/ *#$ "0K > I()0()*)$2 03 *#$ %,DK,)N1L _,&(#$D ,*?(%0D ,$%&C N6$)4DL0F06$`: "0 2.KK0(* *#$ %,DK,)N1? 50-.1*$$(2 #,5$ +($,*$C C0+.D$1*,*)01 ,1C [*00-B)*2]

    *0 N.)C$ )DK-$D$1*,*)01:

    E-*#0.N# *#$ -,1N.,N$ )2 2)DK-$ ,1C +,*+#/? 6$#)1C *#$ 2+$1$2 $,+# 03 *#$2$ T.$2*)012 )2,220+),*$C A)*# , K()D,(/ %01*(0- *#,* K(05)C$2 ,1 ,+*)01 K-,1: "#$ %,DK,)N1 )2 ,-20

    C$2)N1$C *0 6$ )1 ,-)N1D$1* A)*# *#$ 3)(2* > 03 *#$ %&' %()*)+,- '$+.()*/ %01*(0-2? *#$

    E.2*(,-),1 ')N1,-2 7)($+*0(,*$Y2 PE'7Q ["0K \0.( '*(,*$N)$2 *0 W)*)N,*$ ",(N$*$C &1*(.2)012?

    ,1C *#$ 7e' %01*)1.0.2 7),N102*)+ ,1C W)*)N,*)01 P%7WQ I(0N(,D: "#)2 K(05)C$2 , 2*(01N

    ,1C C$3$1C,6-$ 6,2)2 30( *#$ %,DK,)N1 I()0()*)$2? , N(0A*# K,*# 30( D,*.()*/ 6$/01C *#$2$

    6,2)+ ,+*)012? ,1C *#$ 6$1$3)*2 03 , -,(N$ +0DD.1)*/ 03 $RK$(*2? .2$(2? ,1C 5$1C0(2:

    "#$ G,*)01,- %,DK,)N1 30( %/6$( e/N)$1$ #,2 6$$1 U0)1*-/ ,C0K*$C 6/ *#$ %$1*$( 30(&1*$(1$* '$+.()*/ P#0D$ 03 *#$ W.-*)F'*,*$ &130(D,*)01 '#,()1N ,1C E1,-/2)2 %$1*$(Q ,1C

    *#$ G,*)01,- o05$(10(Y2 E220+),*)01 e0D$-,1C '$+.()*/ EC5)20(/ %0.1+)- Poe'E%Q ,2 ,

    30.1C,*)01,- +/6$(2$+.()*/ K(0N(,D ,+(022 D,1/ '*,*$? J0+,-? "()6,-? ,1C "$(()*0(),-N05$(1D$1*2 ,1C 033$(2 *00-B)*2 ,1C ($20.(+$2 30( ,1/ K.6-)+ 0( K()5,*$ 0(N,1)O,*)01:

    @ ." %'-.42%&'G 9& 2& AAA:+)2$+.()*/:0(N

  • 7/25/2019 CSC-MASTER-VER 6.0 CIS Critical Security Controls 10.15.2015

    84/94

    UV

    3FF0#'*Y Q. ,%*$*)6C X&/0%#6#)0 ,$%&C9 6#' $40 ,"- ,%*$*)6C -0)(%*$1 ,$%&C9

    %/6$(2$+.()*/ N05$(1,1+$ )2 , B$/ ($2K012)6)-)*/ 03 *#$ 60,(C 03 C)($+*0(2 ,1C 2$1)0(

    $R$+.*)5$2? ,1C )* D.2* 6$ ,1 )1*$N(,- K,(* 03 05$(,-- $1*$(K()2$ N05$(1,1+$: Z$+,.2$ 03 )*2

    C/1,D)+ 1,*.($? +/6$(2$+.()*/ N05$(1,1+$ D.2* ,-20 6$ ,-)N1$C A)*# ,1 &C"#42%&'4;

    +/6$(2$+.()*/ 3(,D$A0(B:

    "0 $R$(+)2$ $33$+*)5$ N05$(1,1+$? $R$+.*)5$2 D.2* #,5$ , +-$,( .1C$(2*,1C)1N 03 A#,* *0

    $RK$+* 3(0D *#$)( )130(D,*)01 2$+.()*/ K(0N(,D: "#$/ 1$$C *0 B10A #0A *0 C)($+* *#$

    )DK-$D$1*,*)01? $5,-.,*$ *#$)( 0A1 2*,*.2 A)*# ($N,(C *0 $R)2*)1N 2$+.()*/ K(0N(,D2? ,1C

    C$*$(D)1$ *#$ 2*(,*$N/ ,1C 06U$+*)5$2 03 ,1 $33$+*)5$ 2$+.()*/ K(0N(,D:

    @&< $40 ,"- ,%*$*)6C -0)(%*$1 ,$%&C9 ,6# @0CF

    "#$ %01*(0-2 ,($ ,+*)01,6-$? ,.*0D,*$C ,+*)5)*)$2 *#,* C$*$+* ,1C K($5$1* ,**,+B2 ,N,)12*

    /0.( 1$*A0(B ,1C D02* )DK0(*,1* C,*,: "#$/ 2.KK0(* $1*$(K()2$ 2$+.()*/ N05$(1,1+$K(0N(,D2 6/ 6()CN)1N *#$ N,K 3(0D ,1 $R$+.*)5$ 5)$A 03 6.2)1$22 ()2B *0 , *$+#1)+,- 5)$A 032K$+)3)+ ,+*)012 ,1C 0K$(,*)01,- +01*(0-2 *0 D,1,N$ *#02$ ()2B2: j$/ $R$+.*)5$ +01+$(12

    ,60.* )130(D,*)01 2$+.()*/ ()2B2 +,1 6$ *(,12-,*$C )1*0 2K$+)3)+ K(0N(,D2 30( 2$+.()*/)DK(05$D$1*? ,1C ,-20 )1*0 C,/F*0FC,/ 2$+.()*/ *,2B2 30( 3(01*F-)1$ K$(2011$-: "#)2 ,--0A2

    6$**$( ,-)N1D$1* *0KF*0F60**0D 03 +0(K0(,*$ ()2B D,1,N$D$1*: E-20? 2)1+$ *#$ %01*(0-2 ,($

    +($,*$C ,1C 2.KK0(*$C 6/ , -,(N$ )1C$K$1C$1* +0DD.1)*/ 03 K(,+*)*)01$(2 ,1C 5$1C0(2?

    *#$/ K(05)C$ , 2K$+)3)+? 2.KK0(*$C? ,1C 0K$1 6,2$-)1$ 30( D$,2.($D$1* ,1C 1$N0*),*)01

    ,60.* 2$+.()*/ )DK(05$D$1* X 01$ *#,* )2 C$D012*(,6-/ )1 ,-)N1D$1* A)*# $22$1*),--/ ,--

    30(D,- ($N.-,*0(/? N05$(1,1+$? ,1C 05$(2)N#* 3(,D$A0(B2:

    U%&K X&/0%#6#)0 $& $40 ,"- ,%*$*)6C -0)(%*$1 ,$%&C9

    "0 #$-K )DK(05$ /0.( +0DK,1/r2 ,6)-)*/ *0 D,1,N$ )130(D,*)01 ()2B2? #$($ ,($ 20D$

    2,DK-$ 2*$K2 *0 #$-K /0. ,-)N1 +0(K0(,*$ N05$(1,1+$ +01+$(12 A)*# *#$ )DK-$D$1*,*)01 032$+.()*/ +01*(0-2: "#$2$ $R,DK-$2 )C$1*)3/ *#$ K()D,(/? 6.* 10* *#$ 01-/? %&' %()*)+,-

    '$+.()*/ %01*(0-2 A#)+# 2#0.-C 6$ )DK-$D$1*$C:

    X&/0%#6#)0 *$0K a+L =/"'2%-E E&8# .&$2 %.C'2 %'-.42%&' 4$$"2$ 4'/ 2H" %.C462 &'

    E&8# F8$%'"$$ .%$$%&' %- 2H"E A"#" 2& F" 6&.C#&.%$"/*

    &130(D,*)01 )2 *#$ -)3$6-00C 03 $5$(/ D0C$(1 $1*$(K()2$? ,1C *#$ D05$D$1*? 2*0(,N$?

    ,1C +01*(0- 03 *#,* )130(D,*)01 )2 )1$R*()+,6-/ 60.1C *0 *#$ .2$ 03 &130(D,*)01"$+#10-0N/: "#$($30($ *#$ 30--0A)1N %&' %()*)+,- '$+.()*/ %01*(0-2 ,($ *#$ K()D,(/

    D$,12 *0 *(,+B ,1C +01*(0- *#$ 2/2*$D +0DK01$1*2 *#,* D,1,N$ *#$ 3-0A?

    K($2$1*,*)01? ,1C .2$ 03 )130(D,*)01:

    ,-, +b"#/0#$&%1 &2 3($4&%*50' 6#' 7#6($4&%*50' 80/*)09

    ,-, ;b"#/0#$&%1 &2 3($4&%*50' 6#' 7#6($4&%*50' 6#' -&2$

  • 7/25/2019 CSC-MASTER-VER 6.0 CIS Critical Security Controls 10.15.2015

    85/94

    U#

    X&/0%#6#)0 "$0K a;. 54'49" 2H" B'&A' 6EF"# D8;'"#4F%;%2%"$ &- E&8# %'-.42%&' 4'/

    .4B" $8#" 2H" '"6"$$4#E $"68#%2E C&;%6%"$ 4#" %' C;46" 2& .4'49" 2H" #%$B*

    E* , D)1)D.D? /0. 2#0.-C 6$ ,6-$ *0 )C$1*)3/ ,1C D,1,N$ *#$ -,(N$ 50-.D$ 03 B'&A'

    3-,A2 ,1C 5.-1$(,6)-)*)$2 30.1C )1 &130(D,*)01 "$+#10-0N/ ,1C K(0+$22$2: "#$

    30--0A)1N %&' %()*)+,- '$+.()*/ %01*(0-2 ,($ *#$ K()D,(/ D$,12 *0 $2*,6-)2# ,6,2$-)1$ 03 ($2K012)6-$ K(,+*)+$2 *#,* +,1 6$ D$,2.($C? D,1,N$C? ,1C ($K0(*$C:

    ,-, >. -0)(%0 ,*?(%6$* &2 @6%'

  • 7/25/2019 CSC-MASTER-VER 6.0 CIS Critical Security Controls 10.15.2015

    86/94

    U$

    80/0C&F*#? 6# ]/0%6CC X&/0%#6#)0 -$%6$0?1

    V#)-$ *#$ %&' %()*)+,- '$+.()*/ %01*(0-2 K(05)C$ ,1 $33$+*)5$ A,/ *0 K-,1? K()0()*)O$? ,1C)DK-$D$1* K()D,()-/ 2"6H'%64;+01*(0-2 30( +/6$(C$3$12$? *#$/ ,($ 6$2* .2$C ,2 K,(* 03 ,

    #0-)2*)+ )130(D,*)01 N05$(1,1+$ K(0N(,D F 01$ *#,* ,-20 ,CC($22$2 K0-)+)$2? 2*,1C,(C2? ,1C

    N.)C$-)1$2 *#,* 2.KK0(* *$+#1)+,- )DK-$D$1*,*)012: \0( $R,DK-$? +01C.+*)1N ,1 )15$1*0(/03 C$5)+$2 01 /0.( 1$*A0(B )2 ,1 )DK0(*,1* *$+#1)+,- 6$2* K(,+*)+$? 6.* ,1 0(N,1)O,*)01

    D.2* ,-20 C$3)1$ ,1C K.6-)2# K0-)+)$2 ,1C K(0+$22$2 *#,* +-$,(-/ +0DD.1)+,*$ *0 $DK-0/$$2

    *#$ K.(K02$ 03 *#$2$ +01*(0-2? A#,* )2 $RK$+*$C 03 *#$D ,1C *#$ (0-$ *#$/ K-,/ )1 K(0*$+*)1N

    *#$ +0DK,1/Y2 )1*$($2*2:

    "#$ 30--0A)1N *0K)+2 K(05)C$ , .2$3.- 3(,D$A0(B 30( C$5$-0K)1N /0.( 05$(,-- N05$(1,1+$

    2*(,*$N/: Z,2$C 01 0.( $RK$()$1+$? *#$2$ ,($ K()0()*)O$C 6,2$C 01 *#$)( )DK,+* )1 6.)-C)1N

    ,1C 2.KK0(*)1N ,1 $33$+*)5$ )130(D,*)01 ,22.(,1+$ K(0N(,D:

    QY0)($*/0 -F&%94*F. 7$5$-0K )130(D,*)01 ,22.(,1+$ +#,(*$(2 A)*# (0-$2 ,1C

    ($2K012)6)-)*)$2? 2*$$()1N +0DD)**$$2? ,1C 60,(C 03 C)($+*0( 6()$3)1N2 *0 $2*,6-)2#2.KK0(* ,1C -$,C$(2#)K 3(0D $R$+.*)5$2:

    "#2&%K6$* 399(%6#)0 N%&?%6K A6#6?0K0#$. 7$3)1$ D,1,N$D$1* ,1C ($20.(+$

    ,--0+,*)01 +01*(0-2? 2.+# ,2 6.CN$*)1N? ,1C K()0()*)O,*)01 *0 N05$(1 )130(D,*)01

    ,22.(,1+$ K(0N(,D2 .1C$( $R$+.*)5$ 2K0120(2#)K:

    "#2&%K6$* 399(%6#)0 N&C*)*09 6#' -$6#'6%'9 A6#6?0K0#$. 7$3)1$ ,1CC0+.D$1* K0-)+)$2 ,1C 2*,1C,(C2 *0 K(05)C$ C$*,)-$C N.)C,1+$ ($N,(C)1N #0A

    2$+.()*/ +01*(0-2 A)-- 6$ +0DK-$*$C *0 K(0D0*$ +012)2*$1+/ )1 C$3$12$:

    86$6 ,C699*2*)6$*. &C$1*)3/? K()0()*)O$ ,1C -,6$- C,*, ,22$*2? )1+-.C)1N ,1,-0N 0(K#/2)+,- ,22$*2:

    L*9H A6#6?0K0#$. &C$1*)3/ *#0.N#*3.- ,1C K.(K02$3.- C$3$12$ 2*(,*$N)$2 6,2$C 01

    K()0()*/ C$+)2)012 01 #0A 6$2* *0 C$3$1C 5,-.,6-$ C,*, ,22$*2:

    ,&KFC*6#)0 6#' E0?6C A6#6?0K0#$. ECC($22 +0DK-),1+$ ($T.)($D$1*2 6,2$C 01

    *#$ ($N.-,*0(/ ,1C +01*(,+*.,- ($T.)($D$1*2 K-,+$C 01 /0.( 0(N,1)O,*)01:

    -0)(%*$1 3

  • 7/25/2019 CSC-MASTER-VER 6.0 CIS Critical Security Controls 10.15.2015

    87/94

    U%

    N0%9#0C 6#' @(K6# L09&(%)09 A6#6?0K0#$. 'K$+)3/ K$(2011$- ,1C #.D,1

    ($20.(+$2 +01*(0-2 *0 D,1,N$ *#$ A,/ K$0K-$ )1*$(,+* A)*# C,*, ,22$*2: I$0K-$? ,2

    A$-- ,2 *$+#10-0N/ +01*(0-2? ,($ +()*)+,- 30( *#$ C$3$12$ 03 )130(D,*)01 ,22$*2:

    R('?0$9 6#' L09&(%)0 A6#6?0K0#$. E--0+,*$ ,KK(0K(),*$ ($20.(+$2 )1 0(C$( *0

    6$ $33$+*)5$ ,* C$3$12$: &130(D,*)01 ,22.(,1+$ ,(+#)*$+*.($2 ,($ 5)*,- 30( C$3$12$?6.* A)*#0.* 6.CN$*2 ,1C ($20.(+$2? 2.+# K-,12 A)-- 1$5$( 6$ $33$+*)5$:

    N419*)6C -0)(%*$1. I(0*$+* *#$ $T.)KD$1*? 6.)-C)1N2? ,1C -0+,*)012 A#$($ C,*,

    ,22$*2 ,($ 2*0($C *0 K(05)C$ , 30.1C,*)01 30( *#$ -0N)+,- 2$+.()*/ 03 C,*, ,22$*2:

    "#)*'0#$ L09FZ A6#6?0K0#$. 'K$+)3/ *#$ K-,11$C D,1,N$D$1* 03 #0A /0.

    A)-- ($2K01C )1 *#$ 3,+$ 03 K0*$1*),--/ ,C5$(2$ $5$1*2: "#)2 ,+*2 ,2 , +0DK01$1* 03

    6.2)1$22 +01*)1.)*/ ,1C C)2,2*$( D,1,N$D$1*:

    R(9*#099 ,$*#(*$1 6#' 8*969$0% L0)&/0%1 A6#6?0K0#$. 'K$+)3/ ($2)-)$1+/

    +01*(0-2 *0 #$-K D)*)N,*$ K0*$1*),- -022$2 C.$ *0 K0*$1*),- C)2(.K*)012 *0 6.2)1$220K$(,*)012:

    N%&)(%0K0#$ 6#' J0#'&% A6#6?0K0#$. I,(*1$( A)*# 6.2)1$22 ,220+),*$2 )1

    C$3$1C)1N *#$)( C,*, ,22$*2: "#$ %01*(0-2 C$3)1$ #0A ,1 0(N,1)O,*)01 ,-)N12 A)*#

    *#)(C K,(*)$2 ,1C 5$1C0(2 *0 K(0*$+* *#$)( C,*, ,22$*2:

    ,46#?0 6#' ,*?(%6$* A6#6?0K0#$. E22$22? ,++$K* 0( C$1/? ,1C -0N +#,1N$2*0 2/2*$D2? $2K$+),--/ +013)N.(,*)01 +#,1N$2 )1 , 2/2*$D,*)+ 30(D,- D,11$( )1 0(C$(

    *0 C$3$1C *#$ 0(N,1)O,*)01Y2 )130(D,*)01 ,22$*2:

  • 7/25/2019 CSC-MASTER-VER 6.0 CIS Critical Security Controls 10.15.2015

    88/94

    U&

    3FF0#'*Y U. W&"$%9'*aE-- $1*$(K()2$2

    *#,* ,KK-/ *#$ %01*(0-2 2#0.-C .1C$(*,B$ X ,1C D,B$ ,5,)-,6-$ *0 2*,B$#0-C$(2 X K()5,+/)DK,+* ,22$22D$1*2 03 ($-$5,1* 2/2*$D2 *0 $12.($ *#,* ,KK(0K(),*$ K(0*$+*)012 ,($ )1 K-,+$

    ,2 *#$ %01*(0-2 ,($ )DK-$D$1*$C: 45$(/ $1*$(K()2$ 2#0.-C ,-20 ($N.-,(-/ ($5)$A *#$2$

    ,22$22D$1*2 ,2 D,*$(),- +#,1N$2 *0 )*2 +/6$(2$+.()*/ K02*.($ ,($ ,C0K*$C: "#$ ,)D )2 *0,22$22 ,1C D)*)N,*$ *#$ D,U0( K0*$1*),- K()5,+/ ()2B2 ,220+),*$C A)*# )DK-$D$1*)1N 2K$+)3)+

    %01*(0-2 ,2 A$-- ,2 $5,-.,*$ *#$ 05$(,-- )DK,+* 03 *#$ %01*(0-2 01 )1C)5)C.,- K()5,+/:

    "0 ,22)2* $1*$(K()2$2 )1 $330(*2 *0 +01C.+* , K()5,+/ )DK,+* ,22$22D$1* A#$1 )DK-$D$1*)1N

    *#$ %01*(0-2 ,1C *0 +01*()6.*$ *0 *#$ $2*,6-)2#D$1* 03 , D0($ N$1$(,- ($3$($1+$ 2*,1C,(C

    30( K()5,+/ ,1C *#$ %01*(0-2? %&' A)-- +015$1$ *$+#1)+,- ,1C K()5,+/ $RK$(*2 *0 ($5)$A $,+#

    %01*(0- ,1C 033$( ($+0DD$1C,*)012 30( 6$2* K(,+*)+$:

    "#$ 30--0A)1N 3(,D$A0(B A)-- #$-K N.)C$ *#)2 $330(* ,1C K(05)C$ , K022)6-$ 0.*-)1$ 30( ,

    I()5,+/ &DK,+* E22$22D$1*:

    N%*/6)1 "KF6)$ 399099K0#$ &2 $40 ,"- ,%*$*)6C -0)(%*$1 ,$%&C9

    "Z ]/0%/*0"$6#%F" AH42 2"6H'%64; 4'/ C&;%6E F4$"/ $4-"984#/$ 4'/ $"68#%2E ."4$8#"$ .%9H2 F" '""/"/

    2& $8CC 2H" 7&'2#&;* ='6;8/" 4' "X4.%'42%&' &- 2"6H'%64; 4'/ C&;%6E $4-"984#/$G $86H 4$

    %'-.42%&' $H4#%'9 C#&2&6&;$G $C"6%4; 466"$$ #"$2#%62%&'$G 4'/ &2H"# 6&'2#&;$*

    7)2+.22 A#$*#$( *#$ %01*(0- ,--0A2 30( 2$-3F,.C)*2? K$(D)*2 *#)(C K,(*/ ,.C)*2? 0(,--0A2 ($,- *)D$ 0( 30($12)+ ($5)$A2 6/ ,KK(0K(),*$ 05$(2)N#* ,N$1+)$2:

    70 *#$ &" 2/2*$D2 2.KK0(*)1N *#$ %01*(0- #,5$ ,.*0D,*$C *00-2 *0 )1C)+,*$ A#$1

    )130(D,*)01 )2 K022)6-/ 6$)1N D)2.2$C^

    7$2+()6$ A#,* ($T.)($D$1*2 30( K()5,+/ *(,)1)1N 2#0.-C 6$ K(05)C$C *0 .2$(2 $)*#$(

    N$1$(,--/ 0( 2K$+)3)+,--/ ($-$5,1* *0 *#$ %01*(0-? )1+-.C)1N )130(D,*)01 #,1C-)1NK(0+$C.($2 ,1C 2$12)*)5)*/ 03 )130(D,*)01: 7)2+.22 #0A )1C)5)C.,-2 A#0 #,5$ ,++$22

    *0 I&& +0--$+*$C 0( N$1$(,*$C 6/ *#$ %01*(0- 2#0.-C 6$ *(,)1$C *0 ,KK(0K(),*$-/

    #,1C-$ *#,* )130(D,*)01:

    7)2+.22 *#$ */K$2 03 K(0+$22$2 ,1C K(0+$C.($2 1$+$22,(/ *0 ($5)$A ,1C ,KK(05$

    )130(D,*)01 2#,()1N ,N($$D$1*2? 1$A .2$2 03 %01*(0- )130(D,*)01? ,1C 1$A ,++$22

    *0 %01*(0- )130(D,*)01 6/ 0*#$( K,(*)$2:

  • 7/25/2019 CSC-MASTER-VER 6.0 CIS Critical Security Controls 10.15.2015

    94/94