Edge Register
Standards · CIS v8

CIS Controls v8

Rendered when the buyer ticks "CIS Controls v8". The register cites 6 of its 153 clauses, behind 3 findings: intermittent or no link, and no backup stated, home and field devices with encryption not stated, hardware questions unanswered, and on the duty rows of every site it reaches.

Requirement text drawn from the compliance.theartofservice.com corpus, read against the held text of each standard: the corpus statement of each clause, not the instrument verbatim. Source framework: CIS Controls v8. What it attaches to a site: the CIS v8 regime page.

Clauses cited

6 of 153
CIS v8 CIS-1.1 Establish and Maintain Detailed Enterprise Asset Inventory

Establish and maintain an accurate, detailed, and up-to-date inventory of all enterprise assets with the potential to store or process data, to include: end-user devices (including portable and mobile), network devices, non-computing/IoT devices, and servers. Ensure the inventory records the network address (if static), hardware address, machine name, enterprise asset owner, department for each asset, and whether the asset has been approved to connect to the network. For mobile end-user devices, MDM type tools can support this process, where appropriate. This inventory includes assets connected to the infrastructure physically, virtually, remotely, and those within cloud environments. Additionally, it includes assets that are regularly connected to the enterprise’s network infrastructure, even if they are not under control of the enterprise. Review and update the inventory of all enterprise assets bi-annually, or more frequently.

Evidence an auditor accepts: Evidence the safeguard is implemented: Establish and Maintain Detailed Enterprise Asset Inventory; Policy/standard covering CIS Control 1 (Inventory and Control of Enterprise Assets); Configuration / tooling output demonstrating the safeguard
Common gap: Safeguard implemented for some assets but not all in scope
Source framework: CIS Controls v8
CIS v8 CIS-4.11 Enforce Remote Wipe Capability on Portable End-User Devices

Remotely wipe enterprise data from enterprise-owned portable end-user devices when deemed appropriate such as lost or stolen devices, or when an individual no longer supports the enterprise.

Evidence an auditor accepts: Evidence the safeguard is implemented: Enforce Remote Wipe Capability on Portable End-User Devices; Policy/standard covering CIS Control 4 (Secure Configuration of Enterprise Assets and Software); Configuration / tooling output demonstrating the safeguard
Common gap: Safeguard implemented for some assets but not all in scope
Source framework: CIS Controls v8
CIS v8 CIS-10.1 Deploy and Maintain Anti-Malware Software

Deploy and maintain anti-malware software on all enterprise assets.

Evidence an auditor accepts: Evidence the safeguard is implemented: Deploy and Maintain Anti-Malware Software; Policy/standard covering CIS Control 10 (Malware Defenses); Configuration / tooling output demonstrating the safeguard
Common gap: Safeguard implemented for some assets but not all in scope
Source framework: CIS Controls v8
CIS v8 CIS-11.2 Perform Automated Backups

Perform automated backups of in-scope enterprise assets. Run backups weekly, or more frequently, based on the sensitivity of the data.

Evidence an auditor accepts: Evidence the safeguard is implemented: Perform Automated Backups; Policy/standard covering CIS Control 11 (Data Recovery); Configuration / tooling output demonstrating the safeguard
Common gap: Safeguard implemented for some assets but not all in scope
Source framework: CIS Controls v8
CIS v8 CIS-11.4 Establish and Maintain an Isolated Instance of Recovery Data

Establish and maintain an isolated instance of recovery data. Example implementations include, version controlling backup destinations through offline, cloud, or off-site systems or services.

Evidence an auditor accepts: Evidence the safeguard is implemented: Establish and Maintain an Isolated Instance of Recovery Data; Policy/standard covering CIS Control 11 (Data Recovery); Configuration / tooling output demonstrating the safeguard
Common gap: Safeguard implemented for some assets but not all in scope
Source framework: CIS Controls v8
CIS v8 CIS-12.7 Ensure Remote Devices Utilize a VPN and are Connecting to an Enterprise’s AAA Infrastructure

Require users to authenticate to enterprise-managed VPN and authentication services prior to accessing enterprise resources on end-user devices.

Evidence an auditor accepts: Evidence the safeguard is implemented: Ensure Remote Devices Utilize a VPN and are Connecting to an Enterpris; Policy/standard covering CIS Control 12 (Network Infrastructure Management); Configuration / tooling output demonstrating the safeguard
Common gap: Safeguard implemented for some assets but not all in scope
Source framework: CIS Controls v8

See which clauses your list engages

Paste the list and every site names the clauses behind it, filtered to the regimes that apply to you. Eight sites free, no account.

Build my edge register