CIS Controls v8
Rendered when the buyer ticks "CIS Controls v8". The register cites 6 of its 153 clauses, behind 3 findings: intermittent or no link, and no backup stated, home and field devices with encryption not stated, hardware questions unanswered, and on the duty rows of every site it reaches.
Requirement text drawn from the compliance.theartofservice.com corpus, read against the held text of each standard: the corpus statement of each clause, not the instrument verbatim. Source framework: CIS Controls v8. What it attaches to a site: the CIS v8 regime page.
Clauses cited
6 of 153CIS v8 CIS-1.1 Establish and Maintain Detailed Enterprise Asset InventoryEstablish and maintain an accurate, detailed, and up-to-date inventory of all enterprise assets with the potential to store or process data, to include: end-user devices (including portable and mobile), network devices, non-computing/IoT devices, and servers. Ensure the inventory records the network address (if static), hardware address, machine name, enterprise asset owner, department for each asset, and whether the asset has been approved to connect to the network. For mobile end-user devices, MDM type tools can support this process, where appropriate. This inventory includes assets connected to the infrastructure physically, virtually, remotely, and those within cloud environments. Additionally, it includes assets that are regularly connected to the enterprise’s network infrastructure, even if they are not under control of the enterprise. Review and update the inventory of all enterprise assets bi-annually, or more frequently.
Common gap: Safeguard implemented for some assets but not all in scope
Source framework: CIS Controls v8
CIS v8 CIS-4.11 Enforce Remote Wipe Capability on Portable End-User DevicesRemotely wipe enterprise data from enterprise-owned portable end-user devices when deemed appropriate such as lost or stolen devices, or when an individual no longer supports the enterprise.
Common gap: Safeguard implemented for some assets but not all in scope
Source framework: CIS Controls v8
CIS v8 CIS-10.1 Deploy and Maintain Anti-Malware SoftwareDeploy and maintain anti-malware software on all enterprise assets.
Common gap: Safeguard implemented for some assets but not all in scope
Source framework: CIS Controls v8
CIS v8 CIS-11.2 Perform Automated BackupsPerform automated backups of in-scope enterprise assets. Run backups weekly, or more frequently, based on the sensitivity of the data.
Common gap: Safeguard implemented for some assets but not all in scope
Source framework: CIS Controls v8
CIS v8 CIS-11.4 Establish and Maintain an Isolated Instance of Recovery DataEstablish and maintain an isolated instance of recovery data. Example implementations include, version controlling backup destinations through offline, cloud, or off-site systems or services.
Common gap: Safeguard implemented for some assets but not all in scope
Source framework: CIS Controls v8
CIS v8 CIS-12.7 Ensure Remote Devices Utilize a VPN and are Connecting to an Enterprise’s AAA InfrastructureRequire users to authenticate to enterprise-managed VPN and authentication services prior to accessing enterprise resources on end-user devices.
Common gap: Safeguard implemented for some assets but not all in scope
Source framework: CIS Controls v8
See which clauses your list engages
Paste the list and every site names the clauses behind it, filtered to the regimes that apply to you. Eight sites free, no account.
Build my edge register