FoundationCIS Controls 1 & 2NIST CSF ID.AMISO 27001 A.5.9
Authoritative asset and identity inventory
Maintain a single, reconciled view of devices, servers, cloud resources, identities and internet facing services.
Implementation
- Reconcile at least three sources: directory, device management and network or cloud discovery.
- Record an owner and a business service for every asset, not just a hostname.
- Treat anything discovered but unmanaged as an exception with a due date.
- Include internet facing services and public DNS records in the same inventory.
Evidence
Dated inventory export with unmanaged asset count and exception list.
Reduces
IdentityCIS Control 6NIST CSF PR.AAISO 27001 A.5.15 A.5.18NIST SP 800-207
Identity access baseline
Every interactive sign in is multi factor, legacy authentication is impossible, and privilege is temporary.
Implementation
- Require phishing resistant multi factor for administrators and remote access.
- Block legacy authentication protocols outright at the identity provider.
- Remove standing privileged role assignment; require activation with approval and expiry.
- Separate cloud only administrative accounts from everyday user accounts.
- Maintain break glass accounts, excluded from conditional access, stored offline and monitored.
Evidence
Policy export, count of privileged standing assignments, legacy auth sign in report.
Reduces
EndpointsCIS Controls 4 & 10NIST CSF PR.PSISO 27001 A.8.1
Managed endpoint baseline
Every device that accesses corporate data is enrolled, configured to a baseline, encrypted, patched and monitored.
Implementation
- Enrolment as a condition of access, enforced by conditional access rather than policy text.
- Apply a published security baseline and record every deviation with a reason.
- Full disk encryption with escrowed recovery keys.
- Remove standing local administrator rights; unique rotated local admin passwords.
- Endpoint detection with tamper protection and centrally enforced policy.
Evidence
Compliance report by policy, encryption coverage, agent health percentage.
Reduces
NetworkCIS Controls 12 & 13NIST CSF PR.IRISO 27001 A.8.20 A.8.22
Network segmentation and egress control
Traffic is permitted by explicit intent, east west movement is constrained, and outbound access from servers is limited.
Implementation
- Document intended flows per zone before writing rules; remove any any rules.
- Block workstation to workstation administrative protocols with host firewall policy.
- Restrict management protocols to dedicated administrative sources.
- Filter server egress to named destinations; alert on anything else.
- Place management interfaces of infrastructure on an out of band network.
Evidence
Zone to zone flow matrix, rule review date, count of any any rules remaining.
Reduces
ApplicationsCIS Control 9NIST CSF PR.DSISO 27001 A.8.23
Email authentication and message hygiene
Your domains cannot be trivially spoofed, and inbound messages are inspected at delivery and after it.
Implementation
- Publish SPF, DKIM and a DMARC policy that moves beyond monitoring to reject.
- Enable link and attachment inspection, including time of click evaluation.
- Block or quarantine external senders impersonating internal display names.
- Alert on mail forwarding rules created to external destinations.
- Give users a one click report path with a triage service behind it.
Evidence
DNS record export, DMARC aggregate reports, forwarding rule alert history.
Reduces
OperationsCIS Control 7NIST CSF ID.RAISO 27001 A.8.8
Vulnerability and patch cadence
Exposure is measured continuously, and remediation timescales are defined by exposure and exploitation, not by convenience.
Implementation
- Authenticated scanning across servers, endpoints, cloud workloads and appliances.
- Separate emergency lane for internet facing and actively exploited vulnerabilities.
- Defined remediation windows by severity, agreed with service owners in advance.
- Track exceptions with a compensating control and an expiry date.
- Report trend and ageing, not raw vulnerability counts.
Evidence
Ageing report by severity, patch compliance percentage, open exception register.
Reduces
DetectionCIS Control 8NIST CSF DE.CMISO 27001 A.8.15 A.8.16MITRE ATT&CK
Logging and detection coverage
The sources that matter are collected, retained long enough to investigate, and mapped to the techniques you care about.
Implementation
- Collect identity provider, endpoint, network edge, cloud control plane and email telemetry as a minimum.
- Retain at least twelve months for identity and authentication data.
- Map detection rules to technique coverage and record the gaps deliberately.
- Alert on absence of telemetry, not only on events.
- Write each alert with a triage procedure, or do not deploy it.
Evidence
Source inventory with ingestion status, retention settings, technique coverage map.
Reduces
ResilienceCIS Control 11NIST CSF PR.DS & RC.RPISO 27001 A.8.13
Protected and tested recovery
At least one backup copy cannot be destroyed by an intruder holding production administrative rights, and restores are proven.
Implementation
- Immutable retention on at least one copy, plus one logically isolated or offline copy.
- Backup administration on separate credentials, outside the production directory.
- Protect configuration and identity data, not just file and database content.
- Test restores on a schedule and record actual elapsed time against the agreed objective.
- Document dependency order for recovery, including DNS, identity and certificates.
Evidence
Restore test records with elapsed times, immutability settings, isolation design.
Reduces
GovernanceCIS Control 15NIST CSF GV.SCISO 27001 A.5.19 A.5.22
Third party and integration access control
Every external party and application integration has a named owner, bounded access and an expiry.
Implementation
- No standing privileged access for providers; use approved, time bound activation.
- Inventory application registrations and integration accounts with granted scopes.
- Review and expire granted permissions on a fixed cycle.
- Require your own multi factor and device conditions on partner identities.
- Record notification and log sharing obligations in the contract.
Evidence
Third party access register, application permission review records, contract clauses.
Reduces
ResponseCIS Control 17NIST CSF RS.MANIST SP 800-61ISO 27001 A.5.24 A.5.28
Tested incident response capability
Response authority, communications and evidence handling are agreed before an incident, and rehearsed.
Implementation
- Named incident commander role and a documented authority to disconnect systems.
- Out of band communication channel that survives loss of the production estate.
- Evidence preservation steps that precede remediation, including identity data that ages out.
- Contact list covering legal, insurance, regulator and key suppliers, kept current.
- Exercise at least annually, including a scenario where the identity provider is compromised.
Evidence
Plan version and approval date, exercise report, contact list review date.
Reduces