20 critical security controls your organization should focus on

 

The 20 critical security controls identified in the Consensus Audit Guidelines represent the highest-priority defenses that enterprises should focus on, based on the likelihood of real-world attacks. The categories, which are not presented in order of priority, are broken down into those that can be validated at least in part in an automated manner and those that involve manual validation.

Critical controls subject to automated collection, measurement and validation:

1. Inventory of authorized and unauthorized devices.
2. Inventory of authorized and unauthorized software.
3. Secure configurations for hardware and software on laptop PCs, workstations and servers.
4. Secure configurations for network devices such as firewalls, routers and switches.
5. Boundary defense.
6. Maintenance, monitoring and analysis of security audit logs.
7. Application software security.
8. Controlled use of administrative privileges.
9. Controlled access based on need to know.
10. Continuous vulnerability assessment and remediation.
11. Account monitoring and control.
12. Malware defenses.
13. Limitation and control of network ports, protocols and services.
14. Wireless device control.
15. Data loss prevention.

Additional critical controls, not directly supported by automated measurement and validation:

16. Secure network engineering.
17. Penetration tests and red-team exercises.
18. Incident response capability.
19. Data recovery capability.
20. Security skills assessment and appropriate training to fill gaps.

About the Author

John Moore is a freelance writer based in Syracuse, N.Y.

Featured

  • Telecommunications
    Stock photo ID: 658810513 By asharkyu

    GSA extends EIS deadline to 2023

    Agencies are getting up to three more years on existing telecom contracts before having to shift to the $50 billion Enterprise Infrastructure Solutions vehicle.

  • Workforce
    Shutterstock image ID: 569172169 By Zenzen

    OMB looks to retrain feds to fill cyber needs

    The federal government is taking steps to fill high-demand, skills-gap positions in tech by retraining employees already working within agencies without a cyber or IT background.

  • Acquisition
    GSA Headquarters (Photo by Rena Schild/Shutterstock)

    GSA to consolidate multiple award schedules

    The General Services Administration plans to consolidate dozens of its buying schedules across product areas including IT and services to reduce duplication.

Stay Connected

FCW Update

Sign up for our newsletter.

I agree to this site's Privacy Policy.