CIS Controls v7 The Center for Internet Security · CIS Control v7 Launched on March 19, 2018 from...

79
CIS Controls v7 The Center for Internet Security https://www.cisecurity.org/controls/ Partially Translated to Thai by Songkrant Muneenaem CC.PSU. 1May2018

Transcript of CIS Controls v7 The Center for Internet Security · CIS Control v7 Launched on March 19, 2018 from...

Page 1: CIS Controls v7 The Center for Internet Security · CIS Control v7 Launched on March 19, 2018 from Critical Security Controls for Effective Cyber Defense (CSC) Version 6.1 on August

CIS Controls v7The Center for Internet Security

https://www.cisecurity.org/controls/

Partially Translated to Thai by Songkrant Muneenaem CC.PSU. 1May2018

Page 2: CIS Controls v7 The Center for Internet Security · CIS Control v7 Launched on March 19, 2018 from Critical Security Controls for Effective Cyber Defense (CSC) Version 6.1 on August
Page 3: CIS Controls v7 The Center for Internet Security · CIS Control v7 Launched on March 19, 2018 from Critical Security Controls for Effective Cyber Defense (CSC) Version 6.1 on August

CIS Control v7 Launched on March 19, 2018

fromCritical Security Controls for Effective Cyber Defense (CSC)Version 6.1 on August 31, 2016

Page 4: CIS Controls v7 The Center for Internet Security · CIS Control v7 Launched on March 19, 2018 from Critical Security Controls for Effective Cyber Defense (CSC) Version 6.1 on August
Page 5: CIS Controls v7 The Center for Internet Security · CIS Control v7 Launched on March 19, 2018 from Critical Security Controls for Effective Cyber Defense (CSC) Version 6.1 on August
Page 6: CIS Controls v7 The Center for Internet Security · CIS Control v7 Launched on March 19, 2018 from Critical Security Controls for Effective Cyber Defense (CSC) Version 6.1 on August
Page 7: CIS Controls v7 The Center for Internet Security · CIS Control v7 Launched on March 19, 2018 from Critical Security Controls for Effective Cyber Defense (CSC) Version 6.1 on August
Page 8: CIS Controls v7 The Center for Internet Security · CIS Control v7 Launched on March 19, 2018 from Critical Security Controls for Effective Cyber Defense (CSC) Version 6.1 on August
Page 9: CIS Controls v7 The Center for Internet Security · CIS Control v7 Launched on March 19, 2018 from Critical Security Controls for Effective Cyber Defense (CSC) Version 6.1 on August

6 Basic CIS Controls

Page 10: CIS Controls v7 The Center for Internet Security · CIS Control v7 Launched on March 19, 2018 from Critical Security Controls for Effective Cyber Defense (CSC) Version 6.1 on August

Basic CIS Controls

1 Inventory and Control of Hardware Assets

(บันทึกรายการและควบคุมทรัพยสินที่เปนฮารดแวร)

Page 11: CIS Controls v7 The Center for Internet Security · CIS Control v7 Launched on March 19, 2018 from Critical Security Controls for Effective Cyber Defense (CSC) Version 6.1 on August
Page 12: CIS Controls v7 The Center for Internet Security · CIS Control v7 Launched on March 19, 2018 from Critical Security Controls for Effective Cyber Defense (CSC) Version 6.1 on August
Page 13: CIS Controls v7 The Center for Internet Security · CIS Control v7 Launched on March 19, 2018 from Critical Security Controls for Effective Cyber Defense (CSC) Version 6.1 on August
Page 14: CIS Controls v7 The Center for Internet Security · CIS Control v7 Launched on March 19, 2018 from Critical Security Controls for Effective Cyber Defense (CSC) Version 6.1 on August
Page 15: CIS Controls v7 The Center for Internet Security · CIS Control v7 Launched on March 19, 2018 from Critical Security Controls for Effective Cyber Defense (CSC) Version 6.1 on August
Page 16: CIS Controls v7 The Center for Internet Security · CIS Control v7 Launched on March 19, 2018 from Critical Security Controls for Effective Cyber Defense (CSC) Version 6.1 on August
Page 17: CIS Controls v7 The Center for Internet Security · CIS Control v7 Launched on March 19, 2018 from Critical Security Controls for Effective Cyber Defense (CSC) Version 6.1 on August

Inventory and Control of Hardware Assets

Page 18: CIS Controls v7 The Center for Internet Security · CIS Control v7 Launched on March 19, 2018 from Critical Security Controls for Effective Cyber Defense (CSC) Version 6.1 on August

Basic CIS Controls

2 Inventory and Control of Software Assets

(บันทึกรายการและควบคุมทรัพยสินที่เปนซอฟตแวร)

Page 19: CIS Controls v7 The Center for Internet Security · CIS Control v7 Launched on March 19, 2018 from Critical Security Controls for Effective Cyber Defense (CSC) Version 6.1 on August

Inventory and Control of Software Assets

Page 20: CIS Controls v7 The Center for Internet Security · CIS Control v7 Launched on March 19, 2018 from Critical Security Controls for Effective Cyber Defense (CSC) Version 6.1 on August

Basic CIS Controls

3 Continuous Vulnerability Management

(จัดการกับชองโหวอยางตอเนื่อง)

Page 21: CIS Controls v7 The Center for Internet Security · CIS Control v7 Launched on March 19, 2018 from Critical Security Controls for Effective Cyber Defense (CSC) Version 6.1 on August

Continuous Vulnerability Management

Page 22: CIS Controls v7 The Center for Internet Security · CIS Control v7 Launched on March 19, 2018 from Critical Security Controls for Effective Cyber Defense (CSC) Version 6.1 on August

Basic CIS Controls

4 Controlled Use of Administrative Privileges

(ควบคุมการใชสิทธิพิเศษในการบริหารระบบ)

Page 23: CIS Controls v7 The Center for Internet Security · CIS Control v7 Launched on March 19, 2018 from Critical Security Controls for Effective Cyber Defense (CSC) Version 6.1 on August

Controlled Use of

Administrative

Privileges

Page 24: CIS Controls v7 The Center for Internet Security · CIS Control v7 Launched on March 19, 2018 from Critical Security Controls for Effective Cyber Defense (CSC) Version 6.1 on August

Basic CIS Controls

5 Secure Configuration for Hardware and Software on Mobile Devices, Laptops, Workstations and Servers

(กําหนดคาที่ปลอดภัยใหกับฮารดแวรและซอฟทแวร บนอุปกรณพกพา แลปทอป เวิรกสเตชั่น และเซิรฟเวอร)

Page 25: CIS Controls v7 The Center for Internet Security · CIS Control v7 Launched on March 19, 2018 from Critical Security Controls for Effective Cyber Defense (CSC) Version 6.1 on August

Secure Configuration for Hardware and Software on Mobile Devices, Laptops, Workstations and Servers

Page 26: CIS Controls v7 The Center for Internet Security · CIS Control v7 Launched on March 19, 2018 from Critical Security Controls for Effective Cyber Defense (CSC) Version 6.1 on August

Basic CIS Controls

6 Maintenance, Monitoring and Analysis of Audit Logs

(บํารุงรักษา เฝาสังเกต และวิเคราะห ขอมูลลอกการใชงานตางๆ)

Page 27: CIS Controls v7 The Center for Internet Security · CIS Control v7 Launched on March 19, 2018 from Critical Security Controls for Effective Cyber Defense (CSC) Version 6.1 on August

Maintenance, Monitoring and Analysis of Audit Logs

Page 28: CIS Controls v7 The Center for Internet Security · CIS Control v7 Launched on March 19, 2018 from Critical Security Controls for Effective Cyber Defense (CSC) Version 6.1 on August
Page 29: CIS Controls v7 The Center for Internet Security · CIS Control v7 Launched on March 19, 2018 from Critical Security Controls for Effective Cyber Defense (CSC) Version 6.1 on August

10 Foundational CIS Controls

Page 30: CIS Controls v7 The Center for Internet Security · CIS Control v7 Launched on March 19, 2018 from Critical Security Controls for Effective Cyber Defense (CSC) Version 6.1 on August

Foundational CIS Controls

7 Email and Web Browser Protections

(ปองกันอีเมล และเว็บเบราวเซอร)

Page 31: CIS Controls v7 The Center for Internet Security · CIS Control v7 Launched on March 19, 2018 from Critical Security Controls for Effective Cyber Defense (CSC) Version 6.1 on August

Email and Web Browser Protections

Page 32: CIS Controls v7 The Center for Internet Security · CIS Control v7 Launched on March 19, 2018 from Critical Security Controls for Effective Cyber Defense (CSC) Version 6.1 on August

Foundational CIS Controls

8 Malware Defenses

(ปองกันมัลแวร)Malicious software (Longdo Dictionary)ออกแบบมาดวยจุดประสงคแอบแฝงบางอยาง จุดประสงคดังกลาวอาจจะเพื่อสรางหนาตางโฆษณาที่เปดขึ้นมาเองโดยอัติโนมัติ ดวยความหวังที่วาจะใหคุณกดเขาไปและสรางรายไดใหกับบุคคลเหลานั้น หรือ รูปแบบของ spyware และ ไวรัสคอมพิวเตอร ที่สามารถใชเพื่อการขโมยตัวตนของคุณบนอินเตอรเน็ต หรือ ติดตามกิจกรรมตางของคุณ

Page 33: CIS Controls v7 The Center for Internet Security · CIS Control v7 Launched on March 19, 2018 from Critical Security Controls for Effective Cyber Defense (CSC) Version 6.1 on August

Malware Defenses

Page 34: CIS Controls v7 The Center for Internet Security · CIS Control v7 Launched on March 19, 2018 from Critical Security Controls for Effective Cyber Defense (CSC) Version 6.1 on August

Foundational CIS Controls

9 Limitation and Control of Network Ports, Protocols, and Services

(จํากัดและควบคุม พอรต โปรโตคอล และบริการตางๆ บนเครือขาย)

Page 35: CIS Controls v7 The Center for Internet Security · CIS Control v7 Launched on March 19, 2018 from Critical Security Controls for Effective Cyber Defense (CSC) Version 6.1 on August

Limitation and Control of Network Ports, Protocols, and Services

Page 36: CIS Controls v7 The Center for Internet Security · CIS Control v7 Launched on March 19, 2018 from Critical Security Controls for Effective Cyber Defense (CSC) Version 6.1 on August

Foundational CIS Controls

10 Data Recovery Capabilities

(ตองกูคืนขอมูลกลับมาได)

Page 37: CIS Controls v7 The Center for Internet Security · CIS Control v7 Launched on March 19, 2018 from Critical Security Controls for Effective Cyber Defense (CSC) Version 6.1 on August

Data Recovery Capabilities

Page 38: CIS Controls v7 The Center for Internet Security · CIS Control v7 Launched on March 19, 2018 from Critical Security Controls for Effective Cyber Defense (CSC) Version 6.1 on August

Foundational CIS Controls

11 Secure Configuration for Network Devices, such as Firewalls, Routers, and Switches

(กําหนดคาที่ปลอดภัยใหกับอุปกรณเครือขายตางๆเชนไฟรวอลล เราเตอร และสวิตช)

Page 39: CIS Controls v7 The Center for Internet Security · CIS Control v7 Launched on March 19, 2018 from Critical Security Controls for Effective Cyber Defense (CSC) Version 6.1 on August

Secure Configuration for Network Devices, such as Firewalls, Routers, and Switches

Page 40: CIS Controls v7 The Center for Internet Security · CIS Control v7 Launched on March 19, 2018 from Critical Security Controls for Effective Cyber Defense (CSC) Version 6.1 on August

Foundational CIS Controls

12 Boundary Defense

(ปองกันเขตเครือขาย)

Page 41: CIS Controls v7 The Center for Internet Security · CIS Control v7 Launched on March 19, 2018 from Critical Security Controls for Effective Cyber Defense (CSC) Version 6.1 on August

Boundary Defense

Page 42: CIS Controls v7 The Center for Internet Security · CIS Control v7 Launched on March 19, 2018 from Critical Security Controls for Effective Cyber Defense (CSC) Version 6.1 on August

Foundational CIS Controls

13 Data Protection

(ปกปองขอมูล)

Page 43: CIS Controls v7 The Center for Internet Security · CIS Control v7 Launched on March 19, 2018 from Critical Security Controls for Effective Cyber Defense (CSC) Version 6.1 on August

Data Protection

Page 44: CIS Controls v7 The Center for Internet Security · CIS Control v7 Launched on March 19, 2018 from Critical Security Controls for Effective Cyber Defense (CSC) Version 6.1 on August

Foundational CIS Controls

14 Controlled Access Based on the

Need to Know

(ควบคุมใหเขาถึงไดเฉพาะสิ่งจําเปน)

Page 45: CIS Controls v7 The Center for Internet Security · CIS Control v7 Launched on March 19, 2018 from Critical Security Controls for Effective Cyber Defense (CSC) Version 6.1 on August

Controlled Access Based on the Need to Know

Page 46: CIS Controls v7 The Center for Internet Security · CIS Control v7 Launched on March 19, 2018 from Critical Security Controls for Effective Cyber Defense (CSC) Version 6.1 on August

Foundational CIS Controls

15 Wireless Access Control

(ควบคุมการเขาถึงผานทางระบบไรสาย)

Page 47: CIS Controls v7 The Center for Internet Security · CIS Control v7 Launched on March 19, 2018 from Critical Security Controls for Effective Cyber Defense (CSC) Version 6.1 on August

Wireless AccessControl

Page 48: CIS Controls v7 The Center for Internet Security · CIS Control v7 Launched on March 19, 2018 from Critical Security Controls for Effective Cyber Defense (CSC) Version 6.1 on August

Foundational CIS Controls

16 Account Monitoring and Control

(เฝาสังเกตและควบคุม บัญชีผูใช)

Page 49: CIS Controls v7 The Center for Internet Security · CIS Control v7 Launched on March 19, 2018 from Critical Security Controls for Effective Cyber Defense (CSC) Version 6.1 on August

Account Monitoring and Control

Page 50: CIS Controls v7 The Center for Internet Security · CIS Control v7 Launched on March 19, 2018 from Critical Security Controls for Effective Cyber Defense (CSC) Version 6.1 on August
Page 51: CIS Controls v7 The Center for Internet Security · CIS Control v7 Launched on March 19, 2018 from Critical Security Controls for Effective Cyber Defense (CSC) Version 6.1 on August

4 Organizational CIS Controls

Page 52: CIS Controls v7 The Center for Internet Security · CIS Control v7 Launched on March 19, 2018 from Critical Security Controls for Effective Cyber Defense (CSC) Version 6.1 on August

Organizational CIS Controls

17 Implement a Security Awareness and Training Program

(ดําเนินการฝกอบรมสรางความตระหนักรูดานความปลอดภัย)

Page 53: CIS Controls v7 The Center for Internet Security · CIS Control v7 Launched on March 19, 2018 from Critical Security Controls for Effective Cyber Defense (CSC) Version 6.1 on August

Implement a Security Awarenessand Training Program

Page 54: CIS Controls v7 The Center for Internet Security · CIS Control v7 Launched on March 19, 2018 from Critical Security Controls for Effective Cyber Defense (CSC) Version 6.1 on August

Organizational CIS Controls

18 Application Software Security

(จัดการความปลอดภัยของซอฟทแวรโปรแกรมประยุกต)

Page 55: CIS Controls v7 The Center for Internet Security · CIS Control v7 Launched on March 19, 2018 from Critical Security Controls for Effective Cyber Defense (CSC) Version 6.1 on August

Application SoftwareSecurity

Page 56: CIS Controls v7 The Center for Internet Security · CIS Control v7 Launched on March 19, 2018 from Critical Security Controls for Effective Cyber Defense (CSC) Version 6.1 on August

Organizational CIS Controls

19 Incident Response and Management

(จัดการและตอบสนองตอเหตุการณที่ไมปลอดภัย)

Page 57: CIS Controls v7 The Center for Internet Security · CIS Control v7 Launched on March 19, 2018 from Critical Security Controls for Effective Cyber Defense (CSC) Version 6.1 on August

Incident Response and Management

Page 58: CIS Controls v7 The Center for Internet Security · CIS Control v7 Launched on March 19, 2018 from Critical Security Controls for Effective Cyber Defense (CSC) Version 6.1 on August

Organizational CIS Controls

20 Penetration Tests and Red Team Exercises

(ทดสอบเจาะสวนตางๆ และฝกซอมบุกรุกทั้งระบบ)

Page 59: CIS Controls v7 The Center for Internet Security · CIS Control v7 Launched on March 19, 2018 from Critical Security Controls for Effective Cyber Defense (CSC) Version 6.1 on August

Penetration Tests and Red Team Exercises

Page 60: CIS Controls v7 The Center for Internet Security · CIS Control v7 Launched on March 19, 2018 from Critical Security Controls for Effective Cyber Defense (CSC) Version 6.1 on August
Page 61: CIS Controls v7 The Center for Internet Security · CIS Control v7 Launched on March 19, 2018 from Critical Security Controls for Effective Cyber Defense (CSC) Version 6.1 on August
Page 62: CIS Controls v7 The Center for Internet Security · CIS Control v7 Launched on March 19, 2018 from Critical Security Controls for Effective Cyber Defense (CSC) Version 6.1 on August
Page 63: CIS Controls v7 The Center for Internet Security · CIS Control v7 Launched on March 19, 2018 from Critical Security Controls for Effective Cyber Defense (CSC) Version 6.1 on August
Page 64: CIS Controls v7 The Center for Internet Security · CIS Control v7 Launched on March 19, 2018 from Critical Security Controls for Effective Cyber Defense (CSC) Version 6.1 on August
Page 65: CIS Controls v7 The Center for Internet Security · CIS Control v7 Launched on March 19, 2018 from Critical Security Controls for Effective Cyber Defense (CSC) Version 6.1 on August

CIS Benchmarks : Secure Your Systems & Platforms

Proven guidelines will enable you to safeguard operating systems, software and networks that are most vulnerable to cyber attacks.

They are continuously verified by a volunteer IT community to combat evolving cybersecurity challenges.

Page 66: CIS Controls v7 The Center for Internet Security · CIS Control v7 Launched on March 19, 2018 from Critical Security Controls for Effective Cyber Defense (CSC) Version 6.1 on August
Page 67: CIS Controls v7 The Center for Internet Security · CIS Control v7 Launched on March 19, 2018 from Critical Security Controls for Effective Cyber Defense (CSC) Version 6.1 on August

CIS Google Chrome Benchmark (for example)

Page 68: CIS Controls v7 The Center for Internet Security · CIS Control v7 Launched on March 19, 2018 from Critical Security Controls for Effective Cyber Defense (CSC) Version 6.1 on August
Page 69: CIS Controls v7 The Center for Internet Security · CIS Control v7 Launched on March 19, 2018 from Critical Security Controls for Effective Cyber Defense (CSC) Version 6.1 on August
Page 70: CIS Controls v7 The Center for Internet Security · CIS Control v7 Launched on March 19, 2018 from Critical Security Controls for Effective Cyber Defense (CSC) Version 6.1 on August

Continuous Improvement for the latestGoogle Chrome 66.0.3359.117 as 27Apr2018

CIS Google Chrome 46 Benchmark [imported] v1.0.0 Published 2 years ago on Oct 30th 2015 : tested against Google Chrome v46.0.2490.80m

CIS Google Chrome Benchmark [imported] v1.1.0 Published 2 years ago on Mar 22nd 2016 : tested against Google Chrome v49.0.2623.87m

CIS Google Chrome Benchmark v1.2.0 Published 9 months ago on Jun 30th 2017 : tested against Google Chrome v59.0.3071.86

CIS Google Chrome Benchmark v1.3.0 Draft : tested against Google Chrome v62.0.3202.75

Page 71: CIS Controls v7 The Center for Internet Security · CIS Control v7 Launched on March 19, 2018 from Critical Security Controls for Effective Cyber Defense (CSC) Version 6.1 on August
Page 72: CIS Controls v7 The Center for Internet Security · CIS Control v7 Launched on March 19, 2018 from Critical Security Controls for Effective Cyber Defense (CSC) Version 6.1 on August
Page 73: CIS Controls v7 The Center for Internet Security · CIS Control v7 Launched on March 19, 2018 from Critical Security Controls for Effective Cyber Defense (CSC) Version 6.1 on August
Page 74: CIS Controls v7 The Center for Internet Security · CIS Control v7 Launched on March 19, 2018 from Critical Security Controls for Effective Cyber Defense (CSC) Version 6.1 on August
Page 75: CIS Controls v7 The Center for Internet Security · CIS Control v7 Launched on March 19, 2018 from Critical Security Controls for Effective Cyber Defense (CSC) Version 6.1 on August

https://www.cisecurity.org/

Page 76: CIS Controls v7 The Center for Internet Security · CIS Control v7 Launched on March 19, 2018 from Critical Security Controls for Effective Cyber Defense (CSC) Version 6.1 on August
Page 77: CIS Controls v7 The Center for Internet Security · CIS Control v7 Launched on March 19, 2018 from Critical Security Controls for Effective Cyber Defense (CSC) Version 6.1 on August
Page 78: CIS Controls v7 The Center for Internet Security · CIS Control v7 Launched on March 19, 2018 from Critical Security Controls for Effective Cyber Defense (CSC) Version 6.1 on August
Page 79: CIS Controls v7 The Center for Internet Security · CIS Control v7 Launched on March 19, 2018 from Critical Security Controls for Effective Cyber Defense (CSC) Version 6.1 on August

Let's make Internet safeFor

Everyone