Law / Frameworks / CIS Controls
CIS Critical Security Controls
Below are its 153 Safeguards in the framework's own order, and under each one the laws we track that bear on it. Each mapping is our reading that a law bears on a Safeguard, never a finding that running the Safeguard meets the law.
Where the law lands in the framework
9of 153 Safeguards have law175laws108places
Of these laws, 161 are in force, 12 not yet in force, and 2 proposed and not law.
14 of the 14 Safeguards under 16 have no law we track under them.
- in force
- not yet in force
- blocked by a court
- proposed
- no law we track
Read through the kinds of duty each cybersecurity law we track carries, counting a kind of duty only where the law's own requirement lines, as read against the NIST Cybersecurity Framework, bear it out.
1
0 of 5 Safeguards with lawKnowing every device on the network and dealing with the ones nobody approved.
| Control | What it says | Laws, by state | Laws | Places | Not yet in force | Proposed |
|---|---|---|---|---|---|---|
| 1.1 | A maintained list of every enterprise device, with the details needed to manage it. no law we track | no law we track | ||||
| 1.2 | A routine for removing, quarantining or approving devices found on the network without authorization. no law we track | no law we track | ||||
| 1.3 | Scanning the network on a schedule to find devices that are connected. no law we track | no law we track | ||||
| 1.4 | Using address-assignment logs as a feed for keeping the device list current. no law we track | no law we track | ||||
| 1.5 | Listening to network traffic to spot devices without sending probes. no law we track | no law we track | ||||
2
0 of 7 Safeguards with lawKnowing what software runs where, and blocking software that has not been approved.
| Control | What it says | Laws, by state | Laws | Places | Not yet in force | Proposed |
|---|---|---|---|---|---|---|
| 2.1 | A maintained list of the software in use, with its owner, version and purpose. no law we track | no law we track | ||||
| 2.2 | Checking that approved software still receives vendor updates, and dealing with the rest. no law we track | no law we track | ||||
| 2.3 | A routine for removing or approving software found running without authorization. no law we track | no law we track | ||||
| 2.4 | Using tooling to keep the software list up to date. no law we track | no law we track | ||||
| 2.5 | Allowing only approved programs to run. no law we track | no law we track | ||||
| 2.6 | Allowing only approved code libraries to load. no law we track | no law we track | ||||
| 2.7 | Allowing only approved scripts to execute. no law we track | no law we track | ||||
3
4 of 14 Safeguards with lawHandling data according to its sensitivity from creation to disposal, including encryption.
| Control | What it says | Laws, by state | Laws | Places | Not yet in force | Proposed |
|---|---|---|---|---|---|---|
| 3.1 | A documented approach for how data is handled, owned, kept and disposed of. no law we track | no law we track | ||||
| 3.2 | A maintained catalogue of the sensitive data the enterprise holds and where it sits. 51 laws, 4 not yet in force, 1 proposed | 51 | 46 | 4 | 1 | |
| 3.3 | Permissions on data stores that limit who can read or change each set of data. no law we track | no law we track | ||||
| 3.4 | Keeping data only for the period the enterprise has set, then removing it. no law we track | no law we track | ||||
| 3.5 | Destroying data in a way that fits its sensitivity and storage type. 9 laws | 9 | 9 | 0 | 0 | |
| 3.6 | Encryption of information stored on laptops, phones and similar devices. no law we track | no law we track | ||||
| 3.7 | A scheme that sorts data into sensitivity levels with handling rules for each. no law we track | no law we track | ||||
| 3.8 | Recording how sensitive data moves between systems and parties. no law we track | no law we track | ||||
| 3.9 | Encryption of data placed on removable storage. no law we track | no law we track | ||||
| 3.10 | Encryption of sensitive data as it crosses networks. 65 laws, 7 not yet in force, 1 proposed | 65 | 52 | 7 | 1 | |
| 3.11 | Encryption of sensitive data where it is stored on servers and applications. 65 laws, 7 not yet in force, 1 proposed | 65 | 52 | 7 | 1 | |
| 3.12 | Keeping data of different sensitivity in separate processing and storage environments. no law we track | no law we track | ||||
| 3.13 | Tooling that detects and blocks sensitive data leaving the enterprise. no law we track | no law we track | ||||
| 3.14 | Records of who reached sensitive data. no law we track | no law we track | ||||
4
0 of 12 Safeguards with lawHardened baseline settings for devices and software, and keeping them in place.
| Control | What it says | Laws, by state | Laws | Places | Not yet in force | Proposed |
|---|---|---|---|---|---|---|
| 4.1 | A documented, maintained method for setting up and reviewing safe configurations. no law we track | no law we track | ||||
| 4.2 | A documented, maintained method for safe configurations of network devices. no law we track | no law we track | ||||
| 4.3 | Screens that lock by themselves after a period of inactivity. no law we track | no law we track | ||||
| 4.4 | A host firewall running on servers, with rules that are managed. no law we track | no law we track | ||||
| 4.5 | A host firewall running on user devices, with rules that are managed. no law we track | no law we track | ||||
| 4.6 | Managing devices and software over secure channels rather than plain ones. no law we track | no law we track | ||||
| 4.7 | Handling vendor default accounts by changing, disabling or removing them. no law we track | no law we track | ||||
| 4.8 | Switching off or removing services that the business does not need. no law we track | no law we track | ||||
| 4.9 | Pointing devices only at name servers the enterprise trusts. no law we track | no law we track | ||||
| 4.10 | Portable devices that lock themselves out after repeated failed unlock attempts. no law we track | no law we track | ||||
| 4.11 | The ability to erase a lost or stolen portable device remotely. no law we track | no law we track | ||||
| 4.12 | Keeping work and personal data apart on mobile devices. no law we track | no law we track | ||||
5
0 of 6 Safeguards with lawTracking and managing the accounts of people, administrators and services.
| Control | What it says | Laws, by state | Laws | Places | Not yet in force | Proposed |
|---|---|---|---|---|---|---|
| 5.1 | A maintained list of all accounts with owner, dates and role. no law we track | no law we track | ||||
| 5.2 | A different password for each account. no law we track | no law we track | ||||
| 5.3 | Turning off accounts that have gone unused for a set period. no law we track | no law we track | ||||
| 5.4 | Administrators using separate, dedicated accounts for privileged work. no law we track | no law we track | ||||
| 5.5 | A maintained list of non-human accounts used by systems and services. no law we track | no law we track | ||||
| 5.6 | One central place to manage accounts. no law we track | no law we track | ||||
6
1 of 8 Safeguards with lawGranting, removing and tightening access, including multi-factor sign-in and role-based rules.
| Control | What it says | Laws, by state | Laws | Places | Not yet in force | Proposed |
|---|---|---|---|---|---|---|
| 6.1 | A defined routine for giving people access when they join or change roles. no law we track | no law we track | ||||
| 6.2 | A defined routine for taking access away when people leave or change roles. no law we track | no law we track | ||||
| 6.3 | Multi-factor sign-in on applications that face the internet. no law we track | no law we track | ||||
| 6.4 | Multi-factor sign-in for reaching the network from outside. no law we track | no law we track | ||||
| 6.5 | Multi-factor sign-in for all administrator accounts. no law we track | no law we track | ||||
| 6.6 | A maintained list of the systems that verify identity and grant access. no law we track | no law we track | ||||
| 6.7 | Routing access decisions through a central directory or single sign-on service. no law we track | no law we track | ||||
| 6.8 | Access rights defined by job role, and kept up to date. 65 laws, 7 not yet in force, 1 proposed | 65 | 52 | 7 | 1 | |
7
1 of 7 Safeguards with lawFinding, ranking and fixing weaknesses, including patching and scanning.
| Control | What it says | Laws, by state | Laws | Places | Not yet in force | Proposed |
|---|---|---|---|---|---|---|
| 7.1 | A documented, reviewed approach to finding and handling weaknesses. 65 laws, 7 not yet in force, 1 proposed | 65 | 52 | 7 | 1 | |
| 7.2 | A documented approach to ranking and fixing weaknesses within set timeframes. no law we track | no law we track | ||||
| 7.3 | Automated updates for operating systems. no law we track | no law we track | ||||
| 7.4 | Automated updates for applications. no law we track | no law we track | ||||
| 7.5 | Regular automated scans of internal devices for weaknesses. no law we track | no law we track | ||||
| 7.6 | Regular automated scans of internet-facing devices for weaknesses. no law we track | no law we track | ||||
| 7.7 | Fixing the weaknesses that scans and reviews turn up, in order of risk. no law we track | no law we track | ||||
8
1 of 12 Safeguards with lawRecording, storing, centralizing and reviewing event logs.
| Control | What it says | Laws, by state | Laws | Places | Not yet in force | Proposed |
|---|---|---|---|---|---|---|
| 8.1 | A documented approach to collecting, storing, reviewing and disposing of logs. no law we track | no law we track | ||||
| 8.2 | Turning on and gathering logs from the enterprise's systems. 59 laws, 4 not yet in force, 1 proposed | 59 | 54 | 4 | 1 | |
| 8.3 | Enough log storage that records are not lost or overwritten early. no law we track | no law we track | ||||
| 8.4 | Clocks on all systems synchronized to common sources. no law we track | no law we track | ||||
| 8.5 | Logs that record enough detail to reconstruct events, such as who, what and where. no law we track | no law we track | ||||
| 8.6 | Logs of domain-name lookups made by systems. no law we track | no law we track | ||||
| 8.7 | Logs of web addresses requested through the enterprise's network. no law we track | no law we track | ||||
| 8.8 | Logs of commands typed on systems, including scripting shells. no law we track | no law we track | ||||
| 8.9 | Bringing logs together in one location for analysis and storage. no law we track | no law we track | ||||
| 8.10 | Keeping logs for a set period. no law we track | no law we track | ||||
| 8.11 | Regular human review of logs to spot anomalies. no law we track | no law we track | ||||
| 8.12 | Gathering logs that outside providers produce for the enterprise's use. no law we track | no law we track | ||||
9
0 of 7 Safeguards with lawReducing risk that arrives through browsers, mail and web addresses.
| Control | What it says | Laws, by state | Laws | Places | Not yet in force | Proposed |
|---|---|---|---|---|---|---|
| 9.1 | Running only browsers and mail programs that the vendor still supports. no law we track | no law we track | ||||
| 9.2 | Filtering domain-name lookups to block known harmful sites. no law we track | no law we track | ||||
| 9.3 | Filtering web addresses at the network level by category or reputation. no law we track | no law we track | ||||
| 9.4 | Limiting the add-ons that browsers and mail programs may install. no law we track | no law we track | ||||
| 9.5 | Publishing and enforcing a DMARC policy to protect the enterprise's mail domains from spoofing. no law we track | no law we track | ||||
| 9.6 | Stopping mail attachment types that the business has no need for. no law we track | no law we track | ||||
| 9.7 | Malware scanning on the mail server. no law we track | no law we track | ||||
10
0 of 7 Safeguards with lawEndpoint defenses against hostile code and the way it spreads.
| Control | What it says | Laws, by state | Laws | Places | Not yet in force | Proposed |
|---|---|---|---|---|---|---|
| 10.1 | Anti-malware software installed and kept running on devices. no law we track | no law we track | ||||
| 10.2 | Anti-malware detection data that updates by itself. no law we track | no law we track | ||||
| 10.3 | Preventing removable media from launching programs automatically. no law we track | no law we track | ||||
| 10.4 | Automatic malware scans when removable media is connected. no law we track | no law we track | ||||
| 10.5 | Turning on the operating system's built-in defenses against exploits. no law we track | no law we track | ||||
| 10.6 | Managing anti-malware software from a central console. no law we track | no law we track | ||||
| 10.7 | Malware detection based on how software behaves rather than on known signatures. no law we track | no law we track | ||||
11
0 of 5 Safeguards with lawBackups and the tested ability to restore systems and data after an incident.
| Control | What it says | Laws, by state | Laws | Places | Not yet in force | Proposed |
|---|---|---|---|---|---|---|
| 11.1 | A documented approach for backing up and restoring in-scope data. no law we track | no law we track | ||||
| 11.2 | Backups that run on a schedule without manual steps. no law we track | no law we track | ||||
| 11.3 | Applying the same protection to backups as to the source data, including encryption and access limits. no law we track | no law we track | ||||
| 11.4 | A copy of recovery data kept separate from the main environment. no law we track | no law we track | ||||
| 11.5 | Trial restores to show that recovery works. no law we track | no law we track | ||||
12
0 of 8 Safeguards with lawKeeping network equipment current, documented and securely run.
| Control | What it says | Laws, by state | Laws | Places | Not yet in force | Proposed |
|---|---|---|---|---|---|---|
| 12.1 | Keeping network devices on supported software and firmware. no law we track | no law we track | ||||
| 12.2 | A documented network design that is reviewed and maintained. no law we track | no law we track | ||||
| 12.3 | Managing network devices over secure, authenticated channels. no law we track | no law we track | ||||
| 12.4 | Current diagrams of the network design. no law we track | no law we track | ||||
| 12.5 | Central authentication, authorization and accounting for network devices. no law we track | no law we track | ||||
| 12.6 | Using encrypted protocols for running and reaching network equipment. no law we track | no law we track | ||||
| 12.7 | Remote devices connecting through a VPN into the enterprise's central access services. no law we track | no law we track | ||||
| 12.8 | Separate, dedicated machines used only for administrative tasks. no law we track | no law we track | ||||
13
0 of 11 Safeguards with lawWatching for and stopping hostile activity on the network, and tuning the alerts.
| Control | What it says | Laws, by state | Laws | Places | Not yet in force | Proposed |
|---|---|---|---|---|---|---|
| 13.1 | Bringing security event alerts into one place. no law we track | no law we track | ||||
| 13.2 | Intrusion detection running on individual hosts. no law we track | no law we track | ||||
| 13.3 | Intrusion detection running on the network. no law we track | no law we track | ||||
| 13.4 | Filtering traffic that passes between network segments. no law we track | no law we track | ||||
| 13.5 | Controlling which remote devices may reach enterprise resources. no law we track | no law we track | ||||
| 13.6 | Records of traffic flows across the network. no law we track | no law we track | ||||
| 13.7 | Intrusion prevention running on individual hosts. no law we track | no law we track | ||||
| 13.8 | Intrusion prevention running on the network. no law we track | no law we track | ||||
| 13.9 | Port-level admission control, such as 802.1x, for devices joining the network. no law we track | no law we track | ||||
| 13.10 | Filtering traffic at the application layer. no law we track | no law we track | ||||
| 13.11 | Adjusting alert thresholds to cut noise while keeping real detections. no law we track | no law we track | ||||
14
0 of 9 Safeguards with lawTeaching staff to spot and report threats and to handle data properly.
| Control | What it says | Laws, by state | Laws | Places | Not yet in force | Proposed |
|---|---|---|---|---|---|---|
| 14.1 | A running program that builds security habits across the workforce. no law we track | no law we track | ||||
| 14.2 | Training staff to recognize phishing, pretexting and similar manipulation. no law we track | no law we track | ||||
| 14.3 | Training staff in sound sign-in practice, such as passwords and multi-factor use. no law we track | no law we track | ||||
| 14.4 | Training staff to store, transfer, archive and destroy sensitive data properly. no law we track | no law we track | ||||
| 14.5 | Training staff on how data gets exposed by accident, such as misdelivery or careless publishing. no law we track | no law we track | ||||
| 14.6 | Training staff to notice a possible incident and report it. no law we track | no law we track | ||||
| 14.7 | Training staff to tell when their devices are behind on updates and to report it. no law we track | no law we track | ||||
| 14.8 | Training staff on the risks of using untrusted networks for work. no law we track | no law we track | ||||
| 14.9 | Extra training matched to the security duties of specific roles. no law we track | no law we track | ||||
15
1 of 7 Safeguards with lawVetting, contracting with and watching outside providers that hold data or run critical services.
| Control | What it says | Laws, by state | Laws | Places | Not yet in force | Proposed |
|---|---|---|---|---|---|---|
| 15.1 | A maintained list of the outside providers the enterprise depends on. no law we track | no law we track | ||||
| 15.2 | A policy for how providers are evaluated, contracted and overseen. no law we track | no law we track | ||||
| 15.3 | Sorting providers by factors such as data sensitivity and criticality. no law we track | no law we track | ||||
| 15.4 | Contracts that spell out security duties for the provider. 1 law | 1 | 1 | 0 | 0 | |
| 15.5 | Evaluating providers against the policy, scaled to how they are classed. no law we track | no law we track | ||||
| 15.6 | Watching providers over the life of the relationship. no law we track | no law we track | ||||
| 15.7 | Closing out a provider by revoking access and handling its data. no law we track | no law we track | ||||
16
0 of 14 Safeguards with lawBuilding and buying software with security practices across its whole life.
| Control | What it says | Laws, by state | Laws | Places | Not yet in force | Proposed |
|---|---|---|---|---|---|---|
| 16.1 | A documented, reviewed process for building software with security in mind. no law we track | no law we track | ||||
| 16.2 | A way for outsiders to report software flaws and for the enterprise to act on them. no law we track | no law we track | ||||
| 16.3 | Finding the underlying cause of a security flaw so it does not recur. no law we track | no law we track | ||||
| 16.4 | A maintained list of outside components used in the enterprise's software. no law we track | no law we track | ||||
| 16.5 | Choosing outside components that are current and from reliable sources. no law we track | no law we track | ||||
| 16.6 | A scale for rating how serious a software flaw is, with a process that uses it. no law we track | no law we track | ||||
| 16.7 | Using standard hardened settings for the infrastructure that applications run on. no law we track | no law we track | ||||
| 16.8 | Keeping live and development or test environments apart. no law we track | no law we track | ||||
| 16.9 | Teaching developers secure coding and application security concepts. no law we track | no law we track | ||||
| 16.10 | Applying design principles that limit the damage of application weaknesses. no law we track | no law we track | ||||
| 16.11 | Reusing proven modules or services for security functions instead of writing new ones. no law we track | no law we track | ||||
| 16.12 | Automated and manual checks of code for security defects. no law we track | no law we track | ||||
| 16.13 | Attack-style testing of running applications. no law we track | no law we track | ||||
| 16.14 | Analyzing a design for how it could be attacked and how to respond. no law we track | no law we track | ||||
17
1 of 9 Safeguards with lawBeing ready for, and carrying out, the handling of security incidents.
| Control | What it says | Laws, by state | Laws | Places | Not yet in force | Proposed |
|---|---|---|---|---|---|---|
| 17.1 | Naming the people who run incident handling, with a backup. no law we track | no law we track | ||||
| 17.2 | A maintained list of who to contact about a security incident, inside and outside the enterprise. 77 laws, 4 not yet in force | 77 | 66 | 4 | 0 | |
| 17.3 | A defined way for the workforce to report incidents, with timing and what to include. no law we track | no law we track | ||||
| 17.4 | A documented plan for responding to incidents, reviewed on a schedule. no law we track | no law we track | ||||
| 17.5 | Defining who does what during an incident. no law we track | no law we track | ||||
| 17.6 | Choosing in advance how responders will communicate, including backup channels. no law we track | no law we track | ||||
| 17.7 | Practice runs of the response plan with the people who would carry it out. no law we track | no law we track | ||||
| 17.8 | A review after each incident to record what happened and what to change. no law we track | no law we track | ||||
| 17.9 | Agreed criteria for what counts as an incident and how serious it is. no law we track | no law we track | ||||
18
0 of 5 Safeguards with lawTesting defenses by simulating what an attacker would do.
| Control | What it says | Laws, by state | Laws | Places | Not yet in force | Proposed |
|---|---|---|---|---|---|---|
| 18.1 | A defined program for testing defenses by simulated attack. no law we track | no law we track | ||||
| 18.2 | Regular attack simulations from outside the network. no law we track | no law we track | ||||
| 18.3 | Fixing what penetration tests find, guided by the enterprise's risk rules. no law we track | no law we track | ||||
| 18.4 | Testing that the protective measures behave as intended under attack conditions. no law we track | no law we track | ||||
| 18.5 | Regular attack simulations from inside the network. no law we track | no law we track | ||||
Where the law and the framework part
144 of the 153 Safeguards have no law we track under them.
Kinds of duty this framework has no Safeguard for: access restriction, age verification, attribution, biometric, consent, content labelling, data subject rights, design code, disclosure, DPIA, licensing, prohibition, TDM.
The framework's text
CIS Critical Security Controls® (CIS Controls®) v8.1 © Center for Internet Security, Inc. Safeguard numbers are used under a CIS Controls Supporter License; the one-line descriptions beside them are our own, not CIS text.
Read it from the publisher: cas.docs.cisecurity.org