Law / Frameworks / CIS Controls

CIS Critical Security Controls

Below are its 153 Safeguards in the framework's own order, and under each one the laws we track that bear on it. Each mapping is our reading that a law bears on a Safeguard, never a finding that running the Safeguard meets the law.

Where the law lands in the framework

9of 153 Safeguards have law175laws108places

1.1: no law we track1.2: no law we track1.3: no law we track1.4: no law we track1.5: no law we track2.1: no law we track2.2: no law we track2.3: no law we track2.4: no law we track2.5: no law we track2.6: no law we track2.7: no law we track3.1: no law we track3.2: 51 laws in 46 places3.3: no law we track3.4: no law we track3.5: 9 laws in 9 places3.6: no law we track3.7: no law we track3.8: no law we track3.9: no law we track3.10: 65 laws in 52 places3.10 653.11: 65 laws in 52 places3.12: no law we track3.13: no law we track3.14: no law we track4.1: no law we track4.2: no law we track4.3: no law we track4.4: no law we track4.5: no law we track4.6: no law we track4.7: no law we track4.8: no law we track4.9: no law we track4.10: no law we track4.11: no law we track4.12: no law we track5.1: no law we track5.2: no law we track5.3: no law we track5.4: no law we track5.5: no law we track5.6: no law we track6.1: no law we track6.2: no law we track6.3: no law we track6.4: no law we track6.5: no law we track6.6: no law we track6.7: no law we track6.8: 65 laws in 52 places6.8 657.1: 65 laws in 52 places7.2: no law we track7.3: no law we track7.4: no law we track7.5: no law we track7.6: no law we track7.7: no law we track8.1: no law we track8.2: 59 laws in 54 places8.3: no law we track8.4: no law we track8.5: no law we track8.6: no law we track8.7: no law we track8.8: no law we track8.9: no law we track8.10: no law we track8.11: no law we track8.12: no law we track9.1: no law we track9.2: no law we track9.3: no law we track9.4: no law we track9.5: no law we track9.6: no law we track9.7: no law we track10.1: no law we track10.2: no law we track10.3: no law we track10.4: no law we track10.5: no law we track10.6: no law we track10.7: no law we track11.1: no law we track11.2: no law we track11.3: no law we track11.4: no law we track11.5: no law we track12.1: no law we track12.2: no law we track12.3: no law we track12.4: no law we track12.5: no law we track12.6: no law we track12.7: no law we track12.8: no law we track13.1: no law we track13.2: no law we track13.3: no law we track13.4: no law we track13.5: no law we track13.6: no law we track13.7: no law we track13.8: no law we track13.9: no law we track13.10: no law we track13.11: no law we track14.1: no law we track14.2: no law we track14.3: no law we track14.4: no law we track14.5: no law we track14.6: no law we track14.7: no law we track14.8: no law we track14.9: no law we track15.1: no law we track15.2: no law we track15.3: no law we track15.4: 1 law in 1 place15.5: no law we track15.6: no law we track15.7: no law we track16.1: no law we track16.2: no law we track16.3: no law we track16.4: no law we track16.5: no law we track16.6: no law we track16.7: no law we track16.8: no law we track16.9: no law we track16.10: no law we track16.11: no law we track16.12: no law we track16.13: no law we track16.14: no law we track17.1: no law we track17.2: 77 laws in 66 places17.2 7717.3: no law we track17.4: no law we track17.5: no law we track17.6: no law we track17.7: no law we track17.8: no law we track17.9: no law we track18.1: no law we track18.2: no law we track18.3: no law we track18.4: no law we track18.5: no law we track123456789101112131415161718

Of these laws, 161 are in force, 12 not yet in force, and 2 proposed and not law.

14 of the 14 Safeguards under 16 have no law we track under them.

  • in force
  • not yet in force
  • blocked by a court
  • proposed
  • no law we track
A bar's height is its number of laws. Select one to open the Safeguard.

Read through the kinds of duty each cybersecurity law we track carries, counting a kind of duty only where the law's own requirement lines, as read against the NIST Cybersecurity Framework, bear it out.

1

0 of 5 Safeguards with law

Knowing every device on the network and dealing with the ones nobody approved.

ControlWhat it saysLaws, by stateLawsPlacesNot yet in forceProposed
1.1 A maintained list of every enterprise device, with the details needed to manage it. no law we track no law we track
1.2 A routine for removing, quarantining or approving devices found on the network without authorization. no law we track no law we track
1.3 Scanning the network on a schedule to find devices that are connected. no law we track no law we track
1.4 Using address-assignment logs as a feed for keeping the device list current. no law we track no law we track
1.5 Listening to network traffic to spot devices without sending probes. no law we track no law we track

2

0 of 7 Safeguards with law

Knowing what software runs where, and blocking software that has not been approved.

ControlWhat it saysLaws, by stateLawsPlacesNot yet in forceProposed
2.1 A maintained list of the software in use, with its owner, version and purpose. no law we track no law we track
2.2 Checking that approved software still receives vendor updates, and dealing with the rest. no law we track no law we track
2.3 A routine for removing or approving software found running without authorization. no law we track no law we track
2.4 Using tooling to keep the software list up to date. no law we track no law we track
2.5 Allowing only approved programs to run. no law we track no law we track
2.6 Allowing only approved code libraries to load. no law we track no law we track
2.7 Allowing only approved scripts to execute. no law we track no law we track

3

4 of 14 Safeguards with law

Handling data according to its sensitivity from creation to disposal, including encryption.

ControlWhat it saysLaws, by stateLawsPlacesNot yet in forceProposed
3.1 A documented approach for how data is handled, owned, kept and disposed of. no law we track no law we track
3.2 A maintained catalogue of the sensitive data the enterprise holds and where it sits. 51 laws, 4 not yet in force, 1 proposed 51 46 4 1
3.3 Permissions on data stores that limit who can read or change each set of data. no law we track no law we track
3.4 Keeping data only for the period the enterprise has set, then removing it. no law we track no law we track
3.5 Destroying data in a way that fits its sensitivity and storage type. 9 laws 9 9 0 0
3.6 Encryption of information stored on laptops, phones and similar devices. no law we track no law we track
3.7 A scheme that sorts data into sensitivity levels with handling rules for each. no law we track no law we track
3.8 Recording how sensitive data moves between systems and parties. no law we track no law we track
3.9 Encryption of data placed on removable storage. no law we track no law we track
3.10 Encryption of sensitive data as it crosses networks. 65 laws, 7 not yet in force, 1 proposed 65 52 7 1
3.11 Encryption of sensitive data where it is stored on servers and applications. 65 laws, 7 not yet in force, 1 proposed 65 52 7 1
3.12 Keeping data of different sensitivity in separate processing and storage environments. no law we track no law we track
3.13 Tooling that detects and blocks sensitive data leaving the enterprise. no law we track no law we track
3.14 Records of who reached sensitive data. no law we track no law we track

4

0 of 12 Safeguards with law

Hardened baseline settings for devices and software, and keeping them in place.

ControlWhat it saysLaws, by stateLawsPlacesNot yet in forceProposed
4.1 A documented, maintained method for setting up and reviewing safe configurations. no law we track no law we track
4.2 A documented, maintained method for safe configurations of network devices. no law we track no law we track
4.3 Screens that lock by themselves after a period of inactivity. no law we track no law we track
4.4 A host firewall running on servers, with rules that are managed. no law we track no law we track
4.5 A host firewall running on user devices, with rules that are managed. no law we track no law we track
4.6 Managing devices and software over secure channels rather than plain ones. no law we track no law we track
4.7 Handling vendor default accounts by changing, disabling or removing them. no law we track no law we track
4.8 Switching off or removing services that the business does not need. no law we track no law we track
4.9 Pointing devices only at name servers the enterprise trusts. no law we track no law we track
4.10 Portable devices that lock themselves out after repeated failed unlock attempts. no law we track no law we track
4.11 The ability to erase a lost or stolen portable device remotely. no law we track no law we track
4.12 Keeping work and personal data apart on mobile devices. no law we track no law we track

5

0 of 6 Safeguards with law

Tracking and managing the accounts of people, administrators and services.

ControlWhat it saysLaws, by stateLawsPlacesNot yet in forceProposed
5.1 A maintained list of all accounts with owner, dates and role. no law we track no law we track
5.2 A different password for each account. no law we track no law we track
5.3 Turning off accounts that have gone unused for a set period. no law we track no law we track
5.4 Administrators using separate, dedicated accounts for privileged work. no law we track no law we track
5.5 A maintained list of non-human accounts used by systems and services. no law we track no law we track
5.6 One central place to manage accounts. no law we track no law we track

6

1 of 8 Safeguards with law

Granting, removing and tightening access, including multi-factor sign-in and role-based rules.

ControlWhat it saysLaws, by stateLawsPlacesNot yet in forceProposed
6.1 A defined routine for giving people access when they join or change roles. no law we track no law we track
6.2 A defined routine for taking access away when people leave or change roles. no law we track no law we track
6.3 Multi-factor sign-in on applications that face the internet. no law we track no law we track
6.4 Multi-factor sign-in for reaching the network from outside. no law we track no law we track
6.5 Multi-factor sign-in for all administrator accounts. no law we track no law we track
6.6 A maintained list of the systems that verify identity and grant access. no law we track no law we track
6.7 Routing access decisions through a central directory or single sign-on service. no law we track no law we track
6.8 Access rights defined by job role, and kept up to date. 65 laws, 7 not yet in force, 1 proposed 65 52 7 1

7

1 of 7 Safeguards with law

Finding, ranking and fixing weaknesses, including patching and scanning.

ControlWhat it saysLaws, by stateLawsPlacesNot yet in forceProposed
7.1 A documented, reviewed approach to finding and handling weaknesses. 65 laws, 7 not yet in force, 1 proposed 65 52 7 1
7.2 A documented approach to ranking and fixing weaknesses within set timeframes. no law we track no law we track
7.3 Automated updates for operating systems. no law we track no law we track
7.4 Automated updates for applications. no law we track no law we track
7.5 Regular automated scans of internal devices for weaknesses. no law we track no law we track
7.6 Regular automated scans of internet-facing devices for weaknesses. no law we track no law we track
7.7 Fixing the weaknesses that scans and reviews turn up, in order of risk. no law we track no law we track

8

1 of 12 Safeguards with law

Recording, storing, centralizing and reviewing event logs.

ControlWhat it saysLaws, by stateLawsPlacesNot yet in forceProposed
8.1 A documented approach to collecting, storing, reviewing and disposing of logs. no law we track no law we track
8.2 Turning on and gathering logs from the enterprise's systems. 59 laws, 4 not yet in force, 1 proposed 59 54 4 1
8.3 Enough log storage that records are not lost or overwritten early. no law we track no law we track
8.4 Clocks on all systems synchronized to common sources. no law we track no law we track
8.5 Logs that record enough detail to reconstruct events, such as who, what and where. no law we track no law we track
8.6 Logs of domain-name lookups made by systems. no law we track no law we track
8.7 Logs of web addresses requested through the enterprise's network. no law we track no law we track
8.8 Logs of commands typed on systems, including scripting shells. no law we track no law we track
8.9 Bringing logs together in one location for analysis and storage. no law we track no law we track
8.10 Keeping logs for a set period. no law we track no law we track
8.11 Regular human review of logs to spot anomalies. no law we track no law we track
8.12 Gathering logs that outside providers produce for the enterprise's use. no law we track no law we track

9

0 of 7 Safeguards with law

Reducing risk that arrives through browsers, mail and web addresses.

ControlWhat it saysLaws, by stateLawsPlacesNot yet in forceProposed
9.1 Running only browsers and mail programs that the vendor still supports. no law we track no law we track
9.2 Filtering domain-name lookups to block known harmful sites. no law we track no law we track
9.3 Filtering web addresses at the network level by category or reputation. no law we track no law we track
9.4 Limiting the add-ons that browsers and mail programs may install. no law we track no law we track
9.5 Publishing and enforcing a DMARC policy to protect the enterprise's mail domains from spoofing. no law we track no law we track
9.6 Stopping mail attachment types that the business has no need for. no law we track no law we track
9.7 Malware scanning on the mail server. no law we track no law we track

10

0 of 7 Safeguards with law

Endpoint defenses against hostile code and the way it spreads.

ControlWhat it saysLaws, by stateLawsPlacesNot yet in forceProposed
10.1 Anti-malware software installed and kept running on devices. no law we track no law we track
10.2 Anti-malware detection data that updates by itself. no law we track no law we track
10.3 Preventing removable media from launching programs automatically. no law we track no law we track
10.4 Automatic malware scans when removable media is connected. no law we track no law we track
10.5 Turning on the operating system's built-in defenses against exploits. no law we track no law we track
10.6 Managing anti-malware software from a central console. no law we track no law we track
10.7 Malware detection based on how software behaves rather than on known signatures. no law we track no law we track

11

0 of 5 Safeguards with law

Backups and the tested ability to restore systems and data after an incident.

ControlWhat it saysLaws, by stateLawsPlacesNot yet in forceProposed
11.1 A documented approach for backing up and restoring in-scope data. no law we track no law we track
11.2 Backups that run on a schedule without manual steps. no law we track no law we track
11.3 Applying the same protection to backups as to the source data, including encryption and access limits. no law we track no law we track
11.4 A copy of recovery data kept separate from the main environment. no law we track no law we track
11.5 Trial restores to show that recovery works. no law we track no law we track

12

0 of 8 Safeguards with law

Keeping network equipment current, documented and securely run.

ControlWhat it saysLaws, by stateLawsPlacesNot yet in forceProposed
12.1 Keeping network devices on supported software and firmware. no law we track no law we track
12.2 A documented network design that is reviewed and maintained. no law we track no law we track
12.3 Managing network devices over secure, authenticated channels. no law we track no law we track
12.4 Current diagrams of the network design. no law we track no law we track
12.5 Central authentication, authorization and accounting for network devices. no law we track no law we track
12.6 Using encrypted protocols for running and reaching network equipment. no law we track no law we track
12.7 Remote devices connecting through a VPN into the enterprise's central access services. no law we track no law we track
12.8 Separate, dedicated machines used only for administrative tasks. no law we track no law we track

13

0 of 11 Safeguards with law

Watching for and stopping hostile activity on the network, and tuning the alerts.

ControlWhat it saysLaws, by stateLawsPlacesNot yet in forceProposed
13.1 Bringing security event alerts into one place. no law we track no law we track
13.2 Intrusion detection running on individual hosts. no law we track no law we track
13.3 Intrusion detection running on the network. no law we track no law we track
13.4 Filtering traffic that passes between network segments. no law we track no law we track
13.5 Controlling which remote devices may reach enterprise resources. no law we track no law we track
13.6 Records of traffic flows across the network. no law we track no law we track
13.7 Intrusion prevention running on individual hosts. no law we track no law we track
13.8 Intrusion prevention running on the network. no law we track no law we track
13.9 Port-level admission control, such as 802.1x, for devices joining the network. no law we track no law we track
13.10 Filtering traffic at the application layer. no law we track no law we track
13.11 Adjusting alert thresholds to cut noise while keeping real detections. no law we track no law we track

14

0 of 9 Safeguards with law

Teaching staff to spot and report threats and to handle data properly.

ControlWhat it saysLaws, by stateLawsPlacesNot yet in forceProposed
14.1 A running program that builds security habits across the workforce. no law we track no law we track
14.2 Training staff to recognize phishing, pretexting and similar manipulation. no law we track no law we track
14.3 Training staff in sound sign-in practice, such as passwords and multi-factor use. no law we track no law we track
14.4 Training staff to store, transfer, archive and destroy sensitive data properly. no law we track no law we track
14.5 Training staff on how data gets exposed by accident, such as misdelivery or careless publishing. no law we track no law we track
14.6 Training staff to notice a possible incident and report it. no law we track no law we track
14.7 Training staff to tell when their devices are behind on updates and to report it. no law we track no law we track
14.8 Training staff on the risks of using untrusted networks for work. no law we track no law we track
14.9 Extra training matched to the security duties of specific roles. no law we track no law we track

15

1 of 7 Safeguards with law

Vetting, contracting with and watching outside providers that hold data or run critical services.

ControlWhat it saysLaws, by stateLawsPlacesNot yet in forceProposed
15.1 A maintained list of the outside providers the enterprise depends on. no law we track no law we track
15.2 A policy for how providers are evaluated, contracted and overseen. no law we track no law we track
15.3 Sorting providers by factors such as data sensitivity and criticality. no law we track no law we track
15.4 Contracts that spell out security duties for the provider. 1 law 1 1 0 0
15.5 Evaluating providers against the policy, scaled to how they are classed. no law we track no law we track
15.6 Watching providers over the life of the relationship. no law we track no law we track
15.7 Closing out a provider by revoking access and handling its data. no law we track no law we track

16

0 of 14 Safeguards with law

Building and buying software with security practices across its whole life.

ControlWhat it saysLaws, by stateLawsPlacesNot yet in forceProposed
16.1 A documented, reviewed process for building software with security in mind. no law we track no law we track
16.2 A way for outsiders to report software flaws and for the enterprise to act on them. no law we track no law we track
16.3 Finding the underlying cause of a security flaw so it does not recur. no law we track no law we track
16.4 A maintained list of outside components used in the enterprise's software. no law we track no law we track
16.5 Choosing outside components that are current and from reliable sources. no law we track no law we track
16.6 A scale for rating how serious a software flaw is, with a process that uses it. no law we track no law we track
16.7 Using standard hardened settings for the infrastructure that applications run on. no law we track no law we track
16.8 Keeping live and development or test environments apart. no law we track no law we track
16.9 Teaching developers secure coding and application security concepts. no law we track no law we track
16.10 Applying design principles that limit the damage of application weaknesses. no law we track no law we track
16.11 Reusing proven modules or services for security functions instead of writing new ones. no law we track no law we track
16.12 Automated and manual checks of code for security defects. no law we track no law we track
16.13 Attack-style testing of running applications. no law we track no law we track
16.14 Analyzing a design for how it could be attacked and how to respond. no law we track no law we track

17

1 of 9 Safeguards with law

Being ready for, and carrying out, the handling of security incidents.

ControlWhat it saysLaws, by stateLawsPlacesNot yet in forceProposed
17.1 Naming the people who run incident handling, with a backup. no law we track no law we track
17.2 A maintained list of who to contact about a security incident, inside and outside the enterprise. 77 laws, 4 not yet in force 77 66 4 0
17.3 A defined way for the workforce to report incidents, with timing and what to include. no law we track no law we track
17.4 A documented plan for responding to incidents, reviewed on a schedule. no law we track no law we track
17.5 Defining who does what during an incident. no law we track no law we track
17.6 Choosing in advance how responders will communicate, including backup channels. no law we track no law we track
17.7 Practice runs of the response plan with the people who would carry it out. no law we track no law we track
17.8 A review after each incident to record what happened and what to change. no law we track no law we track
17.9 Agreed criteria for what counts as an incident and how serious it is. no law we track no law we track

18

0 of 5 Safeguards with law

Testing defenses by simulating what an attacker would do.

ControlWhat it saysLaws, by stateLawsPlacesNot yet in forceProposed
18.1 A defined program for testing defenses by simulated attack. no law we track no law we track
18.2 Regular attack simulations from outside the network. no law we track no law we track
18.3 Fixing what penetration tests find, guided by the enterprise's risk rules. no law we track no law we track
18.4 Testing that the protective measures behave as intended under attack conditions. no law we track no law we track
18.5 Regular attack simulations from inside the network. no law we track no law we track

Where the law and the framework part

144 of the 153 Safeguards have no law we track under them.

Kinds of duty this framework has no Safeguard for: access restriction, age verification, attribution, biometric, consent, content labelling, data subject rights, design code, disclosure, DPIA, licensing, prohibition, TDM.

The framework's text

CIS Critical Security Controls® (CIS Controls®) v8.1 © Center for Internet Security, Inc. Safeguard numbers are used under a CIS Controls Supporter License; the one-line descriptions beside them are our own, not CIS text.

Read it from the publisher: cas.docs.cisecurity.org