CIS Control MAPPING SCOPE

Scope Overview

Scoping decisions for mapping CIS Critical Security Controls (CIS Controls) are documented below. These scoping decisions were used for control review and selection for mapping according to the Mapping Methodology. For more information about the framework itself, please refer to CIS's resources.

General Scoping Decisions

Operational vs. Policy and Procedural Controls
This effort is focused on the technical and operational elements of the CIS Controls and did not take into account the management elements that are often focused on organization specific policies and procedures. This decision was made because management specific capabilities are policy-based, and the intent of this effort was focusing on technical and operation capabilities that correlate to ATT&CK mitigations, techniques, and sub-techniques.
Mitigation vs. Monitoring
Capabilities that may only monitor adversary behaviors are out of scope. The focus of this effort is on technical capabilities that mitigate adversary techniques and sub-techniques. Consideration is not given for the potential that an adversary might be dissuaded or change their tactics to try and avoid detection if they thought activity was being monitored.
Controls vs.Safeguards
This effort maps at the CIS Safeguard level. Consideration was given to each Safeguard's control grouping for context.
Implicit vs. Explicit Mitigation
This effort focuses on system-specific technical mitigations (e.g., block USB devices, perform data backups) and capabilities that support those mitigations rather than other, non-technical methods of mitigation (e.g., permit physical access to systems, develop a backup policy).
Pre-compromise Mitigation
Those techniques only associated with the Pre-compromise Mitigation are excluded. These apply to techniques occurring before an adversary gains Initial Access, such as Reconnaissance and Resource Development techniques, and are considered out of scope.

CIS Control Scoping Decisions

The CIS scoping decisions are captured below at the CIS Control level along with our rationale for capabilities in those categories being in or out of scope:

Control Family In Scope Rationale
CIS Control 1: Inventory and Control of Enterprise Assets No Enterprise asset inventory safeguards are out of scope as they do not provide technical capabilities that directly mitigate adversary techniques.
CIS Control 2: Inventory and Control of Software Assets Yes The software asset inventory safeguards that implement technical controls to mitigate adversary techniques are in scope.
CIS Control 3: Data Protection Yes Data Protection family is in scope as it provides technical and operational controls for protecting organizational data.
CIS Control 4: Secure Configuration of Enterprise Assets and Software Yes Configuration Management safeguards that provide technical and operational controls for maintaining secure configuration of assets and software are in scope.
CIS Control 5: Account Management Yes Access Control family is in scope as it provides technical and operational controls for managing and enforcing identification and authentication of network and system users and devices.
CIS Control 6: Access Control Management Yes Access Control family is in scope as it provides technical and operational controls for the control and enforcement of system access, accounts, and information.
CIS Control 7: Continuous Vulnerability Management Yes Continuous Vulnerability Management safeguards that provide for the remediation of vulnerabilities are in scope.
CIS Control 8: Audit Log Management No Audit safeguards are not applicable as they do not provide mitigations of specific threats but instead detect successful attacks.
CIS Control 9: Email and Web Browser Protections Yes Email and web browser protections are in scope as they provide technical and operational controls for protecting against threats.
CIS Control 10: Malware Defenses Yes Malware safeguards that provide technical and operational controls for protecting against threats.
CIS Control 11: Data Recovery Yes Data Recovery family is in scope as it provides technical and operational controls for protecting organizational data.
CIS Control 12: Network Infrastructure Management Yes Network Infrastructure Management safeguards that provide technical and operational controls for implementing security at the network level are in scope.
CIS Control 13: Network Monitoring and Defense Yes Network Monitoring and Defense safeguards that provide technical and operational controls for implementing security at the network level are in scope.
CIS Control 14: Security Awareness and Skills Training No Awareness and Training controls are not applicable as they are for general security awareness training and not specific threat mitigations.
CIS Control 15: Service Provider Management Yes Service Provider Management safeguards are generally out of scope except where directly supporting technical actions that mitigate adversary techniques.
CIS Control 16: Application Software Security Yes Application Software Security safeguards that implement technical controls to mitigate adversary techniques are in scope.
CIS Control 17: Incident Response Management No The Incident Response safeguards are out of scope as they primarily provide for management and governance activities.
CIS Control 18: Penetration Testing Yes Penetration testing safeguards are generally out of scope except where directly support technical actions that protect against adversary techniques.