Scoping decisions for mapping CIS Critical Security Controls (CIS Controls) are documented below. These scoping decisions were used for control review and selection for mapping according to the Mapping Methodology. For more information about the framework itself, please refer to CIS's resources.
The CIS scoping decisions are captured below at the CIS Control level along with our rationale for capabilities in those categories being in or out of scope:
| Control Family | In Scope | Rationale |
|---|---|---|
| CIS Control 1: Inventory and Control of Enterprise Assets | No | Enterprise asset inventory safeguards are out of scope as they do not provide technical capabilities that directly mitigate adversary techniques. |
| CIS Control 2: Inventory and Control of Software Assets | Yes | The software asset inventory safeguards that implement technical controls to mitigate adversary techniques are in scope. |
| CIS Control 3: Data Protection | Yes | Data Protection family is in scope as it provides technical and operational controls for protecting organizational data. |
| CIS Control 4: Secure Configuration of Enterprise Assets and Software | Yes | Configuration Management safeguards that provide technical and operational controls for maintaining secure configuration of assets and software are in scope. |
| CIS Control 5: Account Management | Yes | Access Control family is in scope as it provides technical and operational controls for managing and enforcing identification and authentication of network and system users and devices. |
| CIS Control 6: Access Control Management | Yes | Access Control family is in scope as it provides technical and operational controls for the control and enforcement of system access, accounts, and information. |
| CIS Control 7: Continuous Vulnerability Management | Yes | Continuous Vulnerability Management safeguards that provide for the remediation of vulnerabilities are in scope. |
| CIS Control 8: Audit Log Management | No | Audit safeguards are not applicable as they do not provide mitigations of specific threats but instead detect successful attacks. |
| CIS Control 9: Email and Web Browser Protections | Yes | Email and web browser protections are in scope as they provide technical and operational controls for protecting against threats. |
| CIS Control 10: Malware Defenses | Yes | Malware safeguards that provide technical and operational controls for protecting against threats. |
| CIS Control 11: Data Recovery | Yes | Data Recovery family is in scope as it provides technical and operational controls for protecting organizational data. |
| CIS Control 12: Network Infrastructure Management | Yes | Network Infrastructure Management safeguards that provide technical and operational controls for implementing security at the network level are in scope. |
| CIS Control 13: Network Monitoring and Defense | Yes | Network Monitoring and Defense safeguards that provide technical and operational controls for implementing security at the network level are in scope. |
| CIS Control 14: Security Awareness and Skills Training | No | Awareness and Training controls are not applicable as they are for general security awareness training and not specific threat mitigations. |
| CIS Control 15: Service Provider Management | Yes | Service Provider Management safeguards are generally out of scope except where directly supporting technical actions that mitigate adversary techniques. |
| CIS Control 16: Application Software Security | Yes | Application Software Security safeguards that implement technical controls to mitigate adversary techniques are in scope. |
| CIS Control 17: Incident Response Management | No | The Incident Response safeguards are out of scope as they primarily provide for management and governance activities. |
| CIS Control 18: Penetration Testing | Yes | Penetration testing safeguards are generally out of scope except where directly support technical actions that protect against adversary techniques. |