CIS Controls
CIS Controls (sebelumnya dikenal sebagai SANS Top 20) adalah 18 kontrol keamanan prioritas yang dikembangkan oleh Center for Internet Security (CIS). Kontrol ini dirancang berdasarkan data serangan nyata dan praktik terbaik dari berbagai organisasi global.
18 CIS Controls v8:
- Inventory and Control of Enterprise Assets - Inventarisasi seluruh hardware
- Inventory and Control of Software Assets - Inventarisasi seluruh software
- Data Protection - Proteksi data: encryption, DLP, backup
- Secure Configuration - Konfigurasi aman perangkat keras/ lunak
- Account Management - Manajemen akun: MFA, least privilege
- Access Control Management - Kontrol akses: RBAC, IAM
- Continuous Vulnerability Management - Vulnerability scanning & patching
- Audit Log Management - Logging dan monitoring
- Email and Web Browser Protections - Keamanan email & browser
- Malware Defenses - Antimalware, EDR
- Data Recovery - Backup & recovery
- Network Infrastructure Management - Keamanan infrastruktur jaringan
- Network Monitoring and Defense - Monitoring jaringan, IDS/IPS
- Security Awareness and Skills Training - Pelatihan keamanan
- Service Provider Management - Keamanan vendor & third-party
- Application Software Security - Keamanan aplikasi
- Incident Response Management - IR playbook & team
- Penetration Testing - Pentest reguler
Implementation Groups (IG):
- IG1 - Essential cyber hygiene (14 controls) - untuk UKM dengan resource terbatas
- IG2 - Advanced (plus 73 safeguards) - untuk organisasi dengan IT staff dedicated
- IG3 - Expert (plus 63 safeguards) - untuk organisasi dengan security team penuh