
Goal: Select and implement necessary cybersecurity controls
Domain 1: Management & Governance
- Information Security Policy
- Acceptable Use Policy (AUP)
- Password Policy
- Remote Working Policy
- Bring Your Own Device (BYOD) Policy
- Data Classification & Handling Policy
- AI Usage Policy
- Removable Media Policy
- Web Publishing Policy
- Privacy Policy
- Backup & Recovery
- Alternate Sites
- Incident Response (IR) Policy & Plan
- Incident Response Procedures & Playbooks
- Data Breach Policy
- Disaster Recovery Plan (DRP)
- Business Continuity Plan (BCP)
- Third Party Risk Management Policy
Domain 2: Physical
- Perimeter Security
- Entrance Protection
- Visitor Logs
- Device Locks
- Privacy Filters
- Asset Tags
- Cabling Security
- Server Room & Network Closet Protections
- Security Cameras
- Redundant Power Sources
- Surge Protection
- Temperature Control
- Fire Detection & Suppression
- Leak Detection
- Removal of Unnecessary Hardware Components
Domain 3: Personnel
- Screening & Background Checks
- Onboarding, Transfer, and Offboarding Procedures
- Nondisclosure Agreements (NDAs)
- Return of Assets
- Separation of Duties
- Job Rotation
- Mandatory Vacations
- Split Knowledge & Dual Authorization
- Clear Desks & Screens
- Contact With Law Enforcement & Cybercrime Authorities
Domain 4: Identity
- Identity Provider selection & standardization
- Identity & Access Management (IAM) Lifecycle
- Provisioning & De-Provisioning
- Privileged Access Management (PAM)
- Just Enough Access (JEA) & Just In Time (JIT) Access
- Account Lockout
- Multifactor Authentication (MFA)
- Passwordless Authentication
- Password Managers
- Conditional Access
- User & Entity Behavior Analytics (UEBA)
- Session Monitoring
- Federation & Single-Sign On (SSO)
- Privileged Access Workstations (PAWs)
Domain 5: Network
- Default Credentials
- Local & Remote Network Infrastructure Management
- Wi-Fi Standards & Security Protocols
- 802.1X Authentication
- Wireless Transmission Power
- Hidden SSID Broadcast
- Obscured Configuration Pages
- Wireless Access Schedule
- MAC Address Filtering
- Port Security
- DHCP Snooping
- Dynamic ARP Inspection (DAI)
- Network Address Translation (NAT)
- Network Firewalls
- Macrosegmentation
- Microsegmentation
- Three Dumb Routers
- Access Control Lists (ACL)
- Network Access Control (NAC)
- Software Defined Networking (SDN)
- Content Filtering & DNS Sinkholing
- Virtual Private Network (VPN)
- Proxy Servers
- Intrusion Detection & Prevention Systems (IDPS)
- Demilitarized Zone (DMZ) for Public-Facing Systems
- Backup Internet Service Provider (ISP)
- Etherchannel (Link Aggregation)
- Spanning Tree Protocol (STP)
- First Hop Redundancy Protocol (FHRP)
- Cisco IOS Hardening
- DNSSEC
- Email Security Gateway (SEG) & Spam Filters
- DMARC, DKIM, SPF
- Network Time Protocol (NTP)
Domain 6: Endpoint
- Operating System Selection
- Enterprise Mobility Management
- Workgroups
- Active Directory (AD) Domains
- Mobile Device Management (MDM)
- Mobile Application Management (MAM)
- Baselines & Golden Images
- Device Provisioning
- Windows Hardening
- Linux Hardening
- Updates & Patch Management
- Refresh Cycles
- Trusted Platform Module (TPM)
- Unified Extensible Firmware Interface (UEFI)
- UEFI Secure Boot
- Host Firewalls
- Host Intrusion Detection & Prevention Systems (HIDS/HIPS)
- Anti-Malware Software
- Application Whitelisting
- Web Browser Protections
- Adblocking
- Full Disk Encryption (FDE)
- File Integrity Monitoring (FIM)
- Endpoint Detection and Response (EDR) & Extended Detection and Response (XDR)
Domain 7: Data
- Encryption in Transit (TLS, IPSec)
- Encryption at Rest
- Public Key Infrastructure (PKI)
- Data Loss Prevention (DLP)
- Data Tokenization
- Data Watermarking
- File/Folder Encryption
- Redundant Array of Inexpensive Disks (RAID)
- Data Retention & Archiving
- Media Sanitization & Data Destruction
- Steganography
Domain 8: Third Party, Cloud, and Supply Chain
- Shared Responsibility Models
- Service Level Agreements (SLAs)
- Security Clauses in Contracts
- Right to Audit
- Third Party Audit Requirements
- Trusted Supplier Register
- Vendor Security Questionnaires
- Secure Attestations
- Annual Vendor Reviews
- Hardware Root of Trust
- Software Bill of Materials (SBOM)
- Code Signing
- Cloud Security Posture Management (CSPM)
- Cloud Access Security Broker (CASB)
- Security Access Service Edge (SASE)
- Content Delivery Networks (CDNs)
Domain 9: Security Operations
- Event Logging & Monitoring
- Security Information & Event Management (SIEM)
- Security Orchestration, Automation, and Response (SOAR)
- Ticketing Systems
- System Health Monitoring
- Artificial Intelligence (AI) Assistance in Cybersecurity
- Communication Channels
- Maintenance Windows & Blackout Periods
- Configuration & Change Management
- Vulnerability Assessments & Management
- Penetration Testing
- Forensic Investigations
