Goal: Select and implement necessary cybersecurity controls

Domain 1: Management & Governance

  1. Information Security Policy
  2. Acceptable Use Policy (AUP)
  3. Password Policy
  4. Remote Working Policy
  5. Bring Your Own Device (BYOD) Policy
  6. Data Classification & Handling Policy
  7. AI Usage Policy
  8. Removable Media Policy
  9. Web Publishing Policy
  10. Privacy Policy
  11. Backup & Recovery
  12. Alternate Sites
  13. Incident Response (IR) Policy & Plan
  14. Incident Response Procedures & Playbooks
  15. Data Breach Policy
  16. Disaster Recovery Plan (DRP)
  17. Business Continuity Plan (BCP)
  18. Third Party Risk Management Policy

Domain 2: Physical

  1. Perimeter Security
  2. Entrance Protection
  3. Visitor Logs
  4. Device Locks
  5. Privacy Filters
  6. Asset Tags
  7. Cabling Security
  8. Server Room & Network Closet Protections
  9. Security Cameras
  10. Redundant Power Sources
  11. Surge Protection
  12. Temperature Control
  13. Fire Detection & Suppression
  14. Leak Detection
  15. Removal of Unnecessary Hardware Components

Domain 3: Personnel

  1. Screening & Background Checks
  2. Onboarding, Transfer, and Offboarding Procedures
  3. Nondisclosure Agreements (NDAs)
  4. Return of Assets
  5. Separation of Duties
  6. Job Rotation
  7. Mandatory Vacations
  8. Split Knowledge & Dual Authorization
  9. Clear Desks & Screens
  10. Contact With Law Enforcement & Cybercrime Authorities

Domain 4: Identity

  1. Identity Provider selection & standardization
  2. Identity & Access Management (IAM) Lifecycle
  3. Provisioning & De-Provisioning
  4. Privileged Access Management (PAM)
  5. Just Enough Access (JEA) & Just In Time (JIT) Access
  6. Account Lockout
  7. Multifactor Authentication (MFA)
  8. Passwordless Authentication
  9. Password Managers
  10. Conditional Access
  11. User & Entity Behavior Analytics (UEBA)
  12. Session Monitoring
  13. Federation & Single-Sign On (SSO)
  14. Privileged Access Workstations (PAWs)

Domain 5: Network

  1. Default Credentials
  2. Local & Remote Network Infrastructure Management
  3. Wi-Fi Standards & Security Protocols
  4. 802.1X Authentication
  5. Wireless Transmission Power
  6. Hidden SSID Broadcast
  7. Obscured Configuration Pages
  8. Wireless Access Schedule
  9. MAC Address Filtering
  10. Port Security
  11. DHCP Snooping
  12. Dynamic ARP Inspection (DAI)
  13. Network Address Translation (NAT)
  14. Network Firewalls
  15. Macrosegmentation
  16. Microsegmentation
  17. Three Dumb Routers
  18. Access Control Lists (ACL)
  19. Network Access Control (NAC)
  20. Software Defined Networking (SDN)
  21. Content Filtering & DNS Sinkholing
  22. Virtual Private Network (VPN)
  23. Proxy Servers
  24. Intrusion Detection & Prevention Systems (IDPS)
  25. Demilitarized Zone (DMZ) for Public-Facing Systems
  26. Backup Internet Service Provider (ISP)
  27. Etherchannel (Link Aggregation)
  28. Spanning Tree Protocol (STP)
  29. First Hop Redundancy Protocol (FHRP)
  30. Cisco IOS Hardening
  31. DNSSEC
  32. Email Security Gateway (SEG) & Spam Filters
  33. DMARC, DKIM, SPF
  34. Network Time Protocol (NTP)

Domain 6: Endpoint

  1. Operating System Selection
  2. Enterprise Mobility Management
  3. Workgroups
  4. Active Directory (AD) Domains
  5. Mobile Device Management (MDM)
  6. Mobile Application Management (MAM)
  7. Baselines & Golden Images
  8. Device Provisioning
  9. Windows Hardening
  10. Linux Hardening
  11. Updates & Patch Management
  12. Refresh Cycles
  13. Trusted Platform Module (TPM)
  14. Unified Extensible Firmware Interface (UEFI)
  15. UEFI Secure Boot
  16. Host Firewalls
  17. Host Intrusion Detection & Prevention Systems (HIDS/HIPS)
  18. Anti-Malware Software
  19. Application Whitelisting
  20. Web Browser Protections
  21. Adblocking
  22. Full Disk Encryption (FDE)
  23. File Integrity Monitoring (FIM)
  24. Endpoint Detection and Response (EDR) & Extended Detection and Response (XDR)

Domain 7: Data

  1. Encryption in Transit (TLS, IPSec)
  2. Encryption at Rest
  3. Public Key Infrastructure (PKI)
  4. Data Loss Prevention (DLP)
  5. Data Tokenization
  6. Data Watermarking
  7. File/Folder Encryption
  8. Redundant Array of Inexpensive Disks (RAID)
  9. Data Retention & Archiving
  10. Media Sanitization & Data Destruction
  11. Steganography

Domain 8: Third Party, Cloud, and Supply Chain

  1. Shared Responsibility Models
  2. Service Level Agreements (SLAs)
  3. Security Clauses in Contracts
  4. Right to Audit
  5. Third Party Audit Requirements
  6. Trusted Supplier Register
  7. Vendor Security Questionnaires
  8. Secure Attestations
  9. Annual Vendor Reviews
  10. Hardware Root of Trust
  11. Software Bill of Materials (SBOM)
  12. Code Signing
  13. Cloud Security Posture Management (CSPM)
  14. Cloud Access Security Broker (CASB)
  15. Security Access Service Edge (SASE)
  16. Content Delivery Networks (CDNs)

Domain 9: Security Operations

  1. Event Logging & Monitoring
  2. Security Information & Event Management (SIEM)
  3. Security Orchestration, Automation, and Response (SOAR)
  4. Ticketing Systems
  5. System Health Monitoring
  6. Artificial Intelligence (AI) Assistance in Cybersecurity
  7. Communication Channels
  8. Maintenance Windows & Blackout Periods
  9. Configuration & Change Management
  10. Vulnerability Assessments & Management
  11. Penetration Testing
  12. Forensic Investigations