DiscoverSMB CybercastUsing the CIS 20 security controls as a starting point for a security program (Part 1)
Using the CIS 20 security controls as a starting point for a security program (Part 1)

Using the CIS 20 security controls as a starting point for a security program (Part 1)

Update: 2019-07-09
Share

Description

For small and medium organizations, implementing a formal security program can see like a huge task. 


However, breaking this into small steps can help make that goal seem more attainable. 


The CIS 20 security controls is a framework that every SMB should begin implementing. Under CCPA, organizations that are following a proven framework, will be exempt from some of the litigation liabilities. CIS 20 is one of the frameworks that California attorney generals have accepted in the past. 


If you don't have a security program in place, your organization is like tacking the problem in an ad-hoc manner. Should an attack happen, being organized will give a much greater attempt of surviving. 


https://www.cisecurity.org/controls/cis-controls-list/

Comments 
00:00
00:00
x

0.5x

0.8x

1.0x

1.25x

1.5x

2.0x

3.0x

Sleep Timer

Off

End of Episode

5 Minutes

10 Minutes

15 Minutes

30 Minutes

45 Minutes

60 Minutes

120 Minutes

Using the CIS 20 security controls as a starting point for a security program (Part 1)

Using the CIS 20 security controls as a starting point for a security program (Part 1)

CyberX