Audit Checklist

Per-control audit verification items. Everything needed to demonstrate each control is operating effectively and to the standard defined in the framework.

1

Inventory and Control of Enterprise Assets

5 safeguards · 40 checklist items

IG1: 2
IG2: 4
IG3: 5
Gov: 11
Tech: 10
Ops: 19
2

Inventory and Control of Software Assets

7 safeguards · 49 checklist items

IG1: 3
IG2: 6
IG3: 7
Gov: 15
Tech: 16
Ops: 18
3

Data Protection

14 safeguards · 92 checklist items

IG1: 6
IG2: 12
IG3: 14
Gov: 30
Tech: 28
Ops: 34
4

Secure Configuration of Enterprise Assets and Software

12 safeguards · 87 checklist items

IG1: 7
IG2: 11
IG3: 12
Gov: 27
Tech: 33
Ops: 27
5

Account Management

6 safeguards · 40 checklist items

IG1: 4
IG2: 6
IG3: 6
Gov: 13
Tech: 12
Ops: 15
6

Access Control Management

8 safeguards · 64 checklist items

IG1: 5
IG2: 7
IG3: 8
Gov: 19
Tech: 22
Ops: 23
7

Continuous Vulnerability Management

7 safeguards · 47 checklist items

IG1: 4
IG2: 7
IG3: 7
Gov: 16
Tech: 10
Ops: 21
8

Audit Log Management

12 safeguards · 95 checklist items

IG1: 3
IG2: 11
IG3: 12
Gov: 25
Tech: 37
Ops: 33
9

Email and Web Browser Protections

7 safeguards · 53 checklist items

IG1: 2
IG2: 6
IG3: 7
Gov: 15
Tech: 27
Ops: 11
10

Malware Defenses

7 safeguards · 50 checklist items

IG1: 3
IG2: 7
IG3: 7
Gov: 14
Tech: 20
Ops: 16
11

Data Recovery

5 safeguards · 42 checklist items

IG1: 4
IG2: 5
IG3: 5
Gov: 14
Tech: 13
Ops: 15
12

Network Infrastructure Management

8 safeguards · 50 checklist items

IG1: 1
IG2: 7
IG3: 8
Gov: 16
Tech: 20
Ops: 14
13

Network Monitoring and Defense

11 safeguards · 85 checklist items

IG1: 0
IG2: 6
IG3: 11
Gov: 25
Tech: 31
Ops: 29
14

Security Awareness and Skills Training

9 safeguards · 71 checklist items

IG1: 8
IG2: 9
IG3: 9
Gov: 19
Tech: 21
Ops: 31
15

Service Provider Management

7 safeguards · 58 checklist items

IG1: 1
IG2: 4
IG3: 7
Gov: 22
Tech: 9
Ops: 27
16

Application Software Security

14 safeguards · 117 checklist items

IG1: 0
IG2: 11
IG3: 14
Gov: 32
Tech: 41
Ops: 44
17

Incident Response Management

9 safeguards · 75 checklist items

IG1: 3
IG2: 8
IG3: 9
Gov: 38
Tech: 5
Ops: 32
18

Penetration Testing

5 safeguards · 35 checklist items

IG1: 0
IG2: 3
IG3: 5
Gov: 10
Tech: 4
Ops: 21