CIS Controls v8
CIS Control 12: Network Infrastructure Management

CIS Controls v8 CIS-12.1: Ensure Network Infrastructure is Up-to-Date

Keep network infrastructure current, for example by running the newest stable software release and/or using network-as-a-service (NaaS) offerings that are still supported. Check software versions at least monthly to confirm they remain supported.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 43 controls across 22 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

ISO 27002:2022 · 5 controls

  • 5.36 Compliance with policies, rules and standards for information security
  • 8.20 Networks security
  • 8.21 Security of network services
  • 8.8 Management of technical vulnerabilities
  • 8.9 Configuration management

CMMC 2.0 · 4 controls

ISO 27001:2022 · 4 controls

  • 8.20 Networks security
  • 8.21 Security of network services
  • 8.8 Management of technical vulnerabilities
  • 8.9 Configuration management

PCI DSS 4.0 · 4 controls

  • 12.3.4 12.3.4 Annual review of hardware and software technologies
  • 5.3.1 5.3.1 Anti-malware kept current through automatic updates
  • 6.3.2 6.3.2 Inventory of bespoke software and components
  • 6.3.3 6.3.3 Timely installation of security patches
  • ISM-1694 Non-critical OS patches for internet-facing systems within two weeks
  • ISM-1753 Replacing unsupported internet-facing network devices
  • ISM-1981 Replacing unsupported internal network devices
  • NIST-CSF-ID.AM-08 Systems, hardware, software, services, and data are managed throughout their life cycles
  • NIST-CSF-PR.PS-02 Software is maintained, replaced, and removed commensurate with risk
  • NIST-CSF-PR.PS-03 Hardware is maintained, replaced, and removed commensurate with risk

NIST SP 800-53 Rev 5 · 3 controls

  • ANSSI-HYG-34 Define an Update Policy for Information System Components
  • ANSSI-HYG-35 Anticipate the End of Maintenance of Software and Systems

NIST SP 800-171 Rev 3 · 2 controls

  • E8-PATCHOS-ML3 Patch Operating Systems (ML3)
  • ASD37-19 Patch operating systems (Essential)
  • ASBv3-PV-6 Rapidly and automatically remediate vulnerabilities

C5 (Germany) · 1 control

  • C5-OPS-18 Managing Vulnerabilities, Malfunctions and Errors - Concept

DORA · 1 control

FedRAMP High · 1 control

  • SA-22 Unsupported System Components (SA-22)

FedRAMP Moderate · 1 control

  • SA-22 Unsupported System Components (SA-22)

ISO 27701:2019 · 1 control

  • 6.9.6 Technical vulnerability management

SOC 2 · 1 control

  • SOC2-CC8.1 CC8.1 Managing changes to procedures, software, data and infrastructure

UK Cyber Essentials · 1 control

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in CIS Control 12: Network Infrastructure Management

You are reading one control. How much of CIS Controls v8 have you already done?

CIS Controls v8 CIS-12.1 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of CIS Controls v8 your existing evidence covers. Hold ISO 27001:2022 and 102 of 153 CIS Controls v8 controls already carry evidence.

Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 240 were rejected on the ISO 27001:2022 pair alone.

Query this from an agent

The graph holds this control, the 43 it maps to, and the evidence behind each claim, over MCP and REST.