CIS Controls v8
CIS Control 4: Secure Configuration of Enterprise Assets and Software

CIS Controls v8 CIS-4.2: Establish and Maintain a Secure Configuration Process for Network Infrastructure

Set up and keep a process for configuring network devices securely. Revisit the documentation each year, or sooner when a major change in the enterprise could affect this Safeguard.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 48 controls across 20 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

PCI DSS 4.0 · 5 controls

  • 1.2.1 1.2.1 Ruleset configuration standards for NSCs
  • 1.2.2 1.2.2 Network connection and NSC changes under change control
  • 1.2.7 1.2.7 Six-monthly review of NSC configurations
  • 1.2.8 1.2.8 NSC configuration files secured and consistent
  • 2.2.1 2.2.1 System configuration standards maintained

SOC 2 · 5 controls

  • SOC2-CC3.4 CC3.4 Identifying and assessing significant changes (COSO principle 9)
  • SOC2-CC5.2 CC5.2 General controls over technology (COSO principle 11)
  • SOC2-CC5.3 CC5.3 Deploying controls through policies and procedures (COSO principle 12)
  • SOC2-CC7.1 CC7.1 Detecting configuration changes and new vulnerabilities
  • SOC2-CC8.1 CC8.1 Managing changes to procedures, software, data and infrastructure

CMMC 2.0 · 4 controls

ISO 27002:2022 · 4 controls

  • 5.36 Compliance with policies, rules and standards for information security
  • 8.20 Networks security
  • 8.32 Change management
  • 8.9 Configuration management

NIST SP 800-53 Rev 5 · 4 controls

C5 (Germany) · 3 controls

  • C5-COS-01 Technical safeguards
  • C5-COS-02 Security requirements for connections in the Cloud Service Provider's network
  • C5-COS-03 Monitoring of connections in the Cloud Service Provider's network
  • ISM-1912 Device settings in network documentation
  • ISM-1913 Approved configurations for IT equipment
  • ASBv3-GS-4 Define and implement network security strategy
  • ASBv3-NS-7 Simplify network security configuration

FedRAMP High · 2 controls

  • CM-2 Baseline Configuration
  • CM-6 Configuration Settings

FedRAMP Moderate · 2 controls

  • CM-2 Baseline Configuration
  • CM-6 Configuration Settings

ISO 27001:2022 · 2 controls

  • 8.20 Networks security
  • 8.9 Configuration management

NIST SP 800-171 Rev 3 · 2 controls

  • ANSSI-HYG-14 Apply a Minimum Security Level Across the Whole Estate
  • ASD37-11 Operating system hardening (Very Good)

CIS Controls v8.1 · 1 control

  • 4.2 Establish and Maintain a Secure Configuration Process for Network Infrastructure

UK Cyber Essentials · 1 control

  • CE-FW.4 Approve and Document Inbound Rules

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in CIS Control 4: Secure Configuration of Enterprise Assets and Software

You are reading one control. How much of CIS Controls v8 have you already done?

CIS Controls v8 CIS-4.2 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of CIS Controls v8 your existing evidence covers. Hold ISO 27001:2022 and 102 of 153 CIS Controls v8 controls already carry evidence.

Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 240 were rejected on the ISO 27001:2022 pair alone.

Query this from an agent

The graph holds this control, the 48 it maps to, and the evidence behind each claim, over MCP and REST.