CIS Controls v8
CIS Control 4: Secure Configuration of Enterprise Assets and Software

CIS Controls v8 CIS-4.6: Securely Manage Enterprise Assets and Software

Manage enterprise assets and software securely. Examples include handling configuration as version-controlled infrastructure-as-code and reaching administrative interfaces only through secure protocols such as SSH and HTTPS. Insecure management protocols like Telnet and HTTP are not to be used unless the operation truly depends on them.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 63 controls across 19 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

NIST SP 800-53 Rev 5 · 7 controls

FedRAMP High · 6 controls

  • CM-2(2) Automation Support for Accuracy and Currency
  • CM-3 Configuration Change Control
  • CM-5 Access Restrictions for Change
  • CM-5(1) Access Restrictions for Change | Automated Access Enforcement and Audit Records (CM-5(1))
  • CM-6(1) Automated Management, Application, and Verification
  • MA-4 Nonlocal Maintenance

FedRAMP Moderate · 6 controls

  • CM-2(2) Automation Support for Accuracy and Currency
  • CM-3 Configuration Change Control
  • CM-5 Access Restrictions for Change
  • CM-5(1) Access Restrictions for Change | Automated Access Enforcement and Audit Records (CM-5(1))
  • CM-6(1) Automated Management, Application, and Verification
  • MA-4 Nonlocal Maintenance

ISO 27701:2019 · 6 controls

  • 5.6 Operation
  • 6.10.1 Network security management
  • 6.5.1 Responsibility for assets
  • 6.6.4 System and application access control
  • 6.8.2 Equipment
  • 6.9.5 Control of operational software

ISO 27001:2022 · 5 controls

  • 5.9 Inventory of information and other associated assets
  • 8.20 Networks security
  • 8.24 Use of cryptography
  • 8.32 Change management
  • 8.9 Configuration management
  • ASBv3-AM-4 Limit access to asset management
  • ASBv3-PA-6 Use privileged access workstations
  • ASBv3-PV-4 Audit and enforce secure configurations for compute resources
  • PV-2 Audit and enforce secure configurations
  • NIST-CSF-ID.AM-08 Systems, hardware, software, services, and data are managed throughout their life cycles
  • NIST-CSF-PR.DS-02 The confidentiality, integrity, and availability of data-in-transit are protected
  • NIST-CSF-PR.IR-01 Networks and environments are protected from unauthorized logical access and usage
  • NIST-CSF-PR.PS-01 Configuration management practices are established and applied

SOC 2 · 4 controls

  • SOC2-CC5.2 CC5.2 General controls over technology (COSO principle 11)
  • SOC2-CC6.1 CC6.1 Logical access security over protected information assets
  • SOC2-CC6.3 CC6.3 Role-based access, least privilege and segregation of duties
  • SOC2-CC8.1 CC8.1 Managing changes to procedures, software, data and infrastructure
  • SEC01-BP06 Automate deployment of standard security controls
  • SEC04-BP04 Initiate remediation for non-compliant resources
  • SEC06-BP03 Reduce manual management and interactive access

CMMC 2.0 · 3 controls

PCI DSS 4.0 · 3 controls

  • 1.2.8 1.2.8 NSC configuration files secured and consistent
  • 2.2.6 2.2.6 System security parameters configured against misuse
  • 2.2.7 2.2.7 Non-console administrative access encrypted
  • ISM-0484 Configuring the SSH daemon
  • ISM-1863 Management interfaces not exposed to the internet

C5 (Germany) · 2 controls

  • C5-COS-05 Networks for administration
  • C5-OPS-23 Managing Vulnerabilities, Malfunctions and Errors - System Hardening
  • ANSSI-HYG-16 Use a Centralised Management Tool to Standardise Security Policies

ISO 27002:2022 · 1 control

  • 8.9 Configuration management

NIST SP 800-172 · 1 control

  • 3.4.2e Automated Detection and Remediation of Unauthorized Software

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in CIS Control 4: Secure Configuration of Enterprise Assets and Software

You are reading one control. How much of CIS Controls v8 have you already done?

CIS Controls v8 CIS-4.6 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of CIS Controls v8 your existing evidence covers. Hold ISO 27001:2022 and 102 of 153 CIS Controls v8 controls already carry evidence.

Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 240 were rejected on the ISO 27001:2022 pair alone.

Query this from an agent

The graph holds this control, the 63 it maps to, and the evidence behind each claim, over MCP and REST.