Logo

CIS C01 Dashboard

Inventory and Control of Enterprise Assets

Actively manage (inventory, track, and correct) all enterprise assets (end-user devices, including portable and mobile; network devices; non-computing/Internet of Things (IoT) devices; and servers) connected to the infrastructure physically, virtually, remotely, and those within cloud environments, to accurately know the totality of assets that need to be monitored and protected within the enterprise. This will also support identifying unauthorized and unmanaged assets to remove or remediate.

Control
Average Score

84

Control Industry
Average Score

54

Organizations used for average: 39

Percentage
Completed

100

Percentage
Validated

40

1.1  Establish and Maintain Detailed Enterprise Asset Inventory
Group 1
Establish and maintain an accurate, detailed, and up-to-date inventory of all enterprise assets with the potential to store or process data, to include: end-user devices (including portable and mobile), network devices, non-computing/IoT devices, and servers. Ensure the inventory records the network address (if static), hardware address, machine name, enterprise asset owner, department for each asset, and whether the asset has been approved to connect to the network. For mobile end-user devices, MDM type tools can support this process, where appropriate. This inventory includes assets connected to the infrastructure physically, virtually, remotely, and those within cloud environments. Additionally, it includes assets that are regularly connected to the enterprise’s network infrastructure, even if they are not under control of the enterprise. Review and update the inventory of all enterprise assets bi-annually, or more frequently.
NIST SP 800-53 Rev 5
CM-8
pranay
Add


Policy Defined
Control Implemented
Control Automated
Control Reported
Asset Type Devices
Security Function Identify
Assigned by Pranay Paine
Completed by
Validated by -
Send Back
Validate
Assigned to
No due date set
Evidence docs
2000 characters remaining
Add a note

Notes

živjo živjoživjoživjoživjoživjoživjoživjoživjoživjoživjoživjoživjoživjo

Added by Pranay Paine, Sept. 6, 2023, 3:57 p.m.


hellogggggfd

Added by Pranay Paine, Sept. 6, 2023, 3:57 p.m.


živjoživjoživjoživjoživjoživjoživjoživjoživjoživjoživjoživjoživjo
živjoživjoživjoživjoživjoživjoživjoživjoživjoživjoživjoživjoživjo
živjoživjoživjoživjoživjoživjoživjoživjoživjoživjoživjoživjoživjo
živjoživjoživjoživjoživjoživjoživjoživjoživjoživjoživjoživjoživjo
živjoživjoživjoživjoživjoživjoživjoživjoživjoživjoživjoživjoživjo
živjoživjoživjoživjoživjoživjoživjoživjoživjoživjoživjoživjoživjo

Added by Pranay Paine, Sept. 6, 2023, 3:57 p.m.


živjo živjoživjoživjoživjoživjoživjoživjoživjoživjoživjoživjoživjoživjo

Added by Pranay Paine, Sept. 6, 2023, 3:57 p.m.


oláccc

Added by Pranay Paine, Sept. 6, 2023, 3:57 p.m.


Poĺítica estabelecida na wiki

Added by Pranay Paine, Sept. 6, 2023, 3:57 p.m.


Poĺítica estabelecida na wiki

Added by Pranay Paine, Sept. 6, 2023, 3:57 p.m.


200 characters remaining
Comment
Pranay Paine

olá

Sept. 13, 2023, 9:49 a.m.
Pranay Paine changed the state to Applicable
Sept. 13, 2023, 9:48 a.m.
Pranay Paine changed the state to Not Applicable
Sept. 13, 2023, 9:18 a.m.
漢語是 Poĺítica estabelecida na wiki changed Control Automated to Not Automated
Sept. 13, 2023, 9:18 a.m.
漢語是 Poĺítica estabelecida na wiki changed Control Implemented to Not Implemented
Sept. 13, 2023, 9:16 a.m.
漢語是 Poĺítica estabelecida na wiki changed Control Reported to Reported on Most Systems
Sept. 13, 2023, 9:16 a.m.
漢語是 Poĺítica estabelecida na wiki changed Control Automated to Automated on Some Systems
Sept. 13, 2023, 9:16 a.m.
漢語是 Poĺítica estabelecida na wiki changed Control Implemented to Parts of Policy Implemented
Sept. 13, 2023, 9:16 a.m.
漢語是 Poĺítica estabelecida na wiki changed Policy Defined to No Policy
Sept. 6, 2023, 4 p.m.
漢語是 Poĺítica estabelecida na wiki uploaded a policy document
Sept. 6, 2023, 4 p.m.
漢語是 Poĺítica estabelecida na wiki reverted the validation of the assessment
Sept. 6, 2023, 3:57 p.m.
This Assessment is created by 漢語是 中國的主, Using file import feature.
1.2  Address Unauthorized Assets
Group 1
Ensure that a process exists to address unauthorized assets on a weekly basis. The enterprise may choose to remove the asset from the network, deny the asset from connecting remotely to the network, or quarantine the asset.
Add


Policy Defined
Control Implemented
Control Automated
Control Reported
Asset Type Devices
Security Function Respond
Assigned by Pranay Paine
Completed by -
Validated by -
Complete Sub-Control
Assigned to
No due date set
Evidence docs
No evidence doc uploaded
2000 characters remaining
Add a note

Notes

200 characters remaining
Comment
Nov. 1, 2023, 12:08 p.m.
Pranay Paine sent back the assessment
Nov. 1, 2023, 12:07 p.m.
Pranay Paine reverted the validation of the assessment
Sept. 13, 2023, 9:28 a.m.
Pranay Paine changed the state to Applicable
Sept. 13, 2023, 9:28 a.m.
Pranay Paine changed the state to Not Applicable
Sept. 13, 2023, 9:16 a.m.
漢語是 Poĺítica estabelecida na wiki validated the assessment
Sept. 13, 2023, 9:16 a.m.
漢語是 Poĺítica estabelecida na wiki changed Policy Defined to Approved Written Policy
Sept. 6, 2023, 3:57 p.m.
漢語是 Poĺítica estabelecida na wiki changed Policy Defined to No Policy
Sept. 6, 2023, 3:57 p.m.
This Assessment is created by 漢語是 中國的主, Using file import feature.
1.3  Utilize an Active Discovery Tool
Group 2
Utilize an active discovery tool to identify assets connected to the enterprise’s network. Configure the active discovery tool to execute daily, or more frequently.
NIST SP 800-53 Rev 5
SI-4
Add


Policy Defined
Control Implemented
Control Automated
Control Reported
Asset Type Devices
Security Function Detect
Assigned by Pranay Paine
Completed by
Validated by -
Send Back
Validate
Assigned to
No due date set
Evidence docs
No evidence doc uploaded
2000 characters remaining
Add a note

Notes

200 characters remaining
Comment
Sept. 6, 2023, 3:57 p.m.
This Assessment is created by 漢語是 中國的主, Using file import feature.
1.4  Use Dynamic Host Configuration Protocol (DHCP) Logging to Update Enterprise Asset Inventory
Group 2
Use DHCP logging on all DHCP servers or Internet Protocol (IP) address management tools to update the enterprise’s asset inventory. Review and use logs to update the enterprise’s asset inventory weekly, or more frequently.
Add


Policy Defined
Control Implemented
Control Automated
Control Reported
Asset Type Devices
Security Function Identify
Assigned by Pranay Paine
Completed by
Validated by
Revert validation
Assigned to
Due on Sept. 6, 2023
Evidence docs
No evidence doc uploaded
2000 characters remaining
Add a note

Notes

200 characters remaining
Comment
Sept. 6, 2023, 3:57 p.m.
漢語是 Poĺítica estabelecida na wiki changed Control Implemented to Implemented on All Systems
Sept. 6, 2023, 3:57 p.m.
漢語是 Poĺítica estabelecida na wiki completed the assessment
Sept. 6, 2023, 3:57 p.m.
漢語是 Poĺítica estabelecida na wiki changed Control Implemented to Implemented on Most Systems
Sept. 6, 2023, 3:57 p.m.
漢語是 Poĺítica estabelecida na wiki changed Control Automated to Automated on All Systems
Sept. 6, 2023, 3:57 p.m.
漢語是 Poĺítica estabelecida na wiki changed Control Reported to Reported on All Systems
Sept. 6, 2023, 3:57 p.m.
漢語是 Poĺítica estabelecida na wiki changed Policy Defined to Approved Written Policy
Sept. 6, 2023, 3:57 p.m.
漢語是 Poĺítica estabelecida na wiki validated the assessment
1.5  Use a Passive Asset Discovery Tool
Group 3
Use a passive discovery tool to identify assets connected to the enterprise’s network. Review and use scans to update the enterprise’s asset inventory at least weekly, or more frequently.
NIST SP 800-53 Rev 5
SI-4
Add


Policy Defined
Control Implemented
Control Automated
Control Reported
Asset Type Devices
Security Function Detect
Assigned by Pranay Paine
Completed by
Validated by -
Send Back
Validate
Assigned to
Due on Sept. 6, 2023
Evidence docs
No evidence doc uploaded
2000 characters remaining
Add a note

Notes

200 characters remaining
Comment
Sept. 6, 2023, 3:57 p.m.
漢語是 Poĺítica estabelecida na wiki completed the assessment
Sept. 6, 2023, 3:57 p.m.
漢語是 Poĺítica estabelecida na wiki changed Control Implemented to Implemented on All Systems
Sept. 6, 2023, 3:57 p.m.
漢語是 Poĺítica estabelecida na wiki changed Control Automated to Automated on All Systems
Sept. 6, 2023, 3:57 p.m.
漢語是 Poĺítica estabelecida na wiki changed Control Reported to Reported on All Systems
Sept. 6, 2023, 3:57 p.m.
漢語是 Poĺítica estabelecida na wiki changed Policy Defined to Approved Written Policy

Overall Score

87

SPIDER WEB