CIS 18 Questionnaire
i
The outcomes of the CIS18 self-evaluation serve to:
Facilitate a comparative analysis within the Alliance network groups and across the entire Alliance on how members rank their cyber security efforts, particularly in relation to the implementation and policy coverage of the CIS18 Controls.

Utilize these results in juxtaposition with the outcomes of the Assume Breach and Detection tests to ascertain if the employed controls are having their intended mitigative effect, or if their effectiveness warrants further examination.

How to fill out the evaluation questionnaire:
Accumulating the data necessary to accurately respond to all sections of the CIS18 questionnaire can pose a significant challenge for organizations that do not typically undertake such activities or otherwise maintain this perspective and we are aware that it often involves more partakers. Nevertheless, it is acceptable to offer the best effort responses as the CIS18 evaluation of the C-Level Insight Exercise is built on a self-assessment approach where the strength of evidence is inherently low.

Benefits:
Providing these answers will not only bring benefits to the member due to the enhanced consistency in the overall C-Level Insight Exercise outcomes but also can be advantageous to other members within their network group, and to the Alliance as a whole due to the statistics provided on the basis of this.

CIS Control #1: Inventory and Control of Enterprise Assets

1.1

Establish and maintain an accurate, detailed, and up-to-date inventory of all enterprise assets with the potential to store or process data, to include: end-user devices (including portable and mobile), network devices, non-computing/IoT devices, and servers. Ensure the inventory records the network address (if static), hardware address, machine name, data asset owner, department for each asset, and whether the asset has been approved to connect to the network. For mobile end-user devices, MDM type tools can support this process, where appropriate. This inventory includes assets connected to the infrastructure physically, virtually, remotely, and those within cloud environments. Additionally, it includes assets that are regularly connected to the enterprise’s network infrastructure, even if they are not under control of the enterprise. Review and update the inventory of all enterprise assets bi-annually, or more frequently.

Definition: NaN

Asset Type: Devices

Security Function: Identify

Implementation Groups: 1,2,3

1.2

Ensure that a process exists to address unauthorized assets on a weekly basis. The enterprise may choose to remove the asset from the network, deny the asset from connecting remotely to the network, or quarantine the asset.

Definition: NaN

Asset Type: Devices

Security Function: Respond

Implementation Groups: 1,2,3

1.3

Utilize an active discovery tool to identify assets connected to the enterprise’s network. Configure the active discovery tool to execute daily, or more frequently.

Definition: NaN

Asset Type: Devices

Security Function: Detect

Implementation Groups: 2,3

1.4

Use DHCP logging on all DHCP servers or Internet Protocol (IP) address management tools to update the enterprise’s asset inventory. Review and use logs to update the enterprise’s asset inventory weekly, or more frequently.

Definition: NaN

Asset Type: Devices

Security Function: Identify

Implementation Groups: 2,3

1.5

Use a passive discovery tool to identify assets connected to the enterprise’s network. Review and use scans to update the enterprise’s asset inventory at least weekly, or more frequently.

Definition: NaN

Asset Type: Devices

Security Function: Detect

Implementation Groups: 3