Info Security Memo
  • Blog
  • Sitemap
    • Categories
  • Contact
  • About
  • Resources
  • Tools
  • 51sec.org

Build Confidence

Focusing on Information Security 

Info Security Notes

CIS CSAT (On Prem & Host) and Create Assessment

9/25/2022

0 Comments

 
CIS CSAT (On Prem & Host) and Create Assessment
The CIS Controls Self-Assessment Tool, or CIS CSAT, is a free web application that enables security leaders to track and prioritize their implementation of the CIS Controls. CIS CSAT’s questions are based off the popular Critical Security Manual Assessment Tool excel document and the platform was developed by our partners at EthicalHat . For each CIS Control and sub-control, CSAT helps organizations track its documentation, implementation, automation, and reporting.



CIS CSAT Features


CIS CSAT enables security teams to track and prioritize their implementation of the CIS Controls. For each CIS Control and CIS Safeguard, CIS CSAT helps an organization track its documentation, implementation, automation, and reporting.

Use CIS CSAT to:
  • Collaborate across teams and assign user roles
  • Choose which specific Safeguards to include in your assessments
  • Upload documentation as supporting evidence
  • Track assessments over time and view graphs of your progress
  • Monitor alignment to other security frameworks with CIS Controls mappings to frameworks including NIST CSF and NIST SP 800-53
  • Anonymously compare results to industry averages
  • Coming Soon. Estimate an enterprise’s likelihood of being affected by a ransomware attack with the Ransomware Business Impact Analysis tool (created in partnership with Foresight Resilience Strategies (4RS))

There are two versions of CIS CSAT: a CIS-hosted version and an on-premises version for CIS SecureSuite Members called CIS CSAT Pro.

CIS-Hosted CSAT


The CIS-hosted version of CIS CSAT is free to every organization for use in a non-commercial capacity to conduct CIS Controls assessments of their organization. This free, CIS-Hosted version of CSAT was released in early 2019 and is available at CIS CSAT.

Access CIS CSAT Hosted Version

Log in with your registered account. 
Your account will be verified with an OTP sent to your registered email. 

After log in with your free account, you will be prompted to create your organization:

From Administration menu, you will be able to create multiple organizations and define implementation group and critical controls version:


Dashboard:


Create a new assessment



Assign user and due time



User will get an email for each sub-control assigned to him/her. 


Complete the questions


Based on the implementation group assigned to the assessment, you will get different questions for the safeguards:
  • IG1 (Minimum, 56 Safeguards) 
  • IG2 (Recommended, 56 + 74 Safeguards) 
  • IG3 (Full, 56 + 74 + 23 Safeguards) 


Complete each sub-control


Validate



CIS CSAT Pro


The on-premises version of CIS CSAT is available exclusively for CIS SecureSuite Members. This version offers additional features and benefits:
  • Save time by using a simplified scoring method with a reduced number of questions
  • Decide whether to opt in to share data and see how scores compare to industry average
  • Greater flexibility with organization trees for tracking organizations, sub-organizations, and assessments
  • Assign users to different roles for different organizations/sub-organizations as well as greater separation of administrative and non-administrative roles
  • Track multiple concurrent assessments in the same organization
  • Easily access your tasks, assessments, and organizations from a consolidated home page
  • Includes CIS Controls Safeguard mappings to NIST CSF, NIST SP 800-53, and PCI


https://<hostname>/



CIS CSAT Pro Installation


Installation




Videos

 
CIS Hosted CSAT:





References

  • CSAT Pro Deployment Guide
  • CIS Controls Self Assessment Tool (CIS CSAT)
  • CISecurity/SecureSuiteResourceGuide
  • CIS CSAT FAQ



via Blogger http://blog.51sec.org/2022/09/cis-csat-on-prem-host-and-create.html
September 25, 2022 at 08:31AM Security
0 Comments



Leave a Reply.

    Categories

    All
    Architecture
    Blog
    Checkpoint
    Cisco
    Cloud
    CyberArk
    F5
    Fortigate
    Guardium
    Juniper
    Linux
    Network
    Others
    Palo Alto
    Qualys
    Raspberry Pi
    Security
    SIEM
    Software
    Vmware
    VPN
    Wireless

    Archives

    March 2024
    February 2024
    January 2024
    December 2023
    November 2023
    October 2023
    September 2023
    August 2023
    July 2023
    June 2023
    May 2023
    April 2023
    March 2023
    February 2023
    January 2023
    December 2022
    November 2022
    October 2022
    September 2022
    August 2022
    July 2022
    June 2022
    May 2022
    April 2022
    March 2022
    February 2022
    January 2022
    December 2021
    November 2021
    October 2021
    September 2021
    August 2021
    July 2021
    June 2021
    May 2021
    April 2021
    March 2021
    February 2021
    January 2021
    December 2020
    November 2020
    October 2020
    September 2020
    August 2020
    July 2020
    October 2019
    September 2019
    June 2019
    July 2018
    May 2018
    December 2017
    August 2017
    April 2017
    March 2017
    January 2017
    December 2016
    November 2016
    October 2016
    September 2016
    August 2016
    July 2016
    June 2016
    May 2016
    April 2016
    March 2016
    February 2016
    January 2016
    December 2015
    November 2015
    October 2015
    September 2015
    August 2015
    July 2015
    June 2015
    May 2015
    April 2015
    March 2015

    Print Page:

    RSS Feed

    Email Subscribe
Powered by Create your own unique website with customizable templates.
  • Blog
  • Sitemap
    • Categories
  • Contact
  • About
  • Resources
  • Tools
  • 51sec.org