adammontville / cis-controls-71-measures

0 stars 0 forks source link

Subcontrol 12.3 #111

Open adammontville opened 5 years ago

adammontville commented 5 years ago

Deny communications with known malicious or unused Internet IP addresses and limit access only to trusted and necessary IP address ranges at each of the organization's network boundaries.

Measures

a) Coverage --># of sent spoofed packets / # of IP addresses provided by (phishtank or clean-mx)

b) Detectability = # of detected Spoofed packed / # of sent spoofed packets
a) Coverage --># of sent spoofed packets / # of unused IP addresses (nmap)

b) Detectability = # of detected Spoofed packets / # of sent spoofed packets

Metrics

See measure.
adammontville commented 5 years ago

NOTES: Two ways to approach this. First is the method UNCC offers - active testing using spoofed packets. Second is checking the running config. Active testing seems more outcome-focused, so we can try for that first.

Deny communications with known malicious or unused Internet IP addresses and limit access only to trusted and necessary IP address ranges at each of the organization's network boundaries.

Sub-control Notes:

Inputs:

Operations:

Measures:

Metrics:

ealshaer commented 5 years ago

INPUT

Measured

Metric

Ration of network boundary devices that complies with this subcontrol (quality of firewall screening ) = M1/M2

adammontville commented 5 years ago

Deny communications with known malicious or unused Internet IP addresses and limit access only to trusted and necessary IP address ranges at each of the organization's network boundaries.

Per 2019-08-14 discussion: Make this more of a level 1 measure than a level 2 measure.

Inputs:

Operations:

Measures:

Metrics: