The Center provides Internet security benchmarks based on recognized best practices for deployment, configuration, and operation of networked systems. The Center’s security-enhancing benchmarks encompass all three factors in Internet-based attacks and disruptions: technology (software and hardware), process (system and network administration) and human (end user and management behavior). The benchmarks are open, that is, publicly available to everyone.
The Center’s Internet security benchmarks are intended to:
-
Provide managers, business partners and insurance underwriters with a security ‘ruler’, where each increment on the ruler represents a set of security-enhancing actions. This security ruler will enable an organization to select the level of security deemed appropriate for that enterprise and implement the specific technical actions associated with the security level chosen;
-
Include interventions that can be implemented before, during, and after attacks to reduce losses; and
-
Be subject to customization, where appropriate, for specific industries and risk profiles such as those needed by the healthcare sector to implement the extensive privacy and security requirements of the Health Insurance Portability and Accountability Act of 1996 (HIPAA).
Technical requirements without enforcement mechanisms are rarely effective. To ensure that the benchmarks are more than paper products, the Center will develop and deploy:
-
Compliance/auditing methodologies, including automated vendor tools certified by the Center, to ensure efficient and accurate compliance with the benchmarks;
-
Accreditation guidelines for system administrators and auditors to allow them to demonstrate a high level of proficiency in implementing and auditing against the benchmarks, and
-
Methods of maintaining confidentiality that encourage CIS members and others to share information that supports keeping the benchmarks up-to-date.
Cyber attacks will continue; therefore the benchmarks will be enhanced and updated to ensure that available benchmarks respond to real losses.
|
|