CSC V8 control 5.6 – Centralize Account Management Overview CSC V8 control 5.6 recommends that organisations “Centralize account management through a directory or identity service.”. Note CSC V8...
CSC V8 control 6 – Access Control Management Overview CSC V8 control 6 recommends that organisations “Use processes and tools to create, assign, manage, and revoke access credentials...
CSC V8 control 6.1 – Establish an Access Granting Process Overview CSC V8 control 6.1 recommends that organisations “Establish and follow a process, preferably automated, for granting access to enterprise...
CSC V8 control 6.2 – Establish an Access Revoking Process Overview CSC V8 control 6.2 recommends that organisations “Establish and follow a process, preferably automated, for revoking access to enterprise...
CSC V8 control 6.3 – Require MFA for Externally-Exposed Applications Overview CSC V8 control 6.3 recommends that organisations “Require all externally-exposed enterprise or third-party applications to enforce MFA, where supported....
CSC V8 control 6.4 – Require MFA for Remote Network Access Overview CSC V8 control 6.4 recommends that organisations “Require MFA for remote network access.”. Note CSC V8 places this control...
CSC V8 control 6.5 – Require MFA for Administrative Access Overview CSC V8 control 6.5 recommends that organisations “Require MFA for all administrative access accounts, where supported, on all enterprise...
CSC V8 control 4.10 – Enforce Automatic Device Lockout on Portable End-User Devices Overview CSC V8 control 4.10 recommends that organisations “Enforce automatic device lockout following a predetermined threshold of local failed authentication...
CSC V8 control 6.6 – Establish and Maintain an Inventory of Authentication and Authorization Systems Overview CSC V8 control 6.6 recommends that organisations “Establish and maintain an inventory of the enterprise’s authentication and authorization systems,...
CSC V8 control 4.11 – Enforce Remote Wipe Capability on Portable End-User Devices Overview CSC V8 control 4.11 recommends that organisations “Remotely wipe enterprise data from enterprise-owned portable end-user devices when deemed appropriate...