Sekit CSF · Familia
Endpoint Security
24 controles en 8 temas, cada uno visto a través de las lentes de política, proceso y técnica.
Política
RCF-0145Configuration baselines6 mapeosApproved security configuration standards are formally defined for all device types used by the companyRCF-0160Device hardening5 mapeosSecurity hardening requirements are formally defined to reduce the attack surface of all company devicesRCF-0163Disk encryption4 mapeosFull disk encryption is formally required on all portable devices and devices that handle sensitive dataRCF-0148EDR/anti-malware5 mapeosThe company formally requires endpoint detection and response or anti-malware protection on all devicesRCF-0166Local admin control5 mapeosThe use of local administrator rights on company devices is formally restricted and requires approvalRCF-0151MDM/MAM4 mapeosMobile devices and applications used for work are formally required to be managed through an approved systemRCF-0154Patch management5 mapeosThe company formally requires that security patches are applied to all systems within defined timeframesRCF-0157Removable media control4 mapeosThe use of removable storage devices such as USB drives is formally restricted to authorised business needs
Proceso
RCF-0146Configuration baselines7 mapeosDevices are consistently configured to the approved baseline when deployed and after significant changesRCF-0161Device hardening6 mapeosDevices are consistently hardened by disabling unnecessary services and applying approved security settingsRCF-0164Disk encryption4 mapeosDisk encryption is consistently enabled and verified on all devices within scopeRCF-0149EDR/anti-malware5 mapeosEndpoint protection tools are consistently deployed, updated and alerts are investigated promptlyRCF-0167Local admin control5 mapeosLocal administrator access is consistently limited to authorised personnel and reviewed regularlyRCF-0152MDM/MAM4 mapeosMobile device management policies are consistently applied and devices are enrolled before accessing company dataRCF-0155Patch management5 mapeosPatches are consistently applied on schedule and patch status is tracked across all managed endpointsRCF-0158Removable media control4 mapeosRemovable media use is consistently monitored and unauthorised devices are reported and removed
Técnica
RCF-0147Configuration baselines4 mapeosTechnical tools automatically assess device configurations against the approved baseline and report deviationsRCF-0162Device hardening4 mapeosTechnical tools apply and enforce hardening configurations automatically across the device estateRCF-0165Disk encryption4 mapeosTechnical controls enforce disk encryption and can verify encryption status across the entire device fleetRCF-0150EDR/anti-malware6 mapeosEDR tools continuously monitor endpoint behaviour and automatically contain threats when detectedRCF-0168Local admin control4 mapeosTechnical controls prevent users from running with local administrator privileges without approvalRCF-0153MDM/MAM4 mapeosTechnical MDM controls enforce security policies on mobile devices and can remotely wipe lost or stolen devicesRCF-0156Patch management4 mapeosTechnical tools automate patch deployment and report on outstanding patches by age and severityRCF-0159Removable media control4 mapeosTechnical controls block or restrict the use of removable storage devices at the operating system level
Esta familia en ISO/IEC 27001:2022
Cada elemento de marco al que mapean los controles de la familia, primero los más conectados; agrupado por familia del Sekit CSF, nunca por el índice del propio marco.
Esta familia en NIST CSF 2.0
Esta familia en Cyber Essentials
Pregúntale a Sekura: «¿Qué evidencia demuestra Endpoint Security?»
También vía MCP, gratis con cuenta