Sekit CSF · Familia
Endpoint Security
24 controles en 8 temas, cada uno visto a través de las lentes de política, proceso y técnica.
Política
RCF-0145Configuration baselinessin mapeos aúnApproved security configuration standards are formally defined for all device types used by the companyRCF-0160Device hardeningsin mapeos aúnSecurity hardening requirements are formally defined to reduce the attack surface of all company devicesRCF-0163Disk encryptionsin mapeos aúnFull disk encryption is formally required on all portable devices and devices that handle sensitive dataRCF-0148EDR/anti-malwaresin mapeos aúnThe company formally requires endpoint detection and response or anti-malware protection on all devicesRCF-0166Local admin controlsin mapeos aúnThe use of local administrator rights on company devices is formally restricted and requires approvalRCF-0151MDM/MAMsin mapeos aúnMobile devices and applications used for work are formally required to be managed through an approved systemRCF-0154Patch managementsin mapeos aúnThe company formally requires that security patches are applied to all systems within defined timeframesRCF-0157Removable media controlsin mapeos aúnThe use of removable storage devices such as USB drives is formally restricted to authorised business needs
Proceso
RCF-0146Configuration baselinessin mapeos aúnDevices are consistently configured to the approved baseline when deployed and after significant changesRCF-0161Device hardeningsin mapeos aúnDevices are consistently hardened by disabling unnecessary services and applying approved security settingsRCF-0164Disk encryptionsin mapeos aúnDisk encryption is consistently enabled and verified on all devices within scopeRCF-0149EDR/anti-malwaresin mapeos aúnEndpoint protection tools are consistently deployed, updated and alerts are investigated promptlyRCF-0167Local admin controlsin mapeos aúnLocal administrator access is consistently limited to authorised personnel and reviewed regularlyRCF-0152MDM/MAMsin mapeos aúnMobile device management policies are consistently applied and devices are enrolled before accessing company dataRCF-0155Patch managementsin mapeos aúnPatches are consistently applied on schedule and patch status is tracked across all managed endpointsRCF-0158Removable media controlsin mapeos aúnRemovable media use is consistently monitored and unauthorised devices are reported and removed
Técnica
RCF-0147Configuration baselinessin mapeos aúnTechnical tools automatically assess device configurations against the approved baseline and report deviationsRCF-0162Device hardeningsin mapeos aúnTechnical tools apply and enforce hardening configurations automatically across the device estateRCF-0165Disk encryptionsin mapeos aúnTechnical controls enforce disk encryption and can verify encryption status across the entire device fleetRCF-0150EDR/anti-malwaresin mapeos aúnEDR tools continuously monitor endpoint behaviour and automatically contain threats when detectedRCF-0168Local admin controlsin mapeos aúnTechnical controls prevent users from running with local administrator privileges without approvalRCF-0153MDM/MAMsin mapeos aúnTechnical MDM controls enforce security policies on mobile devices and can remotely wipe lost or stolen devicesRCF-0156Patch managementsin mapeos aúnTechnical tools automate patch deployment and report on outstanding patches by age and severityRCF-0159Removable media controlsin mapeos aúnTechnical controls block or restrict the use of removable storage devices at the operating system level
Pregúntale a Sekura: «¿Qué evidencia demuestra Endpoint Security?»
Conecta tu IA · MCP gratis
https://staging.sekit.ai/api/mcp/crosswalk- En Claude o ChatGPT, añade un conector personalizado y pega esta URL.
- Inicia sesión con tu correo para terminar. Gratis, de solo lectura, sin necesidad de organización.