Collect Audit Logs There’s a predictable early move in a lot of intrusions: once an attacker is on a machine, they clear its local logs. If the only record of what happened lives on the same computer that was compromised, you’ve effectively handed the person you’re investigating the ability to edit the evidence. Control 8.2 solves that by getting your logs off the individual machines and into a place an attacker can’t quietly reach. If 8.1 was the decision about what to...

Trending at Forthright.
CIS Safeguard 7.2: Finding the Problem Is Only the Beginning
In Safeguard 7.1, we discussed the difference between running a vulnerability scanner and operating a vulnerability management program. A scan may...
CIS Safeguard 7.1: Why a Vulnerability Scanner Is Not a Vulnerability Management Program
A Vulnerability Scanner Is Not a Vulnerability Management Program As we move into CIS Control 7, Continuous Vulnerability Management, we're going to...
CIS IG1 Safeguard 6.5: Require MFA for Administrative Access
CIS IG1 Safeguard 6.5: Require MFA for Administrative Access by Heath Gieson This final article in the MFA mini‑series focuses on the...
Why 84% of Companies Fail at Digital Transformation. And Why That Number Hasn’t Moved.
Why 84% of Companies Fail at Digital Transformation. And Why That Number Hasn't Moved. By: Frank Merino Nearly a decade ago, Forbes published a...
CIS IG1 Safeguard 6.4: Require MFA for Remote Network Access
CIS IG1 Safeguard 6.4: Require MFA for Remote Network Access by Heath Gieson This article continues our CIS IG1 identity series by extending...
CIS IG1 Safeguard 6.3
Require MFA for Externally‑Exposed Applications This article is part of our ongoing CIS IG1 series focused on practical, high‑impact security...
CIS IG1 Control 6.2 – Establish an Access Revoking Process
CIS IG1 Control 6.2 – Establish an Access Revoking Process by Heath Gieson If access granting is where intent is established, access revoking...
Access Control Management: Access Should Be Granted Intentionally
Access Should Be Granted Intentionally By Tim Marley As we move into CIS Control 6, Access Control Management, we're going to spend the next...
CIS IG1 5.4: How Everyday Admin Access Turned a Phish Into a Crisis
by Heath Gieson CIS IG1 Safeguard 5.4 states that administrator privileges should be restricted to dedicated administrator accounts, and that...












