CIS CSAT - IT Security Assessment Tool
CIS CSAT - IT Security Assessment Tool
Abstract: CSAT is a free web app from CIS. The app lets users run CIS Controls assessments.
This includes a basic set of useful features. It is not yet fully mature in certain areas. It may be
something worth keeping an eye on.
Keywords: Amazon, Assessment, AWS, CIS, Cloud, Dashboard, East, Excel, Framework,
Hotellerie
This paper was written in 2019 as part of a research project Currently in version 7, CIS Controls offers 20 controls,
at scip AG, Switzerland. It was initially published online at each of which includes between 5 and 13 sub-controls.
https://www.scip.ch/en/?labs.20190314 and is available in
English and German. Providing our clients with innovative
research for the information technology of the future is an
essential part of our company culture.
2. Introduction
This means placing your trust in CIS as the operator and Figure: Assessment Formular Sub-Control
Amazon (AWS US East Region) as the provider. If you
A brief introductory text provides information on the
want to be on the safe side you can use the platform
selected sub-control, followed by references to the
anonymously without uploading identifying information,
corresponding PCI DSS [6] and NIST [7] controls, which
while still benefiting from the management and
can sometimes be convenient for further investigation of
visualization features. An initial review suggests that this is
the controls and for compliance reports. The actual
quite simple.
assessment is based on responses to the four questions in
5.1. Walk-through the drop-down menus, and carried out by clicking the
Complete Sub-control button. The sub-control is then
After signing in, you will see the dashboard for the current validated or sent back for reprocessing with an additional
assessment. It will be empty at first. The dashboard click. The user management interface allows other users to
provides a range of information and charts, without being perform validation as well.
too overwhelming.
6. Conclusion
Figure: Overall Dashboard after Assessment
For example, a company without an IT security framework CIS CSAT simplifies the management of CIS Controls,
might see something like this in a first assessment. making it more attractive. The basic structure and feature
set of the web application does this quite well. However,
These graphs can be exported to PowerPoint with a simple CIS should work on offering a smoother workflow for the
click and then used immediately to create reports for assessment run.
stakeholders.
Unfortunately, the absence of a pre-population feature,
which uses data from the previous assessment, makes the
tool very time-consuming to use, particularly when you
have a lot going on in the area of IT security, or when you
need to generate quarterly reviews, say. Hopefully CIS will
implement this feature to make this effective security
management tool a very simple and appealing tool.
7. External Links
[1] https://www.bsi.bund.de/EN/Topics/ITGrundschutz/itgr
undschutz_node.html
[2] https://www.hotelleriesuisse.ch/cybersicherheit
Figure: Maturity Graphs [3] https://www.defcon-switzerland.org/
[4] https://www.cisecurity.org/blog/cis-csat-free-tool-
The assessment run is now complete and a current IT
assessing-implementation-of-cis-controls/
security status report is available.
[5] https://www.cisecurity.org/controls/
This allows you to very effectively and precisely define [6] https://www.pcisecuritystandards.org/
where (control and sub-control) measures should and must [7] https://www.nist.gov/cyberframework
be taken in specific areas (policy, implementation,