June 30, 2022, 12:13 p.m. | /u/skywalker_1391

cybersecurity www.reddit.com

Hey all,

I'm looking for input/ideas on how you tend to scope/track CIS18 controls (or really any security framework) across multiple environments. For example, we have many different environments with varying controls based on data classification. Cloud environments typically provide "out of the box" security features that other on-premise environments do not. As an example:

* AWS (non prod)
* AWS (prod)
* GCP (non prod)
* GCP (prod)
* On-premise (mostly enterprise software)

When performing a self-assessment for CIS18 …

controls cybersecurity people scoping tracking

Information Security Engineers

@ D. E. Shaw Research | New York City

Technology Security Analyst

@ Halton Region | Oakville, Ontario, Canada

Senior Cyber Security Analyst

@ Valley Water | San Jose, CA

Cyber Crime Student Internship

@ West Midlands Police | Birmingham, West Midlands, United Kingdom

Cyber Security Engineer (Junior/Journeyman)

@ CSEngineering | El Segundo, CA 90245, USA

Application Security Lead

@ Tokio Marine HCC | United Kingdom