The CIS v8 audit (2023)
Summer 2023: an external firm measured CERN against CIS Controls v8 as part of the five-yearly internal audit plan. Result: 82 recommendations, 73 accepted by the Director-General — 15 major, 34 medium, 24 minor, none catastrophic. It is the pivot from the historical “academic implicit trust” network toward Zero Trust and secure-by-design, and most of the modern control set descends from it.
Topology
- Part of: security-governance
- Governs: secure-sdlc — SAST/DAST, SBOM and WAF come from its recommendations.
- Governs: mfa-rollout — 2FA for all accounts, likewise.
- Governs: password-policy — strengthened authentication, likewise.
- Cites: security-audited-for-the-better — CERN’s own account, with the numbers.