Findings of the CIS v8 audit (2023)
Summer 2023: an external firm measured CERN against CIS Controls v8 as part of the five-yearly internal audit plan. Result: 82 recommendations, 73 accepted by the Director-General — 15 major, 34 medium, 24 minor, none catastrophic. It is the pivot from the historical “academic implicit trust” network toward Zero Trust and secure-by-design, and most of the modern control set descends from it.
Topology
- Part of: security-governance
- About: cis-controls-v8 — the framework used as the audit baseline.
- About: secure-sdlc — SAST/DAST, SBOM and WAF appear in its recommendations.
- About: mfa-rollout — 2FA for all accounts appears in its recommendations.
- About: password-policy — strengthened authentication appears in its recommendations.
- Cites: security-audited-for-the-better — CERN’s own account, with the numbers.
- Cites: cis-controls-v8-source — the standard specification of the controls.
