Skip to main content
Skip table of contents

CCF – Lists

Functionality Lists

Functionality Lists

List Type


List ID

Insecure Applications List


This list is pre-populated with insecure impacted applications.


Network Search: SSL/TLS


Network application list of SSL/TLS content.


Network: Blacklisted Countries


LogRhythm Global Administrator populated list of countries you wouldn't expect connections to. (rogue states/nations).


Network Devices


Network devices to monitor for configuration changes.


Network: TLS Applications


Network applications that use port 443


CCF: User Whitelist


This list is an integral part of the C C F compliance automation suite. Whitelisted users and Active Directory groups can be added to this list.


CCF: User Blacklist


This list is an integral part of the C C F compliance automation suite. Blacklisted users and Active Directory groups can be added to this list.


CCF: Whitelisted Regions


This list is an integral part of the C C F compliance automation suite. Enabling LogRhythm's GeoIP feature is recommended for the use of this whitelist.


CCF: Blacklisted Regions


This list is an integral part of the C C F compliance automation suite. Enabling LogRhythm's GeoIP feature is recommended for the use of this blacklist.


CCF: Data Storage Systems

Log Source

This list is an integral part of the C C F compliance automation suite. Log Sources classified as data storage should be added to this list.


CCF: Production Servers

Log Source

This list is an integral part of the C C F compliance automation suite. Log Sources classified as production servers should be added to this list.


CCF: Security Systems

Log Source

This list is an integral part of the C C F compliance automation suite. Log Sources classified as security systems should be added to this list.


CCF: Privileged Accounts


This list should be populated with all privileged accounts and updated accordingly based on periodic reviews.


CCF: Privileged Groups

General Value

This list includes default privileged groups included in a standard operating system but can also be customized according to account categorization within an organization.


CCF: Third Party Account List


Contractors, vendors, other third party members and Active Directory groups can be added to this list.


CCF: Default Account List


Default, service, and automation accounts along with Active Directory groups can be added to this list


CCF: Business Users List


General (non-elevated) business users and Active Directory groups can be added to this list.


CCF: Terminated Account List


Terminated, scheduled to be terminated accounts, and Active Directory groups can be added to this list.


CCF: Physical Security Systems

Log Source

This list is to be populated and periodically updated according to physical security systems in-scope for the organization.


CCF: Network Security Systems

Log Source

This list should be populated with production network security systems (firewalls, intrusion detection/prevention systems, proxies, load balancers, routers, firewalls).


CCF: File Integrity Monitors

Log Source

This list includes all production systems that generate file integrity monitoring logs including LogRhythm File Integrity Monitor.


CCF: Internal Environment List


This list should be populated with internal IP addresses of your entire internal network.


CCF: External Environment List


This list should be populated with known external IP addresses of your trusted external network.


CCF: Database Systems

Log Source

This list should be populated with database systems on the network.


CCF: Wireless Environment List


This list should be populated with the IP ranges of the Wireless network.


CCF: Network Access Control Systems

Log Source

This list should be populated with production systems that enforce access controls. Examples include: VPN servers, WAP, LDAP, Active Directory, Dial-In Servers, etc.


CCF: Critical Servers- Systems


This list should be populated with any server or system classified as critical. Further any servers or systems containing proprietary data should be considered as critical.


Host Lists

CCF Scope Definition Lists

List Type


List ID

CCF: All Hosts


This list is a parent list containing all the individual framework host lists. This list is leveraged by the CCF SRP to add scope context based on host list names in AIE rules and alarms. Framework child lists that are not in scope for your organization.


UAE-NESA: All Hosts


This list should be populated with all hosts in scope for UAE-NESA within an organization. This is an embedded list contained in the CCF: All Hosts list. This allows the CCF SRP to function adding host context to rules and alarms based on scope.


GDPR: All Hosts


This list should be populated with all hosts in scope for GDPR within an organization. This is an embedded list contained in the CCF: All Hosts list. This allows the CCF SRP to function adding host context to rules and alarms based on scope.


NIST 800-53: All Hosts


This list should be populated with all hosts in scope for NIST 800-53 within an organization. This is an embedded list contained in the CCF: All Hosts list. This allows the CCF SRP to function adding host context to rules and alarms based on scope.


NIST 800-171: All Hosts


This list should be populated with all hosts in scope for NIST 800-171 within an organization. This is an embedded list contained in the CCF: All Hosts list. This allows the CCF SRP to function adding host context to rules and alarms based on scope.


NY-DFS: All Hosts


This list should be populated with all hosts in scope for NY-DFS within an organization. This is an embedded list contained in the CCF: All Hosts list. This allows the CCF SRP to function adding host context to rules and alarms based on compliance scope.


CJIS: All Hosts


This list should be populated with all hosts in scope for CJIS within an organization. This is an embedded list contained in the  CCF: All Hosts list. This allows the CCF SRP to function adding host context to rules and alarms based on scope.


ISO 27001: All HostsHostThis list should be populated with all hosts in scope for ISO 27001 within an organization. This is an embedded list contained in the  CCF: All Hosts list. This allows the CCF SRP to function adding host context to rules and alarms based on scope.-1000126
ASD: All HostsHostThis list should be populated with all hosts in scope for ASD within an organization. This is an embedded list contained in the  CCF: All Hosts list. This allows the CCF SRP to function adding host context to rules and alarms based on scope.-1000128

JavaScript errors detected

Please note, these errors can depend on your browser setup.

If this problem persists, please contact our support.