Skip to main content
Skip table of contents

CIS Controls - Reports and Reporting Packages

 

The current version of this table is built on Version 7.1 of the CIS Controls. A mapping to Version 8 of the CIS Controls will be completed in 2022. 

Summary Reports 

Implementation Group 1

Report NameReport IDControl SupportData SourceLog Sources
CCF: Access Failure Summary208913.2, 14.6Platform ManagerAll Available Log Sources
CCF: Access Success Summary209113.2, 14.6Platform ManagerAll Available Log Sources
CCF: Account Disabled Summary208416.8, 16.9LogMartAll Available Log Sources
CCF: Applications Accessed By User Summary20632.6Data Processor(s)All Available Log Sources
CCF: Audit Log Summary20766.2Platform ManagerAll Available Log Sources
CCF: Auth Failure Summary208814.6, 16.8Platform ManagerAll Available Log Sources
CCF: Auth Success Summary209014.6Platform ManagerAll Available Log Sources
CCF: Backup Activity Summary206210.1, 10.2Data Processor(s)All Available Log Sources
CCF: Compromises Detected Summary20648.4, 11.4LogMartAll Available Log Sources
CCF: Config/Policy Change Summary20495.1LogMartAll Available Log Sources
CCF: Critical Environment Error Summary20505.1Platform ManagerAll Available Log Sources
CCF: Malware Detected Summary20517.7, 8.2, 8.4Platform ManagerAll Available Log Sources
CCF: Object Access Summary20676.2, 13.1, 13.2, 14.6Data Processor(s)All Available Log Sources
CCF: Patch Activity Summary20523.4, 3.5, 5.1Data Processor(s)All Available Log Sources
CCF: Priv Account Management Activity Summary20804.3Data Processor(s)All Available Log Sources
CCF: Priv Authentication Activity Summary20794.3Platform ManagerAll Available Log Sources
CCF: Rogue Access Point Summary205412.1, 15.10Platform ManagerAll Available Log Sources
CCF: Signature Activity Summary20555.1, 8.2LogMartAll Available Log Sources
CCF: Social Media Summary20704.3Platform ManagerAll Available Log Sources
CCF: Suspected Wireless Attack Summary205611.4Platform ManagerAll Available Log Sources
CCF: Term Account Activity Summary208716.8, 16.9Data Processor(s)All Available Log Sources
CCF: Top Suspicious Users205917.3, 17.5, 17.6, 17.7, 17.8, 17.9Data Processor(s)All Available Log Sources
CCF: Use Of Non-Encrypted Protocols Summary20607.1, 12.4, 13.6, 15.7LogMartAll Available Log Sources
CCF: User Misuse Summary20614.3, 15.10, 17.3Platform ManagerAll Available Log Sources
CCF: User Object Access Summary20686.2, 13.1, 13.2, 14.6Data Processor(s)All Available Log Sources
CCF: User Priv Escalation (SU & SUDO) Summary20784.3Data Processor(s)All Available Log Sources
CCF: User Priv Escalation (Windows) Summary20774.3Data Processor(s)All Available Log Sources
CCF: Vulnerability Detected Summary20582.2, 3.4, 3.5, 8.2, 11.4Platform ManagerAll Available Log Sources
CCF: New Network Host Summary21011.4, 1.6Data Processor(s)All Available Log Sources

Implementation Group 2

Report NameReport IDControl SupportData SourceLog Sources
CCF: Access Failure Summary20894.7, 4.9, 16.6, 16.7, 16.12Platform ManagerAll Available Log Sources
CCF: Access Success Summary20914.1, 4.5, 4.7, 16.6, 16.7, 16.10, 20.8Platform ManagerAll Available Log Sources
CCF: Account Disabled Summary20844.1, 16.6, 16.7, 16.10, 16.12LogMart(s)All Available Log Sources
CCF: Applications Accessed By User Summary20632.3, 2.4, 18.3, 18.8Data Processor(s)All Available Log Sources
CCF: Audit Log Summary20761.3, 4.9, 6.3, 6.4, 6.5, 6.6, 6.7, 7.6, 8.6, 8.7, 8.8Platform ManagerAll Available Log Sources
CCF: Auth Failure Summary20884.1, 4.7, 4.9, 16.10, 16.12Platform ManagerAll Available Log Sources
CCF: Auth Success Summary20904.1, 4.5, 4.7, 16.6, 16.7, 16.10, 16.12, 20.8Platform ManagerAll Available Log Sources
CCF: Backup Activity Summary206210.3Data Processor(s)All Available Log Sources
CCF: Compromises Detected Summary20641.7, 3.1, 3.2, 3.6, 8.1, 8.6, 9.3, 12.3, 12.6, 15.1LogMart(s)All Available Log Sources
CCF: Config/Policy Change Summary20494.8, 5.4, 5.5, 11.2, 11.3LogMart(s)All Available Log Sources
CCF: Critical Environment Error Summary205010.3, 18.11, 20.4Platform ManagerAll Available Log Sources
CCF: LogRhythm Data Loss Defender Log Summary20665.3, 13.7LogMart(s)All Available Log Sources
CCF: Malware Detected Summary20513.1, 3.6, 8.1, 8.6, 12.3, 12.6Platform ManagerAll Available Log Sources
CCF: New Network Host Summary21011.5Data Processor(s)All Available Log Sources
CCF: Object Access Summary20674.7, 5.3Data Processor(s)All Available Log Sources
CCF: Patch Activity Summary20523.1, 3.2, 18.3Data Processor(s)All Available Log Sources
CCF: Priv Account Management Activity Summary20804.1, 4.5, 4.8, 4.9, 16.10, 16.12Data Processor(s)All Available Log Sources
CCF: Priv Authentication Activity Summary20794.1, 4.5, 4.8, 4.9, 16.10, 16.12Platform ManagerAll Available Log Sources
CCF: Rogue Access Point Summary20541.7, 15.1, 15.2Platform ManagerAll Available Log Sources
CCF: Signature Activity Summary20553.1, 3.2, 3.6, 8.1, 8.6LogMart(s)All Available Log Sources
CCF: Social Media Summary20703.3, 7.6, 11.6, 20.8Platform ManagerAll Available Log Sources
CCF: Suspected Wireless Attack Summary20563.1, 7.4, 8.1, 8.6, 9.2, 12.2, 12.3, 15.1, 15.3, 15.6, 15.9Platform ManagerAll Available Log Sources
CCF: Term Account Activity Summary208716.6, 16.7, 16.10, 16.12Data Processor(s)All Available Log Sources
CCF: Time Sync Error Summary6836.1Platform ManagerAll Available Log Sources
CCF: Top Suspicious Users20594.1, 4.8, 16.6, 16.7, 17.1, 20.6, 20.8Data Processor(s)All Available Log Sources
CCF: Use Of Non-Encrypted Protocols Summary206011.5, 14.4, 16.5, 18.5LogMart(s)All Available Log Sources
CCF: User Misuse Summary20613.3, 4.1, 11.6, 16.6, 16.7, 16.10, 16.12, 17.1, 20.6, 20.8Platform ManagerAll Available Log Sources
CCF: User Object Access Summary20683.3, 5.3, 7.9, 11.6, 13.4, 13.7, 17.1, 18.9, 20.4Data Processor(s)All Available Log Sources
CCF: User Priv Escalation (SUDO) Summary20784.1, 4.8, 4.9, 11.6, 16.7, 16.12, 20.8Data Processor(s)All Available Log Sources
CCF: User Priv Escalation (Windows) Summary20774.1, 4.8, 4.9, 11.6, 16.7, 16.12, 20.8Data Processor(s)All Available Log Sources
CCF: Vulnerability Detected Summary20581.7, 3.1, 3.2, 3.6, 8.6, 12.3, 12.6, 18.10, 20.6Platform ManagerAll Available Log Sources


Implementation Group 3

Report NameReport IDControl SupportData SourceLog Sources
CCF: Top Suspicious Users205916.13Data Processor(s)All Log Sources
CCF: User Object Access Summary206813.3, 13.5, 14.5, 14.9Data Processor(s)All Log Sources
CCF: Use Of Non-Encrypted Protocols Summary20601.8, 12.10, 13.9, 14.8, 15.8LogMart(s)All Log Sources
CCF: Auth Success Summary209016.13Platform ManagerAll Log Sources
CCF: LogRhythm Data Loss Defender Log Summary206613.3, 13.5, 14.5, 14.9LogMart(s)All Log Sources
CCF: Object Access Summary206713.3, 13.5, 14.5, 14.9Data Processor(s)All Log Sources
CCF: Auth Failure Summary208816.13Platform Manager(s)All Log Sources
CCF: Config/Policy Change Summary204914.9LogMart(s)All Log Sources


Detailed Reports

The Intelligent Indexing settings are recommendations. The default configuration is No.

Implementation Group 1

Report Name

Report Description

Control SupportData SourceIntelligent IndexingClassificationLog Sources

Report ID

CCF: Account Deleted SummaryThis report provides detailed information when an account has access revoked (deleted) across any logged environments. This should align with the organization's policies regarding deleted accounts.16.9Platform ManagerYesAuditAll Available Log Sources2086
CCF: Account Enabled SummaryThis report provides detailed information when an account has access granted across any logged environments. This should align with the organization's policies regarding enabled accounts.4.3, 16.9Platform ManagerYesAuditAll Available Log Sources2085
CCF: Account Modification SummaryThis report provides summary information around account modifications across all logged environments.4.3, 14.6Platform ManagerYesAuditAll Available Log Sources2092

CCF: Host Access Granted And Revoked Detail

This report details all access granted and revoked for production systems.

4.3, 5.1, 15.10

Data Processor(s)YesAuditAll Available Log Sources

2065

CCF: Unknown User Account Detail

This report provides details of activity from unknown user accounts, based off CCF user lists.

16.8

Data Processor(s)YesSecurityAll Available Log Sources

2071

Implementation Group 2

Report Name

Report Description

Control SupportData SourceIntelligent IndexingClassificationLog Sources

Report ID

CCF: Account Deleted SummaryThis report provides detailed information when an account has access revoked (deleted) across any logged environments. This should align with the organization's policies regarding deleted accounts.16.7, 16.10, 16.12Platform ManagerYesAuditAll Available Log Sources2086
CCF: Account Enabled SummaryThis report provides detailed information when an account has access granted across any logged environments. This should align with the organization's policies regarding enabled accounts.3.3, 4.5, 4.7, 16.7, 16.10, 16.12, 20.8Platform ManagerYesAuditAll Available Log Sources2085
CCF: Account Modification SummaryThis report provides summary information around account modifications across all logged environments.3.3, 4.1, 4.7, 4.8, 4.9, 16.6, 16.7, 16.10, 16.12, 20.8Platform ManagerYesAuditAll Available Log Sources2092
CCF: Host Access Granted And Revoked Detail

This report details all access granted and revoked for production systems.

11.6, 16.7, 16.10Data Processor(s)YesAuditAll Available Log Sources

2065

CCF: Unknown User Account DetailThis report provides details of activity from unknown user accounts, based off CCF user lists.4.1, 4.8, 4.9, 16.6Data Processor(s)YesSecurityAll Available Log Sources

2071


Implementation Group 3

N/A

Reporting Packages

Report Package Name

Report Package Description

Report Package ID

CCF: Daily IT Operations Reporting Package

This reporting package is a template to deliver pertinent content for IT Operations on a daily basis.

89

CCF: Daily IT Security Reporting Package

This reporting package is a template to deliver pertinent content for IT Security on a daily basis.

90

CCF: Executive Reporting Package

This reporting package is a template to deliver pertinent content for Executives on a monthly basis.

87

CCF: Weekly Audit Reporting Package

This reporting package is a template to deliver pertinent content for Internal and/or External Audit groups on a weekly basis.

88

JavaScript errors detected

Please note, these errors can depend on your browser setup.

If this problem persists, please contact our support.