CISecurity/ControlsAssessmentSpecification

1.2: Use a Passive Asset Discovery Tool

Opened this issue · 0 comments

--- Issue 1
M2 = total number of assets (given) is the same list as M1 from control 1.1. Meaning the count of known devices, so if that is the case should the name change to match?
"List of discoverable Assets from manual Inventory".

---- issue 2
using my example from 1.1 the M2 = 207.
with respect to M4 & M5 both are listed at given.

I can see M5 being a "given", but example 7 days the passive data is stored before renewed. But the Time an Asset appeared. Is that the start of the time period.. for example if...
M4 = 00:00:01 Sunday
M5 = 24:00:00 (1 day)
M3 = 03:45:00

The freshness (Time to Discover) = 3 hours, 45 Minutes.
usable examples like this would be most helpful for the assessors to make sure they doing the appropriate assessments.

Thank you for the opportunity to contribute.