• Tenable
  • Audits
  • Settings
    Links
    Tenable Cloud Tenable Community & Support Tenable University
    Theme
  • Tenable
  • Plugins
  • Overview
  • Plugins Pipeline
  • Newest
  • Updated
  • Search
  • Nessus Families
  • WAS Families
  • NNM Families
  • LCE Families
  • Tenable OT Security Families
  • About Plugin Families
  • Release Notes
  • Audits
  • Overview
  • Newest
  • Updated
  • Search Audit Files
  • Search Items
  • References
  • Authorities
  • Documentation
  • Download All Audit Files
  • Indicators
  • Overview
  • Search
  • Indicators of Attack
  • Indicators of Exposure
  • Release Notes
  • CVEs
  • Overview
  • Newest
  • Updated
  • Search
  • Attack Path Techniques
  • Overview
  • Search
    • Links
    • Tenable Cloud
    • Tenable Community & Support
    • Tenable University
    • Settings
    • Theme
Detections
  • Plugins
  • Overview
  • Plugins Pipeline
  • Release Notes
  • Newest
  • Updated
  • Search
  • Nessus Families
  • WAS Families
  • NNM Families
  • LCE Families
  • Tenable OT Security Families
  • About Plugin Families
  • Audits
  • Overview
  • Newest
  • Updated
  • Search Audit Files
  • Search Items
  • References
  • Authorities
  • Documentation
  • Download All Audit Files
  • Indicators
  • Overview
  • Search
  • Indicators of Attack
  • Indicators of Exposure
  • Release Notes
Analytics
  • CVEs
  • Overview
  • Newest
  • Updated
  • Search
  • Attack Path Techniques
  • Overview
  • Search
  1. Audits
  2. References
  3. CSCv7
  4. 12.8
  1. CSCv7

CSCv7|12.8

Title

Deploy NetFlow Collection on Networking Boundary Devices

Description

Enable the collection of NetFlow and logging data on all network boundary devices.

Reference Item Details

Reference: CIS Critical Security Controls v7

Category: Boundary Defense

Audit Items

View all Reference Audit Items

NamePluginAudit Name
3.4 Ensure logging is enabled on all firewall policiesFortiGateCIS Fortigate 7.0.x v1.3.0 L1
3.8 Ensure that VPC Flow Logs is Enabled for Every Subnet in a VPC NetworkGCPCIS Google Cloud Platform v3.0.0 L2
7.1.1.5 Ensure that Network Security Group Flow logs are captured and sent to Log Analyticsmicrosoft_azureCIS Microsoft Azure Foundations v4.0.0 L2
7.1.1.7 Ensure that virtual network flow logs are captured and sent to Log Analyticsmicrosoft_azureCIS Microsoft Azure Foundations v4.0.0 L2
7.7 (L1) Ensure Virtual Distributed Switch Netflow traffic is sent to an authorized collectorVMwareCIS VMware ESXi 7.0 v1.4.0 L1
7.7 Ensure Virtual Disributed Switch Netflow traffic is sent to an authorized collectorVMwareCIS VMware ESXi 6.7 v1.3.0 Level 1
  • Tenable.com
  • Community & Support
  • Documentation
  • Education
  • © 2025 Tenable®, Inc. All Rights Reserved
  • Privacy Policy
  • Legal
  • 508 Compliance