Datasheet | Check Point SASE: Coverage of the CIS Critical Security Controls
Check Point SASE helps organizations address dozens of the Safeguards within the Center for Internet Security Critical Security Controls, either partially, in full, or as a facilitator, as detailed in this Datasheet.

Check Point SASE helps organizations address dozens of the Safeguards within the Center for Internet Security Critical Security Controls, either partially, in full, or as a facilitator, as detailed below.
Check Point SASE: Coverage of the CIS Critical
Security Controls
All rights reserved. Check Point | 2026
CIS Control CIS Safeguard Asset Type Security Function Title How Check Point SASE Helps Full / Partial / Facilitates
Inventory and Control of Enterprise Assets
1 1.1 Devices Identify
Establish and Maintain Detailed Enterprise Asset Inventory
Check Point SASE monitors all managed devices, including Windows, Mac, Linux, iOS, Android and Chromebook. A report can be generated which provides an inventory of all devices, their users, the device type, their location and time of last login and their security health status.
Facilitates
1 1.2 Devices Respond Address Unauthorized Assets
To assist in this this process, Check Point SASE’s management console can be used to view the security health score of company devices and detect any access attempts of unauthorized devices or devices not meeting the company’s security requirements (via the Device Posture Check feature and reports).
Partial
Inventory and Control of Software Assets
2 2.1 Applications Identify Establish and Maintain a Software Inventory
Check Point SASE can help determine all on-prem and cloud based applications for which access rules have been defined in the network management console.
Facilitates
2 2.3 Applications Respond Address Unauthorized Software
Check Point SASE can be used to identify the usage of unauthorized cloud/SaaS applications.
Facilitates
2 2.5 Applications Protect Allowlist Authorized Software
Check Point SASE uses allow listing and access controls to limit access to applications to only authorized users.
Partial
All rights reserved. Check Point | 2026
CIS Control CIS Safeguard Asset Type Security Function Title How Check Point SASE Helps Full / Partial / Facilitates
Data Protection
3 3.3 Data Protect Configure Data Access Control Lists
Check Point SASE can be used to define access rules on a per-user or group level, to specific resources and applications. This enables least privileges access control.
Partial
3 3.6 Devices Protect Encrypt Data on End-User Devices
Check Point SASE includes a Device Posture Check module which is deployed on user endpoints and can detect whether disk encryption is being used. Access to the company network can be limited for users who do not comply with the defined policy.
Facilitates
3 3.10 Data Protect Encrypt Sensitive Data in Transit
Check Point SASE provides encrypted tunnels via IPsec and WireGuard protocols.
Partial
Secure Configuration of Enterprise Assets and Software
4 4.4 Devices Protect Implement and Manage a Firewall on Servers
Check Point SASE offers a cloud-delivered firewall as a service.
Partial
4 4.5 Devices Protect
Implement and Manage a Firewall on End-User Devices
Check Point SASE’s on-device agent leverages a cloud-based firewall that can be set to default-deny all traffic except those services and ports that are explicitly allowed.
Partial
4 4.9 Devices Protect Configure Trusted DNS Servers on Enterprise Assets
Check Point SASE enables the configuration of assets to use private DNS for all network traffic.
Partial
All rights reserved. Check Point | 2026
CIS Control CIS Safeguard Asset Type Security Function Title How Check Point SASE Helps Full / Partial / Facilitates
Account Management
5 5.1 Users Identify
Establish and Maintain an Inventory of Accounts
Check Point SASE manages the inventory of all network users and administrators.
Facilitates
Access Control Management
6 6.3 Users Protect
Require MFA for Externally- Exposed Applications
Check Point SASE supports MFA via leading IdP and SSO providers.
Partial
6 6.4 Users Protect Require MFA for Remote Network Access
Check Point SASE supports MFA for all remote network access.
Partial
6 6.5 Users Protect Require MFA for Administrative Access
Check Point SASE supports MFA-based access for administrator accounts.
Partial
6 6.8 Data Protect
Define and Maintain Role- Based Access Control
Role-based access controls are established and maintained in the Check Point SASE platform. Summary reports enable regular reviews of users and privileges to ensure appropriateness.
Partial
All rights reserved. Check Point | 2026
CIS Control CIS Safeguard Asset Type Security Function Title How Check Point SASE Helps Full / Partial / Facilitates
Audit Log Management
8 8.1 Network Protect
Establish and Maintain an Audit Log Management Process
Check Point SASE supports log management processes related to activity occurring on the Check Point SASE network.
Facilitates
8 8.2 Network Detect Collect Audit Logs Check Point SASE generates logs of network activity, managed devices, and admin changes.
Partial
8 8.5 Network Detect Collect Detailed Audit Logs
Check Point SASE logs provide details about admin, network, user, and group activity that could assist in a forensic investigation.
Partial
8 8.7 Network Detect Collect URL Request Audit Logs
Check Point SASE generates logs of URL requests. Partial
8 8.10 Network Protect Retain Audit Logs Check Point SASE retains all networking and security logs for up to 60 days, which can be exported for extended storage.
Partial
Email and Web Browser Protections
9 9.2 Network Protect Use DNS Filtering Services
Check Point SASE’s secure web gateway provides DNS filtering to block access to known malicious domains.
Partial
9 9.3 Network Protect Maintain and Enforce Network- Based URL Filters
Check Point SASE’s secure web gateway blocks access to malicious or unapproved websites.
Partial
All rights reserved. Check Point | 2026
CIS Control CIS Safeguard Asset Type Security Function Title How Check Point SASE Helps Full / Partial / Facilitates
Malware Defenses
10 10.1 Devices Protect Deploy and Maintain Anti- Malware Software
Check Point SASE’s secure web gateway protects managed enterprise endpoints against malware.
Partial
10 10.2 Devices Protect
Configure Automatic Anti- Malware Signature Updates
The cloud-based Check Point SASE secure web gateway is automatically updated for the most recent malware signatures.
Partial
Network Infrastructure Management
12 12.1 Network Protect Ensure Network Infrastructure is Up-to-Date
Check Point SASE is delivered via a SaaS model and updated automatically, providing customer organizations continuous access to the latest stable release.
Partial
12 12.2 Network Protect
Establish and Maintain a Secure Network Architecture
The Check Point SASE platform is designed specifically for secure network access and built on the principle of least privilege. Defined policies ensure that only authorized resources are available to specific users.
Partial
12 12.3 Network Protect Securely Manage Network Infrastructure
Check Point SASE enables network traffic to be limited to secure network protocols, such as SSH and HTTPS.
Partial
12 12.4 Network Identify
Establish and Maintain Architecture Diagram(s)
The Check Point SASE management console provides a visualization of the managed network architecture, including gateways and connections to internal and external resources.
Partial
All rights reserved. Check Point | 2026
CIS Control CIS Safeguard Asset Type Security Function Title How Check Point SASE Helps Full / Partial / Facilitates
12 12.5 Network Protect
Centralize Network Authentication, Authorization, and Auditing (AAA)
User authorization and audit logs of network activity, and connections to authentication tools are all centralized within the Check Point SASE console.
Partial
12 12.6 Network Protect
Use of Secure Network Management and Communication Protocols
Check Point SASE automatically secures data passing over unsecured Wi-Fi networks with 256-bit AES encryption.
Partial
12 12.7 Devices Protect
Ensure Remote Devices Utilize a VPN and are Connecting to an Enterprise’s AAA Infrastructure
Only authenticated end user devices can connect to the Check Point SASE alwayson VPN. Once connected, two- factor authentication is required for access to enterprise resources.
Full
Network Monitoring and Defense
13 13.4 Network Protect
Perform Traffic Filtering Between Network Segments
The Check Point SASE Firewall as a Service controls traffic between network segments based on granular network policy rules.
Partial
13 13.5 Devices Protect Manage Access Control for Remote Assets
Remote access is limited to user accounts that require it based on the principle of least privilege. The security posture of remote devices is checked to ensure compliance with organizational policies.
Partial
All rights reserved. Check Point | 2026
CIS Control CIS Safeguard Asset Type Security Function Title How Check Point SASE Helps Full / Partial / Facilitates
13 13.6 Network Detect Collect Network Traffic Flow Logs
Check Point SASE network traffic flow is visible within the monitoring dashboard and logs of firewall events are available.
Partial
13 13.9 Devices Protect Deploy Port-Level Access Control
The platform uses identity based access controls to authenticate users attempting to access the managed network.
Partial
13 13.10 Network Protect Perform Application Layer Filtering
Firewall rules control traffic between network resources. Partial
Contact your Check Point SASE representative for the full coverage matrix with additional information.
Visit sase.checkpoint.com to learn more.
https://sase.checkpoint.com/