Datasheet | Check Point SASE: Coverage of the CIS Critical Security Controls

Datasheet | Check Point SASE: Coverage of the CIS Critical Security Controls

Check Point SASE helps organizations address dozens of the Safeguards within the Center for Internet Security Critical Security Controls, either partially, in full, or as a facilitator, as detailed in this Datasheet.

Datasheet | Check Point SASE: Coverage of the CIS Critical Security Controls

Check Point SASE helps organizations address dozens of the Safeguards within the Center for Internet Security Critical Security Controls, either partially, in full, or as a facilitator, as detailed below.

Check Point SASE: Coverage of the CIS Critical

Security Controls

All rights reserved. Check Point | 2026

CIS Control CIS Safeguard Asset Type Security Function Title How Check Point SASE Helps Full / Partial / Facilitates

Inventory and Control of Enterprise Assets

1 1.1 Devices Identify

Establish and Maintain Detailed Enterprise Asset Inventory

Check Point SASE monitors all managed devices, including Windows, Mac, Linux, iOS, Android and Chromebook. A report can be generated which provides an inventory of all devices, their users, the device type, their location and time of last login and their security health status.

Facilitates

1 1.2 Devices Respond Address Unauthorized Assets

To assist in this this process, Check Point SASE’s management console can be used to view the security health score of company devices and detect any access attempts of unauthorized devices or devices not meeting the company’s security requirements (via the Device Posture Check feature and reports).

Partial

Inventory and Control of Software Assets

2 2.1 Applications Identify Establish and Maintain a Software Inventory

Check Point SASE can help determine all on-prem and cloud based applications for which access rules have been defined in the network management console.

Facilitates

2 2.3 Applications Respond Address Unauthorized Software

Check Point SASE can be used to identify the usage of unauthorized cloud/SaaS applications.

Facilitates

2 2.5 Applications Protect Allowlist Authorized Software

Check Point SASE uses allow listing and access controls to limit access to applications to only authorized users.

Partial

All rights reserved. Check Point | 2026

CIS Control CIS Safeguard Asset Type Security Function Title How Check Point SASE Helps Full / Partial / Facilitates

Data Protection

3 3.3 Data Protect Configure Data Access Control Lists

Check Point SASE can be used to define access rules on a per-user or group level, to specific resources and applications. This enables least privileges access control.

Partial

3 3.6 Devices Protect Encrypt Data on End-User Devices

Check Point SASE includes a Device Posture Check module which is deployed on user endpoints and can detect whether disk encryption is being used. Access to the company network can be limited for users who do not comply with the defined policy.

Facilitates

3 3.10 Data Protect Encrypt Sensitive Data in Transit

Check Point SASE provides encrypted tunnels via IPsec and WireGuard protocols.

Partial

Secure Configuration of Enterprise Assets and Software

4 4.4 Devices Protect Implement and Manage a Firewall on Servers

Check Point SASE offers a cloud-delivered firewall as a service.

Partial

4 4.5 Devices Protect

Implement and Manage a Firewall on End-User Devices

Check Point SASE’s on-device agent leverages a cloud-based firewall that can be set to default-deny all traffic except those services and ports that are explicitly allowed.

Partial

4 4.9 Devices Protect Configure Trusted DNS Servers on Enterprise Assets

Check Point SASE enables the configuration of assets to use private DNS for all network traffic.

Partial

All rights reserved. Check Point | 2026

CIS Control CIS Safeguard Asset Type Security Function Title How Check Point SASE Helps Full / Partial / Facilitates

Account Management

5 5.1 Users Identify

Establish and Maintain an Inventory of Accounts

Check Point SASE manages the inventory of all network users and administrators.

Facilitates

Access Control Management

6 6.3 Users Protect

Require MFA for Externally- Exposed Applications

Check Point SASE supports MFA via leading IdP and SSO providers.

Partial

6 6.4 Users Protect Require MFA for Remote Network Access

Check Point SASE supports MFA for all remote network access.

Partial

6 6.5 Users Protect Require MFA for Administrative Access

Check Point SASE supports MFA-based access for administrator accounts.

Partial

6 6.8 Data Protect

Define and Maintain Role- Based Access Control

Role-based access controls are established and maintained in the Check Point SASE platform. Summary reports enable regular reviews of users and privileges to ensure appropriateness.

Partial

All rights reserved. Check Point | 2026

CIS Control CIS Safeguard Asset Type Security Function Title How Check Point SASE Helps Full / Partial / Facilitates

Audit Log Management

8 8.1 Network Protect

Establish and Maintain an Audit Log Management Process

Check Point SASE supports log management processes related to activity occurring on the Check Point SASE network.

Facilitates

8 8.2 Network Detect Collect Audit Logs Check Point SASE generates logs of network activity, managed devices, and admin changes.

Partial

8 8.5 Network Detect Collect Detailed Audit Logs

Check Point SASE logs provide details about admin, network, user, and group activity that could assist in a forensic investigation.

Partial

8 8.7 Network Detect Collect URL Request Audit Logs

Check Point SASE generates logs of URL requests. Partial

8 8.10 Network Protect Retain Audit Logs Check Point SASE retains all networking and security logs for up to 60 days, which can be exported for extended storage.

Partial

Email and Web Browser Protections

9 9.2 Network Protect Use DNS Filtering Services

Check Point SASE’s secure web gateway provides DNS filtering to block access to known malicious domains.

Partial

9 9.3 Network Protect Maintain and Enforce Network- Based URL Filters

Check Point SASE’s secure web gateway blocks access to malicious or unapproved websites.

Partial

All rights reserved. Check Point | 2026

CIS Control CIS Safeguard Asset Type Security Function Title How Check Point SASE Helps Full / Partial / Facilitates

Malware Defenses

10 10.1 Devices Protect Deploy and Maintain Anti- Malware Software

Check Point SASE’s secure web gateway protects managed enterprise endpoints against malware.

Partial

10 10.2 Devices Protect

Configure Automatic Anti- Malware Signature Updates

The cloud-based Check Point SASE secure web gateway is automatically updated for the most recent malware signatures.

Partial

Network Infrastructure Management

12 12.1 Network Protect Ensure Network Infrastructure is Up-to-Date

Check Point SASE is delivered via a SaaS model and updated automatically, providing customer organizations continuous access to the latest stable release.

Partial

12 12.2 Network Protect

Establish and Maintain a Secure Network Architecture

The Check Point SASE platform is designed specifically for secure network access and built on the principle of least privilege. Defined policies ensure that only authorized resources are available to specific users.

Partial

12 12.3 Network Protect Securely Manage Network Infrastructure

Check Point SASE enables network traffic to be limited to secure network protocols, such as SSH and HTTPS.

Partial

12 12.4 Network Identify

Establish and Maintain Architecture Diagram(s)

The Check Point SASE management console provides a visualization of the managed network architecture, including gateways and connections to internal and external resources.

Partial

All rights reserved. Check Point | 2026

CIS Control CIS Safeguard Asset Type Security Function Title How Check Point SASE Helps Full / Partial / Facilitates

12 12.5 Network Protect

Centralize Network Authentication, Authorization, and Auditing (AAA)

User authorization and audit logs of network activity, and connections to authentication tools are all centralized within the Check Point SASE console.

Partial

12 12.6 Network Protect

Use of Secure Network Management and Communication Protocols

Check Point SASE automatically secures data passing over unsecured Wi-Fi networks with 256-bit AES encryption.

Partial

12 12.7 Devices Protect

Ensure Remote Devices Utilize a VPN and are Connecting to an Enterprise’s AAA Infrastructure

Only authenticated end user devices can connect to the Check Point SASE alwayson VPN. Once connected, two- factor authentication is required for access to enterprise resources.

Full

Network Monitoring and Defense

13 13.4 Network Protect

Perform Traffic Filtering Between Network Segments

The Check Point SASE Firewall as a Service controls traffic between network segments based on granular network policy rules.

Partial

13 13.5 Devices Protect Manage Access Control for Remote Assets

Remote access is limited to user accounts that require it based on the principle of least privilege. The security posture of remote devices is checked to ensure compliance with organizational policies.

Partial

All rights reserved. Check Point | 2026

CIS Control CIS Safeguard Asset Type Security Function Title How Check Point SASE Helps Full / Partial / Facilitates

13 13.6 Network Detect Collect Network Traffic Flow Logs

Check Point SASE network traffic flow is visible within the monitoring dashboard and logs of firewall events are available.

Partial

13 13.9 Devices Protect Deploy Port-Level Access Control

The platform uses identity based access controls to authenticate users attempting to access the managed network.

Partial

13 13.10 Network Protect Perform Application Layer Filtering

Firewall rules control traffic between network resources. Partial

Contact your Check Point SASE representative for the full coverage matrix with additional information.

Visit sase.checkpoint.com to learn more.

https://sase.checkpoint.com/


Item Type: pdf