Adding an already registered CSAT user to an existing CSAT Organization


Product Name

CIS-Hosted CSAT

Product Version

all

Date

May 18, 2021



 

Problem

I’m an IT audit consultant, one of our clients has established their CIS-Hosted CSAT dashboard and we need to add one of our consultants to our client’s CSAT Project Dashboard/ Admins list

Since we’ll be doing several communities in this way, I’m wondering what the easiest way to accomplish adding an already registered user to a project will be?

 

Solution

CIS-Hosted CSAT is not generally geared towards consultants so much as independent organizations who wish to assess their security, and the security of their individual sub-organizations. For the Consultants with many sub-organizations, various Admin and User roles, etc. CIS-Hosted CSAT is limited in its capacity to create and manipulate sub-orgs and their Admins. Furthermore, it is challenging, if not impossible, to have an admin of a primary Organization also be an Admin to multiple Sub-Organizations. It is a limitation of the free software.

While CIS-Hosted CSAT is free for organizations to use to assess their own organization’s implementation of the CIS Controls, if you are using CSAT in a commercial capacity (as a paid consultant to assess another organization, for instance), you will need to become a CIS SecureSuite Consulting Member.  Please see https://www.cisecurity.org/cis-securesuite/pricing-and-categories/services-and-consulting/ for details

The CSAT Pro software has several features that can benefit the consultant-use-case that are not available in the CIS-Hosted version of CSAT. CSAT Pro lets you have multiple organization trees, multiple concurrent assessments in each organization/sub-organization, and a more flexible permission model (so the same user can have different roles in different organizations). Additionally, if an assessment has already been started in CIS-Hosted CSAT, it is possible to export an assessment from CIS-Hosted CSAT and import it into CSAT Pro.

Here is a blog post with more information regarding the new CSAT Pro: https://www.cisecurity.org/blog/improve-your-organizations-cyber-hygiene-with-cis-csat-pro/ It is also an excellent resource for anyone hoping to do Cyber Security Consultations for multiple sub-organizations.

There is a CSAT Pro community on CIS WorkBench at ::CIS Controls - CSAT Pro which you can join if you would like to review the discussions and release information.

 

Keywords; CSAT Hosted Register

Content by Label


Copyright © 2020

Center for Internet Security®