number, name 1, Inventory of Authorized and Unauthorized Devices 2, Inventory of Authorized and Unauthorized Software 3, Secure Configuration of End-User Devices 4, Continuous Vulnerability Assessment & Remediation 5, Controlled Use of Administrative Privileges 6, Maintenance Monitoring and Analysis of Audit Logs 7, Email & Web Browser Protections 8, Malware Defense 9, Limitation & Control of Network Ports-Protocols & Services 10, Data Recovery Capability 11, Secure Configuration of Network Devices 12, Boundary Defense 13, Data Protection 14, Controlled Access Based on Need to Know 15, Wireless Access Control 16, Account Monitoring and Control 17, Security Skills Assessment and Appropriate Training 18, Application Software Security 19, Incident Response and Management 20, Penetration Tests and Red Team Exercises