https://www.sans.org/reading-room/whitepapers/riskmanagement/realistic-risk-management-cis-20-security-controls-37135