CIS Controls
Also known as: CIS Critical Security Controls, CIS 18
A ranked, public list of security measures from the Center for Internet Security that tells an organisation what to do first.
Draft - this entry has not been reviewed yet.
Formal
A set of 18 grouped security controls published by the Center for Internet Security, ordered so that the most effective basic steps come first and split into three levels of ambition.
In plain English
Like a checklist from a fire safety expert that says "fit smoke alarms before you buy a sprinkler system" - it tells you which protections give the most for the least.
In practice
A small accounting firm with a single IT person uses the first level of the list to agree with the partners that knowing its devices, updating software and keeping backups come before anything else.
Why it matters
Most organisations cannot do everything at once; a shared, ranked list turns a vague goal into a clear order of work and a way to measure progress.
How to put it into practice
The usual steps, in order. Adapt them to your organisation.
- Name an owner for the programme and download CIS Controls v8.1 with its Implementation Group mapping from cisecurity.org.
- Pick your Implementation Group from your size, IT staff and data sensitivity; most small and medium organisations start with IG1 and its 56 safeguards.
- Run a baseline self-assessment of every safeguard in the chosen group, for example in the CIS Controls Self Assessment Tool (CSAT) or a spreadsheet, scoring how far each is implemented.
- Start with Controls 1 and 2 (enterprise and software asset inventory), because patching, configuration and access control all depend on knowing what you have.
- Turn the gaps into a prioritised roadmap with owners, deadlines and budget, and have management approve it.
- Implement the safeguards and turn their built-in frequencies into routines, such as quarterly internal vulnerability scans and quarterly restore tests.
- Map the safeguards to ISO 27001 or NIS2 requirements where needed, so the same evidence serves several frameworks.
- Reassess at least once a year, report progress to management, and move on to IG2 or IG3 once IG1 is in place and your risk calls for it.
Common pitfalls
- Jumping to advanced IG3 safeguards before IG1 basics like inventory, patching and backup are in place.
- Treating the Controls as a replacement for the governance and risk assessment that ISO 27001 or NIS2 require.
- Scoring a safeguard as done because a tool has been bought, not because it covers all assets.
- Confusing the CIS Controls with the CIS Benchmarks, which are hardening guides for specific platforms.
Good guides
- CIS Critical Security Controls Version 8.1(opens in a new tab) · Center for Internet Security
- CIS Critical Security Controls Implementation Groups(opens in a new tab) · Center for Internet Security
- CIS Critical Security Controls Implementation Group 1(opens in a new tab) · Center for Internet Security
Technical deep dive
The CIS Controls began in 2008 as the Consensus Audit Guidelines, later the SANS Top 20, compiled by US government and private-sector practitioners around a single question: which defensive actions stop the attacks actually observed? Stewardship moved to the Center for Internet Security, and the list went through versions 5, 6 and 7. Version 7 grouped controls into basic, foundational and organisational; version 7.1 (2019) introduced Implementation Groups. Version 8 (2021) reorganised the content by activity rather than by who manages a device, merged and dropped controls to reach 18 controls and 153 safeguards, and updated the language for cloud, mobile and remote work. Version 8.1 (2024) kept the structure but revised safeguard wording, added a Govern security function to align with NIST CSF 2.0, and introduced documentation as an asset type.
Each safeguard is a single, testable action with two attributes: an asset type (devices, software, data, users, network, and in 8.1 documentation) and a security function (Identify, Protect, Detect, Respond, Recover, and in 8.1 Govern). Implementation Groups are cumulative: IG1 has 56 safeguards, IG2 adds 74 and IG3 adds 23. Several safeguards embed concrete frequencies that auditors can check, for example authenticated and unauthenticated vulnerability scans of internal assets at least quarterly (7.5), external scans at least monthly (7.6) and restore tests at least quarterly (11.5).
CIS justifies the prioritisation with the Community Defense Model, which maps safeguards against MITRE ATT&CK techniques used in common attack patterns such as ransomware, web-application hacking and insider misuse, and reports how much of each pattern IG1 alone mitigates. That evidence base is the main methodological difference from ISO/IEC 27002, whose 93 controls are selected through a risk assessment and justified in a Statement of Applicability rather than applied in a fixed order.
Two neighbouring CIS products are often confused with the Controls. The CIS Benchmarks are consensus hardening guides for specific platforms (Windows Server, RHEL, Kubernetes, AWS and many more), with Level 1 and Level 2 profiles; they are how Control 4 (secure configuration) is implemented in practice, and CIS-CAT scans systems against them. The CIS Controls Self Assessment Tool (CSAT) is used to track safeguard implementation. CIS publishes mappings to NIST CSF 2.0, ISO/IEC 27001:2022, PCI DSS and other frameworks, which makes the Controls a practical technical layer under a management-system standard or under NIS2 Art. 21, but not a substitute for the governance, risk-assessment and reporting obligations those impose.
What to learn first
Everything this builds on, foundations first.
- CIA triad
- →Threat
- →Asset
- →Vulnerability
- →Impact
- →Likelihood
- →Risk
- →Security control
- →CIS Controls
Relationships
Sources & further reading
Standards & official texts
- CIS Critical Security Controls v8 · Center for Internet Security
Course material
- Cyber Security Fast Track - Ordliste
Where this data comes from
This entry was drafted by an AI from the sources above and has not yet been checked by a person. Treat it as a starting point, and check anything important against the sources.
See the review queueSuggest a correction on GitHubThis term as JSON
Mentioned in
Check yourself
Loading…