openskills.info
CIS Controls logoCourse Preview

CIS Controls

CIS Controls are a prioritized set of cybersecurity best practices published by the Center for Internet Security. They provide a concrete, ordered checklist of defensive actions organizations implement to reduce their most common attack exposures.

itCybersecurity fundamentals and governance

CIS Controls

The CIS Critical Security Controls turn a broad goal into a prioritized set of defensive actions. The broad goal is reducing exposure to common cyber attacks. The actions tell you what capabilities to establish, maintain, and check.

CIS Controls version 8.1 contains 18 Controls and 153 Safeguards. A Control describes a defensive outcome, such as managing enterprise assets or recovering data. A Safeguard defines a specific action that supports that outcome.

This structure matters because a security program can collect policies and tools without reducing much risk. The CIS Controls give you a shared list of outcomes and actions. You can use that list to find gaps, set priorities, assign owners, and track evidence.

The mental model

Think in four layers:

business context and risk
          ↓
Implementation Group
          ↓
Controls → Safeguards
          ↓
owners, procedures, technology, evidence, review

Your business context shapes the right starting scope. An Implementation Group, or IG, selects a prioritized set of Safeguards. The Controls organize those Safeguards by defensive outcome. Your organization then turns each selected Safeguard into operating work.

The last layer prevents a common failure. Selecting a Safeguard is not the same as implementing it. Implementation needs an owner, a repeatable procedure, suitable technology, and evidence that the action occurs. It also needs review because systems, threats, and business goals change.

Continue the course

This section is part of the paid course.

See pricing to subscribe, or log in if you already have access.

Where this skill leads

Relevant careers

See how this topic contributes to broader role-level skill maps.

Sources

  • https://www.cisecurity.org/controls/v8-1
  • https://www.cisecurity.org/controls/implementation-groups
  • https://www.cisecurity.org/controls/cis-controls-navigator
  • https://www.cisecurity.org/insights/white-papers/cis-critical-security-controls-v8-1
  • https://www.cisecurity.org/insights/white-papers/guide-implementation-groups-ig-cis-critical-security-controls-v8-1