openskills.info
CIS Controls logoCourse Preview

CIS Controls

CIS Controls are a prioritized set of cybersecurity best practices published by the Center for Internet Security. They provide a concrete, ordered checklist of defensive actions organizations implement to reduce their most common attack exposures.

itCybersecurity fundamentals and governance

Don't Panic — CIS Controls

CIS Controls are what happens when a security wish list grows so long that it starts requiring its own security team. They turn the broad ambition of reducing exposure to common attacks into prioritized defensive actions. Instead of beginning with every possible policy, product, and alarming acronym, the Controls give the work a shape: defensive outcomes at one level and specific actions underneath.

The first useful distinction is between a Control, which names an outcome such as managing assets or recovering data, and a Safeguard, which names an action that supports it. There are 18 Controls and 153 Safeguards in version 8.1. That is still a sizeable pile of work, but it is a labeled pile, which is a considerable improvement over the alternative: discovering security priorities by accident.

The second idea is the Implementation Group, or IG. IG1 is the starting baseline. IG2 adds Safeguards for greater complexity or risk. IG3 contains the remaining Safeguards. The groups are cumulative, not three doors in a corridor where you abandon the first room when entering the second. Business context chooses a starting group, while laws, contracts, architecture, and current threats can require more.

The surprising part is that selecting a Safeguard does almost none of the work people mean by “implementing a control.” A selected action needs an owner, a repeatable procedure, suitable technology, coverage across a stated scope, current evidence, and review. A policy can prove that somebody intended a process to exist. It cannot prove the process happened on Tuesday, or that it included the cloud service everyone forgot was a service provider.

Keep the practical loop in your head: version, Implementation Group, scope, assess, remediate, operate, reassess. For each selected Safeguard, ask whether the capability is defined, covers the scope, runs at the expected cadence, and has current evidence. This is why a cheerful completion percentage can be a poor guide: a missing high-risk capability matters differently from several completed low-risk ones.

Read the Intro when the structure and limits need a calm explanation. Use Slides for the relationships and decision points. Keep the Cheatsheet nearby when assessing evidence or writing a gap record. The Practice Reference and Exercise turn one Safeguard into a repeatable assessment. Field Notes is where the tidy model meets the awkward parts of real boundaries, evidence, and ownership.

Where this skill leads

Relevant careers

See how this topic contributes to broader role-level skill maps.

Sources