CIS Controls
CIS Controls are a prioritized set of cybersecurity best practices published by the Center for Internet Security. They provide a concrete, ordered checklist of defensive actions organizations implement to reduce their most common attack exposures.
itCybersecurity fundamentals and governance | OpenSkills.info
Course pathWalk it in order
Look it upDip in anytime
Go furtherLeaves this page
Don't Panic
Don't Panic — CIS Controls
CIS Controls are what happens when a security wish list grows so long that it starts requiring its own security team. They turn the broad ambition of reducing exposure to common attacks into prioritized defensive actions. Instead of beginning with every possible policy, product, and alarming acronym, the Controls give the work a shape: defensive outcomes at one level and specific actions underneath.
The first useful distinction is between a Control, which names an outcome such as managing assets or recovering data, and a Safeguard, which names an action that supports it. There are 18 Controls and 153 Safeguards in version 8.1. That is still a sizeable pile of work, but it is a labeled pile, which is a considerable improvement over the alternative: discovering security priorities by accident.
The second idea is the Implementation Group, or IG. IG1 is the starting baseline. IG2 adds Safeguards for greater complexity or risk. IG3 contains the remaining Safeguards. The groups are cumulative, not three doors in a corridor where you abandon the first room when entering the second. Business context chooses a starting group, while laws, contracts, architecture, and current threats can require more.
The surprising part is that selecting a Safeguard does almost none of the work people mean by “implementing a control.” A selected action needs an owner, a repeatable procedure, suitable technology, coverage across a stated scope, current evidence, and review. A policy can prove that somebody intended a process to exist. It cannot prove the process happened on Tuesday, or that it included the cloud service everyone forgot was a service provider.
Keep the practical loop in your head: version, Implementation Group, scope, assess, remediate, operate, reassess. For each selected Safeguard, ask whether the capability is defined, covers the scope, runs at the expected cadence, and has current evidence. This is why a cheerful completion percentage can be a poor guide: a missing high-risk capability matters differently from several completed low-risk ones.
Read the Intro when the structure and limits need a calm explanation. Use Slides for the relationships and decision points. Keep the Cheatsheet nearby when assessing evidence or writing a gap record. The Practice Reference and Exercise turn one Safeguard into a repeatable assessment. Field Notes is where the tidy model meets the awkward parts of real boundaries, evidence, and ownership.
Where this skill leads
Relevant careers
See how this topic contributes to broader role-level skill maps.
Sources
- https://www.cisecurity.org/controls/v8-1
Supports
- CIS Controls as a prioritized set of Safeguards defending systems and networks against prevalent cyber attacks
- Version 8.1 as an iterative update to version 8.0
- Updated alignment to NIST Cybersecurity Framework 2.0, including the Govern function
- Revised asset classes, expanded glossary definitions, and clarified Safeguard descriptions
- Availability of the version 8.1 PDF, spreadsheet, change log, and Implementation Groups material
- https://www.cisecurity.org/controls/implementation-groups
Supports
- Implementation Groups as prioritized guidance based on enterprise risk profile and resources
- Three groups named IG1, IG2, and IG3
- Total of 153 Safeguards in CIS Controls versions 8 and 8.1
- Every enterprise starts with IG1, described as essential cyber hygiene
- IG2 builds on IG1, while IG3 contains all Controls and Safeguards
- https://www.cisecurity.org/controls/cis-controls-navigator
Supports
- Exact names and numbering of all 18 Controls
- Exact Safeguard names, descriptions, Implementation Group assignments, and stated cadences
- Control 1 asset inventory and unauthorized-asset examples
- Control 6 access granting, revoking, and multifactor authentication examples
- Mappings between CIS Controls v8.1 and other standards and frameworks
- Navigator filtering by version, mapping, and Implementation Group, plus spreadsheet export
- https://www.cisecurity.org/insights/white-papers/cis-critical-security-controls-v8-1
Supports
- Version 8.1 publication on June 24, 2024
- Version 8.1 as prescriptive, prioritized, and simplified cybersecurity best practices
- Glossary, asset-class, Safeguard-description, and NIST Cybersecurity Framework mapping changes
- Governance topics identified in the version 8.1 mapping
- https://www.cisecurity.org/insights/white-papers/guide-implementation-groups-ig-cis-critical-security-controls-v8-1
Supports
- Implementation Group choice based on size or complexity, data types, resources and technology, threat types, and risk
- IG1 as the on-ramp and minimum information-security baseline
- Progression to IG2 and IG3 after IG1 based on enterprise factors
- Safeguard implementation as iterative rather than one-time activity
- https://www.cisecurity.org/insights/blog/ongoing-evolution-cis-critical-security-controls
Supports
- 2008 introduction as the SANS Critical Security Controls
- CIS ownership beginning with version 6 in 2015
- Implementation Groups introduced in version 7.1
- Version 8 release in May 2021, consolidation from 20 Controls to 18, and use of Safeguards
- Version 8.1 release in June 2024 and its governance and mapping updates
- https://www.cisecurity.org/controls/cis-controls-assessment-specification
Supports
- Assessment Specification structure: Safeguard, assumptions, inputs, operations, measures, metrics, and procedure review
- Distinction between determining whether a Safeguard is implemented and how well it is implemented
- Assessment Specification focus on what to measure rather than platform-specific configuration details
- CIS Controls Self Assessment Tool as a tool for measuring implementation quality
- https://www.cisecurity.org/insights/case-study/building-up-cyber-defenses-in-compliance-with-state-laws
Supports
- HDSD's six-month implementation of CIS Controls v7.1 IG1
- Separate student Google Chromebook and staff Windows administrative environments
- Using CIS Controls mappings to support its approach to state-law security requirements
- Using identified gaps to focus security purchases and implementation work
- https://www.cisecurity.org/cybersecurity-tools/cis-csat
Supports
- CIS Controls Self Assessment Tool as a CIS product for assessment work
- https://www.servicenow.com/products/integrated-risk-management.html
Supports
- Integrated Risk Management support for risk and compliance workflows, control assessment, remediation, and audit evidence
- https://www.archerirm.com/reg-corp-compliance-management
Supports
- Archer support for regulatory and corporate compliance program records and reporting
- https://www.logicgate.com/solutions/regulatory-compliance-management/
Supports
- LogicGate support for linking controls, policies, procedures, assessments, remediation workflows, and evidence records
- https://www.auditboard.com/products/controls-management/
Supports
- AuditBoard support for internal controls management and control mapping
- https://hyperproof.io/
Supports
- Hyperproof as a compliance operations platform for evidence and control work
