CIS Controls
CIS Controls are a prioritized set of cybersecurity best practices published by the Center for Internet Security. They provide a concrete, ordered checklist of defensive actions organizations implement to reduce their most common attack exposures.
itCybersecurity fundamentals and governance | OpenSkills.info
Intro
CIS Controls
The CIS Critical Security Controls turn a broad goal into a prioritized set of defensive actions. The broad goal is reducing exposure to common cyber attacks. The actions tell you what capabilities to establish, maintain, and check.
CIS Controls version 8.1 contains 18 Controls and 153 Safeguards. A Control describes a defensive outcome, such as managing enterprise assets or recovering data. A Safeguard defines a specific action that supports that outcome.
This structure matters because a security program can collect policies and tools without reducing much risk. The CIS Controls give you a shared list of outcomes and actions. You can use that list to find gaps, set priorities, assign owners, and track evidence.
The mental model
Think in four layers:
business context and risk
↓
Implementation Group
↓
Controls → Safeguards
↓
owners, procedures, technology, evidence, review
Your business context shapes the right starting scope. An Implementation Group, or IG, selects a prioritized set of Safeguards. The Controls organize those Safeguards by defensive outcome. Your organization then turns each selected Safeguard into operating work.
The last layer prevents a common failure. Selecting a Safeguard is not the same as implementing it. Implementation needs an owner, a repeatable procedure, suitable technology, and evidence that the action occurs. It also needs review because systems, threats, and business goals change.
Continue the course
This section is part of the paid course.
See pricing to subscribe, or log in if you already have access.
Where this skill leads
Relevant careers
See how this topic contributes to broader role-level skill maps.
Sources
- https://www.cisecurity.org/controls/v8-1
Supports
- CIS Controls as a prioritized set of Safeguards defending systems and networks against prevalent cyber attacks
- Version 8.1 as an iterative update to version 8.0
- Updated alignment to NIST Cybersecurity Framework 2.0, including the Govern function
- Revised asset classes, expanded glossary definitions, and clarified Safeguard descriptions
- Availability of the version 8.1 PDF, spreadsheet, change log, and Implementation Groups material
- https://www.cisecurity.org/controls/implementation-groups
Supports
- Implementation Groups as prioritized guidance based on enterprise risk profile and resources
- Three groups named IG1, IG2, and IG3
- Total of 153 Safeguards in CIS Controls versions 8 and 8.1
- Every enterprise starts with IG1, described as essential cyber hygiene
- IG2 builds on IG1, while IG3 contains all Controls and Safeguards
- https://www.cisecurity.org/controls/cis-controls-navigator
Supports
- Exact names and numbering of all 18 Controls
- Exact Safeguard names, descriptions, Implementation Group assignments, and stated cadences
- Control 1 asset inventory and unauthorized-asset examples
- Control 6 access granting, revoking, and multifactor authentication examples
- Mappings between CIS Controls v8.1 and other standards and frameworks
- Navigator filtering by version, mapping, and Implementation Group, plus spreadsheet export
- https://www.cisecurity.org/insights/white-papers/cis-critical-security-controls-v8-1
Supports
- Version 8.1 publication on June 24, 2024
- Version 8.1 as prescriptive, prioritized, and simplified cybersecurity best practices
- Glossary, asset-class, Safeguard-description, and NIST Cybersecurity Framework mapping changes
- Governance topics identified in the version 8.1 mapping
- https://www.cisecurity.org/insights/white-papers/guide-implementation-groups-ig-cis-critical-security-controls-v8-1
Supports
- Implementation Group choice based on size or complexity, data types, resources and technology, threat types, and risk
- IG1 as the on-ramp and minimum information-security baseline
- Progression to IG2 and IG3 after IG1 based on enterprise factors
- Safeguard implementation as iterative rather than one-time activity
