{"licence":{"name":"CC BY-SA 4.0","spdx":"CC-BY-SA-4.0","url":"https://creativecommons.org/licenses/by-sa/4.0/","attribution":"Atlas, a bilingual technical dictionary (https://cmaintz.github.io/tech-atlas/)"},"id":"security/cis-controls","url":{"en":"https://cmaintz.github.io/tech-atlas/en/terms/security/cis-controls/","da":"https://cmaintz.github.io/tech-atlas/da/terms/security/cis-controls/"},"term":{"en":"CIS Controls","da":"CIS-kontroller"},"aka":{"en":["CIS Critical Security Controls","CIS 18"],"da":["CIS Controls","CIS 18"]},"domain":["security"],"cluster":"controls","layer":"governance","status":"current","era":2008,"summary":{"en":"A ranked, public list of security measures from the Center for Internet Security that tells an organisation what to do first.","da":"En prioriteret, offentlig liste over sikkerhedstiltag fra Center for Internet Security, der viser, hvad man bør gøre først."},"body":{"formal":{"en":"A set of 18 grouped security controls published by the Center for Internet Security, ordered so that the most effective basic steps come first and split into three levels of ambition.","da":"Et sæt af 18 grupperede sikkerhedskontroller udgivet af Center for Internet Security, ordnet så de mest effektive grundtiltag kommer først, og delt i tre ambitionsniveauer."},"plain":{"en":"Like a checklist from a fire safety expert that says \"fit smoke alarms before you buy a sprinkler system\" - it tells you which protections give the most for the least.","da":"Som en tjekliste fra en brandekspert, der siger \"sæt røgalarmer op, før du køber et sprinkleranlæg\" - den viser, hvilke beskyttelser der giver mest for mindst."},"inPractice":{"en":"A small accounting firm with a single IT person uses the first level of the list to agree with the partners that knowing its devices, updating software and keeping backups come before anything else.","da":"Et lille revisionsfirma med én IT-medarbejder bruger listens første niveau til at blive enig med partnerne om, at overblik over enheder, opdatering af software og backup kommer før alt andet."},"whyItMatters":{"en":"Most organisations cannot do everything at once; a shared, ranked list turns a vague goal into a clear order of work and a way to measure progress.","da":"De fleste virksomheder kan ikke gøre alt på én gang; en fælles, prioriteret liste gør et vagt mål til en klar rækkefølge og en måde at måle fremskridt på."}},"deepDive":{"en":"The CIS Controls began in 2008 as the Consensus Audit Guidelines, later the SANS Top 20, compiled by US government and private-sector practitioners around a single question: which defensive actions stop the attacks actually observed? Stewardship moved to the Center for Internet Security, and the list went through versions 5, 6 and 7. Version 7 grouped controls into basic, foundational and organisational; version 7.1 (2019) introduced Implementation Groups. Version 8 (2021) reorganised the content by activity rather than by who manages a device, merged and dropped controls to reach 18 controls and 153 safeguards, and updated the language for cloud, mobile and remote work. Version 8.1 (2024) kept the structure but revised safeguard wording, added a Govern security function to align with NIST CSF 2.0, and introduced documentation as an asset type.\n\nEach safeguard is a single, testable action with two attributes: an asset type (devices, software, data, users, network, and in 8.1 documentation) and a security function (Identify, Protect, Detect, Respond, Recover, and in 8.1 Govern). Implementation Groups are cumulative: IG1 has 56 safeguards, IG2 adds 74 and IG3 adds 23. Several safeguards embed concrete frequencies that auditors can check, for example authenticated and unauthenticated vulnerability scans of internal assets at least quarterly (7.5), external scans at least monthly (7.6) and restore tests at least quarterly (11.5).\n\nCIS justifies the prioritisation with the Community Defense Model, which maps safeguards against MITRE ATT&CK techniques used in common attack patterns such as ransomware, web-application hacking and insider misuse, and reports how much of each pattern IG1 alone mitigates. That evidence base is the main methodological difference from ISO/IEC 27002, whose 93 controls are selected through a risk assessment and justified in a Statement of Applicability rather than applied in a fixed order.\n\nTwo neighbouring CIS products are often confused with the Controls. The CIS Benchmarks are consensus hardening guides for specific platforms (Windows Server, RHEL, Kubernetes, AWS and many more), with Level 1 and Level 2 profiles; they are how Control 4 (secure configuration) is implemented in practice, and CIS-CAT scans systems against them. The CIS Controls Self Assessment Tool (CSAT) is used to track safeguard implementation. CIS publishes mappings to NIST CSF 2.0, ISO/IEC 27001:2022, PCI DSS and other frameworks, which makes the Controls a practical technical layer under a management-system standard or under NIS2 Art. 21, but not a substitute for the governance, risk-assessment and reporting obligations those impose.","da":"CIS-kontrollerne opstod i 2008 som Consensus Audit Guidelines, senere kendt som SANS Top 20, samlet af praktikere fra amerikanske myndigheder og den private sektor ud fra ét spørgsmål: hvilke forsvarshandlinger stopper de angreb, man faktisk ser? Forvaltningen overgik til Center for Internet Security, og listen gik gennem version 5, 6 og 7. Version 7 grupperede kontrollerne i basale, grundlæggende og organisatoriske; version 7.1 (2019) indførte Implementation Groups. Version 8 (2021) omorganiserede indholdet efter aktivitet i stedet for efter, hvem der forvalter en enhed, slog kontroller sammen og fjernede andre, så der blev 18 kontroller og 153 safeguards, og moderniserede sproget til cloud, mobil og fjernarbejde. Version 8.1 (2024) bevarede strukturen, men reviderede formuleringerne, tilføjede en Govern-sikkerhedsfunktion for at flugte med NIST CSF 2.0 og indførte dokumentation som aktivtype.\n\nHver safeguard er én testbar handling med to attributter: en aktivtype (enheder, software, data, brugere, netværk og i 8.1 dokumentation) og en sikkerhedsfunktion (Identify, Protect, Detect, Respond, Recover og i 8.1 Govern). Implementation Groups er kumulative: IG1 har 56 safeguards, IG2 tilføjer 74, og IG3 tilføjer 23. Flere safeguards indeholder konkrete frekvenser, som en revisor kan efterprøve, fx autentificerede og uautentificerede sårbarhedsscanninger af interne aktiver mindst kvartalsvist (7.5), eksterne scanninger mindst månedligt (7.6) og gendannelsestest mindst kvartalsvist (11.5).\n\nCIS begrunder prioriteringen med sin Community Defense Model, der kortlægger safeguards mod MITRE ATT&CK-teknikker i udbredte angrebsmønstre som ransomware, angreb på webapplikationer og insidermisbrug, og opgør, hvor stor en del af hvert mønster IG1 alene afbøder. Dette evidensgrundlag er den væsentligste metodiske forskel fra ISO/IEC 27002, hvis 93 kontroller udvælges gennem en risikovurdering og begrundes i en Statement of Applicability (erklæring om anvendelighed) i stedet for at blive anvendt i en fast rækkefølge.\n\nTo nærtstående CIS-produkter forveksles ofte med kontrollerne. CIS Benchmarks er konsensusbaserede hærdningsvejledninger til konkrete platforme (Windows Server, RHEL, Kubernetes, AWS og mange flere) med Level 1- og Level 2-profiler; det er med dem, Control 4 (sikker konfiguration) implementeres i praksis, og CIS-CAT scanner systemer op imod dem. CIS Controls Self Assessment Tool (CSAT) bruges til at følge implementeringen af safeguards. CIS udgiver mappings til NIST CSF 2.0, ISO/IEC 27001:2022, PCI DSS og andre rammer, hvilket gør kontrollerne til et praktisk teknisk lag under en ledelsessystemstandard eller under NIS2 art. 21 - men ikke til en erstatning for de krav om ledelse, risikovurdering og rapportering, som disse stiller."},"edges":[{"type":"requires","to":"security/control","confidence":"high","strength":"normal"},{"type":"kind-of","to":"security/security-framework","confidence":"high","strength":"normal"},{"type":"alternative-to","to":"security/iso-27002","why":{"en":"Both are catalogues of security controls; CIS is shorter and ranked, ISO 27002 is broader and tied to ISO 27001.","da":"Begge er kataloger over sikkerhedskontroller; CIS er kortere og prioriteret, ISO 27002 er bredere og knyttet til ISO 27001."},"confidence":"medium","strength":"normal"},{"type":"used-with","to":"security/d-maerket","confidence":"high","strength":"normal"},{"type":"used-with","to":"security/nis2","confidence":"high","strength":"normal"},{"type":"used-with","to":"security/risk-profile","confidence":"high","strength":"normal"},{"type":"mandates","to":"security/asset-inventory","confidence":"high","strength":"normal"},{"type":"mandates","to":"security/access-management","confidence":"high","strength":"normal"},{"type":"mandates","to":"security/patch-management","confidence":"high","strength":"normal"},{"type":"mandates","to":"security/backup","confidence":"high","strength":"normal"},{"type":"mandates","to":"security/vulnerability-scanning","confidence":"high","strength":"normal"},{"type":"mandates","to":"security/hardening","confidence":"high","strength":"normal"},{"type":"mandates","to":"security/security-awareness","confidence":"high","strength":"normal"},{"type":"mandates","to":"security/incident-response","confidence":"high","strength":"normal"},{"type":"mandates","to":"security/penetration-test","confidence":"high","strength":"normal"},{"type":"mandates","to":"security/log-management","confidence":"high","strength":"normal"}],"depth":5,"sources":[{"title":"Cyber Security Fast Track - Ordliste","tier":"course-material"},{"title":"CIS Critical Security Controls v8","tier":"standard","publisher":"Center for Internet Security"}],"draft":true}