CIS Controls
Also known as: CIS Critical Security Controls, CIS 18
A ranked, public list of security measures from the Center for Internet Security that tells an organisation what to do first.
Draft - this entry has not been reviewed yet.
Formal
A set of 18 grouped security controls published by the Center for Internet Security, ordered so that the most effective basic steps come first and split into three levels of ambition.
In plain English
Like a checklist from a fire safety expert that says "fit smoke alarms before you buy a sprinkler system" - it tells you which protections give the most for the least.
In practice
A small accounting firm with a single IT person uses the first level of the list to agree with the partners that knowing its devices, updating software and keeping backups come before anything else.
Why it matters
Most organisations cannot do everything at once; a shared, ranked list turns a vague goal into a clear order of work and a way to measure progress.
Technical deep dive
The CIS Controls began in 2008 as the Consensus Audit Guidelines, later the SANS Top 20, compiled by US government and private-sector practitioners around a single question: which defensive actions stop the attacks actually observed? Stewardship moved to the Center for Internet Security, and the list went through versions 5, 6 and 7. Version 7 grouped controls into basic, foundational and organisational; version 7.1 (2019) introduced Implementation Groups. Version 8 (2021) reorganised the content by activity rather than by who manages a device, merged and dropped controls to reach 18 controls and 153 safeguards, and updated the language for cloud, mobile and remote work. Version 8.1 (2024) kept the structure but revised safeguard wording, added a Govern security function to align with NIST CSF 2.0, and introduced documentation as an asset type.
Each safeguard is a single, testable action with two attributes: an asset type (devices, software, data, users, network, and in 8.1 documentation) and a security function (Identify, Protect, Detect, Respond, Recover, and in 8.1 Govern). Implementation Groups are cumulative: IG1 has 56 safeguards, IG2 adds 74 and IG3 adds 23. Several safeguards embed concrete frequencies that auditors can check, for example authenticated and unauthenticated vulnerability scans of internal assets at least quarterly (7.5), external scans at least monthly (7.6) and restore tests at least quarterly (11.5).
CIS justifies the prioritisation with the Community Defense Model, which maps safeguards against MITRE ATT&CK techniques used in common attack patterns such as ransomware, web-application hacking and insider misuse, and reports how much of each pattern IG1 alone mitigates. That evidence base is the main methodological difference from ISO/IEC 27002, whose 93 controls are selected through a risk assessment and justified in a Statement of Applicability rather than applied in a fixed order.
Two neighbouring CIS products are often confused with the Controls. The CIS Benchmarks are consensus hardening guides for specific platforms (Windows Server, RHEL, Kubernetes, AWS and many more), with Level 1 and Level 2 profiles; they are how Control 4 (secure configuration) is implemented in practice, and CIS-CAT scans systems against them. The CIS Controls Self Assessment Tool (CSAT) is used to track safeguard implementation. CIS publishes mappings to NIST CSF 2.0, ISO/IEC 27001:2022, PCI DSS and other frameworks, which makes the Controls a practical technical layer under a management-system standard or under NIS2 Art. 21, but not a substitute for the governance, risk-assessment and reporting obligations those impose.
What to learn first
Everything this builds on, foundations first.
- CIA triad
- →Threat
- →Asset
- →Vulnerability
- →Impact
- →Likelihood
- →Risk
- →Security control
- →CIS Controls
Relationships
Sources & further reading
Standards & official texts
- CIS Critical Security Controls v8 · Center for Internet Security
Course material
- Cyber Security Fast Track - Ordliste
Where this data comes from
This entry was drafted by an AI from the sources above and has not yet been checked by a person. Treat it as a starting point, and check anything important against the sources.
See the review queueSuggest a correction on GitHubThis term as JSON
Mentioned in
Check yourself
Loading…