What Are CIS Controls 8.1?
The CIS Critical Security Controls (now in version 8.1) are a prioritized list of cybersecurity actions that defend against the most common and dangerous cyber attacks. They're vendor-neutral, free to access, and built by consensus from security experts across government, academia, and the private sector.
Unlike prescriptive frameworks like ISO 27001 or SOC 2, CIS Controls focus on outcomes (what you actually need to do to reduce risk) rather than how you document it.
Learn more about CIS Controls here.
Why CIS 8.1 Matters Now
Version 8.1 simplified and reorganized the controls to be easier to implement. It cuts through complexity:
- 18 control groups (down from 20 in earlier versions) covering inventory, access, data protection, and incident response
- Implementation groups (IGs) that map controls to organizational maturity: IG1 (foundational), IG2 (intermediate), IG3 (advanced)
- Practical focus: every control ties to reducing actual attack surface
If you're a small or mid-sized business, IG1 and IG2 controls get you to a defensible security posture without requiring enterprise infrastructure.
The 18 Control Groups at a Glance
CIS 8.1 organizes around six core functions:
Govern
- CIS 1: Cyber security roles and responsibilities
- CIS 2: Supply chain risk management
- CIS 3: Information protection processes and procedures
- CIS 4: Secure configuration management
Defend
- CIS 5: Account management
- CIS 6: Access control management
- CIS 7: Data protection
- CIS 8: Asset management
- CIS 9: Log management
- CIS 10: Malware defenses
- CIS 11: Data recovery
- CIS 12: Network infrastructure
- CIS 13: Network monitoring and defense
- CIS 14: Security awareness and skills
- CIS 15: Service provider management
Respond
- CIS 16: Incident management
- CIS 17: Testing, training, and monitoring
- CIS 18: Security incident and event monitoring
Each control includes detailed implementation guidance, but you don't need to do everything at once.
Start with IG1: The Minimum Viable Security Baseline
Implementation Group 1 covers the controls that stop the majority of common attacks. For a typical SMB, this is where you should start:
- Asset inventory: Know what devices and software exist on your network
- Access controls: Users have minimal necessary permissions; admin access is restricted
- Secure configuration: Devices are hardened with sensible defaults (no default passwords, unnecessary services disabled)
- Malware protection: Endpoint protection is installed and updated
- Log collection: You're keeping records of who accessed what and when
- Incident response plan: You have a documented process for handling breaches
IG1 controls typically require:
- Clear ownership and documented procedures (a policy or two)
- Basic tooling (most SMBs already have email, endpoint protection, firewalls)
- Regular audits to confirm controls are working
Time to implement? For a team of 50-200 people, a realistic estimate is 4–8 weeks to establish foundational IG1 controls if you're starting from scratch.
How CIS 8.1 Differs from ISO 27001 and SOC 2
You don't have to choose. Many organizations use CIS Controls as the substance and ISO 27001 or SOC 2 as the documentation requirement.
| Aspect | CIS Controls | ISO 27001 | SOC 2 |
|---|---|---|---|
| Purpose | Risk reduction roadmap | Comprehensive ISMS framework | Trust report for customers |
| Prescriptive? | Guidelines; you decide how | Prescriptive; must document everything | Outcome-focused; tested by auditors |
| Cost to start | Free | ~$2K–10K for external certification | ~$10K–50K for Type II audit |
| Time to "compliant" | Weeks to months (depends on maturity) | 6–12 months typically | 6–24 months (Type II) |
CIS is often the best entry point because it's free, unambiguous about priority, and lets you show measurable progress quickly.
A Practical Implementation Path
Month 1–2: Plan and Inventory
- Document current state: what systems, software, and users you have
- Map your environment to IG1 controls
- Identify quick wins (e.g., enforce MFA, disable old accounts)
Month 2–4: Implement IG1
- Deploy asset management and access controls
- Create a basic incident response plan
- Set up centralized logging (if not already in place)
- Deploy or configure malware defenses
Month 4–6: Validate and Document
- Test that controls are actually working (not just installed)
- Document your policies and procedures
- Train staff on security awareness
- Perform a self-assessment against CIS 8.1 IG1
Month 6+: Iterate to IG2
- Move to intermediate controls (advanced access policies, encryption, vendor risk management)
- Establish continuous monitoring
- Plan for regular audits
Tools That Help
You don't need expensive GRC software to get started, but as you scale, tracking evidence and staying organized gets complicated.
Many teams start with spreadsheets, then graduate to dedicated platforms that can:
- Map your controls across CIS (and other frameworks simultaneously, like ISO 27001 or SOC 2)
- Track evidence in one place (policy documents, access reviews, logs, training records)
- Run self-assessments and gap analyses
- Generate reports for auditors or leadership
Keel's CIS Controls framework includes the full CIS 8.1 control library mapped to other standards you might need later, so you're not reworking compliance each time a new requirement lands.
Common Pitfalls to Avoid
Trying to do everything at once IG1 first. IG3 is overkill for most SMBs until you've matured.
Implementing without buy-in Your CEO and department heads need to understand why this matters (reduced breach risk, customer trust, insurance savings). Frame it as risk reduction, not compliance theater.
Documentation without validation A policy that no one follows isn't a control. Test and verify that what you've implemented actually works.
Treating it as a one-time project CIS Controls require continuous review and updates as your business, threat landscape, and tools evolve. Plan for quarterly reviews.
Next Steps
- Read the CIS Controls documentation: Start here for full guidance.
- Map your current state: Compare what you already have against IG1. Most organizations are already doing some of it.
- Prioritize quick wins: Implement 2–3 controls that have high impact and low friction (MFA, malware protection, access reviews).
- Assign accountability: One person owns each control area and reports monthly on progress.
- Plan for 6 months: Set realistic milestones and celebrate progress.
CIS 8.1 is approachable because it's designed around outcomes, not bureaucracy. Start small, measure results, and build from there.