What are the CIS Controls?
The CIS Critical Security Controls are a prioritized set of 18 safeguards, published by the Center for Internet Security, that defend against the most common cyber attacks. Version 8 organizes them into three Implementation Groups so smaller organizations can start with the essentials.
Definition
The CIS Controls are a prioritized, community-maintained set of defensive actions, published by the Center for Internet Security, that protect against the most prevalent cyber attacks.
Background
The current version, CIS Controls v8, consolidates the guidance into 18 controls (for example, inventory of enterprise assets, data protection, access control management, and malware defenses), each broken into specific safeguards. To make prioritization practical, v8 sorts safeguards into three Implementation Groups: IG1 is the baseline of essential cyber hygiene suited to small organizations, with IG2 and IG3 adding depth for larger or higher-risk enterprises.
Why it matters
The CIS Controls answer “what should we actually do first?” They are prioritized by real-world attack data, so a small team can adopt IG1 and meaningfully reduce risk without boiling the ocean. They also map cleanly into broader frameworks.
Step by step
- Start with an accurate inventory of your assets and software; you can’t protect what you don’t know about.
- Adopt the IG1 safeguards as your baseline of essential cyber hygiene.
- Prioritize the highest-impact controls: access control, data protection, and secure configuration.
- Map the CIS Controls to whatever framework you also report against, so the work counts twice.
- Measure your coverage and improve toward IG2/IG3 as your risk warrants.
Examples
- A 15-person startup adopts CIS IG1 as a pragmatic first security baseline before pursuing SOC 2.
- A company crosswalks its CIS Controls coverage into ISO 27001 Annex A to avoid duplicate work.
Common mistakes
- Skipping asset and software inventory, which underpins almost every other control.
- Trying to implement all 18 controls at once instead of starting with IG1.
- Treating CIS as separate from your other frameworks rather than mapping across them.
FAQ
How many CIS Controls are there?
Version 8 has 18 controls, each made up of specific safeguards. Earlier versions had 20; v8 consolidated them.
What are CIS Implementation Groups?
IG1, IG2, and IG3 are tiers that prioritize the safeguards. IG1 is essential cyber hygiene for smaller organizations; IG2 and IG3 add depth for larger or higher-risk ones.
Are the CIS Controls the same as CIS Benchmarks?
No. The CIS Controls are prioritized safeguards for an overall security program; CIS Benchmarks are detailed, system-specific hardening configurations. They complement each other.
Related
Do this in Keel, not a spreadsheet
Keel is the AI-native GRC platform for SMBs: one control-and-evidence graph across SOC 2, ISO 27001, HIPAA, PCI DSS, NIST CSF, and more. Start free, no credit card.
Start free