What they cover
The 18 controls start with the basics and build up: inventory of hardware and software assets, data protection, secure configuration, account and access management, continuous vulnerability management, audit log management, email and browser protections, malware defences, data recovery, network infrastructure, security awareness, service provider management, application security, incident response and penetration testing. Each control is broken down into specific safeguards.
Implementation Groups
Safeguards are grouped into three Implementation Groups. IG1 is described as essential cyber hygiene, the minimum every organisation should have, and is designed for small companies with limited IT resources. IG2 and IG3 add safeguards for organisations with more complex environments, sensitive data or regulatory exposure.
Why companies use them
They are concrete and prioritised: instead of a long list of requirements, they say what to do first. Many cyber insurers and supplier questionnaires ask about the same basics, such as MFA, backups and patch management, so IG1 is a practical baseline.
Relation to other frameworks
The CIS Controls are not a certification. They map to ISO 27001, the NIST CSF and other frameworks, and can be used to implement their technical controls. The controls and mappings are available from the Center for Internet Security.




