GlossaryCompliance operations

CIS Controls

Short answer

The CIS Critical Security Controls are a prioritised set of 18 defensive measures published by the Center for Internet Security, designed to stop the most common attacks. They are free, practical and grouped into implementation levels, which makes them a popular starting point for smaller organisations.

What they cover

The 18 controls start with the basics and build up: inventory of hardware and software assets, data protection, secure configuration, account and access management, continuous vulnerability management, audit log management, email and browser protections, malware defences, data recovery, network infrastructure, security awareness, service provider management, application security, incident response and penetration testing. Each control is broken down into specific safeguards.

Implementation Groups

Safeguards are grouped into three Implementation Groups. IG1 is described as essential cyber hygiene, the minimum every organisation should have, and is designed for small companies with limited IT resources. IG2 and IG3 add safeguards for organisations with more complex environments, sensitive data or regulatory exposure.

Why companies use them

They are concrete and prioritised: instead of a long list of requirements, they say what to do first. Many cyber insurers and supplier questionnaires ask about the same basics, such as MFA, backups and patch management, so IG1 is a practical baseline.

Relation to other frameworks

The CIS Controls are not a certification. They map to ISO 27001, the NIST CSF and other frameworks, and can be used to implement their technical controls. The controls and mappings are available from the Center for Internet Security.

Related terms

Keep reading on this topic

Running security as a repeatable process: policy management, risk registers, evidence upkeep, supplier assessment and audit readiness between cycles.

Go to the topic hub