CIS Controls v8.1 at a Glance

The CIS Critical Security Controls (CIS Controls) v8.1 are a prioritized, prescriptive set of cybersecurity best practices developed by the Center for Internet Security (CIS) community. The 18 Controls contain 153 Safeguards organized into three Implementation Groups (IGs) based on organizational maturity and risk profile. CIS Controls are free, community-driven, and designed to be actionable — telling you exactly what to do and in what order. They are the most widely used prioritized cybersecurity framework globally and map to virtually every regulatory requirement.

18
Controls
153
Safeguards
3
Implementation Groups
2023
Version 8.1

The 18 CIS Controls

CIS Controls are organized into 18 domains covering the full spectrum of cybersecurity. They progress from foundational asset management to advanced penetration testing.

💻

Asset Management (CIS 1-2)

Inventory and Control of Enterprise Assets; Inventory and Control of Software Assets. You can't protect what you don't know about.

Controls 1–2
🔒

Data & Configuration (CIS 3-4)

Data Protection; Secure Configuration of Enterprise Assets and Software. Protect sensitive data and harden your systems.

Controls 3–4
👤

Account & Access (CIS 5-6)

Account Management; Access Control Management. Control who has access to what with MFA and least privilege.

Controls 5–6
🔧

Vulnerability & Malware (CIS 7-10)

Continuous Vulnerability Management; Audit Log Management; Email and Web Browser Protections; Malware Defenses.

Controls 7–10
📦

Recovery & Network (CIS 11-12)

Data Recovery; Network Infrastructure Management. Ensure you can bounce back and your network is secure.

Controls 11–12
👥

People & Response (CIS 13-18)

Network Monitoring and Defense; Security Awareness; Service Provider Management; Application Security; Incident Response; Penetration Testing.

Controls 13–18

Why Should a Security Engineer Care?

Prioritized and Prescriptive

Unlike outcome-based frameworks (NIST CSF) or management systems (ISO 27001), CIS Controls tell you exactly what to implement and in what order. Start with IG1 — 56 safeguards that stop 80%+ of attacks.

Implementation Groups

The IG model is brilliant for resource allocation. IG1 = essential hygiene (any org), IG2 = enterprise standard (sensitive data), IG3 = mature security (regulated/targeted). You always know what's next.

Community-Driven & Free

Developed by practitioners for practitioners. The CIS Controls are free to download and use. The CIS Benchmarks provide specific implementation guidance for every major platform.

Maps to Everything

CIS Controls map to NIST CSF, ISO 27001, NIST 800-53, PCI DSS, HIPAA, NIS2, and more. Implementing CIS Controls builds compliance with multiple frameworks simultaneously.

CIS Controls vs. Frameworks You Already Know

AspectCIS Controls v8.1NIST CSF 2.0ISO 27001BSI IT-Grundschutz
TypeCommunity best practicesVoluntary frameworkInternational standardNational methodology
ApproachPrioritized, prescriptiveOutcome-basedRisk-based management systemPrescriptive compendium
Structure18 Controls, 153 Safeguards, 3 IGs6 Functions, 22 Categories93 Annex A controls, 4 themes10 Layers, ~100 modules
CostFreeFreePaid standard (~$150)Free (compendium)
CertificationCIS CSAT (self-assessment)NoYes (accredited audit)Yes (BSI certification)
Best ForActionable prioritized security improvementsRisk management taxonomyFormal certificationDACH region, detailed guidance

The 18 CIS Controls — Deep Dive

Select a control group from the sidebar or filter below to focus on a specific domain.

CIS Control 1 — Inventory and Control of Enterprise Assets

Actively manage (inventory, track, and correct) all enterprise assets (end-user devices, including portable and mobile; network devices; non-computing/IoT devices; and servers) connected to the infrastructure, physically, virtually, remotely, and those within cloud environments, to accurately know the totality of assets that need to be monitored and protected.

Safeguards

Click any row for detailed context and implementation guidance.

IDSafeguardIGAsset TypeFunction
1.1Establish and Maintain Detailed Enterprise Asset InventoryIG1DevicesIdentify
1.2Address Unauthorized AssetsIG1DevicesRespond
1.3Utilize an Active Discovery ToolIG2DevicesDetect
1.4Use Dynamic Host Configuration Protocol (DHCP) Logging to Update Asset InventoryIG2DevicesIdentify
1.5Use a Passive Asset Discovery ToolIG3DevicesDetect
Security Engineer Takeaway: CIS Control 1 is intentionally first — asset inventory is the foundation of all security. You can't protect what you don't know about. Start with IG1: maintain a detailed inventory and address unauthorized assets. IG2 adds active discovery tools. IG3 adds passive discovery for complete visibility. Map to NIS2 Art. 21(2)(i) asset management and ISO 27001 A.5.9.

CIS Control 2 — Inventory and Control of Software Assets

Actively manage (inventory, track, and correct) all software (operating systems and applications) on the network so that only authorized software is installed and can execute, and that unauthorized and unmanaged software is found and prevented from installation or execution.

Safeguards

IDSafeguardIGAsset TypeFunction
2.1Establish and Maintain a Software InventoryIG1ApplicationsIdentify
2.2Ensure Authorized Software is Currently SupportedIG1ApplicationsIdentify
2.3Address Unauthorized SoftwareIG1ApplicationsRespond
2.4Utilize Automated Software Inventory ToolsIG2ApplicationsIdentify
2.5Allowlist Authorized SoftwareIG2ApplicationsProtect
2.6Allowlist Authorized LibrariesIG2ApplicationsProtect
2.7Allowlist Authorized ScriptsIG3ApplicationsProtect
Security Engineer Takeaway: Software inventory prevents shadow IT and unsupported application risks. IG1 focuses on knowing what you have and ensuring it's supported. IG2 adds automation and application allowlisting — one of the most effective controls against malware. Maps to BSI OPS.1.1.1 and ISO 27001 A.5.9.

CIS Control 3 — Data Protection

Develop processes and technical controls to identify, classify, securely handle, retain, and dispose of data.

Safeguards

IDSafeguardIGAsset TypeFunction
3.1Establish and Maintain a Data Management ProcessIG1DataIdentify
3.2Establish and Maintain a Data InventoryIG1DataIdentify
3.3Configure Data Access Control ListsIG1DataProtect
3.4Enforce Data RetentionIG1DataProtect
3.5Securely Dispose of DataIG1DataProtect
3.6Encrypt Data on End-User DevicesIG1DataProtect
3.7Establish and Maintain a Data Classification SchemeIG2DataIdentify
3.8Document Data FlowsIG2DataIdentify
3.9Encrypt Data on Removable MediaIG2DataProtect
3.10Encrypt Sensitive Data in TransitIG2DataProtect
3.11Encrypt Sensitive Data at RestIG2DataProtect
3.12Segment Data Processing and Storage Based on SensitivityIG2DataProtect
3.13Deploy a Data Loss Prevention SolutionIG3DataProtect
3.14Log Sensitive Data AccessIG3DataDetect
Security Engineer Takeaway: Data protection is where CIS Controls shine — from basic (data inventory, access controls, encryption on endpoints) to advanced (DLP, data flow documentation, sensitivity-based segmentation). Maps directly to ISO 27001 A.8.10–A.8.12 and NIS2 Art. 21(2)(h).

CIS Control 4 — Secure Configuration of Enterprise Assets and Software

Establish and maintain the secure configuration of enterprise assets (end-user devices, including portable and mobile; network devices; non-computing/IoT devices; and servers) and software (operating systems and applications).

Safeguards

IDSafeguardIGAsset TypeFunction
4.1Establish and Maintain a Secure Configuration ProcessIG1ApplicationsProtect
4.2Establish and Maintain a Secure Configuration Process for Network InfrastructureIG1NetworkProtect
4.3Configure Automatic Session Locking on Enterprise AssetsIG1UsersProtect
4.4Implement and Manage a Firewall on ServersIG1DevicesProtect
4.5Implement and Manage a Firewall on End-User DevicesIG1DevicesProtect
4.6Securely Manage Enterprise Assets and SoftwareIG1DevicesProtect
4.7Manage Default Accounts on Enterprise Assets and SoftwareIG1UsersProtect
4.8Uninstall or Disable Unnecessary ServicesIG2DevicesProtect
4.9Configure Trusted DNS ServersIG2DevicesProtect
4.10Enforce Automatic Device Lockout on Portable End-User DevicesIG2DevicesRespond
4.11Enforce Remote Wipe CapabilityIG2DevicesProtect
4.12Separate Enterprise Workspaces on Mobile End-User DevicesIG3DevicesProtect
Security Engineer Takeaway: Secure configuration = hardening. CIS Benchmarks provide the specific how-to for every major OS, application, and platform. IG1 covers firewalls, session locking, secure management, and default account management. Maps to ISO 27001 A.8.9 and BSI SYS modules.

CIS Control 5 — Account Management

Use processes and tools to assign and manage authorization to credentials for user accounts, including administrator accounts, as well as service accounts, to enterprise assets and software.

Safeguards

IDSafeguardIGAsset TypeFunction
5.1Establish and Maintain an Inventory of AccountsIG1UsersIdentify
5.2Use Unique PasswordsIG1UsersProtect
5.3Disable Dormant AccountsIG1UsersProtect
5.4Restrict Administrator Privileges to Dedicated Administrator AccountsIG1UsersProtect
5.5Establish and Maintain an Inventory of Service AccountsIG2UsersIdentify
5.6Centralize Account ManagementIG2UsersProtect
Security Engineer Takeaway: Account management is your identity security foundation. IG1 essentials: inventory all accounts, enforce unique passwords, disable dormant accounts, and separate admin privileges. IG2 adds service account tracking and centralized management (Active Directory, Azure AD, etc.). Maps to NIS2 Art. 21(2)(i)(j) and ISO 27001 A.5.15–A.5.18.

CIS Control 6 — Access Control Management

Use processes and tools to create, assign, manage, and revoke access credentials and privileges for user, administrator, and service accounts for enterprise assets and software.

Safeguards

IDSafeguardIGAsset TypeFunction
6.1Establish an Access Granting ProcessIG1UsersProtect
6.2Establish an Access Revoking ProcessIG1UsersProtect
6.3Require MFA for Externally-Exposed ApplicationsIG1UsersProtect
6.4Require MFA for Remote Network AccessIG1UsersProtect
6.5Require MFA for Administrative AccessIG1UsersProtect
6.6Establish and Maintain an Inventory of Authentication and Authorization SystemsIG2UsersIdentify
6.7Centralize Access ControlIG2UsersProtect
6.8Define and Maintain Role-Based Access ControlIG3UsersProtect
Security Engineer Takeaway: MFA is the single most impactful control you can deploy. CIS puts three MFA safeguards in IG1 — external apps, remote access, and admin access. This aligns directly with NIS2 Art. 21(2)(j) and is table-stakes for any security programme.

CIS Control 7 — Continuous Vulnerability Management

Develop a plan to continuously assess and track vulnerabilities on all enterprise assets within the enterprise's infrastructure, in order to remediate, and minimize, the window of opportunity for attackers.

Safeguards

IDSafeguardIGAsset TypeFunction
7.1Establish and Maintain a Vulnerability Management ProcessIG1ApplicationsProtect
7.2Establish and Maintain a Remediation ProcessIG1ApplicationsRespond
7.3Perform Automated Operating System Patch ManagementIG1ApplicationsProtect
7.4Perform Automated Application Patch ManagementIG1ApplicationsProtect
7.5Perform Automated Vulnerability Scans of Internal Enterprise AssetsIG2ApplicationsIdentify
7.6Perform Automated Vulnerability Scans of Externally-Exposed Enterprise AssetsIG2ApplicationsIdentify
7.7Remediate Detected VulnerabilitiesIG2ApplicationsRespond
Security Engineer Takeaway: Vulnerability management is a continuous cycle: discover, prioritize, remediate, verify. IG1 requires automated patching — start there. IG2 adds vulnerability scanning. Use risk-based prioritization (CVSS + asset criticality + exploitability) not just raw severity. Maps to NIS2 Art. 21(2)(e) and ISO 27001 A.8.8.

CIS Control 8 — Audit Log Management

Collect, alert, review, and retain audit logs of events that could help detect, understand, or recover from an attack.

Safeguards

IDSafeguardIGAsset TypeFunction
8.1Establish and Maintain an Audit Log Management ProcessIG1NetworkDetect
8.2Collect Audit LogsIG1NetworkDetect
8.3Ensure Adequate Audit Log StorageIG1NetworkDetect
8.4Standardize Time SynchronizationIG2NetworkDetect
8.5Collect Detailed Audit LogsIG2NetworkDetect
8.6Collect DNS Query Audit LogsIG2NetworkDetect
8.7Collect URL Request Audit LogsIG2NetworkDetect
8.8Collect Command-Line Audit LogsIG2NetworkDetect
8.9Centralize Audit LogsIG2NetworkDetect
8.10Retain Audit LogsIG2NetworkDetect
8.11Conduct Audit Log ReviewsIG2NetworkDetect
8.12Collect Service Provider LogsIG3DataDetect
Security Engineer Takeaway: Logging is detective control #1. IG1: establish a process, collect logs, ensure storage. IG2 is where it gets serious: centralized SIEM, DNS/URL/command-line logging, time sync, and regular reviews. This is your SOC foundation. Maps to ISO 27001 A.8.15–A.8.16 and DORA detection requirements.

CIS Control 9 — Email and Web Browser Protections

Improve protections and detections of threats from email and web vectors, as these are opportunities for attackers to manipulate human behavior through direct engagement.

Safeguards

IDSafeguardIGAsset TypeFunction
9.1Ensure Use of Only Fully Supported Browsers and Email ClientsIG1ApplicationsProtect
9.2Use DNS Filtering ServicesIG1NetworkProtect
9.3Maintain and Enforce Network-Based URL FiltersIG2NetworkProtect
9.4Restrict Unnecessary or Unauthorized Browser and Email Client ExtensionsIG2ApplicationsProtect
9.5Implement DMARCIG2NetworkProtect
9.6Block Unnecessary File TypesIG2NetworkProtect
9.7Deploy and Maintain Email Server Anti-Malware ProtectionsIG2NetworkProtect
Security Engineer Takeaway: Email and web are the top two attack vectors. IG1 basics: supported browsers, DNS filtering. IG2 adds URL filtering, extension control, DMARC, and email server protection. DMARC (9.5) alone prevents a huge percentage of phishing attacks.

CIS Control 10 — Malware Defenses

Prevent or control the installation, spread, and execution of malicious applications, code, or scripts on enterprise assets.

Safeguards

IDSafeguardIGAsset TypeFunction
10.1Deploy and Maintain Anti-Malware SoftwareIG1DevicesProtect
10.2Configure Automatic Anti-Malware Signature UpdatesIG1DevicesProtect
10.3Disable Autorun and Autoplay for Removable MediaIG1DevicesProtect
10.4Configure Automatic Anti-Malware Scanning of Removable MediaIG2DevicesDetect
10.5Enable Anti-Exploitation FeaturesIG2DevicesProtect
10.6Centrally Manage Anti-Malware SoftwareIG2DevicesProtect
10.7Use Behavior-Based Anti-Malware SoftwareIG2DevicesDetect
Security Engineer Takeaway: Modern endpoint protection goes far beyond signatures. IG1 covers AV deployment, auto-updates, and disabling autorun. IG2 adds EDR (behavior-based detection), centralized management, and anti-exploitation features. Maps to BSI OPS.1.1.4 and ISO 27001 A.8.7.

CIS Control 11 — Data Recovery

Establish and maintain data recovery practices sufficient to restore in-scope enterprise assets to a pre-incident and trusted state.

Safeguards

IDSafeguardIGAsset TypeFunction
11.1Establish and Maintain a Data Recovery ProcessIG1DataRecover
11.2Perform Automated BackupsIG1DataRecover
11.3Protect Recovery DataIG1DataProtect
11.4Establish and Maintain an Isolated Instance of Recovery DataIG1DataRecover
11.5Test Data RecoveryIG2DataRecover
Security Engineer Takeaway: Ransomware has made data recovery one of the most critical controls. All 4 IG1 safeguards are essential: process, automated backups, protection of backup data, and isolated (air-gapped) recovery instance. IG2 adds recovery testing. If you can't recover, you can't resist ransomware. Maps to NIS2 Art. 21(2)(c) and ISO 27001 A.8.13.

CIS Control 12 — Network Infrastructure Management

Establish and maintain the management and security of network infrastructure devices.

Safeguards

IDSafeguardIGAsset TypeFunction
12.1Ensure Network Infrastructure is Up-to-DateIG1NetworkProtect
12.2Establish and Maintain a Secure Network ArchitectureIG2NetworkProtect
12.3Securely Manage Network InfrastructureIG2NetworkProtect
12.4Establish and Maintain Architecture Diagram(s)IG2NetworkIdentify
12.5Centralize Network Authentication, Authorization, and Auditing (AAA)IG2NetworkProtect
12.6Use of Secure Network Management and Communication ProtocolsIG2NetworkProtect
12.7Ensure Remote Devices Utilize a VPN and are Connecting to an Enterprise's AAA InfrastructureIG2NetworkProtect
12.8Establish and Maintain Dedicated Computing Resources for All Administrative WorkIG3NetworkProtect
Security Engineer Takeaway: Network infrastructure is often the weakest link. IG1 starts simple: keep devices updated. IG2 builds your secure network architecture: segmentation, centralized AAA, architecture diagrams, secure protocols, and VPN. IG3 adds privileged access workstations (PAWs) for admin work.

CIS Control 13 — Network Monitoring and Defense

Operate processes and tooling to establish and maintain comprehensive network monitoring and defense against security threats across the enterprise's network infrastructure and user base.

Safeguards

IDSafeguardIGAsset TypeFunction
13.1Centralize Security Event AlertingIG2NetworkDetect
13.2Deploy a Host-Based Intrusion Detection SolutionIG2DevicesDetect
13.3Deploy a Network Intrusion Detection SolutionIG2NetworkDetect
13.4Perform Traffic Filtering Between Network SegmentsIG2NetworkProtect
13.5Manage Access Control for Remote AssetsIG2DevicesProtect
13.6Collect Network Traffic Flow LogsIG2NetworkDetect
13.7Deploy a Host-Based Intrusion Prevention SolutionIG3DevicesProtect
13.8Deploy a Network Intrusion Prevention SolutionIG3NetworkProtect
13.9Deploy Port-Level Access ControlIG3DevicesProtect
13.10Perform Application Layer FilteringIG3NetworkProtect
13.11Tune Security Event Alerting ThresholdsIG3NetworkDetect
Security Engineer Takeaway: Note that CIS 13 has zero IG1 safeguards — network monitoring and defense is an IG2+ capability. IG2 builds your detection stack: centralized alerting (SIEM), IDS (host and network), traffic filtering, and flow logs. IG3 adds IPS, 802.1X, application layer filtering, and alert tuning.

CIS Control 14 — Security Awareness and Skills Training

Establish and maintain a security awareness program to influence behavior among the workforce to be security conscious and properly skilled to reduce cybersecurity risks to the enterprise.

Safeguards

IDSafeguardIGAsset TypeFunction
14.1Establish and Maintain a Security Awareness ProgramIG1N/AProtect
14.2Train Workforce Members to Recognize Social Engineering AttacksIG1N/AProtect
14.3Train Workforce Members on Authentication Best PracticesIG1N/AProtect
14.4Train Workforce Members on Data Handling Best PracticesIG1N/AProtect
14.5Train Workforce Members on Causes of Unintentional Data ExposureIG1N/AProtect
14.6Train Workforce Members on Recognizing and Reporting Security IncidentsIG1N/AProtect
14.7Train Workforce on How to Identify and Report if Their Enterprise Assets are Missing Security UpdatesIG1N/AProtect
14.8Train Workforce on the Dangers of Connecting to and Transmitting Enterprise Data Over Insecure NetworksIG1N/AProtect
14.9Conduct Role-Specific Security Awareness and Skills TrainingIG2N/AProtect
Security Engineer Takeaway: All 8 IG1 training safeguards reflect how critical human factors are. Map directly to NIS2 Art. 21(2)(g) and ISO 27001 A.6.3. Run phishing simulations monthly, track metrics, and provide role-specific training for developers, admins, and executives.

CIS Control 15 — Service Provider Management

Develop a process to evaluate service providers who hold sensitive data, or are responsible for an enterprise's critical IT platforms or processes, to ensure these providers are protecting those platforms and data appropriately.

Safeguards

IDSafeguardIGAsset TypeFunction
15.1Establish and Maintain an Inventory of Service ProvidersIG1N/AIdentify
15.2Establish and Maintain a Service Provider Management PolicyIG2N/AIdentify
15.3Classify Service ProvidersIG2N/AIdentify
15.4Ensure Service Provider Contracts Include Security RequirementsIG2DataProtect
15.5Assess Service ProvidersIG3N/AIdentify
15.6Monitor Service ProvidersIG3N/ADetect
15.7Securely Decommission Service ProvidersIG3N/AProtect
Security Engineer Takeaway: Service provider management maps directly to NIS2 Art. 21(2)(d) supply chain security and DORA's ICT third-party risk management. IG1 starts with inventory. IG2 adds policy, classification, and contract requirements. IG3 adds assessment, monitoring, and decommissioning.

CIS Control 16 — Application Software Security

Manage the security life cycle of in-house developed, hosted, or acquired software to prevent, detect, and remediate security weaknesses before they can impact the enterprise.

Safeguards

IDSafeguardIGAsset TypeFunction
16.1Establish and Maintain a Secure Application Development ProcessIG2ApplicationsProtect
16.2Establish and Maintain a Process to Accept and Address Software VulnerabilitiesIG2ApplicationsProtect
16.3Perform Root Cause Analysis on Security VulnerabilitiesIG2ApplicationsProtect
16.4Establish and Manage an Inventory of Third-Party Software ComponentsIG2ApplicationsProtect
16.5Use Up-to-Date and Trusted Third-Party Software ComponentsIG2ApplicationsProtect
16.6Establish and Maintain a Severity Rating System and Process for Application VulnerabilitiesIG2ApplicationsProtect
16.7Use Standard Hardening Configuration Templates for Application InfrastructureIG2ApplicationsProtect
16.8Separate Production and Non-Production SystemsIG2ApplicationsProtect
16.9Train Developers in Application Security Concepts and Secure CodingIG2N/AProtect
16.10Apply Secure Design Principles in Application ArchitecturesIG2ApplicationsProtect
16.11Leverage Vetted Modules or Services for Application Security ComponentsIG2ApplicationsProtect
16.12Implement Code-Level Security ChecksIG3ApplicationsProtect
16.13Conduct Application Penetration TestingIG3ApplicationsProtect
16.14Conduct Threat ModelingIG3ApplicationsProtect
Security Engineer Takeaway: Application security is entirely IG2+. CIS 16 covers the full SDLC: secure development processes, SBOM management (16.4), developer training, secure design, hardened infrastructure, and production/non-production separation. IG3 adds SAST/DAST (16.12), app pen testing, and threat modeling.

CIS Control 17 — Incident Response Management

Establish a program to develop and maintain an incident response capability (e.g., policies, plans, procedures, defined roles, training, and communications) to prepare, detect, and quickly respond to an attack.

Safeguards

IDSafeguardIGAsset TypeFunction
17.1Designate Personnel to Manage Incident HandlingIG1N/ARespond
17.2Establish and Maintain Contact Information for Reporting Security IncidentsIG1N/ARespond
17.3Establish and Maintain an Enterprise Process for Reporting IncidentsIG1N/ARespond
17.4Establish and Maintain an Incident Response ProcessIG2N/ARespond
17.5Assign Key Roles and ResponsibilitiesIG2N/ARespond
17.6Define Mechanisms for Communicating During Incident ResponseIG2N/ARespond
17.7Conduct Routine Incident Response ExercisesIG2N/ARespond
17.8Conduct Post-Incident ReviewsIG2N/ARespond
17.9Establish and Maintain Security Incident ThresholdsIG3N/ARespond
Security Engineer Takeaway: IG1 gets you started with designated personnel, contact info, and a reporting process. IG2 builds a mature IR capability: formal process, RACI, communication plans, tabletop exercises, and post-incident reviews. Maps to NIS2 Art. 21(2)(b) and Art. 23.

CIS Control 18 — Penetration Testing

Test the effectiveness and resiliency of enterprise assets through identifying and exploiting weaknesses in controls (people, processes, and technology), and simulating the objectives and actions of an attacker.

Safeguards

IDSafeguardIGAsset TypeFunction
18.1Establish and Maintain a Penetration Testing ProgramIG2N/AIdentify
18.2Perform Periodic External Penetration TestsIG2NetworkIdentify
18.3Remediate Penetration Test FindingsIG2NetworkRespond
18.4Validate Security MeasuresIG3NetworkIdentify
18.5Perform Periodic Internal Penetration TestsIG3NetworkIdentify
Security Engineer Takeaway: Penetration testing validates all your other controls. IG2 requires external pen tests; IG3 adds internal testing and security measure validation. Maps to DORA TLPT requirements and NIS2 Art. 21(2)(f) effectiveness assessment.

Safeguard Explorer

All 18 CIS Controls with their 153 Safeguards. Click to expand details, safeguard lists, and practical security notes.

Basic Hygiene — Controls 1–6

CIS 1 Inventory and Control of Enterprise Assets Critical ▶

Actively manage all enterprise assets connected to the infrastructure to accurately know what needs to be monitored and protected. 5 Safeguards (2 IG1, 2 IG2, 1 IG3).

Safeguards

  • 1.1 (IG1): Establish and Maintain Detailed Enterprise Asset Inventory
  • 1.2 (IG1): Address Unauthorized Assets
  • 1.3 (IG2): Utilize an Active Discovery Tool
  • 1.4 (IG2): Use DHCP Logging to Update Asset Inventory
  • 1.5 (IG3): Use a Passive Asset Discovery Tool
Security Engineer Takeaway: Asset inventory is the foundation. You can't protect what you don't know about. Start with a spreadsheet if needed, automate with discovery tools at IG2.
CIS 2 Inventory and Control of Software Assets Critical ▶

Actively manage all software on the network so that only authorized software is installed and can execute. 7 Safeguards (3 IG1, 3 IG2, 1 IG3).

Safeguards

  • 2.1 (IG1): Establish and Maintain a Software Inventory
  • 2.2 (IG1): Ensure Authorized Software is Currently Supported
  • 2.3 (IG1): Address Unauthorized Software
  • 2.4 (IG2): Utilize Automated Software Inventory Tools
  • 2.5 (IG2): Allowlist Authorized Software
  • 2.6 (IG2): Allowlist Authorized Libraries
  • 2.7 (IG3): Allowlist Authorized Scripts
Security Engineer Takeaway: Application allowlisting (2.5) is one of the most effective controls against malware and unauthorized software execution.
CIS 3 Data Protection Critical ▶

Develop processes and technical controls to identify, classify, securely handle, retain, and dispose of data. 14 Safeguards (6 IG1, 6 IG2, 2 IG3).

Key Safeguards

  • IG1: Data management process, data inventory, access control lists, data retention, secure disposal, endpoint encryption
  • IG2: Data classification, data flow documentation, removable media encryption, transit encryption, at-rest encryption, sensitivity segmentation
  • IG3: DLP solution, sensitive data access logging
Security Engineer Takeaway: CIS 3 has 14 safeguards — the most of any control. Data protection spans from basic (know your data, control access) to advanced (DLP, segmentation). Start with endpoint encryption and access controls.
CIS 4 Secure Configuration of Enterprise Assets and Software Critical ▶

Establish and maintain secure configuration of enterprise assets and software. 12 Safeguards (7 IG1, 5 IG2, 0 IG3).

Key Safeguards

  • IG1: Secure configuration processes, network infrastructure configuration, session locking, server firewalls, endpoint firewalls, secure asset management, default account management
  • IG2: Disable unnecessary services, trusted DNS, device lockout, remote wipe
  • IG3: Separate enterprise workspaces on mobile devices
Security Engineer Takeaway: Use CIS Benchmarks for the specific hardening guidance. CIS 4 has the most IG1 safeguards (7) after CIS 14 (8), showing how important secure configuration is as a baseline.
CIS 5 Account Management Critical ▶

Use processes and tools to assign and manage authorization to credentials for user accounts, including administrator and service accounts. 6 Safeguards (4 IG1, 2 IG2).

Key Safeguards

  • IG1: Account inventory, unique passwords, disable dormant accounts, dedicated admin accounts
  • IG2: Service account inventory, centralized account management
Security Engineer Takeaway: Dedicated admin accounts (5.4) is critical — never use your daily account for administrative tasks. Dormant accounts are a top attack vector.
CIS 6 Access Control Management Critical ▶

Use processes and tools to create, assign, manage, and revoke access credentials and privileges. 8 Safeguards (5 IG1, 2 IG2, 1 IG3).

Key Safeguards

  • IG1: Access granting process, access revoking process, MFA for external apps, MFA for remote access, MFA for admin access
  • IG2: Auth/authz inventory, centralized access control
  • IG3: Role-based access control (RBAC)
Security Engineer Takeaway: Three MFA safeguards in IG1 — this is the single most impactful control family for preventing account compromise. Start here if you're doing nothing else.

Foundational — Controls 7–12

CIS 7 Continuous Vulnerability Management Critical ▶

Develop a plan to continuously assess and track vulnerabilities on all enterprise assets. 7 Safeguards (4 IG1, 3 IG2).

Key Safeguards

  • IG1: Vulnerability management process, remediation process, automated OS patching, automated application patching
  • IG2: Internal vulnerability scanning, external vulnerability scanning, remediate detected vulnerabilities
Security Engineer Takeaway: Automated patching (7.3, 7.4) is IG1 because unpatched systems are the #1 exploited vector. Vulnerability scanning (IG2) tells you what patching missed.
CIS 8 Audit Log Management Critical ▶

Collect, alert, review, and retain audit logs of events that could help detect, understand, or recover from an attack. 12 Safeguards (3 IG1, 8 IG2, 1 IG3).

Key Safeguards

  • IG1: Audit log management process, collect audit logs, ensure adequate storage
  • IG2: Time synchronization, detailed logs, DNS/URL/command-line logging, centralize logs, retention, reviews
  • IG3: Collect service provider logs
Security Engineer Takeaway: IG2 logging is your SIEM foundation. DNS query logs (8.6) and command-line logs (8.8) are incredibly high-value for threat detection.
CIS 9 Email and Web Browser Protections Important ▶

Improve protections and detections of threats from email and web vectors. 7 Safeguards (2 IG1, 5 IG2).

Key Safeguards

  • IG1: Supported browsers/clients, DNS filtering
  • IG2: URL filters, extension control, DMARC, file type blocking, email anti-malware
Security Engineer Takeaway: DMARC (9.5) is one of the highest-ROI controls — prevents domain spoofing at no cost. DNS filtering (9.2) blocks known malicious domains at the network level.
CIS 10 Malware Defenses Critical ▶

Prevent or control the installation, spread, and execution of malicious applications. 7 Safeguards (3 IG1, 4 IG2).

Key Safeguards

  • IG1: Anti-malware deployment, auto-signature updates, disable autorun/autoplay
  • IG2: Removable media scanning, anti-exploitation, centralized management, behavior-based detection
Security Engineer Takeaway: Behavior-based detection (10.7) = EDR. If you're still on signature-only AV, upgrading to EDR is one of the most impactful IG2 investments.
CIS 11 Data Recovery Critical ▶

Establish and maintain data recovery practices sufficient to restore in-scope enterprise assets. 5 Safeguards (4 IG1, 1 IG2).

Key Safeguards

  • IG1: Recovery process, automated backups, protect recovery data, isolated recovery instance
  • IG2: Test data recovery
Security Engineer Takeaway: 4 of 5 safeguards are IG1 — recovery is essential. The isolated instance (11.4) is your ransomware insurance. Test your recovery (11.5) before you need it.
CIS 12 Network Infrastructure Management Important ▶

Establish and maintain the management and security of network infrastructure devices. 8 Safeguards (1 IG1, 6 IG2, 1 IG3).

Key Safeguards

  • IG1: Keep network infrastructure up-to-date
  • IG2: Secure architecture, secure management, architecture diagrams, centralized AAA, secure protocols, VPN
  • IG3: Dedicated admin computing resources (PAW)
Security Engineer Takeaway: Architecture diagrams (12.4) sound basic but are essential for incident response and risk assessment. Centralized AAA (12.5) prevents credential sprawl on network devices.

Organizational — Controls 13–18

CIS 13 Network Monitoring and Defense Important ▶

Operate processes and tooling to establish and maintain comprehensive network monitoring and defense. 11 Safeguards (0 IG1, 6 IG2, 5 IG3).

Key Safeguards

  • IG2: Centralized alerting, HIDS, NIDS, traffic filtering, remote asset access control, network flow logs
  • IG3: HIPS, NIPS, port-level access control, application layer filtering, alert threshold tuning
Security Engineer Takeaway: Zero IG1 safeguards — network monitoring requires organizational maturity. This is where your SOC investment lives. Start with centralized alerting (13.1) and NIDS (13.3).
CIS 14 Security Awareness and Skills Training Critical ▶

Establish and maintain a security awareness program to influence workforce behavior. 9 Safeguards (8 IG1, 1 IG2).

Key Safeguards

  • IG1: Awareness program, social engineering recognition, authentication best practices, data handling, unintentional data exposure, incident recognition/reporting, missing security updates, insecure networks
  • IG2: Role-specific training
Security Engineer Takeaway: 8 of 9 safeguards are IG1 — the most for any control. Humans are both the weakest link and the strongest defense when properly trained. Monthly phishing simulations, track click rates, reward reporters.
CIS 15 Service Provider Management Important ▶

Develop a process to evaluate service providers who hold sensitive data or are responsible for critical IT platforms. 7 Safeguards (1 IG1, 3 IG2, 3 IG3).

Key Safeguards

  • IG1: Service provider inventory
  • IG2: Management policy, classification, contractual security requirements
  • IG3: Assessment, monitoring, secure decommissioning
Security Engineer Takeaway: Start with knowing who your service providers are (15.1 is IG1). Maps to DORA ICT third-party risk and NIS2 supply chain requirements.
CIS 16 Application Software Security Important ▶

Manage the security life cycle of in-house developed, hosted, or acquired software. 14 Safeguards (0 IG1, 11 IG2, 3 IG3).

Key Safeguards

  • IG2: Secure development process, vulnerability acceptance, root cause analysis, third-party component inventory (SBOM), trusted components, severity rating, hardening templates, prod/non-prod separation, developer training, secure design, vetted modules
  • IG3: Code-level security checks (SAST/DAST), application pen testing, threat modeling
Security Engineer Takeaway: Zero IG1 safeguards — AppSec requires development maturity. SBOM (16.4) and third-party component management (16.5) are increasingly critical for supply chain security.
CIS 17 Incident Response Management Critical ▶

Establish a program to develop and maintain an incident response capability. 9 Safeguards (3 IG1, 5 IG2, 1 IG3).

Key Safeguards

  • IG1: Designated IR personnel, contact information for reporting, enterprise reporting process
  • IG2: Formal IR process, roles/responsibilities, communication mechanisms, routine exercises, post-incident reviews
  • IG3: Security incident thresholds
Security Engineer Takeaway: IG1 gets you the basics: know who handles incidents and how to report them. IG2 builds maturity with exercises and post-incident reviews. Maps directly to NIS2 reporting requirements.
CIS 18 Penetration Testing Important ▶

Test the effectiveness and resiliency of enterprise assets through identifying and exploiting weaknesses. 5 Safeguards (0 IG1, 3 IG2, 2 IG3).

Key Safeguards

  • IG2: Pen testing program, external pen tests, remediate findings
  • IG3: Validate security measures, internal pen tests
Security Engineer Takeaway: Pen testing is the ultimate validation of all other controls. External first (IG2), then internal (IG3). Maps to DORA TLPT for financial services.

Implementation Groups (IGs)

CIS Controls use Implementation Groups to prioritize safeguards based on organizational profile. Each IG builds on the previous one, creating a cumulative model — IG2 includes all IG1 safeguards plus additional ones, and IG3 includes everything.

The Three Implementation Groups

IG1 — Essential Cyber Hygiene (56 Safeguards)

Every organization regardless of size
  • Minimum standard of information security for all enterprises
  • Defends against the most common non-targeted attacks
  • Limited cybersecurity expertise assumed
  • Focus: basic asset inventory, data protection, access control, patching, backups, awareness training, incident response
  • Research shows IG1 defends against 80%+ of common attack techniques

IG2 — Enterprise (130 Safeguards = IG1 + 74)

Organizations with moderate cybersecurity resources
  • Managing enterprise-grade environments with sensitive data
  • More complex operating environment
  • Dedicated security team or staff with cybersecurity responsibility
  • Focus: vulnerability scanning, SIEM, network monitoring, penetration testing, secure SDLC, service provider management, formal incident response

IG3 — Mature Security (153 Safeguards = IG2 + 23)

Organizations with significant cybersecurity expertise
  • Handling highly sensitive data or critical infrastructure
  • Advanced adversaries in threat model
  • Dedicated security team with specialized expertise
  • Focus: advanced monitoring, application security testing, threat modeling, host/network intrusion prevention, RBAC, security measure validation

IG Coverage by Control

ControlControl NameIG1IG2 AdditionalIG3 AdditionalTotal
CIS 1Enterprise Asset Inventory2215
CIS 2Software Asset Inventory3317
CIS 3Data Protection66214
CIS 4Secure Configuration75012
CIS 5Account Management4206
CIS 6Access Control Management5218
CIS 7Vulnerability Management4307
CIS 8Audit Log Management38112
CIS 9Email & Web Protections2507
CIS 10Malware Defenses3407
CIS 11Data Recovery4105
CIS 12Network Infrastructure1618
CIS 13Network Monitoring06511
CIS 14Security Awareness8109
CIS 15Service Provider Mgmt1337
CIS 16Application Security011314
CIS 17Incident Response3519
CIS 18Penetration Testing0325
Total567423153
Key Insight: Controls with zero IG1 safeguards (CIS 13 Network Monitoring, CIS 16 Application Security, CIS 18 Penetration Testing) require organizational maturity and dedicated security staff. Controls with the most IG1 safeguards (CIS 14: 8 safeguards, CIS 4: 7 safeguards, CIS 3: 6 safeguards) represent the most critical baseline activities.

Key Dates & Timeline

Evolution of the CIS Critical Security Controls from SANS Top 20 to CIS Controls v8.1.

2008
SANS Top 20 Critical Security Controls
First publication of the Critical Security Controls, then known as the SANS Top 20. Originally developed in response to massive data losses at the US defense industrial base.
2013
Version 5.0 — Center for Internet Security
Stewardship of the Controls transferred to the Center for Internet Security (CIS). Version 5.0 released under CIS governance with community-driven development model.
2015
CIS Controls v6
Major revision with restructured controls and sub-controls. Continued refinement of prioritization and community input.
2018
CIS Controls v7.0
Introduced Implementation Groups (IG1, IG2, IG3) for the first time. 20 Controls with 171 Sub-Controls. Added cloud, mobile, and outsourcing considerations.
2019
CIS Controls v7.1
Minor updates and clarifications to v7.0. Refined Implementation Group assignments. Improved clarity of sub-control descriptions.
May 2021
CIS Controls v8 Released
Major overhaul: consolidated from 20 to 18 Controls, renamed "Sub-Controls" to "Safeguards," and reorganized to be technology-agnostic. Designed for cloud-first, mobile, work-from-anywhere environments.
June 2023
CIS Controls v8.1 Released
Current version. 153 Safeguards with minor refinements. Added asset type and security function classifications to every safeguard. Improved IG assignments and clarified safeguard descriptions.
Ongoing
CIS Benchmarks & Community Maintenance
CIS continuously maintains CIS Benchmarks for platform-specific guidance, the Community Defense Model (CDM) for attack data analysis, and mapping documents to other frameworks.

Compliance Checklist

Track your CIS Controls implementation progress. Checkmarks are saved locally in your browser.

IG1 — Essential Cyber Hygiene

  • Enterprise asset inventory established and maintained (CIS 1.1)
  • Unauthorized assets identified and addressed (CIS 1.2)
  • Software inventory established and maintained (CIS 2.1–2.3)
  • Data management process and inventory established (CIS 3.1–3.2)
  • Data access control lists configured (CIS 3.3)
  • Data on end-user devices encrypted (CIS 3.6)
  • Secure configuration processes for assets and network infrastructure (CIS 4.1–4.2)
  • Host-based firewalls on servers and endpoints (CIS 4.4–4.5)
  • Default accounts managed (CIS 4.7)
  • Account inventory maintained, unique passwords, dormant accounts disabled (CIS 5.1–5.3)
  • Admin privileges restricted to dedicated accounts (CIS 5.4)
  • Access granting and revoking processes established (CIS 6.1–6.2)
  • MFA deployed for external apps, remote access, and admin access (CIS 6.3–6.5)
  • Vulnerability management and patch management processes operational (CIS 7.1–7.4)
  • Audit log collection and storage established (CIS 8.1–8.3)
  • Supported browsers and DNS filtering deployed (CIS 9.1–9.2)
  • Anti-malware deployed with auto-updates (CIS 10.1–10.3)
  • Automated backups with isolated recovery instance (CIS 11.1–11.4)
  • Network infrastructure up-to-date (CIS 12.1)
  • Security awareness programme with phishing training active (CIS 14.1–14.8)
  • Service provider inventory maintained (CIS 15.1)
  • Incident response personnel designated and reporting process established (CIS 17.1–17.3)

IG2 — Enterprise Additions

  • Active asset discovery tools deployed (CIS 1.3–1.4)
  • Application allowlisting implemented (CIS 2.5–2.6)
  • Data classification and DLP strategy in place (CIS 3.7–3.12)
  • SIEM deployed with centralized log management (CIS 8.9–8.11)
  • Network intrusion detection deployed (CIS 13.1–13.6)
  • Secure SDLC and application security programme (CIS 16.1–16.11)
  • Formal incident response process with exercises (CIS 17.4–17.8)
  • External penetration testing programme (CIS 18.1–18.3)

Who Uses CIS Controls

CIS Controls are used globally by organizations of all sizes and sectors. Their free, prioritized nature makes them the most widely adopted cybersecurity framework in the world.

Regulatory Alignment

FrameworkCIS Controls MappingNotes
NIST CSF 2.0Official CIS-published mappingSafeguards map to CSF categories
ISO 27001Community mapping availableGood coverage of Annex A controls
NIS2 Art. 21Maps to all 10 measuresIG2 provides strong NIS2 coverage
DORAAligns with ICT risk managementSupplements DORA implementation
PCI DSS 4.0CIS-published mappingPayment card security
HIPAACIS-published mappingHealthcare security
CMMCCIS-published mappingUS defense supply chain
NIST 800-53CIS-published mappingUS federal controls

Common Adoption

Organization TypeRecommended IGNotes
Small/Medium BusinessIG1Essential cyber hygiene — 56 safeguards
Mid-size EnterpriseIG2Handles sensitive data with moderate security team
Large EnterpriseIG2–IG3Complex environment, dedicated security team
Critical InfrastructureIG3High-value targets, advanced adversaries
HealthcareIG2+HIPAA alignment, patient data protection
Financial ServicesIG2–IG3DORA/regulatory requirements
GovernmentIG2–IG3CMMC, NIST 800-53 alignment
Note: CIS Controls are framework-agnostic and supplement (not replace) regulatory requirements. Organizations subject to DORA, NIS2, or ISO 27001 can use CIS Controls as a prioritized implementation guide, leveraging the official mapping documents to demonstrate coverage.

CIS Controls Mappings & Benchmarks

Official mappings, benchmarks, and guidance documents that connect CIS Controls to other frameworks and provide platform-specific implementation guidance.

Official CIS Mappings

CIS Controls to NIST CSF 2.0

Official CIS Mapping
  • Maps all 153 safeguards to NIST CSF 2.0 categories and subcategories
  • Enables bi-directional crosswalk between frameworks
  • Available free on the CIS website

CIS Controls to NIST 800-53 Rev. 5

Official CIS Mapping
  • Detailed mapping to NIST SP 800-53 controls
  • Essential for US federal and defense compliance
  • Supports CMMC alignment

CIS Controls to ISO 27001

Community Mapping
  • Maps safeguards to ISO 27001:2022 Annex A controls
  • Demonstrates coverage for certification
  • Useful for gap analysis

CIS Controls to PCI DSS 4.0

Official CIS Mapping
  • Payment Card Industry Data Security Standard alignment
  • Supports PCI DSS compliance efforts
  • Covers all 12 PCI DSS requirements

CIS Controls to MITRE ATT&CK

Official CIS Mapping
  • Maps safeguards to MITRE ATT&CK techniques
  • Shows which attack techniques each safeguard mitigates
  • Foundation of the Community Defense Model (CDM)

CIS Benchmarks

CIS Benchmarks are prescriptive configuration guides for specific platforms. They are the "how-to" that complements the "what-to" of CIS Controls.

Operating Systems

Windows, Linux, macOS
  • Windows Server 2022 / Windows 11
  • Ubuntu Linux / Red Hat Enterprise Linux / SUSE
  • macOS Ventura / Sonoma
  • Detailed hardening settings with rationale

Cloud Providers

AWS, Azure, GCP
  • AWS Foundations Benchmark
  • Microsoft Azure Foundations Benchmark
  • Google Cloud Platform Benchmark
  • Oracle Cloud Infrastructure Benchmark

Containers & Orchestration

Docker, Kubernetes
  • Docker Benchmark
  • Kubernetes Benchmark
  • Amazon EKS / Azure AKS / GKE Benchmarks

Network, Database & Web

Various platforms
  • Cisco IOS / Palo Alto / Juniper
  • Microsoft SQL Server / Oracle / PostgreSQL / MySQL
  • Apache / Nginx / IIS
  • Microsoft 365 / Google Workspace

Adoption & Business Benefits

Why implementing CIS Controls delivers measurable value beyond security improvements.

IG1 Stops 80%+ of Attacks

CIS Community Defense Model Research
  • Research shows IG1 safeguards defend against the most common attack techniques
  • 56 safeguards provide disproportionate security improvement
  • Start here for maximum impact with minimum investment
  • Based on real-world attack data mapped to MITRE ATT&CK

Free and Open

No barriers to entry
  • CIS Controls are free to download and use
  • No licensing fees, no vendor lock-in
  • CIS Benchmarks are free for non-commercial use
  • Community-developed by practitioners for practitioners

Cyber Insurance

Improve insurability and reduce premiums
  • Many cyber insurance providers reference CIS Controls (especially IG1) as minimum security expectations
  • Implementing CIS Controls can improve insurability
  • Documented CIS Controls implementation supports claims defense
  • MFA (CIS 6.3-6.5) is now a standard insurance requirement

Supply Chain Trust

Build customer and partner confidence
  • Demonstrating CIS Controls implementation builds trust
  • CSAT (CIS Controls Self Assessment Tool) provides structured assessment
  • Many enterprises require CIS Controls compliance from suppliers
  • CIS SecureSuite membership provides additional assessment tools

Regulatory Efficiency

One implementation, multiple frameworks
  • CIS Controls map officially to NIST CSF, ISO 27001, PCI DSS, HIPAA, CMMC, and more
  • Implementing CIS Controls builds compliance with multiple frameworks simultaneously
  • Reduces audit fatigue through reusable evidence
  • Official mapping documents available free from CIS

External Resources & References

Curated links to official documents, tools, and community resources. All links open in a new tab.

Official

Official

CIS Controls v8.1

The official CIS Controls v8.1 documentation. Free to download. The authoritative source for all 18 Controls and 153 Safeguards.

Primary Source
Official

CIS Controls Navigator

Interactive tool to explore CIS Controls, filter by IG, and view mappings to other frameworks. Essential for gap analysis.

Interactive Tool
Official

CIS Benchmarks

Platform-specific hardening guides for 100+ technologies. Free for non-commercial use. The "how-to" for CIS Control 4 (Secure Configuration).

Benchmarks

Authority & Guidance

Guidance

CIS Controls Implementation Guide

Detailed guidance on implementing CIS Controls by Implementation Group. Practical steps for each safeguard.

Implementation
Guidance

CIS Controls Mobile Companion Guide

Guidance for applying CIS Controls to mobile device environments. Extends Controls to iOS and Android management.

Mobile
Guidance

CIS Community Defense Model (CDM)

Data-driven analysis showing which CIS Safeguards defend against which MITRE ATT&CK techniques. Proves IG1 stops 80%+ of common attacks.

Research ATT&CK

Tools

Tool

CIS-CAT Pro

Automated assessment tool that scans systems against CIS Benchmarks. Provides compliance scores and remediation guidance.

Assessment
Tool

CIS CSAT

Free self-assessment tool for evaluating your implementation of CIS Controls. Tracks progress across all 18 Controls and 3 IGs.

Self-Assessment
Tool

CIS Hardened Images

Pre-hardened virtual machine images available in AWS, Azure, GCP, and Oracle Cloud marketplaces. CIS Benchmark configurations applied out of the box.

Cloud Hardening
Tool

OpenCRE — Common Requirements Enumeration

Map CIS Controls to other standards (ISO 27001, NIST, NIS2, DORA). Excellent crosswalk tool for multi-framework compliance.

Mapping

Community

Community

CIS WorkBench

Community platform for contributing to CIS Benchmarks and Controls development. Join working groups and review drafts.

Contribute
Community

MS-ISAC / EI-ISAC

Multi-State and Elections Infrastructure Information Sharing and Analysis Centers. Threat intelligence and support for state, local, tribal, and territorial governments.

Government ISAC
Community

MITRE ATT&CK Framework

The knowledge base of adversary tactics and techniques that CIS Controls are mapped against. Essential for understanding what your controls defend against.

ATT&CK Threat Intel
Tip: CIS Controls v8.1 is the current version. Always reference the latest version from cisecurity.org. The CIS Controls Navigator is the best starting point for mapping to your existing framework requirements.

Title