The CIS Critical Security Controls (CIS Controls) v8.1 are a prioritized, prescriptive set of cybersecurity best practices developed by the Center for Internet Security (CIS) community. The 18 Controls contain 153 Safeguards organized into three Implementation Groups (IGs) based on organizational maturity and risk profile. CIS Controls are free, community-driven, and designed to be actionable — telling you exactly what to do and in what order. They are the most widely used prioritized cybersecurity framework globally and map to virtually every regulatory requirement.
18
Controls
153
Safeguards
3
Implementation Groups
2023
Version 8.1
The 18 CIS Controls
CIS Controls are organized into 18 domains covering the full spectrum of cybersecurity. They progress from foundational asset management to advanced penetration testing.
💻
Asset Management (CIS 1-2)
Inventory and Control of Enterprise Assets; Inventory and Control of Software Assets. You can't protect what you don't know about.
Controls 1–2
🔒
Data & Configuration (CIS 3-4)
Data Protection; Secure Configuration of Enterprise Assets and Software. Protect sensitive data and harden your systems.
Controls 3–4
👤
Account & Access (CIS 5-6)
Account Management; Access Control Management. Control who has access to what with MFA and least privilege.
Controls 5–6
🔧
Vulnerability & Malware (CIS 7-10)
Continuous Vulnerability Management; Audit Log Management; Email and Web Browser Protections; Malware Defenses.
Controls 7–10
📦
Recovery & Network (CIS 11-12)
Data Recovery; Network Infrastructure Management. Ensure you can bounce back and your network is secure.
Controls 11–12
👥
People & Response (CIS 13-18)
Network Monitoring and Defense; Security Awareness; Service Provider Management; Application Security; Incident Response; Penetration Testing.
Controls 13–18
Why Should a Security Engineer Care?
Prioritized and Prescriptive
Unlike outcome-based frameworks (NIST CSF) or management systems (ISO 27001), CIS Controls tell you exactly what to implement and in what order. Start with IG1 — 56 safeguards that stop 80%+ of attacks.
Implementation Groups
The IG model is brilliant for resource allocation. IG1 = essential hygiene (any org), IG2 = enterprise standard (sensitive data), IG3 = mature security (regulated/targeted). You always know what's next.
Community-Driven & Free
Developed by practitioners for practitioners. The CIS Controls are free to download and use. The CIS Benchmarks provide specific implementation guidance for every major platform.
Maps to Everything
CIS Controls map to NIST CSF, ISO 27001, NIST 800-53, PCI DSS, HIPAA, NIS2, and more. Implementing CIS Controls builds compliance with multiple frameworks simultaneously.
CIS Controls vs. Frameworks You Already Know
Aspect
CIS Controls v8.1
NIST CSF 2.0
ISO 27001
BSI IT-Grundschutz
Type
Community best practices
Voluntary framework
International standard
National methodology
Approach
Prioritized, prescriptive
Outcome-based
Risk-based management system
Prescriptive compendium
Structure
18 Controls, 153 Safeguards, 3 IGs
6 Functions, 22 Categories
93 Annex A controls, 4 themes
10 Layers, ~100 modules
Cost
Free
Free
Paid standard (~$150)
Free (compendium)
Certification
CIS CSAT (self-assessment)
No
Yes (accredited audit)
Yes (BSI certification)
Best For
Actionable prioritized security improvements
Risk management taxonomy
Formal certification
DACH region, detailed guidance
The 18 CIS Controls — Deep Dive
Select a control group from the sidebar or filter below to focus on a specific domain.
CIS Control 1 — Inventory and Control of Enterprise Assets
Actively manage (inventory, track, and correct) all enterprise assets (end-user devices, including portable and mobile; network devices; non-computing/IoT devices; and servers) connected to the infrastructure, physically, virtually, remotely, and those within cloud environments, to accurately know the totality of assets that need to be monitored and protected.
Safeguards
Click any row for detailed context and implementation guidance.
ID
Safeguard
IG
Asset Type
Function
1.1
Establish and Maintain Detailed Enterprise Asset Inventory
IG1
Devices
Identify
1.2
Address Unauthorized Assets
IG1
Devices
Respond
1.3
Utilize an Active Discovery Tool
IG2
Devices
Detect
1.4
Use Dynamic Host Configuration Protocol (DHCP) Logging to Update Asset Inventory
IG2
Devices
Identify
1.5
Use a Passive Asset Discovery Tool
IG3
Devices
Detect
Security Engineer Takeaway: CIS Control 1 is intentionally first — asset inventory is the foundation of all security. You can't protect what you don't know about. Start with IG1: maintain a detailed inventory and address unauthorized assets. IG2 adds active discovery tools. IG3 adds passive discovery for complete visibility. Map to NIS2 Art. 21(2)(i) asset management and ISO 27001 A.5.9.
CIS Control 2 — Inventory and Control of Software Assets
Actively manage (inventory, track, and correct) all software (operating systems and applications) on the network so that only authorized software is installed and can execute, and that unauthorized and unmanaged software is found and prevented from installation or execution.
Safeguards
ID
Safeguard
IG
Asset Type
Function
2.1
Establish and Maintain a Software Inventory
IG1
Applications
Identify
2.2
Ensure Authorized Software is Currently Supported
IG1
Applications
Identify
2.3
Address Unauthorized Software
IG1
Applications
Respond
2.4
Utilize Automated Software Inventory Tools
IG2
Applications
Identify
2.5
Allowlist Authorized Software
IG2
Applications
Protect
2.6
Allowlist Authorized Libraries
IG2
Applications
Protect
2.7
Allowlist Authorized Scripts
IG3
Applications
Protect
Security Engineer Takeaway: Software inventory prevents shadow IT and unsupported application risks. IG1 focuses on knowing what you have and ensuring it's supported. IG2 adds automation and application allowlisting — one of the most effective controls against malware. Maps to BSI OPS.1.1.1 and ISO 27001 A.5.9.
CIS Control 3 — Data Protection
Develop processes and technical controls to identify, classify, securely handle, retain, and dispose of data.
Safeguards
ID
Safeguard
IG
Asset Type
Function
3.1
Establish and Maintain a Data Management Process
IG1
Data
Identify
3.2
Establish and Maintain a Data Inventory
IG1
Data
Identify
3.3
Configure Data Access Control Lists
IG1
Data
Protect
3.4
Enforce Data Retention
IG1
Data
Protect
3.5
Securely Dispose of Data
IG1
Data
Protect
3.6
Encrypt Data on End-User Devices
IG1
Data
Protect
3.7
Establish and Maintain a Data Classification Scheme
IG2
Data
Identify
3.8
Document Data Flows
IG2
Data
Identify
3.9
Encrypt Data on Removable Media
IG2
Data
Protect
3.10
Encrypt Sensitive Data in Transit
IG2
Data
Protect
3.11
Encrypt Sensitive Data at Rest
IG2
Data
Protect
3.12
Segment Data Processing and Storage Based on Sensitivity
IG2
Data
Protect
3.13
Deploy a Data Loss Prevention Solution
IG3
Data
Protect
3.14
Log Sensitive Data Access
IG3
Data
Detect
Security Engineer Takeaway: Data protection is where CIS Controls shine — from basic (data inventory, access controls, encryption on endpoints) to advanced (DLP, data flow documentation, sensitivity-based segmentation). Maps directly to ISO 27001 A.8.10–A.8.12 and NIS2 Art. 21(2)(h).
CIS Control 4 — Secure Configuration of Enterprise Assets and Software
Establish and maintain the secure configuration of enterprise assets (end-user devices, including portable and mobile; network devices; non-computing/IoT devices; and servers) and software (operating systems and applications).
Safeguards
ID
Safeguard
IG
Asset Type
Function
4.1
Establish and Maintain a Secure Configuration Process
IG1
Applications
Protect
4.2
Establish and Maintain a Secure Configuration Process for Network Infrastructure
IG1
Network
Protect
4.3
Configure Automatic Session Locking on Enterprise Assets
IG1
Users
Protect
4.4
Implement and Manage a Firewall on Servers
IG1
Devices
Protect
4.5
Implement and Manage a Firewall on End-User Devices
IG1
Devices
Protect
4.6
Securely Manage Enterprise Assets and Software
IG1
Devices
Protect
4.7
Manage Default Accounts on Enterprise Assets and Software
IG1
Users
Protect
4.8
Uninstall or Disable Unnecessary Services
IG2
Devices
Protect
4.9
Configure Trusted DNS Servers
IG2
Devices
Protect
4.10
Enforce Automatic Device Lockout on Portable End-User Devices
IG2
Devices
Respond
4.11
Enforce Remote Wipe Capability
IG2
Devices
Protect
4.12
Separate Enterprise Workspaces on Mobile End-User Devices
IG3
Devices
Protect
Security Engineer Takeaway: Secure configuration = hardening. CIS Benchmarks provide the specific how-to for every major OS, application, and platform. IG1 covers firewalls, session locking, secure management, and default account management. Maps to ISO 27001 A.8.9 and BSI SYS modules.
CIS Control 5 — Account Management
Use processes and tools to assign and manage authorization to credentials for user accounts, including administrator accounts, as well as service accounts, to enterprise assets and software.
Safeguards
ID
Safeguard
IG
Asset Type
Function
5.1
Establish and Maintain an Inventory of Accounts
IG1
Users
Identify
5.2
Use Unique Passwords
IG1
Users
Protect
5.3
Disable Dormant Accounts
IG1
Users
Protect
5.4
Restrict Administrator Privileges to Dedicated Administrator Accounts
IG1
Users
Protect
5.5
Establish and Maintain an Inventory of Service Accounts
IG2
Users
Identify
5.6
Centralize Account Management
IG2
Users
Protect
Security Engineer Takeaway: Account management is your identity security foundation. IG1 essentials: inventory all accounts, enforce unique passwords, disable dormant accounts, and separate admin privileges. IG2 adds service account tracking and centralized management (Active Directory, Azure AD, etc.). Maps to NIS2 Art. 21(2)(i)(j) and ISO 27001 A.5.15–A.5.18.
CIS Control 6 — Access Control Management
Use processes and tools to create, assign, manage, and revoke access credentials and privileges for user, administrator, and service accounts for enterprise assets and software.
Safeguards
ID
Safeguard
IG
Asset Type
Function
6.1
Establish an Access Granting Process
IG1
Users
Protect
6.2
Establish an Access Revoking Process
IG1
Users
Protect
6.3
Require MFA for Externally-Exposed Applications
IG1
Users
Protect
6.4
Require MFA for Remote Network Access
IG1
Users
Protect
6.5
Require MFA for Administrative Access
IG1
Users
Protect
6.6
Establish and Maintain an Inventory of Authentication and Authorization Systems
IG2
Users
Identify
6.7
Centralize Access Control
IG2
Users
Protect
6.8
Define and Maintain Role-Based Access Control
IG3
Users
Protect
Security Engineer Takeaway: MFA is the single most impactful control you can deploy. CIS puts three MFA safeguards in IG1 — external apps, remote access, and admin access. This aligns directly with NIS2 Art. 21(2)(j) and is table-stakes for any security programme.
CIS Control 7 — Continuous Vulnerability Management
Develop a plan to continuously assess and track vulnerabilities on all enterprise assets within the enterprise's infrastructure, in order to remediate, and minimize, the window of opportunity for attackers.
Safeguards
ID
Safeguard
IG
Asset Type
Function
7.1
Establish and Maintain a Vulnerability Management Process
IG1
Applications
Protect
7.2
Establish and Maintain a Remediation Process
IG1
Applications
Respond
7.3
Perform Automated Operating System Patch Management
IG1
Applications
Protect
7.4
Perform Automated Application Patch Management
IG1
Applications
Protect
7.5
Perform Automated Vulnerability Scans of Internal Enterprise Assets
IG2
Applications
Identify
7.6
Perform Automated Vulnerability Scans of Externally-Exposed Enterprise Assets
IG2
Applications
Identify
7.7
Remediate Detected Vulnerabilities
IG2
Applications
Respond
Security Engineer Takeaway: Vulnerability management is a continuous cycle: discover, prioritize, remediate, verify. IG1 requires automated patching — start there. IG2 adds vulnerability scanning. Use risk-based prioritization (CVSS + asset criticality + exploitability) not just raw severity. Maps to NIS2 Art. 21(2)(e) and ISO 27001 A.8.8.
CIS Control 8 — Audit Log Management
Collect, alert, review, and retain audit logs of events that could help detect, understand, or recover from an attack.
Safeguards
ID
Safeguard
IG
Asset Type
Function
8.1
Establish and Maintain an Audit Log Management Process
IG1
Network
Detect
8.2
Collect Audit Logs
IG1
Network
Detect
8.3
Ensure Adequate Audit Log Storage
IG1
Network
Detect
8.4
Standardize Time Synchronization
IG2
Network
Detect
8.5
Collect Detailed Audit Logs
IG2
Network
Detect
8.6
Collect DNS Query Audit Logs
IG2
Network
Detect
8.7
Collect URL Request Audit Logs
IG2
Network
Detect
8.8
Collect Command-Line Audit Logs
IG2
Network
Detect
8.9
Centralize Audit Logs
IG2
Network
Detect
8.10
Retain Audit Logs
IG2
Network
Detect
8.11
Conduct Audit Log Reviews
IG2
Network
Detect
8.12
Collect Service Provider Logs
IG3
Data
Detect
Security Engineer Takeaway: Logging is detective control #1. IG1: establish a process, collect logs, ensure storage. IG2 is where it gets serious: centralized SIEM, DNS/URL/command-line logging, time sync, and regular reviews. This is your SOC foundation. Maps to ISO 27001 A.8.15–A.8.16 and DORA detection requirements.
CIS Control 9 — Email and Web Browser Protections
Improve protections and detections of threats from email and web vectors, as these are opportunities for attackers to manipulate human behavior through direct engagement.
Safeguards
ID
Safeguard
IG
Asset Type
Function
9.1
Ensure Use of Only Fully Supported Browsers and Email Clients
IG1
Applications
Protect
9.2
Use DNS Filtering Services
IG1
Network
Protect
9.3
Maintain and Enforce Network-Based URL Filters
IG2
Network
Protect
9.4
Restrict Unnecessary or Unauthorized Browser and Email Client Extensions
IG2
Applications
Protect
9.5
Implement DMARC
IG2
Network
Protect
9.6
Block Unnecessary File Types
IG2
Network
Protect
9.7
Deploy and Maintain Email Server Anti-Malware Protections
IG2
Network
Protect
Security Engineer Takeaway: Email and web are the top two attack vectors. IG1 basics: supported browsers, DNS filtering. IG2 adds URL filtering, extension control, DMARC, and email server protection. DMARC (9.5) alone prevents a huge percentage of phishing attacks.
CIS Control 10 — Malware Defenses
Prevent or control the installation, spread, and execution of malicious applications, code, or scripts on enterprise assets.
Configure Automatic Anti-Malware Scanning of Removable Media
IG2
Devices
Detect
10.5
Enable Anti-Exploitation Features
IG2
Devices
Protect
10.6
Centrally Manage Anti-Malware Software
IG2
Devices
Protect
10.7
Use Behavior-Based Anti-Malware Software
IG2
Devices
Detect
Security Engineer Takeaway: Modern endpoint protection goes far beyond signatures. IG1 covers AV deployment, auto-updates, and disabling autorun. IG2 adds EDR (behavior-based detection), centralized management, and anti-exploitation features. Maps to BSI OPS.1.1.4 and ISO 27001 A.8.7.
CIS Control 11 — Data Recovery
Establish and maintain data recovery practices sufficient to restore in-scope enterprise assets to a pre-incident and trusted state.
Safeguards
ID
Safeguard
IG
Asset Type
Function
11.1
Establish and Maintain a Data Recovery Process
IG1
Data
Recover
11.2
Perform Automated Backups
IG1
Data
Recover
11.3
Protect Recovery Data
IG1
Data
Protect
11.4
Establish and Maintain an Isolated Instance of Recovery Data
IG1
Data
Recover
11.5
Test Data Recovery
IG2
Data
Recover
Security Engineer Takeaway: Ransomware has made data recovery one of the most critical controls. All 4 IG1 safeguards are essential: process, automated backups, protection of backup data, and isolated (air-gapped) recovery instance. IG2 adds recovery testing. If you can't recover, you can't resist ransomware. Maps to NIS2 Art. 21(2)(c) and ISO 27001 A.8.13.
CIS Control 12 — Network Infrastructure Management
Establish and maintain the management and security of network infrastructure devices.
Safeguards
ID
Safeguard
IG
Asset Type
Function
12.1
Ensure Network Infrastructure is Up-to-Date
IG1
Network
Protect
12.2
Establish and Maintain a Secure Network Architecture
IG2
Network
Protect
12.3
Securely Manage Network Infrastructure
IG2
Network
Protect
12.4
Establish and Maintain Architecture Diagram(s)
IG2
Network
Identify
12.5
Centralize Network Authentication, Authorization, and Auditing (AAA)
IG2
Network
Protect
12.6
Use of Secure Network Management and Communication Protocols
IG2
Network
Protect
12.7
Ensure Remote Devices Utilize a VPN and are Connecting to an Enterprise's AAA Infrastructure
IG2
Network
Protect
12.8
Establish and Maintain Dedicated Computing Resources for All Administrative Work
IG3
Network
Protect
Security Engineer Takeaway: Network infrastructure is often the weakest link. IG1 starts simple: keep devices updated. IG2 builds your secure network architecture: segmentation, centralized AAA, architecture diagrams, secure protocols, and VPN. IG3 adds privileged access workstations (PAWs) for admin work.
CIS Control 13 — Network Monitoring and Defense
Operate processes and tooling to establish and maintain comprehensive network monitoring and defense against security threats across the enterprise's network infrastructure and user base.
Safeguards
ID
Safeguard
IG
Asset Type
Function
13.1
Centralize Security Event Alerting
IG2
Network
Detect
13.2
Deploy a Host-Based Intrusion Detection Solution
IG2
Devices
Detect
13.3
Deploy a Network Intrusion Detection Solution
IG2
Network
Detect
13.4
Perform Traffic Filtering Between Network Segments
IG2
Network
Protect
13.5
Manage Access Control for Remote Assets
IG2
Devices
Protect
13.6
Collect Network Traffic Flow Logs
IG2
Network
Detect
13.7
Deploy a Host-Based Intrusion Prevention Solution
IG3
Devices
Protect
13.8
Deploy a Network Intrusion Prevention Solution
IG3
Network
Protect
13.9
Deploy Port-Level Access Control
IG3
Devices
Protect
13.10
Perform Application Layer Filtering
IG3
Network
Protect
13.11
Tune Security Event Alerting Thresholds
IG3
Network
Detect
Security Engineer Takeaway: Note that CIS 13 has zero IG1 safeguards — network monitoring and defense is an IG2+ capability. IG2 builds your detection stack: centralized alerting (SIEM), IDS (host and network), traffic filtering, and flow logs. IG3 adds IPS, 802.1X, application layer filtering, and alert tuning.
CIS Control 14 — Security Awareness and Skills Training
Establish and maintain a security awareness program to influence behavior among the workforce to be security conscious and properly skilled to reduce cybersecurity risks to the enterprise.
Safeguards
ID
Safeguard
IG
Asset Type
Function
14.1
Establish and Maintain a Security Awareness Program
IG1
N/A
Protect
14.2
Train Workforce Members to Recognize Social Engineering Attacks
IG1
N/A
Protect
14.3
Train Workforce Members on Authentication Best Practices
IG1
N/A
Protect
14.4
Train Workforce Members on Data Handling Best Practices
IG1
N/A
Protect
14.5
Train Workforce Members on Causes of Unintentional Data Exposure
IG1
N/A
Protect
14.6
Train Workforce Members on Recognizing and Reporting Security Incidents
IG1
N/A
Protect
14.7
Train Workforce on How to Identify and Report if Their Enterprise Assets are Missing Security Updates
IG1
N/A
Protect
14.8
Train Workforce on the Dangers of Connecting to and Transmitting Enterprise Data Over Insecure Networks
IG1
N/A
Protect
14.9
Conduct Role-Specific Security Awareness and Skills Training
IG2
N/A
Protect
Security Engineer Takeaway: All 8 IG1 training safeguards reflect how critical human factors are. Map directly to NIS2 Art. 21(2)(g) and ISO 27001 A.6.3. Run phishing simulations monthly, track metrics, and provide role-specific training for developers, admins, and executives.
CIS Control 15 — Service Provider Management
Develop a process to evaluate service providers who hold sensitive data, or are responsible for an enterprise's critical IT platforms or processes, to ensure these providers are protecting those platforms and data appropriately.
Safeguards
ID
Safeguard
IG
Asset Type
Function
15.1
Establish and Maintain an Inventory of Service Providers
IG1
N/A
Identify
15.2
Establish and Maintain a Service Provider Management Policy
IG2
N/A
Identify
15.3
Classify Service Providers
IG2
N/A
Identify
15.4
Ensure Service Provider Contracts Include Security Requirements
IG2
Data
Protect
15.5
Assess Service Providers
IG3
N/A
Identify
15.6
Monitor Service Providers
IG3
N/A
Detect
15.7
Securely Decommission Service Providers
IG3
N/A
Protect
Security Engineer Takeaway: Service provider management maps directly to NIS2 Art. 21(2)(d) supply chain security and DORA's ICT third-party risk management. IG1 starts with inventory. IG2 adds policy, classification, and contract requirements. IG3 adds assessment, monitoring, and decommissioning.
CIS Control 16 — Application Software Security
Manage the security life cycle of in-house developed, hosted, or acquired software to prevent, detect, and remediate security weaknesses before they can impact the enterprise.
Safeguards
ID
Safeguard
IG
Asset Type
Function
16.1
Establish and Maintain a Secure Application Development Process
IG2
Applications
Protect
16.2
Establish and Maintain a Process to Accept and Address Software Vulnerabilities
IG2
Applications
Protect
16.3
Perform Root Cause Analysis on Security Vulnerabilities
IG2
Applications
Protect
16.4
Establish and Manage an Inventory of Third-Party Software Components
IG2
Applications
Protect
16.5
Use Up-to-Date and Trusted Third-Party Software Components
IG2
Applications
Protect
16.6
Establish and Maintain a Severity Rating System and Process for Application Vulnerabilities
IG2
Applications
Protect
16.7
Use Standard Hardening Configuration Templates for Application Infrastructure
IG2
Applications
Protect
16.8
Separate Production and Non-Production Systems
IG2
Applications
Protect
16.9
Train Developers in Application Security Concepts and Secure Coding
IG2
N/A
Protect
16.10
Apply Secure Design Principles in Application Architectures
IG2
Applications
Protect
16.11
Leverage Vetted Modules or Services for Application Security Components
IG2
Applications
Protect
16.12
Implement Code-Level Security Checks
IG3
Applications
Protect
16.13
Conduct Application Penetration Testing
IG3
Applications
Protect
16.14
Conduct Threat Modeling
IG3
Applications
Protect
Security Engineer Takeaway: Application security is entirely IG2+. CIS 16 covers the full SDLC: secure development processes, SBOM management (16.4), developer training, secure design, hardened infrastructure, and production/non-production separation. IG3 adds SAST/DAST (16.12), app pen testing, and threat modeling.
CIS Control 17 — Incident Response Management
Establish a program to develop and maintain an incident response capability (e.g., policies, plans, procedures, defined roles, training, and communications) to prepare, detect, and quickly respond to an attack.
Safeguards
ID
Safeguard
IG
Asset Type
Function
17.1
Designate Personnel to Manage Incident Handling
IG1
N/A
Respond
17.2
Establish and Maintain Contact Information for Reporting Security Incidents
IG1
N/A
Respond
17.3
Establish and Maintain an Enterprise Process for Reporting Incidents
IG1
N/A
Respond
17.4
Establish and Maintain an Incident Response Process
IG2
N/A
Respond
17.5
Assign Key Roles and Responsibilities
IG2
N/A
Respond
17.6
Define Mechanisms for Communicating During Incident Response
IG2
N/A
Respond
17.7
Conduct Routine Incident Response Exercises
IG2
N/A
Respond
17.8
Conduct Post-Incident Reviews
IG2
N/A
Respond
17.9
Establish and Maintain Security Incident Thresholds
IG3
N/A
Respond
Security Engineer Takeaway: IG1 gets you started with designated personnel, contact info, and a reporting process. IG2 builds a mature IR capability: formal process, RACI, communication plans, tabletop exercises, and post-incident reviews. Maps to NIS2 Art. 21(2)(b) and Art. 23.
CIS Control 18 — Penetration Testing
Test the effectiveness and resiliency of enterprise assets through identifying and exploiting weaknesses in controls (people, processes, and technology), and simulating the objectives and actions of an attacker.
Safeguards
ID
Safeguard
IG
Asset Type
Function
18.1
Establish and Maintain a Penetration Testing Program
IG2
N/A
Identify
18.2
Perform Periodic External Penetration Tests
IG2
Network
Identify
18.3
Remediate Penetration Test Findings
IG2
Network
Respond
18.4
Validate Security Measures
IG3
Network
Identify
18.5
Perform Periodic Internal Penetration Tests
IG3
Network
Identify
Security Engineer Takeaway: Penetration testing validates all your other controls. IG2 requires external pen tests; IG3 adds internal testing and security measure validation. Maps to DORA TLPT requirements and NIS2 Art. 21(2)(f) effectiveness assessment.
Safeguard Explorer
All 18 CIS Controls with their 153 Safeguards. Click to expand details, safeguard lists, and practical security notes.
Basic Hygiene — Controls 1–6
CIS 1Inventory and Control of Enterprise AssetsCritical▶
Actively manage all enterprise assets connected to the infrastructure to accurately know what needs to be monitored and protected. 5 Safeguards (2 IG1, 2 IG2, 1 IG3).
Safeguards
1.1 (IG1): Establish and Maintain Detailed Enterprise Asset Inventory
1.2 (IG1): Address Unauthorized Assets
1.3 (IG2): Utilize an Active Discovery Tool
1.4 (IG2): Use DHCP Logging to Update Asset Inventory
1.5 (IG3): Use a Passive Asset Discovery Tool
Security Engineer Takeaway: Asset inventory is the foundation. You can't protect what you don't know about. Start with a spreadsheet if needed, automate with discovery tools at IG2.
CIS 2Inventory and Control of Software AssetsCritical▶
Actively manage all software on the network so that only authorized software is installed and can execute. 7 Safeguards (3 IG1, 3 IG2, 1 IG3).
Safeguards
2.1 (IG1): Establish and Maintain a Software Inventory
2.2 (IG1): Ensure Authorized Software is Currently Supported
Security Engineer Takeaway: Application allowlisting (2.5) is one of the most effective controls against malware and unauthorized software execution.
CIS 3Data ProtectionCritical▶
Develop processes and technical controls to identify, classify, securely handle, retain, and dispose of data. 14 Safeguards (6 IG1, 6 IG2, 2 IG3).
Key Safeguards
IG1: Data management process, data inventory, access control lists, data retention, secure disposal, endpoint encryption
IG2: Data classification, data flow documentation, removable media encryption, transit encryption, at-rest encryption, sensitivity segmentation
IG3: DLP solution, sensitive data access logging
Security Engineer Takeaway: CIS 3 has 14 safeguards — the most of any control. Data protection spans from basic (know your data, control access) to advanced (DLP, segmentation). Start with endpoint encryption and access controls.
CIS 4Secure Configuration of Enterprise Assets and SoftwareCritical▶
Establish and maintain secure configuration of enterprise assets and software. 12 Safeguards (7 IG1, 5 IG2, 0 IG3).
IG3: Separate enterprise workspaces on mobile devices
Security Engineer Takeaway: Use CIS Benchmarks for the specific hardening guidance. CIS 4 has the most IG1 safeguards (7) after CIS 14 (8), showing how important secure configuration is as a baseline.
CIS 5Account ManagementCritical▶
Use processes and tools to assign and manage authorization to credentials for user accounts, including administrator and service accounts. 6 Safeguards (4 IG1, 2 IG2).
IG2: Service account inventory, centralized account management
Security Engineer Takeaway: Dedicated admin accounts (5.4) is critical — never use your daily account for administrative tasks. Dormant accounts are a top attack vector.
CIS 6Access Control ManagementCritical▶
Use processes and tools to create, assign, manage, and revoke access credentials and privileges. 8 Safeguards (5 IG1, 2 IG2, 1 IG3).
Key Safeguards
IG1: Access granting process, access revoking process, MFA for external apps, MFA for remote access, MFA for admin access
IG2: Auth/authz inventory, centralized access control
IG3: Role-based access control (RBAC)
Security Engineer Takeaway: Three MFA safeguards in IG1 — this is the single most impactful control family for preventing account compromise. Start here if you're doing nothing else.
Foundational — Controls 7–12
CIS 7Continuous Vulnerability ManagementCritical▶
Develop a plan to continuously assess and track vulnerabilities on all enterprise assets. 7 Safeguards (4 IG1, 3 IG2).
Security Engineer Takeaway: Automated patching (7.3, 7.4) is IG1 because unpatched systems are the #1 exploited vector. Vulnerability scanning (IG2) tells you what patching missed.
CIS 8Audit Log ManagementCritical▶
Collect, alert, review, and retain audit logs of events that could help detect, understand, or recover from an attack. 12 Safeguards (3 IG1, 8 IG2, 1 IG3).
Security Engineer Takeaway: IG2 logging is your SIEM foundation. DNS query logs (8.6) and command-line logs (8.8) are incredibly high-value for threat detection.
CIS 9Email and Web Browser ProtectionsImportant▶
Improve protections and detections of threats from email and web vectors. 7 Safeguards (2 IG1, 5 IG2).
Security Engineer Takeaway: DMARC (9.5) is one of the highest-ROI controls — prevents domain spoofing at no cost. DNS filtering (9.2) blocks known malicious domains at the network level.
CIS 10Malware DefensesCritical▶
Prevent or control the installation, spread, and execution of malicious applications. 7 Safeguards (3 IG1, 4 IG2).
IG2: Removable media scanning, anti-exploitation, centralized management, behavior-based detection
Security Engineer Takeaway: Behavior-based detection (10.7) = EDR. If you're still on signature-only AV, upgrading to EDR is one of the most impactful IG2 investments.
CIS 11Data RecoveryCritical▶
Establish and maintain data recovery practices sufficient to restore in-scope enterprise assets. 5 Safeguards (4 IG1, 1 IG2).
Security Engineer Takeaway: 4 of 5 safeguards are IG1 — recovery is essential. The isolated instance (11.4) is your ransomware insurance. Test your recovery (11.5) before you need it.
CIS 12Network Infrastructure ManagementImportant▶
Establish and maintain the management and security of network infrastructure devices. 8 Safeguards (1 IG1, 6 IG2, 1 IG3).
Security Engineer Takeaway: Zero IG1 safeguards — network monitoring requires organizational maturity. This is where your SOC investment lives. Start with centralized alerting (13.1) and NIDS (13.3).
CIS 14Security Awareness and Skills TrainingCritical▶
Establish and maintain a security awareness program to influence workforce behavior. 9 Safeguards (8 IG1, 1 IG2).
Key Safeguards
IG1: Awareness program, social engineering recognition, authentication best practices, data handling, unintentional data exposure, incident recognition/reporting, missing security updates, insecure networks
IG2: Role-specific training
Security Engineer Takeaway: 8 of 9 safeguards are IG1 — the most for any control. Humans are both the weakest link and the strongest defense when properly trained. Monthly phishing simulations, track click rates, reward reporters.
CIS 15Service Provider ManagementImportant▶
Develop a process to evaluate service providers who hold sensitive data or are responsible for critical IT platforms. 7 Safeguards (1 IG1, 3 IG2, 3 IG3).
Security Engineer Takeaway: Start with knowing who your service providers are (15.1 is IG1). Maps to DORA ICT third-party risk and NIS2 supply chain requirements.
CIS 16Application Software SecurityImportant▶
Manage the security life cycle of in-house developed, hosted, or acquired software. 14 Safeguards (0 IG1, 11 IG2, 3 IG3).
Security Engineer Takeaway: Zero IG1 safeguards — AppSec requires development maturity. SBOM (16.4) and third-party component management (16.5) are increasingly critical for supply chain security.
CIS 17Incident Response ManagementCritical▶
Establish a program to develop and maintain an incident response capability. 9 Safeguards (3 IG1, 5 IG2, 1 IG3).
Key Safeguards
IG1: Designated IR personnel, contact information for reporting, enterprise reporting process
IG2: Formal IR process, roles/responsibilities, communication mechanisms, routine exercises, post-incident reviews
IG3: Security incident thresholds
Security Engineer Takeaway: IG1 gets you the basics: know who handles incidents and how to report them. IG2 builds maturity with exercises and post-incident reviews. Maps directly to NIS2 reporting requirements.
CIS 18Penetration TestingImportant▶
Test the effectiveness and resiliency of enterprise assets through identifying and exploiting weaknesses. 5 Safeguards (0 IG1, 3 IG2, 2 IG3).
Security Engineer Takeaway: Pen testing is the ultimate validation of all other controls. External first (IG2), then internal (IG3). Maps to DORA TLPT for financial services.
Implementation Groups (IGs)
CIS Controls use Implementation Groups to prioritize safeguards based on organizational profile. Each IG builds on the previous one, creating a cumulative model — IG2 includes all IG1 safeguards plus additional ones, and IG3 includes everything.
The Three Implementation Groups
IG1 — Essential Cyber Hygiene (56 Safeguards)
Every organization regardless of size
Minimum standard of information security for all enterprises
Defends against the most common non-targeted attacks
Key Insight: Controls with zero IG1 safeguards (CIS 13 Network Monitoring, CIS 16 Application Security, CIS 18 Penetration Testing) require organizational maturity and dedicated security staff. Controls with the most IG1 safeguards (CIS 14: 8 safeguards, CIS 4: 7 safeguards, CIS 3: 6 safeguards) represent the most critical baseline activities.
Key Dates & Timeline
Evolution of the CIS Critical Security Controls from SANS Top 20 to CIS Controls v8.1.
2008
SANS Top 20 Critical Security Controls
First publication of the Critical Security Controls, then known as the SANS Top 20. Originally developed in response to massive data losses at the US defense industrial base.
2013
Version 5.0 — Center for Internet Security
Stewardship of the Controls transferred to the Center for Internet Security (CIS). Version 5.0 released under CIS governance with community-driven development model.
2015
CIS Controls v6
Major revision with restructured controls and sub-controls. Continued refinement of prioritization and community input.
2018
CIS Controls v7.0
Introduced Implementation Groups (IG1, IG2, IG3) for the first time. 20 Controls with 171 Sub-Controls. Added cloud, mobile, and outsourcing considerations.
2019
CIS Controls v7.1
Minor updates and clarifications to v7.0. Refined Implementation Group assignments. Improved clarity of sub-control descriptions.
May 2021
CIS Controls v8 Released
Major overhaul: consolidated from 20 to 18 Controls, renamed "Sub-Controls" to "Safeguards," and reorganized to be technology-agnostic. Designed for cloud-first, mobile, work-from-anywhere environments.
June 2023
CIS Controls v8.1 Released
Current version. 153 Safeguards with minor refinements. Added asset type and security function classifications to every safeguard. Improved IG assignments and clarified safeguard descriptions.
Ongoing
CIS Benchmarks & Community Maintenance
CIS continuously maintains CIS Benchmarks for platform-specific guidance, the Community Defense Model (CDM) for attack data analysis, and mapping documents to other frameworks.
Compliance Checklist
Track your CIS Controls implementation progress. Checkmarks are saved locally in your browser.
IG1 — Essential Cyber Hygiene
Enterprise asset inventory established and maintained (CIS 1.1)
Unauthorized assets identified and addressed (CIS 1.2)
Software inventory established and maintained (CIS 2.1–2.3)
Data management process and inventory established (CIS 3.1–3.2)
Data access control lists configured (CIS 3.3)
Data on end-user devices encrypted (CIS 3.6)
Secure configuration processes for assets and network infrastructure (CIS 4.1–4.2)
Host-based firewalls on servers and endpoints (CIS 4.4–4.5)
CIS Controls are used globally by organizations of all sizes and sectors. Their free, prioritized nature makes them the most widely adopted cybersecurity framework in the world.
Regulatory Alignment
Framework
CIS Controls Mapping
Notes
NIST CSF 2.0
Official CIS-published mapping
Safeguards map to CSF categories
ISO 27001
Community mapping available
Good coverage of Annex A controls
NIS2 Art. 21
Maps to all 10 measures
IG2 provides strong NIS2 coverage
DORA
Aligns with ICT risk management
Supplements DORA implementation
PCI DSS 4.0
CIS-published mapping
Payment card security
HIPAA
CIS-published mapping
Healthcare security
CMMC
CIS-published mapping
US defense supply chain
NIST 800-53
CIS-published mapping
US federal controls
Common Adoption
Organization Type
Recommended IG
Notes
Small/Medium Business
IG1
Essential cyber hygiene — 56 safeguards
Mid-size Enterprise
IG2
Handles sensitive data with moderate security team
Large Enterprise
IG2–IG3
Complex environment, dedicated security team
Critical Infrastructure
IG3
High-value targets, advanced adversaries
Healthcare
IG2+
HIPAA alignment, patient data protection
Financial Services
IG2–IG3
DORA/regulatory requirements
Government
IG2–IG3
CMMC, NIST 800-53 alignment
Note: CIS Controls are framework-agnostic and supplement (not replace) regulatory requirements. Organizations subject to DORA, NIS2, or ISO 27001 can use CIS Controls as a prioritized implementation guide, leveraging the official mapping documents to demonstrate coverage.
CIS Controls Mappings & Benchmarks
Official mappings, benchmarks, and guidance documents that connect CIS Controls to other frameworks and provide platform-specific implementation guidance.
Official CIS Mappings
CIS Controls to NIST CSF 2.0
Official CIS Mapping
Maps all 153 safeguards to NIST CSF 2.0 categories and subcategories
Enables bi-directional crosswalk between frameworks
Available free on the CIS website
CIS Controls to NIST 800-53 Rev. 5
Official CIS Mapping
Detailed mapping to NIST SP 800-53 controls
Essential for US federal and defense compliance
Supports CMMC alignment
CIS Controls to ISO 27001
Community Mapping
Maps safeguards to ISO 27001:2022 Annex A controls
Demonstrates coverage for certification
Useful for gap analysis
CIS Controls to PCI DSS 4.0
Official CIS Mapping
Payment Card Industry Data Security Standard alignment
Supports PCI DSS compliance efforts
Covers all 12 PCI DSS requirements
CIS Controls to MITRE ATT&CK
Official CIS Mapping
Maps safeguards to MITRE ATT&CK techniques
Shows which attack techniques each safeguard mitigates
Foundation of the Community Defense Model (CDM)
CIS Benchmarks
CIS Benchmarks are prescriptive configuration guides for specific platforms. They are the "how-to" that complements the "what-to" of CIS Controls.
Operating Systems
Windows, Linux, macOS
Windows Server 2022 / Windows 11
Ubuntu Linux / Red Hat Enterprise Linux / SUSE
macOS Ventura / Sonoma
Detailed hardening settings with rationale
Cloud Providers
AWS, Azure, GCP
AWS Foundations Benchmark
Microsoft Azure Foundations Benchmark
Google Cloud Platform Benchmark
Oracle Cloud Infrastructure Benchmark
Containers & Orchestration
Docker, Kubernetes
Docker Benchmark
Kubernetes Benchmark
Amazon EKS / Azure AKS / GKE Benchmarks
Network, Database & Web
Various platforms
Cisco IOS / Palo Alto / Juniper
Microsoft SQL Server / Oracle / PostgreSQL / MySQL
Apache / Nginx / IIS
Microsoft 365 / Google Workspace
Adoption & Business Benefits
Why implementing CIS Controls delivers measurable value beyond security improvements.
IG1 Stops 80%+ of Attacks
CIS Community Defense Model Research
Research shows IG1 safeguards defend against the most common attack techniques
56 safeguards provide disproportionate security improvement
Start here for maximum impact with minimum investment
Based on real-world attack data mapped to MITRE ATT&CK
Free and Open
No barriers to entry
CIS Controls are free to download and use
No licensing fees, no vendor lock-in
CIS Benchmarks are free for non-commercial use
Community-developed by practitioners for practitioners
Cyber Insurance
Improve insurability and reduce premiums
Many cyber insurance providers reference CIS Controls (especially IG1) as minimum security expectations
Implementing CIS Controls can improve insurability
Multi-State and Elections Infrastructure Information Sharing and Analysis Centers. Threat intelligence and support for state, local, tribal, and territorial governments.
The knowledge base of adversary tactics and techniques that CIS Controls are mapped against. Essential for understanding what your controls defend against.
ATT&CKThreat Intel
Tip: CIS Controls v8.1 is the current version. Always reference the latest version from cisecurity.org. The CIS Controls Navigator is the best starting point for mapping to your existing framework requirements.
Search Results
🔍
Start typing in the search bar to find controls, safeguards, and keywords.