CIS Controls
What is CIS Controls?
CIS ControlsA prioritized set of best-practice cybersecurity safeguards maintained by the Center for Internet Security to defend against the most common cyberattacks.
The CIS Controls are a community-developed framework of prioritized cybersecurity safeguards published by the Center for Internet Security (CIS). The lineage runs back to the SANS Top 20, later the "Critical Security Controls," before CIS assumed stewardship. The current version 8.1, released in June 2024, defines 18 controls and 153 safeguards, and — reflecting a deliberate shift toward cloud, mobile, and outsourced environments — organizes them around activities rather than device types.
The signature feature is the three Implementation Groups. IG1, the "essential cyber hygiene" baseline every enterprise should meet, comprises 56 safeguards drawn from 15 controls; IG2 and IG3 add safeguards for organizations with greater resources and risk. A small business can therefore start with a concrete, achievable IG1 subset instead of an abstract "do security" mandate. Version 8.1 also aligned with NIST CSF 2.0, adding coverage for the new Govern function and updated asset classes.
Although the CIS Controls carry no legal force, they are widely mapped to NIST CSF, ISO/IEC 27001, PCI DSS, and CMMC, so implementing them once satisfies many overlapping requirements. CIS publishes companion Benchmarks — hardening guides for specific operating systems and cloud services — that turn several safeguards into checkable configuration settings.
flowchart TD A[CIS Controls v8.1<br/>18 controls · 153 safeguards] --> B[IG1: essential cyber hygiene<br/>56 safeguards — all enterprises] A --> C[IG2: adds safeguards<br/>for higher risk/resources] A --> D[IG3: full set<br/>mature, high-value targets] B --> C --> D A --> E[CIS Benchmarks<br/>OS & cloud hardening] A --> F[Mapped to NIST CSF 2.0,<br/>ISO 27001, PCI DSS, CMMC]
● Examples
- 01
An SMB adopting IG1 safeguards to build a baseline security programme.
- 02
A vendor mapping its product to specific CIS safeguards in marketing materials.
● Frequently asked questions
What is CIS Controls?
A prioritized set of best-practice cybersecurity safeguards maintained by the Center for Internet Security to defend against the most common cyberattacks. It belongs to the Compliance & Frameworks category of cybersecurity.
What does CIS Controls mean?
A prioritized set of best-practice cybersecurity safeguards maintained by the Center for Internet Security to defend against the most common cyberattacks.
How do you defend against CIS Controls?
Defences for CIS Controls typically combine technical controls and operational practices, as detailed in the full definition above.
What are other names for CIS Controls?
Common alternative names include: CIS Top 18, SANS Top 20 (legacy).