CIS Controls

Also known as: CIS Critical Security Controls

framework · cybersecurity · regulatory-standard

Center for Internet Security's prioritized set of cybersecurity actions for organizations.

The CIS Controls (formerly the SANS Top 20, then the CIS Critical Security Controls) are the prioritized set of cybersecurity actions developed and maintained by the Center for Internet Security, distinguished from comprehensive control catalogs (NIST 800-53, ISO 27002) by explicit prioritization based on attack-data analysis. The framework's central commitment is that organizations should focus first on controls that block the most common attacks observed in real-world data, with implementation tiers (Implementation Groups IG1, IG2, IG3) allowing organizations of different sizes and risk profiles to focus on appropriate subsets. The current Version 8 (2021, with v8.1 update 2024) consists of 18 controls organized into Implementation Groups, with each control containing safeguards (specific actions). Key control categories include: Inventory and Control of Enterprise Assets (CIS Control 1); Inventory and Control of Software Assets (Control 2); Data Protection (Control 3); Secure Configuration of Enterprise Assets and Software (Control 4); Account Management (Control 5); Access Control Management (Control 6); Continuous Vulnerability Management (Control 7); Audit Log Management (Control 8); through to Application Software Security (Control 16) and Penetration Testing (Control 18). The CIS Controls are widely cited and substantially more accessible than NIST 800-53 or ISO 27002, with explicit mappings to those frameworks. CIS publishes complementary materials including CIS Benchmarks (configuration guidance for specific platforms) and CIS Controls v8 mappings to NIST CSF, NIST 800-53, ISO 27002, MITRE ATT&CK, and other frameworks.

Originators

Center for Internet Security (current); SANS Institute and Council on Cybersecurity (earlier development); broader cybersecurity practitioner community high

Year / Decade

2008-2009 (SANS Top 20 origin); 2015 (Council on Cybersecurity / CIS adoption); 2021 (Version 8); 2024 (v8.1) high

Primary sources

Center for Internet Security (2021, v8.1 2024). CIS Critical Security Controls Version 8, CIS Benchmarks (platform-specific configuration guidance, ongoing updates), historical SANS Institute Top 20 publications high

Core components

Primary use case

Prioritized cybersecurity action framework particularly for small and mid-market organizations; basis for many baseline security programs; foundation for state and local government cybersecurity guidance (some states reference CIS Controls in laws); integration with NIST and ISO frameworks via cross-walks; reference framework in cybersecurity education; widely adopted in cyber-insurance underwriting questions; CIS Benchmarks heavily used for system hardening guidance; influence on commercial vulnerability scanning and configuration management products.

Common criticisms

Lineage

Siblings
NIST 800-53, ISO/IEC 27002