CIS Controls
Also known as: CIS Critical Security Controls
Center for Internet Security's prioritized set of cybersecurity actions for organizations.
The CIS Controls (formerly the SANS Top 20, then the CIS Critical Security Controls) are the prioritized set of cybersecurity actions developed and maintained by the Center for Internet Security, distinguished from comprehensive control catalogs (NIST 800-53, ISO 27002) by explicit prioritization based on attack-data analysis. The framework's central commitment is that organizations should focus first on controls that block the most common attacks observed in real-world data, with implementation tiers (Implementation Groups IG1, IG2, IG3) allowing organizations of different sizes and risk profiles to focus on appropriate subsets. The current Version 8 (2021, with v8.1 update 2024) consists of 18 controls organized into Implementation Groups, with each control containing safeguards (specific actions). Key control categories include: Inventory and Control of Enterprise Assets (CIS Control 1); Inventory and Control of Software Assets (Control 2); Data Protection (Control 3); Secure Configuration of Enterprise Assets and Software (Control 4); Account Management (Control 5); Access Control Management (Control 6); Continuous Vulnerability Management (Control 7); Audit Log Management (Control 8); through to Application Software Security (Control 16) and Penetration Testing (Control 18). The CIS Controls are widely cited and substantially more accessible than NIST 800-53 or ISO 27002, with explicit mappings to those frameworks. CIS publishes complementary materials including CIS Benchmarks (configuration guidance for specific platforms) and CIS Controls v8 mappings to NIST CSF, NIST 800-53, ISO 27002, MITRE ATT&CK, and other frameworks.
Core components
- 18 controls in Version 8 organized by Implementation Group (IG1, IG2, IG3)
- Implementation Groups for different organization sizes and risk profiles
- Safeguards (specific actions within each control)
- Prioritization based on attack-data analysis
- Cross-walks to NIST CSF, NIST 800-53, ISO 27002, MITRE ATT&CK
- CIS Benchmarks (platform-specific configuration guidance)
- Free availability for non-commercial use
- Substantial industry adoption particularly in smaller and mid-market organizations
- Distinction from comprehensive control catalogs by explicit prioritization
Primary use case
Prioritized cybersecurity action framework particularly for small and mid-market organizations; basis for many baseline security programs; foundation for state and local government cybersecurity guidance (some states reference CIS Controls in laws); integration with NIST and ISO frameworks via cross-walks; reference framework in cybersecurity education; widely adopted in cyber-insurance underwriting questions; CIS Benchmarks heavily used for system hardening guidance; influence on commercial vulnerability scanning and configuration management products.
Common criticisms
- Prioritization based on attack-data analysis is empirically grounded but the specific ordering and weighting reflects subjective methodology choices that are not always transparent
- tendency for organizations to claim 'CIS Controls implemented' without evidence of substantive implementation
- framework's accessibility relative to NIST and ISO has produced widespread adoption with varying implementation quality
- commercial vendors marketing 'CIS Controls compliance' tools sometimes overstate what their products actually validate
- integration with cloud-native architecture patterns has improved through V8 but remains incomplete in places
- CIS Benchmarks vary in currency for fast-evolving platforms
- the framework focuses on technical and operational controls but underweights governance, risk management, and supply chain dimensions that comprehensive frameworks address
- cross-walks with other frameworks have minor mismatches that create implementation friction
- CIS as nonprofit funded partially by sponsors has produced occasional concerns about vendor influence on guidance.
Lineage
- Siblings
- NIST 800-53, ISO/IEC 27002