Skip to main content

FRAMEWORKS & CERTIFICATIONS

What Is CIS Controls?

DEFINITION

CIS Controls are a prioritized set of prescriptive cybersecurity safeguards published by the Center for Internet Security. Version 8.1 organizes 18 controls into specific safeguards grouped by Implementation Groups, IG1 through IG3, so organizations can start with an essential cyber hygiene baseline and scale up. They answer the question of what to do first, complementing outcome-based frameworks like the NIST CSF.

Where frameworks like NIST CSF describe outcomes, the CIS Controls prescribe actions: inventory your assets, manage administrative privileges, deploy centralized logging, and so on. Each of the 18 controls breaks into safeguards assigned to one of three Implementation Groups. IG1, called essential cyber hygiene, is the baseline every organization should meet; IG2 and IG3 add safeguards for organizations with more sensitive data and higher risk exposure. Version 8.1 also aligned the controls with the governance emphasis of NIST CSF 2.0, and CIS publishes mappings to CSF, ISO 27001, and other frameworks. The related CIS Benchmarks are a separate product covering secure configuration of specific technologies.

Cyber insurers commonly probe for CIS-style safeguards in underwriting questionnaires, and some U.S. state laws reference the CIS Controls among recognized frameworks in breach litigation safe harbor provisions.

For a mid-market company with no formal program, IG1 is the fastest defensible starting point: a concrete, ordered to-do list rather than a framework to interpret. It also feeds cleanly into a later NIST CSF alignment or SOC 2 readiness effort, since the safeguards map onto both.

Running a program that has to satisfy this?

A Z Cyber advisor can walk your current posture against the requirement and show you what a running program looks like on Glance.

Meet Your Security Team →