CIS Critical Security Controls

Industry StandardGeneral Cybersecurity2021
ByDecipherU Editorial

The CIS Controls are a prioritized set of cybersecurity actions organized into 18 control families and three Implementation Groups (IGs) based on organizational maturity. Developed by the Center for Internet Security through consensus from cybersecurity practitioners, they provide a practical starting point for organizations building their cybersecurity programs. Version 8.1 (June 2024) refined mappings and implementation guidance.

Quick Reference

EnactedOriginal SANS Top 20: 2008; CIS Controls v8: May 2021; v8.1: June 2024
Enforcement BodyVoluntary; Center for Internet Security (CIS) maintains; referenced by many state and local government standards
PenaltiesNo direct penalties (voluntary framework)
Applicable ToAny organization; Implementation Groups allow tailoring to small (IG1), medium (IG2), and large (IG3) enterprises

Key Requirements

Control 1 (Inventory and Control of Enterprise Assets)

Actively manage all enterprise assets connected to the infrastructure to accurately identify which assets need to be monitored and protected

Control 3 (Data Protection)

Develop processes and technical controls to identify, classify, securely handle, retain, and dispose of data

Control 4 (Secure Configuration of Enterprise Assets and Software)

Establish and maintain secure configuration processes for enterprise assets and software

Control 8 (Audit Log Management)

Collect, alert, review, and retain audit logs of events to help detect, understand, and recover from attacks

How Does CIS Controls Affect Cybersecurity Careers?

CIS Controls are often the first cybersecurity framework that junior professionals learn. IG1 (essential cyber hygiene) defines the minimum controls every organization should implement, making it accessible for entry-level cybersecurity roles. GRC analysts use CIS Controls as a practical complement to NIST CSF. Many state and local government contracts reference CIS Controls.

How Does CIS Controls Affect Cybersecurity Sales?

The Implementation Group model helps sales teams tailor product positioning: IG1 for SMBs, IG2 for mid-market, IG3 for enterprise. Asset inventory, endpoint security, and log management solutions map directly to specific CIS Controls. Vendors can use the CIS Controls mapping as a simple way to explain product value to less technical buyers.

Cybersecurity Roles That Work With CIS Controls

Related Cybersecurity Certifications

Related Cybersecurity Laws

Read the full text of CIS Controls at the official source: https://www.cisecurity.org/controls

Frequently Asked Questions

The CIS Controls are a prioritized set of cybersecurity actions organized into 18 control families and three Implementation Groups (IGs) based on organizational maturity. Developed by the Center for Internet Security through consensus from cybersecurity practitioners, they provide a practical starting point for organizations building their cybersecurity programs. Version 8.1 (June 2024) refined mappings and implementation guidance.

CIS Controls are often the first cybersecurity framework that junior professionals learn. IG1 (essential cyber hygiene) defines the minimum controls every organization should implement, making it accessible for entry-level cybersecurity roles. GRC analysts use CIS Controls as a practical complement to NIST CSF. Many state and local government contracts reference CIS Controls.

No direct penalties (voluntary framework)

Last verified: April 2026?Report an inaccuracy

Explore Related Cybersecurity Resources

Was this page helpful?